This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Think I've been struck by virus of some sort

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Don't know exactly what is up. Wondering if I could get some help. Everything is running slow. Mouse seems to be acting up also. Won't respond to single left clicks.

Malwarebytes' Anti-Malware 1.44
Database version: 3753
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

2010-02-17 20:44:43
mbam-log-2010-02-17 (20-44-43).txt

Scan type: Quick Scan
Objects scanned: 120690
Time elapsed: 8 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 21
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\dlp.dlpobj (Adware.WebDir) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\dlp.dlpobj.1 (Adware.WebDir) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b1e22eb8-2ae8-4e8e-96ae-74f2a1764533} (Adware.WebDir) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{bdbebf18-7615-4971-9ac3-bd6ffb7ad6c1} (Adware.WebDir) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{be2ed590-ca49-46b5-8cce-244fb2e0d1aa} (Adware.WebDir) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07851c6a-1c43-41d9-8319-bc89154a8c00} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{bdbebf18-7615-4971-9ac3-bd6ffb7ad6c1} (Adware.WebDir) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{be2ed590-ca49-46b5-8cce-244fb2e0d1aa} (Adware.WebDir) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{1f2f95d9-bafd-4769-85a2-4169957db67e} (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\kernelexe (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dot1XCfg (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
C:\WINDOWS\BM071fc221.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM071fc221.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:55, on 2010-02-17
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\SyncServer.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\MsiExec.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;*.local
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303307750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303296640
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 8094 bytes
Hello hammerfist and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 5 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. OTL ncludes all the scan locations of HijackThis and more. It's not only a more comprehensive scan tool, but also offers more powerful removal features.

Download and Run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file.
  • Save it where you can easily find it, such as your desktop, and copy/paste the results in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
OTL Extras logfile created on: 2010-02-20 08:42:43 - Run 1
OTL by OldTimer - Version 3.1.30.1 Folder = C:\Documents and Settings\Mary\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd

766.00 Mb Total Physical Memory | 328.00 Mb Available Physical Memory | 43.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.84 Gb Total Space | 1.93 Gb Free Space | 3.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D8KG5T21
Current User Name: Mary
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (America Online, Inc.)
"C:\Program Files\Last.fm\LastFM.exe" = C:\Program Files\Last.fm\LastFM.exe:*:Disabled:LastFM – File not found
"C:\Program Files\Soulseek1\slsk.exe" = C:\Program Files\Soulseek1\slsk.exe:*:Enabled:SoulSeek – ()
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – File not found
"C:\Program Files\SoulseekNS\slsk.exe" = C:\Program Files\SoulseekNS\slsk.exe:*:Enabled:SoulSeek – ()
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05C56753-F144-44BC-BA67-83CC5DBF395C}" = F300
"{06C324C1-8477-4125-B81E-C0B2AA1FB564}" = Toy Factory
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{264DEAD1-8B60-A560-4130-0AC47215FA45}" = Seesmic Desktop
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{2968BD2F-AB87-4E47-A6FE-6A881F70E59C}" = Millie's Math House
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Office 2002
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{45893FEB-30FD-4034-8661-3BA4238FE67A}" = Britannica Ready Reference
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = BACS
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA player 4.1
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115286387}" = Operation Mania
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{8795CBED-55E2-4693-9F14-84EC446935BE}" = SpeechRedist
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9D98F245-3010-43C6-B3B0-67A464DA298E}" = ELNKInst
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A435B708-FACA-4740-92ED-03CE0A16D2F0}" = Disneys Digital Coloring Book Featuring Little Mermaid
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A7E6A962-C086-47E3-BAEC-9C84AF292820}" = SpongeBob SquarePants - Battle for Bikini Bottom
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{b350e644-430d-45c9-91e0-cf874f529f6b}.sdb" = Little Mermaid Coloring Book
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{E5966E4C-0A93-4F59-A981-BD3173D4799F}" = F300_Help
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{ED55BFEF-90F3-4926-9536-D94FDBBF65DC}" = Zune
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.7.20090805
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FE242C4A-4AF0-4E9F-ABFF-92CA3CEE8761}" = MySpaceIM
"3DGroove" = 3D Groove Playback Engine
"6F128087AFFFF5D4F4FEE6429736470CD5C1E4E2" = Windows Driver Package - Microsoft WPD (12/01/2006 1.2.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"AOL Instant Messenger" = AOL Instant Messenger
"Barbie Video Phone" = Barbie Video Phone
"Barbie™ Fashion Show™ CD-ROM" = Barbie™ Fashion Show™ CD-ROM
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"BluesCluesKindergartenDKey" = Blue's Kindergarten
"Burn4Free" = Burn4Free CD and DVD
"Catz" = Catz (remove only)
"CDisplay_is1" = CDisplay 1.8
"com.seesmic.desktop.client.D89F32799270693BEF34AAA36E9B2632B59240FA.1" = Seesmic Desktop
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"DreamCast Factory_is1" = DreamCast Factory v0.9.5 (FULL)
"Dreamship Tales" = Dreamship Tales
"ERUNT_is1" = ERUNT 1.1j
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"InstallShield_{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = Broadcom Advanced Control Suite
"InstallShield_{9D98F245-3010-43C6-B3B0-67A464DA298E}" = Earthlink Installer - uninstall 'Earthlink 5.0' entry first if present
"LEGO Racers" = LEGO Racers
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MUSICMATCH Jukebox" = MUSICMATCH Jukebox
"Panda ActiveScan" = Panda ActiveScan
"PeerGuardian_is1" = PeerGuardian 2.0
"Professor Fizzwizzle" = Professor Fizzwizzle
"Putt-Putt Travels Through Time" = Putt-Putt Travels Through Time
"Puzzle Play Mazes" = Puzzle Play Mazes
"Quicken 2002 New User Edition" = Quicken 2002 New User Edition
"Reader Rabbit 1st Grade" = Reader Rabbit 1st Grade
"RealPlayer 6.0" = RealOne Player
"Soulseek" = SoulSeek Client 156c
"Soulseek2" = SoulSeek 157 NS 13c
"SpongeBob SquarePants" = SpongeBob SquarePants® Operation Krabby Patty
"SpongeBob SquarePants Employee of the Month" = SpongeBob SquarePants Employee of the Month
"The SpongeBob SquarePants Movie" = The SpongeBob SquarePants Movie Screen Saver
"Trend Micro HouseCall 6.6" = HouseCall 6.6
"TurboTax Deluxe Deduction Maximizer 2006" = TurboTax Deluxe Deduction Maximizer 2006
"U.B. Funkeys" = U.B. Funkeys
"uTorrent" = µTorrent
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 0.9.8a
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WordPerfect Office 2002" = WordPerfect Office 2002
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2010-01-31 18:54:40 | Computer Name = D8KG5T21 | Source = Application Error | ID = 1000
Description = Faulting application tlclauncher.exe, version 1.0.1.0, faulting module
tlcllshelldll.dll, version 0.0.0.0, fault address 0x0000a8f0.

Error - 2010-02-06 15:15:25 | Computer Name = D8KG5T21 | Source = Application Hang | ID = 1002
Description = Hanging application slsk.exe, version 1.0.0.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2010-02-16 17:07:30 | Computer Name = D8KG5T21 | Source = Application Error | ID = 1000
Description = Faulting application pg2.exe, version 1.0.6.5, faulting module pg2.exe,
version 1.0.6.5, fault address 0x0002ee56.

Error - 2010-02-16 17:09:58 | Computer Name = D8KG5T21 | Source = Application Error | ID = 1000
Description = Faulting application pg2.exe, version 1.0.6.5, faulting module pg2.exe,
version 1.0.6.5, fault address 0x0002ee56.

Error - 2010-02-16 17:12:15 | Computer Name = D8KG5T21 | Source = Application Error | ID = 1000
Description = Faulting application pg2.exe, version 1.0.6.5, faulting module pg2.exe,
version 1.0.6.5, fault address 0x0002ee56.

Error - 2010-02-16 17:44:14 | Computer Name = D8KG5T21 | Source = Application Error | ID = 1000
Description = Faulting application pg2.exe, version 1.0.6.5, faulting module pg2.exe,
version 1.0.6.5, fault address 0x0002ee56.

Error - 2010-02-16 18:32:46 | Computer Name = D8KG5T21 | Source = Application Error | ID = 1000
Description = Faulting application pg2.exe, version 1.0.6.5, faulting module pg2.exe,
version 1.0.6.5, fault address 0x0002ee56.

Error - 2010-02-16 18:39:59 | Computer Name = D8KG5T21 | Source = Application Error | ID = 1000
Description = Faulting application pg2.exe, version 1.0.6.5, faulting module pg2.exe,
version 1.0.6.5, fault address 0x0002ee56.

Error - 2010-02-16 18:51:41 | Computer Name = D8KG5T21 | Source = Application Error | ID = 1000
Description = Faulting application pg2.exe, version 1.0.6.5, faulting module pg2.exe,
version 1.0.6.5, fault address 0x0002ee56.

Error - 2010-02-18 04:03:53 | Computer Name = D8KG5T21 | Source = ASP.NET 1.0.3705.6060 | ID = 1031
Description =

[ System Events ]
Error - 2010-02-12 10:47:56 | Computer Name = D8KG5T21 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 2010-02-12 10:48:06 | Computer Name = D8KG5T21 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 2010-02-12 10:48:33 | Computer Name = D8KG5T21 | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 2010-02-12 10:48:38 | Computer Name = D8KG5T21 | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 2010-02-12 10:48:43 | Computer Name = D8KG5T21 | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 2010-02-16 22:23:27 | Computer Name = D8KG5T21 | Source = atapi | ID = 262169
Description = The driver has detected a device with old or out-of-date firmware.
The device will not be used.

Error - 2010-02-17 20:15:58 | Computer Name = D8KG5T21 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 2010-02-17 20:15:58 | Computer Name = D8KG5T21 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 2010-02-17 20:15:58 | Computer Name = D8KG5T21 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 2010-02-18 08:46:56 | Computer Name = D8KG5T21 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Internet Explorer 8 for Windows XP.


< End of report >
OTL logfile created on: 2010-02-20 08:42:43 - Run 1
OTL by OldTimer - Version 3.1.30.1 Folder = C:\Documents and Settings\Mary\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd

766.00 Mb Total Physical Memory | 328.00 Mb Available Physical Memory | 43.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.84 Gb Total Space | 1.93 Gb Free Space | 3.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D8KG5T21
Current User Name: Mary
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010-02-20 08:40:30 | 000,549,376 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mary\My Documents\Downloads\OTL.exe
PRC - [2010-02-17 21:29:26 | 000,908,248 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-11-12 16:33:10 | 000,141,600 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009-11-12 16:33:00 | 000,545,568 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009-08-28 19:42:54 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009-01-03 10:24:59 | 000,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009-01-03 10:24:59 | 000,136,600 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008-12-12 11:17:38 | 000,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008-02-15 08:04:55 | 000,151,597 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2008-02-15 08:04:54 | 000,049,152 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
PRC - [2008-02-15 08:04:51 | 000,114,688 | —- | M] (Intel Corporation) – C:\WINDOWS\SYSTEM32\hkcmd.exe
PRC - [2007-01-30 00:39:34 | 001,432,064 | —- | M] (Phoenix Labs) – C:\Program Files\PeerGuardian2\pg2.exe
PRC - [2007-01-04 16:38:18 | 000,112,336 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
PRC - [2007-01-04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2006-10-18 20:05:26 | 000,204,288 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2006-02-19 04:24:52 | 000,239,320 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
PRC - [2006-02-19 03:21:22 | 000,288,472 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2004-08-04 02:56:57 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\wscntfy.exe
PRC - [2004-08-04 02:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2003-08-29 03:59:24 | 000,122,880 | —- | M] (Broadcom Corporation) – C:\WINDOWS\BCMSMMSG.exe


========== Modules (SafeList) ==========

MOD - [2010-02-20 08:40:30 | 000,549,376 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mary\My Documents\Downloads\OTL.exe
MOD - [2004-08-04 02:57:00 | 001,050,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2009-11-12 16:33:00 | 000,545,568 | —- | M] (Apple Inc.) [On_Demand | Running] – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service)
SRV - [2009-08-28 19:42:54 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009-01-03 10:24:59 | 000,152,984 | —- | M] (Sun Microsystems, Inc.) [Auto | Running] – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2008-12-12 11:17:38 | 000,238,888 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service)
SRV - [2007-03-14 16:03:40 | 000,975,400 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Zune\ZuneNss.exe – (ZuneNetworkSvc)
SRV - [2007-01-04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2006-03-03 20:03:10 | 000,069,632 | —- | M] (HP) [Unknown | Stopped] – C:\WINDOWS\SYSTEM32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2005-04-03 23:41:10 | 000,069,632 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = http://localhost;*.local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://en.wikipedia.org/wiki/Special:Randompage"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:4.2.1
FF - prefs.js..extensions.enabledItems: [removed]:1.5.1

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-02-17 21:30:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-02-17 21:29:43 | 000,000,000 | —D | M]

[2008-06-20 22:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Extensions
[2005-09-12 17:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\0rc86kj7.Other People\extensions
[2005-09-12 17:59:21 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\0rc86kj7.Other People\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2005-02-27 01:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\c4u037zj.default\extensions
[2005-02-12 13:01:50 | 000,000,000 | —D | M] (ForecastFox) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\c4u037zj.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2005-02-05 12:40:09 | 000,000,000 | —D | M] (Adblock) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\c4u037zj.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2005-02-27 01:42:07 | 000,000,000 | —D | M] (ChatZilla) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\c4u037zj.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2005-02-05 20:28:22 | 000,000,000 | —D | M] (Bandwidth Tester) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\c4u037zj.default\extensions\{7C06F9C2-B0D0-47b4-93B8-116C919084BA}
[2005-02-05 12:22:34 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\c4u037zj.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2005-02-05 12:40:09 | 000,000,000 | —D | M] (Mouse Gestures) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\c4u037zj.default\extensions\{FFA36170-80B1-4535-B0E3-A4569E497DD0}
[2005-02-27 01:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\c4u037zj.default\extensions\temp
[2005-09-11 14:22:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\f9pbfeby.Default User\extensions
[2005-09-11 14:22:46 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\f9pbfeby.Default User\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2005-09-12 04:39:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\fac5x93e.Melissa\extensions
[2005-09-12 04:39:34 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\fac5x93e.Melissa\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2005-09-12 04:39:34 | 000,000,000 | —D | M] (Adblock) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\fac5x93e.Melissa\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2005-09-11 22:02:33 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\fac5x93e.Melissa\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2005-09-12 04:39:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\fac5x93e.Melissa\extensions\temp
[2009-03-31 17:39:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\ktbx8ybv.Logan\extensions
[2009-03-31 17:39:04 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\ktbx8ybv.Logan\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008-07-18 18:19:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\lvm123ib.melissa\extensions
[2010-02-20 08:35:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\extensions
[2008-07-18 19:31:11 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009-06-13 14:06:17 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010-01-30 22:14:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\extensions\[removed]
[2010-01-30 21:56:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\extensions\[removed]
[2009-11-15 16:47:51 | 000,000,964 | —- | M] () – C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\searchplugins\google-blog-search.xml
[2010-02-20 06:38:10 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2005-10-01 06:18:17 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\New Folder (2)\extensions
[2005-10-01 09:46:29 | 000,000,000 | —D | M] (Firefox (default)) – C:\Program Files\Mozilla Firefox\New Folder (2)\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-10-04 16:20:38 | 000,442,368 | —- | M] (Invenda Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPcol308.dll
[2008-06-18 01:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2005-05-28 15:15:00 | 000,110,592 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2006-01-18 11:50:00 | 000,319,488 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
[2008-04-22 15:45:11 | 000,243,136 | —- | M] (Viewpoint Corporation) – C:\Program Files\Mozilla Firefox\plugins\npViewpoint_0306003B.dll

O1 HOSTS File: ([2008-02-16 10:24:35 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BCMSMMSG] C:\WINDOWS\BCMSMMSG.exe (Broadcom Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SYSTEM32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\SYSTEM32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe (Phoenix Labs)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 33 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: 40 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3334504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/C…C4D/mp43dmo.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1192303307750 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1192303296640 (MUWebControl Class)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Groove Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8049.5592824074 (Reg Error: Key error.)
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: ActiveGS.cab http://www.virtualapple.com/activegs.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\klogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\Firefox Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Firefox Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002-09-03 08:59:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2003-05-12 12:20:32 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16610416650092544)

========== Files/Folders - Created Within 14 Days ==========

[2010-02-20 05:58:04 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010-02-20 03:06:20 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010-02-20 03:06:14 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2010-02-20 03:06:12 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2010-02-20 03:06:03 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2010-02-20 03:05:19 | 000,000,000 | —D | C] – C:\71d4d73207be8d3eccc0
[2010-02-18 03:09:07 | 000,000,000 | —D | C] – C:\Program Files\MSXML 6.0
[2010-02-18 03:03:31 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010-02-18 03:01:32 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2010-02-17 21:25:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avg7
[2010-02-17 21:24:27 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2010-02-17 21:23:49 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010-02-17 21:23:49 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010-02-17 21:23:49 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010-02-17 21:18:47 | 000,000,000 | —D | C] – C:\aa10af7944dfb8db5f4077
[2010-02-17 21:07:48 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2010-02-17 20:46:56 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010-02-17 20:13:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Mary\Application Data\Malwarebytes
[2010-02-17 20:13:31 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010-02-17 20:13:29 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010-02-17 20:13:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010-02-17 20:13:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010-02-16 16:41:19 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2010-02-16 15:51:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Mary\My Documents\Downloads
[2008-02-22 16:58:01 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007-05-16 20:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Viewpoint
[2007-02-12 08:21:41 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2006-11-06 18:18:51 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Mozilla
[2006-11-06 18:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Talkback
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010-02-20 03:28:27 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010-02-20 03:28:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010-02-20 03:28:19 | 803,786,752 | -HS- | M] () – C:\hiberfil.sys
[2010-02-20 03:28:19 | 000,165,912 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010-02-20 03:27:29 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Mary\NTUSER.INI
[2010-02-20 03:27:28 | 007,077,888 | -H– | M] () – C:\Documents and Settings\Mary\NTUSER.DAT
[2010-02-20 03:27:23 | 004,252,822 | -H– | M] () – C:\Documents and Settings\Mary\Local Settings\Application Data\IconCache.db
[2010-02-20 03:10:54 | 000,491,366 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010-02-20 03:10:54 | 000,434,468 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2010-02-20 03:10:54 | 000,068,246 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2010-02-19 22:46:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010-02-19 03:01:16 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010-02-17 21:19:10 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010-02-17 20:46:56 | 000,001,734 | —- | M] () – C:\Documents and Settings\Mary\Desktop\HijackThis.lnk
[2010-02-17 20:13:34 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-02-16 17:35:11 | 000,125,440 | —- | M] () – C:\Documents and Settings\Mary\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-02-06 16:26:28 | 000,001,547 | —- | M] () – C:\WINDOWS\hegames.ini
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010-02-17 20:46:56 | 000,001,734 | —- | C] () – C:\Documents and Settings\Mary\Desktop\HijackThis.lnk
[2010-02-17 20:13:34 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008-12-31 13:08:46 | 000,000,119 | —- | C] () – C:\WINDOWS\ka.ini
[2008-07-19 15:38:28 | 000,000,168 | —- | C] () – C:\WINDOWS\BluesCluesKindergarten.ini
[2008-02-28 23:14:04 | 000,223,744 | —- | C] () – C:\WINDOWS\System32\b4fm.dll
[2008-01-19 16:19:27 | 000,012,288 | —- | C] () – C:\WINDOWS\impborl.dll
[2007-09-03 15:44:59 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2007-09-03 15:35:21 | 000,002,519 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007-05-26 17:04:12 | 000,001,437 | —- | C] () – C:\WINDOWS\disney.ini
[2007-05-13 09:30:35 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2007-01-22 18:23:34 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2006-08-29 23:29:53 | 000,002,535 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006-08-28 08:24:06 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2006-06-21 19:39:53 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005-08-21 15:15:07 | 000,000,021 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.24554863501262644635642126105
[2005-07-23 16:28:59 | 000,000,000 | —- | C] () – C:\WINDOWS\QFN.ini
[2005-07-23 16:28:59 | 000,000,000 | —- | C] () – C:\WINDOWS\QDQICK.ini
[2005-05-21 07:01:46 | 000,001,547 | —- | C] () – C:\WINDOWS\hegames.ini
[2005-05-21 00:36:24 | 000,125,440 | —- | C] () – C:\Documents and Settings\Mary\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005-05-11 20:27:25 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\impborl.dll
[2005-04-01 22:32:58 | 000,000,091 | —- | C] () – C:\WINDOWS\CIV.INI
[2005-03-01 14:30:20 | 000,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[2005-02-26 17:28:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005-02-13 10:37:34 | 000,000,527 | —- | C] () – C:\WINDOWS\wininit.ini
[2005-02-13 10:37:25 | 000,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005-02-12 13:06:35 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005-02-07 19:00:13 | 000,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2004-09-12 17:51:33 | 000,061,678 | —- | C] () – C:\Documents and Settings\Mary\Application Data\PFP100JPR.{PB
[2004-09-12 17:51:33 | 000,012,358 | —- | C] () – C:\Documents and Settings\Mary\Application Data\PFP100JCM.{PB
[2003-05-12 12:58:45 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003-05-12 12:52:37 | 000,207,759 | —- | C] () – C:\Program Files\INSTALL.LOG
[2003-05-12 12:49:17 | 000,000,908 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003-05-12 12:49:17 | 000,000,185 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003-05-12 12:43:42 | 000,000,788 | —- | C] () – C:\WINDOWS\orun32.ini
[2003-05-12 12:23:42 | 000,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002-08-29 05:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\SECDRV.SYS
[2001-07-07 02:00:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010-02-17 21:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2010-01-18 09:59:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Barbie Fashion Show
[2005-08-21 15:15:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Final Draft
[2010-02-16 13:15:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soulseek
[2008-12-02 16:38:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009-04-04 13:41:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ubisoft
[2007-01-18 21:10:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009-12-25 08:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2005-02-05 12:30:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Aim
[2007-05-02 22:06:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Azureus
[2009-10-04 14:54:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\com.seesmic.desktop.client.D89F32799270693BEF34AAA36E9B2632B59240FA.1
[2005-08-21 15:22:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Final Draft
[2008-02-09 23:04:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\HouseCall 6.6
[2009-02-08 09:42:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\PlayFirst
[2008-08-24 09:53:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Pogo Games
[2008-06-02 16:19:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\School Zone Preferences
[2007-05-10 20:09:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\SecondLife
[2006-05-13 17:21:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Snapfish
[2005-03-30 18:45:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Thunderbird
[2010-02-17 20:53:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\uTorrent
[2007-01-18 21:10:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Mary\Application Data\Viewpoint
[2003-05-21 17:05:43 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job

========== Purity Check ==========



========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.exe >
[2005-12-05 21:25:08 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2005-02-05 12:21:36 | 004,918,270 | —- | M] (Mozilla) – C:\Firefox Setup 1.0.exe
[2004-08-04 02:56:48 | 000,388,608 | —- | M] (Microsoft Corporation) – C:\kmd.exe
[2004-05-14 15:16:38 | 000,769,543 | —- | M] (Network Associates Inc.) – C:\stinger.exe
[2004-05-14 15:20:45 | 000,115,960 | —- | M] (Microsoft Corporation) – C:\Windows-KB841720-ENU-V4.exe
[2004-05-14 15:23:04 | 001,291,040 | —- | M] (Microsoft Corporation) – C:\WindowsXP-KB823980-x86-ENU.exe


< MD5 for: AGP440.SYS >
[2007-10-13 15:57:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2007-10-13 15:57:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008-04-13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2004-08-04 01:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2004-08-04 01:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2001-08-17 13:58:00 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\I386\AGP440.SYS
[2001-08-17 13:58:00 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2002-08-29 05:00:00 | 010,158,890 | —- | M] () .cab file – C:\I386\sp1.cab:atapi.sys
[2002-08-29 05:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp1.cab:atapi.sys
[2007-10-13 15:57:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2007-10-13 15:57:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2002-10-16 17:31:10 | 000,087,040 | —- | M] (Microsoft Corporation) MD5=3DF589B9A15FF9EF4AA499F98C1C16D5 – C:\I386\atapi.sys
[2002-10-16 17:31:10 | 000,087,040 | —- | M] (Microsoft Corporation) MD5=3DF589B9A15FF9EF4AA499F98C1C16D5 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008-04-13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004-08-04 00:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004-08-04 00:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008-04-13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2004-08-04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2004-08-04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\SYSTEM32\eventlog.dll
[2002-08-29 05:00:00 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\I386\EVENTLOG.DLL
[2002-08-29 05:00:00 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2002-01-03 23:18:54 | 000,049,152 | —- | M] (EarthLink, Inc.) MD5=CC5BD74A878581FC2322FA21BEB12CD8 – C:\Program Files\EarthLink 5.0\Access\eventlog.dll
[2002-01-03 23:18:54 | 000,049,152 | —- | M] (EarthLink, Inc.) MD5=CC5BD74A878581FC2322FA21BEB12CD8 – C:\Program Files\EarthLink 5.0\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008-04-13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2002-08-29 05:00:00 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\I386\NETLOGON.DLL
[2002-08-29 05:00:00 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2009-02-06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009-02-06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009-02-06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\SoftwareDistribution\Download\78cf8552430e25a8f24bc1e4dfb1970e\sp2qfe\netlogon.dll
[2009-02-06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\SoftwareDistribution\Download\de81b460c3abcfc5b8494c785a5f3944\sp2qfe\netlogon.dll
[2004-08-04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2004-08-04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\SYSTEM32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004-08-04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2004-08-04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\SYSTEM32\scecli.dll
[2002-08-29 05:00:00 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\I386\SCECLI.DLL
[2002-08-29 05:00:00 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008-04-13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2002-09-03 08:47:18 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002-09-03 08:47:18 | 000,602,112 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002-09-03 08:47:18 | 000,380,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

========== Alternate Data Streams ==========

@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9E985157
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:588B60C7
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BDBBA690
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0E799D7F
< End of report >
was running gmer and got the blue screen of death. everything was normal when I restarted, but wanted to check with you before I ran it again.
Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Make sure all other programs are closed and security programs are totally disabled.

Then go ahead and try to run GMER again.
Be sure to do the following:
Uncheck the box beside "files" as well as "Sections" and "IAT/EAT"

If it still does not run, please Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Try running GMER again
  • When you are finished , close all programs and restart the computer as you normally would.

Please copy and paste the GMER log in your next reply. If you still can't get it to run please let me know.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-21 07:35:10
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Mary\LOCALS~1\Temp\pgdoapod.sys


—- Files - GMER 1.0.15 —-

File C:\WINDOWS\INF\oem50.inf 22257 bytes
File C:\WINDOWS\INF\oem50.PNF 0 bytes
File C:\WINDOWS\ntprint.cat 0 bytes
File C:\WINDOWS\LastGood 0 bytes
File C:\WINDOWS\LastGood\INF 0 bytes
File C:\WINDOWS\LastGood\INF\oem50.inf 0 bytes
File C:\WINDOWS\LastGood\INF\oem50.PNF 0 bytes
File C:\WINDOWS\$NtUninstallKB925720$ 0 bytes
File C:\WINDOWS\$NtUninstallKB925720$\magnify.exe 72704 bytes executable
File C:\WINDOWS\$NtUninstallKB925720$\narrator.exe 53760 bytes executable
File C:\WINDOWS\$NtUninstallKB925720$\osk.exe 215552 bytes executable
File C:\WINDOWS\$NtUninstallKB925720$\spuninst 0 bytes
File C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe 213216 bytes executable
File C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.inf 13214 bytes
File C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.txt 1080 bytes
File C:\WINDOWS\$NtUninstallKB925720$\spuninst\updspapi.dll 371424 bytes executable
File C:\WINDOWS\$NtUninstallKB925720$\umandlg.dll 35840 bytes executable
File C:\WINDOWS\$NtUninstallKB925720$\utilman.exe 50176 bytes executable
File C:\WINDOWS\KB961118.log 7450 bytes
File C:\WINDOWS\$NtUninstallKB961118$ 0 bytes
File C:\b5efd4d175b650f181a20f87909b 0 bytes
File C:\b5efd4d175b650f181a20f87909b\$shtdwn$.req 0 bytes
File C:\b5efd4d175b650f181a20f87909b\1025 0 bytes

—- EOF - GMER 1.0.15 —-
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI