Hello,
The main symptoms have been dealt with, being apparent removal of XP anti-malware trojan (not sure how she got this to begin with, but my suspicion is some kind of exploit that led to automatic execution of remote code). She originally had the trojan running trying to tell her that she was infected (of course, I'm sure these detections were bogus).
I suspect there may still be some cooties left on the machine, however, since a scan probably hasn't been performed since the last time my assistance was required.
Remember when reading the active processes that I am helping her via remote assistance (through MS Messenger), so whatever process that is is expected to show.
Thank you in advance for all your help.
Here is the GMER log you requested:
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-03-28 19:03:28
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Denise\LOCALS~1\Temp\pxtdipow.sys
—- System - GMER 1.0.15 —-
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF7392E64]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF7372EEE]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF73730E0]
SSDT F7AE29FC ZwCreateThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF7393652]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF7393906]
SSDT F7AE2A1A ZwLoadKey
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF7391B64]
SSDT F7AE29E8 ZwOpenProcess
SSDT F7AE29ED ZwOpenThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF7393D72]
SSDT F7AE2A24 ZwReplaceKey
SSDT F7AE2A1F ZwRestoreKey
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF7393124]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF7372B5C]
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!_abnormal_termination + F0 804E275C 1 Byte [64]
.text ntoskrnl.exe!_abnormal_termination + 234 804E28A0 4 Bytes CALL B645D6CE
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Mozilla Firefox\firefox.exe[1604] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1
—- EOF - GMER 1.0.15 —-
Here is the OTL log (from OTL):
OTL logfile created on: 3/28/2010 7:05:27 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Denise\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
382.00 Mb Total Physical Memory | 90.00 Mb Available Physical Memory | 23.00% Memory free
725.00 Mb Paging File | 225.00 Mb Available in Paging File | 31.00% Paging File free
Paging file location(s): C:\pagefile.sys 288 576 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 27.95 Gb Total Space | 6.93 Gb Free Space | 24.81% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME
Current User Name: Denise
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/03/28 15:41:35 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Denise\My Documents\Downloads\OTL.exe
PRC - [2010/03/26 12:30:23 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/01/22 09:56:24 | 000,112,592 | —- | M] (Threat Expert Ltd.) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
PRC - [2009/12/15 11:24:00 | 000,293,376 | —- | M] () – C:\Documents and Settings\Denise\Desktop\gmer.exe
PRC - [2009/08/05 20:33:21 | 000,185,089 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009/06/09 16:30:20 | 000,108,289 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009/03/02 13:08:47 | 000,209,153 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2009/02/06 17:07:48 | 000,027,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2009/02/03 10:32:00 | 003,550,592 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Program Files\Process Explorer\procexp.exe
PRC - [2008/04/13 17:12:32 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\rdshost.exe
PRC - [2008/04/13 17:12:21 | 000,769,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/06/18 15:51:50 | 000,565,248 | —- | M] (Lavasoft AB) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
PRC - [2007/01/31 14:55:42 | 000,096,370 | —- | M] (Canon Inc.) – C:\Program Files\Canon\CAL\CALMAIN.exe
========== Modules (SafeList) ==========
MOD - [2010/03/28 15:41:35 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Denise\My Documents\Downloads\OTL.exe
MOD - [2008/04/13 17:12:04 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\safrcdlg.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] – – (IBEQH)
SRV - [2010/03/15 12:50:36 | 001,142,224 | —- | M] (PC Tools) [On_Demand | Stopped] – C:\Program Files\Spyware Doctor\pctsSvc.exe – (sdCoreService)
SRV - [2010/03/11 12:09:22 | 000,366,840 | —- | M] (PC Tools) [On_Demand | Stopped] – C:\Program Files\Spyware Doctor\pctsAuxs.exe – (sdAuxService)
SRV - [2010/01/22 09:56:24 | 000,112,592 | —- | M] (Threat Expert Ltd.) [Auto | Running] – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2009/08/05 20:33:21 | 000,185,089 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2009/06/09 16:30:20 | 000,108,289 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2007/06/18 15:51:50 | 000,565,248 | —- | M] (Lavasoft AB) [Auto | Running] – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe – (aawservice)
SRV - [2007/01/31 14:55:42 | 000,096,370 | —- | M] (Canon Inc.) [Auto | Running] – C:\Program Files\Canon\CAL\CALMAIN.exe – (CCALib8)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {9D6218B8-03C7-4b91-AA43-680B305DD35C}:1.7.9.7
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/26 12:30:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/26 12:30:45 | 000,000,000 | —D | M]
[2008/12/17 18:38:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\Mozilla\Extensions
[2010/03/28 10:42:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\Mozilla\Firefox\Profiles\6h4y4i0n.default\extensions
[2009/09/03 09:22:29 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Denise\Application Data\Mozilla\Firefox\Profiles\6h4y4i0n.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/02 16:44:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Denise\Application Data\Mozilla\Firefox\Profiles\6h4y4i0n.default\extensions\{9D6218B8-03C7-4b91-AA43-680B305DD35C}
[2010/03/28 10:42:53 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/06/19 02:16:24 | 000,118,784 | —- | M] (CANON INC.) – C:\Program Files\Mozilla Firefox\plugins\MyCamera.dll
[2008/06/19 02:16:24 | 000,053,248 | —- | M] (CANON INC.) – C:\Program Files\Mozilla Firefox\plugins\NPCIG.dll
[2005/12/05 22:31:00 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2002/09/27 09:59:00 | 000,090,112 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\NpPopup.dll
O1 HOSTS File: ([2009/07/05 16:59:51 | 000,315,985 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123haustiereundmehr.com
O1 - Hosts: 10867 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKCU..\Run: [Aim6] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O8 - Extra context menu item: Copy to Semagic - C:\Program Files\Semagic\copy.htm ()
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Semagic - C:\Program Files\Semagic\link.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\npjpi160_04.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: amazon.com ([www] https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697}
http://ak.imgag.com/imgag/cp/install/AxCtp2.cab (Create & Print ActiveX Plug-in)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: PackageCab
http://ak.imgag.com/imgag/cp/install/AxCtp2.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Denise\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Denise\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/06/24 18:52:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{c93397a5-22c0-11dc-9c34-0010b58da32d}\Shell - "" = AutoRun
O33 - MountPoints2\{c93397a5-22c0-11dc-9c34-0010b58da32d}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c93397a5-22c0-11dc-9c34-0010b58da32d}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007/06/24 18:50:58 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891891626803200)
========== Files/Folders - Created Within 14 Days ==========
[2010/03/26 11:58:05 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/03/26 11:56:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Denise\Local Settings\Application Data\Threat Expert
[2010/03/23 16:48:08 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2010/03/23 16:48:07 | 001,652,688 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2010/03/23 16:48:07 | 000,165,840 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2010/03/23 16:43:42 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/03/23 16:43:24 | 000,233,136 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010/03/23 16:42:53 | 000,217,032 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/03/23 16:42:53 | 000,088,040 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010/03/23 16:41:47 | 000,070,408 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2010/03/23 16:40:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/03/23 16:40:17 | 000,000,000 | —D | C] – C:\Program Files\Spyware Doctor
[2010/03/23 16:40:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Denise\Application Data\PC Tools
[2010/03/23 16:40:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/03/23 16:38:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/22 20:14:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Denise\Application Data\Facebook
[2009/07/22 03:04:54 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/09/21 16:17:47 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/09/21 16:17:46 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/09/21 16:17:46 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2007/10/17 23:26:03 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Denise\My Documents\*.tmp files -> C:\Documents and Settings\Denise\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 14 Days ==========
[2010/03/28 15:35:45 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/28 10:02:55 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/28 10:02:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/28 10:02:43 | 401,133,568 | -HS- | M] () – C:\hiberfil.sys
[2010/03/28 10:00:44 | 009,437,184 | —- | M] () – C:\Documents and Settings\Denise\ntuser.dat
[2010/03/28 10:00:44 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Denise\ntuser.ini
[2010/03/28 09:01:35 | 000,000,372 | —- | M] () – C:\Documents and Settings\Denise\My Documents\spider.sav
[2010/03/28 03:14:05 | 000,000,456 | —- | M] () – C:\WINDOWS\tasks\Driver Robot.job
[2010/03/26 11:58:08 | 000,001,734 | —- | M] () – C:\Documents and Settings\Denise\Desktop\HijackThis.lnk
[2010/03/23 19:52:06 | 000,017,452 | -HS- | M] () – C:\Documents and Settings\Denise\Local Settings\Application Data\Mh3jm32txN
[2010/03/23 19:52:06 | 000,017,452 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\Mh3jm32txN
[2010/03/23 16:42:23 | 000,001,637 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/03/16 14:12:12 | 000,001,565 | —- | M] () – C:\Documents and Settings\Denise\Desktop\Semagic.lnk
[2010/03/15 18:59:27 | 000,073,728 | —- | M] () – C:\Documents and Settings\Denise\Desktop\important phone numbers(2).doc
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Denise\My Documents\*.tmp files -> C:\Documents and Settings\Denise\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/03/28 15:42:52 | 000,293,376 | —- | C] () – C:\Documents and Settings\Denise\Desktop\gmer.exe
[2010/03/26 11:58:07 | 000,001,734 | —- | C] () – C:\Documents and Settings\Denise\Desktop\HijackThis.lnk
[2010/03/23 16:48:10 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/03/23 16:48:09 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2010/03/23 16:48:08 | 001,152,444 | —- | C] () – C:\WINDOWS\UDB.zip
[2010/03/23 16:48:08 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2010/03/23 16:48:08 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2010/03/23 16:43:24 | 000,007,387 | —- | C] () – C:\WINDOWS\System32\drivers\pctgntdi.cat
[2010/03/23 16:42:53 | 000,007,412 | —- | C] () – C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2010/03/23 16:42:53 | 000,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctcore.cat
[2010/03/23 16:42:23 | 000,001,637 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/03/23 16:41:47 | 000,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctplsg.cat
[2010/03/23 15:15:46 | 000,017,452 | -HS- | C] () – C:\Documents and Settings\Denise\Local Settings\Application Data\Mh3jm32txN
[2010/03/23 15:15:46 | 000,017,452 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\Mh3jm32txN
[2010/03/16 14:12:12 | 000,001,565 | —- | C] () – C:\Documents and Settings\Denise\Desktop\Semagic.lnk
[2009/07/04 13:51:57 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009/05/21 09:37:34 | 000,013,007 | —- | C] () – C:\Documents and Settings\Denise\Application Data\Comma Separated Values (Windows).CAL
[2008/11/06 09:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/11/06 09:34:00 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/11/06 09:34:00 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/11/06 09:33:02 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/09/02 12:06:38 | 000,032,256 | —- | C] () – C:\WINDOWS\System32\Decln.dll
[2008/09/02 12:06:38 | 000,014,629 | —- | C] () – C:\WINDOWS\System32\Declw.dll
[2008/03/18 10:43:06 | 000,000,311 | —- | C] () – C:\WINDOWS\pagebreeze.ini
[2008/03/18 10:43:06 | 000,000,044 | —- | C] () – C:\WINDOWS\formbreeze.ini
[2007/11/13 17:50:53 | 000,000,195 | —- | C] () – C:\WINDOWS\MPLAYER.INI
[2007/11/01 19:37:31 | 000,001,387 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/09/08 14:46:13 | 000,182,272 | —- | C] () – C:\WINDOWS\patchw32.dll
[2007/09/08 14:07:31 | 000,000,265 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2007/08/11 10:12:38 | 000,000,604 | —- | C] () – C:\WINDOWS\Sof2.INI
[2007/07/06 20:43:25 | 000,000,054 | —- | C] () – C:\WINDOWS\TwUI215.INI
[2007/07/03 14:48:23 | 000,000,169 | —- | C] () – C:\WINDOWS\ACTIVEBK.INI
[2007/07/03 14:48:23 | 000,000,167 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2007/07/03 14:48:14 | 000,002,254 | —- | C] () – C:\WINDOWS\OLDWPR.INI
[2007/07/03 14:48:07 | 000,006,940 | —- | C] () – C:\WINDOWS\reader.ini
[2007/06/30 17:59:18 | 000,010,240 | —- | C] () – C:\Documents and Settings\Denise\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/06/25 18:40:19 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/06/25 17:51:44 | 000,000,419 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2007/06/24 20:09:02 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/03/05 13:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2007/06/25 17:16:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2007/06/25 17:51:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/03/28 10:03:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/08 16:06:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/08/23 10:09:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{5EEDDC93-4693-445F-9928-358F46BFE787}
[2008/08/26 09:16:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\1&1
[2007/06/26 21:33:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\acccore
[2009/11/21 14:11:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\Blitware
[2007/07/06 20:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\Canon
[2009/09/06 12:13:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\com.comcast.callerid.13A1FA90F0FC9DC009FB0956ADD0F13F8608561B.1
[2007/06/28 09:11:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\ComcastToolbar
[2010/03/22 20:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\Facebook
[2010/03/05 14:43:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\Favor Software
[2009/02/16 20:37:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\FileZilla
[2007/07/08 07:40:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\iWin
[2007/06/25 17:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\ScanSoft
[2008/12/08 16:11:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Denise\Application Data\Viewpoint
[2010/03/28 03:14:05 | 000,000,456 | —- | M] () – C:\WINDOWS\Tasks\Driver Robot.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007/06/24 18:52:40 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/09/21 15:23:14 | 000,000,210 | -HS- | M] () – C:\boot.ini
[2008/09/21 14:36:07 | 000,008,026 | —- | M] () – C:\ComboFix.txt
[2007/06/24 18:52:40 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/03/28 10:02:43 | 401,133,568 | -HS- | M] () – C:\hiberfil.sys
[2007/06/24 18:52:40 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2007/10/27 11:34:40 | 000,001,648 | -H– | M] () – C:\IPH.PH
[2007/06/24 18:52:40 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/06/25 12:49:49 | 000,001,042 | —- | M] () – C:\net_save.dna
[2006/02/28 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/20 11:28:42 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/03/28 19:34:35 | 493,445,120 | -HS- | M] () – C:\pagefile.sys
[2010/02/02 22:04:13 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2007/09/24 08:21:02 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2007/09/24 08:21:02 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
< MD5 for: AGP440.SYS >
[2006/02/28 05:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/08/20 10:44:16 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/08/20 10:44:16 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2006/02/28 05:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/08/20 10:44:16 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/08/20 10:44:16 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2006/02/28 05:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2006/02/28 05:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2006/02/28 05:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006/02/28 05:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 17:12:03 | 000,043,520 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\racpldlg.dll
[2008/04/13 17:12:04 | 000,043,520 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\safrcdlg.dll
[2008/04/13 17:12:04 | 000,029,696 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\safrdm.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2007/06/24 11:17:21 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/06/24 11:17:21 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/06/24 11:17:21 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 203 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >
Here is the Extras log (from OTL):
OTL Extras logfile created on: 3/28/2010 7:05:27 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Denise\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
382.00 Mb Total Physical Memory | 90.00 Mb Available Physical Memory | 23.00% Memory free
725.00 Mb Paging File | 225.00 Mb Available in Paging File | 31.00% Paging File free
Paging file location(s): C:\pagefile.sys 288 576 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 27.95 Gb Total Space | 6.93 Gb Free Space | 24.81% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME
Current User Name: Denise
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – %1
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Grisoft\AVG7\avginet.exe" = C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe – File not found
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe" = C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe – File not found
"C:\Program Files\Grisoft\AVG7\avgcc.exe" = C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe – File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\NetMeeting\conf.exe" = C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® – (Microsoft Corporation)
"C:\AV-CLS\WGET.EXE" = C:\AV-CLS\WGET.EXE:*:Enabled:WGET.EXE – ()
"C:\Program Files\AceBIT\WISE-FTP\wise_ftp.exe" = C:\Program Files\AceBIT\WISE-FTP\wise_ftp.exe:*:Enabled:WISE-FTP application executable – (AceBIT GmbH)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe" = C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice – (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{069A34F5-30EE-45E2-BC10-96EF76E64588}" = Sweater Wizard V3
"{0D2E80C8-0875-43EB-9623-47118E2DFBCA}" = Quicken 2007
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160" = Canon MP160
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{29D851C2-048C-4B5E-8D1F-25D473342BB5}" = ScanSoft OmniPage SE 4.0
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B0541D7-B083-4ADC-814C-840034F4C55B}" = Stitch Motif Maker 3
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{45AB2DEF-2577-43CC-95FF-A027AD6ADFE8}" = Sweater Wizard V3
"{46AC899A-9ECB-43DC-85DE-272E0D116A1E}" = Ad-Aware 2007
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5B09BD67-4C99-46A1-8161-B7208CE18121}" = QuickTime
"{6A69D94E-C569-4154-9643-72E94D1DDFDA}" = XPS Essentials Pack
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{AEDDF5A3-29CE-11D5-A8C2-000102246AAE}" = ubi.com
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7B82700-3944-4EA1-8D0A-95600855C04E}" = Sock Wizard
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1DD4D69-9649-4C70-9D46-94C04F0B6856}" = Knitting Math Wizard
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F22C63FE-DBA4-4FDA-9306-55AA627CE6C7}" = Wise-FTP
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"AIM_6" = AIM 6
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Browser Defender_is1" = Browser Defender 2.0.6.15
"CAL" = Canon Camera Access Library
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MP160 User Registration" = Canon MP160 User Registration
"CanonMyPrinter" = Canon My Printer
"comcastDD" = Desktop Doctor
"ComcastHSI" = Comcast High-Speed Internet Install Wizard
"ComcastToolbar" = Comcast Toolbar
"Creative MuVo N200 Media Explorer" = Creative MuVo N200 Media Explorer
"CSCLIB" = Canon Camera Support Core Library
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"Dual Mode Camera_is1" = Uninstall Dual Mode Camera
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"EOS Utility" = Canon Utilities EOS Utility
"FavorSoftware_IntwinedPatternStudio_Version1x_is1" = Intwined Pattern Studio version 1
"FileZilla Client" = FileZilla Client 3.2.1
"HijackThis" = HijackThis 2.0.2
"Hijackthis_is1" = Hijackthis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Knit Visualizer Demo 1.2a" = Knit Visualizer Demo 1.2a
"Knit Visualizer Demo 2.0" = Knit Visualizer Demo 2.0
"Knitware Sweaters 2.50" = Knitware Sweaters 2.50
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.6.2)" = Mozilla Firefox (3.6.2)
"MP Navigator 3.0" = Canon MP Navigator 3.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"MuVo Driver" = MuVo Driver
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PageBreeze Free HTML Editor" = PageBreeze Free HTML Editor
"PhoTagsExpress" = PhoTags Express
"PhotoStitch" = Canon Utilities PhotoStitch
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureDC" = Canon Utilities RemoteCapture DC
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Semagic" = Semagic (remove only)
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Spyware Doctor" = Spyware Doctor 7.0
"Sweater Designer 1.0_is1" = Sweater Designer 1.0
"Sweater Wizard V3" = Sweater Wizard V3
"Sweater Wizard V3 Update" = Sweater Wizard V3 Update
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEP" = XPS Essentials Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/19/2010 7:03:24 PM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application wmplayer.exe, version 11.0.5721.5145, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/22/2010 12:30:34 AM | Computer Name = HOME | Source = Avira AntiVir | ID = 4112
Description = An error occurred during a resource request to the Windows NT system.
The resource has not been allocated. This could be due to an out-of-memory
error or any other system failure. Returned error code: 0x18
Error - 3/23/2010 12:34:10 PM | Computer Name = HOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 3/23/2010 7:01:42 PM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application ave.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/23/2010 7:01:42 PM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application ave.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/23/2010 7:02:58 PM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application ave.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/23/2010 11:13:06 PM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.1.3685, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/24/2010 12:04:02 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.1.3685, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/24/2010 12:48:09 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.1.3685, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/26/2010 3:01:14 PM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application HijackThis.exe, version 2.0.0.2, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 3/23/2010 11:53:18 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PC Tools Security Service
service to connect.
Error - 3/23/2010 11:53:18 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7000
Description = The PC Tools Security Service service failed to start due to the following
error: %%1053
Error - 3/23/2010 11:58:59 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7034
Description = The PC Tools Security Service service terminated unexpectedly. It
has done this 2 time(s).
Error - 3/23/2010 11:59:57 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PC Tools Security Service
service to connect.
Error - 3/23/2010 11:59:58 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7000
Description = The PC Tools Security Service service failed to start due to the following
error: %%1053
Error - 3/24/2010 12:56:40 AM | Computer Name = HOME | Source = Service Control Manager | ID = 7034
Description = The PC Tools Security Service service terminated unexpectedly. It
has done this 1 time(s).
Error - 3/25/2010 1:37:30 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.
Error - 3/25/2010 1:37:30 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053
Error - 3/26/2010 2:52:57 PM | Computer Name = HOME | Source = TermServDevices | ID = 1112
Description = Failed to register for user printing preferences change notification.
Open the Services snap-in and confirm that the Printer Spooler service is running
Error - 3/28/2010 6:35:46 PM | Computer Name = HOME | Source = TermServDevices | ID = 1112
Description = Failed to register for user printing preferences change notification.
Open the Services snap-in and confirm that the Printer Spooler service is running
< End of report >