This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Found some things with Kaspersky

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I ran the Kaspersky online scanner and it found some things. First, here's the DDS log: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 0:34:05.57 on Sat 06/05/2010 Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_20 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1699 [GMT -4:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files\Fingerprint Sensor\AtService.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\Ati2evxx.exe C:\Program Files\DigitalPersona\Bin\DpHostW.exe C:\Program Files\Juniper Networks\Common Files\dsNcService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe C:\Program Files\McAfee\VirusScan\Mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\Windows\system32\IoctlSvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\rpcnet.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\System32\WLTRYSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\System32\bcmwltry.exe C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe C:\Program Files\DigitalPersona\Bin\DpAgent.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Palm\Hotsync.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\McAfee\MSC\mcmscsvc.exe C:\Windows\System32\mobsync.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\McAfee\VirusScan\mcsysmon.exe C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\taskeng.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Chad\Downloads\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: DigitalPersona Fingerprint Software Extension: {395610ae-c624-4f58-b89e-23733ea00f9a} - c:\program files\digitalpersona\bin\DpOtsPluginIe8.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon mRun: [Dell Webcam Central] "c:\program files\dell webcam\dell webcam central\WebcamDell.exe" /mode2 mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [DpAgent] c:\program files\digitalpersona\bin\dpagent.exe mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [ECenter] c:\dell\e-center\EULALauncher.exe mRun: [EEventManager] c:\program files\epson\creativity suite\event manager\EEventManager.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe" mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [Name of App] c:\program files\samsung\fw liveupdate\FWManager.exe r mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe" mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe" mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\users\chad\appdata\roaming\microsoft\windows\start menu\programs\startup\PowerReg Scheduler.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~2.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll AppInit_DLLs: c:\progra~1\google\google~2\goec62~1.dll c:\progra~1\google\google~1\GOEC62~1.DLL LSA: Notification Packages = scecli DPPWDFLT ================= FIREFOX =================== FF - ProfilePath - c:\users\chad\appdata\roaming\mozilla\firefox\profiles\an0vaf5c.default\ FF - prefs.js: browser.startup.homepage - hxxp://rr.com/ FF - component: c:\program files\digitalpersona\bin\firefoxext\components\dpffcli.dll FF - plugin: c:\progra~1\palm\packag~1\NPInstal.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_f6ef8056\AEstSrv.exe [2010-4-14 81920] R2 ATService;AuthenTec Fingerprint Service;c:\program files\fingerprint sensor\AtService.exe [2008-5-5 1168632] R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-5-2 161048] R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\drivers\ATSwpWDF.sys [2010-4-14 475136] R3 itecir;ITECIR Infrared Receiver;c:\windows\system32\drivers\itecir.sys [2010-4-14 54784] R3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60x.sys [2010-4-14 203264] R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2010-4-14 133632] R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2010-4-14 280096] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-5 135664] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-10-13 30192] =============== Created Last 30 ================ 2010-06-04 16:20 –d—– c:\users\chad\appdata\roaming\Malwarebytes 2010-06-04 16:20 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-04 16:20 –d—– c:\programdata\Malwarebytes 2010-06-04 16:20 –d—– c:\progra~2\Malwarebytes 2010-06-04 16:20 20,952 a——- c:\windows\system32\drivers\mbam.sys 2010-06-04 16:20 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-05-26 14:37 –d—– c:\users\chad\appdata\roaming\Foxit Software 2010-05-22 17:07 –d—– c:\program files\common files\SureThing Shared 2010-05-22 17:06 –d—– c:\program files\common files\PX Storage Engine 2010-05-22 17:06 –d—– c:\program files\common files\Sonic Shared 2010-05-22 17:04 –d—– c:\program files\Roxio 2010-05-22 17:04 146 a——- c:\windows\WININIT.INI 2010-05-17 20:10 –dsh— C:\found.000 2010-05-12 10:01 738,816 a——- c:\windows\system32\inetcomm.dll ==================== Find3M ==================== 2010-06-04 16:15 17,408 a——- c:\windows\system32\rpcnetp.exe 2010-06-04 16:15 57,752 a——- c:\windows\system32\rpcnet.dll 2010-05-17 20:15 17,408 a——- c:\windows\system32\rpcnetp.dll 2010-04-26 22:50 143,360 a——- c:\windows\inf\infstrng.dat 2010-04-26 22:50 86,016 a——- c:\windows\inf\infstor.dat 2010-04-26 22:50 51,200 a——- c:\windows\inf\infpub.dat 2010-04-23 17:27 411,368 a——- c:\windows\system32\deployJava1.dll 2010-04-15 20:01 665,600 a——- c:\windows\inf\drvindex.dat 2010-04-14 02:03 21,316 a——- c:\windows\system32\emptyregdb.dat 2010-04-14 01:34 0 a—h— c:\windows\system32\drivers\Msft_Kernel_ATSwpWDF_01005.Wdf 2010-04-14 01:33 0 a—h— c:\windows\system32\drivers\Msft_Kernel_Apfiltr_01005.Wdf 2010-04-12 21:21 57,752 ——– c:\windows\system32\rpcnet.exe 2010-03-09 12:25 78,336 a——- c:\windows\system32\ieencode.dll 2010-03-09 11:42 834,048 a——- c:\windows\system32\wininet.dll 2008-10-26 12:12 61,224 a——- c:\users\chad\GoToAssistDownloadHelper.exe 2008-10-22 18:08 1,844 a——- c:\users\chad\appdata\roaming\install.dat 2008-01-20 22:43 174 a–sh— c:\program files\desktop.ini 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2008-10-13 19:40 76 a–shr– c:\windows\CT4CET.bin ============= FINISH: 0:34:41.50 =============== Here is the Kaspersky log: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, June 5, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, June 04, 2010 18:05:58 Records in database: 4200047 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 154590 Threats found: 6 Infected objects found: 24 Suspicious objects found: 0 Scan duration: 02:09:55 File name / Threat / Threats count C:\Users\Chad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\7ebc7b8-56858ac6 Infected: Exploit.Java.Agent.f 1 C:\Users\Chad\Outlook.bak Infected: Trojan.Win32.Small.accn 8 C:\Users\Chad\Outlook.bak Infected: Trojan.Win32.Sasfis.akzx 1 C:\Users\Chad\Outlook.pst Infected: Trojan.Win32.Tdss.beln 2 C:\Users\Chad\Outlook.pst Infected: Trojan.Win32.Tdss.belr 4 C:\Users\Chad\Outlook.pst Infected: Trojan.Win32.Tdss.bemg 8 Selected area has been scanned.
Hello ChadA,

Most of those ones found by Kaspersky are in your Outlook. I am reluctant to use a tool to remove them in case we remove all items in your e-mail including ones you want to keep. I suggest you go to Outlook and delete all your old e-mail in all folders including archives.

After that

Please download ComboFix from:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop

———————————————————————————————————-

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.

———————————————————————————————————-

Open notepad and copy/paste the text in the quotebox below into it:

KillAll::

File::
C:\Users\Chad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\7ebc7b8-56858ac6

Reboot::


Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it will produce a log for you at C:\ComboFix.txt Please post that here for further review.
I have disabled the ever-useless McAfee and tried to run ComboFix a few times (including once after a restart). Every time I run it, I get the error message "Windows Command Processor has stopped working" after it creates the restore point. Then ComboFix closes on its own and creates no log. It kills my internet connection, too. FWIW, McAfee didn't let me download it at first because it thought it was a Trojan. :) Edit: McAfee claims it found the following Trojan in ComboFix.exe: Artemis!FDD5E87649AD
Hmm…

You have used Malwarebytes before. If you still have it on your machine please update and run. Post the scan report back here.

If you no-longer have Malwarebytes please download from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy & Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Next

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /180
    %systemroot%system32user32.dll /md5
    %systemroot%system32ws2_32.dll /md5
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so.
    o When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    o Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post back here.
Note: Unless otherwise instructed always post the logs in the forum. If reports don't fit on one post. It might be necessary to break the logs up to get them on the forum. Just use as many posts as you need, that's fine. :)

So when you return please post
  • MBAM log
  • OTL logs - OTL.txt and OTL.Extras.txt
I'll do that and post back. By the way, McAfee claims it found the following Trojan in ComboFix.exe: Artemis!FDD5E87649AD . What do you make of that?
MBAM Log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4177 Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005 6/7/2010 9:16:26 PM mbam-log-2010-06-07 (21-16-26).txt Scan type: Quick scan Objects scanned: 130125 Time elapsed: 7 minute(s), 22 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) **** I should mention that since my first post on 6/4, I uninstalled and re-installed Java and deleted the old infected Outlook.bak file. I useed Kaspesky's virus detector to help. OTL logs to follow….

What do you make of that?


One reason that ComboFix won't work is because it has been compromised. The reason for the

Hmm…

in the my last post.

There is a very nasty infection out there that can do this.

The prognosis is not good if you machine has that. For now though let's do a bit more digging. Carry out those last actions I suggested and we will look at things again.
OTL Log:

OTL logfile created on: 6/7/2010 9:18:38 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Chad\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 57.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.29 Gb Total Space | 200.25 Gb Free Space | 69.46% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 4.89 Gb Free Space | 50.10% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 1.91 Gb Total Space | 1.65 Gb Free Space | 86.56% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHAD-PC
Current User Name: Chad
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/07 21:17:44 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Chad\Desktop\OTL.exe
PRC - [2010/04/12 21:21:54 | 000,057,752 | —- | M] (Absolute Software Corp.) – C:\Windows\System32\rpcnet.exe
PRC - [2010/04/02 16:08:13 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/03/21 14:08:33 | 000,202,256 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/11/26 11:06:03 | 000,030,192 | —- | M] (Google) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2009/10/29 07:54:44 | 001,218,008 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2009/10/27 12:19:46 | 000,895,696 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\MPF\MpfSrv.exe
PRC - [2009/09/16 10:22:08 | 000,144,704 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan\Mcshield.exe
PRC - [2009/09/16 09:28:38 | 000,606,736 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/08/25 19:11:06 | 000,611,624 | —- | M] (Juniper Networks) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
PRC - [2009/07/10 00:26:20 | 000,865,832 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2009/07/08 14:48:48 | 000,026,640 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\MSK\msksrver.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 002,482,848 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2009/05/21 11:13:58 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/05/12 17:50:32 | 000,842,816 | —- | M] (DigitalPersona, Inc.) – C:\Program Files\DigitalPersona\Bin\DpAgent.exe
PRC - [2009/05/12 17:50:32 | 000,322,624 | —- | M] (DigitalPersona, Inc.) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/03/16 19:59:22 | 000,483,428 | —- | M] (IDT, Inc.) – C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009/03/16 19:59:20 | 000,254,042 | —- | M] (IDT, Inc.) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe
PRC - [2009/03/16 19:59:18 | 000,081,920 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe
PRC - [2008/10/13 19:36:32 | 000,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/06/30 06:28:24 | 000,040,960 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/06/30 06:28:14 | 000,196,608 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\Apoint.exe
PRC - [2008/06/30 06:28:12 | 000,049,152 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\ApntEx.exe
PRC - [2008/06/30 06:28:12 | 000,046,376 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008/06/03 16:54:56 | 000,446,635 | —- | M] (Creative Technology Ltd.) – C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
PRC - [2008/05/05 18:46:38 | 001,168,632 | —- | M] (AuthenTec, Inc.) – C:\Program Files\Fingerprint Sensor\AtService.exe
PRC - [2008/05/02 15:09:04 | 000,161,048 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/01/14 11:13:02 | 000,132,392 | —- | M] (CyberLink Corp.) – C:\Program Files\Dell\MediaDirect\PCMService.exe
PRC - [2008/01/03 18:28:08 | 001,392,640 | R— | M] (PalmSource, Inc) – C:\Program Files\Palm\Hotsync.exe
PRC - [2007/10/03 16:45:02 | 000,358,936 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/10/03 16:44:58 | 000,178,712 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007/04/13 12:20:22 | 000,097,432 | —- | M] () – C:\Program Files\Canon\IJPLM\ijplmsvc.exe
PRC - [2007/04/03 21:50:00 | 001,603,152 | —- | M] (CANON INC.) – C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2007/02/04 12:02:14 | 000,079,400 | —- | M] (Nuance Communications, Inc.) – C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
PRC - [2006/10/12 15:57:08 | 000,102,400 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe


========== Modules (SafeList) ==========

MOD - [2010/06/07 21:17:44 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Chad\Desktop\OTL.exe
MOD - [2009/05/12 17:50:28 | 000,494,656 | —- | M] (DigitalPersona, Inc.) – C:\Program Files\DigitalPersona\Bin\DpOFeedb.dll
MOD - [2009/05/12 17:50:28 | 000,359,488 | —- | M] (DigitalPersona, Inc.) – C:\Program Files\DigitalPersona\Bin\DpOSet.dll
MOD - [2009/04/11 02:21:38 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/20 22:24:37 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2010/04/12 21:21:54 | 000,057,752 | —- | M] (Absolute Software Corp.) [Auto | Running] – C:\Windows\System32\rpcnet.exe – (rpcnet) Remote Procedure Call (RPC)
SRV - [2009/11/26 11:06:03 | 000,030,192 | —- | M] (Google) [On_Demand | Stopped] – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe – (GoogleDesktopManager-110309-193829)
SRV - [2009/10/27 12:19:46 | 000,895,696 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\MPF\MPFSrv.exe – (MpfService)
SRV - [2009/09/24 21:27:04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2009/09/16 11:23:32 | 000,365,072 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2009/09/16 10:22:08 | 000,144,704 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\McAfee\VirusScan\Mcshield.exe – (McShield)
SRV - [2009/09/16 09:28:38 | 000,606,736 | —- | M] (McAfee, Inc.) [On_Demand | Running] – C:\Program Files\McAfee\VirusScan\mcsysmon.exe – (McSysmon)
SRV - [2009/08/25 19:11:06 | 000,611,624 | —- | M] (Juniper Networks) [Auto | Running] – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe – (dsNcService)
SRV - [2009/07/10 00:26:20 | 000,865,832 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\MSC\mcmscsvc.exe – (mcmscsvc)
SRV - [2009/07/08 14:48:48 | 000,026,640 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\MSK\MskSrver.exe – (MSK80Service)
SRV - [2009/07/08 11:54:34 | 000,359,952 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe – (McProxy)
SRV - [2009/07/07 19:10:02 | 002,482,848 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe – (McNASvc)
SRV - [2009/05/12 17:50:32 | 000,322,624 | —- | M] (DigitalPersona, Inc.) [Auto | Running] – C:\Program Files\DigitalPersona\Bin\DpHostW.exe – (DpHost)
SRV - [2009/03/16 19:59:20 | 000,254,042 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe – (STacSV)
SRV - [2009/03/16 19:59:18 | 000,081,920 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe – (AESTFilters)
SRV - [2008/10/13 19:44:41 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2008/08/14 00:04:44 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/05/05 18:46:38 | 001,168,632 | —- | M] (AuthenTec, Inc.) [Auto | Running] – C:\Program Files\Fingerprint Sensor\AtService.exe – (ATService)
SRV - [2008/05/02 15:09:04 | 000,161,048 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2008/01/20 22:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/10/03 16:45:02 | 000,358,936 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2007/04/13 12:20:22 | 000,097,432 | —- | M] () [Auto | Running] – C:\Program Files\Canon\IJPLM\ijplmsvc.exe – (IJPLMSVC)


========== Driver Services (SafeList) ==========

DRV - [2009/09/16 10:22:48 | 000,214,664 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\mfehidk.sys – (mfehidk)
DRV - [2009/09/16 10:22:48 | 000,079,816 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2009/09/16 10:22:48 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/09/16 10:22:48 | 000,035,272 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfebopk.sys – (mfebopk)
DRV - [2009/09/16 10:22:14 | 000,034,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mferkdk.sys – (mferkdk)
DRV - [2009/07/16 12:32:26 | 000,130,424 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\Mpfp.sys – (MPFP)
DRV - [2009/03/16 19:59:22 | 000,398,336 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2009/03/09 01:06:00 | 000,280,096 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\OA001Vid.sys – (OA001Vid)
DRV - [2009/03/06 15:30:08 | 000,133,632 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\OA001Ufd.sys – (OA001Ufd)
DRV - [2008/11/17 07:29:14 | 001,331,192 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XX)
DRV - [2008/11/17 07:29:08 | 000,018,424 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\bcm42rly.sys – (BCM42RLY)
DRV - [2008/06/30 06:28:10 | 000,170,032 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Apfiltr.sys – (ApfiltrService)
DRV - [2008/06/30 01:54:56 | 000,475,136 | —- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\ATSwpWDF.sys – (ATSwpWDF)
DRV - [2008/05/04 04:42:18 | 003,548,672 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\atikmdag.sys – (atikmdag)
DRV - [2008/03/14 09:04:26 | 000,054,784 | —- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\itecir.sys – (itecir)
DRV - [2008/03/11 02:44:12 | 000,305,176 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\iastor.sys – (iaStor)
DRV - [2008/03/11 02:42:24 | 000,203,264 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\k57nd60x.sys – (k57nd60x) Broadcom NetLink ™
DRV - [2008/03/11 02:24:46 | 000,038,400 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2008/03/11 02:24:44 | 000,046,592 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2008/03/11 02:24:42 | 000,043,008 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2008/01/20 22:23:27 | 000,386,616 | —- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasr.sys – (MegaSR)
DRV - [2008/01/20 22:23:27 | 000,149,560 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2008/01/20 22:23:27 | 000,031,288 | —- | M] (LSI Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2008/01/20 22:23:26 | 000,101,432 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2008/01/20 22:23:26 | 000,074,808 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2008/01/20 22:23:26 | 000,040,504 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2008/01/20 22:23:25 | 000,300,600 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2008/01/20 22:23:25 | 000,089,656 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2008/01/20 22:23:24 | 001,122,360 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2008/01/20 22:23:24 | 000,118,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2008/01/20 22:23:24 | 000,079,928 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2008/01/20 22:23:23 | 000,235,064 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2008/01/20 22:23:23 | 000,130,616 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2008/01/20 22:23:23 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2008/01/20 22:23:23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2008/01/20 22:23:23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2008/01/20 22:23:23 | 000,079,416 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2008/01/20 22:23:22 | 000,342,584 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2008/01/20 22:23:21 | 000,422,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2008/01/20 22:23:21 | 000,102,968 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2008/01/20 22:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2008/01/20 22:23:20 | 000,238,648 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2008/01/20 22:23:00 | 000,020,024 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2008/01/20 22:23:00 | 000,019,000 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2008/01/20 22:23:00 | 000,017,464 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2007/12/04 17:10:30 | 000,016,640 | —- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\PalmUSBD.sys – (PalmUSBD)
DRV - [2007/01/18 15:28:02 | 000,005,275 | —- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CVirtA.sys – (CVirtA)
DRV - [2006/11/02 05:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 05:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 05:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 05:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 05:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 05:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 05:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 05:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 05:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 05:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 05:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 04:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 04:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 04:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 04:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 04:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 04:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 03:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://rr.com/"
FF - prefs.js..extensions.enabledItems: [removed]:5.0.0.3767
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\DigitalPersona\Bin\FirefoxExt\ [2010/04/14 01:39:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/05 16:59:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/26 19:46:34 | 000,000,000 | —D | M]

[2010/04/14 01:56:40 | 000,000,000 | —D | M] – C:\Users\Chad\AppData\Roaming\Mozilla\Extensions
[2010/06/07 21:04:23 | 000,000,000 | —D | M] – C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\an0vaf5c.default\extensions
[2010/04/29 13:44:52 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\an0vaf5c.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/07 21:04:23 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/06 11:46:33 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/06/06 11:46:14 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (DigitalPersona Fingerprint Software Extension) - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [EEventManager] C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe ( )
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - c:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/20 22:34:27 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/06/07 21:17:36 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\Chad\Desktop\OTL.exe
[2010/06/07 20:52:26 | 000,000,000 | –SD | C] – C:\ComboFix
[2010/06/07 20:52:06 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/06/07 20:41:42 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/06/07 20:41:42 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/06/07 20:41:42 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/06/07 20:41:37 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/06/07 20:41:08 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/07 10:53:27 | 000,000,000 | —D | C] – C:\Users\Chad\Documents\Grainger Book Notes
[2010/06/06 21:22:39 | 000,000,000 | —D | C] – C:\Users\Chad\Documents\Trombone Ped
[2010/06/06 11:47:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/06/06 11:46:29 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/06/06 11:46:29 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/06/06 11:46:29 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/06/06 00:45:10 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2010/06/04 16:20:51 | 000,000,000 | —D | C] – C:\Users\Chad\AppData\Roaming\Malwarebytes
[2010/06/04 16:20:44 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/06/04 16:20:43 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/06/04 16:20:42 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/06/04 16:20:42 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/26 14:37:28 | 000,000,000 | —D | C] – C:\Users\Chad\AppData\Roaming\Foxit Software
[2010/05/22 17:07:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SureThing Shared
[2010/05/22 17:06:20 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PX Storage Engine
[2010/05/22 17:06:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Sonic Shared
[2010/05/22 17:04:55 | 000,000,000 | —D | C] – C:\Program Files\Roxio
[2010/05/17 20:10:22 | 000,000,000 | -HSD | C] – C:\found.000
[2008/05/22 11:17:50 | 000,008,192 | —- | C] ( ) – C:\Windows\System32\cshost.dll

========== Files - Modified Within 30 Days ==========

[2010/06/07 21:22:05 | 003,145,728 | -HS- | M] () – C:\Users\Chad\NTUSER.DAT
[2010/06/07 21:17:44 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Chad\Desktop\OTL.exe
[2010/06/07 21:11:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/07 21:09:39 | 1950,368,768 | —- | M] () – C:\Users\Chad\Outlook.pst
[2010/06/07 20:58:07 | 000,691,140 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/06/07 20:58:07 | 000,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/06/07 20:58:07 | 000,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/06/07 20:55:47 | 000,028,659 | —- | M] () – C:\Windows\System32\Config.MPF
[2010/06/07 20:50:33 | 000,017,408 | —- | M] () – C:\Windows\System32\rpcnetp.exe
[2010/06/07 20:50:30 | 000,057,752 | —- | M] (Absolute Software Corp.) – C:\Windows\System32\rpcnet.dll
[2010/06/07 20:50:28 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/07 20:50:25 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/07 20:50:25 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/07 20:50:22 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/07 20:50:20 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/07 20:49:26 | 000,524,288 | -HS- | M] () – C:\Users\Chad\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/06/07 20:49:26 | 000,065,536 | -HS- | M] () – C:\Users\Chad\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/06/07 20:49:22 | 002,736,339 | -H– | M] () – C:\Users\Chad\AppData\Local\IconCache.db
[2010/06/07 20:36:13 | 000,000,116 | —- | M] () – C:\Windows\NeroDigital.ini
[2010/06/06 13:04:24 | 1971,192,832 | —- | M] () – C:\Users\Chad\Outlook - Copy (1).pst
[2010/06/06 11:46:13 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/06/06 11:46:13 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/06/06 11:46:13 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/06/06 11:46:13 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/06/06 00:39:49 | 000,000,000 | —- | M] () – C:\Windows\System32\null
[2010/06/04 12:01:18 | 000,001,724 | -H– | M] () – C:\Users\Chad\Documents\Default.rdp
[2010/06/04 11:12:33 | 000,000,704 | —- | M] () – C:\Users\Chad\Desktop\FOXUSER.FPT
[2010/05/26 14:24:30 | 000,002,549 | —- | M] () – C:\Windows\1way.ini
[2010/05/22 17:04:16 | 000,000,146 | —- | M] () – C:\Windows\WININIT.INI
[2010/05/17 20:15:37 | 000,017,408 | —- | M] () – C:\Windows\System32\rpcnetp.dll
[2010/05/13 10:13:54 | 000,009,728 | —- | M] () – C:\Users\Chad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/13 09:53:09 | 000,000,680 | —- | M] () – C:\Users\Chad\AppData\Local\d3d9caps.dat

========== Files Created - No Company Name ==========

[2010/06/07 20:41:42 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/06/07 20:41:42 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/06/07 20:41:42 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/06/07 20:41:42 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/06/07 20:41:42 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/06/06 11:25:43 | 1971,192,832 | —- | C] () – C:\Users\Chad\Outlook - Copy (1).pst
[2010/05/22 17:04:16 | 000,000,146 | —- | C] () – C:\Windows\WININIT.INI
[2010/05/13 10:13:09 | 000,009,728 | —- | C] () – C:\Users\Chad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/13 09:53:09 | 000,000,680 | —- | C] () – C:\Users\Chad\AppData\Local\d3d9caps.dat
[2010/04/14 23:48:04 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/04/14 05:24:06 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2010/04/14 01:31:50 | 000,017,408 | —- | C] () – C:\Windows\System32\rpcnetp.dll
[2010/03/31 11:00:26 | 000,000,029 | —- | C] () – C:\Windows\DEBUGSM.INI
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/06/04 22:55:39 | 000,006,656 | —- | C] () – C:\Windows\System32\bcmwlrc.dll
[2009/03/24 21:18:55 | 000,000,412 | —- | C] () – C:\Windows\MAXLINK.INI
[2009/03/24 16:22:35 | 000,000,028 | —- | C] () – C:\Windows\ODBC.INI
[2009/01/22 23:50:08 | 000,000,116 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/01/09 00:01:13 | 000,000,000 | —- | C] () – C:\Windows\Dvm.INI
[2008/10/24 14:49:18 | 000,152,368 | —- | C] () – C:\Windows\System32\WIN2PDFS.DLL
[2008/10/24 14:49:18 | 000,022,832 | —- | C] () – C:\Windows\System32\WIN2PDFM.DLL
[2008/10/24 14:49:17 | 000,002,549 | —- | C] () – C:\Windows\1way.ini
[2008/10/23 19:07:47 | 000,210,944 | —- | C] () – C:\Windows\System32\MSVCRT10.DLL
[2008/10/23 19:07:47 | 000,000,149 | —- | C] () – C:\Windows\KPCMS.INI
[2008/10/23 19:02:52 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2008/10/23 18:58:40 | 000,000,044 | —- | C] () – C:\Windows\PERF4490.ini
[2008/10/13 19:35:43 | 000,054,784 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/06/07 20:36:13 | 000,000,223 | —- | M] () – C:\AACParser.log
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2010/04/14 05:24:25 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/10/13 22:15:42 | 000,003,760 | RH– | M] () – C:\dell.sdr
[2010/04/14 02:00:37 | 3219,103,744 | -HS- | M] () – C:\hiberfil.sys
[2008/10/23 19:06:10 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/10/23 19:06:10 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/06/07 14:09:00 | 000,000,457 | —- | M] () – C:\NeAudio.log
[2010/06/07 20:50:16 | 3532,906,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/05/04 04:42:16 | 000,372,736 | —- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 – C:\Windows\System32\ATIDEMGX.dll
[2008/11/17 07:29:10 | 000,054,784 | —- | M] () Unable to obtain MD5 – C:\Windows\System32\bcmwlrmt.dll
[2009/04/11 02:27:47 | 000,241,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2009/04/11 02:28:23 | 000,228,352 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2010/04/14 05:23:54 | 012,820,480 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2010/04/14 05:23:49 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2010/04/14 05:23:54 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2010/04/14 05:24:01 | 017,412,096 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2010/04/14 05:24:03 | 006,733,824 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\system32\drivers\*.sys /180 >
[2010/02/20 16:53:34 | 000,411,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\http.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/23 07:10:13 | 000,106,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb.sys
[2010/02/23 07:10:19 | 000,212,992 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys
[2010/02/23 07:10:13 | 000,079,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys
[2009/12/11 07:43:30 | 000,302,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2009/12/11 07:43:11 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2010/02/18 10:07:16 | 000,904,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpip.sys
[2010/02/18 07:28:13 | 000,025,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tunnel.sys

< %systemroot%system32user32.dll /md5 >

< %systemroot%system32ws2_32.dll /md5 >
< End of report >
OTL Extras:

OTL Extras logfile created on: 6/7/2010 9:18:38 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Chad\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 57.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.29 Gb Total Space | 200.25 Gb Free Space | 69.46% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 4.89 Gb Free Space | 50.10% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 1.91 Gb Total Space | 1.65 Gb Free Space | 86.56% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHAD-PC
Current User Name: Chad
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-260708253-2613895943-1272409466-1000]
"EnableNotifications" = 1
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{6AA55C50-8920-4606-9F33-C592ABEE418E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{09BD3065-9760-4B13-90CA-2F6E06DB2788}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{11CA68CA-11E0-4215-8C55-EFCDC5D9AD93}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2C48C8D7-6F97-42C9-988E-0C3559625AF4}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dmp\clbrowserengine.exe |
"{497EF1E1-2743-46D9-8F9A-7ECE9D84230D}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{5167D1A4-6F4F-4325-AE93-1C16F7FDAF2D}" = protocol=17 | dir=in | app=c:\program files\dell video chat\dellvideochat.exe |
"{5B9D770B-E462-406C-AE33-F8B139B713FD}" = protocol=6 | dir=in | app=c:\program files\dell video chat\dellvideochat.exe |
"{AA5A53BA-F3D5-40CB-A9FD-178B7ECD84D7}" = dir=in | app=c:\program files\dell\mediadirect\mediadirect.exe |
"{AF252A41-2755-4F50-8320-94B8486C86BE}" = dir=in | app=c:\program files\dell\mediadirect\pcmservice.exe |
"{CEC6A2B8-9C31-463A-9780-1FCD09E28648}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D7073388-C1AF-4120-B38D-C6DC03F416D0}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dms\clmsservice.exe |
"{D932BDAE-BDE0-49EB-BE48-ECA8608ADFA0}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{05A677ED-F6EB-C225-0852-C8EDA143F637}" = Catalyst Control Center Core Implementation
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{10CCF16B-F1C9-4B24-9570-B4CCEE42392D}" = LightScribe System Software
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP520_series" = Canon MP520 series
"{11F5D779-7BD9-465A-BBC4-10701386BCB9}" = FW LiveUpdate
"{1339C679-8EBD-A264-F51B-8AFF9E5178AB}" = Catalyst Control Center Localization Chinese Standard
"{140BF0D0-E848-405C-9A01-D3256B918B6D}" = AuthenTec Fingerprint System
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{235D8A8E-2F97-11D6-A551-0090278A1BB8}" = Visual FoxPro 8.0 Baseline - English
"{235D8A94-2F97-11D6-A551-0090278A1BB8}" = Visual FoxPro 8.0 Professional - English
"{263BC7B3-1E34-447C-A666-F0E5AE80697F}" = InstallShield Express Visual FoxPro Limited Edition
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28DFA10C-2588-4CF2-9275-E0EFF1E9BB0C}" = Complete Care Consumer Service Agreement
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{326957C7-83FD-4550-A59A-849B7B4297DE}" = Microsoft Easy Assist v2
"{33D38429-A417-2939-F2ED-68B02C60524B}" = CCC Help Italian
"{348982C0-1053-041B-90E9-27E52C5CBAC4}" = Catalyst Control Center Localization Chinese Traditional
"{3683198D-D48D-8F78-D544-E0CEEDA9A5AD}" = Catalyst Control Center Localization Norwegian
"{39874C29-6A64-A5E4-15E8-48CAB1630758}" = Catalyst Control Center Graphics Full New
"{3D8AE086-030F-4EF4-B705-63F8130B043E}" = DigitalPersona Personal 4.01
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{470C8EFE-AEB0-402E-B05A-91E08C201033}" = Nero 8 Essentials
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = EPSON Event Manager
"{497CDC20-F32E-B732-D5A7-C508832901B1}" = Catalyst Control Center Localization Italian
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CA09BF7-1CFC-44B8-80EA-7B4D15D12DC5}" = Catalyst Control Center - Branding
"{4E8B4C51-20A4-A946-F2FD-361E1E64CBFE}" = Catalyst Control Center Localization Dutch
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{66E07661-1C3B-EBB3-DDD7-CA2D9CF728E5}" = CCC Help Chinese Standard
"{67192DDF-D12C-7C14-0891-1999A8322D9A}" = ccc-core-static
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{693C5CAC-E43C-4A5F-0793-DB1A91576F00}" = Catalyst Control Center Localization Swedish
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}" = EDocs
"{6BA2D1B0-0892-AF53-1542-767C1B1B558F}" = CCC Help German
"{706136D4-648C-92B9-FF9E-BDAC45C977CB}" = CCC Help Norwegian
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{732784F2-BBB3-AF93-F0F8-2B28D93F023E}" = Catalyst Control Center Localization Finnish
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{75554025-5756-D2A8-E12A-3996A174E1AF}" = Catalyst Control Center Localization German
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7842F022-6597-76DA-4DE4-DA3FBD82ECF2}" = Skins
"{7A4CE9D2-DC5E-4B5B-0ED2-A2F66E76DD52}" = CCC Help Russian
"{7BE855E5-8130-A624-1C47-D5EB13FA6DF2}" = Catalyst Control Center Graphics Previews Vista
"{7D712AFE-2D7C-13B8-DEB7-BA8A28FED665}" = Catalyst Control Center Localization Danish
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7E00AAF2-89F3-F7FC-A8F2-8C651449671E}" = CCC Help English
"{80EFBB50-5B6C-4A9D-AFBC-C7664AFF252F}" = Digital Voice Recorder
"{828816F4-629A-233E-DB02-A6F8BD004643}" = Catalyst Control Center Localization Portuguese
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{903679E8-44C8-4C07-9600-05C92654FC50}" = QualXServ Service Agreement
"{90601456-1F28-AD6C-C1CE-740526D3BC27}" = Catalyst Control Center Localization French
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{975F5675-8FC8-04A8-92CD-4653BD12282F}" = CCC Help French
"{97900633-AADE-35DC-A424-21380BFC5431}" = Catalyst Control Center Graphics Previews Common
"{98C948A6-5498-9DEE-BA4C-74B0A96CB521}" = CCC Help Danish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A7969E95-7E39-A1AC-2D6F-85531D8A371D}" = CCC Help Japanese
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9C78107-7CBC-B05B-083B-562FA9C1EA0B}" = CCC Help Portuguese
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BB883D70-5B1D-9430-E626-7F495925590D}" = Catalyst Control Center Localization Spanish
"{C0A88AB8-DB02-42C8-B55A-F29019AE829C}" = OutlookTools 2
"{C4972073-2BFE-475D-8441-564EA97DA161}" = QuickSet
"{C49E407D-A6A0-6F9A-767D-67387EF5523F}" = CCC Help Finnish
"{CBF91610-C661-3464-8831-DA8AE2589DB9}" = Catalyst Control Center Localization Japanese
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2DB5404-378B-2821-513E-A8F230A0E948}" = ccc-utility
"{D5D92C28-42FB-5E24-DBFA-07232A50D670}" = CCC Help Dutch
"{D9DD6E03-ACE1-2503-205E-4FA74267CDC6}" = CCC Help Spanish
"{DB549485-9D94-E7AE-2FE7-DCB33A54FBD7}" = Catalyst Control Center Localization Russian
"{DE200E10-45BD-E11E-EC8E-1DAD80EF8EA9}" = Catalyst Control Center Graphics Full Existing
"{DEF19AE8-B330-CF2A-AEAA-1E23BBBC7B00}" = CCC Help Chinese Traditional
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E5BE4931-F31C-2BA0-F06E-4FEC56725673}" = CCC Help Swedish
"{EC2C71BB-42DF-6F53-FB23-F7B3B160467B}" = Catalyst Control Center Graphics Light
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F1465B68-4D9A-D412-2528-4F84A681F15C}" = Catalyst Control Center Localization Korean
"{F1E18790-4053-4031-483B-80E932CE3910}" = CCC Help Korean
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"{FCED9B62-34FF-4C15-8A23-F65221F7874D}" = ITECIR Driver
"{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}" = Palm Desktop by ACCESS
"Active@ KillDisk FREE Suite" = Active@ KillDisk FREE Suite
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 2.0" = Adobe Photoshop Elements 2.0
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Audacity_is1" = Audacity 1.2.6
"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility
"Canon MP520 series User Registration" = Canon MP520 series User Registration
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Creative OA001" = Integrated Webcam Driver (1.06.03.0309)
"Dell Video Chat" = Dell Video Chat (remove only)
"Dell Webcam Central" = Dell Webcam Central
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"EPSON Scanner" = EPSON Scan
"FileZilla Client" = FileZilla Client [removed]
"FTDICOMM" = OCT LAN DOCK Serial Converter Drivers
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist 8.0.0.514
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"InstallShield_{263BC7B3-1E34-447C-A666-F0E5AE80697F}" = InstallShield Express Visual FoxPro Limited Edition
"Juniper Network Connect 6.4.0" = Juniper Networks Network Connect 6.4.0
"Juniper_Setup_Client Activex Control" = Juniper Networks Setup Client Activex Control
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"MSC" = McAfee SecurityCenter
"MVApplication1" = SureThing CD Labeler Deluxe 3.0
"PROR" = Microsoft Office Professional 2007
"RealPlayer 12.0" = RealPlayer
"Silent Package Run-Time Sample" = EPSON Perf 4490P Guide
"Some PDF Image Extract_is1" = Some PDF Image Extractr 1.5
"StyleEase for CHI Style" = StyleEase for CHI Style
"Visual FoxPro 8.0 Professional - English" = Microsoft Visual FoxPro 8.0 Professional - English
"Win2PDF Font Helper_is1" = Win2PDF Font Helper 1.21 (GPL Ghostscript 8.62)
"Win2PDF_is1" = Win2PDF 3.40.1

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Setup_Client" = Juniper Networks Setup Client

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/17/2010 1:14:42 PM | Computer Name = Chad-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/18/2010 9:44:01 AM | Computer Name = Chad-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/18/2010 7:32:34 PM | Computer Name = Chad-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/19/2010 10:22:50 AM | Computer Name = Chad-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/19/2010 9:22:39 PM | Computer Name = Chad-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/20/2010 11:08:58 AM | Computer Name = Chad-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/21/2010 11:32:56 AM | Computer Name = Chad-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/21/2010 12:25:09 PM | Computer Name = Chad-PC | Source = Application Error | ID = 1000
Description = Faulting application WebcamDell.exe, version 1.1.3.0, time stamp 0x4844f8d0,
faulting module WebcamDell.exe, version 1.1.3.0, time stamp 0x4844f8d0, exception
code 0xc0000005, fault offset 0x0000879e, process id 0xbc0, application start time
0x01cae16f2369d13e.

Error - 4/21/2010 12:26:08 PM | Computer Name = Chad-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/21/2010 4:50:33 PM | Computer Name = Chad-PC | Source = WinMgmt | ID = 10
Description =

[ Broadcom Wireless LAN Events ]
Error - 4/14/2010 2:44:25 AM | Computer Name = Chad-PC | Source = WLAN-Tray | ID = 0
Description = 02:44:21, Wed, Apr 14, 10 Error - Unable to gain access to user store


Error - 5/15/2010 9:19:31 AM | Computer Name = Chad-PC | Source = WLAN-Tray | ID = 0
Description = 09:19:31, Sat, May 15, 10 Error - Unable to gain access to user store


Error - 5/31/2010 3:14:20 PM | Computer Name = Chad-PC | Source = WLAN-Tray | ID = 0
Description = 15:14:20, Mon, May 31, 10 Error - Unable to gain access to user store


Error - 6/6/2010 2:04:01 PM | Computer Name = Chad-PC | Source = WLAN-Tray | ID = 0
Description = 14:04:01, Sun, Jun 06, 10 Error - Unable to gain access to user store


[ DigitalPersona Pro Events ]
Error - 9/8/2009 1:18:23 PM | Computer Name = Chad-PC | Source = DigitalPersona Pro | ID = 17827589
Description = DPHost cannot start. Error: 0x8009000f

Error - 10/14/2009 10:12:58 AM | Computer Name = Chad-PC | Source = DigitalPersona Pro | ID = 17827589
Description = DPHost cannot start. Error: 0x8009000f

[ OSession Events ]
Error - 7/27/2009 2:51:13 PM | Computer Name = Chad-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 692
seconds with 600 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 6/7/2010 8:47:37 PM | Computer Name = Chad-PC | Source = netbt | ID = 4321
Description = The name "CHAD-PC :20" could not be registered on the interface
with IP address 192.168.2.12. The computer with the IP address 192.168.2.4 did not
allow the name to be claimed by this computer.

Error - 6/7/2010 8:50:32 PM | Computer Name = Chad-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{51A96C95-2ABB-45A4-A245-467AE1DC700D}
because another computer on the network has the same name. The server could not
start.

Error - 6/7/2010 8:50:32 PM | Computer Name = Chad-PC | Source = netbt | ID = 4321
Description = The name "CHAD-PC :0" could not be registered on the interface
with IP address 192.168.2.12. The computer with the IP address 192.168.2.4 did not
allow the name to be claimed by this computer.

Error - 6/7/2010 8:50:32 PM | Computer Name = Chad-PC | Source = netbt | ID = 4321
Description = The name "CHAD-PC :0" could not be registered on the interface
with IP address 192.168.2.12. The computer with the IP address 192.168.2.4 did not
allow the name to be claimed by this computer.

Error - 6/7/2010 8:50:32 PM | Computer Name = Chad-PC | Source = netbt | ID = 4321
Description = The name "CHAD-PC :20" could not be registered on the interface
with IP address 192.168.2.12. The computer with the IP address 192.168.2.4 did not
allow the name to be claimed by this computer.

Error - 6/7/2010 8:52:04 PM | Computer Name = Chad-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/7/2010 8:55:22 PM | Computer Name = Chad-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{51A96C95-2ABB-45A4-A245-467AE1DC700D}
because another computer on the network has the same name. The server could not
start.

Error - 6/7/2010 8:55:22 PM | Computer Name = Chad-PC | Source = netbt | ID = 4321
Description = The name "CHAD-PC :0" could not be registered on the interface
with IP address 192.168.2.12. The computer with the IP address 192.168.2.4 did not
allow the name to be claimed by this computer.

Error - 6/7/2010 8:55:22 PM | Computer Name = Chad-PC | Source = netbt | ID = 4321
Description = The name "CHAD-PC :0" could not be registered on the interface
with IP address 192.168.2.12. The computer with the IP address 192.168.2.4 did not
allow the name to be claimed by this computer.

Error - 6/7/2010 8:55:22 PM | Computer Name = Chad-PC | Source = netbt | ID = 4321
Description = The name "CHAD-PC :20" could not be registered on the interface
with IP address 192.168.2.12. The computer with the IP address 192.168.2.4 did not
allow the name to be claimed by this computer.


< End of report >
Hi ChadA,

Nothing leaping out at me there.

I think it likely that that McAfee one was just a false positive. McAfee is notorious for interfering with ComboFix.

Now

I know you have used Kaspersky on line scanner which is pretty comprehensive but just to make sure that McAfee one wasn't something bad let's do this.

It is a pretty big download but is very useful at detecting\cleaning rootkits or whatever it finds.

Please click here to download VRT Tool by Kaspersky.
  • Save it to your desktop
  • Double click the setup file to run it
  • Accept the agreement
  • A pop up window will appear.
  • On the Autoscan panel check all items
  • Click on Start Scan
  • When finished (this can take some time… just be patient and let it do its job) click the Report button
  • Click the + button left top to expand the critical events
  • Highlight Ctrl A and copy Ctrl C
  • Save to Notepad Ctrl V
Copy and past the report back here.

Click exit to uninstall Kaspersky VRT. Click yes to the prompts to complete the process.

Note: This tool will self uninstall when you click Exit so please save the log before closing it.

Here are the results of the Kaspersky VRT scan: Autoscan: completed 8 hours ago (events: 2, objects: 651630, time: 04:15:37) 6/7/2010 9:54:35 PM Task started 6/8/2010 2:10:12 AM Task completed ***** Looks pretty clean. :)
Hello ChadA,

Well I think your machine is clean.

Unless there is anything else you want to bring up we can go to clearing away the tools we have been using.

We have a couple of last steps to perform and then you're all set.[image unavailable: Posted Image]

Follow these steps to uninstall Combofix and tools used in the removal of malware. This will also clean out and reset your Restore Points.
Step 2
  • Double-click OTL.exe to run it. (Vista users, please right click on OTL.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

MBAM can be uninstalled via control panel add/remove but it may be a useful tool to keep.

——————————————————————————————————————-

A reminder: Remember to turn back on any anti-malware programs you may have turned off during the cleaning process.

——————————————————————————————————————-

Now that your machine is clean here are some things that I think are worth having a look at if you don't already know a bout them:

———————————————————————————————————————

Regularly check that your Java is up to date. Older versions are vunerable to malicious attack.
  • Download from here Java Runtime Environment (JDK) Update
  • Scroll to where it says "Windows XP/Vista/2000/2003/2008 online" and download and follow the instructions to install.

    Reboot your computer.
    You also need to uininstall older versions of Java.

  • Click Start > Control Panel > Programs
  • Remove all Java updates except the latest one you have just installed.
——————————————————————————————————————–

Be sure and give the Temp folders a cleaning out now and then. This helps with security and your computer will run more efficiently. I clean mine once a week.

For ease of use, you might consider the following free program:
  • TFC.exe
——————————————————————————————————————–

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
* Consider using an alternate browser.

Opera may be downloaded from here. It is one of the least targeted of all browers.

Avant may be downloaded from here. Another one that is less well known.

Firefox may be downloaded from Here. I use Firefox because I like it. Used to be one of the safest but now targeted probably as much as IE.

Adblock Plus is a good Add-on for Firefox that helps prevent those annoying pop ups.

———————————————————————————————————————–

To help protect your computer in the future here are some free programs you can look at:

  • If you do not already have automatic updates set then it is recommended that you do set Windows to check, download and install your updates automatically.

    * Click Start > Control Panel > System and Security > Windows Update
    * Under Windows Update click on Turn automatic updating on or off
    * Check items shown to ensure you receive updates automatically. Click OK.

    And to keep your system clean consider choosing from these free for home use malware scanners and updating and running weekly.
  • Malwarebytes
  • SuperAntiSpyWare
Be aware of what emails you open and websites you visit.

Go here for some good advice about how to prevent infection.

Have a safe and happy computing day!
Thanks! I've gotten infected a couple of times and McAfee has failed to prevent it. Are there better options out there? A friend recommended MS's Windows Security Essentials. Is it any better or worse than McAfee?
Hello again ChadA,

Are there better options out there? A friend recommended MS's Windows Security Essentials. Is it any better or worse than McAfee?


Here are my thoughts on anti-virus programs for what they are worth.

Most of the well known anti-virus products are good. Some perform better in some aspects than others but if you were to look at the overall picture they are mostly good.

Sometimes one will be on top of the pops one month and another on another month. Of course there are some rogue programs out there too that you must steer clear of because they bring infection with them.

Some of the free ones are good but you do not get the full service. The sound "pay for products" out there have packages which include anti-spyware, firewalls and adware blocking so you get the whole lot in one go.

This link will take you to an independant site showing comparatives for Anti-virus products. Look at comparatives with caution because one month a program may do well and in another not so well.

http://www.av-comparatives.org/

All of the ones shown there are good products. Sometimes it comes down to your personal taste. In other words you like a particular product because to you it is user friendly or looks good.

Ones I personally like at the moment are Avira and Kaspersky but that is only a personal preference and my preferences do change as products undergo improvement.

Of the free ones, I recommend Avast, Avira and AVG. All are good.

If you are looking at free products you should look at combining an anti-virus, with a firewall and also look at and anti-spyware product.

Here are three good free for personal use antivirus : I like Avira but some people find the pop up advertisements each time it updates a bit trying.

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

Here are two good firewalls free for personal use:

A more recent arrival and one to consider is Microsoft Security Essentials
  • Microsoft Security Essientials
I have Microsoft Security Essentials and it is working beautifully.

It's so unobtrusive and works well with Windows Firewall but… when I first installed it (which I did as a test) I ran it with a proprietory firewall. Seemed to work fine for a couple of weeks then my computer started to freeze up. Couldn't work it out… lots of experimenting… took ages, finally worked out that when I uninstalled MSE things started working fine.

However I liked the way MSE was, so light on resources, so experimented some more and found that it did work fine so long as it didn't have to work with other things. You can set it to allow other real time anti-malware programs but it is a bit of a finicky job to do.

I now have it on two of my three machines with Windows Firewall. Probably don't get quite the security I got before (last time I looked Windows Firewall only works on incoming traffic), but then again, you really need to be a bit of a geek to know which files to allow, and which to say no to each time one of those other firewalls asks for a decision.

My thought now is that Microsoft Security Essentials together with Windows Firewall (which comes with Windows) is probably a good choice for the run of the mill user. This because it is light on resources, it is unobtrusive (it works away in the background without interrupting) and you don't have to be an expert.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI