This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tests clean, but numerous errors, glitches

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm not sure this is where I should post this but "Paws" moved me over from Asking for and Offering Help and suggested I post my logs here for review. I've been having major issues with memory going 100% & staying there. I think that's been resolved now. It was something that happened a few months back. Turns out that it was a poorly written update to Kaspersky Anti Vi. It looks like they have resolved it in a subsequent update. But… when this first happened I tried LOTS of fixes. Some things worked kinda, other things blew up in my face. All in all I realized I'm not really qualified, and the learning curve is a b*tch!

Anyway, my current or on-going issues

3 to many pages of errors noted in firefox, each time I use it.

I have pages of error postings in my Event Viewer Admin files something called DCOM, and MSInstaller appear to have gone ROGUE!!


I've been trying to download a working copy of JAVA for 6 months FAIL……
FAIL……FAIL……

My host file popped up as an issue somewhere,
Kaspersky says there should be one entry, I've got 11 pages of entries, can not edit with Notepad, Spybot appears to be involved.

Evidently I need a new driver from Intel for my motherboard, simple fix? guess again,
FAIL……FAIL……FAIL…… Their software glitches in the process & tells me to notify the administrator. snigger snigger, that's me.

Its not all bad, I got IE8 to work today, only took 4 hours to ferret out the old files & uninstall, and I was able to revive my printer function.

I also have a "Hijack This" Log If you think It would help


Your comments & suggestions will be greatly appreciated.

I realize now that I was supposed to post the entire copy of the OTL scan here goes:

OTL logfile created on: 7/25/2010 4:30:55 PM - Run 2
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Lee\My Documents\Desktop\Tools\OTL
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 248.00 Mb Available Physical Memory | 49.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 2500 2500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 22.46 Gb Free Space | 30.14% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LEE-153B35BBE54
Current User Name: Lee
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Documents and Settings\Lee\My Documents\Desktop\Tools\OTL\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Password Safe\pwsafe.exe (SourceForge.net)
PRC - C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe (Sierra Wireless Inc.)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Bunzilla\NetMeter\NetMeter.exe ()
PRC - C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions ™)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\HP DeskJet 710C Series\ereg\Remind32.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Lee\My Documents\Desktop\Tools\OTL\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SprintRcAppSvc) – C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe File not found
SRV - (NetTcpPortSharing) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe File not found
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe File not found
SRV - (idsvc) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe File not found
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe File not found
SRV - (ClipInc001) – C:\Program Files\Tobit ClipInc\Server\ClipInc-Server.exe File not found
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (a2free) – File not found
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
SRV - (spupdsvc) – C:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)


========== Driver Services (SafeList) ==========

DRV - (TDIMSYS) – C:\WINDOWS\System32\drivers\TDIMSYS.SYS File not found
DRV - (SWUMX20) Sierra Wireless USB MUX Driver (UMTS20) – C:\WINDOWS\System32\DRIVERS\swumx20.sys File not found
DRV - (SMSIVZAM5) – C:\PROGRA~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS File not found
DRV - (SMNDIS5) – C:\PROGRA~1\VERIZO~1\VERIZO~1\VERIZO~1\VZACCE~1\SMNDIS5.SYS File not found
DRV - (PTDMVsp) – C:\WINDOWS\System32\DRIVERS\PTDMVsp.sys File not found
DRV - (PTDMBus) – C:\WINDOWS\System32\DRIVERS\PTDMBus.sys File not found
DRV - (MEMSWEEP2) – C:\WINDOWS\System32\4.tmp File not found
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys File not found
DRV - (BW2NDIS5) – C:\WINDOWS\System32\Drivers\BW2NDIS5.sys File not found
DRV - (ADSFilter) ADSFilter - (Aluria Filter Driver) – C:\WINDOWS\System32\DRIVERS\ADSFilter.sys File not found
DRV - (NWUSBPort2) – C:\WINDOWS\system32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\WINDOWS\system32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\WINDOWS\system32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBCDFIL) – C:\WINDOWS\system32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (tcpipBM) – C:\WINDOWS\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (Nmea) – C:\WINDOWS\system32\drivers\pctnullport.sys (PCTEL Inc.)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (klbg) – C:\WINDOWS\system32\drivers\klbg.sys (Kaspersky Lab)
DRV - (klmouflt) – C:\WINDOWS\system32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (klim5) – C:\WINDOWS\system32\drivers\klim5.sys (Kaspersky Lab)
DRV - (swmsflt) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (kl1) – C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Lab)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (PTDUMdm) – C:\WINDOWS\system32\drivers\PTDUMdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (PTDUWWAN) – C:\WINDOWS\system32\drivers\PTDUWWAN.sys (DEVGURU Co., LTD.)
DRV - (PTDUBus) – C:\WINDOWS\system32\drivers\PTDUBus.sys (DEVGURU Co., LTD.)
DRV - (PTDUVsp) – C:\WINDOWS\system32\drivers\PTDUVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (PTDUWFLT) – C:\WINDOWS\system32\drivers\PTDUWFLT.sys (DEVGURU Co., LTD.)
DRV - (SWMX00) Sierra Wireless USB MUX Driver (#00) – C:\WINDOWS\system32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\WINDOWS\system32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (PCTINDIS5) – C:\WINDOWS\system32\PCTINDIS5.sys (Smith Micro Inc.)
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SWUMX80) Sierra Wireless USB MUX Driver (UMTS80) – C:\WINDOWS\system32\drivers\swumx80.sys (Sierra Wireless Inc.)
DRV - (SWNC8U80) Sierra Wireless MUX NDIS Driver (UMTS80) – C:\WINDOWS\system32\drivers\swnc8u80.sys (Sierra Wireless Inc.)
DRV - (KLFLTDEV) – C:\WINDOWS\system32\drivers\klfltdev.sys (Kaspersky Lab)
DRV - (NCHSSVAD) – C:\WINDOWS\system32\drivers\nchssvad.sys (NCH Swift Sound)
DRV - (PTDMWWAN) – C:\WINDOWS\system32\drivers\PTDMWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDMMdm) – C:\WINDOWS\system32\drivers\PTDMMdm.sys (DEVGURU Co,LTD.)
DRV - (SWNC8U12) Sierra Wireless MUX NDIS Driver (UMTS12) – C:\WINDOWS\system32\drivers\swnc8u12.sys (Sierra Wireless Inc.)
DRV - (swumx12) Sierra Wireless USB MUX Driver (UMTS12) – C:\WINDOWS\system32\drivers\swumx12.sys (Sierra Wireless Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (IntelS51) Intel® – C:\WINDOWS\system32\drivers\IntelS51.sys (Intel Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (cdudf_xp) – C:\WINDOWS\System32\drivers\Cdudf_xp.sys (Roxio)
DRV - (dvd_2K) – C:\WINDOWS\System32\drivers\dvd_2k.sys (Roxio)
DRV - (DVDVRRdr_xp) – C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys (Windows ® 2000 DDK provider)
DRV - (UDFReadr) – C:\WINDOWS\System32\drivers\Udfreadr.sys (Roxio)
DRV - (mmc_2K) – C:\WINDOWS\System32\drivers\mmc_2k.sys (Roxio)
DRV - (pwd_2k) – C:\WINDOWS\System32\drivers\Pwd_2k.sys (Roxio)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (NAL) – C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (HPFECP13) – C:\WINDOWS\System32\drivers\HPFECP13.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google.com (in English)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://my.msn.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {455D905A-D37C-4643-A9E2-F6FEFAA0424A}:0.8.13
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 5400
FF - prefs.js..network.proxy.no_proxies_on: "localho,t,127.0.0.1,127.0.0.1:5400,*update.microsoft.com,*windowsupdate.com
,download.microsoft.com,codecs.microsoft.com,activex.microsoft.com,liveupdate.sy
m
antecliveupdate.com,liveupdate.symantec.com,download.mcafee.com,*.phobos.apple.c
o
m,update.adobe.com,localhost"
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/23 18:25:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/23 18:25:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2010/06/28 15:40:47 | 000,000,000 | —D | M]

[2008/08/25 19:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Mozilla\Extensions
[2010/07/23 14:18:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\extensions
[2010/05/24 22:14:47 | 000,000,000 | —D | M] (PDF Download) – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2010/07/04 11:03:06 | 000,000,000 | —D | M] (RefControl) – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}
[2010/07/22 09:50:30 | 000,000,000 | —D | M] (Google Shortcuts) – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}
[2010/03/16 18:04:15 | 000,000,000 | —D | M] (googlebar) – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\extensions\{6b6601f1-361e-4b9f-bb6d-f8305000e4f6}
[2010/05/30 11:57:04 | 000,000,000 | —D | M] (PriceTrace Toolbar) – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\extensions\{72938f90-8d8a-11de-8a39-0800200c9a66}
[2010/07/22 09:50:34 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/05/30 09:46:25 | 000,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/07/04 11:56:14 | 000,005,002 | —- | M] () – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\searchplugins\alltheinternet.xml
[2010/03/15 17:40:12 | 000,002,073 | —- | M] () – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\searchplugins\dogpile.xml
[2010/03/15 17:45:41 | 000,002,035 | —- | M] () – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\searchplugins\google-translate-any–en.xml
[2010/07/06 21:01:23 | 000,005,475 | —- | M] () – C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\searchplugins\googlecom-in-english.xml
[2010/07/23 14:18:00 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/21 14:18:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/06/16 05:57:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/05/21 14:17:53 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/03/09 16:16:44 | 000,189,496 | —- | M] (Yahoo! Inc.) – C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll

O1 HOSTS File: ([2010/07/23 20:08:39 | 000,377,749 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 13043 more lines…
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Tools\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (OToolbarHelper Class) - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (PayPal Plug-In) - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [hpfsched] C:\WINDOWS\hpfsched.exe ()
O4 - HKLM..\Run: [TRUUpdater] C:\Program Files\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe (Sierra Wireless, Inc.)
O4 - HKLM..\Run: [WatcherHelper] C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe (Sierra Wireless Inc.)
O4 - HKCU..\Run: [C:\Program Files\Bunzilla\NetMeter\NetMeter.exe] C:\Program Files\Bunzilla\NetMeter\NetMeter.exe ()
O4 - HKCU..\Run: [FreeRAM XP] C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions ™)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Lee\Start Menu\Programs\Startup\Password Safe.lnk = C:\Program Files\Password Safe\pwsafe.exe (SourceForge.net)
O4 - Startup: C:\Documents and Settings\Lee\Start Menu\Programs\Startup\Reminder-hpc41001.lnk = C:\Program Files\HP DeskJet 710C Series\ereg\Remind32.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: &Windows; Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_21.dll (Oracle)
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - Reg Error: Key error. File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Virtual; keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Tools\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/Dcode/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab (Windows Live Safety Center Base Module)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} http://downloads.facilitiesmap.com/MapGuid…nt/mgaxctrl.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1266484308390 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1266520637671 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - Reg Error: Key error. File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - Reg Error: Key error. File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - Reg Error: Key error. File not found
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd.dll) - C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd.dll File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll) - C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\adialhk.dll) - C:\PROGRA~1\KASPER~1\KASPER~2\adialhk.dll File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll) - C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Documents and Settings\Lee\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lee\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/02/07 18:47:46 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{ef9e320a-4988-11df-baf3-7a8020000200}\Shell - "" = AutoRun
O33 - MountPoints2\{ef9e320a-4988-11df-baf3-7a8020000200}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ef9e320a-4988-11df-baf3-7a8020000200}\Shell\AutoRun\command - "" = F:\LiteAuto.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: LanmanServer - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)

========== Files/Folders - Created Within 30 Days ==========

[2010/07/25 16:09:35 | 000,000,000 | —D | C] – C:\Google
[2010/07/25 14:15:39 | 000,000,000 | —D | C] – C:\Program Files\Cool Iris
[2010/07/24 20:07:02 | 000,000,000 | —D | C] – C:\sqmndata
[2010/07/24 17:49:29 | 000,000,000 | —D | C] – C:\Intel
[2010/07/24 17:49:28 | 000,155,648 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxres.dll
[2010/07/24 00:45:48 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/07/23 00:16:44 | 000,000,000 | —D | C] – C:\Program Files\Sophos
[2010/07/22 11:29:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/07/22 11:29:38 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/22 11:02:02 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/07/22 10:43:51 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Lee\IECompatCache
[2010/07/21 23:18:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee\My Documents\My Safes
[2010/07/21 23:13:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee\Local Settings\Application Data\PasswordSafe
[2010/07/21 22:58:40 | 000,000,000 | —D | C] – C:\Program Files\Password Safe
[2010/07/19 17:03:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee\Application Data\Uniblue
[2010/07/18 16:15:17 | 000,000,000 | —D | C] – C:\Program Files\Sierra Wireless Inc
[2010/07/18 16:15:17 | 000,000,000 | —D | C] – C:\Program Files\Sierra Wireless
[2010/07/14 13:35:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee\Application Data\Media Player Classic
[2010/07/14 13:32:49 | 000,000,000 | —D | C] – C:\Program Files\Essentials Codec Pack
[2010/07/10 01:27:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee\Start Menu
[2010/07/09 01:48:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/07/09 00:07:35 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Lee\PrivacIE
[2010/07/08 15:30:24 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Lee\IETldCache
[2010/07/08 14:56:58 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2010/07/08 14:56:35 | 000,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2010/07/08 14:50:50 | 000,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2010/07/08 14:05:08 | 000,000,000 | —D | C] – C:\!KillBox
[2010/07/08 12:15:39 | 000,000,000 | —D | C] – C:\Program Files\Novatel Wireless
[2010/07/08 12:13:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2010/07/08 12:13:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2010/07/08 12:13:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2010/07/05 11:13:59 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Mozilla
[2010/07/05 11:13:58 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2010/07/02 13:06:56 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/07/02 13:06:54 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/06/29 21:57:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Adobe PDF
[2005/03/02 14:09:15 | 000,029,696 | —- | C] ( ) – C:\WINDOWS\System32\shllink.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/25 16:10:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/25 16:09:34 | 014,155,776 | —- | M] () – C:\Documents and Settings\Lee\ntuser.dat
[2010/07/25 16:09:17 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Lee\ntuser.ini
[2010/07/25 16:08:25 | 005,882,700 | -H– | M] () – C:\Documents and Settings\Lee\Local Settings\Application Data\IconCache.db
[2010/07/25 15:20:24 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2010/07/25 15:20:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/07/25 14:30:16 | 000,000,667 | —- | M] () – C:\Documents and Settings\Lee\My Documents\Desktop\IExplore.lnk
[2010/07/24 20:07:31 | 000,001,243 | -H– | M] () – C:\sqmnoopt19.sqm
[2010/07/24 08:15:43 | 000,000,815 | —- | M] () – C:\Documents and Settings\Lee\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/24 03:10:13 | 000,002,549 | —- | M] () – C:\WINDOWS\System32\spupdsvc.inf
[2010/07/24 02:37:35 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2010/07/24 02:37:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/07/24 00:53:26 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/07/24 00:44:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/07/24 00:44:06 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2010/07/24 00:14:15 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/24 00:01:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/07/24 00:01:01 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2010/07/23 23:23:18 | 000,531,566 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/23 23:23:18 | 000,448,098 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/23 23:23:18 | 000,074,592 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/23 23:21:33 | 000,000,600 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
[2010/07/23 20:24:20 | 000,098,168 | —- | M] () – C:\Documents and Settings\Lee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/23 20:08:39 | 000,377,749 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/07/23 15:33:59 | 000,000,475 | —- | M] () – C:\WINDOWS\HPFTBX13.INI
[2010/07/23 15:33:58 | 000,001,002 | —- | M] () – C:\WINDOWS\HPFCSS13.INI
[2010/07/23 15:11:36 | 000,000,869 | —- | M] () – C:\Documents and Settings\Lee\Start Menu\Programs\Startup\Reminder-hpc41001.lnk
[2010/07/23 15:09:53 | 000,000,197 | —- | M] () – C:\WINDOWS\hpfsched.ini
[2010/07/23 15:03:09 | 000,001,495 | —- | M] () – C:\Documents and Settings\Lee\My Documents\Desktop\Windows Explorer (2).lnk
[2010/07/22 10:48:48 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2010/07/22 10:48:47 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/07/22 10:44:53 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2010/07/22 10:44:52 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/07/21 23:12:27 | 000,000,723 | —- | M] () – C:\Documents and Settings\Lee\Start Menu\Programs\Startup\Password Safe.lnk
[2010/07/19 14:49:33 | 000,000,084 | —- | M] () – C:\WINDOWS\avrack.ini
[2010/07/19 14:49:29 | 000,000,169 | —- | M] () – C:\WINDOWS\RtlRack.ini
[2010/07/19 12:21:41 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/18 23:51:15 | 000,346,608 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/18 16:15:30 | 000,001,950 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Watcher.lnk
[2010/07/18 15:53:41 | 000,000,528 | —- | M] () – C:\WINDOWS\win.ini
[2010/07/18 15:53:41 | 000,000,227 | —- | M] () – C:\WINDOWS\SYSTEM.INI
[2010/07/18 15:53:41 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/07/14 13:33:34 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\Windows Codec Update Service.job
[2010/07/09 16:56:48 | 000,243,712 | —- | M] () – C:\Documents and Settings\Lee\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/09 12:03:43 | 000,000,011 | —- | M] () – C:\AuResult.ini
[2010/07/09 02:05:27 | 000,001,854 | —- | M] () – C:\Documents and Settings\Lee\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/07/08 14:20:32 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2010/07/08 14:20:30 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/07/07 12:47:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/07/07 12:47:12 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2010/07/07 03:35:38 | 000,000,610 | —- | M] () – C:\Documents and Settings\Lee\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/07/07 03:35:38 | 000,000,592 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/07/06 15:43:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/07/06 15:43:39 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2010/07/05 20:29:33 | 000,032,422 | —- | M] () – C:\Documents and Settings\Lee\My Documents\tumblr_l123tsMAxc1qbz0k5o1_500.jpg
[2010/07/05 12:24:23 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/05 11:29:38 | 000,001,495 | —- | M] () – C:\Documents and Settings\Lee\My Documents\Desktop\Windows Explorer.lnk
[2010/07/05 10:34:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/07/05 10:34:23 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2010/07/05 02:38:02 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/07/05 02:38:02 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2010/06/29 22:18:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/06/29 22:18:57 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2010/06/26 11:55:31 | 000,113,933 | —- | M] () – C:\WINDOWS\System32\drivers\klin.dat
[2010/06/26 11:55:29 | 000,097,549 | —- | M] () – C:\WINDOWS\System32\drivers\klick.dat
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/25 14:30:15 | 000,000,667 | —- | C] () – C:\Documents and Settings\Lee\My Documents\Desktop\IExplore.lnk
[2010/07/23 23:22:57 | 000,000,815 | —- | C] () – C:\Documents and Settings\Lee\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/23 15:11:35 | 000,000,869 | —- | C] () – C:\Documents and Settings\Lee\Start Menu\Programs\Startup\Reminder-hpc41001.lnk
[2010/07/23 15:03:09 | 000,001,495 | —- | C] () – C:\Documents and Settings\Lee\My Documents\Desktop\Windows Explorer (2).lnk
[2010/07/21 23:12:24 | 000,000,723 | —- | C] () – C:\Documents and Settings\Lee\Start Menu\Programs\Startup\Password Safe.lnk
[2010/07/19 14:49:32 | 000,000,084 | —- | C] () – C:\WINDOWS\avrack.ini
[2010/07/19 14:49:28 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2010/07/19 12:21:41 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/18 16:15:30 | 000,001,950 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Watcher.lnk
[2010/07/14 13:33:34 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\Windows Codec Update Service.job
[2010/07/09 12:03:43 | 000,000,011 | —- | C] () – C:\AuResult.ini
[2010/07/09 02:05:27 | 000,001,854 | —- | C] () – C:\Documents and Settings\Lee\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/07/08 15:12:46 | 000,002,549 | —- | C] () – C:\WINDOWS\System32\spupdsvc.inf
[2010/07/05 20:29:32 | 000,032,422 | —- | C] () – C:\Documents and Settings\Lee\My Documents\tumblr_l123tsMAxc1qbz0k5o1_500.jpg
[2008/09/16 15:18:32 | 000,028,288 | —- | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2008/03/03 12:51:35 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\dvmsg.dll
[2008/02/04 19:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/12/14 11:58:07 | 000,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2007/12/14 11:58:04 | 000,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2007/11/10 13:12:57 | 000,000,228 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/02/24 13:34:48 | 000,049,152 | —- | C] () – C:\WINDOWS\StiRegstEng.dll
[2007/02/24 13:33:04 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2007/02/24 13:28:37 | 000,000,044 | —- | C] () – C:\WINDOWS\PERF4490.ini
[2006/05/08 19:49:27 | 000,000,093 | —- | C] () – C:\WINDOWS\System32\EUSOFT.SYS
[2006/04/18 00:11:01 | 000,001,002 | —- | C] () – C:\WINDOWS\HPFCSS13.INI
[2006/04/09 00:20:57 | 000,000,475 | —- | C] () – C:\WINDOWS\HPFTBX13.INI
[2006/03/27 21:21:36 | 000,000,197 | —- | C] () – C:\WINDOWS\hpfsched.ini
[2006/03/11 13:41:09 | 000,000,019 | —- | C] () – C:\WINDOWS\WSURVEY.INI
[2006/01/14 12:54:33 | 000,000,488 | —- | C] () – C:\WINDOWS\Cmousecc.ini
[2006/01/12 21:34:23 | 000,000,034 | —- | C] () – C:\WINDOWS\AuthMgr.INI
[2005/12/12 20:08:42 | 000,000,104 | —- | C] () – C:\WINDOWS\ALBUM.INI
[2005/10/29 05:09:16 | 000,000,067 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/10/22 18:33:23 | 000,000,663 | —- | C] () – C:\WINDOWS\videoimp.ini
[2005/10/22 18:32:47 | 000,000,021 | —- | C] () – C:\WINDOWS\CS_setup.ini
[2005/06/06 20:01:55 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2005/06/06 19:58:14 | 000,000,000 | —- | C] () – C:\WINDOWS\CorelDrw.INI
[2005/06/06 19:57:54 | 000,000,848 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/04/10 13:40:07 | 000,000,258 | —- | C] () – C:\WINDOWS\System32\BDEMERGE.INI
[2005/04/02 15:51:36 | 000,000,544 | —- | C] () – C:\WINDOWS\ArtStudio.INI
[2005/03/29 22:48:37 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\5E6E1C4C69.sys
[2005/03/02 14:09:16 | 000,383,488 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2005/02/08 10:24:41 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/02/07 20:04:46 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2004/08/04 05:00:00 | 000,013,576 | —- | C] () – C:\WINDOWS\System32\syscorecfg256.dll
[2002/10/07 19:15:36 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2002/03/13 16:46:46 | 000,053,248 | R— | C] () – C:\WINDOWS\System32\zlib.dll
[1998/09/25 02:43:10 | 000,004,404 | —- | C] () – C:\WINDOWS\System32\HPFlnk13.ini
[1998/09/25 02:35:52 | 000,152,064 | —- | C] () – C:\WINDOWS\System32\HPFdat13.dll
[1998/09/25 02:33:44 | 000,181,248 | —- | C] () – C:\WINDOWS\System32\HPFscp13.dll
[1998/09/25 02:22:28 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\HPFhrl13.dll
[1998/09/25 02:22:26 | 000,271,360 | —- | C] () – C:\WINDOWS\System32\HPFsrl13.dll
[1998/09/25 02:22:20 | 000,297,472 | —- | C] () – C:\WINDOWS\System32\HPFmrl13.dll
[1998/09/25 02:22:14 | 001,080,320 | —- | C] () – C:\WINDOWS\System32\HPFtrl13.dll
[1998/09/25 02:17:48 | 000,194,048 | —- | C] () – C:\WINDOWS\System32\HPFcps13.dll
[1998/09/25 02:17:20 | 000,076,800 | —- | C] () – C:\WINDOWS\System32\HPF24r13.dll
[1998/09/25 02:16:06 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\HPFtst13.dll
[1998/09/25 02:08:42 | 000,395,264 | —- | C] () – C:\WINDOWS\System32\HPFui13.dll
[1998/09/25 02:03:08 | 000,187,904 | —- | C] () – C:\WINDOWS\System32\HPFwin13.dll
[1998/09/25 01:59:52 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\HPFmon13.dll
[1998/09/25 01:59:14 | 000,033,280 | —- | C] () – C:\WINDOWS\System32\HPFcbl13.dll
[1998/09/25 01:56:58 | 000,033,384 | —- | C] () – C:\WINDOWS\System32\HPFiop13.dll
[1998/09/25 01:56:46 | 000,069,284 | —- | C] () – C:\WINDOWS\System32\HPFpml13.dll
[1998/09/25 01:56:40 | 000,137,232 | —- | C] () – C:\WINDOWS\System32\HPFmlc13.dll
[1998/09/25 01:56:32 | 000,057,240 | —- | C] () – C:\WINDOWS\System32\HPFmem13.dll
[1998/09/25 01:56:28 | 000,048,292 | —- | C] () – C:\WINDOWS\System32\HPFlpm13.dll
[1998/09/25 01:56:16 | 000,072,368 | —- | C] () – C:\WINDOWS\System32\HPFcom13.dll
[1998/09/25 01:55:24 | 000,052,800 | —- | C] () – C:\WINDOWS\System32\drivers\HPFecp13.sys
[1998/09/25 01:54:34 | 000,029,184 | —- | C] () – C:\WINDOWS\System32\HPFrsu13.dll
[1998/09/25 01:54:04 | 000,117,760 | —- | C] () – C:\WINDOWS\System32\HPFrsa13.dll
[1998/09/25 01:49:34 | 001,777,664 | —- | C] () – C:\WINDOWS\System32\HPFimg13.dll
[1998/09/25 01:46:14 | 000,124,928 | —- | C] () – C:\WINDOWS\System32\HPFcnt13.dll
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2007/09/02 15:17:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2009/03/04 19:15:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2005/12/24 13:51:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GrayTech
[2010/04/16 15:08:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Novatel Wireless
[2008/10/28 22:06:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\sjgfojyt
[2010/07/18 14:54:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sprint
[2010/07/24 02:25:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/02/22 17:28:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2010/01/14 13:17:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEngineLite
[2008/10/29 21:35:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2010/02/10 03:05:56 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2010/04/19 14:57:03 | 000,000,000 | -HSD | M] – C:\Documents and Settings\Lee\Application Data\.#
[2007/01/30 19:15:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Alibre Design
[2008/08/20 18:17:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\AT&T;
[2008/08/20 18:13:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Bytemobile
[2009/05/01 15:53:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/06/13 00:06:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\com.zipeg
[2009/08/23 10:08:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Convivea
[2008/08/20 18:12:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\DBUpdater
[2006/01/12 21:29:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Earthlink
[2007/05/19 14:16:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\EPSON
[2005/12/24 13:51:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\GrayTech
[2009/09/14 17:21:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Image Zone Express
[2010/02/13 02:16:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\IObit
[2007/02/24 13:36:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Leadertech
[2009/08/22 10:13:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\MP3Rocket
[2010/02/27 12:47:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\MSNInstaller
[2005/10/22 18:34:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Nikon
[2009/09/09 13:04:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\NoteTab Light
[2008/11/18 19:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\OfficeUpdate12
[2005/02/26 13:31:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Opera
[2008/03/02 23:45:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Recordpad
[2010/07/18 16:31:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Sierra Wireless
[2007/12/18 09:49:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\SlipStream
[2006/04/24 21:23:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\SmartDraw
[2009/12/15 01:47:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Smith Micro
[2010/04/16 12:41:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Sprint
[2009/04/09 18:23:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Tobit
[2010/02/10 03:07:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\TuneUp Software
[2010/07/19 17:03:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\Uniblue
[2010/05/18 11:31:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\uTorrent
[2008/03/06 12:09:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\wootalyzer
[2008/02/21 17:57:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee\Application Data\XnView
[2010/07/14 13:33:34 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\Windows Codec Update Service.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 05:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/11/29 13:17:19 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/11/29 13:17:19 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 05:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/11/29 13:17:19 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/11/29 13:17:19 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 05:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 05:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 05:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 05:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 17:11:48 | 000,098,304 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\actxprxy.dll
[2008/04/13 17:11:50 | 000,029,184 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\batmeter.dll
[2008/04/13 10:03:24 | 000,063,488 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\browselc.dll
[2008/04/13 17:09:05 | 000,016,896 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\cfgmgr32.dll
[2008/04/13 17:11:51 | 000,163,840 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\credui.dll
[2008/04/13 17:11:51 | 000,025,088 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\davclnt.dll
[2004/08/04 05:00:00 | 000,847,872 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dbgeng.dll
[2008/04/13 17:11:51 | 000,640,000 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dbghelp.dll
[2008/04/13 17:11:52 | 000,026,112 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dot3api.dll
[2008/04/13 17:11:52 | 000,009,216 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dot3dlg.dll
[2008/04/13 17:11:52 | 000,014,336 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\drprov.dll
[2008/04/13 17:11:52 | 000,304,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\duser.dll
[2008/04/13 17:11:52 | 000,126,976 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\eappcfg.dll
[2008/04/13 17:11:52 | 000,040,960 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\eappprxy.dll
[2008/04/13 17:11:53 | 000,125,952 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\exts.dll
[2008/04/13 17:11:53 | 000,080,384 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\faultrep.dll
[2004/02/10 11:50:36 | 000,118,784 | —- | M] (Intel Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\hccutils.dll
[2004/02/10 11:50:26 | 000,143,360 | —- | M] (Intel Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\igfxdev.dll
[2004/02/10 11:55:08 | 000,225,280 | —- | M] (Intel Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\igfxpph.dll
[2004/02/10 11:50:42 | 000,155,648 | —- | M] (Intel Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\igfxres.dll
[2004/02/10 11:51:10 | 000,339,968 | —- | M] (Intel Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\igfxsrvc.dll
[2008/04/13 17:11:55 | 000,094,720 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\iphlpapi.dll
[2009/03/08 04:33:26 | 000,025,600 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\jsproxy.dll
[2008/04/13 17:11:57 | 000,586,240 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\mlang.dll
[2008/04/13 17:11:58 | 000,071,680 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msacm32.dll
[2008/04/13 17:11:59 | 000,997,376 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msgina.dll
[2008/04/13 17:11:59 | 002,843,136 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msi.dll
[2008/04/13 17:12:00 | 001,384,479 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msvbvm60.dll
[2008/04/13 17:12:01 | 000,413,696 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msvcp60.dll
[2008/04/13 17:12:01 | 000,011,776 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\netrap.dll
[2008/04/13 17:12:02 | 000,080,896 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\netui0.dll
[2008/04/13 17:12:02 | 000,245,760 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\netui1.dll
[2008/04/13 17:12:02 | 000,044,032 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\ntlanman.dll
[2004/08/04 05:00:00 | 000,036,864 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\ntsdexts.dll
[2008/04/13 17:12:02 | 000,249,856 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\odbc32.dll
[2008/04/13 10:26:05 | 000,094,208 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\odbcint.dll
[2008/04/13 17:12:02 | 000,144,384 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\onex.dll
[2006/10/18 22:47:18 | 000,284,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\PortableDeviceApi.dll
[2008/04/13 17:12:03 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\powrprof.dll
[2008/04/13 17:12:04 | 000,044,032 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\rtutils.dll
[2008/04/13 10:03:19 | 000,549,376 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\shdoclc.dll
[2008/04/13 17:12:05 | 000,068,096 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\shgina.dll
[2008/04/13 17:12:07 | 000,068,096 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\sti.dll
[2008/04/13 17:12:09 | 000,053,760 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\winsta.dll
[2007/10/27 18:40:30 | 000,222,720 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\wmasf.dll
[2010/04/06 04:52:46 | 002,462,720 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\WMVCore.dll
[2008/04/13 17:12:10 | 000,022,528 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\wsock32.dll
[2008/04/13 17:12:10 | 000,018,432 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\wtsapi32.dll
[2008/04/13 10:39:24 | 002,897,920 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\xpsp2res.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/02/07 10:26:47 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/02/07 10:26:47 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/02/07 10:26:47 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\svchost.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\ctfmon.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\alcupd.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\IPH.PH:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Lee\My Documents\mspaint.exe:SummaryInformation
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E965A533
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D2F2F703
< End of report >
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
CatByte, O.k. I got the download, on the desktop, ran the file. First glitch, program says Authentium Antivirus is still on, I can't find it any where, Not in Security Center, Not in C:, not in windows security folder, I've also searched for dvpapi.exe as I think this is associated, not in Services. This thing is buried somewhere. Tried to start in SAFEMODE, same result, program says Authentium Antivirus is still on. I've searched this and other forums nobody talks about this program. Any suggestions, I'm fairly certain that this is software that arrived with one of the service Paks, not sure though … they don't label the files other thatn a stupid numeric code. angst…angst… angst…angst…angst…angst…angst…angst…angst…angst…angst…angst… angst…angst…angst…angst…angst…angst…angst…angst…
CatByte, got frustrated trying to shut off Adventium Antivirus, ComboFix seemed to allow it to be running, and I did get a Log.file run. Let me know if you have a fix for Adventium, I hate having software running that I did'nt install & I can't find, or control. I'll certainly run the test again if we need to do this. Here's the log File.txt

ComboFix 10-07-30.01 - Lee 07/31/2010 1:34.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.114 [GMT -7:00]
Running from: c:\documents and settings\[removed]\My Documents\Desktop\ComboFix.exe
AV: Authentium Antivirus *On-access scanning enabled* (Updated) {A4E803B3-4E6E-4271-B1CD-56FBC0992D36}
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Authentium Firewall *enabled* {38254411-9AEC-4967-913E-F892C2A4DF89}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
ADS - svchost.exe: deleted 88 bytes in 2 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Lee\Application Data\.#
c:\documents and settings\Lee\My Documents\mspaint.exe
c:\documents and settings\snaffle\My Documents\spider.exe
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\Downloaded Program Files\Temp
c:\windows\system32\SHELLLNK.TLB
c:\windows\system32\tmp.reg

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-31 )))))))))))))))))))))))))))))))
.

2010-07-31 04:24 . 2010-07-31 04:24 98168 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-31 04:24 . 2010-07-31 04:24 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-07-30 15:10 . 2010-07-30 15:10 ——– d—–w- c:\documents and settings\snaffle\Application Data\Malwarebytes
2010-07-29 22:56 . 2010-07-29 22:59 ——– d—–w- c:\documents and settings\snaffle\IE Bookmarks 7-29-10
2010-07-29 21:35 . 2010-07-29 21:35 98168 —-a-w- c:\documents and settings\snaffle\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-29 21:03 . 2010-07-29 21:03 ——– d-sh–w- c:\documents and settings\snaffle\PrivacIE
2010-07-29 20:55 . 2010-07-29 21:08 ——– d—–w- c:\documents and settings\snaffle\Local Settings\Application Data\Google
2010-07-28 07:30 . 2010-07-28 07:43 ——– d—–w- c:\documents and settings\snaffle\Local Settings\Application Data\Apple Computer
2010-07-28 07:30 . 2010-07-28 07:30 ——– d—–w- c:\documents and settings\snaffle\Application Data\Apple Computer
2010-07-26 18:30 . 2010-07-26 18:31 ——– d—–w- c:\documents and settings\snaffle\Local Settings\Application Data\Adobe
2010-07-26 17:32 . 2010-07-26 17:32 ——– d—–w- c:\documents and settings\snaffle\Local Settings\Application Data\Mozilla
2010-07-26 00:12 . 2010-07-26 00:12 ——– d—–w- c:\documents and settings\snaffle\Application Data\Bytemobile
2010-07-26 00:11 . 2010-07-26 00:13 ——– d—–w- c:\documents and settings\snaffle\Application Data\Sierra Wireless
2010-07-25 23:09 . 2010-07-25 23:09 ——– d—–w- C:\Google
2010-07-25 21:15 . 2010-07-25 21:16 ——– d—–w- c:\program files\Cool Iris
2010-07-25 00:49 . 2010-07-25 00:49 ——– d—–w- C:\Intel
2010-07-25 00:49 . 2004-02-10 18:50 155648 —-a-w- c:\windows\system32\igfxres.dll
2010-07-24 15:33 . 2010-07-24 15:33 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-07-24 07:45 . 2010-07-24 10:10 ——– dc-h–w- c:\windows\ie8
2010-07-23 07:16 . 2010-07-23 07:16 ——– d—–w- c:\program files\Sophos
2010-07-22 18:29 . 2010-07-25 09:00 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-22 18:02 . 2010-07-24 06:27 ——– d—–w- c:\program files\Java
2010-07-22 17:43 . 2010-07-22 17:43 ——– d-sh–w- c:\documents and settings\Lee\IECompatCache
2010-07-22 06:13 . 2010-07-31 09:09 ——– d—–w- c:\documents and settings\Lee\Local Settings\Application Data\PasswordSafe
2010-07-22 05:58 . 2010-07-22 06:12 ——– d—–w- c:\program files\Password Safe
2010-07-20 00:03 . 2010-07-20 00:03 ——– d—–w- c:\documents and settings\Lee\Application Data\Uniblue
2010-07-18 23:15 . 2010-07-18 23:15 ——– d—–w- c:\program files\Sierra Wireless
2010-07-18 23:15 . 2010-07-18 23:15 ——– d—–w- c:\program files\Sierra Wireless Inc
2010-07-14 20:35 . 2010-07-14 20:37 ——– d—–w- c:\documents and settings\Lee\Application Data\Media Player Classic
2010-07-14 20:32 . 2010-07-14 20:33 ——– d—–w- c:\program files\Essentials Codec Pack
2010-07-10 08:22 . 2010-07-10 08:22 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-09 08:48 . 2010-07-09 08:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-07-09 07:07 . 2010-07-09 07:07 ——– d-sh–w- c:\documents and settings\Lee\PrivacIE
2010-07-08 23:16 . 2010-07-08 23:16 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-07-08 22:30 . 2010-07-08 22:30 ——– d-sh–w- c:\documents and settings\Lee\IETldCache
2010-07-08 21:56 . 2010-07-08 21:56 ——– d—–w- c:\program files\Microsoft
2010-07-08 21:56 . 2010-07-08 21:56 ——– d—–w- c:\program files\MSN Toolbar
2010-07-08 21:50 . 2010-07-08 22:14 ——– d–h–w- c:\windows\msdownld.tmp
2010-07-08 21:05 . 2010-07-22 17:21 ——– d—–w- C:\!KillBox
2010-07-08 19:15 . 2010-07-08 19:15 ——– d—–w- c:\program files\Novatel Wireless
2010-07-05 18:13 . 2010-07-05 18:13 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-31 09:09 . 2008-11-23 03:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-07-26 05:28 . 2005-02-14 05:05 ——– d—–w- c:\program files\Google
2010-07-26 00:10 . 2010-07-26 00:10 166912 —-a-r- c:\documents and settings\snaffle\Application Data\Microsoft\Installer\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}\places.exe
2010-07-25 03:00 . 2005-02-08 03:00 ——– d—–w- c:\program files\Intel
2010-07-24 17:57 . 2005-02-13 08:35 ——– d—–w- c:\program files\Tools
2010-07-24 09:25 . 2008-10-29 05:06 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-24 06:27 . 2010-05-21 21:18 ——– d—–w- c:\program files\Common Files\Java
2010-07-24 03:24 . 2005-02-11 05:09 98168 -c–a-w- c:\documents and settings\Lee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-23 22:04 . 2006-03-28 04:21 ——– d—–w- c:\program files\HP DeskJet 710C Series
2010-07-22 14:28 . 2008-10-31 03:07 ——– d—–w- c:\program files\Kaspersky Lab
2010-07-21 07:56 . 2009-03-04 01:52 ——– d—–w- c:\program files\Option
2010-07-21 07:36 . 2007-11-12 01:23 ——– d—–w- c:\program files\Games
2010-07-21 07:34 . 2008-03-07 07:32 ——– d—–w- c:\documents and settings\Lee\Application Data\ESTsoft
2010-07-21 07:33 . 2005-12-30 16:29 ——– d—–w- c:\program files\Drafting & Drawing
2010-07-20 19:55 . 2005-05-07 18:13 ——– d—–w- c:\program files\Media
2010-07-19 19:27 . 2005-04-02 08:55 ——– d—–w- c:\program files\QuickTime
2010-07-19 19:13 . 2005-02-08 02:59 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-19 19:13 . 2005-10-23 01:34 ——– d—–w- c:\program files\Nikon
2010-07-19 06:41 . 2010-06-14 07:23 ——– d—–w- c:\program files\Safari
2010-07-18 23:31 . 2008-08-21 01:19 ——– d—–w- c:\documents and settings\Lee\Application Data\Sierra Wireless
2010-07-18 22:37 . 2009-09-09 19:36 ——– d—–w- c:\program files\Winamp
2010-07-18 21:54 . 2010-04-16 23:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Sprint
2010-07-08 20:59 . 2008-03-07 19:16 ——– d—–w- c:\program files\Microsoft Works
2010-07-08 20:51 . 2005-05-19 16:32 ——– d—–w- c:\program files\My Music
2010-07-08 20:39 . 2008-11-24 03:30 ——– d—–w- c:\program files\Common Files\Apple
2010-07-07 10:35 . 2005-02-26 20:31 ——– d—–w- c:\program files\Opera
2010-06-26 18:55 . 2008-11-23 03:21 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-06-26 18:55 . 2008-11-23 03:21 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-06-23 18:02 . 2009-12-08 06:24 ——– d—–w- c:\program files\Config.Msi
2010-06-15 20:01 . 2010-06-15 20:01 133720 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-14 07:32 . 2010-06-14 07:32 79384 —ha-w- c:\windows\system32\mlfcache.dat
2010-06-14 07:23 . 2007-02-19 03:30 ——– d—–w- c:\documents and settings\Lee\Application Data\Apple Computer
2010-06-14 07:18 . 2010-05-21 21:00 ——– d—–w- c:\program files\Firefox
2010-06-14 06:55 . 2010-01-23 21:38 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-14 04:56 . 2008-03-07 19:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-08 23:48 . 2010-06-08 23:48 66880 —-a-w- c:\windows\system32\pxfhwmcp.dll
2010-06-08 23:35 . 2010-06-08 23:35 174720 —-a-w- c:\windows\system32\drivers\nwusbser2.sys
2010-06-08 23:35 . 2010-06-08 23:35 174720 —-a-w- c:\windows\system32\drivers\nwusbser.sys
2010-06-08 23:35 . 2010-06-08 23:35 174720 —-a-w- c:\windows\system32\drivers\nwusbmdm.sys
2010-06-08 23:35 . 2010-06-08 23:35 229376 —-a-w- c:\windows\system32\drivers\NWADIenum.sys
2010-06-08 23:35 . 2010-06-08 23:35 20480 —-a-w- c:\windows\system32\drivers\NwUsbCdFil.sys
2010-06-08 23:35 . 2010-06-08 23:35 724608 —-a-w- c:\windows\system32\bmutil.dll
2010-06-08 23:35 . 2010-06-08 23:35 480384 —-a-w- c:\windows\system32\bmnet.dll
2010-06-08 23:35 . 2010-06-08 23:35 24192 —-a-w- c:\windows\system32\drivers\tcpipBM.sys
2010-06-08 23:35 . 2010-06-08 23:35 13712 —-a-w- c:\windows\system32\sporder.dll
2010-06-08 23:35 . 2010-06-08 23:35 13184 —-a-w- c:\windows\system32\drivers\BMLoad.sys
2010-06-08 23:35 . 2010-06-08 23:35 132224 —-a-w- c:\windows\system32\bmdumpd.bin
2010-06-08 23:35 . 2010-06-08 23:35 38680 —-a-w- c:\windows\system32\drivers\pctnullport.sys
2010-06-04 19:29 . 2010-06-04 19:29 71992 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-05-28 01:47 . 2010-05-28 01:47 503808 —-a-w- c:\documents and settings\Lee\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-62d6f89e-n\msvcp71.dll
2010-05-28 01:47 . 2010-05-28 01:47 499712 —-a-w- c:\documents and settings\Lee\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-62d6f89e-n\jmc.dll
2010-05-28 01:47 . 2010-05-28 01:47 348160 —-a-w- c:\documents and settings\Lee\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-62d6f89e-n\msvcr71.dll
2010-05-28 01:47 . 2010-05-28 01:47 12800 —-a-w- c:\documents and settings\Lee\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2efc70e9-n\decora-d3d.dll
2010-05-28 01:47 . 2010-05-28 01:47 61440 —-a-w- c:\documents and settings\Lee\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2efc70e9-n\decora-sse.dll
2010-05-21 21:17 . 2010-04-20 04:51 411368 —-a-w- c:\windows\system32\deployJava1.dll
2006-12-03 19:37 . 2006-12-03 19:37 203 -c–a-w- c:\program files\Shortcut to CD Drive.lnk
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\opera\program\plugins\ssldivx.dll
2005-04-21 01:48 . 2005-03-30 05:48 56 -csh–r- c:\windows\system32\5E6E1C4C69.sys
2005-06-07 04:24 . 2005-06-07 02:57 848 -csha-w- c:\windows\system32\KGyGaAvL.sys
2009-12-08 21:27 . 2008-11-23 03:19 3612704 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-12-08 21:27 . 2008-11-23 03:19 958496 –sha-w- c:\windows\system32\drivers\fidbox2.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"c:\program files\Bunzilla\NetMeter\NetMeter.exe"="c:\program files\Bunzilla\NetMeter\NetMeter.exe" [2007-08-11 331264]
"FreeRAM XP"="c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 1591808]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-07-24 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-21 340456]
"TRUUpdater"="c:\program files\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe" [2009-04-13 554264]
"WatcherHelper"="c:\program files\Sierra Wireless Inc\Watcher\WaHelper.exe" [2009-11-11 53248]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"hpfsched"="c:\windows\hpfsched.exe" [1998-09-23 35328]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]

c:\documents and settings\Lee\Start Menu\Programs\Startup\
Password Safe.lnk - c:\program files\Password Safe\pwsafe.exe [2010-5-22 2539520]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^Lee^Start Menu^Programs^Startup^Reminder-hpc41001.lnk]
path=c:\documents and settings\Lee\Start Menu\Programs\Startup\Reminder-hpc41001.lnk
backup=c:\windows\pss\Reminder-hpc41001.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClipIncSrvTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Iusage
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RDVCHG
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sprint SmartView

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WRConsumerService"=2 (0x2)
"WebrootSpySweeperService"=2 (0x2)
"xmlprov"=3 (0x3)
"wuauserv"=2 (0x2)
"WMDM PMSP Service"=2 (0x2)
"VSS"=3 (0x3)
"usnjsvc"=3 (0x3)
"UPS"=3 (0x3)
"SwPrv"=3 (0x3)
"SPTISRV"=3 (0x3)
"seclogon"=3 (0x3)
"Schedule"=2 (0x2)
"SamSs"=2 (0x2)
"RSVP"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"hkmsvc"=3 (0x3)
"gusvc"=3 (0x3)
"MSCSPTISRV"=3 (0x3)
"Netman"=3 (0x3)
"LanmanWorkstation"=3 (0x3)
"PACSPTISVR"=3 (0x3)
"RasAuto"=2 (0x2)
"SprintRcAppSvc"=3 (0x3)
"SharedAccess"=2 (0x2)
"AVP"=2 (0x2)
"a2free"=2 (0x2)
"gupdate"=2 (0x2)
"AcrSch2Svc"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"SpybotSD TeaTimer"=c:\program files\tools\Spybot - Search & Destroy\TeaTimer.exe
"uTorrent"="c:\program files\Media\MP3 Rocket\U Torrent\uTorrent.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"IgfxTray"=c:\windows\system32\igfxtray.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Drafting & Drawing\\PC Draft\\PC Draft P.E.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe"=
"c:\\Program Files\\Media\\MP3 Rocket\\U Torrent\\uTorrent.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 2010\\avp.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\Installer\\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}\\_SHCT_Sprint.exe.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:*:Disabled:EarthLink UHP Modem Support
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"10857:TCP"= 10857:TCP:*:Disabled:Manual

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 7:29 PM 36880]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [3/13/2008 8:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [9/14/2009 1:42 PM 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [10/2/2009 7:39 PM 19472]
S2 HPFECP13;HPFECP13;c:\windows\system32\drivers\HPFecp13.sys [9/25/1998 1:55 AM 52800]
S3 ADSFilter;ADSFilter - (Aluria Filter Driver);c:\windows\system32\DRIVERS\ADSFilter.sys –> c:\windows\system32\DRIVERS\ADSFilter.sys [?]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\Drivers\BW2NDIS5.sys –> c:\windows\system32\Drivers\BW2NDIS5.sys [?]
S3 cpudrv;cpudrv;\??\c:\program files\SystemRequirementsLab\cpudrv.sys –> c:\program files\SystemRequirementsLab\cpudrv.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [12/13/2009 12:31 PM 38224]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\4.tmp –> c:\windows\system32\4.tmp [?]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [6/8/2010 4:35 PM 20480]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [6/8/2010 4:35 PM 174720]
S3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\DRIVERS\PTDMBus.sys –> c:\windows\system32\DRIVERS\PTDMBus.sys [?]
S3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\PTDMMdm.sys [6/23/2008 9:53 AM 41856]
S3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\DRIVERS\PTDMVsp.sys –> c:\windows\system32\DRIVERS\PTDMVsp.sys [?]
S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\drivers\PTDMWWAN.sys [6/23/2008 9:43 AM 59520]
S3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [11/1/2009 1:10 PM 54416]
S3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [11/1/2009 1:10 PM 160272]
S3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [11/1/2009 1:10 PM 160272]
S3 PTDUWFLT;PTDUWWAN Filter Driver;c:\windows\system32\drivers\PTDUWFLT.sys [11/1/2009 1:10 PM 11920]
S3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [11/1/2009 1:10 PM 113680]
S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;\??\c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS –> c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [?]
S3 SWNC8U12;Sierra Wireless MUX NDIS Driver (UMTS12);c:\windows\system32\drivers\swnc8u12.sys [3/26/2007 12:21 PM 82432]
S3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80);c:\windows\system32\drivers\swnc8u80.sys [8/20/2008 2:35 PM 168192]
S3 swumx12;Sierra Wireless USB MUX Driver (UMTS12);c:\windows\system32\drivers\swumx12.sys [3/26/2007 12:21 PM 66304]
S3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80);c:\windows\system32\drivers\swumx80.sys [8/20/2008 2:36 PM 142976]

— Other Services/Drivers In Memory —

*Deregistered* - BMLoad
.
Contents of the 'Scheduled Tasks' folder

2010-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-28 00:10]

2010-07-29 c:\windows\Tasks\User_Feed_Synchronization-{BCD8E78D-4DC0-4BD6-B80B-88EE84FA2B4F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]

2010-07-14 c:\windows\Tasks\Windows Codec Update Service.job
- c:\program files\Essentials Codec Pack\WECPUpdate.exe [2010-05-30 13:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.hotmail.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
IE: &Windows; Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
IE: Block frame with Ad Muncher - http://www.admuncher.com/request_will_be_i…d=menu_ie_frame
IE: Block image with Ad Muncher - http://www.admuncher.com/request_will_be_i…d=menu_ie_image
IE: Block link with Ad Muncher - http://www.admuncher.com/request_will_be_i…id=menu_ie_link
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_be_i…menu_ie_exclude
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_be_i…=menu_ie_report
LSP: bmnet.dll
TCP: {344585F3-6A51-49C8-AC75-177EAA28CEA6} = 68.28.50.91 68.28.58.92
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Lee\Application Data\Mozilla\Firefox\Profiles\8zlfk28q.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Dogpile
FF - prefs.js: browser.startup.homepage - hxxp://my.msn.com
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 5400
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\Lee\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\npjpi160_21.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\Opera\program\plugins\npdrmv2.dll

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-WRConsumerService
MSConfigStartUp-Load - d:\enu\ereg\16\remind.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-31 02:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\4.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2990282154-3897308282-1305558377-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-2990282154-3897308282-1305558377-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:3b,ff,23,08,ef,62,f5,31,7e,db,a5,36,2b,0d,ed,8d,67,ab,32,94,d8,89,33,
29,70,cf,24,4f,d4,8d,b8,67,f3,01,2b,4e,42,4b,7a,e8,c8,cc,ec,9c,11,f7,e5,cf,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(1444)
c:\windows\system32\relog_ap.dll
c:\windows\system32\bmnet.dll

- - - - - - - > 'explorer.exe'(1764)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-07-31 02:22:17 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-31 09:22

Pre-Run: 23,767,220,224 bytes free
Post-Run: 23,625,650,176 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 2E6AB1F50FC93134272D718B3A056EC5
Hi

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

SecCenter::
AV: Authentium Antivirus *On-access scanning enabled* (Updated) {A4E803B3-4E6E-4271-B1CD-56FBC0992D36}
FW: Authentium Firewall *enabled* {38254411-9AEC-4967-913E-F892C2A4DF89}

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
CatByte, what an ordeal, attempted to update malwareByte, it crashed & burned, needed to reload. Ran Eset, It stalled 3 times. but I got them done here's the reports Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4375 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 7/31/2010 1:55:55 PM mbam-log-2010-07-31 (13-55-55).txt Scan type: Quick scan Objects scanned: 153236 Time elapsed: 21 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hpfsched (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\hpfsched.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. C:\Documents and Settings\snaffle\Desktop\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully. ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=fc250927ffcf5a4fa06d08ee342ebf4c # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-07-31 10:12:04 # local_time=2010-07-31 03:12:04 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1281 16774489 100 0 0 0 19417727 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=168 # found=0 # cleaned=0 # scan_time=2137 esets_scanner_update returned -1 esets_gle=53251 # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=fc250927ffcf5a4fa06d08ee342ebf4c # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-07-31 10:46:33 # local_time=2010-07-31 03:46:33 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1281 16774505 100 0 0 0 19420158 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=168 # found=0 # cleaned=0 # scan_time=1759 esets_scanner_update returned -1 esets_gle=53251 # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=fc250927ffcf5a4fa06d08ee342ebf4c # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-08-01 01:35:17 # local_time=2010-07-31 06:35:17 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1281 16774570 100 0 0 0 19422859 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=129687 # found=6 # cleaned=0 # scan_time=9166 C:\Documents and Settings\Lee\My Documents\Desktop\Tools\Trojan Spy Fix\SmitfraudFix.zip multiple threats 00000000000000000000000000000000 I C:\Documents and Settings\Lee\My Documents\Desktop\Tools\Trojan Spy Fix\smitfraud\SmitfraudFix\Process.exe Win32/PrcView application 00000000000000000000000000000000 I C:\Documents and Settings\Lee\My Documents\Desktop\Tools\Trojan Spy Fix\smitfraud\SmitfraudFix\restart.exe Win32/Shutdown.NAA application 00000000000000000000000000000000 I C:\Documents and Settings\Lee\My Documents\Desktop\Tools\Trojan Spy Fix\SmitfraudFix\SmitfraudFix\Process.exe Win32/PrcView application 00000000000000000000000000000000 I C:\Documents and Settings\Lee\My Documents\Desktop\Tools\Trojan Spy Fix\SmitfraudFix\SmitfraudFix\restart.exe Win32/Shutdown.NAA application 00000000000000000000000000000000 I C:\Program Files\Tools\MP3 Rocket\MP3Rocket-Win-pro.exe a variant of Win32/AdInstaller application 00000000000000000000000000000000 I
Hi

Please do the following:


  • Hold down the Windows key and press R to open a run box
  • type the following text into the run box

    appwiz.cpl

  • Add or Remove Programs
  • A list of installed programs will populate
  • Remove the following program:

J2SE Runtime Environment 5.0 Update 2


NEXT


ESET is reporting this program is bundled with adware, I recommend removing it if you don't use it:

C:\Program Files\Tools\MP3 Rocket\MP3Rocket-Win-pro.exe a variant of Win32/AdInstaller application


NEXT


Please advise how your computer is running and if there are any outstanding issues:
CatByte, did not find "J2SE Runtime Environment 5.0 Update 2" in Add or Remove Programs, but did locate & delete after a search. Will this be enough of an erase? I also ran across "J2SE Runtime Environment 5.0 Update 1.msi C:\Documents and Settings\Lee\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150010} July 03, 2007. Seems to be a similar file, although newer, do we keep this one?
I'm curious, I try to keep all my Java downloads in a Java Folder in c:/programs, does the download & install process allow Java to spread files to any old destination java chooses. I've been trying to remove old Java when I update. It never goes easily, Add or Remove Programs, never seems to work fully to remove remnants.
I've also had this problem with getting java to function across all platforms, when I test in firefox it tells me there's a problem. The previous version of Firefox had a terrible issue with Java scripts looping forever (resolved now). To fix that I tried to remove every vestige of java & the load a clean fix but keep getting errors. The website hints that removing old downloads may or will resolve, then directs me to Add or Remove Programs. I delete the file & then still find remnants in the directory. I think the partial removal results in the weird disappearing function buttons. They are present on the screen but you cannot see them. You have to mouse around & watch for the arrow to cursor changes. This isn't all the buttons, just the ones you want to use. Java seems to work in IE but I still get weird error messages on the pages. I get a message in the lower left corner that says the page loaded but has errors.
Anyway, let me know if I should delete that other j2se file. The box seems improved, my memory isn't pegging quite so often, I'm still getting stalls though it's hard to tell if this is just me over doing it with multiple windows & functions going. Let me run it for awhile to get a feel for normal operating.
After all the scanning it doesn't seem that we did that much. With all my 3 am. tinkering I was worried that I might have a disaster to fix, jeese we removed one file? & that did it? amazing. Oh one last question, Kaspersky website says my ROOTKIT should have one entry. When I looked at it there are 8 pages of entries, & the file says they were put there by "SpyBot" Most of the entries are for sites I've never been to, what gives, do I delete or leave them be?? ……lee
I would remove all instances of Java on your computer

then manually re-install the latest update, choose to have java update automatically

allow Java to put the program where it wants to.

Use Revo Uninstaller to remove java

Download and install the Revo Uninstaller
  • Double click the new Revo Uninstaller icon on your desktop to start the program
  • Scroll through the listed programs and Right Click on the program you wish to uninstall (Java)
  • From the pop out menu choose Uninstall
  • Click Yes to the confirmation dialogue
  • In the next window select the Advanced mode
  • Click Next to start uninstalling the program
  • Answer Yes to confirm the uninstall
  • When the program has completed the four steps, click Next to allow the program to search for leftovers
  • Once complete, click Next, then Finish
  • Repeat the above steps for any other programs you wish to remove.


NEXT


download from here version 6 update 21

http://java.com/en/download/index.jsp


NEXT




Kaspersky website says my ROOTKIT should have one entry. When I looked at it there are 8 pages of entries, & the file says they were put there by "SpyBot" Most of the entries are for sites I've never been to, what gives, do I delete or leave them be?? ……lee


sorry - I'm not sure what you are referring to here?
Catbyte, Truly frustrated with this machine, Revo installer could not remove 2 older versions of java. I went through the process (4 times) and it would always come back telling me it needed an original .ini file to do removal process. After mucking about with this & "Windows Installer clean up" I got rid of all vestiges of the old versions. Then back to the JAVA site & downloaded, well you guessed it, same issue as previous. It either tells me that the program is already installed (oh sure) or it tells me the download failed & must terminate. Tried with Windows IE & Firefox. Both have similar issues. It was interesting that I got some extreme behavior problems during this process, one complete lockup for more than 20 mins, once all dumped & I got redirected to IE, JAVA Runtime kept trying to download in Firefox but would just loop to a pop up that asked if I wanted to download the latest version of JAVA (again) I now have the following in C:/Program files/java

jre1.6.0_20

jxpiinstall-rv.exe

jre-6u21-windows-i586-iftw-rv.exe

JavaSetup6u21-rv.exe


In Documents & settings/ Lee/Application Data/Sun File; I've got folders for jre 1.60 20, jre 1.60 21 a file marked AU 7 & one labeled Deployment.

All the files have today's date including jre1.6.0_20 which I know is the older version, & which I did not request a download for.!! Hence my befuddlement and perplexity. The machine is now acting normally without JAVA. I'm inclined to leave it be & go commando ( no java ) unless you think I need it & you have a next fix.
Of Note: The JAVA website eventually leads you to a page where they offer professional assistance for a $50.00/ hr fee, it's a perfect ploy, launch a peripheral that's helpful, smart & cheap. Let it go viral for a few years so everyone's using it, then install a glitch in the program that requires a $50.00/ hr fee to fix ….lee
Hi

I'm not the person to assist when it comes to resolving issues with Java but one of our techs is a complete whiz with it, so I'll send you off to him after we are done.

Right now I want to make sure there is no underlying cause,

please run the following:


Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.


NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
CatByte, For once every thing downloaded & ran without mishap. Here are the reports.

MBRCheck, version 1.2.3
© 2010, AD


Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003d

Kernel Drivers (total 137):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EE000 \WINDOWS\system32\hal.dll
0xF8D78000 \WINDOWS\system32\KDCOM.DLL
0xF8C88000 \WINDOWS\system32\BOOTVID.dll
0xF8829000 ACPI.sys
0xF8D7A000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF8818000 pci.sys
0xF8878000 isapnp.sys
0xF8E40000 pciide.sys
0xF8AF8000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF8D7C000 intelide.sys
0xF8888000 MountMgr.sys
0xF87F9000 ftdisk.sys
0xF8B00000 PartMgr.sys
0xF8898000 VolSnap.sys
0xF87E1000 atapi.sys
0xF88A8000 disk.sys
0xF88B8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF87C1000 fltmgr.sys
0xF87AF000 sr.sys
0xF88C8000 PxHelp20.sys
0xF8798000 KSecDD.sys
0xF8785000 WudfPf.sys
0xF86F8000 Ntfs.sys
0xF86CB000 NDIS.sys
0xF868E000 timntr.sys
0xF8676000 snapman.sys
0xF865C000 Mup.sys
0xF88D8000 klbg.sys
0xF8D7E000 BMLoad.sys
0xF89E8000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF7974000 \SystemRoot\system32\DRIVERS\ialmnt5.sys
0xF7960000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF8C58000 \SystemRoot\System32\drivers\swmsflt.sys
0xF8C60000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF793C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF89F8000 \SystemRoot\system32\DRIVERS\klfltdev.sys
0xF8C68000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF76E5000 \SystemRoot\system32\DRIVERS\IntelS51.sys
0xF76C2000 \SystemRoot\system32\DRIVERS\ks.sys
0xF8C70000 \SystemRoot\System32\Drivers\Modem.SYS
0xF769F000 \SystemRoot\system32\DRIVERS\e100b325.sys
0xF8C78000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF8A08000 \SystemRoot\system32\DRIVERS\serial.sys
0xF8614000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF768B000 \SystemRoot\system32\DRIVERS\parport.sys
0xF8A18000 \SystemRoot\System32\DRIVERS\i8042prt.sys
0xF8C80000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF8A28000 \SystemRoot\system32\DRIVERS\L8042pr2.Sys
0xF8A38000 \SystemRoot\system32\DRIVERS\LMouFlt2.Sys
0xF8A48000 \SystemRoot\system32\DRIVERS\klmouflt.sys
0xF8B20000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF8A58000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF8A68000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF8A78000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF766E000 \SystemRoot\System32\Drivers\pwd_2k.SYS
0xF7440000 \SystemRoot\system32\drivers\ALCXWDM.SYS
0xF741C000 \SystemRoot\system32\drivers\portcls.sys
0xF8A98000 \SystemRoot\system32\drivers\drmk.sys
0xF8AA8000 \SystemRoot\system32\DRIVERS\klim5.sys
0xF8EA2000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF8AB8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF8608000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF73ED000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF8AC8000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF8AD8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF8B28000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF73DC000 \SystemRoot\system32\DRIVERS\psched.sys
0xF8AE8000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF8B30000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF8B38000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF8B40000 \SystemRoot\system32\DRIVERS\pctnullport.sys
0xF8908000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF8DB2000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF737E000 \SystemRoot\system32\DRIVERS\update.sys
0xF85F0000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF7341000 \SystemRoot\system32\DRIVERS\NWADIenum.sys
0xF8B50000 \SystemRoot\System32\Drivers\mmc_2K.SYS
0xF8B68000 \SystemRoot\System32\Drivers\dvd_2K.SYS
0xF7CF1000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF7CB1000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF8DC8000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF8D58000 \SystemRoot\system32\drivers\MODEMCSA.sys
0xF8B90000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xEE818000 \SystemRoot\system32\DRIVERS\klif.sys
0xF8F24000 \SystemRoot\System32\Drivers\Cdr4_xp.SYS
0xF8F26000 \SystemRoot\System32\Drivers\Cdralw2k.SYS
0xF8DD4000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF8F27000 \SystemRoot\System32\Drivers\Null.SYS
0xF8DD6000 \SystemRoot\System32\Drivers\Beep.SYS
0xF8BA0000 \SystemRoot\System32\drivers\vga.sys
0xF8DD8000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF8DDA000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xEE7B1000 \SystemRoot\System32\Drivers\cdudf_xp.SYS
0xEE77C000 \SystemRoot\System32\Drivers\DVDVRRdr_xp.SYS
0xF8BA8000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF8BB0000 \SystemRoot\System32\Drivers\Npfs.SYS
0xEE710000 \SystemRoot\System32\Drivers\UDFReadr.SYS
0xF861C000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xEE1DE000 \??\C:\WINDOWS\system32\drivers\kl1.sys
0xEE1CB000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xEE14A000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF8BB8000 \SystemRoot\System32\Drivers\tcpipBM.SYS
0xEE122000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF7A33000 \SystemRoot\System32\drivers\ws2ifsl.sys
0xEE100000 \SystemRoot\System32\drivers\afd.sys
0xEE0D5000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xEE03D000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF8918000 \SystemRoot\System32\Drivers\Fips.SYS
0xEE017000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF8928000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xEF23B000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xEDDA0000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF8DE8000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xEE0CD000 \SystemRoot\System32\drivers\Dxapi.sys
0xF8C18000 \SystemRoot\System32\watchdog.sys
0xBF9C4000 \SystemRoot\System32\drivers\dxg.sys
0xF8F56000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF9E4000 \SystemRoot\System32\ialmdnt5.dll
0xBF9D6000 \SystemRoot\System32\ialmrnt5.dll
0xBFA03000 \SystemRoot\System32\ialmdev5.DLL
0xBFA22000 \SystemRoot\System32\ialmdd5.DLL
0xEDD9C000 \??\C:\WINDOWS\system32\drivers\mbam.sys
0xF8C20000 \SystemRoot\system32\DRIVERS\tifsfilt.sys
0xF8E18000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xF89D8000 \SystemRoot\system32\DRIVERS\secdrv.sys
0xED6D3000 \SystemRoot\system32\drivers\wdmaud.sys
0xEDE08000 \SystemRoot\system32\drivers\sysaudio.sys
0xED9F8000 \SystemRoot\system32\DRIVERS\ipfltdrv.sys
0xF8B58000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xED330000 \SystemRoot\system32\DRIVERS\swmx00.sys
0xF8B88000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xED2FE000 \SystemRoot\system32\DRIVERS\SWNC5E00.sys
0xED794000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0xECEC6000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 32):
0 System Idle Process
4 System
1248 C:\WINDOWS\system32\smss.exe
1360 csrss.exe
1388 C:\WINDOWS\system32\winlogon.exe
1464 C:\WINDOWS\system32\services.exe
1476 C:\WINDOWS\system32\lsass.exe
1668 C:\WINDOWS\system32\svchost.exe
1748 svchost.exe
1900 C:\WINDOWS\system32\svchost.exe
1972 C:\WINDOWS\system32\svchost.exe
316 C:\WINDOWS\system32\spoolsv.exe
368 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
420 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
692 C:\WINDOWS\system32\svchost.exe
2216 C:\WINDOWS\system32\wscntfy.exe
2504 C:\WINDOWS\explorer.exe
916 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
2056 C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe
1416 C:\WINDOWS\system32\igfxtray.exe
2252 C:\WINDOWS\system32\hkcmd.exe
2360 C:\Program Files\Common Files\Java\Java Update\jusched.exe
2440 C:\Program Files\Bunzilla\NetMeter\NetMeter.exe
2528 C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
2620 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
2920 C:\Program Files\Password Safe\pwsafe.exe
3004 C:\Program Files\Mozilla Firefox\firefox.exe
4068 C:\Program Files\Sierra Wireless Inc\Watcher\SwiApiMux.exe
3152 C:\WINDOWS\system32\wbem\unsecapp.exe
2700 wmiprvse.exe
2952 C:\Program Files\Sierra Wireless Inc\Watcher\Watcher.exe
3028 C:\Documents and Settings\Lee\My Documents\Desktop\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

PhysicalDrive0 Model Number: WDCWD800JB-00FMA0, Rev: 13.03G13

Size Device Name MBR Status
——————————————–
74 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-02 17:43:07
Windows 5.1.2600 Service Pack 3
Running: 8b88shnh.exe; Driver: C:\DOCUME~1\Lee\LOCALS~1\Temp\ufnirfod.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xEE83858C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xEE838E0C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xEE839922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xEE839E94]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xEE8390EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xEE837436]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xEE839D6C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xEE838192]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xEE839C28]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xEE83834E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xEE839FC6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xEE83BC08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xEE838AAA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xEE839CCA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDebugActiveProcess [0xEE83B5FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xEE8379FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xEE837D88]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xEE839576]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xEE83C5CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xEE837ECA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xEE837F74]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xEE839382]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xEE83B68C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xEE837412]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xEE837424]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwMapViewOfSection [0xEE83BCBC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xEE8380C0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xEE839F36]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xEE838E8E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xEE8375DC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xEE839E04]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xEE838792]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xEE83BC32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xEE83A068]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xEE8386B6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xEE83801E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xEE837C46]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQuerySection [0xEE83BFD4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xEE837896]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xEE83B922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xEE837B0E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xEE8372B0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xEE83A3F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xEE83A2B8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xEE83B39A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xEE83EE2C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xEE83C4AC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xEE837248]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xEE83965C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xEE838CC8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xEE83AC4A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xEE83B786]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xEE83C114]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xEE83771E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xEE83C1F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xEE83C320]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xEE83B526]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xEE83890A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xEE838860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0xEE83BE8A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xEE8389EA]

Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!_abnormal_termination + 114 804E2780 16 Bytes [4E, 83, 83, EE, C6, 9F, 83, …] {DEC ESI; ADD DWORD [EBX-0x7c603912], -0x12; OR [EBX+EAX*4-0x7c755512], BH; OUT DX, AL }
.text ntoskrnl.exe!_abnormal_termination + 12C 804E2798 5 Bytes [CA, 9C, 83, EE, FA] {RETF 0x839c; OUT DX, AL ; CLI }
.text ntoskrnl.exe!_abnormal_termination + 132 804E279E 2 Bytes [83, EE]
.text ntoskrnl.exe!_abnormal_termination + 1D0 804E283C 12 Bytes [8C, B6, 83, EE, 12, 74, 83, …]
.text ntoskrnl.exe!_abnormal_termination + 34C 804E29B8 16 Bytes [0E, 7B, 83, EE, B0, 72, 83, …]
.text …
.text ntoskrnl.exe!IoIsOperationSynchronous 804E876A 5 Bytes JMP EE82D8B6 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
.text ntoskrnl.exe!FsRtlCheckLockForReadAccess 80512939 5 Bytes JMP EE82D4DC \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[3004] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

—- EOF - GMER 1.0.15 —-
CatByte, I'm afraid to type it but I think you're right, running O.K.. That last scan took 4+ hours, I don't want to repeat that process. I'm still getting weird stalls in Firefox but I think it's a combo of program quirks, too little RAM & me opening too many windows then running apps on top. I was just cruising E-Bay looking at used computers that are 4 times as powerful as this thing for about $250. But I think I'll save the planetary resources & keep using this one, at least until they end support of XP or until I crash it again. Even Jesus only had one resurrection. Thanks much for all your kind effort, I'll be passing it on tomorrow, some friends are looking to buy an older building in town. I'm an ex builder, inspector & tinker extraordinaire. So I'll inspect & weigh in on whether it's a deal or a bust, plus I''l drop some loot in the kitty to keep your thing floatin…. next time I meet a cat I'll be sure to leave it purring. ………….lee

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI