This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need help getting rid of Security Master AV remnants

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First, here's the mbam log (in blue) I told you about from last night. As you can see i let it clean the items in restore, but unchecked the combo-fix.sys thinking it might be a false positive. Following the mbam log is the new combofix log (in brown) from this evening. A note on the combofix log: it reports avg and comodo enabled for the run; the avg you know about, and i exited the comodo firewall before doing the combofix run.

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4442

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

8/17/2010 10:00:36 PM
mbam-log-2010-08-17 (22-00-36).txt

Scan type: Full scan (C:\|)
Objects scanned: 175378
Time elapsed: 31 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\ComboFix\Combo-Fix.sys (Trojan.Agent.Gen) -> Not selected for removal.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP227\A0023862.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP229\A0024099.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP229\A0024150.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP229\A0024248.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.



ComboFix 10-08-17.04 - Tom Spencer 08/18/2010 18:17:09.7.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.685 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\documents and settings\All Users\Application Data\SMBIRMCAV
c:\documents and settings\All Users\Application Data\SMBIRMCAV\SMYPAV.cfg

.
((((((((((((((((((((((((( Files Created from 2010-07-18 to 2010-08-18 )))))))))))))))))))))))))))))))
.

2010-08-16 23:30 . 2010-08-16 23:30 ——– d—–w- c:\program files\Java
2010-08-15 19:54 . 2010-08-15 19:54 ——– d—–w- c:\program files\Common Files\Java
2010-08-09 19:00 . 2010-08-09 19:00 61440 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-44d523b0-n\decora-sse.dll
2010-08-09 19:00 . 2010-08-09 19:00 503808 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-583aa9bc-n\msvcp71.dll
2010-08-09 19:00 . 2010-08-09 19:00 499712 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-583aa9bc-n\jmc.dll
2010-08-09 19:00 . 2010-08-09 19:00 348160 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-583aa9bc-n\msvcr71.dll
2010-08-08 22:44 . 2010-08-08 22:44 ——– d—–w- c:\documents and settings\Coby
2010-08-08 22:44 . 2010-04-07 22:59 ——– d—–w- c:\documents and settings\Coby\Local Settings\Application Data\Google
2010-08-08 22:35 . 2010-08-18 00:50 0 —-a-w- c:\documents and settings\Tom Spencer\Local Settings\Application Data\prvlcl.dat
2010-08-08 17:23 . 2010-08-08 17:23 388096 —-a-r- c:\documents and settings\Tom Spencer\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-08 15:30 . 2010-08-08 15:30 ——– d—–w- c:\documents and settings\All Users\Application Data\COMODO
2010-08-08 15:29 . 2010-08-08 15:29 ——– d—–w- c:\program files\COMODO
2010-08-08 15:27 . 2010-08-08 15:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo Downloader
2010-08-08 14:40 . 2010-08-18 22:16 ——– d—–w- c:\program files\Everything
2010-08-08 14:16 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2010-08-08 01:09 . 2010-08-16 22:37 63488 —-a-w- c:\documents and settings\Tom Spencer\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-08 01:09 . 2010-08-08 01:09 52224 —-a-w- c:\documents and settings\Tom Spencer\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-08-07 22:08 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-07 22:08 . 2010-08-07 23:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-07 22:08 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-07 22:02 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2010-08-07 22:02 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\hidserv.dll
2010-08-07 21:59 . 2010-08-07 21:59 ——– d—–w- c:\windows\system32\wbem\Repository
2010-08-02 21:35 . 2010-08-02 21:35 61440 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-13a0aad3-n\decora-sse.dll
2010-08-02 21:35 . 2010-08-02 21:35 503808 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-740df2f0-n\msvcp71.dll
2010-08-02 21:35 . 2010-08-02 21:35 499712 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-740df2f0-n\jmc.dll
2010-08-02 21:35 . 2010-08-02 21:35 348160 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-740df2f0-n\msvcr71.dll
2010-08-02 21:35 . 2010-08-02 21:35 12800 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-13a0aad3-n\decora-d3d.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 23:30 . 2010-06-13 20:51 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-16 22:37 . 2009-10-29 23:32 117760 —-a-w- c:\documents and settings\Tom Spencer\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-09 19:00 . 2010-08-09 19:00 12800 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-44d523b0-n\decora-d3d.dll
2010-08-08 14:16 . 2010-08-08 14:16 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-08-08 14:16 . 2010-08-08 14:16 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-08-08 14:04 . 2008-12-10 19:40 ——– d—–w- c:\program files\Trend Micro
2010-08-08 03:26 . 2008-11-25 15:40 ——– d—–w- c:\program files\Defraggler
2010-08-08 00:23 . 2008-11-25 15:38 ——– d—–w- c:\program files\CCleaner
2010-07-27 23:15 . 2008-11-25 16:02 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-06-30 12:31 . 2004-08-04 10:00 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:15 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-06-23 13:44 . 2004-08-04 10:00 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-04 10:00 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-08-04 10:00 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2008-08-02 18:19 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2004-08-04 10:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
2010-06-14 00:48 . 2008-08-02 18:57 13104 —-a-w- c:\documents and settings\Tom Spencer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-04 15:55 . 2010-06-04 15:55 229312 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-06-01 23:00 . 2010-06-01 23:00 278288 —-a-w- c:\windows\system32\guard32.dll
2010-06-01 23:00 . 2010-06-01 23:00 87824 —-a-w- c:\windows\system32\drivers\inspect.sys
2010-06-01 23:00 . 2010-06-01 23:00 25240 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-06-01 23:00 . 2010-06-01 23:00 15464 —-a-w- c:\windows\system32\drivers\cmderd.sys
2010-05-26 22:18 . 2010-05-26 22:18 503808 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-426a6f5d-n\msvcp71.dll
2010-05-26 22:18 . 2010-05-26 22:18 499712 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-426a6f5d-n\jmc.dll
2010-05-26 22:18 . 2010-05-26 22:18 348160 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-426a6f5d-n\msvcr71.dll
2010-05-26 22:18 . 2010-05-26 22:18 61440 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2579a0a2-n\decora-sse.dll
2010-05-26 22:18 . 2010-05-26 22:18 12800 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2579a0a2-n\decora-d3d.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-08-15_16.53.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-18 22:05 . 2010-08-18 22:05 16384 c:\windows\temp\Perflib_Perfdata_7dc.dat
+ 2004-08-04 10:00 . 2008-04-14 00:12 30749 c:\windows\system32\dllcache\vbajet32.dll
+ 2007-04-02 16:36 . 2007-04-02 16:36 16384 c:\windows\system32\dllcache\tcptsat.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 32827 c:\windows\system32\dllcache\tcptest.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 25088 c:\windows\system32\dllcache\slayerxp.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 16437 c:\windows\system32\dllcache\shtml.exe
+ 2008-04-14 00:12 . 2008-04-14 00:12 20536 c:\windows\system32\dllcache\shtml.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 65024 c:\windows\system32\dllcache\shimeng.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 77312 c:\windows\system32\dllcache\sdbinst.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 64000 c:\windows\system32\dllcache\samlib.dll
+ 2010-08-18 03:02 . 2001-08-17 18:56 66048 c:\windows\system32\dllcache\s3legacy.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 84992 c:\windows\system32\dllcache\olepro32.dll
+ 2008-08-02 18:19 . 2008-04-14 00:12 65536 c:\windows\system32\dllcache\oledb32r.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20511 c:\windows\system32\dllcache\odtext32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20510 c:\windows\system32\dllcache\odpdx32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20510 c:\windows\system32\dllcache\odfox32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20510 c:\windows\system32\dllcache\odexl32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20511 c:\windows\system32\dllcache\oddbse32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:10 53279 c:\windows\system32\dllcache\odbcji32.dll
+ 2004-08-04 10:00 . 2008-04-13 17:26 94208 c:\windows\system32\dllcache\odbcint.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 65536 c:\windows\system32\dllcache\odbccu32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 65536 c:\windows\system32\dllcache\odbccr32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 69632 c:\windows\system32\dllcache\odbcconf.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 32768 c:\windows\system32\dllcache\odbcad32.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 16384 c:\windows\system32\dllcache\odbc32gt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 67584 c:\windows\system32\dllcache\ocmanage.dll
+ 2004-08-04 10:00 . 2008-04-13 19:20 91520 c:\windows\system32\dllcache\ndiswan.sys
+ 2008-08-02 18:18 . 2008-04-14 00:12 24576 c:\windows\system32\dllcache\msxactps.dll
+ 2004-08-04 10:00 . 2008-04-13 18:30 61440 c:\windows\system32\dllcache\msvcrt40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:49 60192 c:\windows\system32\dllcache\msjter40.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 36864 c:\windows\system32\dllcache\msdfmap.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 20480 c:\windows\system32\dllcache\msdatt.dll
+ 2008-08-02 18:18 . 2008-04-13 17:26 16384 c:\windows\system32\dllcache\msdasqlr.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msdaremr.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msdaprsr.dll
+ 2008-08-02 18:19 . 2008-04-14 00:11 77824 c:\windows\system32\dllcache\msdaosp.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 36864 c:\windows\system32\dllcache\mscpxl32.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 57344 c:\windows\system32\dllcache\msadrh15.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 57344 c:\windows\system32\dllcache\msador15.dll
+ 2008-08-02 18:18 . 2008-04-13 17:26 24576 c:\windows\system32\dllcache\msader15.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 24576 c:\windows\system32\dllcache\msaddsr.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 53248 c:\windows\system32\dllcache\msadcs.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msadcor.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msadcfr.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 61440 c:\windows\system32\dllcache\msadcf.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 20480 c:\windows\system32\dllcache\msadcer.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 22528 c:\windows\system32\dllcache\mfcsubs.dll
+ 2004-08-04 10:00 . 2010-06-24 12:15 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-08-13 22:54 . 2010-06-24 12:15 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-04 10:00 . 2008-04-13 19:19 75264 c:\windows\system32\dllcache\ipsec.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 36921 c:\windows\system32\dllcache\imeshare.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 20538 c:\windows\system32\dllcache\fpremadm.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 20541 c:\windows\system32\dllcache\fpexedll.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 15120 c:\windows\system32\dllcache\fp98sadm.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 49212 c:\windows\system32\dllcache\fp4awebs.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 32826 c:\windows\system32\dllcache\fp4avss.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 41020 c:\windows\system32\dllcache\fp4avnb.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 49210 c:\windows\system32\dllcache\fp4areg.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 82035 c:\windows\system32\dllcache\fp4anscp.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 16384 c:\windows\system32\dllcache\ds32gt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 32768 c:\windows\system32\dllcache\dispex.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 39936 c:\windows\system32\dllcache\dimsroam.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 19456 c:\windows\system32\dllcache\dimsntfy.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 62464 c:\windows\system32\dllcache\cryptsvc.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 64512 c:\windows\system32\dllcache\cryptnet.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 53760 c:\windows\system32\dllcache\cryptext.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 33280 c:\windows\system32\dllcache\cryptdll.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 74752 c:\windows\system32\dllcache\cryptdlg.dll
+ 2004-08-04 10:00 . 2008-04-14 00:09 16896 c:\windows\system32\dllcache\cfgmgr32.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 16439 c:\windows\system32\dllcache\author.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 20540 c:\windows\system32\dllcache\author.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 30208 c:\windows\system32\dllcache\atmlib.dll
- 2010-03-05 14:37 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2004-08-04 10:00 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 98304 c:\windows\system32\dllcache\ahui.exe
+ 2004-08-04 10:00 . 2008-04-14 00:11 68096 c:\windows\system32\dllcache\adsmsext.dll
+ 2010-08-18 03:02 . 2001-08-17 16:11 46112 c:\windows\system32\dllcache\adptsf50.sys
- 2007-08-13 22:39 . 2007-08-13 22:39 71680 c:\windows\system32\dllcache\admparse.dll
+ 2004-08-04 10:00 . 2007-08-13 22:39 71680 c:\windows\system32\dllcache\admparse.dll
+ 2010-08-18 03:02 . 2004-08-04 02:32 10880 c:\windows\system32\dllcache\admjoy.sys
+ 2008-04-14 00:12 . 2008-04-14 00:12 16439 c:\windows\system32\dllcache\admin.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 20540 c:\windows\system32\dllcache\admin.dll
+ 2010-08-18 03:02 . 2001-08-17 16:11 20160 c:\windows\system32\dllcache\adm8511.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 98304 c:\windows\system32\dllcache\actxprxy.dll
+ 2004-08-04 10:00 . 2004-08-04 10:00 11648 c:\windows\system32\dllcache\acpiec.sys
+ 2010-08-18 03:02 . 2001-08-18 02:36 61440 c:\windows\system32\dllcache\acerscad.dll
+ 2010-08-18 03:02 . 2004-08-04 02:32 84480 c:\windows\system32\dllcache\ac97via.sys
+ 2010-08-18 03:02 . 2001-08-17 16:20 96256 c:\windows\system32\dllcache\ac97intc.sys
+ 2010-08-18 03:02 . 2001-08-17 17:52 23552 c:\windows\system32\dllcache\abp480n5.sys
+ 2010-08-18 03:02 . 2001-08-18 02:36 98304 c:\windows\system32\dllcache\a3d.dll
+ 2010-08-18 03:02 . 2001-08-17 18:55 38400 c:\windows\system32\dllcache\8514a.dll
+ 2010-08-18 03:02 . 2008-04-13 18:46 48128 c:\windows\system32\dllcache\61883.sys
+ 2010-08-18 03:02 . 2008-04-13 18:40 12288 c:\windows\system32\dllcache\4mmdat.sys
+ 2010-08-18 03:02 . 2001-08-17 18:06 11264 c:\windows\system32\dllcache\1394vdbg.sys
+ 2010-08-18 03:02 . 2008-04-13 18:46 53376 c:\windows\system32\dllcache\1394bus.sys
+ 2004-08-04 10:00 . 2008-04-14 00:12 5120 c:\windows\system32\dllcache\sfc.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdaurl.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdasc.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdaer.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdaenum.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdadc.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdpash.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdnepr.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdiultn.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdbhc.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 7168 c:\windows\system32\dllcache\bitsprx4.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3775 c:\windows\system32\dllcache\adv11nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3711 c:\windows\system32\dllcache\adv09nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3135 c:\windows\system32\dllcache\adv08nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3647 c:\windows\system32\dllcache\adv07nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3615 c:\windows\system32\dllcache\adv05nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3967 c:\windows\system32\dllcache\adv02nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 4255 c:\windows\system32\dllcache\adv01nt5.dll
+ 2010-08-18 03:02 . 2001-08-17 17:53 7424 c:\windows\system32\dllcache\adicvls.sys
+ 2004-08-04 10:00 . 2008-04-14 00:12 4096 c:\windows\system32\dllcache\actmovie.exe
- 2010-06-13 20:51 . 2010-04-12 21:29 153376 c:\windows\system32\javaws.exe
+ 2010-08-16 23:30 . 2010-08-16 23:30 153376 c:\windows\system32\javaws.exe
- 2010-06-13 20:51 . 2010-04-12 21:29 145184 c:\windows\system32\javaw.exe
+ 2010-08-16 23:30 . 2010-08-16 23:30 145184 c:\windows\system32\javaw.exe
+ 2010-08-16 23:30 . 2010-08-16 23:30 145184 c:\windows\system32\java.exe
- 2010-06-13 20:51 . 2010-04-12 21:29 145184 c:\windows\system32\java.exe
+ 2004-08-04 10:00 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
- 2009-12-24 06:59 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 507904 c:\windows\system32\dllcache\winlogon.exe
+ 2006-03-04 03:33 . 2010-06-24 12:15 832512 c:\windows\system32\dllcache\wininet.dll
- 2007-08-13 22:54 . 2010-06-24 12:15 832512 c:\windows\system32\dllcache\wininet.dll
- 2007-08-13 22:54 . 2010-03-09 11:09 430080 c:\windows\system32\dllcache\vbscript.dll
+ 2004-08-04 10:00 . 2010-03-09 11:09 430080 c:\windows\system32\dllcache\vbscript.dll
- 2007-08-13 22:44 . 2010-06-24 12:15 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-04 10:00 . 2010-06-24 12:15 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 123392 c:\windows\system32\dllcache\umpnpmgr.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 106496 c:\windows\system32\dllcache\sysocmgr.exe
+ 2004-08-04 10:00 . 2008-04-14 09:42 985088 c:\windows\system32\dllcache\setupapi.dll
+ 2004-08-04 10:00 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
- 2008-05-09 10:53 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
+ 2004-08-04 10:00 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
- 2008-05-09 10:53 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
+ 2004-08-04 10:00 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
- 2008-12-05 06:54 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 415744 c:\windows\system32\dllcache\samsrv.dll
+ 2004-08-04 10:00 . 2008-04-13 17:37 208384 c:\windows\system32\dllcache\rsaenh.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 433664 c:\windows\system32\dllcache\riched20.dll
+ 2008-08-02 18:19 . 2008-04-14 00:12 487424 c:\windows\system32\dllcache\oledb32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 551936 c:\windows\system32\dllcache\oleaut32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 147456 c:\windows\system32\dllcache\odbctrac.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 278559 c:\windows\system32\dllcache\odbcjt32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 106496 c:\windows\system32\dllcache\odbccp32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 135168 c:\windows\system32\dllcache\odbcconf.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 249856 c:\windows\system32\dllcache\odbc32.dll
+ 2004-08-04 10:00 . 2008-04-13 19:15 574976 c:\windows\system32\dllcache\ntfs.sys
- 2009-04-14 19:32 . 2009-02-09 12:10 714752 c:\windows\system32\dllcache\ntdll.dll
+ 2004-08-04 10:00 . 2009-02-09 12:10 714752 c:\windows\system32\dllcache\ntdll.dll
+ 2004-08-04 10:00 . 2008-10-15 16:34 337408 c:\windows\system32\dllcache\netapi32.dll
- 2008-10-23 22:32 . 2008-10-15 16:34 337408 c:\windows\system32\dllcache\netapi32.dll
+ 2004-08-04 10:00 . 2007-04-02 12:52 355104 c:\windows\system32\dllcache\msxbde40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 621344 c:\windows\system32\dllcache\mswstr10.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 838432 c:\windows\system32\dllcache\mswdat10.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 343040 c:\windows\system32\dllcache\msvcrt.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 264992 c:\windows\system32\dllcache\mstext40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 559904 c:\windows\system32\dllcache\msrepl40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:50 322336 c:\windows\system32\dllcache\msrd3x40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:50 432928 c:\windows\system32\dllcache\msrd2x40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:50 355104 c:\windows\system32\dllcache\mspbde40.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 143360 c:\windows\system32\dllcache\msorcl32.dll
+ 2004-08-04 10:00 . 2007-04-02 12:49 219936 c:\windows\system32\dllcache\msltus40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:49 248608 c:\windows\system32\dllcache\msjtes40.dll
+ 2008-08-02 18:18 . 2008-04-14 00:12 102400 c:\windows\system32\dllcache\msjro.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 151583 c:\windows\system32\dllcache\msjint40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:47 326432 c:\windows\system32\dllcache\msexcl40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:47 518944 c:\windows\system32\dllcache\msexch40.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 315392 c:\windows\system32\dllcache\msdasql.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 118784 c:\windows\system32\dllcache\msdarem.dll
+ 2008-08-02 18:19 . 2008-04-14 00:11 204800 c:\windows\system32\dllcache\msdaps.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 200704 c:\windows\system32\dllcache\msdaprst.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 233472 c:\windows\system32\dllcache\msdaora.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 200704 c:\windows\system32\dllcache\msadox.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 180224 c:\windows\system32\dllcache\msadomd.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 536576 c:\windows\system32\dllcache\msado15.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 155648 c:\windows\system32\dllcache\msadds.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 143360 c:\windows\system32\dllcache\msadco.dll
- 2008-08-30 23:00 . 2008-05-01 14:33 331776 c:\windows\system32\dllcache\msadce.dll
+ 2008-08-02 18:18 . 2008-05-01 14:33 331776 c:\windows\system32\dllcache\msadce.dll
+ 2004-08-04 10:00 . 2007-04-03 03:14 981760 c:\windows\system32\dllcache\mfc42u.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 927504 c:\windows\system32\dllcache\mfc40u.dll
- 2009-04-14 19:32 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
+ 2004-08-04 10:00 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
- 2009-03-21 14:06 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2004-08-04 10:00 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2004-08-04 10:00 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
- 2007-08-13 22:38 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 138240 c:\windows\system32\dllcache\itss.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 155136 c:\windows\system32\dllcache\itircl.dll
+ 2007-04-02 16:36 . 2007-04-02 16:36 208896 c:\windows\system32\dllcache\fpmmcsat.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 598071 c:\windows\system32\dllcache\fpmmc.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 188494 c:\windows\system32\dllcache\fpcount.exe
+ 2008-04-14 00:12 . 2008-04-14 00:12 109840 c:\windows\system32\dllcache\fp98swin.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 876653 c:\windows\system32\dllcache\fp4awel.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 102509 c:\windows\system32\dllcache\fp4atxt.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 147513 c:\windows\system32\dllcache\fp4apws.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 184435 c:\windows\system32\dllcache\fp4amsft.dll
+ 2004-08-04 10:00 . 2008-04-13 19:14 143744 c:\windows\system32\dllcache\fastfat.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 380445 c:\windows\system32\dllcache\expsrv.dll
+ 2004-08-04 10:00 . 2008-04-13 17:37 138752 c:\windows\system32\dllcache\dssenh.dll
+ 2008-08-02 18:19 . 2008-01-19 11:04 554008 c:\windows\system32\dllcache\dao360.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 512512 c:\windows\system32\dllcache\cryptui.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 252928 c:\windows\system32\dllcache\compatui.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 276992 c:\windows\system32\dllcache\comdlg32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 188480 c:\windows\system32\dllcache\cfgwiz.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 233472 c:\windows\system32\dllcache\azroles.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 125952 c:\windows\system32\dllcache\apphelp.dll
+ 2004-08-04 10:00 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
- 2008-06-20 11:40 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
+ 2008-08-02 18:51 . 2008-04-13 16:39 142592 c:\windows\system32\dllcache\aec.sys
+ 2004-08-04 10:00 . 2010-06-24 12:15 124928 c:\windows\system32\dllcache\advpack.dll
- 2007-08-13 22:39 . 2010-06-24 12:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-04 10:00 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
- 2009-04-14 19:32 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 263680 c:\windows\system32\dllcache\adsnt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 143360 c:\windows\system32\dllcache\adsldpc.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 175616 c:\windows\system32\dllcache\adsldp.dll
+ 2010-08-18 03:02 . 2001-08-17 18:07 101888 c:\windows\system32\dllcache\adpu160m.sys
+ 2010-08-18 03:02 . 2001-08-17 16:19 747392 c:\windows\system32\dllcache\adm8830.sys
+ 2010-08-18 03:02 . 2001-08-17 16:19 553984 c:\windows\system32\dllcache\adm8820.sys
+ 2010-08-18 03:02 . 2001-08-17 16:19 584448 c:\windows\system32\dllcache\adm8810.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 116224 c:\windows\system32\dllcache\acxtrnal.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 193536 c:\windows\system32\dllcache\activeds.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 245248 c:\windows\system32\dllcache\acspecfc.dll
+ 2004-08-04 10:00 . 2008-04-13 18:36 187776 c:\windows\system32\dllcache\acpi.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 115712 c:\windows\system32\dllcache\aclui.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 141312 c:\windows\system32\dllcache\aclua.dll
- 2010-01-12 20:28 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2004-08-04 10:00 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2008-08-02 18:17 . 2008-04-14 00:12 184320 c:\windows\system32\dllcache\accwiz.exe
+ 2010-08-18 03:02 . 2001-08-17 16:20 297728 c:\windows\system32\dllcache\ac97sis.sys
+ 2010-08-18 03:02 . 2004-08-04 02:32 231552 c:\windows\system32\dllcache\ac97ali.sys
+ 2008-04-14 00:11 . 2008-04-14 00:11 136192 c:\windows\system32\dllcache\aaclient.dll
+ 2010-08-18 03:02 . 2001-08-18 02:36 462848 c:\windows\system32\dllcache\a3dapi.dll
- 2010-02-12 04:33 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2004-08-04 10:00 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2010-08-18 03:02 . 2001-08-17 16:48 148352 c:\windows\system32\dllcache\3dfxvsm.sys
+ 2010-08-18 03:02 . 2001-08-17 18:55 689216 c:\windows\system32\dllcache\3dfxvs.dll
+ 2010-08-18 03:02 . 2001-08-17 17:28 762780 c:\windows\system32\dllcache\3cwmcru.sys
+ 2010-08-15 19:54 . 2010-08-15 19:54 180224 c:\windows\Installer\afe9a.msi
+ 2010-08-16 23:30 . 2010-08-16 23:30 676352 c:\windows\Installer\360fe4.msi
+ 2006-03-18 11:09 . 2010-06-24 12:15 1168384 c:\windows\system32\dllcache\urlmon.dll
- 2007-08-13 22:54 . 2010-06-24 12:15 1168384 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 1614848 c:\windows\system32\dllcache\sfcfiles.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 1287168 c:\windows\system32\dllcache\ole32.dll
- 2008-10-14 21:38 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2005-03-30 01:23 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2004-08-04 10:00 . 2007-10-22 09:30 1516568 c:\windows\system32\dllcache\msjet40.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 1028096 c:\windows\system32\dllcache\mfc42.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 1852928 c:\windows\system32\dllcache\acgenral.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-07-27 2403568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-06-06 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-06 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-06 118784]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-06-01 2039240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-05 00:09 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
2007-02-21 15:17 970752 —-a-w- c:\program files\Intel\Wireless\Bin\iFrmewrk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
2007-02-21 15:19 819200 —-a-w- c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [6/4/2010 11:55 AM 229312]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [6/1/2010 7:00 PM 25240]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [11/17/2008 4:11 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/17/2008 4:11 PM 67656]
S2 gupdate1c9cccb13c57a8a;Google Update Service (gupdate1c9cccb13c57a8a);c:\program files\Google\Update\GoogleUpdate.exe [5/4/2009 11:14 AM 133104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/17/2008 4:11 PM 12872]
.
Contents of the 'Scheduled Tasks' folder

2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 15:14]

2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 15:14]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
FF - ProfilePath - c:\documents and settings\Tom Spencer\Application Data\Mozilla\Firefox\Profiles\8m02ir7m.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=VI2TDF&PC=VI2TDF&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=VI2TDF&PC=VI2TDF&q=
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-18 18:21
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(832)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(1280)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-08-18 18:23:20
ComboFix-quarantined-files.txt 2010-08-18 22:23
ComboFix2.txt 2010-08-15 16:55

Pre-Run: 48,212,836,352 bytes free
Post-Run: 48,334,557,184 bytes free

- - End Of File - - 00286502314FF1BDF2BA0C8236BCD23D
This is the only one I see bad, but it shows 0 bytes. See if deleting it makes any difference.
c:\documents and settings\Tom Spencer\Local Settings\Application Data\prvlcl.dat
No difference. After that i rebooted into safe mode, reran avgremover. rebooted into safe mode again, ran combofix from there, and it STILL reported avg as active and wanted me to close it! windows also still reported avg on as well. ??? shall i try installing another av as earlier suggested? doesn't make much sense to me if windows etc still keep seeing one that isn't there, but it might be an interesting data point. whatever change is causing this behavior must be very deep (permanent?) and invisible. if you have any other thoughts (short of the obvious reformat) i'm game. what's equally weird about this is that in all other aspects the computer seems to be operating perfectly normally; no problems with boot, speed, connectivity, etc.
Lets see if OTL will list anything about AVG

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
otl.txt


OTL logfile created on: 8/19/2010 6:53:47 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Tom Spencer\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 704.00 Mb Available Physical Memory | 69.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 44.99 Gb Free Space | 80.50% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOMSPENCER
Current User Name: Tom Spencer
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Tom Spencer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Tom Spencer\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (UIUSys) – C:\WINDOWS\System32\DRIVERS\UIUSYS.SYS File not found
DRV - (catchme) – C:\DOCUME~1\TOMSPE~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=VI2TDF&PC=VI2TDF&q="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=VI2TDF&PC=VI2TDF&q="


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/15 19:08:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/07 21:06:21 | 000,000,000 | —D | M]

[2009/04/20 10:10:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Tom Spencer\Application Data\Mozilla\Extensions
[2010/08/07 20:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Tom Spencer\Application Data\Mozilla\Firefox\Profiles\8m02ir7m.default\extensions
[2010/06/09 20:10:51 | 000,002,555 | —- | M] () – C:\Documents and Settings\Tom Spencer\Application Data\Mozilla\Firefox\Profiles\8m02ir7m.default\searchplugins\askcom.xml
[2010/06/12 11:27:30 | 000,001,834 | —- | M] () – C:\Documents and Settings\Tom Spencer\Application Data\Mozilla\Firefox\Profiles\8m02ir7m.default\searchplugins\bing.xml
[2010/08/18 23:02:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/13 16:51:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/16 19:30:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/08/16 19:30:38 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/08/15 16:58:48 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1217703636602 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tom Spencer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tom Spencer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/02 14:21:55 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/19 18:23:37 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Tom Spencer\Desktop\OTL.exe
[2010/08/18 22:42:24 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/08/18 22:03:01 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Tom Spencer\Recent
[2010/08/17 23:03:05 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agcgauge.ax
[2010/08/17 23:02:50 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adpu160m.sys
[2010/08/17 23:02:50 | 000,046,112 | —- | C] (Adaptec, Inc ) – C:\WINDOWS\System32\dllcache\adptsf50.sys
[2010/08/17 23:02:49 | 000,747,392 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8830.sys
[2010/08/17 23:02:49 | 000,010,880 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\admjoy.sys
[2010/08/17 23:02:48 | 000,584,448 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8810.sys
[2010/08/17 23:02:48 | 000,553,984 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8820.sys
[2010/08/17 23:02:47 | 000,020,160 | —- | C] (ADMtek Incorporated) – C:\WINDOWS\System32\dllcache\adm8511.sys
[2010/08/17 23:02:47 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adicvls.sys
[2010/08/17 23:02:46 | 000,061,440 | —- | C] (Color Flatbed Scanner) – C:\WINDOWS\System32\dllcache\acerscad.dll
[2010/08/17 23:02:45 | 000,297,728 | —- | C] (Silicon Integrated Systems Corp.) – C:\WINDOWS\System32\dllcache\ac97sis.sys
[2010/08/17 23:02:45 | 000,084,480 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ac97via.sys
[2010/08/17 23:02:44 | 000,231,552 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ac97ali.sys
[2010/08/17 23:02:44 | 000,096,256 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ac97intc.sys
[2010/08/17 23:02:43 | 000,462,848 | —- | C] (Aureal Inc.) – C:\WINDOWS\System32\dllcache\a3dapi.dll
[2010/08/17 23:02:43 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\abp480n5.sys
[2010/08/17 23:02:42 | 000,098,304 | —- | C] (Aureal Semiconductor) – C:\WINDOWS\System32\dllcache\a3d.dll
[2010/08/17 23:02:42 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\8514a.dll
[2010/08/17 23:02:41 | 000,148,352 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2010/08/17 23:02:41 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\61883.sys
[2010/08/17 23:02:41 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\4mmdat.sys
[2010/08/17 23:02:40 | 000,762,780 | —- | C] (3Com, Inc.) – C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2010/08/17 23:02:40 | 000,689,216 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2010/08/17 23:02:39 | 000,053,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394bus.sys
[2010/08/17 23:02:39 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2010/08/17 23:02:20 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.dll
[2010/08/16 19:30:53 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/08/16 19:30:52 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/08/16 19:30:52 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/08/16 19:30:52 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/08/16 19:30:33 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/08/15 15:54:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/08/15 12:49:04 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/08/15 12:47:10 | 000,000,000 | —D | C] – C:\Qoobox
[2010/08/08 11:30:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\COMODO
[2010/08/08 11:29:13 | 000,000,000 | —D | C] – C:\Program Files\COMODO
[2010/08/08 11:27:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Comodo Downloader
[2010/08/08 10:40:02 | 000,000,000 | —D | C] – C:\Program Files\Everything
[2010/08/08 10:16:35 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidserv.dll
[2010/08/07 23:25:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Tom Spencer\My Documents\Downloads
[2010/08/07 18:08:11 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/07 18:08:09 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/07 18:08:09 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/07 18:02:15 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/19 18:55:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/19 18:23:17 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Tom Spencer\Desktop\OTL.exe
[2010/08/19 18:21:09 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/19 18:19:42 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/19 18:19:37 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/19 18:18:56 | 003,002,368 | —- | M] () – C:\Documents and Settings\Tom Spencer\ntuser.dat
[2010/08/19 18:18:52 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Tom Spencer\ntuser.ini
[2010/08/19 18:13:37 | 001,414,884 | -H– | M] () – C:\Documents and Settings\Tom Spencer\Local Settings\Application Data\IconCache.db
[2010/08/18 22:39:18 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/17 22:26:26 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/16 19:30:37 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/08/16 19:30:37 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/08/16 19:30:37 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/08/16 19:30:37 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/08/16 19:30:37 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/08/15 16:58:48 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/15 12:49:10 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/08/12 18:19:15 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/12 18:04:30 | 000,489,254 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/12 18:04:30 | 000,432,924 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/12 18:04:30 | 000,067,714 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/08 11:29:23 | 000,001,653 | —- | M] () – C:\Documents and Settings\All Users\Desktop\COMODO Firewall.lnk
[2010/08/08 10:16:53 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2010/08/08 10:16:52 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2010/08/07 23:26:18 | 000,001,580 | —- | M] () – C:\Documents and Settings\Tom Spencer\Desktop\Defraggler.lnk
[2010/08/07 21:06:45 | 000,000,507 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/07 21:06:45 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/08/07 20:01:25 | 000,000,682 | —- | M] () – C:\Documents and Settings\Tom Spencer\Desktop\CCleaner.lnk
[2010/08/07 18:08:13 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/07 18:07:25 | 000,001,487 | —- | M] () – C:\Documents and Settings\Tom Spencer\Desktop\Windows Explorer.lnk
[2010/07/27 02:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/15 12:49:09 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/08/15 12:49:05 | 000,260,272 | —- | C] () – C:\cmldr
[2010/08/15 12:47:51 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/08/15 12:47:51 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/08/08 11:29:23 | 000,001,653 | —- | C] () – C:\Documents and Settings\All Users\Desktop\COMODO Firewall.lnk
[2010/08/08 10:16:53 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2010/08/08 10:16:52 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2010/08/07 18:08:13 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/07 18:07:25 | 000,001,487 | —- | C] () – C:\Documents and Settings\Tom Spencer\Desktop\Windows Explorer.lnk
[2010/08/03 19:42:27 | 003,002,368 | —- | C] () – C:\Documents and Settings\Tom Spencer\ntuser.dat
[2008/12/10 15:40:30 | 000,002,146 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2008/12/10 13:06:12 | 000,000,149 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/01/09 15:01:48 | 000,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini

========== LOP Check ==========

[2010/01/24 13:12:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP

========== Purity Check ==========


< End of report >
extras.txt


OTL Extras logfile created on: 8/19/2010 6:53:47 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Tom Spencer\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 704.00 Mb Available Physical Memory | 69.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 44.99 Gb Free Space | 80.50% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOMSPENCER
Current User Name: Tom Spencer
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{829CD169-E692-48E8-9BDE-A3E8D8B65538}" = mSCfg
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CC6B1BB4-4E06-4A5B-A166-B371B551324B}" = COMODO Internet Security
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"Defraggler" = Defraggler
"Everything" = Everything 1.2.1.371
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ProInst" = Intel® PROSet/Wireless Software
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/8/2010 1:27:59 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/8/2010 1:27:59 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/8/2010 1:28:14 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 8/8/2010 1:28:14 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/8/2010 1:28:14 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/8/2010 1:28:16 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/8/2010 11:52:59 PM | Computer Name = TOMSPENCER | Source = ESENT | ID = 490
Description = svchost (1320) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 8/8/2010 11:53:10 PM | Computer Name = TOMSPENCER | Source = ESENT | ID = 490
Description = svchost (1320) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 8/8/2010 11:53:10 PM | Computer Name = TOMSPENCER | Source = ESENT | ID = 470
Description = Catalog Database (1320) Database C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
is partially attached. Attachment stage: 3. Error: -1032.

Error - 8/16/2010 7:24:24 PM | Computer Name = TOMSPENCER | Source = Application Error | ID = 1000
Description = Faulting application javara.exe, version 1.16.1.1763, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

[ Application Events ]
Error - 8/8/2010 1:27:59 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/8/2010 1:27:59 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/8/2010 1:28:14 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 8/8/2010 1:28:14 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/8/2010 1:28:14 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/8/2010 1:28:16 PM | Computer Name = TOMSPENCER | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/8/2010 11:52:59 PM | Computer Name = TOMSPENCER | Source = ESENT | ID = 490
Description = svchost (1320) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 8/8/2010 11:53:10 PM | Computer Name = TOMSPENCER | Source = ESENT | ID = 490
Description = svchost (1320) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 8/8/2010 11:53:10 PM | Computer Name = TOMSPENCER | Source = ESENT | ID = 470
Description = Catalog Database (1320) Database C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
is partially attached. Attachment stage: 3. Error: -1032.

Error - 8/16/2010 7:24:24 PM | Computer Name = TOMSPENCER | Source = Application Error | ID = 1000
Description = Faulting application javara.exe, version 1.16.1.1763, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

[ System Events ]
Error - 8/18/2010 10:27:47 PM | Computer Name = TOMSPENCER | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 8/18/2010 10:30:50 PM | Computer Name = TOMSPENCER | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 8/18/2010 10:40:58 PM | Computer Name = TOMSPENCER | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 8/18/2010 10:47:56 PM | Computer Name = TOMSPENCER | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 8/18/2010 10:49:09 PM | Computer Name = TOMSPENCER | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 8/18/2010 10:50:23 PM | Computer Name = TOMSPENCER | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cmdGuard Fips intelppm SASDIFSV SASKUTIL

Error - 8/18/2010 10:50:48 PM | Computer Name = TOMSPENCER | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 8/18/2010 10:51:46 PM | Computer Name = TOMSPENCER | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126

Error - 8/19/2010 6:14:41 PM | Computer Name = TOMSPENCER | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126

Error - 8/19/2010 6:19:45 PM | Computer Name = TOMSPENCER | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126


< End of report >
Installed avast, rebooted. Windows security center reports AVG is up to date and virus scanning is on. Unbelievable! Avast is on, updated itself, etc. Avg is nowhere to be seen - except in the windows security center reference.
Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
Did that, and I'm happy to say that at least the windows security center message changed. it now says 'windows found more than one av…' i guess that's progress. might the 'other' av be comodo, which even when installing the firewall only (which is all that's installed here) seems to have at least refs to the av. or maybe it's seeing super-antispyware as the additional av. still no security center manage settings direct access to av, but who really cares. maybe that's a vendor decision, and avira puts it there while others don't?
i would agree. thanks so much for your patience and all the good help. i personally got something out of it too, having picked up a few new tricks and tools from you during this prolonged exercise. have a great weekend, and thanks again!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI