agoodlytouch
Topic Starter
Hi there I have a few problems ….
IE is not working, Can not remove norton, Tickin noise in normal mode startup not safe, Administrator errors Please Help
OTL logfile created on: 9/1/2010 8:50:09 PM - Run 2
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Bishop\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.04 Gb Total Space | 255.50 Gb Free Space | 88.70% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.05 Gb Free Space | 60.47% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NEWOWNER-PC
Current User Name: Bishop
Logged in as Administrator.
Current Boot Mode: SafeMode
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Bishop\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Bishop\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (stllssvr) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe File not found
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (SprintRcAppSvc) – C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (PCTEL)
SRV - (CASprint) – C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe (PCTEL)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (LiveUpdate Notice Ex) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SymAppCore) – C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
SRV - (comHost) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (ISPwdSvc) – C:\Program Files\Norton Internet Security\isPwdSvc.exe (Symantec Corporation)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (SABKUTIL) – E:\SUPERAntiSpyware\SABKUTIL.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NAVEX15) – C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080314.003\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080314.003\NAVENG.SYS File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (DgiVecp) – C:\Windows\System32\Drivers\DgiVecp.sys File not found
DRV - (catchme) – C:\Users\Bishop\AppData\Local\Temp\catchme.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (ATMFNVsp) – C:\Windows\System32\drivers\ATMFNVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFCVsp) – C:\Windows\System32\drivers\ATMFCVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFVsp) – C:\Windows\System32\drivers\ATMFVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFMdm) – C:\Windows\System32\drivers\ATMFMdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFNET) – C:\Windows\System32\drivers\ATMFNET.sys (DEVGURU Co., LTD.)
DRV - (ATMFBUS) – C:\Windows\System32\drivers\ATMFBUS.sys (DEVGURU Co., LTD.)
DRV - (ATMFFLT) – C:\Windows\System32\drivers\ATMFFLT.sys (DEVGURU Co., LTD.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (X4HS32Ex) – C:\Program Files\Free Ride Games\X4HS32Ex.sys (Exent Technologies Ltd.)
DRV - (motport) – C:\Windows\System32\drivers\motport.sys (Motorola)
DRV - (motmodem) – C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (motccgp) – C:\Windows\System32\drivers\motccgp.sys (Motorola)
DRV - (motccgpfl) – C:\Windows\System32\drivers\motccgpfl.sys (Motorola)
DRV - (Nmea) – C:\Windows\System32\drivers\pctnullport.sys (PCTEL Inc.)
DRV - (PCTINDIS5) – C:\Windows\System32\PCTINDIS5.sys (PCTEL Inc.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\Windows\System32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (swmx00) Sierra Wireless USB MUX Driver (#00) – C:\Windows\System32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20080314.001\IDSvix86.sys (Symantec Corporation)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (SYMNDISV) – C:\Windows\System32\Drivers\SYMNDISV.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\Windows\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\Windows\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (SRS_SSCFilter) SRS Labs Audio Sandbox (WDM) – C:\Windows\System32\drivers\SRS_SSCFilter_i386.sys ()
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (ppsio2) – C:\Windows\System32\drivers\ppsio2.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\URLSearchHook: {64711c62-1970-4231-aa8f-c109834921d5} - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=http://search.yahoo.com/search?fr=yff3u&p;="
FF - prefs.js..browser.search.defaultthis.engineName: "Free Ride Games Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "PureDef Music"
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT1320680&SearchSource;=13"
FF - prefs.js..extensions.enabledItems: {f92a9fe4-2850-4198-b9d5-279880e49b16}:2.3.0.4
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.0.20080712
FF - prefs.js..keyword.URL: "http://results.myway.com/dft_redir.jhtml?id=YD&ptb;=13C4B1C4-3805-4024-9B90-528DDDE8D3E4&psa;=&ind;=2009121314&ptnrS;=YD&si;=&st;=kwd&n;=&searchfor;="
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/20 22:58:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/21 00:33:33 | 000,000,000 | —D | M]
[2009/11/18 20:48:33 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Mozilla\Extensions
[2009/11/18 20:48:33 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/09/01 06:01:58 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\extensions
[2010/05/21 00:57:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/09/05 13:37:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/08/25 16:56:38 | 000,000,892 | —- | M] () – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\searchplugins\conduit.xml
[2010/05/20 17:38:56 | 000,009,949 | —- | M] () – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\searchplugins\mywebsearch.xml
[2010/05/20 17:38:58 | 000,009,944 | —- | M] () – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\searchplugins\puredefmusic.xml
[2010/03/17 17:17:32 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/09/05 13:34:46 | 000,000,000 | —D | M] (FoxyTunes) – C:\Program Files\Mozilla Firefox\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2008/09/05 13:37:26 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/11/10 13:10:18 | 000,000,000 | —D | M] (Free Ride Games Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{f92a9fe4-2850-4198-b9d5-279880e49b16}
[2009/12/13 15:25:51 | 000,024,576 | —- | M] (TightRope, Inc) – C:\Program Files\Mozilla Firefox\plugins\NPp3Stub.dll
O1 HOSTS File: ([2010/09/01 05:26:58 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKCU..\Run: [PPWebCap] C:\Program Files\ScanSoft\PaperPort\PPWEBCAP.EXE (Scansoft Inc.)
O4 - HKCU..\Run: [SRS Audio Sandbox] C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe (SRS Labs, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] E:\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\Bishop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\reminder-ScanSoft Product Registration.lnk = C:\Program Files\ScanSoft\PaperPort\Config\Ereg\REMIND32.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Bishop\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\Bishop\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - File not found
O29 - HKLM SecurityProviders - (digest.dll) - File not found
O29 - HKLM SecurityProviders - (msnsspc.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2010/09/01 20:47:25 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Bishop\Desktop\OTL.exe
[2010/09/01 20:47:09 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Bishop\Desktop\HijackThis.exe
[2010/09/01 05:53:21 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/09/01 05:50:16 | 000,000,000 | —D | C] – C:\Users\Bishop\AppData\Roaming\SUPERAntiSpyware.com
[2010/09/01 05:50:16 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/09/01 05:28:51 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/09/01 05:28:51 | 000,000,000 | —D | C] – C:\Users\Bishop\AppData\Local\temp
[2010/09/01 05:28:27 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/09/01 05:16:54 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/09/01 05:16:54 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/09/01 05:16:54 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/09/01 05:16:18 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/09/01 05:16:15 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/09/01 05:04:53 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/09/01 05:04:22 | 000,000,000 | —D | C] – C:\Qoobox
========== Files - Modified Within 30 Days ==========
[2010/09/01 20:50:08 | 002,883,584 | -HS- | M] () – C:\Users\Bishop\ntuser.dat
[2010/09/01 19:10:34 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Bishop\Desktop\HijackThis.exe
[2010/09/01 19:09:30 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Bishop\Desktop\OTL.exe
[2010/09/01 18:02:37 | 000,000,680 | —- | M] () – C:\Users\Bishop\AppData\Local\d3d9caps.dat
[2010/09/01 17:46:02 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/01 06:29:53 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/01 06:29:19 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/01 06:28:35 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/01 05:43:51 | 000,001,182 | —- | M] () – C:\Users\Bishop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\reminder-ScanSoft Product Registration.lnk
[2010/09/01 05:37:15 | 000,000,554 | —- | M] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - New owner.job
[2010/09/01 05:31:17 | 000,524,288 | -HS- | M] () – C:\Users\Bishop\ntuser.dat{d91fab6d-3ffa-11dd-83bd-001aa073dc0a}.TMContainer00000000000000000001.regtrans-ms
[2010/09/01 05:31:17 | 000,065,536 | -HS- | M] () – C:\Users\Bishop\ntuser.dat{d91fab6d-3ffa-11dd-83bd-001aa073dc0a}.TM.blf
[2010/09/01 05:27:05 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/09/01 05:26:58 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/08/31 20:33:59 | 000,000,000 | —- | M] () – C:\Users\Bishop\defogger_reenable
========== Files Created - No Company Name ==========
[2010/09/01 20:47:42 | 000,525,824 | —- | C] () – C:\Users\Bishop\Desktop\dds.scr
[2010/09/01 18:02:37 | 000,000,680 | —- | C] () – C:\Users\Bishop\AppData\Local\d3d9caps.dat
[2010/09/01 05:16:54 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/09/01 05:16:54 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/09/01 05:16:54 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/09/01 05:16:54 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/09/01 05:16:54 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/08/31 20:33:59 | 000,000,000 | —- | C] () – C:\Users\Bishop\defogger_reenable
[2009/11/10 04:39:32 | 000,000,074 | —- | C] () – C:\Windows\st_affiliate.ini
[2009/09/26 13:08:01 | 000,023,200 | —- | C] () – C:\Windows\System32\drivers\ppsio2.sys
[2009/09/26 13:05:30 | 000,001,056 | —- | C] () – C:\Windows\maxlink.ini
[2009/09/26 13:05:30 | 000,000,090 | —- | C] () – C:\Windows\calera.ini
[2009/09/26 13:05:21 | 000,269,312 | —- | C] () – C:\Windows\System32\FPXIG.DLL
[2009/09/26 13:05:21 | 000,065,024 | —- | C] () – C:\Windows\System32\JPEGACC.DLL
[2009/09/26 13:05:20 | 000,068,096 | —- | C] () – C:\Windows\System32\IGFPX32P.DLL
[2009/09/26 13:05:08 | 000,101,376 | —- | C] () – C:\Windows\System32\WELSOF32.DLL
[2008/05/17 21:37:44 | 000,000,008 | —- | C] () – C:\Users\Bishop\AppData\Local\.mpid
[2008/04/19 14:15:10 | 000,003,932 | —- | C] () – C:\Users\Bishop\AppData\Roaming\LMLayout.dat
[2008/04/19 14:11:03 | 000,000,150 | —- | C] () – C:\Windows\System32\LM_SUPPORT.INI
[2008/03/28 07:06:26 | 000,027,136 | —- | C] () – C:\Users\Bishop\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/03/21 22:58:08 | 000,000,028 | —- | C] () – C:\Windows\ODBC.INI
[2008/03/21 22:58:02 | 000,036,864 | R— | C] () – C:\Windows\System32\ODBCSTF.DLL
[2008/03/08 01:25:53 | 000,047,360 | —- | C] () – C:\Windows\System32\drivers\Surroundhp_kern_i386.sys
[2008/03/08 01:25:53 | 000,042,112 | —- | C] () – C:\Windows\System32\drivers\csiidecoder_kern_i386.sys
[2008/03/08 01:25:52 | 000,047,104 | —- | C] () – C:\Windows\System32\drivers\tshd4_kern_i386.sys
[2008/03/08 01:25:52 | 000,039,808 | —- | C] () – C:\Windows\System32\drivers\SRS_SSCFilter_i386.sys
[2008/03/05 15:41:58 | 000,024,840 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys
[2007/03/19 06:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 06:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 06:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 06:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 06:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 06:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 06:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 06:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 06:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 06:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 06:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2008/08/15 16:21:46 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Astraware
[2010/05/21 00:56:14 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Cricket
[2009/11/19 19:43:41 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\LimeWire
[2008/06/28 01:07:40 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Sprite PC Agent
[2008/06/28 01:07:40 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Sprite Setup Wizard
[2008/07/15 21:31:30 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Sprite Software
[2010/07/30 04:12:57 | 000,032,614 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/19 03:45:45 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/11/10 09:22:24 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2010/09/01 05:28:49 | 000,012,143 | —- | M] () – C:\ComboFix.txt
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/08/31 20:49:55 | 000,064,331 | —- | M] () – C:\CybDefInstallInfo.log
[2007/11/21 22:51:47 | 000,004,722 | RH– | M] () – C:\dell.sdr
[2009/11/09 21:28:03 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2009/11/09 21:28:03 | 000,005,120 | -H– | M] () – C:\ntuser.dat.LOG1
[2009/11/09 21:28:02 | 000,000,000 | -H– | M] () – C:\ntuser.dat.LOG2
[2009/11/09 21:28:03 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{8ac1b226-cc7f-11de-aab5-001aa073dc0a}.TM.blf
[2009/11/09 21:28:03 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{8ac1b226-cc7f-11de-aab5-001aa073dc0a}.TMContainer00000000000000000001.regtrans-ms
[2009/11/09 21:28:03 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{8ac1b226-cc7f-11de-aab5-001aa073dc0a}.TMContainer00000000000000000002.regtrans-ms
[2009/11/09 21:28:03 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{8ac1b22a-cc7f-11de-aab5-001aa073dc0a}.TM.blf
[2009/11/09 21:28:03 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{8ac1b22a-cc7f-11de-aab5-001aa073dc0a}.TMContainer00000000000000000001.regtrans-ms
[2009/11/09 21:28:03 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{8ac1b22a-cc7f-11de-aab5-001aa073dc0a}.TMContainer00000000000000000002.regtrans-ms
[2010/09/01 17:45:28 | 2392,596,480 | -HS- | M] () – C:\pagefile.sys
[2007/11/21 15:26:37 | 000,000,071 | —- | M] () – C:\SystemInfo.ini
[2008/08/15 16:23:18 | 000,000,192 | —- | M] () – C:\WMProDesktop.log
< %systemroot%\Fonts\*.com >
[2006/11/02 08:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 08:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/10/22 01:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNMPD97.DLL
[2007/10/22 01:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNMPP97.DLL
[2006/11/02 08:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2002/09/05 10:07:32 | 000,176,128 | —- | M] (DeviceGuys) – C:\Windows\System32\spool\prtprocs\w32x86\LMPriNT.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2001/02/20 14:30:00 | 000,046,592 | —- | M] (Black Ice Software) – C:\Windows\System32\spool\prtprocs\w32x86\Ppbiproc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/06/14 20:19:36 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 06:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 06:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 06:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/11/20 14:56:59 | 000,000,286 | -HS- | M] () – C:\Users\Bishop\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/09/01 19:10:34 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Bishop\Desktop\HijackThis.exe
[2010/09/01 19:09:30 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Bishop\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-01 09:49:19
========== Alternate Data Streams ==========
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:74B502CB
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:B623B5B8
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:73933431
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:2BDCFAD6
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:7C60A173
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:8BB2EC84
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:C228601A
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:54:44 PM, on 9/1/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Safe mode
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\notepad.exe
C:\Users\Bishop\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - HKCU\..\Run: [Exetender] "C:\Program Files\Free Ride Games\GPlayer.exe /runonstartup"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] E:\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:\Program Files\ScanSoft\PaperPort\Config\Ereg\REMIND32.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Sprint Con App Svc (CASprint) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 5686 bytes
DDS (Ver_10-03-17.01) - NTFSx86 MINIMAL
Run by [removed] at 20:55:05.91 on Wed 09/01/2010
Internet Explorer: 8.0.6001.18928 BrowserJavaVersion: 1.6.0_15
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1982.1026 [GMT -4:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\notepad.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Bishop\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [PPWebCap] c:\progra~1\scansoft\paperp~1\PPWebCap.exe
uRun: [SRS Audio Sandbox] "c:\program files\srs labs\audio sandbox\SRSSSC.exe" /hideme
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9
uRun: [Exetender] "c:\program files\free ride games\GPlayer.exe /runonstartup"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SUPERAntiSpyware] e:\superantispyware\SUPERAntiSpyware.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [SpiralFrog] c:\program files\spiralfrog\Spiralfrog.exe
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\bishop\appdata\roaming\micros~1\windows\startm~1\programs\startup\remind~1.lnk - c:\program files\scansoft\paperport\config\ereg\REMIND32.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\bishop\appdata\roaming\mozilla\firefox\profiles\m8ejpczk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - PureDef Music
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1320680&SearchSource;=13
FF - prefs.js: keyword.URL - hxxp://results.myway.com/dft_redir.jhtml?id=YD&ptb;=13C4B1C4-3805-4024-9B90-528DDDE8D3E4&psa;=&ind;=2009121314&ptnrS;=YD&si;=&st;=kwd&n;=&searchfor;=
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\mozilla firefox\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll
FF - component: c:\program files\mozilla firefox\extensions\{f92a9fe4-2850-4198-b9d5-279880e49b16}\components\FFExternalAlert.dll
FF - plugin: c:\program files\free ride games\npExentCtl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPp3Stub.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20080314.001\IDSvix86.sys [2008-3-14 261680]
S2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [2009-9-26 23200]
S2 X4HS32Ex;X4HS32Ex;c:\program files\free ride games\X4HS32Ex.sys [2009-11-10 53280]
S3 ATMFBUS;A600 USB Composite Device Driver;c:\windows\system32\drivers\ATMFBUS.sys [2010-5-20 47360]
S3 ATMFCVsp;A600 Cricket CM Port;c:\windows\system32\drivers\ATMFCVsp.sys [2010-5-20 153600]
S3 ATMFFLT;A600 USB Modem Installation CD;c:\windows\system32\drivers\ATMFFLT.sys [2010-5-20 13312]
S3 ATMFMdm;A600 Cricket EVDO Modem;c:\windows\system32\drivers\ATMFMdm.sys [2010-5-20 153472]
S3 ATMFNET;A600 Cricket EVDO Network Adapter;c:\windows\system32\drivers\ATMFNET.sys [2010-5-20 103424]
S3 ATMFNVsp;A600 Cricket NMEA Port Serial Port;c:\windows\system32\drivers\ATMFNVsp.sys [2010-5-20 153600]
S3 ATMFVsp;A600 Cricket Diagnostics Port;c:\windows\system32\drivers\ATMFVsp.sys [2010-5-20 153472]
S3 CASprint;Sprint Con App Svc;c:\program files\sprint\sprint smartview\ConAppsSvc.exe [2008-6-19 124184]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-11-21 30192]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-6-19 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-6-19 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2008-6-19 23680]
S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2008-2-14 1251720]
S3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2007-10-30 37936]
=============== Created Last 30 ================
2010-09-01 09:53:21 0 d—–w- c:\program files\ESET
2010-09-01 09:50:16 0 d—–w- c:\users\bishop\appdata\roaming\SUPERAntiSpyware.com
2010-09-01 09:50:16 0 d—–w- c:\programdata\SUPERAntiSpyware.com
2010-09-01 09:28:27 0 d-sh–w- C:\$RECYCLE.BIN
2010-09-01 09:16:54 98816 —-a-w- c:\windows\sed.exe
2010-09-01 09:16:54 77312 —-a-w- c:\windows\MBR.exe
2010-09-01 09:16:54 256512 —-a-w- c:\windows\PEV.exe
2010-09-01 09:16:54 161792 —-a-w- c:\windows\SWREG.exe
2010-09-01 00:33:59 0 —-a-w- c:\users\bishop\defogger_reenable
==================== Find3M ====================
2010-07-07 07:01:57 51200 —-a-w- c:\windows\inf\infpub.dat
2010-07-07 07:01:57 143360 —-a-w- c:\windows\inf\infstrng.dat
2010-07-07 07:01:56 86016 —-a-w- c:\windows\inf\infstor.dat
2008-06-15 00:19:36 174 –sha-w- c:\program files\desktop.ini
2008-06-15 00:01:17 665600 —-a-w- c:\windows\inf\drvindex.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2001-09-10 12:10:36 61440 —-a-w- c:\windows\inf\i386\onetUSD.dll
1998-05-12 08:01:00 8944 —-a-w- c:\windows\inf\i386\usbscan.sys
2010-01-16 21:40:06 245760 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-11-17 02:52:39 245760 –sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2007-11-22 02:51:19 8192 –sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 20:55:17.94 ===============
IE is not working, Can not remove norton, Tickin noise in normal mode startup not safe, Administrator errors Please Help
OTL logfile created on: 9/1/2010 8:50:09 PM - Run 2
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Bishop\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.04 Gb Total Space | 255.50 Gb Free Space | 88.70% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.05 Gb Free Space | 60.47% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NEWOWNER-PC
Current User Name: Bishop
Logged in as Administrator.
Current Boot Mode: SafeMode
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Bishop\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Bishop\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (stllssvr) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe File not found
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (SprintRcAppSvc) – C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (PCTEL)
SRV - (CASprint) – C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe (PCTEL)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (LiveUpdate Notice Ex) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SymAppCore) – C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
SRV - (comHost) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (ISPwdSvc) – C:\Program Files\Norton Internet Security\isPwdSvc.exe (Symantec Corporation)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (SABKUTIL) – E:\SUPERAntiSpyware\SABKUTIL.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NAVEX15) – C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080314.003\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080314.003\NAVENG.SYS File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (DgiVecp) – C:\Windows\System32\Drivers\DgiVecp.sys File not found
DRV - (catchme) – C:\Users\Bishop\AppData\Local\Temp\catchme.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (ATMFNVsp) – C:\Windows\System32\drivers\ATMFNVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFCVsp) – C:\Windows\System32\drivers\ATMFCVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFVsp) – C:\Windows\System32\drivers\ATMFVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFMdm) – C:\Windows\System32\drivers\ATMFMdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFNET) – C:\Windows\System32\drivers\ATMFNET.sys (DEVGURU Co., LTD.)
DRV - (ATMFBUS) – C:\Windows\System32\drivers\ATMFBUS.sys (DEVGURU Co., LTD.)
DRV - (ATMFFLT) – C:\Windows\System32\drivers\ATMFFLT.sys (DEVGURU Co., LTD.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (X4HS32Ex) – C:\Program Files\Free Ride Games\X4HS32Ex.sys (Exent Technologies Ltd.)
DRV - (motport) – C:\Windows\System32\drivers\motport.sys (Motorola)
DRV - (motmodem) – C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (motccgp) – C:\Windows\System32\drivers\motccgp.sys (Motorola)
DRV - (motccgpfl) – C:\Windows\System32\drivers\motccgpfl.sys (Motorola)
DRV - (Nmea) – C:\Windows\System32\drivers\pctnullport.sys (PCTEL Inc.)
DRV - (PCTINDIS5) – C:\Windows\System32\PCTINDIS5.sys (PCTEL Inc.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\Windows\System32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (swmx00) Sierra Wireless USB MUX Driver (#00) – C:\Windows\System32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20080314.001\IDSvix86.sys (Symantec Corporation)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (SYMNDISV) – C:\Windows\System32\Drivers\SYMNDISV.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\Windows\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\Windows\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (SRS_SSCFilter) SRS Labs Audio Sandbox (WDM) – C:\Windows\System32\drivers\SRS_SSCFilter_i386.sys ()
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (ppsio2) – C:\Windows\System32\drivers\ppsio2.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\URLSearchHook: {64711c62-1970-4231-aa8f-c109834921d5} - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=http://search.yahoo.com/search?fr=yff3u&p;="
FF - prefs.js..browser.search.defaultthis.engineName: "Free Ride Games Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "PureDef Music"
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT1320680&SearchSource;=13"
FF - prefs.js..extensions.enabledItems: {f92a9fe4-2850-4198-b9d5-279880e49b16}:2.3.0.4
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.0.20080712
FF - prefs.js..keyword.URL: "http://results.myway.com/dft_redir.jhtml?id=YD&ptb;=13C4B1C4-3805-4024-9B90-528DDDE8D3E4&psa;=&ind;=2009121314&ptnrS;=YD&si;=&st;=kwd&n;=&searchfor;="
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/20 22:58:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/21 00:33:33 | 000,000,000 | —D | M]
[2009/11/18 20:48:33 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Mozilla\Extensions
[2009/11/18 20:48:33 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/09/01 06:01:58 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\extensions
[2010/05/21 00:57:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/09/05 13:37:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/08/25 16:56:38 | 000,000,892 | —- | M] () – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\searchplugins\conduit.xml
[2010/05/20 17:38:56 | 000,009,949 | —- | M] () – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\searchplugins\mywebsearch.xml
[2010/05/20 17:38:58 | 000,009,944 | —- | M] () – C:\Users\Bishop\AppData\Roaming\Mozilla\Firefox\Profiles\m8ejpczk.default\searchplugins\puredefmusic.xml
[2010/03/17 17:17:32 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/09/05 13:34:46 | 000,000,000 | —D | M] (FoxyTunes) – C:\Program Files\Mozilla Firefox\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2008/09/05 13:37:26 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/11/10 13:10:18 | 000,000,000 | —D | M] (Free Ride Games Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{f92a9fe4-2850-4198-b9d5-279880e49b16}
[2009/12/13 15:25:51 | 000,024,576 | —- | M] (TightRope, Inc) – C:\Program Files\Mozilla Firefox\plugins\NPp3Stub.dll
O1 HOSTS File: ([2010/09/01 05:26:58 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKCU..\Run: [PPWebCap] C:\Program Files\ScanSoft\PaperPort\PPWEBCAP.EXE (Scansoft Inc.)
O4 - HKCU..\Run: [SRS Audio Sandbox] C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe (SRS Labs, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] E:\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\Bishop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\reminder-ScanSoft Product Registration.lnk = C:\Program Files\ScanSoft\PaperPort\Config\Ereg\REMIND32.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Bishop\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\Bishop\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - File not found
O29 - HKLM SecurityProviders - (digest.dll) - File not found
O29 - HKLM SecurityProviders - (msnsspc.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2010/09/01 20:47:25 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Bishop\Desktop\OTL.exe
[2010/09/01 20:47:09 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Bishop\Desktop\HijackThis.exe
[2010/09/01 05:53:21 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/09/01 05:50:16 | 000,000,000 | —D | C] – C:\Users\Bishop\AppData\Roaming\SUPERAntiSpyware.com
[2010/09/01 05:50:16 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/09/01 05:28:51 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/09/01 05:28:51 | 000,000,000 | —D | C] – C:\Users\Bishop\AppData\Local\temp
[2010/09/01 05:28:27 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/09/01 05:16:54 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/09/01 05:16:54 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/09/01 05:16:54 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/09/01 05:16:18 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/09/01 05:16:15 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/09/01 05:04:53 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/09/01 05:04:22 | 000,000,000 | —D | C] – C:\Qoobox
========== Files - Modified Within 30 Days ==========
[2010/09/01 20:50:08 | 002,883,584 | -HS- | M] () – C:\Users\Bishop\ntuser.dat
[2010/09/01 19:10:34 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Bishop\Desktop\HijackThis.exe
[2010/09/01 19:09:30 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Bishop\Desktop\OTL.exe
[2010/09/01 18:02:37 | 000,000,680 | —- | M] () – C:\Users\Bishop\AppData\Local\d3d9caps.dat
[2010/09/01 17:46:02 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/01 06:29:53 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/01 06:29:19 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/01 06:28:35 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/01 05:43:51 | 000,001,182 | —- | M] () – C:\Users\Bishop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\reminder-ScanSoft Product Registration.lnk
[2010/09/01 05:37:15 | 000,000,554 | —- | M] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - New owner.job
[2010/09/01 05:31:17 | 000,524,288 | -HS- | M] () – C:\Users\Bishop\ntuser.dat{d91fab6d-3ffa-11dd-83bd-001aa073dc0a}.TMContainer00000000000000000001.regtrans-ms
[2010/09/01 05:31:17 | 000,065,536 | -HS- | M] () – C:\Users\Bishop\ntuser.dat{d91fab6d-3ffa-11dd-83bd-001aa073dc0a}.TM.blf
[2010/09/01 05:27:05 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/09/01 05:26:58 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/08/31 20:33:59 | 000,000,000 | —- | M] () – C:\Users\Bishop\defogger_reenable
========== Files Created - No Company Name ==========
[2010/09/01 20:47:42 | 000,525,824 | —- | C] () – C:\Users\Bishop\Desktop\dds.scr
[2010/09/01 18:02:37 | 000,000,680 | —- | C] () – C:\Users\Bishop\AppData\Local\d3d9caps.dat
[2010/09/01 05:16:54 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/09/01 05:16:54 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/09/01 05:16:54 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/09/01 05:16:54 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/09/01 05:16:54 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/08/31 20:33:59 | 000,000,000 | —- | C] () – C:\Users\Bishop\defogger_reenable
[2009/11/10 04:39:32 | 000,000,074 | —- | C] () – C:\Windows\st_affiliate.ini
[2009/09/26 13:08:01 | 000,023,200 | —- | C] () – C:\Windows\System32\drivers\ppsio2.sys
[2009/09/26 13:05:30 | 000,001,056 | —- | C] () – C:\Windows\maxlink.ini
[2009/09/26 13:05:30 | 000,000,090 | —- | C] () – C:\Windows\calera.ini
[2009/09/26 13:05:21 | 000,269,312 | —- | C] () – C:\Windows\System32\FPXIG.DLL
[2009/09/26 13:05:21 | 000,065,024 | —- | C] () – C:\Windows\System32\JPEGACC.DLL
[2009/09/26 13:05:20 | 000,068,096 | —- | C] () – C:\Windows\System32\IGFPX32P.DLL
[2009/09/26 13:05:08 | 000,101,376 | —- | C] () – C:\Windows\System32\WELSOF32.DLL
[2008/05/17 21:37:44 | 000,000,008 | —- | C] () – C:\Users\Bishop\AppData\Local\.mpid
[2008/04/19 14:15:10 | 000,003,932 | —- | C] () – C:\Users\Bishop\AppData\Roaming\LMLayout.dat
[2008/04/19 14:11:03 | 000,000,150 | —- | C] () – C:\Windows\System32\LM_SUPPORT.INI
[2008/03/28 07:06:26 | 000,027,136 | —- | C] () – C:\Users\Bishop\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/03/21 22:58:08 | 000,000,028 | —- | C] () – C:\Windows\ODBC.INI
[2008/03/21 22:58:02 | 000,036,864 | R— | C] () – C:\Windows\System32\ODBCSTF.DLL
[2008/03/08 01:25:53 | 000,047,360 | —- | C] () – C:\Windows\System32\drivers\Surroundhp_kern_i386.sys
[2008/03/08 01:25:53 | 000,042,112 | —- | C] () – C:\Windows\System32\drivers\csiidecoder_kern_i386.sys
[2008/03/08 01:25:52 | 000,047,104 | —- | C] () – C:\Windows\System32\drivers\tshd4_kern_i386.sys
[2008/03/08 01:25:52 | 000,039,808 | —- | C] () – C:\Windows\System32\drivers\SRS_SSCFilter_i386.sys
[2008/03/05 15:41:58 | 000,024,840 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys
[2007/03/19 06:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 06:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 06:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 06:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 06:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 06:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 06:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 06:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 06:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 06:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 06:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2008/08/15 16:21:46 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Astraware
[2010/05/21 00:56:14 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Cricket
[2009/11/19 19:43:41 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\LimeWire
[2008/06/28 01:07:40 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Sprite PC Agent
[2008/06/28 01:07:40 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Sprite Setup Wizard
[2008/07/15 21:31:30 | 000,000,000 | —D | M] – C:\Users\Bishop\AppData\Roaming\Sprite Software
[2010/07/30 04:12:57 | 000,032,614 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/19 03:45:45 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/11/10 09:22:24 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2010/09/01 05:28:49 | 000,012,143 | —- | M] () – C:\ComboFix.txt
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/08/31 20:49:55 | 000,064,331 | —- | M] () – C:\CybDefInstallInfo.log
[2007/11/21 22:51:47 | 000,004,722 | RH– | M] () – C:\dell.sdr
[2009/11/09 21:28:03 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2009/11/09 21:28:03 | 000,005,120 | -H– | M] () – C:\ntuser.dat.LOG1
[2009/11/09 21:28:02 | 000,000,000 | -H– | M] () – C:\ntuser.dat.LOG2
[2009/11/09 21:28:03 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{8ac1b226-cc7f-11de-aab5-001aa073dc0a}.TM.blf
[2009/11/09 21:28:03 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{8ac1b226-cc7f-11de-aab5-001aa073dc0a}.TMContainer00000000000000000001.regtrans-ms
[2009/11/09 21:28:03 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{8ac1b226-cc7f-11de-aab5-001aa073dc0a}.TMContainer00000000000000000002.regtrans-ms
[2009/11/09 21:28:03 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{8ac1b22a-cc7f-11de-aab5-001aa073dc0a}.TM.blf
[2009/11/09 21:28:03 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{8ac1b22a-cc7f-11de-aab5-001aa073dc0a}.TMContainer00000000000000000001.regtrans-ms
[2009/11/09 21:28:03 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{8ac1b22a-cc7f-11de-aab5-001aa073dc0a}.TMContainer00000000000000000002.regtrans-ms
[2010/09/01 17:45:28 | 2392,596,480 | -HS- | M] () – C:\pagefile.sys
[2007/11/21 15:26:37 | 000,000,071 | —- | M] () – C:\SystemInfo.ini
[2008/08/15 16:23:18 | 000,000,192 | —- | M] () – C:\WMProDesktop.log
< %systemroot%\Fonts\*.com >
[2006/11/02 08:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 08:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/10/22 01:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNMPD97.DLL
[2007/10/22 01:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNMPP97.DLL
[2006/11/02 08:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2002/09/05 10:07:32 | 000,176,128 | —- | M] (DeviceGuys) – C:\Windows\System32\spool\prtprocs\w32x86\LMPriNT.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2001/02/20 14:30:00 | 000,046,592 | —- | M] (Black Ice Software) – C:\Windows\System32\spool\prtprocs\w32x86\Ppbiproc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/06/14 20:19:36 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 06:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 06:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 06:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/11/20 14:56:59 | 000,000,286 | -HS- | M] () – C:\Users\Bishop\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/09/01 19:10:34 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Bishop\Desktop\HijackThis.exe
[2010/09/01 19:09:30 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Bishop\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-01 09:49:19
========== Alternate Data Streams ==========
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:74B502CB
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:B623B5B8
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:73933431
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:2BDCFAD6
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:7C60A173
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:8BB2EC84
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:C228601A
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:54:44 PM, on 9/1/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Safe mode
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\notepad.exe
C:\Users\Bishop\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - HKCU\..\Run: [Exetender] "C:\Program Files\Free Ride Games\GPlayer.exe /runonstartup"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] E:\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:\Program Files\ScanSoft\PaperPort\Config\Ereg\REMIND32.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Sprint Con App Svc (CASprint) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 5686 bytes
DDS (Ver_10-03-17.01) - NTFSx86 MINIMAL
Run by [removed] at 20:55:05.91 on Wed 09/01/2010
Internet Explorer: 8.0.6001.18928 BrowserJavaVersion: 1.6.0_15
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1982.1026 [GMT -4:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\notepad.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Bishop\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [PPWebCap] c:\progra~1\scansoft\paperp~1\PPWebCap.exe
uRun: [SRS Audio Sandbox] "c:\program files\srs labs\audio sandbox\SRSSSC.exe" /hideme
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9
uRun: [Exetender] "c:\program files\free ride games\GPlayer.exe /runonstartup"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SUPERAntiSpyware] e:\superantispyware\SUPERAntiSpyware.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [SpiralFrog] c:\program files\spiralfrog\Spiralfrog.exe
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\bishop\appdata\roaming\micros~1\windows\startm~1\programs\startup\remind~1.lnk - c:\program files\scansoft\paperport\config\ereg\REMIND32.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\bishop\appdata\roaming\mozilla\firefox\profiles\m8ejpczk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - PureDef Music
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1320680&SearchSource;=13
FF - prefs.js: keyword.URL - hxxp://results.myway.com/dft_redir.jhtml?id=YD&ptb;=13C4B1C4-3805-4024-9B90-528DDDE8D3E4&psa;=&ind;=2009121314&ptnrS;=YD&si;=&st;=kwd&n;=&searchfor;=
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\mozilla firefox\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll
FF - component: c:\program files\mozilla firefox\extensions\{f92a9fe4-2850-4198-b9d5-279880e49b16}\components\FFExternalAlert.dll
FF - plugin: c:\program files\free ride games\npExentCtl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPp3Stub.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20080314.001\IDSvix86.sys [2008-3-14 261680]
S2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [2009-9-26 23200]
S2 X4HS32Ex;X4HS32Ex;c:\program files\free ride games\X4HS32Ex.sys [2009-11-10 53280]
S3 ATMFBUS;A600 USB Composite Device Driver;c:\windows\system32\drivers\ATMFBUS.sys [2010-5-20 47360]
S3 ATMFCVsp;A600 Cricket CM Port;c:\windows\system32\drivers\ATMFCVsp.sys [2010-5-20 153600]
S3 ATMFFLT;A600 USB Modem Installation CD;c:\windows\system32\drivers\ATMFFLT.sys [2010-5-20 13312]
S3 ATMFMdm;A600 Cricket EVDO Modem;c:\windows\system32\drivers\ATMFMdm.sys [2010-5-20 153472]
S3 ATMFNET;A600 Cricket EVDO Network Adapter;c:\windows\system32\drivers\ATMFNET.sys [2010-5-20 103424]
S3 ATMFNVsp;A600 Cricket NMEA Port Serial Port;c:\windows\system32\drivers\ATMFNVsp.sys [2010-5-20 153600]
S3 ATMFVsp;A600 Cricket Diagnostics Port;c:\windows\system32\drivers\ATMFVsp.sys [2010-5-20 153472]
S3 CASprint;Sprint Con App Svc;c:\program files\sprint\sprint smartview\ConAppsSvc.exe [2008-6-19 124184]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-11-21 30192]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-6-19 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-6-19 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2008-6-19 23680]
S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2008-2-14 1251720]
S3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2007-10-30 37936]
=============== Created Last 30 ================
2010-09-01 09:53:21 0 d—–w- c:\program files\ESET
2010-09-01 09:50:16 0 d—–w- c:\users\bishop\appdata\roaming\SUPERAntiSpyware.com
2010-09-01 09:50:16 0 d—–w- c:\programdata\SUPERAntiSpyware.com
2010-09-01 09:28:27 0 d-sh–w- C:\$RECYCLE.BIN
2010-09-01 09:16:54 98816 —-a-w- c:\windows\sed.exe
2010-09-01 09:16:54 77312 —-a-w- c:\windows\MBR.exe
2010-09-01 09:16:54 256512 —-a-w- c:\windows\PEV.exe
2010-09-01 09:16:54 161792 —-a-w- c:\windows\SWREG.exe
2010-09-01 00:33:59 0 —-a-w- c:\users\bishop\defogger_reenable
==================== Find3M ====================
2010-07-07 07:01:57 51200 —-a-w- c:\windows\inf\infpub.dat
2010-07-07 07:01:57 143360 —-a-w- c:\windows\inf\infstrng.dat
2010-07-07 07:01:56 86016 —-a-w- c:\windows\inf\infstor.dat
2008-06-15 00:19:36 174 –sha-w- c:\program files\desktop.ini
2008-06-15 00:01:17 665600 —-a-w- c:\windows\inf\drvindex.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2001-09-10 12:10:36 61440 —-a-w- c:\windows\inf\i386\onetUSD.dll
1998-05-12 08:01:00 8944 —-a-w- c:\windows\inf\i386\usbscan.sys
2010-01-16 21:40:06 245760 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-11-17 02:52:39 245760 –sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2007-11-22 02:51:19 8192 –sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 20:55:17.94 ===============