This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trouble running/updating anti-malware, computer always on

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. Thanks in advance.

Computer seems to be slower, also having standby and hibernating issues, whereas it's always on. Other than that, it's running "fine," except I noticed today that MBAM and Adaware would not update. Strange because I can't trace where I may have gotten infected. Let me know how it looks.

OTL results:

OTL logfile created on: 9/23/2010 1:32:31 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Shrews\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): F:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.51 Gb Total Space | 5.36 Gb Free Space | 36.97% Space Free | Partition Type: NTFS
Drive D: | 6.55 Gb Total Space | 1.72 Gb Free Space | 26.32% Space Free | Partition Type: NTFS
Drive E: | 6.04 Gb Total Space | 1.44 Gb Free Space | 23.77% Space Free | Partition Type: NTFS
Drive F: | 82.11 Gb Total Space | 53.13 Gb Free Space | 64.70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GBS-LAPTOP
Current User Name: Shrews
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Shrews\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Internet\avg\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - D:\Internet\java\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - D:\Internet\Safari\Safari.exe (Apple Inc.)
PRC - D:\Internet\avg\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Internet\avg\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\System\blckarmorbackup\TimounterMonitor.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\BlackArmorBackup\BlackArmorBackupNotify.exe (Seagate)
PRC - D:\System\blckarmorbackup\BlackArmorBackupMonitor.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\BlackArmorBackup\BlackArmorBackupService.exe (Seagate)
PRC - D:\Internet\xampp\mysql\bin\mysqld.exe ()
PRC - D:\Internet\xampp\apache\bin\httpd.exe (Apache Software Foundation)
PRC - D:\Internet\adaware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe (Mediafour Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe (Mediafour Corporation)
PRC - D:\Text\Acrobat_6_prof\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\system32\WISPTIS.EXE (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Shrews\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (JavaQuickStarterService) – D:\Internet\java\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg8wd) – D:\Internet\avg\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Norton Ghost) – D:\System\Norton\Agent\VProSvc.exe (Symantec Corporation)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (SgtSch2Svc) – C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Seagate)
SRV - (MySQL) – D:\Internet\xampp\mysql\bin\mysqld.exe ()
SRV - (Apache2.2) – D:\Internet\xampp\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (aawservice) – D:\Internet\adaware\aawservice.exe (Lavasoft)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\logishrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LicCtrlService) – C:\WINDOWS\mmfs.DLL ()
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (hnmsvc) – C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
SRV - (MacDriveService) – C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe (Mediafour Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (UIUSys) – C:\WINDOWS\System32\DRIVERS\UIUSYS.SYS File not found
DRV - (srescan) – C:\WINDOWS\System32\ZoneLabs\srescan.sys File not found
DRV - (catchme) – C:\DOCUME~1\Shrews\LOCALS~1\Temp\catchme.sys File not found
DRV - (tdrpman174) Acronis Try&Decide; and Restore Points filter (build 174) – C:\WINDOWS\system32\DRIVERS\tdrpm174.sys (Acronis)
DRV - (truecrypt) – C:\WINDOWS\system32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (oreans32) – C:\WINDOWS\system32\drivers\oreans32.sys ()
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman380) Acronis Snapshots Manager (Build 380) – C:\WINDOWS\system32\DRIVERS\snman380.sys (Acronis)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (VClone) – C:\WINDOWS\system32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PTDUWWAN) – C:\WINDOWS\system32\drivers\PTDUWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDUVsp) – C:\WINDOWS\system32\drivers\PTDUVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDUMdm) – C:\WINDOWS\system32\drivers\PTDUMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDUBus) – C:\WINDOWS\system32\drivers\PTDUBus.sys (DEVGURU Co,LTD.)
DRV - (PID_0928) Logitech QuickCam Express(PID_0928) – C:\WINDOWS\system32\drivers\LV561AV.SYS (Logitech Inc.)
DRV - (LVcKap) – C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.)
DRV - (LVMVDrv) – C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (MDFSYSNT) – C:\WINDOWS\System32\drivers\MDFSYSNT.SYS (Mediafour Corporation)
DRV - (datunidr) – C:\WINDOWS\system32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\WINDOWS\system32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\WINDOWS\system32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\WINDOWS\system32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (MDPMGRNT) – C:\WINDOWS\System32\drivers\MDPMGRNT.sys (Mediafour Corporation)
DRV - (Packet) – C:\WINDOWS\system32\drivers\packet.sys (SingleClick Systems)
DRV - (DXEC02) – C:\WINDOWS\system32\drivers\dxec02.sys (Knowles Acoustics)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (pnetmdm) – C:\WINDOWS\system32\drivers\pnetmdm.sys (June Fabrics Technology)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (SymSnap) – C:\WINDOWS\System32\drivers\SymSnap.sys (StorageCraft)
DRV - (V2IMount) – C:\WINDOWS\System32\drivers\V2iMount.sys (Symantec Corporation)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (61883) – C:\WINDOWS\system32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) – C:\WINDOWS\system32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) – C:\WINDOWS\system32\drivers\msdv.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Imagedrv) – C:\WINDOWS\system32\DRIVERS\imagedrv.sys (Ahead Software AG and its licensors)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (ENUM1394) – C:\WINDOWS\system32\drivers\enum1394.sys (Microsoft Corporation)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0071211
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0071211

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0071211
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.newperspectivefilms.com/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.5.4
FF - prefs.js..extensions.enabledItems: [removed]:1.3.4
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {9458ca25-39fd-4ba8-9520-acc5c0d877b6}:1.6
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: [removed]:3.8.6
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.2
FF - prefs.js..extensions.enabledItems: {b749fc7c-e949-447f-926c-3f4eed6accfe}:0.6.6

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: D:\Internet\avg\Firefox [2009/12/22 10:56:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2009/11/09 23:03:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: D:\Internet\java\lib\deploy\jqs\ff [2009/11/09 21:43:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: D:\Internet\Mozilla_Firefox\components [2010/07/31 12:50:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: D:\Internet\Mozilla_Firefox\plugins [2010/08/28 20:55:26 | 000,000,000 | —D | M]

[2010/04/28 23:42:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Extensions
[2010/04/28 23:42:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Extensions\[removed]
[2010/09/16 11:33:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions
[2010/07/17 16:19:16 | 000,000,000 | —D | M] (OPML Support) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{9458ca25-39fd-4ba8-9520-acc5c0d877b6}
[2010/05/22 17:23:06 | 000,000,000 | —D | M] (Modify Headers) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}
[2009/07/01 00:33:46 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/04/14 01:42:03 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/05/22 16:07:35 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2010/05/18 19:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\[removed]
[2010/08/28 20:47:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\[removed]

O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Internet\avg\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Text\Acrobat_6_prof\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Internet\java\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll (Google Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Internet\java\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (ZoneAlarm Spy Blocker BHO) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Text\Acrobat_6_prof\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O4 - HKLM..\Run: [{B179023B-6238-4499-8F26-CD73E9D90E0A}] C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe (Mediafour Corporation)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] D:\System\blckarmorbackup\TimounterMonitor.exe (Seagate)
O4 - HKLM..\Run: [AVG8_TRAY] D:\Internet\avg\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BlackArmorBackupMonitor.exe] D:\System\blckarmorbackup\BlackArmorBackupMonitor.exe (Seagate)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Seagate Scheduler2 Service] C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] D:\Internet\ZoneAlarm\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [EPSON Artisan 50 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFFA.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10i_Plugin.exe (Adobe Systems, Inc.)
O4 - HKLM..\RunServices: [LicCtrl] C:\WINDOWS\mmfs.DLL ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all with Free Download Manager - D:\Internet\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - D:\Internet\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - D:\Internet\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - D:\Internet\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - D:\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll (Google Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Internet\avg\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Shrews\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Shrews\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{1c0c5865-2184-11df-a86e-001d09ad8627}\Shell\AutoRun\command - "" = G:\Setup.exe – File not found
O33 - MountPoints2\{1c0c5865-2184-11df-a86e-001d09ad8627}\Shell\Install\command - "" = G:\Setup.exe – File not found
O33 - MountPoints2\{4e66e8fb-39bc-11df-a877-001d09ad8627}\Shell\AutoRun\command - "" = H:\MI.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.dfscacm - C:\WINDOWS\System32\dfscacm.dll ()
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.dfsc - C:\WINDOWS\System32\dfsc.dll ()
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: vidc.hdyc - D:\video\blackmagic codecs\BMDCodecLib.dll (Blackmagic Design)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.MP42 - C:\WINDOWS\System32\MPG4C32.DLL (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\WINDOWS\System32\MPG4C32.DLL (Microsoft Corporation)
Drivers32: vidc.r210 - D:\video\blackmagic codecs\BMDCodecLib.dll (Blackmagic Design)
Drivers32: vidc.v210 - D:\video\blackmagic codecs\BMDCodecLib.dll (Blackmagic Design)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/23 13:31:33 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Shrews\Desktop\OTL.exe
[2010/08/30 00:49:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Shrews\Desktop\logos
[2010/08/30 00:13:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Shrews\Local Settings\Application Data\Sony
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/23 13:31:34 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shrews\Desktop\OTL.exe
[2010/09/23 13:10:10 | 016,252,928 | —- | M] () – C:\Documents and Settings\Shrews\ntuser.dat
[2010/09/23 13:06:31 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/23 11:42:39 | 065,173,360 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/09/21 09:49:17 | 000,528,020 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/21 09:49:17 | 000,445,938 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/21 09:49:17 | 000,072,978 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/20 15:40:43 | 000,721,675 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\Common_Gain_Stage.pdf
[2010/09/17 13:59:07 | 000,000,004 | —- | M] () – C:\WINDOWS\Twain001.Mtx
[2010/09/17 13:59:03 | 000,000,156 | —- | M] () – C:\WINDOWS\Twunk001.MTX
[2010/09/17 13:33:11 | 000,000,256 | —- | M] () – C:\WINDOWS\System32\pool.bin
[2010/09/17 13:00:05 | 002,285,676 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\teesandtapes.pdf
[2010/09/15 21:51:32 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/15 21:51:00 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/15 21:50:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/15 21:50:36 | 2137,038,848 | -HS- | M] () – C:\hiberfil.sys
[2010/09/15 21:49:50 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Shrews\ntuser.ini
[2010/09/15 15:05:49 | 001,749,464 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/15 12:44:34 | 000,103,392 | —- | M] () – C:\Documents and Settings\Shrews\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/10 05:28:52 | 000,078,668 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/09/06 23:34:30 | 000,003,584 | —- | M] () – C:\Documents and Settings\Shrews\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/01 00:24:12 | 000,019,968 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\Blog.doc
[2010/08/28 21:22:04 | 000,000,202 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/28 18:08:16 | 000,140,752 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\GBS.pdf
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/23 13:28:34 | 000,721,675 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\Common_Gain_Stage.pdf
[2010/09/17 13:00:04 | 002,285,676 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\teesandtapes.pdf
[2010/09/15 21:50:36 | 2137,038,848 | -HS- | C] () – C:\hiberfil.sys
[2010/09/01 00:24:11 | 000,019,968 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\Blog.doc
[2010/08/28 18:08:15 | 000,140,752 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\GBS.pdf
[2010/08/15 15:43:30 | 000,003,584 | —- | C] () – C:\Documents and Settings\Shrews\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/10 13:59:30 | 000,025,713 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2010/07/23 11:47:22 | 000,024,287 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4C49C79A.zip
[2010/07/09 12:52:52 | 000,021,188 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4C3761F3.zip
[2010/07/02 16:55:16 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/07/02 16:52:17 | 000,000,025 | —- | C] () – C:\WINDOWS\EPART50.ini
[2010/06/24 20:19:02 | 002,463,976 | —- | C] () – C:\WINDOWS\System32\NPSWF32.dll
[2010/05/29 16:27:29 | 000,000,945 | —- | C] () – C:\WINDOWS\vista32.ini
[2010/05/29 16:01:08 | 000,000,118 | —- | C] () – C:\WINDOWS\ppdrv.ini
[2010/05/29 15:51:10 | 000,079,360 | —- | C] () – C:\WINDOWS\u1200_32.dll
[2010/05/29 15:51:10 | 000,006,932 | —- | C] () – C:\WINDOWS\System32\glscan.sys
[2010/05/29 15:51:09 | 000,030,208 | —- | C] () – C:\WINDOWS\uxmail32.dll
[2010/05/29 15:51:08 | 000,068,608 | —- | C] () – C:\WINDOWS\vufile32.dll
[2010/05/29 15:51:07 | 000,076,260 | —- | C] () – C:\WINDOWS\System32\drivers\udnt.sys
[2010/05/06 11:44:14 | 000,023,333 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4BE2F1DE.zip
[2010/05/05 13:44:21 | 000,020,017 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4BE1BC85.zip
[2010/04/18 12:14:54 | 000,033,824 | —- | C] () – C:\WINDOWS\System32\drivers\oreans32.sys
[2009/09/08 17:10:57 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\clauth2.dll
[2009/09/08 17:10:57 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\clauth1.dll
[2009/09/08 17:10:56 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2009/06/03 18:40:58 | 000,175,104 | —- | C] () – C:\WINDOWS\System32\RemoteControl.dll
[2009/04/09 21:23:03 | 000,000,347 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/03/30 15:41:48 | 000,000,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/03/03 13:38:58 | 000,027,211 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\Personal Address Book.ADR
[2008/10/20 23:16:02 | 000,796,048 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2008/10/20 21:55:13 | 000,036,483 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\Comma Separated Values (Windows).ADR
[2008/10/20 21:55:13 | 000,000,020 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\Final Draft Tagger Preferences
[2008/10/18 01:16:00 | 000,000,012 | —- | C] () – C:\WINDOWS\pol32.ini
[2008/10/15 16:26:22 | 000,009,728 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2008/07/04 12:51:57 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2008/06/28 17:32:09 | 000,408,576 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2008/06/28 17:32:04 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2008/06/28 15:08:13 | 000,027,648 | -HS- | C] () – C:\WINDOWS\System32\Smab0.dll
[2008/04/17 00:41:55 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2008/04/10 16:55:37 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/04/10 16:45:21 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2008/03/23 21:51:05 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/02/20 00:55:30 | 000,000,202 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/01/20 14:12:49 | 000,000,026 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.119889580931711767808769176
[2008/01/20 14:10:06 | 000,000,021 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.24554863501262644635642126105
[2008/01/09 19:02:39 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/01/09 19:02:38 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/12/29 00:10:34 | 000,039,424 | —- | C] () – C:\WINDOWS\mmfs.dll
[2007/12/28 19:52:38 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/12/27 20:40:18 | 000,013,840 | —- | C] () – C:\WINDOWS\System32\wnaspi32.dll
[2007/12/27 20:37:04 | 003,870,720 | —- | C] () – C:\WINDOWS\System32\qt-mt323.dll
[2007/12/11 14:40:40 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/12/11 14:32:59 | 000,000,859 | —- | C] () – C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2007/12/11 14:31:06 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/12/11 14:30:39 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2007/12/11 14:30:39 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/12/11 14:22:53 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2007/12/11 14:22:51 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2007/12/11 13:59:38 | 000,910,304 | —- | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2007/12/11 13:59:38 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4831.dll
[2007/12/11 13:59:36 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2007/12/11 13:57:48 | 000,001,118 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/11/29 17:30:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/11/29 17:28:24 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2007/11/29 17:28:24 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2007/11/28 16:52:32 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/10/12 02:11:58 | 000,066,482 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007/10/11 19:59:24 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2006/11/07 05:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/17 00:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/07/08 23:07:46 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\dfscacm.dll
[2005/07/08 23:07:44 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\dfsc.dll
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/01/07 10:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1999/01/27 14:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2010/02/27 14:49:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2010/07/02 17:18:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2008/01/20 14:10:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Final Draft
[2009/01/16 08:54:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
[2007/12/28 01:21:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/06/28 15:21:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Mediafour
[2009/09/08 17:10:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Minnetonka Audio Software
[2010/05/04 14:46:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/02/27 15:11:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2007/12/11 14:33:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SingleClick Systems
[2008/04/17 00:42:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2008/09/03 18:24:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2007/12/11 14:37:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/05/18 23:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sync App Settings
[2010/04/09 16:44:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/18 21:04:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TrueCrypt
[2009/05/30 21:05:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2008/10/20 21:56:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Alien Skin
[2010/08/07 18:26:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\AMPSoft
[2009/06/15 00:47:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Artisteer
[2010/05/13 21:33:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Blackberry Desktop
[2010/09/17 12:49:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Canon
[2009/06/13 13:58:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\ctpo
[2009/06/13 13:58:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\engadven
[2008/10/20 21:56:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Final Draft
[2008/10/20 21:56:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Flickr
[2009/11/15 00:33:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Foxit
[2010/02/25 14:43:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Foxit Software
[2009/08/05 10:07:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Free Download Manager
[2008/12/09 01:45:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Leadertech
[2009/05/18 20:45:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\LEAPS
[2009/05/24 15:56:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\MPEG Streamclip
[2009/03/03 01:00:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\NeoDownloader
[2008/10/20 21:55:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Opera
[2009/11/06 01:26:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Pamela
[2009/05/18 20:11:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Pegasys Inc
[2008/10/20 21:55:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Publish Providers
[2010/05/14 00:29:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Research In Motion
[2010/02/27 15:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Seagate
[2009/02/06 13:54:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Smith Micro
[2008/10/20 21:55:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Sony
[2008/10/20 21:55:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Sony Setup
[2010/05/18 23:07:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Sync App Settings
[2008/10/20 21:55:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Thunderbird
[2010/05/19 00:29:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\TrueCrypt
[2010/08/28 20:33:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\uTorrent
[2008/10/20 21:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\W Photo Studio Viewer

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/12/31 14:07:07 | 000,000,000 | —- | M] () – C:\asoutput.log
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/11/08 01:33:37 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/05/21 11:20:12 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/11/09 15:48:54 | 000,015,036 | —- | M] () – C:\ComboFix.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/12/11 14:02:42 | 000,006,843 | RH– | M] () – C:\dell.sdr
[2010/09/15 21:50:36 | 2137,038,848 | -HS- | M] () – C:\hiberfil.sys
[2007/12/27 18:57:09 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009/12/09 21:41:38 | 000,006,508 | —- | M] () – C:\JavaRa.log
[2006/05/05 13:47:34 | 000,090,792 | —- | M] () – C:\keyfingers.jpg
[2008/04/03 00:43:27 | 000,023,224 | —- | M] () – C:\keyfingers_dell.jpg
[2009/05/09 14:31:09 | 000,300,751 | —- | M] () – C:\log_fs.log
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 06:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2009/04/04 17:48:40 | 000,001,760 | —- | M] () – C:\Rescued document 1.txt
[2009/04/04 17:48:34 | 000,002,741 | —- | M] () – C:\Rescued document.txt
[2009/11/06 12:00:26 | 000,007,196 | —- | M] () – C:\RootRepeal report 11-06-09 (12-00-26).txt
[2010/04/14 00:41:39 | 000,004,096 | -HS- | M] () – C:\VSNAP.IDX
[2008/04/09 18:38:22 | 000,000,252 | —- | M] () – C:\VundoFix.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 14:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/03/28 13:57:34 | 000,274,944 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5ha.dll
[2003/06/18 16:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >
[2007/05/17 21:32:50 | 000,326,742 | —- | M] () – C:\WINDOWS\Vostro_NB_1280x864_01.jpg
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 13:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 13:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2004/08/10 14:04:12 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/12/25 14:04:38 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Shrews\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 14:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Shrews\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/09/23 13:31:34 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shrews\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-26 16:43:20

========== Alternate Data Streams ==========

@Alternate Data Stream - 60 bytes -> C:\WINDOWS\System32\ssprs.tgz:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\WINDOWS\System32\lsprst7.tgz:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Shrews\Desktop\ROLEX AWARDS.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Shrews\Desktop\cool_money.txt:AFP_AfpInfo
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
< End of report >

OTL Extras logfile created on: 9/23/2010 1:32:31 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Shrews\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): F:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.51 Gb Total Space | 5.36 Gb Free Space | 36.97% Space Free | Partition Type: NTFS
Drive D: | 6.55 Gb Total Space | 1.72 Gb Free Space | 26.32% Space Free | Partition Type: NTFS
Drive E: | 6.04 Gb Total Space | 1.44 Gb Free Space | 23.77% Space Free | Partition Type: NTFS
Drive F: | 82.11 Gb Total Space | 53.13 Gb Free Space | 64.70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GBS-LAPTOP
Current User Name: Shrews
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Internet\Mozilla_Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Internet\Mozilla_Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
https [open] – "D:\Internet\Mozilla_Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
jsfile – "D:\graphics\dreamweaver\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"10421:UDP" = 10421:UDP:*:Enabled:SingleClick Discovery Protocol
"10426:UDP" = 10426:UDP:*:Enabled:SingleClick ICC
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network Assistant – (SingleClick Systems)
"C:\Program Files\Dell\MediaDirect\PCMService.exe" = C:\Program Files\Dell\MediaDirect\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program – (CyberLink Corp.)
"D:\Internet\avg\avgupd.exe" = D:\Internet\avg\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"D:\Internet\utorrent\uTorrent.exe" = D:\Internet\utorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – File not found
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon – (Check Point Software Technologies LTD)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}" = Sony Noise Reduction Plug-In 2.0h
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{0D2E80C8-0875-43EB-9623-47118E2DFBCA}" = Quicken 2007
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{190D0C6E-C8A7-4019-8FB5-FD041EC1F2D2}" = Mobile Broadband Drivers
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 18
"{26D77DBB-E7BF-4B2F-8C02-E731F2E224C0}_is1" = JoomlaPack Native Tools 2009.3
"{2715D1D6-2B81-4DD5-A9DC-6EFF4D5E0993}" = Ahead Nero Burning Rom PlugIn Pack 2.0.2 by MadHacker2k4
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{31228E31-2BFF-11D2-8866-00805F0D9D40}" = QPST
"{32F720F5-2D0D-4245-A2B0-9EB3CECF8101}" = Norton Ghost 10.0
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40A594D0-1490-4979-9382-D2B764F949C6}" = BlackBerry® Media Sync
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AEA9A23-D627-4699-8A0F-FC474308C2E6}" = Sony Sound Forge 9.0
"{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}" = Macromedia Fireworks 8
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{5BACA8C1-909F-4AA4-90EB-6CAE5241FA96}" = MacDrive 7
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{78D62D17-D970-42DA-B8CF-5E5576293B33}" = Final Draft 7
"{7B4174E8-FE92-4269-808A-3B8D116D9538}" = Advanced Security for Outlook
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C9AD221-994C-45B2-B46D-26F5735158CF}" = Sony Vegas Pro 8.0
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{885A63EA-382B-4DD4-A755-14809B8557D6}" = Macromedia Flash Player 8
"{88908767-B7AD-4b0d-ACBC-FBCCF2761D31}" = HP Photosmart All-In-One Software 9.0
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8D55AC33-2CB4-4A4D-93A9-F5C76124BBC3}" = BlackBerry Device Software v5.0.0 for the BlackBerry 8530 smartphone
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}" = Logitech QuickCam
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9DF6EC22-733E-4EDC-AC88-54CAD4BF4E7B}" = BlackArmor Backup
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A14F7508-B784-40B8-B11A-E0E2EEB7229F}" = Adobe Premiere Pro 1.5
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BC2FE771-EDBE-3087-A676-2B6C45A2BF7E}" = Google Gears
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C13AF9C7-8E06-4354-B629-DF6192CE4A66}" = PANTECH UM175 Driver
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}" = WinZip 12.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D16A31F9-276D-4968-A753-FFEAC56995D0}" = Epson Print CD
"{D1B5E9C8-4CCF-44E3-87D6-7C00D7DA5370}" = IntelliSonic Speech Enhancement
"{D26F7C78-E2D7-49AB-8E64-53CB8AE99074}" = XDCAM EX Clip Browser
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E28750A2-45F2-4b63-99F7-9F81A94B1E2D}" = PS_AIO_Software_min
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E76CDDCE-EFC0-4FE5-9972-9489CE49AA55}_is1" = NeoDownloader 2.2
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{ED80F174-B621-4B8F-BBB9-3E031A59555A}" = TMPGEnc 4.0 XPress
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F5A6583A-3051-45ED-BE87-10CF079CB6B4}" = Blackmagic Codecs
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.6
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"7-Zip" = 7-Zip 4.65
"ABC Amber vCard Converter" = ABC Amber vCard Converter
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Allway Sync_is1" = Allway Sync version 10.3.8
"AMP Font Viewer" = AMP Font Viewer
"AnyDVD" = AnyDVD
"AVG8Uninstall" = AVG Free 8.5
"BBE Sonic Maximizer Plugin" = BBE Sonic Maximizer Plugin
"BlackBerry_{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"Blow Up" = Alien Skin Blow Up
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"DebugMode FrameServer" = DebugMode FrameServer
"Easy Duplicate Finder_is1" = Easy Duplicate Finder v. 2.2.1
"EPSON Artisan 50 Series" = EPSON Artisan 50 Series Printer Uninstall
"EPSON Printer and Utilities" = EPSON Printer Software
"ERUNT_is1" = ERUNT 1.1j
"Exposure 2" = Alien Skin Exposure 2
"FileZilla" = FileZilla (remove only)
"Flickr Uploadr" = Flickr Uploadr 3.0.5
"Foxit PDF Editor" = Foxit PDF Editor
"Foxit Reader" = Foxit Reader
"Free Download Manager_is1" = Free Download Manager 3.0
"FriendBlasterPro_is1" = FriendBlasterPro
"HardlinkShellExt" = Link Shell Extension
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie7" = Windows Internet Explorer 7
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"IrfanView" = IrfanView (remove only)
"LiveReg" = LiveReg (Symantec Corporation)
"lvdrivers_11.50" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Moleskinsoft Clone Remover 3.8_is1" = Moleskinsoft Clone Remover 3.8
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NeroVision!UninstallKey" = Nero Digital
"Pamela" = Pamela Pro 4.5
"PandoraSaver (standalone)_is1" = PandoraSaver 1.008e (standalone)
"PdaNet_is1" = PdaNet for BlackBerry 1.30
"Picasa 3" = Picasa 3
"SpywareBlaster_is1" = SpywareBlaster 4.2
"SUPER ©" = SUPER © Version 2008.bld.30 (Mar 22, 2008)
"SynTPDeinstKey" = Dell Touchpad
"The Rosetta Stone" = The Rosetta Stone
"TrueCrypt" = TrueCrypt
"Tweak UI 2.10" = Tweak UI
"VirtualCloneDrive" = VirtualCloneDrive
"Web Album Maker" = Web Album Maker 2.20
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"xampp" = XAMPP 1.7.1
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Xvid_is1" = Xvid 1.1.3 final uninstall
"ZoneAlarm" = ZoneAlarm
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/22/2010 11:47:10 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =

Error - 9/23/2010 12:06:30 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =

Error - 9/23/2010 12:47:09 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =

Error - 9/23/2010 1:06:29 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =

Error - 9/23/2010 1:47:09 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =

Error - 9/23/2010 2:06:28 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =

Error - 9/23/2010 12:40:47 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =

Error - 9/23/2010 1:06:35 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =

Error - 9/23/2010 1:43:44 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =

Error - 9/23/2010 2:06:30 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 9/15/2010 7:04:49 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 9/15/2010 7:05:26 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 9/15/2010 7:06:18 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 9/15/2010 7:06:27 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 9/15/2010 7:06:27 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 9/15/2010 10:49:48 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 9/15/2010 10:52:30 PM | Computer Name = GBS-LAPTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LicCtrl Service service
to connect.

Error - 9/15/2010 10:52:30 PM | Computer Name = GBS-LAPTOP | Source = Service Control Manager | ID = 7000
Description = The LicCtrl Service service failed to start due to the following error:
%%1053

Error - 9/20/2010 2:33:48 AM | Computer Name = GBS-LAPTOP | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.105 on
the Network Card with network address 001E8C317C52.

Error - 9/22/2010 3:43:41 PM | Computer Name = GBS-LAPTOP | Source = ipnathlp | ID = 32003
Description = The Network Address Translator (NAT) was unable to request an operation
of
the kernel-mode translation module. This may indicate misconfiguration, insufficient
resources, or an internal error. The data is the error code.


< End of report >
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
I was not given a "Firefox" option in ATM; it was grayed out. Ran as instructed under "Main" tab. Updated MBAM prior to running. Computer seems to be working okay. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4729 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 10/1/2010 4:40:28 PM mbam-log-2010-10-01 (16-40-28).txt Scan type: Quick scan Objects scanned: 149589 Time elapsed: 8 minute(s), 10 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected)
We can have a look with Combofix


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
computer seems to be behaving well…

ComboFix 10-10-01.07 - Shrews 10/02/2010 22:34:43.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2038.1303 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((( Files Created from 2010-09-03 to 2010-10-03 )))))))))))))))))))))))))))))))
.

2010-10-01 02:35 . 2010-10-01 02:35 ——– d—–w- c:\documents and settings\Shrews\Application Data\Pavtube
2010-09-30 21:02 . 2010-08-12 12:15 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-09-30 21:02 . 2010-09-30 21:02 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-09-30 20:08 . 2010-09-30 20:08 ——– d—–w- c:\documents and settings\Shrews\Local Settings\Application Data\Sunbelt Software
2010-09-30 20:07 . 2010-09-30 20:07 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-09-30 20:07 . 2010-08-12 12:16 2979848 -c–a-w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe
2010-09-30 20:07 . 2010-09-30 20:07 ——– d—–w- c:\program files\Lavasoft
2010-09-23 18:40 . 2010-09-23 18:40 ——– d—–w- c:\documents and settings\Shrews\Local Settings\Application Data\Temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-01 03:16 . 2007-12-11 19:40 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-30 20:07 . 2008-01-20 19:09 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-09-30 18:41 . 2009-11-10 00:37 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-30 18:34 . 2009-01-05 15:00 10448924 —-a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-09-17 18:33 . 2010-05-04 06:29 256 —-a-w- c:\windows\system32\pool.bin
2010-09-17 17:49 . 2008-10-21 02:56 ——– d—–w- c:\documents and settings\Shrews\Application Data\Canon
2010-09-15 19:21 . 2008-10-21 02:55 ——– d—–w- c:\documents and settings\Shrews\Application Data\Skype
2010-09-15 17:44 . 2010-08-09 04:53 103392 —-a-w- c:\documents and settings\Shrews\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-10 10:28 . 2009-12-13 04:01 78668 —ha-w- c:\windows\system32\mlfcache.dat
2010-08-07 23:26 . 2010-08-07 23:26 ——– d—–w- c:\documents and settings\Shrews\Application Data\AMPSoft
2010-07-23 16:46 . 2010-07-23 16:47 24287 —-a-w- c:\documents and settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4C49C79A.zip
2010-07-23 14:17 . 2007-12-28 06:21 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-07-14 12:52 . 2010-07-14 12:53 2760192 —-a-w- c:\windows\Internet Logs\xDB29.tmp
2010-07-14 12:52 . 2010-07-14 12:53 2597888 —-a-w- c:\windows\Internet Logs\xDB2A.tmp
2010-07-14 04:36 . 2008-07-15 20:59 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-09 17:51 . 2010-07-09 17:52 21188 —-a-w- c:\documents and settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4C3761F3.zip
2008-04-17 05:41 . 2008-04-17 05:38 24 -csh–w- c:\windows\SDA93FE72.tmp
2006-05-03 09:06 . 2008-06-28 20:08 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2008-06-28 20:08 31232 -csh–r- c:\windows\system32\msfDX.dll
2007-12-17 12:43 . 2008-06-28 20:08 27648 -csh–w- c:\windows\system32\Smab0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\HardLinkMenu]
@="{0A479751-02BC-11d3-A855-0004AC2568AA}"
[HKEY_CLASSES_ROOT\CLSID\{0A479751-02BC-11d3-A855-0004AC2568AA}]
2010-05-22 06:16 256200 —-a-w- d:\system\LinkShellExtension\HardlinkShellExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IconOverlayHardLink]
@="{0A479751-02BC-11d3-A855-0004AC2568DD}"
[HKEY_CLASSES_ROOT\CLSID\{0A479751-02BC-11d3-A855-0004AC2568DD}]
2010-05-22 06:16 256200 —-a-w- d:\system\LinkShellExtension\HardlinkShellExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 851968]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-06 138008]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]
"AVG8_TRAY"="d:\internet\avg\avgtray.exe" [2010-07-09 2048352]
"{B179023B-6238-4499-8F26-CD73E9D90E0A}"="c:\program files\Mediafour\MacDrive 7\MacDrive.exe" [2007-07-12 179288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"BlackArmorBackupMonitor.exe"="d:\system\blckarmorbackup\BlackArmorBackupMonitor.exe" [2009-04-15 4352928]
"AcronisTimounterMonitor"="d:\system\blckarmorbackup\TimounterMonitor.exe" [2009-04-15 959672]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-03-15 390600]
"Seagate Scheduler2 Service"="c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe" [2009-04-15 376272]
"ZoneAlarm Client"="d:\internet\ZoneAlarm\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2008-02-01 439568]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
P2 Card Manager.lnk - d:\video\p2driver\Drivers\App\P2TaskTray.exe [2007-3-8 14336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-17 17:30 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Shrews^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Shrews\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2004-12-13 19:30 58992 —-a-w- c:\program files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 11:00 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellAutomatedPCTuneUp]
2007-10-11 15:49 465136 -c–a-w- c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
2008-08-14 00:32 206064 —-a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2007-10-10 00:57 16384 —-a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-06-06 21:30 162584 —-a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2006-10-03 17:35 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2006-10-03 17:37 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KADxMain]
2006-11-02 20:05 282624 —-a-w- c:\windows\system32\KADxMain.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2007-10-25 22:33 563984 -c–a-w- c:\program files\Common Files\logishrd\LComMgr\Communications_Helper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2007-10-25 22:37 2178832 —-a-w- d:\system\webcam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MDGetStarted.exe]
2007-06-13 18:23 139264 —-a-w- c:\program files\Mediafour\MacDrive 7\MDGetStarted.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MorEmoticons]
2007-11-12 02:35 64000 —-a-w- d:\internet\skype\MorEmoticons\Moremoticons.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 16:50 155648 -c–a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 10.0]
2005-09-09 23:09 1537648 —-a-w- d:\system\Norton\Agent\GhostTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2007-04-16 22:10 184320 ——w- c:\program files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-06-06 21:30 138008 —-a-w- c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 06:54 417792 —-a-w- d:\players\quicktime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2006-08-17 15:00 1116920 —-a-w- c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2006-11-05 17:22 221184 —-a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seagate Scheduler2 Service]
2009-04-15 05:32 376272 —-a-w- c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
2009-05-26 22:31 85160 —-a-w- d:\system\VirtualCloneDrive\VCDDaemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Symantec Core LC"=3 (0x3)
"sprtsvc_dellsupportcenter"=2 (0x2)
"Norton Ghost"=2 (0x2)
"gupdate1c93d85b83e6994"=2 (0x2)
"GEARSecurity"=2 (0x2)
"DellAMBrokerService"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"Bonjour Service"=2 (0x2)
"SgtSch2Svc"=2 (0x2)
"RoxWatch9"=3 (0x3)
"RoxMediaDB9"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"d:\\Internet\\avg\\avgupd.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [9/30/2010 4:02 PM 64288]
R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [9/5/2007 3:01 PM 277888]
R0 MDPMGRNT;MDPMGRNT;c:\windows\system32\drivers\MDPMGRNT.sys [2/28/2007 11:15 AM 19072]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/28/2008 12:26 AM 335240]
R1 oreans32;oreans32;c:\windows\system32\drivers\oreans32.sys [4/18/2010 12:14 PM 33824]
R2 Apache2.2;Apache2.2;d:\internet\xampp\apache\bin\httpd.exe [12/9/2008 6:10 PM 24636]
R2 avg8wd;AVG8 WatchDog;d:\internet\avg\avgwdsvc.exe [8/17/2009 12:29 PM 297752]
R2 MacDriveService;MacDriveService;c:\program files\Mediafour\MacDrive 7\MacDriveService.exe [5/1/2007 2:55 PM 143360]
R2 p2csvc;p2csvc;c:\windows\system32\p2csvc.exe -service –> c:\windows\system32\p2csvc.exe -service [?]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\Common Files\Seagate\Schedule2\schedul2.exe [4/15/2009 12:31 AM 617968]
R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [6/13/2010 5:44 PM 9472]
S2 LicCtrlService;LicCtrl Service;rundll32.exe c:\windows\mmfs.dll,Service –> rundll32.exe c:\windows\mmfs.dll,Service [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [8/12/2010 7:15 AM 1356952]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [4/19/2007 12:09 PM 99200]
S3 p2usb;Panasonic P2 Series USB Device;c:\windows\system32\drivers\p2usb.sys [6/1/2010 2:19 PM 22144]
S3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [3/7/2009 6:35 PM 29824]
S3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [3/7/2009 6:35 PM 41344]
S3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [3/7/2009 6:35 PM 39936]
S3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [3/7/2009 6:35 PM 59776]
S4 gupdate1c93d85b83e6994;Google Update Service (gupdate1c93d85b83e6994);c:\program files\Google\Update\GoogleUpdate.exe [11/3/2008 2:26 AM 133104]

— Other Services/Drivers In Memory —

*NewlyCreated* - P2CSVC

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-11-03 07:26]

2010-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-11-03 07:26]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0071211
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all with Free Download Manager - file://d:\internet\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://d:\internet\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://d:\internet\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://d:\internet\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - d:\micros~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.newperspectivefilms.com/
FF - component: d:\internet\avg\Firefox\components\avgssff.dll
FF - component: d:\internet\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - plugin: c:\documents and settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: d:\graphics\Picasa3\npPicasa3.dll
FF - plugin: d:\internet\java\bin\new_plugin\npdeploytk.dll
FF - plugin: d:\internet\java\bin\new_plugin\npjp2.dll
FF - plugin: d:\internet\Mozilla_Firefox\plugins\npCouponPrinter.dll
FF - plugin: d:\internet\Mozilla_Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: d:\internet\Mozilla_Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: d:\internet\Mozilla_Firefox\plugins\NPTURNMED.dll
FF - plugin: d:\internet\Mozilla_Firefox\plugins\NPZoneSB.dll
FF - plugin: d:\players\quicktime\Plugins\npqtplugin.dll
FF - plugin: d:\players\quicktime\Plugins\npqtplugin2.dll
FF - plugin: d:\players\quicktime\Plugins\npqtplugin3.dll
FF - plugin: d:\players\quicktime\Plugins\npqtplugin4.dll
FF - plugin: d:\players\quicktime\Plugins\npqtplugin5.dll
FF - plugin: d:\players\quicktime\Plugins\npqtplugin6.dll
FF - plugin: d:\players\quicktime\Plugins\npqtplugin7.dll
FF - plugin: d:\text\Acrobat_6_prof\Acrobat\browser\nppdf32.dll

—- FIREFOX POLICIES —-
d:\internet\Mozilla_Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
d:\internet\Mozilla_Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
d:\internet\Mozilla_Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-02 22:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:07,4a,74,5f,2f,65,dd,6d,63,27,54,5f,a2,52,1b,6f,cc,f0,99,a5,ff,
22,38,3e,cb,b2,b2,06,f9,5d,e9,d3,3b,18,af,fe,b7,ed,fe,e4,50,a5,e9,cf,b1,0d,\

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:07,4a,74,5f,2f,65,dd,6d,63,27,54,5f,a2,52,1b,6f,cc,f0,99,a5,ff,
22,38,3e,cb,b2,b2,06,f9,5d,e9,d3,3b,18,af,fe,b7,ed,fe,e4,50,a5,e9,cf,b1,0d,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1068)
c:\windows\System32\BCMLogon.dll
c:\windows\system32\igfxdev.dll
.
Completion time: 2010-10-02 22:43:55
ComboFix-quarantined-files.txt 2010-10-03 03:43
ComboFix2.txt 2009-11-09 20:48

Pre-Run: 5,559,201,792 bytes free
Post-Run: 5,563,760,640 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 34E951CFA04F70250CA1AFF18FDE28F5
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

For XP:
  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

For Vista / Windows 7
  • Click START Search
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.


Here's my usual all clean post

To be on the safe side, I would also change all my passwords.

This infection appears to have been cleaned, but as the malware could be configured to run any program a remote attacker requires, it's impossible to be 100% sure that any machine is clean.


Log looks good :D


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

Only run one Anti-Virus and Firewall program.


I would suggest you read:
PC Safety and Security–What Do I Need?.
How to Prevent Malware:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI