This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect Logs (ATFGooredTDS didnt Work)

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ComboFix 10-10-23.02 - Jeremy 10/24/2010 23:31:06.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.633 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2010-09-25 to 2010-10-25 )))))))))))))))))))))))))))))))
.

2010-10-24 23:32 . 2010-10-12 21:59 16856 —-a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2010-10-24 23:32 . 2010-10-12 21:58 719832 —-a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2010-10-09 05:49 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-09 05:49 . 2010-10-09 05:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-10-09 05:49 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-10-08 00:53 . 2010-10-08 00:53 62464 –sha-r- c:\windows\system32\iernonceu.dll
2010-10-05 14:10 . 2010-10-05 14:11 ——– d—–w- c:\documents and settings\Jeremy\Application Data\Research In Motion
2010-10-05 14:10 . 2009-01-09 22:18 27136 —-a-r- c:\windows\system32\drivers\RimSerial.sys
2010-10-05 14:09 . 2010-10-05 14:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Research In Motion
2010-10-05 14:09 . 2010-10-05 14:09 ——– d—–w- c:\program files\Common Files\Research In Motion
2010-10-05 14:09 . 2010-10-05 14:09 ——– d—–w- c:\program files\Research In Motion
2010-10-05 00:24 . 2010-10-05 00:24 ——– d—–w- c:\program files\Common Files\Skype

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-11 17:44 . 2010-08-11 17:44 507904 —-a-r- c:\windows\system32\btwapi.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-10-18_20.16.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-20 08:55 . 2008-03-20 08:55 16384 c:\windows\temp\Perflib_Perfdata_754.dat
- 2004-08-10 18:51 . 2010-09-22 02:16 73620 c:\windows\system32\perfc009.dat
+ 2004-08-10 18:51 . 2010-10-24 23:02 73620 c:\windows\system32\perfc009.dat
- 2004-08-10 18:51 . 2010-09-22 02:16 447134 c:\windows\system32\perfh009.dat
+ 2004-08-10 18:51 . 2010-10-24 23:02 447134 c:\windows\system32\perfh009.dat
+ 2008-03-20 08:46 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\3-20-2008\ERDNT.EXE
+ 2008-03-20 05:12 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\3-19-2008\ERDNT.EXE
+ 2010-10-24 18:11 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\10-24-2010\ERDNT.EXE
+ 2010-10-20 16:37 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\10-20-2010\ERDNT.EXE
+ 2010-10-19 07:02 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\10-19-2010\ERDNT.EXE
+ 2008-03-20 08:46 . 2008-03-20 08:46 4222976 c:\windows\ERDNT\AutoBackup\3-20-2008\Users\00000002\UsrClass.dat
+ 2008-03-20 08:46 . 2008-03-20 08:46 9654272 c:\windows\ERDNT\AutoBackup\3-20-2008\Users\00000001\NTUSER.DAT
+ 2008-03-20 05:12 . 2008-03-20 05:12 4222976 c:\windows\ERDNT\AutoBackup\3-19-2008\Users\00000002\UsrClass.dat
+ 2008-03-20 05:12 . 2008-03-20 05:12 9654272 c:\windows\ERDNT\AutoBackup\3-19-2008\Users\00000001\NTUSER.DAT
+ 2010-10-24 18:11 . 2010-10-24 18:11 4222976 c:\windows\ERDNT\AutoBackup\10-24-2010\Users\00000002\UsrClass.dat
+ 2010-10-24 18:11 . 2010-10-24 18:11 9654272 c:\windows\ERDNT\AutoBackup\10-24-2010\Users\00000001\NTUSER.DAT
+ 2010-10-20 16:37 . 2010-10-20 16:37 4222976 c:\windows\ERDNT\AutoBackup\10-20-2010\Users\00000002\UsrClass.dat
+ 2010-10-20 16:37 . 2010-10-20 16:37 9580544 c:\windows\ERDNT\AutoBackup\10-20-2010\Users\00000001\NTUSER.DAT
+ 2010-10-19 07:02 . 2010-10-19 07:02 4222976 c:\windows\ERDNT\AutoBackup\10-19-2010\Users\00000002\UsrClass.dat
+ 2010-10-19 07:02 . 2010-10-19 07:02 9580544 c:\windows\ERDNT\AutoBackup\10-19-2010\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-26 16132608]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 53760]

c:\documents and settings\Jeremy\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-10 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\DivX\\DivX Converter\\Converter.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [6/29/2010 4:51 PM 25832]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
IE: &Download; by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab; video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload; selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load; all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
Trusted Zone: aol.com\kdc.uas
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - ProfilePath - c:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\
FF - prefs.js: browser.startup.homepage - yahoo.com
FF - plugin: c:\documents and settings\Jeremy\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\Jeremy\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Jeremy\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll

—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-24 23:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3838388586-3754024616-3633734521-1006\Software\SecuROM\License information*]
"datasecu"=hex:5b,e9,7c,8f,7b,e1,d1,70,dd,44,91,9c,48,48,c0,83,27,d1,03,96,9e,
b3,84,b0,bf,21,41,ea,7b,6e,ac,55,6f,ab,6f,fd,60,64,11,36,0e,41,80,5e,73,0b,\
"rkeysecu"=hex:0b,af,8a,d7,c5,2e,48,29,68,b4,a2,96,f4,d8,26,81
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3332)
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2010-10-24 23:36:44
ComboFix-quarantined-files.txt 2010-10-25 04:36
ComboFix2.txt 2010-10-18 20:18
ComboFix3.txt 2009-06-28 21:21

Pre-Run: 146,019,581,952 bytes free
Post-Run: 146,009,337,856 bytes free

- - End Of File - - 46EDE97D5DCD2A365910F6EBA1D38EBD
That file is still showing in the log,lets see if CF will remove it.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File:: 
    c:\windows\system32\iernonceu.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Again thanks for all of this help. ComboFix 10-10-25.01 - Jeremy 10/26/2010 2:30.6.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.763 [GMT -5:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Jeremy\Desktop\CFScript.txt FILE :: "c:\windows\system32\iernonceu.dll" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\iernonceu.dll . ((((((((((((((((((((((((( Files Created from 2010-09-26 to 2010-10-26 ))))))))))))))))))))))))))))))) . 2010-10-24 23:32 . 2010-10-12 21:59 16856 —-a-w- c:\program files\Mozilla Firefox\plugin-container.exe 2010-10-24 23:32 . 2010-10-12 21:58 719832 —-a-w- c:\program files\Mozilla Firefox\mozcpp19.dll 2010-10-09 05:49 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-10-09 05:49 . 2010-10-09 05:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-10-09 05:49 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-10-05 14:10 . 2010-10-05 14:11 ——– d—–w- c:\documents and settings\Jeremy\Application Data\Research In Motion 2010-10-05 14:10 . 2009-01-09 22:18 27136 —-a-r- c:\windows\system32\drivers\RimSerial.sys 2010-10-05 14:09 . 2010-10-05 14:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Research In Motion 2010-10-05 14:09 . 2010-10-05 14:09 ——– d—–w- c:\program files\Common Files\Research In Motion 2010-10-05 14:09 . 2010-10-05 14:09 ——– d—–w- c:\program files\Research In Motion 2010-10-05 00:24 . 2010-10-05 00:24 ——– d—–w- c:\program files\Common Files\Skype . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-08-11 17:44 . 2010-08-11 17:44 507904 —-a-r- c:\windows\system32\btwapi.dll . ((((((((((((((((((((((((((((( SnapShot@2010-10-18_20.16.52 ))))))))))))))))))))))))))))))))))))))))) . + 2010-10-25 16:24 . 2010-10-25 16:24 16384 c:\windows\temp\Perflib_Perfdata_774.dat + 2004-08-10 18:51 . 2010-10-24 23:02 73620 c:\windows\system32\perfc009.dat - 2004-08-10 18:51 . 2010-09-22 02:16 73620 c:\windows\system32\perfc009.dat + 2004-08-10 18:51 . 2010-10-24 23:02 447134 c:\windows\system32\perfh009.dat - 2004-08-10 18:51 . 2010-09-22 02:16 447134 c:\windows\system32\perfh009.dat + 2010-10-25 16:24 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\10-25-2010\ERDNT.EXE + 2010-10-24 18:11 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\10-24-2010\ERDNT.EXE + 2010-10-20 16:37 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\10-20-2010\ERDNT.EXE + 2010-10-19 07:02 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\10-19-2010\ERDNT.EXE + 2010-10-25 16:24 . 2010-10-25 16:24 4222976 c:\windows\ERDNT\AutoBackup\10-25-2010\Users\00000002\UsrClass.dat + 2010-10-25 16:24 . 2010-10-25 16:24 9654272 c:\windows\ERDNT\AutoBackup\10-25-2010\Users\00000001\NTUSER.DAT + 2010-10-24 18:11 . 2010-10-24 18:11 4222976 c:\windows\ERDNT\AutoBackup\10-24-2010\Users\00000002\UsrClass.dat + 2010-10-24 18:11 . 2010-10-24 18:11 9654272 c:\windows\ERDNT\AutoBackup\10-24-2010\Users\00000001\NTUSER.DAT + 2010-10-20 16:37 . 2010-10-20 16:37 4222976 c:\windows\ERDNT\AutoBackup\10-20-2010\Users\00000002\UsrClass.dat + 2010-10-20 16:37 . 2010-10-20 16:37 9580544 c:\windows\ERDNT\AutoBackup\10-20-2010\Users\00000001\NTUSER.DAT + 2010-10-19 07:02 . 2010-10-19 07:02 4222976 c:\windows\ERDNT\AutoBackup\10-19-2010\Users\00000002\UsrClass.dat + 2010-10-19 07:02 . 2010-10-19 07:02 9580544 c:\windows\ERDNT\AutoBackup\10-19-2010\Users\00000001\NTUSER.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008] "RTHDCPL"="RTHDCPL.EXE" [2007-04-26 16132608] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2004-08-04 53760] c:\documents and settings\Jeremy\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-10 24576] [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Curse\\CurseClient.exe"= "c:\\Program Files\\DivX\\DivX Converter\\Converter.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\Launcher.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"= "c:\\Program Files\\Orbitdownloader\\orbitdm.exe"= "c:\\Program Files\\Orbitdownloader\\orbitnet.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"= "c:\\Program Files\\AIM\\aim.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe"= "c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"= "c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"= "c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 "3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009 S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [6/29/2010 4:51 PM 25832] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ IE: &Download; by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201 IE: &Grab; video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204 IE: Do&wnload; selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203 IE: Down&load; all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202 IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000 Trusted Zone: aol.com\kdc.uas DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - ProfilePath - c:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\ FF - prefs.js: browser.startup.homepage - yahoo.com FF - plugin: c:\documents and settings\Jeremy\Application Data\Facebook\npfbplugin_1_0_1.dll FF - plugin: c:\documents and settings\Jeremy\Application Data\Facebook\npfbplugin_1_0_3.dll FF - plugin: c:\documents and settings\Jeremy\Application Data\Move Networks\plugins\npqmp071505000010.dll FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll —- FIREFOX POLICIES —- FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\S-1-5-21-3838388586-3754024616-3633734521-1006\Software\SecuROM\License information*] "datasecu"=hex:5b,e9,7c,8f,7b,e1,d1,70,dd,44,91,9c,48,48,c0,83,27,d1,03,96,9e, b3,84,b0,bf,21,41,ea,7b,6e,ac,55,6f,ab,6f,fd,60,64,11,36,0e,41,80,5e,73,0b,\ "rkeysecu"=hex:0b,af,8a,d7,c5,2e,48,29,68,b4,a2,96,f4,d8,26,81 . Completion time: 2010-10-26 02:36:09 ComboFix-quarantined-files.txt 2010-10-26 07:36 ComboFix2.txt 2010-10-25 04:36 ComboFix3.txt 2010-10-18 20:18 ComboFix4.txt 2009-06-28 21:21 Pre-Run: 146,068,922,368 bytes free Post-Run: 146,059,624,448 bytes free - - End Of File - - 3E7C4F04130EED8A2A171A04612BBA17
I am not seeing any more malware in your logs that would be a cause the lock ups,we will try one last scan,this one may be long as it is deep. Run Drweb-cureit .

Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download Dr.Web CureIt and save it to your desktop. DO NOT perform a scan yet.
alternate download link
Note: The file will be randomly named (i.e. 5mkuvc4z.exe).

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on the randomly named file to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the anti-virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All. (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • After the Express Scan is finished, put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and uncheck "Heuristic analysis" under the "Scanning" tab, then click Apply, Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • Please be patient as this scan could take a long time to complete.
  • When the scan has finished, a message will be displayed at the bottom indicating if any viruses were found.
  • Click Select All, then choose Cure > Move incurable.
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
b060010-74031c8a\a2ea.class;C:\_OTL\MovedFiles\03202008_025017\C_Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\16\b060010-74;Exploit.Java.145;; b060010-74031c8a\ab66.class;C:\_OTL\MovedFiles\03202008_025017\C_Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\16\b060010-74;Exploit.Java.145;; b060010-74031c8a\ac60.class;C:\_OTL\MovedFiles\03202008_025017\C_Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\16\b060010-74;Exploit.Java.145;; b060010-74031c8a\ac98.class;C:\_OTL\MovedFiles\03202008_025017\C_Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\16\b060010-74;Exploit.Java.145;; b060010-74031c8a\aefe.class;C:\_OTL\MovedFiles\03202008_025017\C_Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\16\b060010-74;Exploit.Java.145;; b060010-74031c8a\WhatTheJava.class;C:\_OTL\MovedFiles\03202008_025017\C_Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\16\b060010-74;Exploit.Java.145;; b060010-74031c8a;C:\_OTL\MovedFiles\03202008_025017\C_Documents and Settings\Jeremy\Application Data\Sun\Java\Deployment\cache\6.0\16;Archive contains infected objects;Moved.;
Drweb found nothing apart from files in quarantine

Please open OTL

Change the Extra registry to use safe list

  • Click the Run Scan button.The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTL logfile created on: 11/1/2010 1:52:16 AM - Run 3
OTL by OldTimer - Version 3.2.17.2 Folder = C:\Documents and Settings\Jeremy\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 653.00 Mb Available Physical Memory | 64.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): c:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 229.77 Gb Total Space | 136.28 Gb Free Space | 59.31% Space Free | Partition Type: NTFS

Computer Name: DARKSCOMP | User Name: Jeremy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jeremy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jeremy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (stllssvr) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (DAUpdaterSvc) – C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (OMCI) – C:\WINDOWS\System32\DRIVERS\OMCI.SYS File not found
DRV - (catchme) – C:\DOCUME~1\Jeremy\LOCALS~1\Temp\catchme.sys File not found
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=6071210
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=6071210

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "yahoo.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {5b175400-2368-11de-8c30-0800200c9a66}:1.9
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/26 00:49:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/24 17:32:43 | 000,000,000 | —D | M]

[2009/10/04 23:05:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Extensions
[2010/10/31 13:43:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions
[2010/10/24 17:36:15 | 000,000,000 | —D | M] (Oskar) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{5b175400-2368-11de-8c30-0800200c9a66}
[2010/10/18 14:59:29 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/10/04 23:10:17 | 000,000,000 | —D | M] (PitchDark) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}
[2010/10/24 18:08:30 | 000,000,000 | —D | M] (AmbientFox) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}
[2010/08/18 12:35:56 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/08/03 01:05:29 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\wqlbpwew.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/10/31 13:43:09 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/29 16:18:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/12 00:51:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/26 15:36:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 03:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/10/26 01:34:51 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\Jeremy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: aol.com ([kdc.uas] https in Trusted sites)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1245991674359 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} http://myitlab.pearsoned.com/Pegasus/Modul…ces/ax/stub.cab (Enlite 2.x Simulation Engine Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jeremy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jeremy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/01 01:51:41 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jeremy\Desktop\OTL.exe
[2010/10/28 10:59:12 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/10/28 10:33:01 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jeremy\Recent
[2010/10/26 23:41:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Jeremy\DoctorWeb
[2010/10/26 15:36:13 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/10/26 15:36:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/10/26 15:36:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/10/26 01:28:31 | 000,000,000 | —D | C] – C:\ComboFix
[2010/10/18 14:12:02 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/10/18 14:09:08 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/10/18 14:09:08 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/10/18 14:09:08 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/10/18 14:09:08 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/10/18 14:08:27 | 000,000,000 | —D | C] – C:\Qoobox
[2010/10/08 23:49:31 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/10/08 23:49:21 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/10/08 23:49:21 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/05 11:52:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Jeremy\My Documents\JeremyCreditReport_files
[2010/10/05 08:10:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Jeremy\Application Data\Research In Motion
[2010/10/05 08:09:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/10/05 08:09:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Research In Motion
[2010/10/05 08:09:41 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion
[2010/10/04 18:24:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype

========== Files - Modified Within 30 Days ==========

[2010/11/01 01:51:48 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jeremy\Desktop\OTL.exe
[2010/10/30 18:05:06 | 161,652,480 | -H– | M] () – C:\Documents and Settings\Jeremy\Desktop\1500 - mh got arrested for this.rar.part
[2010/10/30 17:31:22 | 000,000,000 | -H– | M] () – C:\Documents and Settings\Jeremy\Desktop\1500 - mh got arrested for this.rar
[2010/10/30 16:42:38 | 000,254,654 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2010/10/30 16:42:27 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/30 16:42:26 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/30 16:42:23 | 1071,824,896 | -HS- | M] () – C:\hiberfil.sys
[2010/10/30 16:40:13 | 003,801,088 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\vlc-1.1.4-win32.exe
[2010/10/30 12:49:03 | 000,032,256 | —- | M] () – C:\Documents and Settings\Jeremy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/29 01:05:11 | 000,000,818 | —- | M] () – C:\Documents and Settings\Jeremy\Application Data\wklnhst.dat
[2010/10/27 23:36:36 | 000,000,762 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/10/27 22:00:38 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/10/26 01:34:51 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/10/25 21:16:10 | 000,079,872 | —- | M] () – C:\WINDOWS\MBR.exe
[2010/10/25 20:02:21 | 000,011,367 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 4 Part 1.docx
[2010/10/24 17:32:46 | 000,001,631 | —- | M] () – C:\Documents and Settings\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/10/24 17:32:46 | 000,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/10/24 17:02:14 | 000,447,134 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/10/24 17:02:14 | 000,073,620 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/10/18 14:12:07 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2010/10/17 11:21:45 | 1071,853,568 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/10/09 13:39:41 | 000,012,811 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\CIS 140 Assignment 1.docx
[2010/10/08 23:49:33 | 000,000,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/08 11:37:14 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/10/06 11:58:21 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/10/05 11:52:16 | 000,123,849 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\JeremyCreditReport.htm
[2010/10/05 08:10:03 | 000,001,967 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2010/10/04 18:22:20 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/10/04 17:47:14 | 000,013,470 | —- | M] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 3.docx

========== Files Created - No Company Name ==========

[2010/10/30 17:31:22 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Jeremy\Desktop\1500 - mh got arrested for this.rar
[2010/10/30 17:31:17 | 161,652,480 | -H– | C] () – C:\Documents and Settings\Jeremy\Desktop\1500 - mh got arrested for this.rar.part
[2010/10/30 16:40:13 | 003,801,088 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\vlc-1.1.4-win32.exe
[2010/10/27 11:26:54 | 1071,824,896 | -HS- | C] () – C:\hiberfil.sys
[2010/10/25 19:52:48 | 000,011,367 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 4 Part 1.docx
[2010/10/24 17:32:46 | 000,001,631 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/10/18 14:09:08 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/10/18 14:09:08 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/10/18 14:09:08 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/10/18 14:09:08 | 000,079,872 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/10/18 14:09:08 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/10/09 13:39:41 | 000,012,811 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\CIS 140 Assignment 1.docx
[2010/10/08 23:49:33 | 000,000,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/05 11:52:15 | 000,123,849 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\JeremyCreditReport.htm
[2010/10/05 08:10:51 | 000,000,077 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\Rim.Desktop.Exception.log
[2010/10/05 08:10:09 | 000,000,759 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\Rim.Desktop.HttpServerSetup.log
[2010/10/05 08:10:03 | 000,001,967 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2010/10/04 17:30:34 | 000,013,470 | —- | C] () – C:\Documents and Settings\Jeremy\My Documents\CIS 111 Assignment 3.docx
[2010/02/02 19:19:38 | 000,402,928 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/12/31 00:08:42 | 000,000,040 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ra3.ini
[2009/09/02 16:14:31 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/06/25 15:34:01 | 000,000,267 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\up_sp1v1.cab
[2009/06/25 15:34:01 | 000,000,016 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\up_sp1v2.cab
[2009/06/25 15:33:54 | 000,000,189 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\up_sp2v1.cab
[2008/10/07 08:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/09/29 13:57:08 | 000,000,818 | —- | C] () – C:\Documents and Settings\Jeremy\Application Data\wklnhst.dat
[2008/07/09 11:28:43 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/09 11:28:43 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/09 11:28:43 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/07/06 18:25:02 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/05/30 11:22:22 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/02/11 09:39:26 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008/02/11 09:39:18 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008/02/10 16:35:05 | 000,032,256 | —- | C] () – C:\Documents and Settings\Jeremy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/08 13:53:46 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2007/12/10 00:11:00 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/12/10 00:03:53 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/12/09 23:38:53 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2007/12/09 23:37:29 | 000,001,028 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/07/27 14:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 14:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2005/12/05 19:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 12:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2004/08/10 13:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/04 04:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys

< End of report >



OTL Extras logfile created on: 11/1/2010 1:52:16 AM - Run 3
OTL by OldTimer - Version 3.2.17.2 Folder = C:\Documents and Settings\Jeremy\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 653.00 Mb Available Physical Memory | 64.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): c:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 229.77 Gb Total Space | 136.28 Gb Free Space | 59.31% Space Free | Partition Type: NTFS

Computer Name: DARKSCOMP | User Name: Jeremy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software music sync service data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software music sync service discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software music sync service data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software music sync service discovery

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Curse\CurseClient.exe" = C:\Program Files\Curse\CurseClient.exe:*:Enabled:Curse Client – ()
"C:\Program Files\DivX\DivX Converter\Converter.exe" = C:\Program Files\DivX\DivX Converter\Converter.exe:*:Disabled:Converter – (DivX, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – (Flagship Industries, Inc.)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\World of Warcraft\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.3.2.11403-to-3.3.3.11685-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\Dragon Age\bin_ship\daorigins.exe" = C:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Origins Game – (BioWare)
"C:\Program Files\Dragon Age\DAOriginsLauncher.exe" = C:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Origins Launcher – (BioWare)
"C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe" = C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Origins Updater – (BioWare)
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 22
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}" = Dell DataSafe Online
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A81300000003}_814" = KB408682
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C252EB7B-7AE0-46DE-9BEE-DF681B885F13}" = Modem Diagnostic Tool
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D25F26E6-7F37-4580-9E83-2BDD9BE9E0CE}" = BlackBerry Desktop Software 6.0
"{E42BD75A-FC23-4E3F-9F91-2658334C644F}" = Internet Service Offers Launcher
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM_7" = AIM 7
"Army Builder V3.2d" = Army Builder V3.2d
"Audacity_is1" = Audacity 1.2.6
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"CurseClient" = Curse Client
"DivX Setup.divx.com" = DivX Setup
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"EsetOnlineScanner" = ESET Online Scanner
"FLV Player" = FLV Player 2.0 (build 25)
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla ActiveX Control v1.7.12" = Mozilla ActiveX Control v1.7.12
"Mozilla Firefox (3.6.11)" = Mozilla Firefox (3.6.11)
"MyITLab ActiveX Installer_is1" = MyITLab ActiveX Installer 2, 9, 8, 65535
"NVIDIA Drivers" = NVIDIA Drivers
"Orbit_is1" = Orbit Downloader
"PokerStars" = PokerStars
"PROSet" = Intel® PRO Network Connections Drivers
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"StarCraft II" = StarCraft II
"VASSAL (3.1.14)" = VASSAL (3.1.14)
"VLC media player" = VLC media player 1.1.2
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"WinRAR archiver" = WinRAR archiver
"World of Warcraft" = World of Warcraft
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Facebook Plug-In" = Facebook Plug-In
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/28/2010 1:44:41 PM | Computer Name = DARKSCOMP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/28/2010 1:44:41 PM | Computer Name = DARKSCOMP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/30/2010 2:53:42 AM | Computer Name = DARKSCOMP | Source = Application Error | ID = 1000
Description = Faulting application divxupdate.exe, version 1.0.1.10, faulting module
ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.

Error - 9/6/2010 7:00:17 PM | Computer Name = DARKSCOMP | Source = Application Error | ID = 1000
Description = Faulting application aim.exe, version 7.1.6.4, faulting module unknown,
version 0.0.0.0, fault address 0x00002606.

Error - 9/8/2010 8:21:53 PM | Computer Name = DARKSCOMP | Source = Application Hang | ID = 1002
Description = Hanging application Wow.exe, version 3.3.5.12340, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/10/2010 12:46:08 PM | Computer Name = DARKSCOMP | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.1.3834, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/16/2010 10:50:45 AM | Computer Name = DARKSCOMP | Source = Application Error | ID = 1000
Description = Faulting application backgrounddownloader.exe, version 2.2.0.1092,
faulting module backgrounddownloader.exe, version 2.2.0.1092, fault address 0x0002c0dc.

Error - 9/20/2010 12:48:24 PM | Computer Name = DARKSCOMP | Source = Application Error | ID = 1000
Description = Faulting application backgrounddownloader.exe, version 2.2.0.1092,
faulting module backgrounddownloader.exe, version 2.2.0.1092, fault address 0x0002c0dc.

Error - 9/20/2010 7:16:08 PM | Computer Name = DARKSCOMP | Source = Application Error | ID = 1000
Description = Faulting application backgrounddownloader.exe, version 2.2.0.1092,
faulting module backgrounddownloader.exe, version 2.2.0.1092, fault address 0x0002c0dc.

Error - 10/28/2010 1:21:59 AM | Computer Name = DARKSCOMP | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3937, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 10/31/2010 3:43:29 PM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/31/2010 3:43:29 PM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/31/2010 3:43:29 PM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/31/2010 3:43:29 PM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/31/2010 3:43:29 PM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/31/2010 3:43:29 PM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/31/2010 4:00:05 PM | Computer Name = DARKSCOMP | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 10/31/2010 4:00:05 PM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083

Error - 10/31/2010 5:00:22 PM | Computer Name = DARKSCOMP | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 10/31/2010 5:00:22 PM | Computer Name = DARKSCOMP | Source = Service Control Manager | ID = 7000
Description = The Background Intelligent Transfer Service service failed to start
due to the following error: %%1083


< End of report >


sorry it took so long busy weekend
From your logs i do not see any evidence of any Antivirus running,if this is the case install Avira free from the link below,run a full scan and post the log if it finds anything.

http://www.avira.com/en/avira-free-antivirus

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI