This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Heur: Trojan.script.iframer

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm having worsening problems with my IE 8 browser. Started with constant crashes "This tab has been recovered." Not! Then could not play any videos. That would just close the browser completely. Same behavior with Mozilla. Decided to remove IE8 and go back to IE7, but it would not uninstall. I have Windows XP, SP2, so it should uninstall, but it won't. Zone Alarm found the iframer infection, but I'm unable to remove that, either. So far have only run ZoneAlarm and Malwarebytes. Condition has deteriorated to the point where only partial web pages load, or shut down altogether. I really, really don't want to reinstall the OS. I hope someone can HELP ME!

Here are the results of HijackThis scan:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:30:24 PM, on 1/30/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\CheckPoint\ZAForceField\ISWMGR.exe
C:\Program Files\CheckPoint\ZAForceField\ISWMGR.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\bean\Desktop\Downloads\HiJackThis.exe
C:\WINNT\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [{F9AA8FE2-E89A-E99B-E8b8-E9AE9B9ABA99}] "C:\Program Files\Cricket Broadband Connect\AvqAutoRun.exe" "C:\Program Files\Cricket Broadband Connect\mPhonetools.exe" /OnPlug=%s
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.0] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cab
O16 - DPF: {CAEAFE12-7726-4C39-B620-2601216CFBB5} - http://phughescw.hughes.motive.com/wizlet/…/Mcci_6-1-0.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{C65391FA-87DA-4AB3-BF70-E7BCA3D82F8D}: NameServer = 64.203.112.13,64.203.112.14
O20 - Winlogon Notify: ATINotify - logonnfy.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINNT\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINNT\System32\browseui.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ZoneAlarm ForceField IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINNT\system32\ZoneLabs\vsmon.exe

–
End of file - 6733 bytes

Thank you so much, anyone!
Sierra
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post









Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)








  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Dearest Mowman,
Thanks for coming to my rescue! I will love you for life. I ran the TDSSKiller and got nothing to report. Results were 240 object processed with no infections found. Here are the results of the OTL scan:
OTL logfile created on: 2/1/2011 6:38:07 PM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\bean\Desktop\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 436.00 Mb Available Physical Memory | 43.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 76.25 Gb Free Space | 68.21% Space Free | Partition Type: NTFS
Drive D: | 115.76 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: BEAN | User Name: bean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\bean\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\WINNT\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWMGR.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe (SonicWALL, Inc.)
PRC - C:\WINNT\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\bean\Desktop\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Program Files\CheckPoint\ZAForceField\AK\icsak.dll (Check Point Software Technologies)
MOD - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MlfHook.dll ()
MOD - C:\WINNT\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINNT\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINNT\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (vsmon) – C:\WINNT\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Adobe Version Cue CS3) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
SRV - (UtilMan) – C:\WINNT\system32\utilman.exe (Microsoft Corporation)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (vsdatant) – C:\WINNT\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (icsak) – C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys (Check Point Software Technologies)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (TSP) – C:\WINNT\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (LMouFilt) – C:\WINNT\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINNT\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LHidEqd) – C:\WINNT\system32\drivers\LHidEqd.sys (Logitech, Inc.)
DRV - (LEqdUsb) – C:\WINNT\system32\drivers\LEqdUsb.sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINNT\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (SWUMXA3) Sierra Wireless USB MUX Driver (UMTSA3) – C:\WINNT\system32\drivers\swumxa3.sys (Sierra Wireless Inc.)
DRV - (SWNC8UA3) Sierra Wireless MUX NDIS Driver (UMTSA3) – C:\WINNT\system32\drivers\swnc8ua3.sys (Sierra Wireless Inc.)
DRV - (ati2mtag) – C:\WINNT\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (MPE) – C:\WINNT\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (mf) – C:\WINNT\system32\drivers\mf.sys (Microsoft Corporation)
DRV - (Cdr4_2K) – C:\WINNT\System32\drivers\cdr4_2K.sys (Roxio)
DRV - (Cdralw2k) – C:\WINNT\System32\drivers\cdralw2k.sys (Roxio)
DRV - (avpnnic) – C:\WINNT\system32\drivers\avpnnic.sys (AT&T)
DRV - (pfc) – C:\WINNT\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (MidiSyn) – C:\WINNT\system32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (Nbf) – C:\WINNT\system32\drivers\NBF.SYS (Microsoft Corporation)
DRV - (portmon) – C:\WINNT\system32\drivers\portmon.sys ()
DRV - (cbserial) – C:\WINNT\system32\drivers\cbserial.sys (Windows ® 2000 DDK provider)
DRV - (mrtRate) – C:\WINNT\System32\drivers\MrtRate.sys (Marimba, Inc.)
DRV - (aslm75) – C:\WINNT\system32\drivers\ASLM75.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.36.15

FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/01/10 06:14:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/30 11:34:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/30 11:35:16 | 000,000,000 | —D | M]

[2009/10/10 13:20:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\bean\Application Data\Mozilla\Extensions
[2009/12/22 21:11:54 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\bean\Application Data\Mozilla\Firefox\Profiles\zyuntfv5.default\extensions
[2009/10/10 13:49:00 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\bean\Application Data\Mozilla\Firefox\Profiles\zyuntfv5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/22 21:11:54 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\bean\Application Data\Mozilla\Firefox\Profiles\zyuntfv5.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2009/10/10 13:20:29 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/01/10 06:14:19 | 000,000,000 | —D | M] (ForceField Toolbar) – C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
[2009/08/14 12:33:22 | 000,070,488 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2009/08/14 12:33:30 | 000,091,480 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2009/08/14 12:33:26 | 000,020,824 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2008/05/21 07:41:08 | 000,479,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2008/05/21 07:41:08 | 000,548,864 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2008/05/21 07:41:08 | 000,626,688 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2009/08/14 12:35:40 | 000,427,344 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2009/08/14 12:33:22 | 000,023,896 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll

O1 HOSTS File: ([1999/12/07 04:00:00 | 000,000,734 | —- | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O2 - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (ZoneAlarm Spy Blocker BHO) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O4 - HKLM..\Run: [{F9AA8FE2-E89A-E99B-E8b8-E9AE9B9ABA99}] File not found
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Gadwin PrintScreen 3.0] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} http://www.verizon.net/checkmypc/includes/MotivePreQual.cab (PreQualifier Class)
O16 - DPF: {CAEAFE12-7726-4C39-B620-2601216CFBB5} http://phughescw.hughes.motive.com/wizlet/…/Mcci_6-1-0.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll (PCPitstop Exam)
O16 - DPF: DirectAnimation Java Classes file://C:\WINNT\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINNT\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\ATINotify: DllName - logonnfy.dll - File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\wzcnotif: DllName - wzcdlg.dll - C:\WINNT\System32\wzcdlg.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\bean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\bean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/07 11:50:14 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{5be50018-78d9-11df-aeef-000ea669ad29}\Shell - "" = AutoRun
O33 - MountPoints2\{5be50018-78d9-11df-aeef-000ea669ad29}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5be50018-78d9-11df-aeef-000ea669ad29}\Shell\AutoRun\command - "" = G:\WIN\setup.exe
O33 - MountPoints2\{d01331ec-888a-11df-af04-000ea669ad29}\Shell - "" = AutoRun
O33 - MountPoints2\{d01331ec-888a-11df-af04-000ea669ad29}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d01331ec-888a-11df-af04-000ea669ad29}\Shell\AutoRun\command - "" = E:\Start.exe
O33 - MountPoints2\{d01331ec-888a-11df-af04-000ea669ad29}\Shell\menu1\command - "" = E:\Start.exe
O33 - MountPoints2\{e54d80c0-0558-11e0-af79-000ea669ad29}\Shell\AutoRun\command - "" = TranscendService(JF).exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: LanmanServer - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: Ip6FwHlp - File not found

Drivers32: aux - C:\WINNT\System32\mmdrv.dll (Microsoft Corporation)
Drivers32: aux1 - File not found
Drivers32: aux2 - File not found
Drivers32: aux3 - File not found
Drivers32: aux4 - File not found
Drivers32: aux5 - File not found
Drivers32: aux6 - File not found
Drivers32: aux7 - File not found
Drivers32: aux8 - File not found
Drivers32: aux9 - File not found
Drivers32: midi1 - File not found
Drivers32: midi2 - File not found
Drivers32: midi3 - File not found
Drivers32: midi4 - File not found
Drivers32: midi5 - File not found
Drivers32: midi6 - File not found
Drivers32: midi7 - File not found
Drivers32: midi8 - File not found
Drivers32: midi9 - File not found
Drivers32: mixer1 - File not found
Drivers32: mixer2 - File not found
Drivers32: mixer3 - File not found
Drivers32: mixer4 - File not found
Drivers32: mixer5 - File not found
Drivers32: mixer6 - File not found
Drivers32: mixer7 - File not found
Drivers32: mixer8 - File not found
Drivers32: mixer9 - File not found
Drivers32: msacm.iac2 - C:\WINNT\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINNT\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINNT\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINNT\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINNT\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINNT\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINNT\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINNT\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINNT\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINNT\System32\ir50_32.dll (Intel Corporation)
Drivers32: wave1 - File not found
Drivers32: wave2 - File not found
Drivers32: wave3 - File not found
Drivers32: wave4 - File not found
Drivers32: wave5 - File not found
Drivers32: wave6 - File not found
Drivers32: wave7 - File not found
Drivers32: wave8 - File not found
Drivers32: wave9 - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (76011854463238144)

========== Files/Folders - Created Within 30 Days ==========

[2011/02/01 18:24:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2011/01/22 15:08:03 | 000,000,000 | —D | C] – C:\Program Files\Exterminate It!
[2011/01/22 15:08:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Exterminate It!
[2011/01/22 13:44:08 | 000,000,000 | —D | C] – C:\Documents and Settings\bean\Application Data\Malwarebytes
[2011/01/22 13:43:56 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbamswissarmy.sys
[2011/01/22 13:43:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/01/22 13:43:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/01/22 13:43:52 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2011/01/22 13:43:52 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/01/21 12:25:27 | 000,000,000 | —D | C] – C:\389d4af3da7b443f79
[2011/01/21 12:22:57 | 000,231,456 | —- | C] (Microsoft Corporation) – C:\spuninst.exe
[2011/01/21 10:16:12 | 000,000,000 | —D | C] – C:\Documents and Settings\bean\My Documents\Favorites
[2011/01/21 10:14:45 | 000,000,000 | —D | C] – C:\Favorites
[2008/05/29 14:46:26 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\bean\Application Data\pcouffin.sys
[2004/08/25 14:22:08 | 000,151,552 | —- | C] ( ) – C:\WINNT\System32\ATIDEMGR.dll
[6 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
[13 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/01 18:24:58 | 000,001,728 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2011/02/01 18:20:52 | 000,000,740 | —- | M] () – C:\WINNT\WORDZAP.INI
[2011/02/01 18:17:33 | 000,004,212 | -H– | M] () – C:\WINNT\System32\zllictbl.dat
[2011/02/01 18:03:36 | 000,000,144 | —- | M] () – C:\WINNT\System32\pdfl.dat
[2011/02/01 18:02:35 | 000,001,374 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2011/02/01 18:01:58 | 000,000,256 | —- | M] () – C:\WINNT\tasks\WGASetup.job
[2011/02/01 18:01:17 | 000,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2011/02/01 18:01:13 | 1072,484,352 | -HS- | M] () – C:\hiberfil.sys
[2011/01/31 00:33:01 | 000,000,414 | —- | M] () – C:\WINNT\tasks\ParetoLogic Update Version2.job
[2011/01/30 18:00:00 | 000,000,436 | —- | M] () – C:\WINNT\tasks\ParetoLogic Registration.job
[2011/01/30 12:55:43 | 000,002,529 | —- | M] () – C:\Documents and Settings\bean\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007 (2).lnk
[2011/01/25 18:00:00 | 000,000,404 | —- | M] () – C:\WINNT\tasks\Pareto UNS.job
[2011/01/25 17:22:35 | 000,000,304 | —- | M] () – C:\WINNT\QTW.INI
[2011/01/22 15:08:03 | 000,000,756 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Exterminate It!.lnk
[2011/01/22 13:43:56 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/21 13:24:38 | 000,380,159 | —- | M] () – C:\Documents and Settings\bean\My Documents\Reinstalling XP.docx
[2011/01/21 12:31:52 | 000,001,374 | —- | M] () – C:\WINNT\imsins.BAK
[2011/01/15 22:15:14 | 000,002,411 | —- | M] () – C:\WINNT\panose.bin
[6 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
[13 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/01 18:24:58 | 000,001,728 | —- | C] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2011/01/22 15:08:03 | 000,000,756 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Exterminate It!.lnk
[2011/01/22 13:43:56 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/21 13:24:35 | 000,380,159 | —- | C] () – C:\Documents and Settings\bean\My Documents\Reinstalling XP.docx
[2010/06/20 13:06:39 | 000,000,031 | —- | C] () – C:\WINNT\warhead.ini
[2009/06/04 20:03:11 | 002,463,976 | —- | C] () – C:\WINNT\System32\NPSWF32.dll
[2009/04/18 13:20:00 | 000,005,824 | —- | C] () – C:\WINNT\System32\drivers\ASUSHWIO.SYS
[2008/05/29 14:46:47 | 000,000,034 | —- | C] () – C:\Documents and Settings\bean\Application Data\pcouffin.log
[2008/05/29 14:46:26 | 000,087,608 | —- | C] () – C:\Documents and Settings\bean\Application Data\inst.exe
[2008/05/29 14:46:26 | 000,007,887 | —- | C] () – C:\Documents and Settings\bean\Application Data\pcouffin.cat
[2008/05/29 14:46:26 | 000,001,144 | —- | C] () – C:\Documents and Settings\bean\Application Data\pcouffin.inf
[2006/09/01 09:27:07 | 000,016,384 | —- | C] () – C:\WINNT\System32\WINKRNME.DLL
[2006/07/02 13:07:52 | 000,000,049 | —- | C] () – C:\WINNT\NeroDigital.ini
[2006/02/07 20:44:58 | 000,007,680 | —- | C] () – C:\WINNT\System32\CNMVS6y.DLL
[2006/02/06 19:36:33 | 000,000,532 | —- | C] () – C:\WINNT\MAXLINK.INI
[2006/02/06 19:22:07 | 000,000,398 | —- | C] () – C:\WINNT\System32\CNCMP60.INI
[2005/10/17 16:35:46 | 000,000,117 | —- | C] () – C:\WINNT\ulead32.ini
[2005/10/03 15:16:49 | 000,000,000 | —- | C] () – C:\WINNT\ATIMMC.INI
[2004/09/03 12:42:39 | 000,010,009 | —- | C] () – C:\WINNT\agnslang.ini
[2004/06/15 16:24:15 | 000,013,824 | —- | C] () – C:\Documents and Settings\bean\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/06/14 03:06:50 | 000,003,654 | —- | C] () – C:\WINNT\System32\drivers\Sonyhcp.dll
[2004/06/12 15:40:28 | 000,000,000 | —- | C] () – C:\WINNT\QFN.ini
[2004/06/12 15:40:28 | 000,000,000 | —- | C] () – C:\WINNT\QDQICK.ini
[2004/06/02 19:47:59 | 000,000,286 | —- | C] () – C:\WINNT\pcps.ini
[2004/05/26 18:59:11 | 000,001,270 | —- | C] () – C:\WINNT\HPW5CSS.INI
[2004/05/26 18:59:11 | 000,000,650 | —- | C] () – C:\WINNT\HPW5DSM.INI
[2004/05/16 14:00:25 | 000,000,059 | —- | C] () – C:\WINNT\INTUIT.INI
[2004/05/08 12:30:02 | 000,000,004 | —- | C] () – C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameD.txt
[2004/04/30 12:26:35 | 000,000,266 | —- | C] () – C:\WINNT\cdplayer.ini
[2004/04/29 10:41:17 | 000,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2004/04/29 09:03:05 | 000,001,793 | —- | C] () – C:\WINNT\System32\fxsperf.ini
[2004/04/15 13:04:08 | 000,036,864 | —- | C] () – C:\WINNT\System32\hpcoinst.dll
[2004/04/12 17:32:16 | 000,000,024 | —- | C] () – C:\WINNT\qfnonl.ini
[2004/04/09 10:44:59 | 000,000,976 | —- | C] () – C:\WINNT\QUICKEN.INI
[2004/04/09 10:44:59 | 000,000,607 | —- | C] () – C:\WINNT\intuprof.ini
[2004/04/09 10:21:30 | 000,000,304 | —- | C] () – C:\WINNT\QTW.INI
[2004/04/09 10:17:46 | 000,210,944 | —- | C] () – C:\WINNT\System32\MSVCRT10.DLL
[2004/04/09 10:17:46 | 000,027,648 | —- | C] () – C:\WINNT\PFPICK.DLL
[2004/04/09 10:17:39 | 000,000,176 | —- | C] () – C:\WINNT\KPCMS.INI
[2004/04/09 09:44:59 | 000,000,740 | —- | C] () – C:\WINNT\WORDZAP.INI
[2004/04/07 14:54:26 | 000,204,800 | —- | C] () – C:\WINNT\System32\IVIresizeW7.dll
[2004/04/07 14:54:26 | 000,200,704 | —- | C] () – C:\WINNT\System32\IVIresizeA6.dll
[2004/04/07 14:54:26 | 000,192,512 | —- | C] () – C:\WINNT\System32\IVIresizeP6.dll
[2004/04/07 14:54:26 | 000,192,512 | —- | C] () – C:\WINNT\System32\IVIresizeM6.dll
[2004/04/07 14:54:26 | 000,188,416 | —- | C] () – C:\WINNT\System32\IVIresizePX.dll
[2004/04/07 14:54:26 | 000,020,480 | —- | C] () – C:\WINNT\System32\IVIresize.dll
[2004/04/07 14:43:54 | 000,000,008 | —- | C] () – C:\WINNT\System32\PROTOCOL.INI
[2004/04/07 12:36:32 | 000,000,065 | —- | C] () – C:\WINNT\iTouch.ini
[2004/04/07 12:17:56 | 000,000,701 | —- | C] () – C:\WINNT\ODBC.INI
[2004/04/07 12:10:30 | 000,006,272 | —- | C] () – C:\WINNT\System32\drivers\ASLM75.SYS
[2004/04/07 11:58:45 | 000,003,046 | —- | C] () – C:\WINNT\Ascd_tmp.ini
[2004/04/07 11:49:19 | 000,021,952 | -H– | C] () – C:\Program Files\folder.htt
[2004/04/07 04:36:59 | 000,004,073 | —- | C] () – C:\WINNT\ODBCINST.INI
[2003/02/11 08:58:50 | 000,126,976 | —- | C] () – C:\WINNT\System32\e1000msg.dll
[2002/12/18 15:10:36 | 000,006,048 | —- | C] () – C:\WINNT\System32\MCC16.DLL
[2002/09/23 14:39:44 | 000,013,601 | —- | C] () – C:\WINNT\System32\vctest.ini
[2000/03/30 19:16:48 | 000,004,961 | —- | C] () – C:\WINNT\System32\drivers\portmon.sys
[1999/12/07 04:00:00 | 000,176,400 | —- | C] () – C:\WINNT\System32\qcut.dll
[1999/09/25 02:36:24 | 000,088,816 | —- | C] () – C:\WINNT\System32\drivers\lvcam.sys
[1999/09/25 02:36:22 | 000,017,424 | —- | C] () – C:\WINNT\System32\drivers\lvsound.sys

========== LOP Check ==========

[2010/07/07 15:05:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T
[2009/11/05 16:58:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2009/03/20 14:31:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cached Installations
[2009/04/11 12:47:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/03/29 17:44:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2009/10/14 17:31:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
[2008/11/29 15:40:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2010/03/29 18:00:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/03/20 14:21:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
[2009/04/18 13:01:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/01/22 20:27:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2007/07/23 04:06:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/07/23 04:09:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2007/07/23 04:10:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2010/03/29 17:43:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/02/01 18:25:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/10/10 11:45:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipSE
[2011/02/01 18:31:03 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\#ISW.FS#
[2010/06/15 16:05:59 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\AT&T
[2011/01/22 16:22:15 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\Canon
[2009/10/14 17:27:11 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\CheckPoint
[2009/01/22 20:41:46 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\DriverCure
[2009/10/30 13:03:09 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\ICAClient
[2004/06/15 03:18:57 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\InterVideo
[2010/08/17 10:07:19 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\Leadertech
[2009/11/05 19:44:26 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\MailFrontier
[2009/03/20 14:36:20 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\ParetoLogic
[2006/02/06 19:36:36 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\ScanSoft
[2010/06/15 15:54:50 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\Sierra Wireless
[2008/06/13 05:31:32 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\Vso
[2010/12/15 18:25:46 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\Windows Search
[2009/01/28 15:22:00 | 000,000,818 | —- | M] () – C:\WINNT\Tasks\01-28-09 backup.job
[2011/01/25 18:00:00 | 000,000,404 | —- | M] () – C:\WINNT\Tasks\Pareto UNS.job
[2011/01/30 18:00:00 | 000,000,436 | —- | M] () – C:\WINNT\Tasks\ParetoLogic Registration.job
[2011/01/31 00:33:01 | 000,000,414 | —- | M] () – C:\WINNT\Tasks\ParetoLogic Update Version2.job
[2011/02/01 18:01:58 | 000,000,256 | —- | M] () – C:\WINNT\Tasks\WGASetup.job
[2006/10/12 16:56:23 | 000,000,298 | —- | M] () – C:\WINNT\Tasks\XoftSpy.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/04/07 11:50:14 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2010/12/18 16:16:14 | 000,000,207 | RHS- | M] () – C:\boot.ini
[2004/04/07 11:50:14 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2010/06/16 15:26:48 | 001,510,089 | —- | M] () – C:\drivers.log
[2004/10/14 17:16:52 | 000,000,081 | —- | M] () – C:\DVDPATH.TXT
[2009/03/20 14:32:33 | 000,000,000 | —- | M] () – C:\FileRecovery.log
[2011/02/01 18:01:13 | 1072,484,352 | -HS- | M] () – C:\hiberfil.sys
[2009/07/27 18:52:46 | 000,000,427 | —- | M] () – C:\INSTALL.LOG
[2004/04/07 11:50:14 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/20 12:54:43 | 000,000,090 | —- | M] () – C:\itouch.log
[2007/05/03 01:45:16 | 000,000,158 | —- | M] () – C:\itouch_config_crash_info.txt
[2004/04/07 12:33:04 | 000,000,000 | —- | M] () – C:\itouch_crash_info.txt
[2004/04/07 11:50:14 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/06/20 12:54:49 | 000,000,090 | —- | M] () – C:\mw.log
[2004/10/01 18:02:21 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/10/01 18:02:20 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/02/01 18:01:12 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2009/07/17 15:48:56 | 005,269,432 | —- | M] () – C:\PERSONA1.QDF
[2008/12/18 18:53:26 | 000,015,360 | —- | M] () – C:\PERSONA1.QEL
[2009/07/17 15:48:58 | 000,383,548 | —- | M] () – C:\PERSONA1.QSD
[2004/04/07 14:20:18 | 000,002,625 | —- | M] () – C:\PollSt.txt
[2005/01/22 19:50:57 | 000,000,023 | —- | M] () – C:\Q3.DIR
[2010/03/29 17:05:27 | 000,005,707 | —- | M] () – C:\rollback.ini
[2004/04/20 15:42:10 | 000,000,381 | —- | M] () – C:\Shortcut to SIIG20x.lnk
[2009/01/07 17:20:58 | 000,231,456 | —- | M] (Microsoft Corporation) – C:\spuninst.exe
[2011/02/01 18:30:14 | 000,040,994 | —- | M] () – C:\TDSSKiller.2.4.16.0_01.02.2011_18.26.17_log.txt
[2009/06/11 15:11:40 | 000,000,149 | —- | M] () – C:\UI_bean.log

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINNT\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINNT\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINNT\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINNT\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/04/29 09:08:31 | 000,000,067 | -HS- | M] () – C:\WINNT\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/06/14 12:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINNT\system32\spool\prtprocs\w32x86\CNMPD6y.DLL
[2004/06/14 12:00:00 | 000,054,272 | —- | M] (CANON INC.) – C:\WINNT\system32\spool\prtprocs\w32x86\CNMPP6y.DLL
[2008/07/06 04:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINNT\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINNT\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINNT\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 02:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINNT\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2004/04/07 11:49:19 | 000,000,271 | -HS- | M] () – C:\Program Files\desktop.ini
[2004/04/07 11:49:19 | 000,021,952 | -H– | M] () – C:\Program Files\folder.htt

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/04/29 01:56:28 | 000,262,144 | —- | M] () – C:\WINNT\system32\config\default.sav
[2004/04/29 08:48:53 | 000,024,576 | —- | M] () – C:\WINNT\system32\config\security.sav
[2004/04/29 01:56:28 | 018,612,224 | —- | M] () – C:\WINNT\system32\config\software.sav
[2004/04/29 01:56:29 | 003,145,728 | —- | M] () – C:\WINNT\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2004/10/01 18:07:43 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/10/01 18:19:06 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\bean\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2005/12/15 16:38:13 | 000,250,368 | —- | M] () – C:\Documents and Settings\bean\Desktop\CSAMP.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >
[2008/09/01 12:42:52 | 000,000,840 | —- | M] () – C:\WINNT\java\javalog.txt

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2001/08/23 04:00:00 | 000,000,791 | —- | M] () – C:\WINNT\addins\fxsext.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >
[1999/12/07 04:00:00 | 000,000,654 | —- | M] () – C:\WINNT\Config\general.idf
[1999/12/07 04:00:00 | 000,000,658 | —- | M] () – C:\WINNT\Config\hindered.idf
[1999/12/07 04:00:00 | 000,000,302 | —- | M] () – C:\WINNT\Config\msadlib.idf

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/12/14 10:58:32 | 000,000,371 | —- | M] () – C:\Documents and Settings\bean\Favorites\.LNK
[2010/12/14 10:58:32 | 000,000,519 | —- | M] () – C:\Documents and Settings\bean\Favorites\Christmas.LNK
[2004/10/01 18:19:06 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\bean\Favorites\Desktop.ini
[2010/12/14 10:58:32 | 000,000,423 | —- | M] () – C:\Documents and Settings\bean\Favorites\Digital Pictures.LNK
[2010/12/14 10:58:33 | 000,000,406 | —- | M] () – C:\Documents and Settings\bean\Favorites\Shared.LNK

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2004/04/29 09:14:32 | 000,002,334 | RHS- | M] () – C:\Documents and Settings\All Users\ntuser.pol

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/02/01 18:25:06 | 000,081,920 | -HS- | M] () – C:\Documents and Settings\bean\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-19 00:28:53

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >


OTL Extras logfile created on: 2/1/2011 6:33:08 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\bean\Desktop\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 461.00 Mb Available Physical Memory | 45.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 76.25 Gb Free Space | 68.22% Space Free | Partition Type: NTFS
Drive D: | 115.76 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: BEAN | User Name: bean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – %1
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3703:TCP" = 3703:TCP:*:Enabled:Adobe Version Cue CS3 Server
"3704:TCP" = 3704:TCP:*:Enabled:Adobe Version Cue CS3 Server
"50900:TCP" = 50900:TCP:*:Enabled:Adobe Version Cue CS3 Server
"50901:TCP" = 50901:TCP:*:Enabled:Adobe Version Cue CS3 Server

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sprint VPN Client\Extranet.exe" = C:\Program Files\Sprint VPN Client\Extranet.exe:*:Enabled:Contivity VPN Client
"C:\Program Files\Grisoft\AVG7\avginet.exe" = C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe" = C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe
"C:\Program Files\Grisoft\AVG7\avgcc.exe" = C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe
"C:\Program Files\Grisoft\AVG7\avgemc.exe" = C:\Program Files\Grisoft\AVG7\avgemc.exe:*:Enabled:avgemc.exe
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" = C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:*:Enabled:Adobe Version Cue CS3 Server – (Adobe Systems Incorporated)
"C:\Program Files\AT&T Global Network Client\NetClient.exe" = C:\Program Files\AT&T Global Network Client\NetClient.exe:*:Enabled:Network access client
"C:\Program Files\AT&T\Communication Manager\SwiApiMux.exe" = C:\Program Files\AT&T\Communication Manager\SwiApiMux.exe:*:Enabled:SwiApiMux


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{109AB81D-9732-40B3-9C1F-113A86CE6F93}" = Canon MP Navigator 1.0
"{13413C6C-C640-40B8-917E-CA3062826B18}" = PIXELA ImageMixer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18A5DFF2-8A95-49F3-873F-743CB5549F3D}" = Canon ScanGear Starter
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1D58229F-C505-45CA-8223-F35F3A34B963}" = Adobe Version Cue CS3 Server
"{21BAC2EC-527A-4AD5-954E-08BE4C9B2C38}" = Adobe Creative Suite 3 Web Standard
"{26CE07F6-E85C-473D-833C-E8C83118D0C2}" = PlexTools Professional V2.01
"{28ADA52D-B7AF-442C-8B7F-CEB9ECC28078}" = MMC81
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HydraVision
"{3FF3DD04-F386-46B0-97FC-B86238B65487}" = Canon MP Drivers 6.0
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{5EB503D5-F057-47B0-A49C-EBDDAA249927}" = Adobe Setup
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE 2.0
"{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}" = Adobe Dreamweaver CS3
"{7DFC1012-D346-46CE-B03E-FF79125AE029}" = Adobe Fireworks CS3
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD 4
"{9933F0EE-DFCD-4829-B979-3C56C367CB1A}" = InterVideo WinDVD Creator
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-0000-7760-000000000004}" = Adobe Acrobat 9 Pro
"{AC76BA86-1033-0000-7760-000000000004}_934" = Adobe Acrobat 9.3.4 - CPSID_83708
"{AC76BA86-1033-0000-7760-000000000004}{AC76BA86-1033-0000-7760-000000000004}" = Adobe Acrobat 9 Pro
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0B165DC-F037-483F-B1C9-D89D91529CEB}" = Citrix XenApp Web Plugin
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}" = WinZip 15.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D3661269-10B6-495F-B4EE-539ABE3F9AA9}" = DVDDec
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{FC9E08AA-CD59-4C59-BEF9-87E05B9E37D7}" = Adobe Contribute CS3
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"ACDSee" = ACDSee
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe PageMaker 6.5" = Adobe PageMaker 6.5
"Adobe Photoshop 4.0 LE" = Adobe Photoshop 4.0 LE
"Adobe_fca3a29c624ecd6945fd31fd99a1eb1" = Add or Remove Adobe Creative Suite 3 Web Standard
"All ATI Software" = ATI - Software Uninstall Utility
"ASUS Probe V2.21.07" = ASUS Probe V2.21.07
"AsusUpdate" = AsusUpdate
"ATI Display Driver" = ATI Display Driver
"ClickArt 10,000 Image Pack 1.0" = ClickArt® 10,000 Image Pack
"ClickArt Celebrations & Holidays 2 2.0" = ClickArt Celebrations & Holidays 2
"ClickArt Gallery 1.0" = ClickArt® Gallery
"DAO 3.5" = DAO 3.5
"DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5_is1" = DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.0.3.0
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"ENTERPRISER" = Microsoft Office Enterprise 2007
"Exterminate It!" = Exterminate It!
"Gadwin PrintScreen" = Gadwin PrintScreen
"HP Photo Imaging Software" = HP Photo Imaging Software
"HP Photo Printing Software" = HP Photo Printing Software
"InstallShield_{28ADA52D-B7AF-442C-8B7F-CEB9ECC28078}" = ATI Multimedia Center [removed]
"InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"InstallShield_{D3661269-10B6-495F-B4EE-539ABE3F9AA9}" = ATI DVD Decoder 2.2.0.0
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NeroMultiInstaller!UninstallKey" = Nero Suite
"PROSet" = Intel® PRO Network Adapters and Drivers
"Quicken Basic 2000" = Quicken Basic 2000
"QuickTime32" = QuickTime for Windows (32-bit)
"RealPlayer 6.0" = RealPlayer
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoneAlarm Extreme Security" = ZoneAlarm Extreme Security
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/31/2011 9:10:50 AM | Computer Name = BEAN | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 1/31/2011 9:10:50 AM | Computer Name = BEAN | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 1/31/2011 9:44:52 AM | Computer Name = BEAN | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 1/31/2011 9:44:52 AM | Computer Name = BEAN | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 1/31/2011 10:55:50 AM | Computer Name = BEAN | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 1/31/2011 10:55:50 AM | Computer Name = BEAN | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/1/2011 10:01:29 PM | Computer Name = BEAN | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/1/2011 10:01:29 PM | Computer Name = BEAN | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/1/2011 10:01:32 PM | Computer Name = BEAN | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/1/2011 10:01:32 PM | Computer Name = BEAN | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

[ System Events ]
Error - 1/22/2011 4:46:30 PM | Computer Name = BEAN | Source = Service Control Manager | ID = 7034
Description = The TrueVector Internet Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 1/22/2011 6:46:05 PM | Computer Name = BEAN | Source = cbserial | ID = 393234
Description = No Parameters subkey was found for user defined data. This is odd,
and it also means no user configuration can be found.

Error - 1/22/2011 7:37:34 PM | Computer Name = BEAN | Source = cbserial | ID = 393234
Description = No Parameters subkey was found for user defined data. This is odd,
and it also means no user configuration can be found.

Error - 1/25/2011 8:50:35 PM | Computer Name = BEAN | Source = cbserial | ID = 393234
Description = No Parameters subkey was found for user defined data. This is odd,
and it also means no user configuration can be found.

Error - 1/27/2011 12:00:29 PM | Computer Name = BEAN | Source = cbserial | ID = 393234
Description = No Parameters subkey was found for user defined data. This is odd,
and it also means no user configuration can be found.

Error - 1/30/2011 2:47:56 PM | Computer Name = BEAN | Source = cbserial | ID = 393234
Description = No Parameters subkey was found for user defined data. This is odd,
and it also means no user configuration can be found.

Error - 1/30/2011 6:38:08 PM | Computer Name = BEAN | Source = Removable Storage Service | ID = 262255
Description = RSM could not load media in drive Drive 0 of library Sony Sony DSC
USB Device.

Error - 1/30/2011 6:38:09 PM | Computer Name = BEAN | Source = Removable Storage Service | ID = 262255
Description = RSM could not load media in drive Drive 0 of library Sony Sony DSC
USB Device.

Error - 2/1/2011 10:01:37 PM | Computer Name = BEAN | Source = cbserial | ID = 393234
Description = No Parameters subkey was found for user defined data. This is odd,
and it also means no user configuration can be found.

Error - 2/1/2011 10:03:21 PM | Computer Name = BEAN | Source = Service Control Manager | ID = 7034
Description = The TrueVector Internet Monitor service terminated unexpectedly.
It has done this 1 time(s).


< End of report >

I humbly await your analysis and next set of instructions.
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Good morning, mowman! Here you go…..
ComboFix 11-01-31.02 - bean 02/02/2011 5:40.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.667 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: ZoneAlarm Extreme Security Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\bean\Application Data\inst.exe
c:\winnt\system32\system
c:\winnt\system32\win.ini
c:\winnt\Web\default.htt

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_IAS


((((((((((((((((((((((((( Files Created from 2011-01-02 to 2011-02-02 )))))))))))))))))))))))))))))))
.

2011-01-22 23:08 . 2011-01-22 23:26 ——– d—–w- c:\program files\Exterminate It!
2011-01-22 21:44 . 2011-01-22 21:44 ——– d—–w- c:\documents and settings\bean\Application Data\Malwarebytes
2011-01-22 21:43 . 2010-12-21 02:09 38224 —-a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2011-01-22 21:43 . 2011-01-22 21:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-01-22 21:43 . 2011-01-22 21:43 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-01-22 21:43 . 2010-12-21 02:08 20952 —-a-w- c:\winnt\system32\drivers\mbam.sys
2011-01-21 20:25 . 2011-01-21 20:33 ——– d—–w- C:\389d4af3da7b443f79
2011-01-21 20:22 . 2009-01-08 01:20 231456 —-a-w- C:\spuninst.exe
2011-01-21 18:14 . 2011-01-21 18:15 ——– d—–w- C:\Favorites

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-14 20:33 . 2009-08-14 20:33 13136 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2009-08-14 20:33 . 2009-08-14 20:33 70488 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2009-08-14 20:33 . 2009-08-14 20:33 91480 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2009-08-14 20:33 . 2009-08-14 20:33 20824 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2009-08-14 20:34 . 2009-08-14 20:34 206160 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2009-08-14 20:33 . 2009-08-14 20:33 31064 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2009-08-14 20:33 . 2009-08-14 20:33 40280 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2008-05-21 15:41 . 2008-05-21 15:41 479232 —-a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2008-05-21 15:41 . 2008-05-21 15:41 548864 —-a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2008-05-21 15:41 . 2008-05-21 15:41 626688 —-a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2009-08-14 19:50 . 2009-08-14 19:50 652640 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2009-08-14 20:33 . 2009-08-14 20:33 23896 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadwin PrintScreen 3.0"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2005-07-25 946176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-09-24 1011080]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2004-08-04 214528]
"tscuninstall"="c:\winnt\system32\tscupgrd.exe" [2004-08-04 44544]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 19:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\winnt\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\winnt\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^bean^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\documents and settings\bean\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\winnt\pss\Logitech . Product Registration.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^bean^Start Menu^Programs^Startup^MSOFFICE.EXE.lnk]
path=c:\documents and settings\bean\Start Menu\Programs\Startup\MSOFFICE.EXE.lnk
backup=c:\winnt\pss\MSOFFICE.EXE.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2010-06-19 19:36 640440 —-a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2010-06-20 02:04 38840 —-a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0EYTHM]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 07:56 15360 —-a-w- c:\winnt\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CXMon]
2000-08-14 23:48 32768 —-a-w- c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2009-06-17 16:55 55824 —-a-w- c:\winnt\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 19:50 155648 —-a-w- c:\winnt\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
2003-05-08 20:00 49152 —-a-w- c:\program files\ScanSoft\OmniPageSE2.0\opwareSE2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
2003-03-11 23:24 86016 —-a-w- c:\program files\Intel\NCS\PROSet\PRONoMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
2003-05-02 01:44 65536 —-a-w- c:\program files\Common Files\Roxio Shared\System\EngUtil.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
2003-05-30 16:42 585728 —-a-w- c:\program files\Analog Devices\SoundMAX\SMax4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2003-05-29 23:28 790528 —-a-w- c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
2004-08-04 07:56 143360 —-a-w- c:\winnt\system32\mobsync.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2007-03-10 22:02 180269 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SoundMAX Agent Service (default)"=2 (0x2)
"Bonjour Service"=2 (0x2)
"SCardSvr"=3 (0x3)
"ose"=3 (0x3)
"xmlprov"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Netlogon"=3 (0x3)
"NtLmSsp"=3 (0x3)
"SwPrv"=3 (0x3)
"NetSvc"=3 (0x3)
"gusvc"=2 (0x2)
"SharedAccess"=2 (0x2)
"seclogon"=2 (0x2)
"ERSvc"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R2 ISWKL;ZoneAlarm ForceField ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [4/17/2009 12:11 AM 25208]
R2 IswSvc;ZoneAlarm ForceField IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [4/17/2009 12:11 AM 439664]
R2 LBeepKE;LBeepKE;c:\winnt\system32\drivers\LBeepKE.sys [8/17/2010 10:06 AM 10384]
R2 mrtRate;mrtRate;c:\winnt\system32\drivers\MrtRate.sys [4/9/2004 10:44 AM 34916]
R2 portmon;Cyber10x Driver;c:\winnt\system32\drivers\portmon.sys [3/30/2000 7:16 PM 4961]
R3 cbserial;Cyber Port Driver;c:\winnt\system32\drivers\cbserial.sys [2/6/2000 12:47 PM 60856]
R3 icsak;icsak;c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [4/17/2009 12:11 AM 35448]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\winnt\system32\drivers\LEqdUsb.sys [6/17/2009 8:55 AM 40720]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\winnt\system32\drivers\LHidEqd.sys [6/17/2009 8:55 AM 10384]
S3 PTUMWBus;PANTECH USB Modem V2 Composite Device Driver;c:\winnt\system32\DRIVERS\PTUMWBus.sys –> c:\winnt\system32\DRIVERS\PTUMWBus.sys [?]
S3 PTUMWCDF;PANTECH USB Modem V2 Installation CD;c:\winnt\system32\DRIVERS\PTUMWCDF.sys –> c:\winnt\system32\DRIVERS\PTUMWCDF.sys [?]
S3 PTUMWFLT;PTUMWNET Filter Driver;c:\winnt\system32\DRIVERS\PTUMWFLT.sys –> c:\winnt\system32\DRIVERS\PTUMWFLT.sys [?]
S3 PTUMWMdm;PANTECH USB Modem V2 Modem Driver;c:\winnt\system32\DRIVERS\PTUMWMdm.sys –> c:\winnt\system32\DRIVERS\PTUMWMdm.sys [?]
S3 PTUMWNET;PANTECH USB Modem V2 WWAN Driver;c:\winnt\system32\DRIVERS\PTUMWNET.sys –> c:\winnt\system32\DRIVERS\PTUMWNET.sys [?]
S3 PTUMWVsp;PANTECH USB Modem V2 Diagnostic Port;c:\winnt\system32\DRIVERS\PTUMWVsp.sys –> c:\winnt\system32\DRIVERS\PTUMWVsp.sys [?]
S3 SWNC8UA3;Sierra Wireless MUX NDIS Driver (UMTSA3);c:\winnt\system32\drivers\swnc8ua3.sys [3/31/2009 12:45 PM 190080]
S3 SWUMXA3;Sierra Wireless USB MUX Driver (UMTSA3);c:\winnt\system32\drivers\swumxa3.sys [5/4/2009 1:57 PM 148096]
.
Contents of the 'Scheduled Tasks' folder

2009-01-28 c:\winnt\Tasks\01-28-09 backup.job
- c:\winnt\system32\ntbackup.exe [2001-08-23 07:56]

2011-01-31 c:\winnt\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2008-02-22 19:25]

2011-01-31 c:\winnt\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 19:25]

2011-02-02 c:\winnt\Tasks\WGASetup.job
- c:\winnt\system32\KB905474\wgasetup.exe [2009-05-13 05:18]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = about:blank
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: interfaces = 63.241.202.77,165.110.40.99
TCP: {C65391FA-87DA-4AB3-BF70-E7BCA3D82F8D} = 64.203.112.13,64.203.112.14
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
DPF: {CAEAFE12-7726-4C39-B620-2601216CFBB5} - hxxp://phughescw.hughes.motive.com/wizlet/spaceway/static/controls/Mcci_6-1-0.cab
FF - ProfilePath - c:\documents and settings\bean\Application Data\Mozilla\Firefox\Profiles\zyuntfv5.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: ForceField Toolbar: {FFB96CC1-7EB3-449D-B827-DB661701C6BB} - c:\program files\CheckPoint\ZAForceField\TrustChecker
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\winnt\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
HKLM-Run-{F9AA8FE2-E89A-E99B-E8b8-E9AE9B9ABA99} - c:\program files\Cricket Broadband Connect\AvqAutoRun.exe
ShellExecuteHooks-{56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
Notify-ATINotify - logonnfy.dll
SafeBoot-sglfb.sys
SafeBoot-tga.sys
MSConfigStartUp-DriverCure - c:\program files\ParetoLogic\DriverCure\DriverCure.exe
MSConfigStartUp-HughesNetTools_McciTrayApp - c:\program files\HughesNetTools\1\McciTrayApp_SSR.exe
MSConfigStartUp-Logitech Utility - Logi_MwX.Exe
MSConfigStartUp-NetSP - restore settings on power failure - c:\program files\AT&T Global Network Client\NetSP.exe
MSConfigStartUp-ParetoLogic Anti-Spyware - c:\program files\ParetoLogic\Anti-Spyware\Pareto_AS.exe
MSConfigStartUp-PC Pitstop Optimize Reminder - c:\program files\PCPitstop\Optimize2\Reminder.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-zBrowser Launcher - c:\program files\Logitech\iTouch\iTouch.exe
AddRemove-Adobe PageMaker 6.5 - c:\pm65\DeIsL1.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-02 05:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(548)
c:\winnt\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\program files\CheckPoint\ZAForceField\AK\icsak.dll

- - - - - - - > 'lsass.exe'(604)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\program files\CheckPoint\ZAForceField\AK\icsak.dll

- - - - - - - > 'explorer.exe'(3972)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\program files\CheckPoint\ZAForceField\AK\icsak.dll
c:\winnt\system32\WPDShServiceObj.dll
c:\winnt\system32\PortableDeviceTypes.dll
c:\winnt\system32\PortableDeviceApi.dll

- - - - - - - > 'csrss.exe'(516)
c:\program files\CheckPoint\ZAForceField\AK\akconsole.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\winnt\System32\MsPMSPSv.exe
c:\winnt\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-02-02 05:59:48 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-02 13:59

Pre-Run: 83,631,882,240 bytes free
Post-Run: 83,899,953,152 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 61165B6F4BF99CDD12F5D25DEA1A9420

Many, many thanks!
Sierra
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Ok, mowman…here are the results of both scans. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5667 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 2/3/2011 5:23:55 AM mbam-log-2011-02-03 (05-23-55).txt Scan type: Quick scan Objects scanned: 143708 Time elapsed: 4 minute(s), 25 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=c1db639880d5a246821c442b98486373 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-02-03 02:39:21 # local_time=2011-02-03 06:39:21 (-0800, Pacific Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5890 16777214 0 6 57011291 57011538 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # compatibility_mode=9217 16776874 100 77 8279094 42751822 0 0 # scanned=143695 # found=4 # cleaned=4 # scan_time=3495 C:\Program Files\ZoneAlarmSB\bar\1.bin\NPZONESB.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\ZoneAlarmSB\bar\1.bin\Z4PLUGIN.DLL a variant of Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{D3C81392-F794-4711-A70E-C69EC7A66CBA}\RP190\A0049943.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{D3C81392-F794-4711-A70E-C69EC7A66CBA}\RP190\A0049944.DLL a variant of Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
Hi, mowman,
I haven't tried to use the internet until you were finished. The computer runs fine, it's my internet and videos specifically that would not work or display. I will go for a test drive right now and get back to you. In the meantime, here are the scan results.

OTL logfile created on: 2/3/2011 7:15:29 PM - Run 3
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\bean\Desktop\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 497.00 Mb Available Physical Memory | 49.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 78.01 Gb Free Space | 69.79% Space Free | Partition Type: NTFS
Drive D: | 115.76 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: BEAN | User Name: bean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\bean\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\WINNT\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWMGR.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe (SonicWALL, Inc.)
PRC - C:\WINNT\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\bean\Desktop\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Program Files\CheckPoint\ZAForceField\AK\icsak.dll (Check Point Software Technologies)
MOD - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MlfHook.dll ()
MOD - C:\WINNT\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINNT\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINNT\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (wuauserv) – File not found
SRV - (vsmon) – C:\WINNT\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Adobe Version Cue CS3) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
SRV - (UtilMan) – C:\WINNT\system32\utilman.exe (Microsoft Corporation)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (vsdatant) – C:\WINNT\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (icsak) – C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys (Check Point Software Technologies)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (TSP) – C:\WINNT\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (LMouFilt) – C:\WINNT\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINNT\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LHidEqd) – C:\WINNT\system32\drivers\LHidEqd.sys (Logitech, Inc.)
DRV - (LEqdUsb) – C:\WINNT\system32\drivers\LEqdUsb.sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINNT\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (SWUMXA3) Sierra Wireless USB MUX Driver (UMTSA3) – C:\WINNT\system32\drivers\swumxa3.sys (Sierra Wireless Inc.)
DRV - (SWNC8UA3) Sierra Wireless MUX NDIS Driver (UMTSA3) – C:\WINNT\system32\drivers\swnc8ua3.sys (Sierra Wireless Inc.)
DRV - (ati2mtag) – C:\WINNT\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (MPE) – C:\WINNT\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (mf) – C:\WINNT\system32\drivers\mf.sys (Microsoft Corporation)
DRV - (Cdr4_2K) – C:\WINNT\System32\drivers\cdr4_2K.sys (Roxio)
DRV - (Cdralw2k) – C:\WINNT\System32\drivers\cdralw2k.sys (Roxio)
DRV - (avpnnic) – C:\WINNT\system32\drivers\avpnnic.sys (AT&T)
DRV - (pfc) – C:\WINNT\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (MidiSyn) – C:\WINNT\system32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (Nbf) – C:\WINNT\system32\drivers\NBF.SYS (Microsoft Corporation)
DRV - (portmon) – C:\WINNT\system32\drivers\portmon.sys ()
DRV - (cbserial) – C:\WINNT\system32\drivers\cbserial.sys (Windows ® 2000 DDK provider)
DRV - (mrtRate) – C:\WINNT\System32\drivers\MrtRate.sys (Marimba, Inc.)
DRV - (aslm75) – C:\WINNT\system32\drivers\ASLM75.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.36.15

FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/01/10 06:14:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/30 11:34:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/30 11:35:16 | 000,000,000 | —D | M]

[2009/10/10 13:20:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\bean\Application Data\Mozilla\Extensions
[2009/12/22 21:11:54 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\bean\Application Data\Mozilla\Firefox\Profiles\zyuntfv5.default\extensions
[2009/10/10 13:49:00 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\bean\Application Data\Mozilla\Firefox\Profiles\zyuntfv5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/22 21:11:54 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\bean\Application Data\Mozilla\Firefox\Profiles\zyuntfv5.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2009/10/10 13:20:29 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/01/10 06:14:19 | 000,000,000 | —D | M] (ForceField Toolbar) – C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
[2009/08/14 12:33:22 | 000,070,488 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2009/08/14 12:33:30 | 000,091,480 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2009/08/14 12:33:26 | 000,020,824 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2008/05/21 07:41:08 | 000,479,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2008/05/21 07:41:08 | 000,548,864 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2008/05/21 07:41:08 | 000,626,688 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2009/08/14 12:35:40 | 000,427,344 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2009/08/14 12:33:22 | 000,023,896 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll

O1 HOSTS File: ([2011/02/02 05:51:04 | 000,000,027 | —- | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O2 - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (ZoneAlarm Spy Blocker BHO) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Gadwin PrintScreen 3.0] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} http://www.verizon.net/checkmypc/includes/MotivePreQual.cab (PreQualifier Class)
O16 - DPF: {CAEAFE12-7726-4C39-B620-2601216CFBB5} http://phughescw.hughes.motive.com/wizlet/…/Mcci_6-1-0.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll (PCPitstop Exam)
O16 - DPF: DirectAnimation Java Classes file://C:\WINNT\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINNT\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\wzcnotif: DllName - wzcdlg.dll - C:\WINNT\System32\wzcdlg.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\bean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\bean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/07 11:50:14 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/03 05:36:49 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/02/02 05:39:13 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/02/02 05:36:06 | 000,212,480 | —- | C] (SteelWerX) – C:\WINNT\SWXCACLS.exe
[2011/02/02 05:36:06 | 000,161,792 | —- | C] (SteelWerX) – C:\WINNT\SWREG.exe
[2011/02/02 05:36:06 | 000,136,704 | —- | C] (SteelWerX) – C:\WINNT\SWSC.exe
[2011/02/02 05:36:06 | 000,031,232 | —- | C] (NirSoft) – C:\WINNT\NIRCMD.exe
[2011/02/02 05:35:53 | 000,000,000 | —D | C] – C:\WINNT\ERDNT
[2011/02/02 05:33:48 | 000,000,000 | —D | C] – C:\Qoobox
[2011/02/02 05:31:13 | 000,000,000 | —D | C] – C:\Documents and Settings\bean\Desktop\What the Tech
[2011/02/01 18:24:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2011/01/22 15:08:03 | 000,000,000 | —D | C] – C:\Program Files\Exterminate It!
[2011/01/22 15:08:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Exterminate It!
[2011/01/22 13:44:08 | 000,000,000 | —D | C] – C:\Documents and Settings\bean\Application Data\Malwarebytes
[2011/01/22 13:43:56 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbamswissarmy.sys
[2011/01/22 13:43:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/01/22 13:43:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/01/22 13:43:52 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2011/01/22 13:43:52 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/01/21 12:25:27 | 000,000,000 | —D | C] – C:\389d4af3da7b443f79
[2011/01/21 12:22:57 | 000,231,456 | —- | C] (Microsoft Corporation) – C:\spuninst.exe
[2011/01/21 10:16:12 | 000,000,000 | —D | C] – C:\Documents and Settings\bean\My Documents\Favorites
[2011/01/21 10:14:45 | 000,000,000 | —D | C] – C:\Favorites
[2008/05/29 14:46:26 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\bean\Application Data\pcouffin.sys
[2004/08/25 14:22:08 | 000,151,552 | —- | C] ( ) – C:\WINNT\System32\ATIDEMGR.dll
[6 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
[13 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/03 19:05:33 | 000,000,741 | —- | M] () – C:\WINNT\WORDZAP.INI
[2011/02/03 18:00:00 | 000,000,436 | —- | M] () – C:\WINNT\tasks\ParetoLogic Registration.job
[2011/02/03 17:07:17 | 000,004,212 | -H– | M] () – C:\WINNT\System32\zllictbl.dat
[2011/02/03 16:54:37 | 000,000,256 | —- | M] () – C:\WINNT\tasks\WGASetup.job
[2011/02/03 16:52:10 | 000,000,144 | —- | M] () – C:\WINNT\System32\pdfl.dat
[2011/02/03 16:52:03 | 000,001,374 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2011/02/03 16:50:49 | 000,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2011/02/03 16:50:46 | 1072,484,352 | -HS- | M] () – C:\hiberfil.sys
[2011/02/03 05:16:37 | 000,002,529 | —- | M] () – C:\Documents and Settings\bean\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007 (2).lnk
[2011/02/02 05:53:00 | 000,478,734 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2011/02/02 05:53:00 | 000,087,192 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2011/02/02 05:51:04 | 000,000,027 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2011/02/02 05:39:19 | 000,000,323 | RHS- | M] () – C:\boot.ini
[2011/02/02 05:32:58 | 004,263,406 | R— | M] () – C:\Documents and Settings\bean\Desktop\ComboFix.exe
[2011/02/01 18:24:58 | 000,001,728 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2011/01/31 00:33:01 | 000,000,414 | —- | M] () – C:\WINNT\tasks\ParetoLogic Update Version2.job
[2011/01/25 17:22:35 | 000,000,304 | —- | M] () – C:\WINNT\QTW.INI
[2011/01/22 15:08:03 | 000,000,756 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Exterminate It!.lnk
[2011/01/22 13:43:56 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/21 13:24:38 | 000,380,159 | —- | M] () – C:\Documents and Settings\bean\My Documents\Reinstalling XP.docx
[2011/01/21 12:31:52 | 000,001,374 | —- | M] () – C:\WINNT\imsins.BAK
[2011/01/15 22:15:14 | 000,002,411 | —- | M] () – C:\WINNT\panose.bin
[6 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
[13 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/02 05:39:19 | 000,000,207 | —- | C] () – C:\Boot.bak
[2011/02/02 05:39:14 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/02/02 05:36:06 | 000,256,512 | —- | C] () – C:\WINNT\PEV.exe
[2011/02/02 05:36:06 | 000,098,816 | —- | C] () – C:\WINNT\sed.exe
[2011/02/02 05:36:06 | 000,089,088 | —- | C] () – C:\WINNT\MBR.exe
[2011/02/02 05:36:06 | 000,080,412 | —- | C] () – C:\WINNT\grep.exe
[2011/02/02 05:36:06 | 000,068,096 | —- | C] () – C:\WINNT\zip.exe
[2011/02/02 05:32:58 | 004,263,406 | R— | C] () – C:\Documents and Settings\bean\Desktop\ComboFix.exe
[2011/02/01 18:24:58 | 000,001,728 | —- | C] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2011/01/22 15:08:03 | 000,000,756 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Exterminate It!.lnk
[2011/01/22 13:43:56 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/21 13:24:35 | 000,380,159 | —- | C] () – C:\Documents and Settings\bean\My Documents\Reinstalling XP.docx
[2010/06/20 13:06:39 | 000,000,031 | —- | C] () – C:\WINNT\warhead.ini
[2009/06/04 20:03:11 | 002,463,976 | —- | C] () – C:\WINNT\System32\NPSWF32.dll
[2009/04/18 13:20:00 | 000,005,824 | —- | C] () – C:\WINNT\System32\drivers\ASUSHWIO.SYS
[2008/05/29 14:46:47 | 000,000,034 | —- | C] () – C:\Documents and Settings\bean\Application Data\pcouffin.log
[2008/05/29 14:46:26 | 000,007,887 | —- | C] () – C:\Documents and Settings\bean\Application Data\pcouffin.cat
[2008/05/29 14:46:26 | 000,001,144 | —- | C] () – C:\Documents and Settings\bean\Application Data\pcouffin.inf
[2006/09/01 09:27:07 | 000,016,384 | —- | C] () – C:\WINNT\System32\WINKRNME.DLL
[2006/07/02 13:07:52 | 000,000,049 | —- | C] () – C:\WINNT\NeroDigital.ini
[2006/02/07 20:44:58 | 000,007,680 | —- | C] () – C:\WINNT\System32\CNMVS6y.DLL
[2006/02/06 19:36:33 | 000,000,532 | —- | C] () – C:\WINNT\MAXLINK.INI
[2006/02/06 19:22:07 | 000,000,398 | —- | C] () – C:\WINNT\System32\CNCMP60.INI
[2005/10/17 16:35:46 | 000,000,117 | —- | C] () – C:\WINNT\ulead32.ini
[2005/10/03 15:16:49 | 000,000,000 | —- | C] () – C:\WINNT\ATIMMC.INI
[2004/09/03 12:42:39 | 000,010,009 | —- | C] () – C:\WINNT\agnslang.ini
[2004/06/15 16:24:15 | 000,013,824 | —- | C] () – C:\Documents and Settings\bean\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/06/14 03:06:50 | 000,003,654 | —- | C] () – C:\WINNT\System32\drivers\Sonyhcp.dll
[2004/06/12 15:40:28 | 000,000,000 | —- | C] () – C:\WINNT\QFN.ini
[2004/06/12 15:40:28 | 000,000,000 | —- | C] () – C:\WINNT\QDQICK.ini
[2004/06/02 19:47:59 | 000,000,286 | —- | C] () – C:\WINNT\pcps.ini
[2004/05/26 18:59:11 | 000,001,270 | —- | C] () – C:\WINNT\HPW5CSS.INI
[2004/05/26 18:59:11 | 000,000,650 | —- | C] () – C:\WINNT\HPW5DSM.INI
[2004/05/16 14:00:25 | 000,000,059 | —- | C] () – C:\WINNT\INTUIT.INI
[2004/05/08 12:30:02 | 000,000,004 | —- | C] () – C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameD.txt
[2004/04/30 12:26:35 | 000,000,266 | —- | C] () – C:\WINNT\cdplayer.ini
[2004/04/29 10:41:17 | 000,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2004/04/29 09:03:05 | 000,001,793 | —- | C] () – C:\WINNT\System32\fxsperf.ini
[2004/04/15 13:04:08 | 000,036,864 | —- | C] () – C:\WINNT\System32\hpcoinst.dll
[2004/04/12 17:32:16 | 000,000,024 | —- | C] () – C:\WINNT\qfnonl.ini
[2004/04/09 10:44:59 | 000,000,976 | —- | C] () – C:\WINNT\QUICKEN.INI
[2004/04/09 10:44:59 | 000,000,607 | —- | C] () – C:\WINNT\intuprof.ini
[2004/04/09 10:21:30 | 000,000,304 | —- | C] () – C:\WINNT\QTW.INI
[2004/04/09 10:17:46 | 000,210,944 | —- | C] () – C:\WINNT\System32\MSVCRT10.DLL
[2004/04/09 10:17:46 | 000,027,648 | —- | C] () – C:\WINNT\PFPICK.DLL
[2004/04/09 10:17:39 | 000,000,176 | —- | C] () – C:\WINNT\KPCMS.INI
[2004/04/09 09:44:59 | 000,000,741 | —- | C] () – C:\WINNT\WORDZAP.INI
[2004/04/07 14:54:26 | 000,204,800 | —- | C] () – C:\WINNT\System32\IVIresizeW7.dll
[2004/04/07 14:54:26 | 000,200,704 | —- | C] () – C:\WINNT\System32\IVIresizeA6.dll
[2004/04/07 14:54:26 | 000,192,512 | —- | C] () – C:\WINNT\System32\IVIresizeP6.dll
[2004/04/07 14:54:26 | 000,192,512 | —- | C] () – C:\WINNT\System32\IVIresizeM6.dll
[2004/04/07 14:54:26 | 000,188,416 | —- | C] () – C:\WINNT\System32\IVIresizePX.dll
[2004/04/07 14:54:26 | 000,020,480 | —- | C] () – C:\WINNT\System32\IVIresize.dll
[2004/04/07 14:43:54 | 000,000,008 | —- | C] () – C:\WINNT\System32\PROTOCOL.INI
[2004/04/07 12:36:32 | 000,000,065 | —- | C] () – C:\WINNT\iTouch.ini
[2004/04/07 12:17:56 | 000,000,701 | —- | C] () – C:\WINNT\ODBC.INI
[2004/04/07 12:10:30 | 000,006,272 | —- | C] () – C:\WINNT\System32\drivers\ASLM75.SYS
[2004/04/07 11:58:45 | 000,003,046 | —- | C] () – C:\WINNT\Ascd_tmp.ini
[2004/04/07 11:49:19 | 000,021,952 | -H– | C] () – C:\Program Files\folder.htt
[2004/04/07 04:36:59 | 000,004,073 | —- | C] () – C:\WINNT\ODBCINST.INI
[2003/02/11 08:58:50 | 000,126,976 | —- | C] () – C:\WINNT\System32\e1000msg.dll
[2002/12/18 15:10:36 | 000,006,048 | —- | C] () – C:\WINNT\System32\MCC16.DLL
[2002/09/23 14:39:44 | 000,013,601 | —- | C] () – C:\WINNT\System32\vctest.ini
[2000/03/30 19:16:48 | 000,004,961 | —- | C] () – C:\WINNT\System32\drivers\portmon.sys
[1999/12/07 04:00:00 | 000,176,400 | —- | C] () – C:\WINNT\System32\qcut.dll
[1999/09/25 02:36:24 | 000,088,816 | —- | C] () – C:\WINNT\System32\drivers\lvcam.sys
[1999/09/25 02:36:22 | 000,017,424 | —- | C] () – C:\WINNT\System32\drivers\lvsound.sys

========== LOP Check ==========

[2010/07/07 15:05:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T
[2009/11/05 16:58:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2009/03/20 14:31:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cached Installations
[2009/04/11 12:47:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/03/29 17:44:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2009/10/14 17:31:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
[2008/11/29 15:40:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2010/03/29 18:00:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/03/20 14:21:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
[2009/04/18 13:01:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/01/22 20:27:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2007/07/23 04:06:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/07/23 04:09:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2007/07/23 04:10:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2010/03/29 17:43:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/02/01 18:25:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/10/10 11:45:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipSE
[2011/02/02 05:21:30 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\#ISW.FS#
[2010/06/15 16:05:59 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\AT&T
[2011/01/22 16:22:15 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\Canon
[2009/10/14 17:27:11 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\CheckPoint
[2009/01/22 20:41:46 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\DriverCure
[2009/10/30 13:03:09 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\ICAClient
[2004/06/15 03:18:57 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\InterVideo
[2010/08/17 10:07:19 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\Leadertech
[2009/11/05 19:44:26 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\MailFrontier
[2009/03/20 14:36:20 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\ParetoLogic
[2006/02/06 19:36:36 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\ScanSoft
[2010/06/15 15:54:50 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\Sierra Wireless
[2008/06/13 05:31:32 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\Vso
[2010/12/15 18:25:46 | 000,000,000 | —D | M] – C:\Documents and Settings\bean\Application Data\Windows Search
[2009/01/28 15:22:00 | 000,000,818 | —- | M] () – C:\WINNT\Tasks\01-28-09 backup.job
[2011/02/03 18:00:00 | 000,000,436 | —- | M] () – C:\WINNT\Tasks\ParetoLogic Registration.job
[2011/01/31 00:33:01 | 000,000,414 | —- | M] () – C:\WINNT\Tasks\ParetoLogic Update Version2.job
[2011/02/03 16:54:37 | 000,000,256 | —- | M] () – C:\WINNT\Tasks\WGASetup.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
Well, mowman, there has been no improvement with my browser. RottenTomatoes.com does not fully load, nor does YouTube. I tried to play a video on YouTube and it shut the browser down completely. Poof. Same problem as before. Next I went to cbs.com to play a video there and same thing, browser just shut down immediately. Now what? Sierra
Mozilla is worse now, if that is possible. Tried to run a video from cbs.com and it shut down summarily. Same thing with You Tube. I could at least view some videos there, but not now, not at all. My problem from the very begining was with the browser, and with videos specifically. At least with the "This tab has been recovered" I could keep closing and reopening the brower and maybe on the third or fourth try, it would play or I could connect to the site I wanted to visit. That's not the case now. It's no videos all the time. Plus any page that loads with animation or scripting just fails to load completely. Lots of white space, if you know what I mean. I do not have a problem accessing my Gmail account, or my banking website, nor my connection to my office via a secured Citrix connection. So some sites are just fine, but it remains a browser problem. That's why I tried to uninstall it (IE8) and go back to IE7….with absolutely no success. That brought me to you. I thought I the iframer trojan was the culprit, but I don't think we can "clean" this system any more. Maybe it's a browser setting that has been disabled, or some plug ins are missing? So, okay, I'm signing off for now and will update to SP3. I did not do so because it caused so many problems when it came out. I hope I will be installing an updated, fixed version of SP3 from its original. Otherwise, I think I'm just in for more trouble. You'll be the first to know! Bye for now. Sierra
Hello, mowman. I successfully updated to SP3. After doing so, my browser reverted to IE6, but was VERY stable. Could watch all the videos I wanted without any trouble. Upgraded to IE7 and am still enjoying my stable internet connection. I''m still afraid of IE8, though. We never learned the cause of my problem, did we? Maybe it was SP2 and IE8 were incompatible? Anyway, I now have an uber squeaky clean pc after all those cleaners we ran! Thanks so much for your time and assistance. Sierra

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI