This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Will exeHelper run in XP?

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I saw the pinned post "Not able to run any tools or executables?" and believe I have the same problem. I can't run executables except in secure mode. The solution given is to download & run exeHelper but states it's for Vista or Windows7. Is there any similar fix for XP? I've run DDS and pasted the results below: . DDS (Ver_2011-08-26.01) - NTFSx86 MINIMAL Internet Explorer: 7.0.5730.13 Run by [removed] at 17:51:55 on 2011-11-05 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2310 [GMT -4:00] . FW: Online Armor Firewall *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe C:\WINDOWS\system32\svchost.exe -k netsvcs . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = uURLSearchHooks: H - No File BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - No File BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [Advanced SystemCare 4] "c:\program files\iobit\advanced systemcare 4\ASCTray.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe mPolicies-system: EnableLUA = 0 (0x0) IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www1.snapfish.com/SnapfishActivia.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1223389252718 DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://javadl.sun.com/webapps/download/AutoDL?BundleId=23100 DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.1 192.168.1.1 TCP: Interfaces\{A1BE310A-5B1F-440A-B860-E3090E99F7CA} : DhcpNameServer = 192.168.1.1 192.168.1.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\tallem~1\online~1\oaevent.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\george\application data\mozilla\firefox\profiles\df87ekpm.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 5555 FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\documents and settings\george\application data\move networks\plugins\npqmp071505000011.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll . ============= SERVICES / DRIVERS =============== . R?2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664] R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-6-9 13496] R2 IMFservice;IMF Service;c:\program files\iobit\iobit malware fighter\IMFsrv.exe [2011-6-9 821080] S0 PSeries;PSeries;c:\windows\system32\drivers\pseries.sys [2009-8-22 15390] S1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2009-6-20 198224] S1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2009-6-20 31824] S1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [2009-6-20 29776] S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-6-9 328536] S2 gupdate1ca543039bf9260;Google Update Service (gupdate1ca543039bf9260);c:\program files\google\update\GoogleUpdate.exe [2009-10-23 133104] S2 OAcat;Online Armor Helper Service;c:\program files\tall emu\online armor\oacat.exe [2009-6-20 361672] S2 SvcOnlineArmor;Online Armor;c:\program files\tall emu\online armor\oasrv.exe [2009-6-20 3052744] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-10-23 133104] S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe [2005-9-23 2799808] . =============== Created Last 30 ================ . . ==================== Find3M ==================== . 2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-06 13:20:51 1858944 —-a-w- c:\windows\system32\win32k.sys 2011-08-17 21:32:17 832512 —-a-w- c:\windows\system32\wininet.dll 2011-08-17 21:32:16 78336 —-a-w- c:\windows\system32\ieencode.dll 2011-08-17 21:32:16 1830912 ——w- c:\windows\system32\inetcpl.cpl 2011-08-17 21:32:15 17408 ——w- c:\windows\system32\corpol.dll 2011-08-17 13:49:54 138496 —-a-w- c:\windows\system32\drivers\afd.sys 2011-08-17 12:22:23 389120 —-a-w- c:\windows\system32\html.iec . ============= FINISH: 17:53:55.89 ===============
Hi

Yes,

exeHelper will run on XP, give it a try


then please run the following:


Please download exeHelper to your desktop.
  • Double-click on exeHelper.com to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).



NEXT


Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs
Almost nothing will run in normal operation, including exeHelper or any of the rkill programs. So far Firefox is the only successful executable I've found. The log file I posted was from DDS run in safe mode. Any hope of recovery? Thanks
Does the OTL program run in safe mode? the extension I gave you was .scr which is the same as the DDS extension.

Try this - if it wont run in normal mode, try safe mode:


  • Please download OTH.scr to your desktop.
  • Now download OTL to your desktop.
  • Double click the OTH file and select Kill All Processes, your desktop will go blank


    [external image: Posted Image]


    Then select Start OTL, - OTL will now run:
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Under Custom scan's and fixes section paste in the below in bold


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT


  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Neither OTL or OTH will run in normal mode

I did find out that Microsoft Word will run in normal mode

Is this a virus? Does it have a name? Any idea how it got onto my computer?

Here's contents of OTL and Extras text files

OTL logfile created on: 11/9/2011 6:43:22 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\George\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 75.07% Memory free
4.84 Gb Paging File | 4.29 Gb Available in Paging File | 88.60% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 99.20 Gb Total Space | 57.58 Gb Free Space | 58.05% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 2.59 Gb Free Space | 25.87% Space Free | Partition Type: NTFS

Computer Name: KELLY-LAPTOP | User Name: George | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\George\Desktop\OTH.scr (OldTimer Tools)
PRC - C:\Documents and Settings\George\Desktop\OTL.scr (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (IMFservice) – C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (SolidWorks Licensing Service) – C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (OAcat) – C:\Program Files\Tall Emu\Online Armor\OAcat.exe (Tall Emu)
SRV - (SvcOnlineArmor) – C:\Program Files\Tall Emu\Online Armor\oasrv.exe (Tall Emu)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (STacSV) – C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (msvsmon80) – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SmartDefragDriver) – C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
DRV - (OAnet) – C:\WINDOWS\system32\drivers\OAnet.sys (Tall Emu Pty Ltd)
DRV - (OAmon) – C:\WINDOWS\system32\drivers\OAmon.sys (Tall Emu)
DRV - (OADevice) – C:\WINDOWS\system32\drivers\OADriver.sys (Tall Emu)
DRV - (OEM02Dev) – C:\WINDOWS\system32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corp.)
DRV - (BCMWLNPF) – C:\WINDOWS\system32\drivers\BCMWLNPF.SYS (CACE Technologies)
DRV - (DLADResM) – C:\WINDOWS\system32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Roxio)
DRV - (OEM02Afx) – C:\WINDOWS\system32\drivers\OEM02Afx.sys (Creative Technology Ltd.)
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (OEM02Vfx) – C:\WINDOWS\system32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (PSeries) – C:\WINDOWS\System32\drivers\pseries.sys (Elan Digital Systems Ltd)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-21-1177238915-651377827-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1177238915-651377827-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-1177238915-651377827-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-21-1177238915-651377827-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKU\S-1-5-21-1177238915-651377827-839522115-1004\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\S-1-5-21-1177238915-651377827-839522115-1004\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-21-1177238915-651377827-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1177238915-651377827-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.%(version)s
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 5555
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\George\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\George\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/08/31 18:52:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/30 09:06:01 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Documents and Settings\George\Application Data\Move Networks [2010/04/04 18:47:30 | 000,000,000 | —D | M]

[2011/02/24 18:42:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\George\Application Data\Mozilla\Extensions
[2011/02/24 18:42:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\George\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2011/02/24 18:42:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\George\Application Data\Mozilla\Firefox\Profiles\df87ekpm.default\extensions
[2011/08/26 11:49:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/08/26 11:49:15 | 000,000,000 | —D | M] (Click to call with Skype) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/08/31 18:52:47 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/08/31 18:52:47 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/03/17 17:29:27 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/03/17 17:29:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/01/30 10:45:12 | 000,135,568 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2011/05/08 21:23:44 | 000,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2010/12/03 12:36:32 | 000,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2011/05/08 21:23:44 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/12/03 12:36:32 | 000,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2011/05/08 21:23:44 | 000,001,131 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2011/05/08 21:23:44 | 000,002,364 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2011/05/08 21:23:44 | 000,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2011/05/08 21:23:44 | 000,001,096 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: ([2010/12/11 17:51:09 | 000,412,950 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 14232 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - Reg Error: Value error. File not found
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-1177238915-651377827-839522115-1004\..\Toolbar\ShellBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1177238915-651377827-839522115-1004\..\Toolbar\WebBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1177238915-651377827-839522115-1004\..\Toolbar\WebBrowser: (&Links;) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKU\S-1-5-21-1177238915-651377827-839522115-1004..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKU\S-1-5-21-1177238915-651377827-839522115-1004..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1177238915-651377827-839522115-1004..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1177238915-651377827-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1177238915-651377827-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Value error.)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www1.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1223389252718 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100 (Java Plug-in 1.6.0_07)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} http://www.cvsphoto.com/upload/activex/v3_…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A1BE310A-5B1F-440A-B860-E3090E99F7CA}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) -C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) -C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") -C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - (%SystemRoot%\System32\dimsntfy.dll) - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (WgaLogon.dll) - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 () - About:Home
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Tall Emu\Online Armor\oaevent.dll (Tall Emu)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) -C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) -C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) -C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) -C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) -C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) -C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) -C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) -C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) -C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/30 13:19:28 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{736ec8bc-98f5-11dd-a6a0-001fe2dcbb1f}\Shell\auto\command - "" = Knight.exe open
O33 - MountPoints2\{736ec8bc-98f5-11dd-a6a0-001fe2dcbb1f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{736ec8bc-98f5-11dd-a6a0-001fe2dcbb1f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
O33 - MountPoints2\{736ec8bc-98f5-11dd-a6a0-001fe2dcbb1f}\Shell\explore\command - "" = Knight.exe open
O33 - MountPoints2\{736ec8bc-98f5-11dd-a6a0-001fe2dcbb1f}\Shell\find\command - "" = Knight.exe open
O33 - MountPoints2\{736ec8bc-98f5-11dd-a6a0-001fe2dcbb1f}\Shell\install\command - "" = Knight.exe open
O33 - MountPoints2\{736ec8bc-98f5-11dd-a6a0-001fe2dcbb1f}\Shell\open\command - "" = Knight.exe open
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/11/09 18:17:01 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\George\Desktop\OTL.exe
[2011/11/09 18:16:46 | 000,258,560 | —- | C] (OldTimer Tools) – C:\Documents and Settings\George\Desktop\OTH.scr
[2011/11/09 18:15:35 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\George\Desktop\OTL.scr
[2011/11/06 13:16:46 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\George\Desktop\aswMBR.exe
[2011/11/05 16:47:00 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\George\Desktop\dds.scr
[2011/11/05 10:48:10 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2008/09/06 11:49:00 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\George\Application Data\pcouffin.sys
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/09 18:30:18 | 000,426,070 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/09 18:30:18 | 000,065,080 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/09 18:26:20 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/09 18:24:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/09 18:19:03 | 000,142,511 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2011/11/09 18:17:02 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/09 18:17:01 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\George\Desktop\OTL.exe
[2011/11/09 18:16:44 | 000,258,560 | —- | M] (OldTimer Tools) – C:\Documents and Settings\George\Desktop\OTH.scr
[2011/11/09 18:15:33 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\George\Desktop\OTL.scr
[2011/11/09 06:09:42 | 000,000,526 | —- | M] () – C:\WINDOWS\tasks\PandaUSBVaccine.job
[2011/11/09 06:09:40 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/09 06:09:39 | 000,000,290 | —- | M] () – C:\WINDOWS\tasks\ASC4_AutoSweep.job
[2011/11/09 06:09:39 | 000,000,270 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/11/09 06:09:38 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/11/08 17:00:00 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\ASC4_AutoUpdate.job
[2011/11/06 13:52:17 | 001,008,092 | —- | M] () – C:\Documents and Settings\George\Desktop\uSeRiNiT.exe
[2011/11/06 13:52:11 | 001,008,092 | —- | M] () – C:\Documents and Settings\George\Desktop\WiNlOgOn.exe
[2011/11/06 13:16:50 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\George\Desktop\aswMBR.exe
[2011/11/05 16:02:48 | 000,302,592 | —- | M] () – C:\Documents and Settings\George\Desktop\v64fqms7.exe
[2011/11/05 15:57:32 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\George\Desktop\dds.scr
[2011/11/05 15:56:26 | 000,050,477 | —- | M] () – C:\Documents and Settings\George\Desktop\Defogger.exe
[2011/11/05 10:53:12 | 000,000,896 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Quick Care.lnk
[2011/11/05 10:53:12 | 000,000,892 | —- | M] () – C:\Documents and Settings\George\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/11/05 10:53:12 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk
[2011/10/28 16:00:00 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\ASC4_AutoCare.job
[2011/10/23 21:00:00 | 000,000,386 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag.job
[2011/10/14 14:43:50 | 000,253,472 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/06 13:53:24 | 001,008,092 | —- | C] () – C:\Documents and Settings\George\Desktop\WiNlOgOn.exe
[2011/11/06 13:53:24 | 001,008,092 | —- | C] () – C:\Documents and Settings\George\Desktop\uSeRiNiT.exe
[2011/11/06 13:19:16 | 001,006,778 | —- | C] () – C:\Documents and Settings\George\Desktop\rkill.scr
[2011/11/06 13:19:16 | 001,006,778 | —- | C] () – C:\Documents and Settings\George\Desktop\rkill.com
[2011/11/05 16:47:11 | 000,050,477 | —- | C] () – C:\Documents and Settings\George\Desktop\Defogger.exe
[2011/11/05 16:46:48 | 000,302,592 | —- | C] () – C:\Documents and Settings\George\Desktop\v64fqms7.exe
[2011/11/05 10:53:12 | 000,000,892 | —- | C] () – C:\Documents and Settings\George\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/06/09 20:38:39 | 000,029,520 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/06/09 20:38:38 | 000,013,496 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/02/23 18:09:16 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/02/07 18:52:15 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/30 20:28:27 | 000,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2010/10/23 13:50:22 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/10/03 09:49:58 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2010/09/12 11:30:18 | 000,120,200 | —- | C] () – C:\WINDOWS\System32\DLLDEV32i.dll
[2010/09/12 11:29:39 | 000,006,211 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2010/06/15 12:06:08 | 000,753,664 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2010/06/15 12:06:08 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2010/06/15 12:06:08 | 000,024,064 | —- | C] () – C:\WINDOWS\System32\WLTRYSVC.EXE
[2010/04/11 14:54:50 | 000,000,036 | —- | C] () – C:\Documents and Settings\George\Local Settings\Application Data\housecall.guid.cache
[2010/03/30 17:58:41 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2009/11/28 18:04:33 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2009/10/24 19:05:09 | 000,000,034 | -H– | C] () – C:\WINDOWS\System32\Converter_sysquict.dat
[2009/09/22 21:27:38 | 000,006,144 | —- | C] () – C:\Documents and Settings\George\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/09 17:10:29 | 000,001,044 | —- | C] () – C:\Documents and Settings\George\Application Data\vso_ts_preview.xml
[2008/09/06 11:49:00 | 000,087,608 | —- | C] () – C:\Documents and Settings\George\Application Data\inst.exe
[2008/09/06 11:49:00 | 000,007,887 | —- | C] () – C:\Documents and Settings\George\Application Data\pcouffin.cat
[2008/09/06 11:49:00 | 000,001,144 | —- | C] () – C:\Documents and Settings\George\Application Data\pcouffin.inf
[2008/09/04 20:33:25 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/09/01 14:01:33 | 000,000,047 | —- | C] () – C:\Documents and Settings\George\Application Data\AVSDVDPlayer.m3u
[2008/09/01 09:45:50 | 000,074,976 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2008/08/30 21:57:54 | 000,000,234 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/08/30 21:52:08 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/08/30 18:13:59 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2008/08/30 17:54:44 | 000,142,511 | —- | C] () – C:\WINDOWS\System32\nvModes.dat
[2008/08/30 17:52:08 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/08/30 17:52:08 | 001,626,112 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2008/08/30 17:52:08 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/08/30 17:52:08 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/08/30 17:52:07 | 001,482,752 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/08/30 17:52:07 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2008/08/30 17:52:06 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2008/08/30 17:52:05 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2008/08/30 15:27:36 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/08/30 13:22:20 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/08/30 13:16:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/08/30 09:09:10 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/08/30 09:08:03 | 000,253,472 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/16 10:58:04 | 000,012,632 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2007/08/21 20:46:34 | 000,059,160 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2006/05/24 17:16:22 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2005/03/21 18:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 18:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 05:00:00 | 000,426,070 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 05:00:00 | 000,065,080 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2001/11/14 12:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[1999/01/22 13:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/10/11 00:07:38 | 000,088,576 | —- | C] () – C:\WINDOWS\System32\Iticheck.dll
[1998/01/12 03:00:00 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\REGOBJ.DLL

========== LOP Check ==========

[2008/09/27 13:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVSVideoBurner
[2010/10/03 09:50:07 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/09/20 13:22:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/09/12 11:30:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MAGIX
[2008/08/30 18:14:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/08/30 19:34:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Novatel Wireless
[2009/06/20 15:49:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OnlineArmor
[2011/04/19 18:28:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2008/09/16 17:30:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBT
[2010/03/30 04:47:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2008/09/01 09:50:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/02/20 22:29:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/08/30 22:00:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2010/03/12 22:56:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/09/02 04:19:25 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\3M
[2010/12/11 15:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\Any Video Converter
[2010/12/11 15:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\Aura Video Converter
[2010/12/11 15:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\DeepBurner
[2011/11/05 11:19:05 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\FrostWire
[2009/11/28 19:36:40 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\IM
[2011/11/05 10:53:18 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\IObit
[2009/06/20 15:49:16 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\OnlineArmor
[2010/03/30 04:47:06 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\Sony
[2008/08/30 19:42:29 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\tmp
[2010/10/04 18:35:00 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\Vso
[2010/10/23 13:50:42 | 000,000,000 | —D | M] – C:\Documents and Settings\George\Application Data\WeatherBug
[2009/09/01 07:56:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\3M
[2009/08/22 20:30:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\Crayon Physics Deluxe
[2010/12/11 15:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\DeepBurner
[2008/12/17 10:58:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\FMZilla
[2010/12/30 17:39:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\FrostWire
[2010/02/20 22:24:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\GetRightToGo
[2011/06/09 20:39:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\IObit
[2010/12/11 15:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\MailFrontier
[2009/06/20 16:05:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\OnlineArmor
[2011/04/25 18:34:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\Ovusoft
[2008/09/13 16:13:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\Snapfish
[2008/11/06 04:57:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\tmp
[2010/03/07 10:13:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Kelly\Application Data\To-Do DeskList
[2011/10/28 16:00:00 | 000,000,288 | —- | M] () – C:\WINDOWS\Tasks\ASC4_AutoCare.job
[2011/11/09 06:09:39 | 000,000,290 | —- | M] () – C:\WINDOWS\Tasks\ASC4_AutoSweep.job
[2011/11/08 17:00:00 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\ASC4_AutoUpdate.job
[2011/11/09 06:09:39 | 000,000,270 | —- | M] () – C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/11/09 06:09:42 | 000,000,526 | —- | M] () – C:\WINDOWS\Tasks\PandaUSBVaccine.job
[2011/10/23 21:00:00 | 000,000,386 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job
[2011/11/09 06:09:38 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 05:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 19:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 19:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/04 05:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 05:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2011/11/06 13:52:17 | 001,008,092 | —- | M] () MD5=645A8F39A10306D50382EB49A6C49AAB – C:\Documents and Settings\George\Desktop\uSeRiNiT.exe
[2011/11/06 13:52:17 | 001,008,092 | —- | M] () MD5=645A8F39A10306D50382EB49A6C49AAB – C:\Documents and Settings\George\My Documents\Downloads\uSeRiNiT.exe
[2008/04/13 19:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 05:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2011/11/06 13:52:11 | 001,008,092 | —- | M] () MD5=645A8F39A10306D50382EB49A6C49AAB – C:\Documents and Settings\George\Desktop\WiNlOgOn.exe
[2011/11/06 13:52:11 | 001,008,092 | —- | M] () MD5=645A8F39A10306D50382EB49A6C49AAB – C:\Documents and Settings\George\My Documents\Downloads\WiNlOgOn.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 834 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:35E5AF34
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2D6E5D55

< End of report >


OTL Extras logfile created on: 11/9/2011 6:43:22 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\George\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 75.07% Memory free
4.84 Gb Paging File | 4.29 Gb Available in Paging File | 88.60% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 99.20 Gb Total Space | 57.58 Gb Free Space | 58.05% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 2.59 Gb Free Space | 25.87% Space Free | Partition Type: NTFS

Computer Name: KELLY-LAPTOP | User Name: George | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-1177238915-651377827-839522115-1004\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire 4.17.0 – (FrostWire Group)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger – (Microsoft Corporation)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Professional
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Disc 2
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1ADE23D7-7A1E-4AEC-BA5D-EB8A01BED943}" = DeepBurner v1.8.0.224
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{2FC099BD-AC9B-33EB-809C-D332E1B27C40}" = Microsoft .NET Framework 3.5
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{30F63D82-A342-11D4-B5BD-0050BA00A4DC}" = PCI PC Card Drive
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{4160A344-5848-4332-919F-0CB063822AA3}" = Dell Mobile Broadband Card Utility
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1" = Panda USB Vaccine 1.0.1.4
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6ABA1658-6429-4D01-875C-0EA6EE851AD1}" = Wireless PC Card
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B7917E0-AF55-4E8A-9473-017F0AA03AC8}" = QuickTime
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}" = Broadcom Gigabit Integrated Controller
"{D45E8C45-B601-4A80-AFD8-E16338744DE1}" = ArcSoft Panorama Maker 4
"{D481EA96-2313-4A7C-98EE-710D1AF884AC}" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"{DC888258-F37C-11D2-9594-00A0C9CD527E}" = PhotoAlbum Add-In
"{DCF67823-AFC3-11D3-BD80-0010A4E5C232}" = French Dictionary Update for Office 2000
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"4569969E1360D2854474C661EF9B4D54F143EB16" = Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
"7-Zip" = 7-Zip 4.57
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced DVD PlayerPro_is1" = Advanced DVD PlayerPro
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"Advanced Video FX Engine" = Advanced Video FX Engine
"Applian FLV Player2.0.24" = Applian FLV Player
"AviSynth" = AviSynth 2.5
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"Crayon Physics Deluxe Demo_is1" = Crayon Physics Deluxe Demo - release 52
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"DELL Webcam Center" = DELL Webcam Center
"DELL Webcam Manager" = DELL Webcam Manager
"DivX Setup.divx.com" = DivX Setup
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Flick_is1" = DVD Flick 1.3.0.7
"DVD Shrink_is1" = DVD Shrink 3.2
"DVD2one V2" = DVD2one V2.2.2
"ffdshow_is1" = ffdshow
"FrostWire" = FrostWire 4.17.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"MAGIX FunPix Maker US" = MAGIX FunPix Maker 1.0.0.0 (US)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5" = Microsoft .NET Framework 3.5
"Microsoft Visual Studio 2005 Tools for Applications - ENU" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"Mozilla Firefox 6.0.1 (x86 en-US)" = Mozilla Firefox 6.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OnlineArmor_is1" = Online Armor 3.5
"OpenMG HotFix4.7-07-13-22-01" = OpenMG Limited Patch 4.7-07-14-05-01
"PCFriendly" = PCFriendly
"Replay Media Catcher 3.01" = Replay Media Catcher 3.01
"SlowView" = SlowView
"Smart Defrag 2_is1" = Smart Defrag 2
"Taking Charge of Your Fertility Software" = Taking Charge of Your Fertility Software
"The Rosetta Stone" = The Rosetta Stone
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XVid;-)" = XVid;-)

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1177238915-651377827-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/9/2011 5:31:21 AM | Computer Name = KELLY-LAPTOP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 11/9/2011 5:31:21 AM | Computer Name = KELLY-LAPTOP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 11/9/2011 7:09:38 AM | Computer Name = KELLY-LAPTOP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 11/9/2011 7:09:38 AM | Computer Name = KELLY-LAPTOP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 11/9/2011 7:14:43 AM | Computer Name = KELLY-LAPTOP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 11/9/2011 7:14:43 AM | Computer Name = KELLY-LAPTOP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 11/9/2011 7:10:07 PM | Computer Name = KELLY-LAPTOP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 11/9/2011 7:10:07 PM | Computer Name = KELLY-LAPTOP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 11/9/2011 7:10:07 PM | Computer Name = KELLY-LAPTOP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 11/9/2011 7:10:07 PM | Computer Name = KELLY-LAPTOP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

[ System Events ]
Error - 11/9/2011 7:11:56 PM | Computer Name = KELLY-LAPTOP | Source = Service Control Manager | ID = 7001
Description = The SSDP Discovery Service service depends on the HTTP service which
failed to start because of the following error: %%5

Error - 11/9/2011 7:17:00 PM | Computer Name = KELLY-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdate1ca543039bf9260
with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}

Error - 11/9/2011 7:26:14 PM | Computer Name = KELLY-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 11/9/2011 7:26:21 PM | Computer Name = KELLY-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 11/9/2011 7:26:27 PM | Computer Name = KELLY-LAPTOP | Source = Service Control Manager | ID = 7001
Description = The DHCP Client service depends on the NetBios over Tcpip service
which failed to start because of the following error: %%31

Error - 11/9/2011 7:26:27 PM | Computer Name = KELLY-LAPTOP | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31

Error - 11/9/2011 7:26:27 PM | Computer Name = KELLY-LAPTOP | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 11/9/2011 7:26:27 PM | Computer Name = KELLY-LAPTOP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT OADevice OAmon OAnet RasAcd Rdbss Tcpip

Error - 11/9/2011 7:41:16 PM | Computer Name = KELLY-LAPTOP | Source = Service Control Manager | ID = 7031
Description = The Lavasoft Ad-Aware Service service terminated unexpectedly. It
has done this 1 time(s). The following corrective action will be taken in 5000
milliseconds: Restart the service.

Error - 11/9/2011 7:41:16 PM | Computer Name = KELLY-LAPTOP | Source = Service Control Manager | ID = 7034
Description = The IMF Service service terminated unexpectedly. It has done this
1 time(s).


< End of report >

Thanks for your help
Hi,

Please do the following:

first, make sure file extensions are showing:

  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Click Apply, and then click OK.



Download Combofix from either of the links below. You must rename it to combo.com before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

———————————————————–


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.

    ———————————————————–

  • Double click on the renamed ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

———————————————————–

I downloaded on a different computer, renamed, transfered to thumb drive then copied to desktop on problem computer. No luck. It won't execute and the same error message pops up. Should I run it in safe mode? Thanks
ran combofix in safe mode but without network connection
restore console not installed and I don't have DP discs

ComboFix 11-11-10.01 - George 11/10/2011 19:13:55.2.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2041 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo.com
FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((( Files Created from 2011-10-11 to 2011-11-11 )))))))))))))))))))))))))))))))
.
.
2011-11-06 18:54 . 2011-11-06 18:54 ——– d—–w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-26 15:41 . 2007-10-09 17:03 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 10:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 10:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12 . 2004-08-04 10:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2004-08-04 10:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-17 21:32 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2011-08-17 21:32 . 2008-09-06 01:36 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-08-17 21:32 . 2004-08-04 10:00 1830912 ——w- c:\windows\system32\inetcpl.cpl
2011-08-17 21:32 . 2004-08-04 10:00 17408 ——w- c:\windows\system32\corpol.dll
2011-08-17 13:49 . 2004-08-04 10:00 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2011-08-17 12:22 . 2004-08-04 10:00 389120 —-a-w- c:\windows\system32\html.iec
2011-08-31 23:52 . 2011-05-09 02:23 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-10_23.48.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 10:00 . 2011-11-11 00:14 65080 c:\windows\system32\perfc009.dat
+ 2004-08-04 10:00 . 2011-11-11 00:14 426070 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-08-09 417112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-22 13508608]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-9-1 50688]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-04-28 335048]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2007-10-09 23:17 2183168 —-a-w- c:\windows\system32\WLTRAY.EXE
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [6/9/2011 8:38 PM 13496]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [6/20/2009 3:47 PM 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [6/20/2009 3:47 PM 29776]
S0 PSeries;PSeries;c:\windows\system32\drivers\pseries.sys [8/22/2009 11:31 AM 15390]
S1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [6/20/2009 3:47 PM 198224]
S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [6/9/2011 8:35 PM 328536]
S2 gupdate1ca543039bf9260;Google Update Service (gupdate1ca543039bf9260);c:\program files\Google\Update\GoogleUpdate.exe [10/23/2009 5:29 PM 133104]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [6/9/2011 8:39 PM 821080]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [6/20/2009 3:45 PM 361672]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [6/20/2009 3:45 PM 3052744]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/23/2009 5:29 PM 133104]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [9/6/2008 11:49 AM 47360]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-28 c:\windows\Tasks\ASC4_AutoCare.job
- c:\program files\IObit\Advanced SystemCare 4\AutoCare.exe [2011-06-10 20:38]
.
2011-11-10 c:\windows\Tasks\ASC4_AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 4\AutoSweep.exe [2011-06-10 20:38]
.
2011-11-10 c:\windows\Tasks\ASC4_AutoUpdate.job
- c:\program files\IObit\Advanced SystemCare 4\AutoUpdate.exe [2011-06-10 21:39]
.
2011-11-10 c:\windows\Tasks\ASC4_PerformanceMonitor.job
- c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe [2011-06-10 20:40]
.
2011-11-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-23 22:28]
.
2011-11-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-23 22:28]
.
2011-11-10 c:\windows\Tasks\PandaUSBVaccine.job
- c:\program files\Panda USB Vaccine\RunInteractiveWin.exe [2011-04-19 20:45]
.
2011-11-10 c:\windows\Tasks\SmartDefrag_Startup.job
- c:\program files\IObit\Smart Defrag 2\SmartDefrag.exe [2011-06-10 21:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride =
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\documents and settings\George\Application Data\Mozilla\Firefox\Profiles\df87ekpm.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 5555
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-10 19:25
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(332)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2011-11-10 19:28:52
ComboFix-quarantined-files.txt 2011-11-11 00:28
ComboFix2.txt 2011-11-10 23:54
.
Pre-Run: 61,958,049,792 bytes free
Post-Run: 61,940,797,440 bytes free
.
- - End Of File - - 713DD74CE0DD5CA0FAC411E9D1C7DF94
hi,

Please try running the script in normal mode,

If it still wont run, then try it in safemode with networking and allow it to update/install the recovery console

please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

FireFox::
FF - ProfilePath - c:\documents and settings\George\Application Data\Mozilla\Firefox\Profiles\df87ekpm.default\
FF - prefs.js: network.proxy.http_port - 5555

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
I'm having a problem with network connection in safe mode and combo fix is unable to download & install Restore Console. I believe the issue is Windows is not currently handling network connection. I'm not sure how to change this and attempting anything in normal mode is very frustrating. I'll try again tonight. Thanks for your help and patience
This hijacked port is an issue and may be causing your problems

FF - prefs.js: network.proxy.http_port - 5555


I'm trying to fix that with ComboFix,

so run it in safe mode

then try running ComboFix without the script in Normal mode afterwards

post both logs
I ran combo fix in safe mode.

I updated MalwareBytes and ran quick scan in safemode

I ran ESETSCAN in safe mode

I rebooted and at first had blue screen with error message about inaccessible disc section and improperly installed software or hardware

I shut down computer, restarted and log in normal mode.
Same problem- most programs won't run, including combofix

Here's 3 logs from safe mode scans :

ComboFix 11-11-10.01 - George 11/11/2011 22:47:49.3.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2763 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo.com
Command switches used :: c:\docume~1\George\Desktop\CFScript.txt
FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
.
((((((((((((((((((((((((( Files Created from 2011-10-12 to 2011-11-12 )))))))))))))))))))))))))))))))
.
.
2011-11-06 18:54 . 2011-11-06 18:54 ——– d—–w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2008-08-30 18:17 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-26 15:41 . 2007-10-09 17:03 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 10:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 10:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12 . 2004-08-04 10:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2004-08-04 10:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-17 21:32 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2011-08-17 21:32 . 2008-09-06 01:36 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-08-17 21:32 . 2004-08-04 10:00 1830912 ——w- c:\windows\system32\inetcpl.cpl
2011-08-17 21:32 . 2004-08-04 10:00 17408 ——w- c:\windows\system32\corpol.dll
2011-08-17 13:49 . 2004-08-04 10:00 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2011-08-17 12:22 . 2004-08-04 10:00 389120 —-a-w- c:\windows\system32\html.iec
2011-08-31 23:52 . 2011-05-09 02:23 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-10_23.48.40 )))))))))))))))))))))))))))))))))))))))))
.
- 2010-10-23 17:10 . 2011-08-12 17:51 17272 c:\windows\system32\spmsg.dll
+ 2010-10-23 17:10 . 2010-07-05 13:15 17272 c:\windows\system32\spmsg.dll
+ 2004-08-04 10:00 . 2011-11-12 03:31 65080 c:\windows\system32\perfc009.dat
+ 2011-11-12 03:13 . 2011-11-12 03:13 7366 c:\windows\SoftwareDistribution\EventCache\{482BAC8A-2606-44E3-B8CD-0B1BC2D89311}.bin
+ 2004-08-04 10:00 . 2011-11-12 03:31 426070 c:\windows\system32\perfh009.dat
+ 2008-08-31 20:20 . 2011-10-10 14:22 692736 c:\windows\system32\dllcache\inetcomm.dll
- 2008-08-31 20:20 . 2011-05-02 15:31 692736 c:\windows\system32\dllcache\inetcomm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-08-09 417112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-22 13508608]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-9-1 50688]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-04-28 335048]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2007-10-09 23:17 2183168 —-a-w- c:\windows\system32\WLTRAY.EXE
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [6/9/2011 8:38 PM 13496]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [6/20/2009 3:47 PM 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [6/20/2009 3:47 PM 29776]
S0 PSeries;PSeries;c:\windows\system32\drivers\pseries.sys [8/22/2009 11:31 AM 15390]
S1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [6/20/2009 3:47 PM 198224]
S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [6/9/2011 8:35 PM 328536]
S2 gupdate1ca543039bf9260;Google Update Service (gupdate1ca543039bf9260);c:\program files\Google\Update\GoogleUpdate.exe [10/23/2009 5:29 PM 133104]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [6/9/2011 8:39 PM 821080]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [6/20/2009 3:45 PM 361672]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [6/20/2009 3:45 PM 3052744]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/23/2009 5:29 PM 133104]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [9/6/2008 11:49 AM 47360]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-28 c:\windows\Tasks\ASC4_AutoCare.job
- c:\program files\IObit\Advanced SystemCare 4\AutoCare.exe [2011-06-10 20:38]
.
2011-11-12 c:\windows\Tasks\ASC4_AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 4\AutoSweep.exe [2011-06-10 20:38]
.
2011-11-10 c:\windows\Tasks\ASC4_AutoUpdate.job
- c:\program files\IObit\Advanced SystemCare 4\AutoUpdate.exe [2011-06-10 21:39]
.
2011-11-12 c:\windows\Tasks\ASC4_PerformanceMonitor.job
- c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe [2011-06-10 20:40]
.
2011-11-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-23 22:28]
.
2011-11-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-23 22:28]
.
2011-11-12 c:\windows\Tasks\PandaUSBVaccine.job
- c:\program files\Panda USB Vaccine\RunInteractiveWin.exe [2011-04-19 20:45]
.
2011-11-12 c:\windows\Tasks\SmartDefrag_Startup.job
- c:\program files\IObit\Smart Defrag 2\SmartDefrag.exe [2011-06-10 21:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride =
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\documents and settings\George\Application Data\Mozilla\Firefox\Profiles\df87ekpm.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-11 22:57
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1436)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2011-11-11 23:01:07
ComboFix-quarantined-files.txt 2011-11-12 04:01
ComboFix2.txt 2011-11-11 00:28
ComboFix3.txt 2011-11-10 23:54
.
Pre-Run: 61,714,706,432 bytes free
Post-Run: 61,698,220,032 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(3)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - B1D82B33BE8039026404E24B110D74A4


Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8144

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 7.0.5730.13

11/11/2011 11:10:43 PM
mbam-log-2011-11-11 (23-10-42).txt

Scan type: Quick scan
Objects scanned: 183108
Time elapsed: 2 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


ESETSCAN Log from 11-11-11:

C:\Documents and Settings\Kelly\Desktop\Unused Desktop Shortcuts\ultrasurf.zip a variant of Win32/UltraReach.AB application
C:\Documents and Settings\Kelly\My Documents\Downloads\registrybooster.exe Win32/RegistryBooster application
C:\Documents and Settings\Kelly\My Documents\FrostWire\Saved\ne rentre pas chez toi ce soir.wma probably a variant of Win32/Agent.GLICIDR trojan
C:\Documents and Settings\Kelly\My Documents\FrostWire\Saved\zac brown bag.wma probably a variant of Win32/Agent.CDRFCTY trojan
Hi

Please run the following (safe mode if normal mode wont work)


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)



NEXT



  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Log files for TDSSKiller and aswMBR pasted DAT file compressed and attached 18:51:00.0093 1792 TDSS rootkit removing tool [removed] Nov 11 2011 15:47:15 18:51:00.0296 1792 ============================================================ 18:51:00.0296 1792 Current date / time: 2011/11/12 18:51:00.0296 18:51:00.0296 1792 SystemInfo: 18:51:00.0296 1792 18:51:00.0296 1792 OS Version: 5.1.2600 ServicePack: 3.0 18:51:00.0296 1792 Product type: Workstation 18:51:00.0296 1792 ComputerName: KELLY-LAPTOP 18:51:00.0296 1792 UserName: George 18:51:00.0296 1792 Windows directory: C:\WINDOWS 18:51:00.0296 1792 System windows directory: C:\WINDOWS 18:51:00.0296 1792 Processor architecture: Intel x86 18:51:00.0296 1792 Number of processors: 2 18:51:00.0296 1792 Page size: 0x1000 18:51:00.0296 1792 Boot type: Safe boot with network 18:51:00.0296 1792 ============================================================ 18:51:00.0765 1792 Initialize success 18:51:03.0468 1064 ============================================================ 18:51:03.0468 1064 Scan started 18:51:03.0484 1064 Mode: Manual; 18:51:03.0484 1064 ============================================================ 18:51:04.0437 1064 Scan interrupted by user! 18:51:04.0437 1064 Scan interrupted by user! 18:51:04.0437 1064 Scan interrupted by user! 18:51:04.0437 1064 ============================================================ 18:51:04.0437 1064 Scan finished 18:51:04.0437 1064 ============================================================ 18:51:04.0531 1892 Detected object count: 0 18:51:04.0531 1892 Actual detected object count: 0 18:51:07.0125 2032 ============================================================ 18:51:07.0125 2032 Scan started 18:51:07.0125 2032 Mode: Manual; 18:51:07.0125 2032 ============================================================ 18:51:08.0328 2032 Abiosdsk - ok 18:51:08.0437 2032 abp480n5 - ok 18:51:08.0546 2032 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 18:51:08.0546 2032 ACPI - ok 18:51:08.0609 2032 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 18:51:08.0609 2032 ACPIEC - ok 18:51:08.0671 2032 adpu160m - ok 18:51:08.0828 2032 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 18:51:08.0828 2032 aec - ok 18:51:08.0906 2032 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 18:51:08.0906 2032 AFD - ok 18:51:08.0968 2032 Aha154x - ok 18:51:09.0046 2032 aic78u2 - ok 18:51:09.0125 2032 aic78xx - ok 18:51:09.0281 2032 AliIde - ok 18:51:09.0359 2032 amsint - ok 18:51:09.0515 2032 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 18:51:09.0515 2032 Arp1394 - ok 18:51:09.0562 2032 asc - ok 18:51:09.0640 2032 asc3350p - ok 18:51:09.0734 2032 asc3550 - ok 18:51:09.0953 2032 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 18:51:09.0953 2032 AsyncMac - ok 18:51:10.0015 2032 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 18:51:10.0015 2032 atapi - ok 18:51:10.0093 2032 Atdisk - ok 18:51:10.0187 2032 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 18:51:10.0187 2032 Atmarpc - ok 18:51:10.0312 2032 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 18:51:10.0328 2032 audstub - ok 18:51:10.0406 2032 b57w2k (74a65415dfaad20f06e7550fa9b6e012) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 18:51:10.0406 2032 b57w2k - ok 18:51:10.0562 2032 BCM43XX (e9ea635b8432d68f0005b3f6cebab837) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys 18:51:10.0593 2032 BCM43XX - ok 18:51:10.0687 2032 BCMWLNPF (8c31c9db77ed6143ad09dc5fd2c9d9cc) C:\WINDOWS\system32\drivers\bcmwlnpf.sys 18:51:10.0687 2032 BCMWLNPF - ok 18:51:10.0765 2032 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 18:51:10.0765 2032 Beep - ok 18:51:10.0953 2032 btaudio (8893ae0b6b9b60e0521a60e8b2160216) C:\WINDOWS\system32\drivers\btaudio.sys 18:51:10.0953 2032 btaudio - ok 18:51:11.0062 2032 BTDriver (fde318e3569f57264af74b7e431f60ae) C:\WINDOWS\system32\DRIVERS\btport.sys 18:51:11.0062 2032 BTDriver - ok 18:51:11.0171 2032 BTKRNL (9c3c8b9e2eda516eb44b51dab81dbd68) C:\WINDOWS\system32\DRIVERS\btkrnl.sys 18:51:11.0187 2032 BTKRNL - ok 18:51:11.0250 2032 BTSERIAL (089f7526ff41c17b0a43896d0553d5a2) C:\WINDOWS\system32\drivers\btserial.sys 18:51:11.0250 2032 BTSERIAL - ok 18:51:11.0359 2032 BTWDNDIS (28531ab3183f498e58d93d585e6a6b70) C:\WINDOWS\system32\DRIVERS\btwdndis.sys 18:51:11.0359 2032 BTWDNDIS - ok 18:51:11.0437 2032 btwhid (c5c0e21c67089f053b964e0a8b8adbac) C:\WINDOWS\system32\DRIVERS\btwhid.sys 18:51:11.0437 2032 btwhid - ok 18:51:11.0515 2032 btwmodem (7d295223c172ab4d61dc256721b2f09e) C:\WINDOWS\system32\DRIVERS\btwmodem.sys 18:51:11.0515 2032 btwmodem - ok 18:51:11.0609 2032 BTWUSB (56c701580f2891952761362ba7594b3d) C:\WINDOWS\system32\Drivers\btwusb.sys 18:51:11.0625 2032 BTWUSB - ok 18:51:11.0796 2032 catchme - ok 18:51:11.0890 2032 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 18:51:11.0890 2032 cbidf2k - ok 18:51:11.0968 2032 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 18:51:11.0968 2032 CCDECODE - ok 18:51:12.0046 2032 cd20xrnt - ok 18:51:12.0140 2032 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 18:51:12.0140 2032 Cdaudio - ok 18:51:12.0218 2032 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 18:51:12.0218 2032 Cdfs - ok 18:51:12.0296 2032 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 18:51:12.0296 2032 Cdrom - ok 18:51:12.0390 2032 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys 18:51:12.0390 2032 cercsr6 - ok 18:51:12.0453 2032 Changer - ok 18:51:12.0656 2032 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 18:51:12.0656 2032 CmBatt - ok 18:51:12.0734 2032 CmdIde - ok 18:51:12.0859 2032 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 18:51:12.0859 2032 Compbatt - ok 18:51:13.0062 2032 Cpqarray - ok 18:51:13.0187 2032 dac2w2k - ok 18:51:13.0265 2032 dac960nt - ok 18:51:13.0421 2032 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 18:51:13.0421 2032 Disk - ok 18:51:13.0500 2032 DLABMFSM (a0500678a33802d8954153839301d539) C:\WINDOWS\system32\Drivers\DLABMFSM.SYS 18:51:13.0515 2032 DLABMFSM - ok 18:51:13.0593 2032 DLABOIOM (b8d2f68cac54d46281399f9092644794) C:\WINDOWS\system32\Drivers\DLABOIOM.SYS 18:51:13.0593 2032 DLABOIOM - ok 18:51:13.0671 2032 DLACDBHM (0ee93ab799d1cb4ec90b36f3612fe907) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS 18:51:13.0671 2032 DLACDBHM - ok 18:51:13.0750 2032 DLADResM (87413b94ae1fabc117c4e8ae6725134e) C:\WINDOWS\system32\Drivers\DLADResM.SYS 18:51:13.0750 2032 DLADResM - ok 18:51:13.0843 2032 DLAIFS_M (766a148235be1c0039c974446e4c0edc) C:\WINDOWS\system32\Drivers\DLAIFS_M.SYS 18:51:13.0843 2032 DLAIFS_M - ok 18:51:13.0921 2032 DLAOPIOM (38267cca177354f1c64450a43a4f7627) C:\WINDOWS\system32\Drivers\DLAOPIOM.SYS 18:51:13.0921 2032 DLAOPIOM - ok 18:51:14.0000 2032 DLAPoolM (fd363369fd313b46b5aeab1a688b52e9) C:\WINDOWS\system32\Drivers\DLAPoolM.SYS 18:51:14.0000 2032 DLAPoolM - ok 18:51:14.0078 2032 DLARTL_M (336ae18f0912ef4fbe5518849e004d74) C:\WINDOWS\system32\Drivers\DLARTL_M.SYS 18:51:14.0078 2032 DLARTL_M - ok 18:51:14.0187 2032 DLAUDFAM (fd85f682c1cc2a7ca878c7a448e6d87e) C:\WINDOWS\system32\Drivers\DLAUDFAM.SYS 18:51:14.0187 2032 DLAUDFAM - ok 18:51:14.0250 2032 DLAUDF_M (af389ce587b6bf5bbdcd6f6abe5eabc0) C:\WINDOWS\system32\Drivers\DLAUDF_M.SYS 18:51:14.0250 2032 DLAUDF_M - ok 18:51:14.0406 2032 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 18:51:14.0421 2032 dmboot - ok 18:51:14.0468 2032 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 18:51:14.0468 2032 dmio - ok 18:51:14.0546 2032 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 18:51:14.0546 2032 dmload - ok 18:51:14.0687 2032 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 18:51:14.0687 2032 DMusic - ok 18:51:14.0828 2032 dpti2o - ok 18:51:14.0906 2032 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 18:51:14.0906 2032 drmkaud - ok 18:51:15.0000 2032 DRVMCDB (5d3b71bb2bb0009d65d290e2ef374bd3) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS 18:51:15.0000 2032 DRVMCDB - ok 18:51:15.0078 2032 DRVNDDM (c591ba9f96f40a1fd6494dafdcd17185) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS 18:51:15.0078 2032 DRVNDDM - ok 18:51:15.0343 2032 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 18:51:15.0343 2032 Fastfat - ok 18:51:15.0453 2032 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 18:51:15.0453 2032 Fdc - ok 18:51:15.0531 2032 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 18:51:15.0531 2032 Fips - ok 18:51:15.0609 2032 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 18:51:15.0609 2032 Flpydisk - ok 18:51:15.0687 2032 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 18:51:15.0687 2032 FltMgr - ok 18:51:15.0812 2032 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 18:51:15.0812 2032 Fs_Rec - ok 18:51:15.0890 2032 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 18:51:15.0906 2032 Ftdisk - ok 18:51:15.0968 2032 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 18:51:15.0968 2032 Gpc - ok 18:51:16.0187 2032 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 18:51:16.0187 2032 HDAudBus - ok 18:51:16.0343 2032 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 18:51:16.0343 2032 hidusb - ok 18:51:16.0453 2032 hpn - ok 18:51:16.0562 2032 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 18:51:16.0578 2032 HTTP - ok 18:51:16.0656 2032 i2omgmt - ok 18:51:16.0734 2032 i2omp - ok 18:51:16.0828 2032 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 18:51:16.0843 2032 i8042prt - ok 18:51:16.0906 2032 iastor (2358c53f30cb9dcd1d3843c4e2f299b2) C:\WINDOWS\system32\DRIVERS\iaStor.sys 18:51:16.0921 2032 iastor - ok 18:51:17.0062 2032 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 18:51:17.0062 2032 Imapi - ok 18:51:17.0265 2032 ini910u - ok 18:51:17.0390 2032 IntelIde - ok 18:51:17.0468 2032 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 18:51:17.0468 2032 intelppm - ok 18:51:17.0562 2032 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 18:51:17.0562 2032 Ip6Fw - ok 18:51:17.0640 2032 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 18:51:17.0640 2032 IpFilterDriver - ok 18:51:17.0718 2032 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 18:51:17.0718 2032 IpInIp - ok 18:51:17.0812 2032 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 18:51:17.0828 2032 IpNat - ok 18:51:17.0875 2032 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 18:51:17.0890 2032 IPSec - ok 18:51:17.0968 2032 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 18:51:17.0968 2032 IRENUM - ok 18:51:18.0093 2032 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 18:51:18.0093 2032 isapnp - ok 18:51:18.0171 2032 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 18:51:18.0171 2032 Kbdclass - ok 18:51:18.0234 2032 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 18:51:18.0250 2032 kbdhid - ok 18:51:18.0343 2032 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 18:51:18.0343 2032 kmixer - ok 18:51:18.0406 2032 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 18:51:18.0406 2032 KSecDD - ok 18:51:18.0562 2032 lbrtfdc - ok 18:51:18.0812 2032 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 18:51:18.0812 2032 mnmdd - ok 18:51:18.0937 2032 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 18:51:18.0953 2032 Modem - ok 18:51:19.0015 2032 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 18:51:19.0015 2032 Mouclass - ok 18:51:19.0093 2032 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 18:51:19.0093 2032 mouhid - ok 18:51:19.0171 2032 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 18:51:19.0171 2032 MountMgr - ok 18:51:19.0250 2032 mraid35x - ok 18:51:19.0359 2032 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 18:51:19.0359 2032 MRxDAV - ok 18:51:19.0453 2032 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 18:51:19.0468 2032 MRxSmb - ok 18:51:19.0625 2032 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 18:51:19.0625 2032 Msfs - ok 18:51:19.0750 2032 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 18:51:19.0765 2032 MSKSSRV - ok 18:51:19.0843 2032 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 18:51:19.0843 2032 MSPCLOCK - ok 18:51:19.0921 2032 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 18:51:19.0921 2032 MSPQM - ok 18:51:20.0031 2032 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 18:51:20.0031 2032 mssmbios - ok 18:51:20.0093 2032 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 18:51:20.0109 2032 MSTEE - ok 18:51:20.0203 2032 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 18:51:20.0203 2032 Mup - ok 18:51:20.0296 2032 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 18:51:20.0296 2032 NABTSFEC - ok 18:51:20.0406 2032 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 18:51:20.0406 2032 NDIS - ok 18:51:20.0500 2032 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 18:51:20.0500 2032 NdisIP - ok 18:51:20.0578 2032 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 18:51:20.0578 2032 NdisTapi - ok 18:51:20.0656 2032 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 18:51:20.0656 2032 Ndisuio - ok 18:51:20.0734 2032 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 18:51:20.0734 2032 NdisWan - ok 18:51:20.0828 2032 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 18:51:20.0828 2032 NDProxy - ok 18:51:20.0890 2032 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 18:51:20.0890 2032 NetBIOS - ok 18:51:20.0984 2032 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 18:51:20.0984 2032 NetBT - ok 18:51:21.0265 2032 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 18:51:21.0265 2032 NIC1394 - ok 18:51:21.0421 2032 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 18:51:21.0421 2032 Npfs - ok 18:51:21.0546 2032 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 18:51:21.0562 2032 Ntfs - ok 18:51:21.0687 2032 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 18:51:21.0687 2032 Null - ok 18:51:22.0078 2032 nv (0390b9368ea20dfb9e416a520b28a555) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 18:51:22.0203 2032 nv - ok 18:51:22.0328 2032 NWADI (9edf6fd48a9eb4afdf225eb9c5111df6) C:\WINDOWS\system32\DRIVERS\NWADIenum.sys 18:51:22.0328 2032 NWADI - ok 18:51:22.0437 2032 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 18:51:22.0437 2032 NwlnkFlt - ok 18:51:22.0500 2032 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 18:51:22.0500 2032 NwlnkFwd - ok 18:51:22.0656 2032 OADevice (700c3d5b0b1b8177a9d35ca572ffa080) C:\WINDOWS\system32\drivers\OADriver.sys 18:51:22.0656 2032 OADevice - ok 18:51:22.0703 2032 OAmon (468c8c804af770af9695c5d633c47807) C:\WINDOWS\system32\drivers\OAmon.sys 18:51:22.0703 2032 OAmon - ok 18:51:22.0796 2032 OAnet (58a8213a187fd9063a5cc29c4af388af) C:\WINDOWS\system32\drivers\OAnet.sys 18:51:22.0796 2032 OAnet - ok 18:51:22.0890 2032 OEM02Afx (58f478fd0115012ceec75fb73628901c) C:\WINDOWS\system32\Drivers\OEM02Afx.sys 18:51:22.0890 2032 OEM02Afx - ok 18:51:22.0984 2032 OEM02Dev (19cac780b858822055f46c58a111723c) C:\WINDOWS\system32\DRIVERS\OEM02Dev.sys 18:51:22.0984 2032 OEM02Dev - ok 18:51:23.0031 2032 OEM02Vfx (86326062a90494bdd79ce383511d7d69) C:\WINDOWS\system32\DRIVERS\OEM02Vfx.sys 18:51:23.0031 2032 OEM02Vfx - ok 18:51:23.0125 2032 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 18:51:23.0125 2032 ohci1394 - ok 18:51:23.0296 2032 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 18:51:23.0296 2032 Parport - ok 18:51:23.0359 2032 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 18:51:23.0359 2032 PartMgr - ok 18:51:23.0453 2032 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 18:51:23.0453 2032 ParVdm - ok 18:51:23.0531 2032 PCASp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\WINDOWS\system32\Drivers\PCASp50.sys 18:51:23.0531 2032 PCASp50 - ok 18:51:23.0593 2032 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 18:51:23.0609 2032 PCI - ok 18:51:23.0671 2032 PCIDump - ok 18:51:23.0765 2032 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 18:51:23.0765 2032 PCIIde - ok 18:51:23.0859 2032 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 18:51:23.0859 2032 Pcmcia - ok 18:51:23.0937 2032 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys 18:51:23.0937 2032 pcouffin - ok 18:51:24.0000 2032 PDCOMP - ok 18:51:24.0078 2032 PDFRAME - ok 18:51:24.0171 2032 PDRELI - ok 18:51:24.0250 2032 PDRFRAME - ok 18:51:24.0328 2032 perc2 - ok 18:51:24.0406 2032 perc2hib - ok 18:51:24.0765 2032 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 18:51:24.0765 2032 PptpMiniport - ok 18:51:24.0859 2032 PSeries (cbb7b01bf346837ab919e2744b742bef) C:\WINDOWS\system32\drivers\PSeries.sys 18:51:24.0859 2032 PSeries - ok 18:51:24.0937 2032 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 18:51:24.0937 2032 Ptilink - ok 18:51:25.0015 2032 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 18:51:25.0015 2032 PxHelp20 - ok 18:51:25.0093 2032 ql1080 - ok 18:51:25.0171 2032 Ql10wnt - ok 18:51:25.0250 2032 ql12160 - ok 18:51:25.0343 2032 ql1240 - ok 18:51:25.0421 2032 ql1280 - ok 18:51:25.0515 2032 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 18:51:25.0515 2032 RasAcd - ok 18:51:25.0625 2032 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 18:51:25.0640 2032 Rasl2tp - ok 18:51:25.0750 2032 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 18:51:25.0750 2032 RasPppoe - ok 18:51:25.0828 2032 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 18:51:25.0828 2032 Raspti - ok 18:51:25.0921 2032 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 18:51:25.0921 2032 Rdbss - ok 18:51:26.0000 2032 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 18:51:26.0000 2032 RDPCDD - ok 18:51:26.0109 2032 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 18:51:26.0125 2032 rdpdr - ok 18:51:26.0250 2032 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 18:51:26.0250 2032 RDPWD - ok 18:51:26.0375 2032 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 18:51:26.0375 2032 redbook - ok 18:51:26.0531 2032 rimmptsk (d85e3fa9f5b1f29bb4ed185c450d1470) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys 18:51:26.0531 2032 rimmptsk - ok 18:51:26.0593 2032 rimsptsk (db8eb01c58c9fada00c70b1775278ae0) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys 18:51:26.0593 2032 rimsptsk - ok 18:51:26.0671 2032 rismxdp (6c1f93c0760c9f79a1869d07233df39d) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys 18:51:26.0687 2032 rismxdp - ok 18:51:27.0093 2032 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys 18:51:27.0109 2032 sdbus - ok 18:51:27.0171 2032 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 18:51:27.0171 2032 Secdrv - ok 18:51:27.0343 2032 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 18:51:27.0343 2032 Serial - ok 18:51:27.0531 2032 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys 18:51:27.0531 2032 sffdisk - ok 18:51:27.0625 2032 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys 18:51:27.0625 2032 sffp_sd - ok 18:51:27.0703 2032 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 18:51:27.0703 2032 Sfloppy - ok 18:51:27.0843 2032 Simbad - ok 18:51:27.0937 2032 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 18:51:27.0953 2032 SLIP - ok 18:51:28.0062 2032 SmartDefragDriver (972dea0d8149d73c5b7a2c97b2e749e3) C:\WINDOWS\system32\Drivers\SmartDefragDriver.sys 18:51:28.0062 2032 SmartDefragDriver - ok 18:51:28.0203 2032 Sparrow - ok 18:51:28.0281 2032 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 18:51:28.0296 2032 splitter - ok 18:51:28.0453 2032 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 18:51:28.0453 2032 sr - ok 18:51:28.0578 2032 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 18:51:28.0593 2032 Srv - ok 18:51:28.0796 2032 STHDA (951801dfb54d86f611f0af47825476f9) C:\WINDOWS\system32\drivers\sthda.sys 18:51:28.0828 2032 STHDA - ok 18:51:28.0968 2032 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 18:51:28.0984 2032 streamip - ok 18:51:29.0093 2032 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 18:51:29.0093 2032 swenum - ok 18:51:29.0171 2032 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 18:51:29.0171 2032 swmidi - ok 18:51:29.0312 2032 symc810 - ok 18:51:29.0390 2032 symc8xx - ok 18:51:29.0468 2032 sym_hi - ok 18:51:29.0562 2032 sym_u3 - ok 18:51:29.0640 2032 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 18:51:29.0640 2032 sysaudio - ok 18:51:29.0828 2032 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 18:51:29.0843 2032 Tcpip - ok 18:51:29.0937 2032 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 18:51:29.0937 2032 TDPIPE - ok 18:51:30.0015 2032 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 18:51:30.0015 2032 TDTCP - ok 18:51:30.0109 2032 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 18:51:30.0109 2032 TermDD - ok 18:51:30.0281 2032 TosIde - ok 18:51:30.0453 2032 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 18:51:30.0468 2032 Udfs - ok 18:51:30.0531 2032 ultra - ok 18:51:30.0625 2032 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 18:51:30.0625 2032 Update - ok 18:51:30.0812 2032 USBAAPL - ok 18:51:30.0906 2032 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 18:51:30.0906 2032 usbccgp - ok 18:51:31.0000 2032 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 18:51:31.0000 2032 usbehci - ok 18:51:31.0062 2032 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 18:51:31.0078 2032 usbhub - ok 18:51:31.0156 2032 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 18:51:31.0156 2032 usbprint - ok 18:51:31.0234 2032 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 18:51:31.0234 2032 usbscan - ok 18:51:31.0328 2032 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 18:51:31.0328 2032 USBSTOR - ok 18:51:31.0390 2032 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 18:51:31.0406 2032 usbuhci - ok 18:51:31.0484 2032 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 18:51:31.0484 2032 usbvideo - ok 18:51:31.0562 2032 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 18:51:31.0562 2032 VgaSave - ok 18:51:31.0625 2032 ViaIde - ok 18:51:31.0718 2032 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 18:51:31.0718 2032 VolSnap - ok 18:51:31.0906 2032 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 18:51:31.0921 2032 Wanarp - ok 18:51:31.0984 2032 WDICA - ok 18:51:32.0093 2032 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 18:51:32.0093 2032 wdmaud - ok 18:51:32.0578 2032 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 18:51:32.0578 2032 WmiAcpi - ok 18:51:32.0859 2032 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 18:51:32.0859 2032 WSTCODEC - ok 18:51:32.0968 2032 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 18:51:32.0984 2032 WudfPf - ok 18:51:33.0046 2032 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 18:51:33.0046 2032 WudfRd - ok 18:51:33.0453 2032 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 18:51:33.0640 2032 \Device\Harddisk0\DR0 - ok 18:51:33.0703 2032 Boot (0x1200) (dc40fe1d204908040f99eccf9736ff12) \Device\Harddisk0\DR0\Partition0 18:51:33.0703 2032 \Device\Harddisk0\DR0\Partition0 - ok 18:51:33.0765 2032 Boot (0x1200) (8ccd191a81f0e40295a4b77e11248479) \Device\Harddisk0\DR0\Partition1 18:51:33.0765 2032 \Device\Harddisk0\DR0\Partition1 - ok 18:51:33.0796 2032 ============================================================ 18:51:33.0796 2032 Scan finished 18:51:33.0796 2032 ============================================================ 18:51:33.0937 1904 Detected object count: 0 18:51:33.0937 1904 Actual detected object count: 0 18:52:00.0781 0496 Deinitialize success aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-12 19:02:01 —————————– 19:02:01.765 OS Version: Windows 5.1.2600 Service Pack 3 19:02:01.765 Number of processors: 2 586 0xF0D 19:02:01.765 ComputerName: KELLY-LAPTOP UserName: George 19:02:02.218 Initialize success 19:02:21.796 AVAST engine defs: 11111201 19:07:43.156 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 19:07:43.203 Disk 0 Vendor: WDC_WD12 01.0 Size: 114473MB BusType: 3 19:07:43.281 Disk 0 MBR read successfully 19:07:43.328 Disk 0 MBR scan 19:07:43.437 Disk 0 Windows XP default MBR code 19:07:43.484 Disk 0 scanning sectors +234438656 19:07:43.640 Disk 0 scanning C:\WINDOWS\system32\drivers 19:08:00.562 Service scanning 19:08:04.968 Modules scanning 19:08:11.000 Disk 0 trace - called modules: 19:08:11.140 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 19:08:11.203 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8acf62e0] 19:08:11.265 3 CLASSPNP.SYS[f7657fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8a6bb030] 19:08:11.796 AVAST engine scan C:\WINDOWS 19:08:22.828 AVAST engine scan C:\WINDOWS\system32 19:11:29.890 AVAST engine scan C:\WINDOWS\system32\drivers 19:11:54.468 AVAST engine scan C:\Documents and Settings\George 20:03:54.234 AVAST engine scan C:\Documents and Settings\All Users 20:09:49.734 Scan finished successfully 20:11:20.437 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\George\Desktop\MBR.dat" 20:11:20.515 The log file has been saved successfully to "C:\Documents and Settings\George\Desktop\aswMBR.txt"

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI