Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93085 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Something Is Not Right! [Closed]


  • This topic is locked This topic is locked
53 replies to this topic

#1 Lewg

Lewg

    Silver Member

  • Authentic Member
  • PipPipPip
  • 393 posts

Posted 22 February 2012 - 08:14 AM

Trying to run HJT and save the log file takes 4 to 5 minutes to complete.I have never had this problem before. It normally would take seconds to complete.
Something is just not quite right here. Recently ran TFC by Oldtimer, the ATF cleaner, SuperANTIspyware, and the Malwarebytes scan. No infections were found.
I appreciate someone looking over the recent log file for me.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:27:49 PM, on 02/21/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\arservice.exe
C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\mswinext.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: AutorunsDisabled
O4 - Startup: WKCALREM.LNK.disabled
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Garmin Communicator Plug-In - https://static.garmi...inAxControl.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.co...sreqlab_nvd.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2....re/HPDEXAXO.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset...lineScanner.cab
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} -
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} -
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} -
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.m...ash/swflash.cab
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: CLDTVHNService - Unknown owner - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c9316637dc9d00) (gupdate1c9316637dc9d00) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: User Profile Hive Cleanup (UPHClean) - Windows ® Codename Longhorn DDK provider - C:\Program Files\UPHClean\uphclean.exe

--
End of file - 8683 bytes

    Advertisements

Register to Remove


#2 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 22 February 2012 - 10:32 AM

Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
----------

Please download DDS from one of the following links and save it to your desktop.
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
---------------------------------------------------
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
----------

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

Posted Image
Click the image to enlarge it
----------

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
Posted Image
 
 

#3 Lewg

Lewg

    Silver Member

  • Authentic Member
  • PipPipPip
  • 393 posts

Posted 22 February 2012 - 07:21 PM

.aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software Run date: 2012-02-22 20:16:51 ----------------------------- 20:16:51.265 OS Version: Windows 5.1.2600 Service Pack 3 20:16:51.265 Number of processors: 1 586 0x2F02 20:16:51.265 ComputerName: COMPAQ-PRESARIO UserName: 20:16:51.921 Initialize success 20:18:47.921 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-c 20:18:47.921 Disk 0 Vendor: Maxtor_6L100P0 BAH41G10 Size: 95611MB BusType: 3 20:18:47.921 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17 20:18:47.921 Disk 1 Vendor: WDC_WD2500JS-60NCB1 10.02E02 Size: 238475MB BusType: 3 20:18:47.953 Disk 1 MBR read successfully 20:18:47.953 Disk 1 MBR scan 20:18:47.953 Disk 1 unknown MBR code 20:18:47.953 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 230071 MB offset 63 20:18:47.984 Disk 1 Partition 2 00 0C FAT32 LBA RECOVERY 8393 MB offset 471202515 20:18:48.000 Disk 1 scanning sectors +488392065 20:18:48.031 Disk 1 scanning C:\WINDOWS\system32\drivers 20:18:58.421 Service scanning 20:19:06.843 Service MpKsl29a60357 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{335BE3CD-6179-4E6C-9D5F-F6B1BA5E7002}\MpKsl29a60357.sys **LOCKED** 32 20:19:15.312 Modules scanning 20:19:22.593 Disk 1 trace - called modules: 20:19:22.921 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 20:19:22.921 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x86742ab8] 20:19:22.937 3 CLASSPNP.SYS[f7690fd7] -> nt!IofCallDriver -> \Device\00000075[0x866f69e8] 20:19:22.937 5 ACPI.sys[f7507620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-17[0x866f5d98] 20:19:22.937 Scan finished successfully 20:20:01.531 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\Compaq_Administrator\Desktop\MBR.dat" 20:20:01.546 The log file has been saved successfully to "C:\Documents and Settings\Compaq_Administrator\Desktop\aswMBR.txt" . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 07/13/2006 10:01:56 PM System Uptime: 02/22/2012 11:45:43 AM (9 hours ago) . Motherboard: ASUSTek Computer INC. | | NAGAMI2 Processor: AMD Athlon™ 64 Processor 3800+ | Socket 939 | 2405/199mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 225 GiB total, 186.946 GiB free. D: is FIXED (FAT32) - 8 GiB total, 0.542 GiB free. E: is CDROM () F: is FIXED (NTFS) - 93 GiB total, 56.019 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E96D-E325-11CE-BFC1-08002BE10318} Description: Agere Systems PCI-SV92PP Soft Modem Device ID: PCI\VEN_11C1&DEV_0620&SUBSYS_062011C1&REV_00\4&DC268A3&0&4880 Manufacturer: Agere Name: Agere Systems PCI-SV92PP Soft Modem PNP Device ID: PCI\VEN_11C1&DEV_0620&SUBSYS_062011C1&REV_00\4&DC268A3&0&4880 Service: Modem . ==== System Restore Points =================== . RP158: 12/31/2011 1:11:35 PM - System Checkpoint RP159: 01/01/2012 1:22:47 PM - System Checkpoint RP160: 01/01/2012 3:25:31 PM - Software Distribution Service 3.0 RP161: 01/02/2012 3:24:23 PM - Software Distribution Service 3.0 RP162: 01/03/2012 10:23:56 AM - Restore Operation RP163: 01/03/2012 10:38:27 AM - Software Distribution Service 3.0 RP164: 01/03/2012 3:26:41 PM - Configured DirecTV RP165: 01/03/2012 3:27:30 PM - Configured DTCPIP Advisor RP166: 01/03/2012 3:32:08 PM - Installed DirecTV RP167: 01/03/2012 4:06:53 PM - Installed DirecTV RP168: 01/03/2012 4:07:13 PM - Installed DTCPIP Advisor RP169: 01/03/2012 4:11:05 PM - Installed DirecTV RP170: 01/03/2012 4:16:01 PM - Installed DirecTV RP171: 01/04/2012 11:48:15 AM - Software Distribution Service 3.0 RP172: 01/05/2012 11:43:40 AM - Software Distribution Service 3.0 RP173: 01/06/2012 11:48:16 AM - System Checkpoint RP174: 01/06/2012 12:50:46 PM - Software Distribution Service 3.0 RP175: 01/07/2012 12:56:08 PM - System Checkpoint RP176: 01/08/2012 12:54:26 AM - Software Distribution Service 3.0 RP177: 01/09/2012 12:49:18 AM - Software Distribution Service 3.0 RP178: 01/10/2012 1:36:25 AM - System Checkpoint RP179: 01/10/2012 1:34:09 PM - Software Distribution Service 3.0 RP180: 01/11/2012 1:29:05 PM - Software Distribution Service 3.0 RP181: 01/11/2012 8:01:09 PM - Software Distribution Service 3.0 RP182: 01/12/2012 8:16:56 PM - System Checkpoint RP183: 01/13/2012 10:19:45 AM - Software Distribution Service 3.0 RP184: 01/14/2012 10:18:45 AM - Software Distribution Service 3.0 RP185: 01/15/2012 2:27:22 AM - Software Distribution Service 3.0 RP186: 01/16/2012 2:38:20 AM - System Checkpoint RP187: 01/16/2012 1:40:28 PM - Software Distribution Service 3.0 RP188: 01/17/2012 1:40:00 PM - Software Distribution Service 3.0 RP189: 01/18/2012 1:41:26 PM - Software Distribution Service 3.0 RP190: 01/19/2012 1:46:28 PM - System Checkpoint RP191: 01/19/2012 2:48:26 PM - Software Distribution Service 3.0 RP192: 01/20/2012 4:27:50 PM - System Checkpoint RP193: 01/21/2012 2:20:54 AM - Software Distribution Service 3.0 RP194: 01/22/2012 1:57:22 AM - Software Distribution Service 3.0 RP195: 01/22/2012 10:34:07 PM - Software Distribution Service 3.0 RP196: 01/23/2012 1:09:54 PM - Software Distribution Service 3.0 RP197: 01/23/2012 10:34:19 PM - Software Distribution Service 3.0 RP198: 01/24/2012 10:34:17 PM - Software Distribution Service 3.0 RP199: 01/27/2012 6:03:31 PM - Software Distribution Service 3.0 RP200: 01/28/2012 5:58:15 PM - Software Distribution Service 3.0 RP201: 01/29/2012 1:49:12 AM - Software Distribution Service 3.0 RP202: 01/29/2012 5:58:50 PM - Software Distribution Service 3.0 RP203: 01/30/2012 6:18:18 PM - System Checkpoint RP204: 01/31/2012 3:00:16 AM - Software Distribution Service 3.0 RP205: 01/31/2012 3:15:11 AM - Software Distribution Service 3.0 RP206: 02/01/2012 3:46:13 AM - System Checkpoint RP207: 02/01/2012 10:06:06 AM - Software Distribution Service 3.0 RP208: 02/02/2012 10:00:39 AM - Software Distribution Service 3.0 RP209: 02/03/2012 12:28:19 PM - System Checkpoint RP210: 02/03/2012 11:59:18 PM - Software Distribution Service 3.0 RP211: 02/04/2012 11:59:11 PM - Software Distribution Service 3.0 RP212: 02/05/2012 2:25:00 AM - Software Distribution Service 3.0 RP213: 02/06/2012 3:03:03 AM - System Checkpoint RP214: 02/06/2012 5:05:01 PM - Software Distribution Service 3.0 RP215: 02/07/2012 6:32:50 PM - System Checkpoint RP216: 02/08/2012 9:56:21 AM - Software Distribution Service 3.0 RP217: 02/09/2012 10:01:56 AM - System Checkpoint RP218: 02/10/2012 8:03:49 AM - Software Distribution Service 3.0 RP219: 02/11/2012 8:03:46 AM - Software Distribution Service 3.0 RP220: 02/12/2012 1:43:35 AM - Software Distribution Service 3.0 RP221: 02/13/2012 2:01:54 AM - System Checkpoint RP222: 02/13/2012 8:03:30 AM - Software Distribution Service 3.0 RP223: 02/14/2012 8:08:18 AM - System Checkpoint RP224: 02/14/2012 8:10:34 PM - Software Distribution Service 3.0 RP225: 02/15/2012 8:48:36 PM - System Checkpoint RP226: 02/16/2012 3:00:16 AM - Software Distribution Service 3.0 RP227: 02/16/2012 7:50:53 AM - Software Distribution Service 3.0 RP228: 02/17/2012 7:50:24 AM - Software Distribution Service 3.0 RP229: 02/18/2012 8:05:12 AM - System Checkpoint RP230: 02/18/2012 1:07:34 PM - Software Distribution Service 3.0 RP231: 02/19/2012 1:45:03 AM - Software Distribution Service 3.0 RP232: 02/19/2012 1:07:15 PM - Software Distribution Service 3.0 RP233: 02/20/2012 2:09:52 PM - Software Distribution Service 3.0 RP234: 02/21/2012 3:02:00 PM - System Checkpoint RP235: 02/22/2012 9:27:48 AM - Software Distribution Service 3.0 RP236: 02/22/2012 11:33:17 AM - Removed Microsoft .NET Framework 1.1 . ==== Installed Programs ====================== . Adobe AIR Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X (10.1.2) Agere Systems PCI-SV92PP Soft Modem Apple Application Support Apple Software Update ATT-RC Self Support Tool Audacity 1.2.6 Autodesk MapGuide® Viewer ActiveX Control Release 6.5 Bing Bar Bing Bar Platform BufferChm CameraDrivers CCleaner (remove only) Chart Navigator Compaq Connections (remove only) Cook'n with Pillsbury Coupon Printer for Windows CreativeProjects CreativeProjectsTemplates CueTour Customer Experience Enhancement Destinations Director DIRECTV2PC Playback Advisor DIRECTV2PC™ DISCover Driver Detective DriverAgent by eSupport.com Enhanced Multimedia Keyboard Solution ERUNT 1.1j Extra_POI_Editor_Installer Garmin Communicator Plugin Garmin MapSource Garmin nRoute Garmin POI Loader Garmin Trip and Waypoint Manager v3 Garmin USB Drivers Garmin WebUpdater GdiplusUpgrade Google Desktop Google Earth Google Earth Plug-in Google Update Helper Hampton Hotels eDirectory with MultiView Reader High Definition Audio Driver Package - KB888111 HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Boot Optimizer HP Deskjet 3050 J610 series Basic Device Software HP Deskjet 3050 J610 series Help HP Deskjet 3050 J610 series Product Improvement Study HP Driver Diagnostics HP DVD Play 2.1 HP Image Zone 4.5 HP Photo Creations HP Rhapsody HP Support Overview HP Update HpSdpAppCoreApp HPSystemDiagnostics InstantShare Interactive User’s Guide iTunes Java Auto Updater Java™ 7 Update 1 LightScribe 1.4.84.1 Malwarebytes Anti-Malware version 1.60.1.1000 Microsoft .NET Framework 1.0 Hotfix (KB2572066) Microsoft .NET Framework 1.1 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Antimalware Microsoft Application Error Reporting Microsoft Default Manager Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Search Enhancement Pack Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works Miro Mozilla Firefox 9.0.1 (x86 en-US) MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB973686) NVIDIA Control Panel 285.58 NVIDIA Drivers NVIDIA Graphics Driver 285.58 NVIDIA Install Application NVIDIA nView 135.95 NVIDIA nView Desktop Manager Otto Outlook Express Quick Backup overland PanoStandAlone PartyPoker PC-Doctor 5 for Windows PCFriendly PDFCreator Photodex Presenter PhotoGallery Python 2.2 pywin32 extensions (build 203) Python 2.2.3 QFolder Quicken 2006 Quicken Legal Business Pro 2006 Quicken WillMaker Plus 2006 QuickTime RealPlayer Realtek High Definition Audio Driver Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft Windows (KB2564958) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB2482017) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB2530548) Security Update for Windows Internet Explorer 7 (KB2544521) Security Update for Windows Internet Explorer 7 (KB2559049) Security Update for Windows Internet Explorer 7 (KB2586448) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2647516) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2660465) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) ShareIns SkinsHP1 SpeedFan (remove only) Spell Checker For OE 2.1 Spelling Dictionaries Support For Adobe Reader 8 Spybot - Search & Destroy SpywareBlaster v3.5.1 Super GameHouse Solitaire Vol. 1 SUPERAntiSpyware System Requirements Lab TaxACT 2006 TaxACT 2007 TaxACT 2008 TaxACT 2008 Georgia TaxACT 2009 TaxACT 2009 Georgia TaxACT 2010 TaxACT 2010 Georgia TaxACT 2011 - 1040 Edition TaxACT 2011 Georgia TaxACT Georgia 2006 TaxACT Georgia 2007 TrayApp Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows Internet Explorer 8 (KB2598845) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB953356) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 User Profile Hive Cleanup Service WebFldrs XP WebReg Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) Windows Driver Package - Ross-Tech USB Driver Package (08/16/2011 2.08.14) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format Runtime Windows Media Player Firefox Plugin Windows XP Media Center Edition 2005 KB2502898 Windows XP Media Center Edition 2005 KB2619340 Windows XP Media Center Edition 2005 KB2628259 Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB912067 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 WordWeb World Championship Checkers (Gold Plus) WOT for Internet Explorer . ==== Event Viewer Messages From Past Week ======== . 02/22/2012 9:15:30 AM, error: Service Control Manager [7034] - The User Profile Hive Cleanup service terminated unexpectedly. It has done this 1 time(s). 02/22/2012 9:15:30 AM, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s). 02/22/2012 9:15:30 AM, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s). 02/22/2012 9:15:30 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). 02/22/2012 9:15:30 AM, error: Service Control Manager [7034] - The McciCMService service terminated unexpectedly. It has done this 1 time(s). 02/22/2012 9:15:29 AM, error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s). 02/22/2012 9:15:29 AM, error: Service Control Manager [7034] - The CLDTVHNService service terminated unexpectedly. It has done this 1 time(s). 02/22/2012 9:15:29 AM, error: Service Control Manager [7034] - The ARSVC service terminated unexpectedly. It has done this 1 time(s). 02/22/2012 9:15:29 AM, error: Service Control Manager [7031] - The SAS Core Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. 02/22/2012 9:15:29 AM, error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service. 02/22/2012 11:57:14 AM, error: Service Control Manager [7000] - The SABProcEnum service failed to start due to the following error: The system cannot find the file specified. 02/15/2012 7:45:01 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ftsata2 02/15/2012 7:45:00 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Google Update Service (gupdate1c9316637dc9d00) service to connect. 02/15/2012 7:45:00 AM, error: Service Control Manager [7000] - The Google Update Service (gupdate1c9316637dc9d00) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. . ==== End Of File =========================== DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.1.0 Run by Compaq_Administrator at 20:11:04 on 2012-02-22 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.364 [GMT -5:00] . AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\WINDOWS\arservice.exe C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\UPHClean\uphclean.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Microsoft Security Client\msseces.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\mswinext.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE . ============== Pseudo HJT Report =============== . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uStart Page = hxxp://msn.com/ uInternet Connection Wizard,ShellNext = iexplore BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar3.dll BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\webhelper.dll BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2291.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll TB: @c:\program files\msn toolbar\platform\6.3.2291.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2291.0\npwinext.dll TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\documents and settings\compaq_administrator\start menu\programs\startup\WKCALREM.LNK.disabled StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\autoru~1\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\documents and settings\compaq_administrator\start menu\programs\startup\autorunsdisabled\wkcalrem.lnk.disabled StartupFolder: c:\documents and settings\compaq_administrator\start menu\programs\startup\autorunsdisabled\wordweb.lnk.disabled IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\documents and settings\compaq_administrator\desktop\PartyPoker.lnk IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} - hxxp://www.photodex.com/pxplay.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D} : DhcpNameServer = 16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243 TCP: Interfaces\{A7C78262-8D81-4086-BCD4-535ECA720CFA} : DhcpNameServer = 192.168.2.1 Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\compaq_administrator\application data\mozilla\firefox\profiles\788pfasp.default\ FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\documents and settings\compaq_administrator\application data\mozilla\plugins\npPxPlay.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648] R1 MpKsl29a60357;MpKsl29a60357;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{335be3cd-6179-4e6c-9d5f-f6b1ba5e7002}\MpKsl29a60357.sys [2012-2-22 29904] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608] R2 CLDTVHNService;CLDTVHNService;c:\program files\directv\directv\kernel\dmp\CLDTVHNService.exe [2009-9-17 75048] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 ntk_dtv;ntk_dtv;c:\program files\directv\directv\kernel\dmp\ntk_dtv.sys [2009-9-17 119792] S2 gupdate1c9316637dc9d00;Google Update Service (gupdate1c9316637dc9d00);c:\program files\google\update\GoogleUpdate.exe [2008-10-18 133104] S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2011-12-2 23456] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-8-15 30192] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2008-10-18 133104] S3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\PCD5SRVC.pkms [2006-2-7 21120] . =============== Created Last 30 ================ . 2012-02-22 16:46:33 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{335be3cd-6179-4e6c-9d5f-f6b1ba5e7002}\MpKsl29a60357.sys 2012-02-22 14:27:50 6552120 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{335be3cd-6179-4e6c-9d5f-f6b1ba5e7002}\mpengine.dll 2012-02-22 14:25:28 1409 ----a-w- c:\windows\system32\tmp8EA68.FOT 2012-02-22 14:25:28 1409 ----a-w- c:\windows\system32\tmp63B68.FOT 2012-02-22 14:25:27 1409 ----a-w- c:\windows\system32\tmpC3A68.FOT 2012-02-22 14:25:27 1409 ----a-w- c:\windows\system32\tmpA8A68.FOT 2012-02-22 14:25:27 1409 ----a-w- c:\windows\system32\tmp83868.FOT 2012-02-22 14:25:27 1409 ----a-w- c:\windows\system32\tmp6A868.FOT 2012-02-22 14:25:27 1409 ----a-w- c:\windows\system32\tmp0A968.FOT 2012-02-16 03:13:57 3072 ------w- c:\windows\system32\iacenc.dll 2012-02-16 03:13:57 3072 ------w- c:\windows\system32\dllcache\iacenc.dll . ==================== Find3M ==================== . 2012-01-31 12:44:05 237072 ------w- c:\windows\system32\MpSigStub.exe 2012-01-12 16:53:24 1859968 ----a-w- c:\windows\system32\win32k.sys 2012-01-03 22:07:29 285176 ----a-w- c:\windows\system32\nvdrsdb0.bin 2012-01-03 22:07:29 1 ----a-w- c:\windows\system32\nvdrssel.bin 2012-01-03 22:06:51 285176 ----a-w- c:\windows\system32\nvdrsdb1.bin 2011-12-30 12:39:11 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-12-17 19:46:36 916992 ----a-w- c:\windows\system32\wininet.dll 2011-12-17 19:46:36 43520 ------w- c:\windows\system32\licmgr10.dll 2011-12-17 19:46:36 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-12-17 13:38:58 38400 ----a-w- c:\windows\system32\pcdhdm.cpl 2011-12-16 12:22:58 385024 ------w- c:\windows\system32\html.iec 2011-12-14 13:34:59 1409 ----a-w- c:\windows\system32\tmpE5054.FOT 2011-12-14 13:34:59 1409 ----a-w- c:\windows\system32\tmp1EF44.FOT 2011-12-14 13:34:59 1409 ----a-w- c:\windows\system32\tmp02054.FOT 2011-12-14 13:34:58 1409 ----a-w- c:\windows\system32\tmpADB44.FOT 2011-12-14 13:34:58 1409 ----a-w- c:\windows\system32\tmp55F44.FOT 2011-12-14 13:34:58 1409 ----a-w- c:\windows\system32\tmp39F44.FOT 2011-12-14 13:34:57 1409 ----a-w- c:\windows\system32\tmpD6B44.FOT 2011-12-14 13:18:56 1409 ----a-w- c:\windows\system32\tmpF6BE2.FOT 2011-12-14 13:18:56 1409 ----a-w- c:\windows\system32\tmpEABE2.FOT 2011-12-14 13:18:56 1409 ----a-w- c:\windows\system32\tmpD39E2.FOT 2011-12-14 13:18:56 1409 ----a-w- c:\windows\system32\tmpB89E2.FOT 2011-12-14 13:18:56 1409 ----a-w- c:\windows\system32\tmp65AE2.FOT 2011-12-14 13:18:56 1409 ----a-w- c:\windows\system32\tmp3DAE2.FOT 2011-12-14 13:18:56 1409 ----a-w- c:\windows\system32\tmp12BE2.FOT 2011-12-10 20:24:06 20464 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-12-02 17:36:15 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys 2011-11-25 21:57:19 293376 ----a-w- c:\windows\system32\winsrv.dll . ============= FINISH: 20:12:05.09 ===============

#4 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 23 February 2012 - 09:30 AM

Hi,

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.

Posted Image
 
 

#5 Lewg

Lewg

    Silver Member

  • Authentic Member
  • PipPipPip
  • 393 posts

Posted 23 February 2012 - 09:56 AM

MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000003c Kernel Drivers (total 127): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806D1000 \WINDOWS\system32\hal.dll 0xF7B30000 \WINDOWS\system32\KDCOM.DLL 0xF7A40000 \WINDOWS\system32\BOOTVID.dll 0xF7501000 ACPI.sys 0xF7B32000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF74F0000 pci.sys 0xF7630000 isapnp.sys 0xF7640000 ohci1394.sys 0xF7650000 \WINDOWS\system32\DRIVERS\1394BUS.SYS 0xF7BF8000 pciide.sys 0xF78B0000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7B34000 viaide.sys 0xF7B36000 intelide.sys 0xF7660000 MountMgr.sys 0xF74D1000 ftdisk.sys 0xF7B38000 dmload.sys 0xF74AB000 dmio.sys 0xF78B8000 PartMgr.sys 0xF7670000 VolSnap.sys 0xF73D6000 iaStor.sys 0xF73BE000 atapi.sys 0xF7680000 disk.sys 0xF7690000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF739E000 fltmgr.sys 0xF738C000 sr.sys 0xF76A0000 PxHelp20.sys 0xF7375000 KSecDD.sys 0xF72E8000 Ntfs.sys 0xF72BB000 NDIS.sys 0xF78C0000 speedfan.sys 0xF72A1000 Mup.sys 0xF7BF9000 giveio.sys 0xF76D0000 \SystemRoot\system32\DRIVERS\nic1394.sys 0xF7760000 \SystemRoot\system32\DRIVERS\AmdK8.sys 0xF7A10000 \SystemRoot\system32\DRIVERS\aracpi.sys 0xF63A0000 \SystemRoot\system32\DRIVERS\nv4_mini.sys 0xF638C000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF7A18000 \SystemRoot\system32\DRIVERS\usbohci.sys 0xF6368000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF7A20000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF7770000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF7780000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF7790000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF6345000 \SystemRoot\system32\DRIVERS\ks.sys 0xF7A28000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys 0xF631D000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF6B67000 \SystemRoot\system32\DRIVERS\nvnetbus.sys 0xF62D2000 \SystemRoot\system32\DRIVERS\NVNRM.SYS 0xF629B000 \SystemRoot\system32\DRIVERS\NVSNPU.SYS 0xF77A0000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF7A30000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7B7A000 \SystemRoot\system32\DRIVERS\armoucfltr.sys 0xF7A38000 \SystemRoot\system32\DRIVERS\PS2.sys 0xF7900000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF7B7C000 \SystemRoot\system32\DRIVERS\arkbcfltr.sys 0xF6B63000 \SystemRoot\system32\DRIVERS\arpolicy.sys 0xF7C59000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF77B0000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF6B5F000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF6284000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF77C0000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF77D0000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF7908000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF6273000 \SystemRoot\system32\DRIVERS\psched.sys 0xF77E0000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF7910000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF7918000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF6243000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xF77F0000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7B7E000 \SystemRoot\system32\DRIVERS\serscan.sys 0xF7B80000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF61E5000 \SystemRoot\system32\DRIVERS\update.sys 0xF7ADC000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF7800000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF7810000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7B82000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF7830000 \SystemRoot\system32\DRIVERS\NVENETFD.sys 0xF3768000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xF3744000 \SystemRoot\system32\drivers\portcls.sys 0xF6790000 \SystemRoot\system32\drivers\drmk.sys 0xF3350000 \SystemRoot\system32\DRIVERS\MpFilter.sys 0xF7B9E000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7C2C000 \SystemRoot\System32\Drivers\Null.SYS 0xF7BA0000 \SystemRoot\System32\Drivers\Beep.SYS 0xF79A0000 \SystemRoot\System32\drivers\vga.sys 0xF7BA2000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7BA4000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF79A8000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF79B0000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF61E1000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xF31AD000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xF3154000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xF312C000 \SystemRoot\system32\DRIVERS\netbt.sys 0xF61DD000 \SystemRoot\System32\drivers\ws2ifsl.sys 0xF310A000 \SystemRoot\System32\drivers\afd.sys 0xF6730000 \SystemRoot\system32\DRIVERS\netbios.sys 0xF30E8000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 0xF79B8000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 0xF30BD000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xF3025000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF6710000 \SystemRoot\System32\Drivers\Fips.SYS 0xF2FFF000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF6700000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xF7840000 \SystemRoot\system32\DRIVERS\arp1394.sys 0xF2FDB000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xF76F0000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF3740000 \SystemRoot\System32\drivers\Dxapi.sys 0xF79F8000 \SystemRoot\System32\watchdog.sys 0xBD000000 \SystemRoot\System32\drivers\dxg.sys 0xF7D3C000 \SystemRoot\System32\drivers\dxgthk.sys 0xBD012000 \SystemRoot\System32\nv4_disp.dll 0xBD3D8000 \SystemRoot\System32\ATMFD.DLL 0xB8510000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xB71C3000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xB71AE000 \SystemRoot\system32\drivers\wdmaud.sys 0xB8428000 \SystemRoot\system32\drivers\sysaudio.sys 0xB6E75000 \SystemRoot\System32\Drivers\HTTP.sys 0xB6DF5000 \SystemRoot\system32\DRIVERS\srv.sys 0xF7B48000 \SystemRoot\System32\Drivers\MCSTRM.SYS 0xB6CE9000 \??\C:\Program Files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys 0xB6C15000 \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys 0xF79D8000 \??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\mbr.sys 0xB5DC9000 \??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\aswMBR.sys 0xAC5AE000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 42): 0 System Idle Process 4 System 668 C:\WINDOWS\system32\smss.exe 720 csrss.exe 744 C:\WINDOWS\system32\winlogon.exe 788 C:\WINDOWS\system32\services.exe 800 C:\WINDOWS\system32\lsass.exe 964 C:\WINDOWS\system32\svchost.exe 1016 svchost.exe 1112 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe 1148 C:\WINDOWS\system32\svchost.exe 1236 svchost.exe 1384 svchost.exe 1540 C:\WINDOWS\system32\spoolsv.exe 1920 svchost.exe 2020 C:\Program Files\SUPERAntiSpyware\SASCore.exe 2032 C:\WINDOWS\arservice.exe 204 C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe 236 C:\WINDOWS\ehome\ehrecvr.exe 256 C:\WINDOWS\ehome\ehSched.exe 700 C:\Program Files\Common Files\LightScribe\LSSrvc.exe 764 C:\Program Files\Common Files\Motive\McciCMService.exe 932 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 1204 C:\WINDOWS\system32\nvsvc32.exe 1228 C:\WINDOWS\system32\HPZipm12.exe 1380 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 436 svchost.exe 484 C:\WINDOWS\system32\svchost.exe 692 C:\Program Files\UPHClean\uphclean.exe 1316 mcrdsvc.exe 2752 alg.exe 3016 C:\WINDOWS\system32\dllhost.exe 3320 C:\WINDOWS\explorer.exe 3576 C:\Program Files\Microsoft Security Client\msseces.exe 1812 C:\hp\KBD\kbd.exe 2112 C:\WINDOWS\system32\rundll32.exe 3532 C:\Program Files\Internet Explorer\iexplore.exe 1652 C:\Program Files\Internet Explorer\iexplore.exe 3984 C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe 1724 C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\mswinext.exe 352 C:\Program Files\Internet Explorer\iexplore.exe 2396 C:\Documents and Settings\Compaq_Administrator\Desktop\MBRCheck.exe \\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS) \\.\D: --> \\.\PhysicalDrive1 at offset 0x00000038`2bf5a600 (FAT32) \\.\F: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive1 Model Number: WDCWD2500JS-60NCB1, Rev: 10.02E02 PhysicalDrive0 Model Number: Maxtor6L100P0, Rev: BAH41G10 Size Device Name MBR Status -------------------------------------------- 232 GB \\.\PhysicalDrive1 Unknown MBR code SHA1: 4A3BF69CA3259413E25A52D6E01242850E3B0E3A 93 GB \\.\PhysicalDrive0 Legit MBR code detected SHA1: 317A49A9E93F077F2D004734D2A7B6CA7E7B9495 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!

#6 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 23 February 2012 - 10:19 AM

Hi,

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
----------
Posted Image
 
 

#7 Lewg

Lewg

    Silver Member

  • Authentic Member
  • PipPipPip
  • 393 posts

Posted 23 February 2012 - 11:14 AM

ComboFix 12-02-22.01 - Compaq_Administrator 02/23/2012 11:56:03.6.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.389 [GMT -5:00]
Running from: c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\{479F8C12-576B-4A58-AB78-4B70F7012AA8}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{516A7A9D-5659-4DF1-ADCA-3AB2770664F6}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{E9B10AA5-E5F6-4DEF-A435-FB20704AF1E8}\PostBuild.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-01-23 to 2012-02-23 )))))))))))))))))))))))))))))))
.
.
2012-02-23 16:52 . 2012-02-08 06:03 6552120 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1E2CE53D-2253-48CC-B07A-C15B2E7202A6}\mpengine.dll
2012-02-22 14:25 . 2012-02-22 14:25 1409 ----a-w- c:\windows\system32\tmp8EA68.FOT
2012-02-22 14:25 . 2012-02-22 14:25 1409 ----a-w- c:\windows\system32\tmp63B68.FOT
2012-02-22 14:25 . 2012-02-22 14:25 1409 ----a-w- c:\windows\system32\tmpC3A68.FOT
2012-02-22 14:25 . 2012-02-22 14:25 1409 ----a-w- c:\windows\system32\tmpA8A68.FOT
2012-02-22 14:25 . 2012-02-22 14:25 1409 ----a-w- c:\windows\system32\tmp83868.FOT
2012-02-22 14:25 . 2012-02-22 14:25 1409 ----a-w- c:\windows\system32\tmp6A868.FOT
2012-02-22 14:25 . 2012-02-22 14:25 1409 ----a-w- c:\windows\system32\tmp0A968.FOT
2012-02-16 03:13 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-16 03:13 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\dllcache\iacenc.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-08 06:03 . 2011-07-16 14:34 6552120 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-31 12:44 . 2011-03-08 21:25 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-12 16:53 . 2004-08-09 21:00 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-30 12:39 . 2011-07-09 13:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-17 19:46 . 2004-08-09 21:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2004-08-09 21:00 43520 ------w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2004-08-09 21:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-12-17 13:38 . 2008-01-03 02:08 38400 ----a-w- c:\windows\system32\pcdhdm.cpl
2011-12-16 12:22 . 2004-08-09 21:00 385024 ------w- c:\windows\system32\html.iec
2011-12-14 13:34 . 2011-12-14 13:34 1409 ----a-w- c:\windows\system32\tmpE5054.FOT
2011-12-14 13:34 . 2011-12-14 13:34 1409 ----a-w- c:\windows\system32\tmp1EF44.FOT
2011-12-14 13:34 . 2011-12-14 13:34 1409 ----a-w- c:\windows\system32\tmp02054.FOT
2011-12-14 13:34 . 2011-12-14 13:34 1409 ----a-w- c:\windows\system32\tmpADB44.FOT
2011-12-14 13:34 . 2011-12-14 13:34 1409 ----a-w- c:\windows\system32\tmp55F44.FOT
2011-12-14 13:34 . 2011-12-14 13:34 1409 ----a-w- c:\windows\system32\tmp39F44.FOT
2011-12-14 13:34 . 2011-12-14 13:34 1409 ----a-w- c:\windows\system32\tmpD6B44.FOT
2011-12-14 13:18 . 2011-12-14 13:18 1409 ----a-w- c:\windows\system32\tmpF6BE2.FOT
2011-12-14 13:18 . 2011-12-14 13:18 1409 ----a-w- c:\windows\system32\tmpEABE2.FOT
2011-12-14 13:18 . 2011-12-14 13:18 1409 ----a-w- c:\windows\system32\tmpD39E2.FOT
2011-12-14 13:18 . 2011-12-14 13:18 1409 ----a-w- c:\windows\system32\tmpB89E2.FOT
2011-12-14 13:18 . 2011-12-14 13:18 1409 ----a-w- c:\windows\system32\tmp65AE2.FOT
2011-12-14 13:18 . 2011-12-14 13:18 1409 ----a-w- c:\windows\system32\tmp3DAE2.FOT
2011-12-14 13:18 . 2011-12-14 13:18 1409 ----a-w- c:\windows\system32\tmp12BE2.FOT
2011-12-10 20:24 . 2008-05-31 18:04 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-02 17:36 . 2011-12-02 17:36 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2011-11-25 21:57 . 2004-08-09 21:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-12-21 07:24 . 2011-12-31 19:27 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-09-12 17:33 . 2011-09-12 17:33 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2006-01-24 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-01-24 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-24 7311360]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\
WKCALREM.LNK.disabled [2010-8-31 938]
.
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\AutorunsDisabled
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
wkcalrem.lnk.disabled [2007-9-12 938]
wordweb.lnk.disabled [2007-8-3 1601]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk.disabled [2005-8-17 572]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ SDEarlyDelete \??\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk.disabled]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.disabledCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk.disabled]
backup=c:\windows\pss\Compaq Connections.lnk.disabledCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk.disabled]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.disabledCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LiveUpdate Notice Service"=2 (0x2)
"LiveUpdate Notice Ex"=2 (0x2)
"LiveUpdate"=3 (0x3)
"ISPwdSvc"=3 (0x3)
"comHost"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
"PCPal"=c:\program files\PCPal\PalAgnt.exe /startup
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"AVG8_TRAY"=c:\progra~1\AVG\AVG8\avgtray.exe
"SmartRAM"=e:\advanced windowscare v2\MemCleaner.exe /m
"MediaGet2"=c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\MediaGet2\mediaget.exe --minimized
"SUPERAntiSpyware"=c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"<NO NAME>"=
"KBD"=c:\hp\KBD\KBD.EXE
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"AlwaysReady Power Message APP"=ARPWRMSG.EXE
"DISCover"=c:\program files\DISC\DISCover.exe
"nwiz"=c:\program files\NVIDIA Corporation\nview\nwiz.exe /installquiet
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
"ehTray"=c:\windows\ehome\ehtray.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" -h
"NvMediaCenter"=RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
"HPDJ Taskbar Utility"=c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
"HP Software Update"=c:\program files\Hp\HP Software Update\HPWuSchd2.exe
"Info Center"=c:\program files\PCPitstop\Info Center\InfoCenter.exe
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"PC Pitstop PC Matic Reminder"=c:\program files\PCPitstop\PC Matic\Reminder-PCMatic.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\DirecTV\\DirecTV\\DIRECTV2PC™.exe"=
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [07/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [07/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [08/11/2011 6:38 PM 116608]
R2 CLDTVHNService;CLDTVHNService;c:\program files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe [09/17/2009 6:40 PM 75048]
R2 ntk_dtv;ntk_dtv;c:\program files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys [09/17/2009 6:40 PM 119792]
S2 gupdate1c9316637dc9d00;Google Update Service (gupdate1c9316637dc9d00);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2008 4:12 PM 133104]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [12/02/2011 12:36 PM 23456]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [08/15/2007 8:31 AM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2008 4:12 PM 133104]
S3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [02/07/2006 8:38 PM 21120]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL29A60357
*Deregistered* - aswMBR
*Deregistered* - MpKsl29a60357
*Deregistered* - uphcleanhlp
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 21:19]
.
2012-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 21:19]
.
2012-02-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2007-11-22 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2007-03-17 20:31]
.
2012-02-23 c:\windows\Tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://msn.com/
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 192.168.2.1
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\788pfasp.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Notify-WgaLogon - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-23 12:06
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\PCD5SRVC{8A863ACB-F5F6CC6A-05010003}]
"ImagePath"="\??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3019693388-2064130007-760773113-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(744)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2012-02-23 12:10:53
ComboFix-quarantined-files.txt 2012-02-23 17:10
.
Pre-Run: 200,427,253,760 bytes free
Post-Run: 200,444,633,088 bytes free
.
- - End Of File - - 04A7B6DA71D4DD65CDC9817098D5B78E

#8 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 23 February 2012 - 12:33 PM

Hi,
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
    BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File
    TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
    TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
    DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
    
    File::
    c:\windows\system32\tmp8EA68.FOT
    c:\windows\system32\tmp63B68.FOT
    c:\windows\system32\tmpC3A68.FOT
    c:\windows\system32\tmpA8A68.FOT
    c:\windows\system32\tmp83868.FOT
    c:\windows\system32\tmp6A868.FOT
    c:\windows\system32\tmp0A968.FOT
    c:\windows\system32\tmpE5054.FOT
    c:\windows\system32\tmp1EF44.FOT
    c:\windows\system32\tmp02054.FOT
    c:\windows\system32\tmpADB44.FOT
    c:\windows\system32\tmp55F44.FOT
    c:\windows\system32\tmp39F44.FOT
    c:\windows\system32\tmpD6B44.FOT
    c:\windows\system32\tmpF6BE2.FOT
    c:\windows\system32\tmpEABE2.FOT
    c:\windows\system32\tmpD39E2.FOT
    c:\windows\system32\tmpB89E2.FOT
    c:\windows\system32\tmp65AE2.FOT
    c:\windows\system32\tmp3DAE2.FOT
    c:\windows\system32\tmp12BE2.FOT
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    Posted Image
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------
Posted Image
 
 

#9 Lewg

Lewg

    Silver Member

  • Authentic Member
  • PipPipPip
  • 393 posts

Posted 23 February 2012 - 01:16 PM

ComboFix 12-02-22.01 - Compaq_Administrator 02/23/2012 14:00:08.7.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.364 [GMT -5:00]
Running from: c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Compaq_Administrator\Desktop\CFScript.txt.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\windows\system32\tmp02054.FOT"
"c:\windows\system32\tmp0A968.FOT"
"c:\windows\system32\tmp12BE2.FOT"
"c:\windows\system32\tmp1EF44.FOT"
"c:\windows\system32\tmp39F44.FOT"
"c:\windows\system32\tmp3DAE2.FOT"
"c:\windows\system32\tmp55F44.FOT"
"c:\windows\system32\tmp63B68.FOT"
"c:\windows\system32\tmp65AE2.FOT"
"c:\windows\system32\tmp6A868.FOT"
"c:\windows\system32\tmp83868.FOT"
"c:\windows\system32\tmp8EA68.FOT"
"c:\windows\system32\tmpA8A68.FOT"
"c:\windows\system32\tmpADB44.FOT"
"c:\windows\system32\tmpB89E2.FOT"
"c:\windows\system32\tmpC3A68.FOT"
"c:\windows\system32\tmpD39E2.FOT"
"c:\windows\system32\tmpD6B44.FOT"
"c:\windows\system32\tmpE5054.FOT"
"c:\windows\system32\tmpEABE2.FOT"
"c:\windows\system32\tmpF6BE2.FOT"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\roboot.exe
c:\windows\system32\tmp02054.FOT
c:\windows\system32\tmp0A968.FOT
c:\windows\system32\tmp12BE2.FOT
c:\windows\system32\tmp1EF44.FOT
c:\windows\system32\tmp39F44.FOT
c:\windows\system32\tmp3DAE2.FOT
c:\windows\system32\tmp55F44.FOT
c:\windows\system32\tmp63B68.FOT
c:\windows\system32\tmp65AE2.FOT
c:\windows\system32\tmp6A868.FOT
c:\windows\system32\tmp83868.FOT
c:\windows\system32\tmp8EA68.FOT
c:\windows\system32\tmpA8A68.FOT
c:\windows\system32\tmpADB44.FOT
c:\windows\system32\tmpB89E2.FOT
c:\windows\system32\tmpC3A68.FOT
c:\windows\system32\tmpD39E2.FOT
c:\windows\system32\tmpD6B44.FOT
c:\windows\system32\tmpE5054.FOT
c:\windows\system32\tmpEABE2.FOT
c:\windows\system32\tmpF6BE2.FOT
.
.
((((((((((((((((((((((((( Files Created from 2012-01-23 to 2012-02-23 )))))))))))))))))))))))))))))))
.
.
2012-02-23 17:21 . 2012-02-23 17:21 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2012-02-23 17:21 . 2012-02-23 17:21 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple
2012-02-23 17:12 . 2012-02-08 06:03 6552120 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DA70EB07-0189-4AAF-89B7-81A1F10B6A56}\mpengine.dll
2012-02-16 03:13 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-16 03:13 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\dllcache\iacenc.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-08 06:03 . 2011-07-16 14:34 6552120 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-31 12:44 . 2011-03-08 21:25 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-12 16:53 . 2004-08-09 21:00 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-30 12:39 . 2011-07-09 13:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-17 19:46 . 2004-08-09 21:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2004-08-09 21:00 43520 ------w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2004-08-09 21:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-12-17 13:38 . 2008-01-03 02:08 38400 ----a-w- c:\windows\system32\pcdhdm.cpl
2011-12-16 12:22 . 2004-08-09 21:00 385024 ------w- c:\windows\system32\html.iec
2011-12-10 20:24 . 2008-05-31 18:04 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-02 17:36 . 2011-12-02 17:36 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2011-11-25 21:57 . 2004-08-09 21:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-12-21 07:24 . 2011-12-31 19:27 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-09-12 17:33 . 2011-09-12 17:33 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-02-23_17.06.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-23 16:53 . 2012-02-23 18:58 8192 c:\windows\ERDNT\Hiv-backup\DEFAUL~1.DAT
- 2012-02-23 16:53 . 2012-02-23 16:53 8192 c:\windows\ERDNT\Hiv-backup\DEFAUL~1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2006-01-24 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-01-24 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-24 7311360]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\
WKCALREM.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-6-23 15360]
WKCALREM.LNK.disabled [2010-8-31 938]
.
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\AutorunsDisabled
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
wkcalrem.lnk.disabled [2007-9-12 938]
wordweb.lnk.disabled [2007-8-3 1601]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk.disabled [2005-8-17 572]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[BU]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ SDEarlyDelete \??\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk.disabled]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.disabledCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk.disabled]
backup=c:\windows\pss\Compaq Connections.lnk.disabledCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk.disabled]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.disabledCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LiveUpdate Notice Service"=2 (0x2)
"LiveUpdate Notice Ex"=2 (0x2)
"LiveUpdate"=3 (0x3)
"ISPwdSvc"=3 (0x3)
"comHost"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
"PCPal"=c:\program files\PCPal\PalAgnt.exe /startup
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"AVG8_TRAY"=c:\progra~1\AVG\AVG8\avgtray.exe
"SmartRAM"=e:\advanced windowscare v2\MemCleaner.exe /m
"MediaGet2"=c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\MediaGet2\mediaget.exe --minimized
"SUPERAntiSpyware"=c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"<NO NAME>"=
"KBD"=c:\hp\KBD\KBD.EXE
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"AlwaysReady Power Message APP"=ARPWRMSG.EXE
"DISCover"=c:\program files\DISC\DISCover.exe
"nwiz"=c:\program files\NVIDIA Corporation\nview\nwiz.exe /installquiet
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
"ehTray"=c:\windows\ehome\ehtray.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" -h
"NvMediaCenter"=RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
"HPDJ Taskbar Utility"=c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
"HP Software Update"=c:\program files\Hp\HP Software Update\HPWuSchd2.exe
"Info Center"=c:\program files\PCPitstop\Info Center\InfoCenter.exe
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"PC Pitstop PC Matic Reminder"=c:\program files\PCPitstop\PC Matic\Reminder-PCMatic.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\DirecTV\\DirecTV\\DIRECTV2PC™.exe"=
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [07/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [07/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [08/11/2011 6:38 PM 116608]
R2 CLDTVHNService;CLDTVHNService;c:\program files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe [09/17/2009 6:40 PM 75048]
R2 ntk_dtv;ntk_dtv;c:\program files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys [09/17/2009 6:40 PM 119792]
S2 gupdate1c9316637dc9d00;Google Update Service (gupdate1c9316637dc9d00);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2008 4:12 PM 133104]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [12/02/2011 12:36 PM 23456]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [08/15/2007 8:31 AM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2008 4:12 PM 133104]
S3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [02/07/2006 8:38 PM 21120]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL29A60357
*Deregistered* - aswMBR
*Deregistered* - MpKsl29a60357
*Deregistered* - uphcleanhlp
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 21:19]
.
2012-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 21:19]
.
2012-02-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2007-11-22 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2007-03-17 20:31]
.
2012-02-23 c:\windows\Tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://msn.com/
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 192.168.2.1
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\788pfasp.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-23 14:10
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\PCD5SRVC{8A863ACB-F5F6CC6A-05010003}]
"ImagePath"="\??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3019693388-2064130007-760773113-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(744)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2012-02-23 14:13:33
ComboFix-quarantined-files.txt 2012-02-23 19:13
ComboFix2.txt 2012-02-23 17:10
.
Pre-Run: 200,430,133,248 bytes free
Post-Run: 200,433,668,096 bytes free
.
- - End Of File - - 5DC5D78F8A37E192180C4EDD56DF0B5C

#10 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 23 February 2012 - 01:34 PM

Hi Lewg,


I see that you have Malwarebytes on your computer. Please open Malwarebytes, update it and then run a Quick Scan. There will be a log created that I will need in your next reply.
----------

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: Posted Image
  • [quote]Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: Posted Image
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: Posted Image
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: Posted Image
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
----------

In your next reply post the logs made by Malwarebytes, ESET online scanner and let me know how your system is running. :)
Posted Image
 
 

    Advertisements

Register to Remove


#11 Lewg

Lewg

    Silver Member

  • Authentic Member
  • PipPipPip
  • 393 posts

Posted 23 February 2012 - 06:32 PM

Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org Database version: v2012.02.23.03 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Compaq_Administrator :: COMPAQ-PRESARIO [administrator] 02/23/2012 4:54:11 PM mbam-log-2012-02-23 (16-54-11).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 214826 Time elapsed: 6 minute(s), 30 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=02110984f4043046b24f37e8b6e604cc # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2012-02-24 12:14:55 # local_time=2012-02-23 07:14:55 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 91285720 91285720 0 0 # compatibility_mode=5891 16776869 42 87 0 25966550 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=153721 # found=1 # cleaned=0 # scan_time=7219 C:\Documents and Settings\Compaq_Administrator\My Documents\cnet_framxpro_zip.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I

#12 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 23 February 2012 - 08:03 PM

How is your system running? What malware problems are you still experiencing? :)
Posted Image
 
 

#13 Lewg

Lewg

    Silver Member

  • Authentic Member
  • PipPipPip
  • 393 posts

Posted 23 February 2012 - 08:17 PM

The same, HD whinning way to much. Takes forever to get to WTT.

#14 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 23 February 2012 - 08:21 PM

Hi Lewg,

Lets get a different look at your system.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Posted Image
 
 

#15 Lewg

Lewg

    Silver Member

  • Authentic Member
  • PipPipPip
  • 393 posts

Posted 23 February 2012 - 08:42 PM

OTL logfile created on: 02/23/2012 9:34:29 PM - Run 1
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Documents and Settings\Compaq_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

958.48 Mb Total Physical Memory | 469.29 Mb Available Physical Memory | 48.96% Memory free
2.26 Gb Paging File | 1.94 Gb Available in Paging File | 85.96% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.68 Gb Total Space | 186.40 Gb Free Space | 82.96% Space Free | Partition Type: NTFS
Drive D: | 8.18 Gb Total Space | 0.54 Gb Free Space | 6.63% Space Free | Partition Type: FAT32
Drive F: | 93.37 Gb Total Space | 56.02 Gb Free Space | 60.00% Space Free | Partition Type: NTFS

Computer Name: COMPAQ-PRESARIO | User Name: Compaq_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Compaq_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\UPHClean\uphclean.exe (Windows ® Codename Longhorn DDK provider)
PRC - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\arservice.exe (Microsoft)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\nview.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()
MOD - C:\WINDOWS\system32\pdfcmnnt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (UPHClean) -- C:\Program Files\UPHClean\uphclean.exe (Windows ® Codename Longhorn DDK provider)
SRV - (CLDTVHNService) -- C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
SRV - (ARSVC) -- C:\WINDOWS\arservice.exe (Microsoft)
SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (MpKsl3cc1ba34) -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2E0C1E08-D4A4-420E-9BC7-375F78EF1004}\MpKsl3cc1ba34.sys (Microsoft Corporation)
DRV - (DrvAgent32) -- C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Almico Software)
DRV - (ntk_dtv) -- C:\Program Files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys (Cyberlink Corp.)
DRV - (USB_RNDIS_XP) -- C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (MCSTRM) -- C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (PCD5SRVC{8A863ACB-F5F6CC6A-05010003}) -- C:\Program Files\PC-Doctor 5 for Windows\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (Ps2) -- C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (rtl8139) Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...m...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 76 86 02 AA 3E C7 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/10/17 11:04:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/10/17 11:05:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/31 14:27:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/12 09:44:28 | 000,000,000 | ---D | M]

[2011/12/31 14:28:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Extensions
[2011/12/31 14:27:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/07/03 00:06:59 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2
[2011/12/21 02:24:52 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/03/18 13:32:12 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/11/24 16:22:52 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 13:32:14 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/12/20 23:30:41 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/20 23:30:41 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/02/23 14:10:05 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O2 - BHO: (hpWebHelper Class) - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll (TODO: <Company name>)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\AutorunsDisabled [2010/09/14 07:43:53 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\WKCALREM.LNK.disabled ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2....re/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} http://download.micr...N-US/msorun.cab (Reg Error: Key error.)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadbl...ivex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} http://www.photodex.com/pxplay.cab (Photodex Presenter AX control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmi...inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D}: DhcpNameServer = 16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A7C78262-8D81-4086-BCD4-535ECA720CFA}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (SDEarlyDelete \??)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/02/23 21:31:26 | 000,583,680 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Compaq_Administrator\Desktop\OTL.exe
[2012/02/23 17:05:50 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/02/23 17:02:25 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/02/23 14:13:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012/02/23 13:58:46 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/02/23 11:53:33 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/02/23 11:53:33 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/02/23 11:53:33 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/02/23 11:53:19 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/02/23 11:51:53 | 004,417,295 | R--- | C] (Swearware) -- C:\Documents and Settings\Compaq_Administrator\Desktop\ComboFix.exe
[2012/02/22 20:08:30 | 004,730,880 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Compaq_Administrator\Desktop\aswMBR.exe
[2012/02/22 20:06:37 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\Compaq_Administrator\Desktop\dds.com
[2012/02/22 20:06:15 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\Compaq_Administrator\Desktop\dds.scr
[2012/02/17 19:08:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Compaq_Administrator\My Documents\Maritime Museum Sleeping Bear Point

========== Files - Modified Within 30 Days ==========

[2012/02/23 21:37:00 | 000,000,500 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job
[2012/02/23 21:31:40 | 000,583,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Compaq_Administrator\Desktop\OTL.exe
[2012/02/23 21:27:18 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/23 21:22:36 | 000,049,362 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2012/02/23 21:22:13 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/23 21:22:11 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/23 20:54:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/23 14:10:05 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/02/23 12:28:06 | 000,000,938 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\WKCALREM.LNK
[2012/02/23 12:21:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/02/23 11:52:51 | 004,417,295 | R--- | M] (Swearware) -- C:\Documents and Settings\Compaq_Administrator\Desktop\ComboFix.exe
[2012/02/23 10:52:55 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\MBRCheck.exe
[2012/02/23 06:58:14 | 000,000,455 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\The Five.url
[2012/02/23 03:01:27 | 000,458,446 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/02/23 03:01:27 | 000,078,716 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/02/23 02:54:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/22 23:45:44 | 003,686,454 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Wiring Diagram for Light Switches on 1972 Beetle.bmp
[2012/02/22 22:45:59 | 000,000,586 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Yahoo!.url
[2012/02/22 21:14:58 | 003,686,454 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\VW Bug Flasher and Light Switch Diagram.bmp
[2012/02/22 20:20:01 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\MBR.dat
[2012/02/22 20:08:38 | 004,730,880 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Compaq_Administrator\Desktop\aswMBR.exe
[2012/02/22 20:06:46 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\Compaq_Administrator\Desktop\dds.com
[2012/02/22 20:06:28 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\Compaq_Administrator\Desktop\dds.scr
[2012/02/22 11:51:35 | 000,000,273 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\SSI Pier Web Camera.url
[2012/02/22 11:39:00 | 000,002,043 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Interactive User's Guide.lnk
[2012/02/22 11:35:44 | 000,047,807 | ---- | M] () -- C:\WINDOWS\hpiins01.dat.temp
[2012/02/22 11:27:40 | 000,000,267 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Manual Removal Guide for Moozy - Safer-Networking Forums.url
[2012/02/22 10:05:17 | 000,000,211 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Google.url
[2012/02/21 18:14:02 | 000,000,928 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Photo Gallery - Winter Preview 2012 New TV Shows - TV Shows & TV Series Pictures & Photos TWoP.url
[2012/02/20 18:39:50 | 000,002,213 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Watch Doc Martin Season.url
[2012/02/20 10:10:51 | 000,000,264 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Watch Live Sports Events and ESPN Programs Online and on Mobile Applications - WatchESPN.url
[2012/02/20 09:35:26 | 000,000,302 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\CBS Radio Mystery Theater CBSRMT - Old Time Radio Shows - OTR.url
[2012/02/19 14:57:42 | 000,001,135 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Shortcut to bug_std_super_72 wiring diagrahm.lnk
[2012/02/18 23:44:24 | 006,849,352 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Microsoft PowerPointSTFWIRING.pdf
[2012/02/17 13:01:21 | 000,322,728 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/17 11:00:35 | 000,000,271 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Glynn County, GA - Official Website - Live Meeting Video.url
[2012/02/16 17:35:42 | 000,081,455 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Run-on-Trout.jpg
[2012/02/16 17:28:09 | 000,000,261 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\912-638-5778 - Pipl - People Search.url
[2012/02/16 08:52:49 | 000,000,312 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Walmart Toshiba Toshiba Black Trax 17.3 C675-S7308 Laptop PC with Intel Core i3-2330M Processor and Windows 7 Home Premium Questions, Answers, How To, FAQs, Tips, Advice, Answers, Buying Guide.url
[2012/02/16 03:02:59 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/02/15 22:38:19 | 000,014,798 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Application Data\wklnhst.dat
[2012/02/15 22:38:19 | 000,010,240 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Internal Revenue Service.wps
[2012/02/15 22:36:33 | 000,000,061 | ---- | M] () -- C:\WINDOWS\TaxACT11.ini
[2012/02/15 22:18:09 | 000,009,728 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Ga Dept Of Revenue.wps
[2012/02/14 22:47:39 | 000,000,180 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Tom's Bug Gauges.url
[2012/02/14 14:03:36 | 000,000,964 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\HP Home & Home Office Store - Shopping Cart and Checkout.url
[2012/02/14 09:20:19 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\WunderMap Interactive Radar & Weather Stations Weather Underground.url
[2012/02/12 14:31:34 | 003,888,054 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\HP INK ORDER.bmp
[2012/02/12 13:02:19 | 002,395,062 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Me and Carol at the Lake Mirror Classic in 2011.bmp
[2012/02/11 12:02:02 | 000,000,331 | ---- | M] () -- C:\WINDOWS\System32\msxkwn.vxp
[2012/02/09 07:29:13 | 000,000,281 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\SSI Pier Web Camera (2).url
[2012/02/08 16:07:37 | 000,000,061 | ---- | M] () -- C:\WINDOWS\TaxACT10.ini
[2012/02/07 09:44:47 | 000,000,350 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\#player (2).url
[2012/02/04 14:03:01 | 000,000,061 | ---- | M] () -- C:\WINDOWS\TaxACT09.ini
[2012/02/04 13:47:46 | 000,000,075 | ---- | M] () -- C:\WINDOWS\TaxACT08.ini
[2012/02/04 12:19:34 | 000,065,644 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\2011 Individual Tax Return File.ta1
[2012/02/01 09:23:11 | 000,000,074 | ---- | M] () -- C:\WINDOWS\TaxACT07.ini
[2012/01/31 07:44:05 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2012/01/29 14:24:53 | 000,290,648 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Mecum Auction Layout in Kissimmee FL 2.jpg
[2012/01/29 14:23:03 | 001,175,860 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Mecum Auction Layout in Kissimmee FL 1.jpg
[2012/01/29 14:19:59 | 000,703,139 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Biddin Application for Mecum Auction.jpg
[2012/01/29 14:17:58 | 000,411,061 | ---- | M] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Mecum Auction Layout in Kissimmee FL.jpg

========== Files Created - No Company Name ==========

[2012/02/23 12:28:06 | 000,000,938 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\WKCALREM.LNK
[2012/02/23 11:53:33 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/23 11:53:33 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/23 11:53:33 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/02/23 11:53:33 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/02/23 11:53:33 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/02/23 10:52:52 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\MBRCheck.exe
[2012/02/22 23:45:38 | 003,686,454 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Wiring Diagram for Light Switches on 1972 Beetle.bmp
[2012/02/22 21:14:58 | 003,686,454 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\VW Bug Flasher and Light Switch Diagram.bmp
[2012/02/22 20:20:01 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\MBR.dat
[2012/02/22 11:39:00 | 000,002,043 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Interactive User's Guide.lnk
[2012/02/22 11:27:40 | 000,000,267 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Manual Removal Guide for Moozy - Safer-Networking Forums.url
[2012/02/20 10:10:51 | 000,000,264 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Watch Live Sports Events and ESPN Programs Online and on Mobile Applications - WatchESPN.url
[2012/02/20 09:35:26 | 000,000,302 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\CBS Radio Mystery Theater CBSRMT - Old Time Radio Shows - OTR.url
[2012/02/19 14:57:42 | 000,001,135 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Shortcut to bug_std_super_72 wiring diagrahm.lnk
[2012/02/18 23:44:22 | 006,849,352 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Microsoft PowerPointSTFWIRING.pdf
[2012/02/16 17:32:40 | 000,081,455 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Run-on-Trout.jpg
[2012/02/16 17:17:37 | 000,000,271 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Glynn County, GA - Official Website - Live Meeting Video.url
[2012/02/15 22:13:57 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/15 22:13:57 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/14 22:47:39 | 000,000,180 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Tom's Bug Gauges.url
[2012/02/12 14:31:33 | 003,888,054 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\HP INK ORDER.bmp
[2012/02/12 12:56:17 | 002,395,062 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Me and Carol at the Lake Mirror Classic in 2011.bmp
[2012/02/12 09:57:23 | 000,000,261 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\912-638-5778 - Pipl - People Search.url
[2012/02/10 19:25:30 | 000,000,933 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\WunderMap Interactive Radar & Weather Stations Weather Underground.url
[2012/02/07 09:44:47 | 000,000,350 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\#player (2).url
[2012/02/06 09:26:08 | 000,002,213 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Watch Doc Martin Season.url
[2012/02/04 15:33:12 | 000,000,281 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\SSI Pier Web Camera (2).url
[2012/02/04 12:22:54 | 000,065,644 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\2011 Individual Tax Return File.ta1
[2012/02/02 14:05:03 | 000,000,273 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\SSI Pier Web Camera.url
[2012/01/31 03:01:21 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2012/01/29 14:25:22 | 000,290,648 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Mecum Auction Layout in Kissimmee FL 2.jpg
[2012/01/29 14:23:45 | 001,175,860 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Mecum Auction Layout in Kissimmee FL 1.jpg
[2012/01/29 14:20:27 | 000,703,139 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Biddin Application for Mecum Auction.jpg
[2012/01/29 14:18:53 | 000,411,061 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\My Documents\Mecum Auction Layout in Kissimmee FL.jpg
[2012/01/28 13:12:38 | 000,000,312 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Desktop\Walmart Toshiba Toshiba Black Trax 17.3 C675-S7308 Laptop PC with Intel Core i3-2330M Processor and Windows 7 Home Premium Questions, Answers, How To, FAQs, Tips, Advice, Answers, Buying Guide.url
[2012/01/06 17:08:24 | 000,000,061 | ---- | C] () -- C:\WINDOWS\TaxACT11.ini
[2011/11/30 23:46:28 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\default_user_class.dat
[2011/07/24 14:47:34 | 002,130,002 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2011/07/10 12:48:52 | 000,024,408 | ---- | C] () -- C:\WINDOWS\System32\ventmon.dll
[2011/07/03 00:10:37 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\WebpageIcons.db
[2011/05/14 15:11:18 | 000,285,176 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/05/14 15:11:18 | 000,285,176 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/05/14 15:11:18 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/01/12 17:31:18 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\PUTTY.RND
[2011/01/07 16:08:16 | 000,000,061 | ---- | C] () -- C:\WINDOWS\TaxACT10.ini
[2010/07/04 12:58:02 | 000,158,536 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

========== LOP Check ==========

[2011/03/08 16:13:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/06 10:39:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/12/15 10:22:00 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/03 13:52:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2008/08/04 05:10:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GARMIN
[2009/06/06 22:17:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2010/12/15 10:01:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2006/08/23 08:54:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/12/24 12:12:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\National Instruments
[2006/07/14 18:28:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Otto
[2009/04/28 15:03:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/12/21 11:57:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2007/10/02 17:02:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2008/01/14 10:46:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Uniblue
[2011/11/20 17:01:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Uninstall
[2011/07/10 12:48:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Venta
[2007/08/21 08:13:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2010/07/03 14:45:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\GARMIN
[2009/04/28 15:02:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\GetRightToGo
[2007/08/16 18:00:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\GPS Utility
[2011/01/04 17:17:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\gtk-2.0
[2009/10/14 23:36:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\IE7pro
[2009/01/22 19:52:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\IObit
[2006/07/14 22:06:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Leadertech
[2006/09/18 18:48:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\MSNInstaller
[2007/12/13 08:38:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Netscape
[2006/07/14 18:28:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Otto
[2011/01/02 09:58:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Participatory Culture Foundation
[2011/12/08 15:41:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\PCF-VLC
[2006/08/08 19:19:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Registry Booster
[2008/10/24 09:58:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Safer Networking
[2011/11/30 23:56:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Systweak
[2006/07/14 09:57:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Template
[2011/12/16 20:53:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Uniblue
[2009/12/02 18:54:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\Wal-Mart
[2007/07/07 07:48:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\WinBatch
[2010/08/11 18:19:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Compaq_Administrator\Application Data\wsInspector
[2012/02/23 21:27:18 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2012/02/23 21:37:00 | 000,000,500 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job

========== Purity Check ==========




< End of report >


OTL Extras logfile created on: 02/23/2012 9:34:29 PM - Run 1
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Documents and Settings\Compaq_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

958.48 Mb Total Physical Memory | 469.29 Mb Available Physical Memory | 48.96% Memory free
2.26 Gb Paging File | 1.94 Gb Available in Paging File | 85.96% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.68 Gb Total Space | 186.40 Gb Free Space | 82.96% Space Free | Partition Type: NTFS
Drive D: | 8.18 Gb Total Space | 0.54 Gb Free Space | 6.63% Space Free | Partition Type: FAT32
Drive F: | 93.37 Gb Total Space | 56.02 Gb Free Space | 60.00% Space Free | Partition Type: NTFS

Computer Name: COMPAQ-PRESARIO | User Name: Compaq_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\A譨彮孞aﱢ嘀赗ﱅ事倄⵪韨￯诿ࡽo赦ﱅw챡�삄ﱜ嘀h譮մ쀳b]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\A譨彮孞aﱢ嘀赗ﱅ事倄⵪韨￯诿ࡽo赦ﱅw챡�삄ﱜ嘀h譮մ쀳b\譖3p事ッ‹�삄S�譎ヒ譕囬譗ࡽ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe" = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe:*:Enabled:Compaq Connections -- (Hewlett-Packard)
"C:\Program Files\DirecTV\DirecTV\DIRECTV2PC™.exe" = C:\Program Files\DirecTV\DirecTV\DIRECTV2PC™.exe:*:Enabled:DIRECTV2PC™ -- (DIRECTV Corp.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\DISC\DISCover.exe" = C:\Program Files\DISC\DISCover.exe:*:Enabled:DISCover Drop & Play System -- (Digital Interactive Systems Corporation)
"C:\Program Files\DISC\DiscStreamHub.exe" = C:\Program Files\DISC\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub -- (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\DISC\myFTP.exe" = C:\Program Files\DISC\myFTP.exe:*:Enabled:DISCover FTP -- (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe" = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe:*:Enabled:Compaq Connections -- (Hewlett-Packard)
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console -- (Microsoft Corporation)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- (Google)
"C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe" = C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe:LocalSubNet:Enabled:HP Device Setup -- (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe" = C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe:LocalSubNet:Enabled:HP Network Communicator -- (Hewlett-Packard Co.)
"C:\Program Files\DirecTV\DirecTV\DIRECTV2PC™.exe" = C:\Program Files\DirecTV\DirecTV\DIRECTV2PC™.exe:*:Enabled:DIRECTV2PC™ -- (DIRECTV Corp.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0564C76B-8E1F-4157-8654-B0F9F308BEE9}" = HP Deskjet 3050 J610 series Basic Device Software
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{08E4AE58-748D-4983-9B8A-495E2341769F}" = Garmin POI Loader
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{1341D838-719C-4A05-B50F-49420CA1B4BB}" = HP Boot Optimizer
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1D10C273-3F95-42A2-8371-AB6B1F59821B}" = WOT for Internet Explorer
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{24FBE9FC-6C0E-4221-AE41-55A40BEFE93F}" = CameraDrivers
"{26A24AE4-039D-4CA4-87B4-2F83217001FF}" = Java™ 7 Update 1
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{328019A7-0012-401D-96A2-4CDDD02675A8}" = Garmin POI Loader
"{34E90074-C80C-4182-A995-65E88B5B56E0}" = HP Deskjet 3050 J610 series Product Improvement Study
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352F5013-07DC-446D-8DB6-38F339086C60}" = LightScribe 1.4.84.1
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{38B9A4E1-4482-44D9-AC14-64F70938CCB5}" = Garmin MapSource
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 2.1
"{479F8C12-576B-4A58-AB78-4B70F7012AA8}" = DIRECTV2PC Playback Advisor
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CCC7F68-A437-4559-A840-F5E010934951}" = HP Driver Diagnostics
"{5414086B-AE06-4332-8A59-26FF0F630D1B}" = Garmin Trip and Waypoint Manager v3
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{590D4F8F-98FE-47FA-AC2B-3F22FDCF7C09}" = ShareIns
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
"{623B8278-8CAD-45C1-B844-58B687C07805}" = Bing Bar Platform
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AEDEDA7-411A-4BDD-80F5-BA653D8ED143}" = World Championship Checkers (Gold Plus)
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{7D15B945-2725-4443-AB3F-D900556612FE}" = User Profile Hive Cleanup Service
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{9357AE3A-B2ED-4138-BB9B-0564352C3F0A}" = iTunes
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 285.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 285.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.95
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3EBEF79-DE34-44AE-8774-F6A17ABE27B2}" = Garmin nRoute
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D7DBA21A-CDE5-42EC-BB1C-AE4B3E616B9A}_is1" = HP Support Overview
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide® Viewer ActiveX Control Release 6.5
"{E0783143-EAE2-4047-A8D6-E155523C594C}" = Garmin WebUpdater
"{E786D4DB-EB0D-4474-ADC2-3C229BC17FCA}" = Interactive User’s Guide
"{E9B10AA5-E5F6-4DEF-A435-FB20704AF1E8}" = DIRECTV2PC™
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6970FBD-809A-4C51-BAB3-D94A04C6C8E7}" = Garmin Communicator Plugin
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series Help
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Agere Systems Soft Modem" = Agere Systems PCI-SV92PP Soft Modem
"ATT-RC" = ATT-RC Self Support Tool
"Audacity_is1" = Audacity 1.2.6
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"C79A3D5A32F77A371781A114DED85F082849F61E" = Windows Driver Package - Ross-Tech USB Driver Package (08/16/2011 2.08.14)
"CCleaner" = CCleaner (remove only)
"Chart Navigator" = Chart Navigator
"Cook'n with Pillsbury" = Cook'n with Pillsbury
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"DISCover" = DISCover
"DriverAgent.exe" = DriverAgent by eSupport.com
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"Google Desktop" = Google Desktop
"Hampton Hotels eDirectory_is1" = Hampton Hotels eDirectory with MultiView Reader
"HP Photo & Imaging" = HP Image Zone 4.5
"HP Photo Creations" = HP Photo Creations
"HP Rhapsody" = HP Rhapsody
"HPOOVClient-5577497 Uninstaller" = Compaq Connections (remove only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{479F8C12-576B-4A58-AB78-4B70F7012AA8}" = DIRECTV2PC Playback Advisor
"InstallShield_{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
"InstallShield_{E9B10AA5-E5F6-4DEF-A435-FB20704AF1E8}" = DIRECTV2PC™
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Miro" = Miro
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"PartyPoker" = PartyPoker
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"PCFriendly" = PCFriendly
"Photodex Presenter" = Photodex Presenter
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"Quicken Legal Business Pro 2006" = Quicken Legal Business Pro 2006
"Quicken WillMaker Plus 2006" = Quicken WillMaker Plus 2006
"RealPlayer 6.0" = RealPlayer
"SpeedFan" = SpeedFan (remove only)
"Spell Checker For OE 2.1" = Spell Checker For OE 2.1
"SpywareBlaster_is1" = SpywareBlaster v3.5.1
"ST6UNST #1" = Outlook Express Quick Backup
"ST6UNST #2" = Extra_POI_Editor_Installer
"Super GameHouse Solitaire Vol. 1" = Super GameHouse Solitaire Vol. 1
"SystemRequirementsLab" = System Requirements Lab
"TaxACT 2006" = TaxACT 2006
"TaxACT 2007" = TaxACT 2007
"TaxACT 2008" = TaxACT 2008
"TaxACT 2008 Georgia" = TaxACT 2008 Georgia
"TaxACT 2009" = TaxACT 2009
"TaxACT 2009 Georgia" = TaxACT 2009 Georgia
"TaxACT 2010" = TaxACT 2010
"TaxACT 2010 Georgia" = TaxACT 2010 Georgia
"TaxACT 2011 - 1040 Edition" = TaxACT 2011 - 1040 Edition
"TaxACT 2011 Georgia" = TaxACT 2011 Georgia
"TaxACT Georgia 2006" = TaxACT Georgia 2006
"TaxACT Georgia 2007" = TaxACT Georgia 2007
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WordWeb" = WordWeb

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 01/11/2012 9:05:09 PM | Computer Name = COMPAQ-PRESARIO | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service ASP.NET_2.0.50727
(ASP.NET_2.0.50727) failed. The Error code is the first DWORD in Data section.

Error - 01/11/2012 9:05:11 PM | Computer Name = COMPAQ-PRESARIO | Source = LoadPerf | ID = 3001
Description = The performance counter name string value in the registry is incorrectly
formatted.
The bogus string is 14390, the bogus index value is the first DWORD in Data section
while the last valid index values are the second and third DWORD in Data section.

Error - 01/11/2012 9:05:11 PM | Computer Name = COMPAQ-PRESARIO | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service aspnet_state
(ASP.NET State Service) failed. The Error code is the first DWORD in Data section.

Error - 01/11/2012 9:05:12 PM | Computer Name = COMPAQ-PRESARIO | Source = LoadPerf | ID = 3001
Description = The performance counter name string value in the registry is incorrectly
formatted.
The bogus string is 14390, the bogus index value is the first DWORD in Data section
while the last valid index values are the second and third DWORD in Data section.

Error - 01/15/2012 11:28:40 AM | Computer Name = COMPAQ-PRESARIO | Source = Application Error | ID = 1000
Description = Faulting application nvcplui.exe, version 3.9.730.0, faulting module
nvcpl.dll, version 6.14.10.8205, fault address 0x0017e1cc.

Error - 01/15/2012 11:33:24 AM | Computer Name = COMPAQ-PRESARIO | Source = Application Error | ID = 1000
Description = Faulting application nvcplui.exe, version 3.9.730.0, faulting module
nvcpl.dll, version 6.14.10.8205, fault address 0x0017e1cc.

Error - 01/15/2012 12:50:18 PM | Computer Name = COMPAQ-PRESARIO | Source = Application Error | ID = 1000
Description = Faulting application nvcplui.exe, version 3.9.730.0, faulting module
nvcpl.dll, version 6.14.10.8205, fault address 0x0002b136.

Error - 01/23/2012 1:58:21 PM | Computer Name = COMPAQ-PRESARIO | Source = Application Error | ID = 1000
Description = Faulting application helpctr.exe, version 5.1.2600.5512, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 01/23/2012 1:58:21 PM | Computer Name = COMPAQ-PRESARIO | Source = Application Error | ID = 1000
Description = Faulting application helpctr.exe, version 5.1.2600.5512, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 01/23/2012 1:58:21 PM | Computer Name = COMPAQ-PRESARIO | Source = Application Error | ID = 1000
Description = Faulting application helpctr.exe, version 5.1.2600.5512, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

[ System Events ]
Error - 01/18/2012 3:42:53 PM | Computer Name = COMPAQ-PRESARIO | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate1c9316637dc9d00) service failed
to start due to the following error: %%1053

Error - 01/18/2012 3:42:54 PM | Computer Name = COMPAQ-PRESARIO | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
ftsata2

Error - 01/20/2012 3:15:21 AM | Computer Name = COMPAQ-PRESARIO | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Update Service
(gupdate1c9316637dc9d00) service to connect.

Error - 01/20/2012 3:15:21 AM | Computer Name = COMPAQ-PRESARIO | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate1c9316637dc9d00) service failed
to start due to the following error: %%1053

Error - 01/20/2012 3:15:24 AM | Computer Name = COMPAQ-PRESARIO | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
ftsata2

Error - 01/21/2012 11:28:52 PM | Computer Name = COMPAQ-PRESARIO | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Update Service
(gupdate1c9316637dc9d00) service to connect.

Error - 01/21/2012 11:28:52 PM | Computer Name = COMPAQ-PRESARIO | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate1c9316637dc9d00) service failed
to start due to the following error: %%1053

Error - 01/21/2012 11:28:55 PM | Computer Name = COMPAQ-PRESARIO | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
ftsata2

Error - 01/23/2012 1:50:56 PM | Computer Name = COMPAQ-PRESARIO | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.2.3
with the system having network hardware address DC:D3:21:0E:39:12. Network operations
on this system may be disrupted as a result.

Error - 01/23/2012 2:45:43 PM | Computer Name = COMPAQ-PRESARIO | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.2.3
with the system having network hardware address DC:D3:21:0E:39:12. Network operations
on this system may be disrupted as a result.


< End of report >

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users