msdcsc.exe causing havoc - WinXP freezing on load with over 200 proces
16 min read
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
File::
C:\Documents and Settings\Administrator\My Documents\MSDCSC\msdcsc.exe
C:\Documents and Settings\Administrator\My Documents\MSDCSC\B7EZdErG82Pg\msdcsc.exe
C:\Documents and Settings\Administrator\My Documents\MSDCSC\B7EZdErG82Pg\B7EZdErG82Pg\msdcsc.exe
C:\Documents and Settings\ATHLON\My Documents\MSDCSC\msdcsc.exe
C:\Documents and Settings\ATHLON\My Documents\MSDCSC\B7EZdErG82Pg\msdcsc.exe
C:\Documents and Settings\ATHLON\My Documents\MSDCSC\B7EZdErG82Pg\B7EZdErG82Pg\msdcsc.exe
C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe
C:\WINDOWS\system32\update SN\update.exe
Save this as CFScript.txt, in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, please post the C:\ComboFix.txt for further review.
- Download OTL to your desktop.
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- When the window appears, underneath Output at the top change it to Minimal Output.
- Check the boxes beside LOP Check and Purity Check.
- Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically. - Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Hi Tomk
Scan results are as follows - many thanks
B
:-)
—
-OTL logfile created on: 24/06/2012 21:52:36 - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Documents and Settings\ATHLON\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
895.23 Mb Total Physical Memory | 495.28 Mb Available Physical Memory | 55.32% Memory free
2.12 Gb Paging File | 1.81 Gb Available in Paging File | 85.30% Paging File free
Paging file location(s): c:\pagefile.sys 1344 2688 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 274.63 Gb Free Space | 92.13% Space Free | Partition Type: NTFS
Computer Name: ATHLON-0E1DCF7F | User Name: ATHLON | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\ATHLON\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
PRC - \\?\C:\windows\System32\WBEM\WMIADAP.EXE ()
PRC - C:\WINDOWS\system32\savedump.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VPrintOnline.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESCom.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\KFx.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SpiffyExt.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VPrintOnlineHelper40.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\kpries40.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\LocAcqMod.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\keml40.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\DibLibIP.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\KPCDInterface.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\LocCamBack.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\LocUpdateCheck.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESSkin.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESCliWicMDRW.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\ESEmail.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\Atlas.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaAdapter.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaPrintOnline.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\AppCore.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaControls.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\Pcd.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\IStorageMediaStore.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\VistaCDBackup.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\UpdateChecker.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\DXRawFormatHandler.esx ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxXML2V.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxImV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxProcV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxZipV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxFFV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxCommonV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxCmpV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\SkinuxBaseV.dll ()
MOD - C:\Program Files\Kodak\Kodak EasyShare software\bin\areaifdll.dll ()
MOD - \\?\C:\windows\System32\WBEM\WMIADAP.EXE ()
MOD - \\?\C:\windows\System32\WBEM\wbemcomn.dll ()
MOD - C:\Program Files\ArcSoft\PhotoImpression 5\Share\PIHook.dll ()
========== Win32 Services (SafeList) ==========
SRV - (NetTcpPortSharing) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AresChatServer) – C:\Documents and Settings\ATHLON\My Documents\Ares\chatServer.exe File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (p2pgasvc) – C:\WINDOWS\system32\p2pgasvc.dll (Microsoft Corporation)
SRV - (Iprip) – C:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys File not found
DRV - (PxHelp20) – System32\Drivers\PxHelp20.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (nielprt) – system32\DRIVERS\nielprt.sys File not found
DRV - (NielGfx) – system32\drivers\nielgfx.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (Lbd) – system32\DRIVERS\Lbd.sys File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\ATHLON\LOCALS~1\Temp\catchme.sys File not found
DRV - (RapportIaso) – c:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportIaso.sys (Trusteer Ltd.)
DRV - (RapportEI) – C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\WINDOWS\system32\drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (RapportCerberus_34302) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys ()
DRV - (StarOpen) – C:\windows\System32\drivers\StarOpen.sys ()
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (ss_bmdm) – C:\WINDOWS\system32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) – C:\WINDOWS\system32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) – C:\WINDOWS\system32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (s0017mdm) – C:\WINDOWS\system32\drivers\s0017mdm.sys (MCCI Corporation)
DRV - (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM) – C:\WINDOWS\system32\drivers\s0017unic.sys (MCCI Corporation)
DRV - (s0017obex) – C:\WINDOWS\system32\drivers\s0017obex.sys (MCCI Corporation)
DRV - (s0017bus) Sony Ericsson Device 0017 driver (WDM) – C:\WINDOWS\system32\drivers\s0017bus.sys (MCCI Corporation)
DRV - (s0017mdfl) – C:\WINDOWS\system32\drivers\s0017mdfl.sys (MCCI Corporation)
DRV - (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s0017mgmt.sys (MCCI Corporation)
DRV - (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS) – C:\WINDOWS\system32\drivers\s0017nd5.sys (MCCI Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (optovcm) – C:\WINDOWS\system32\drivers\optovcm.sys (OPTO ELECTRONICS CO.,LTD.)
DRV - (optousb) – C:\WINDOWS\system32\drivers\optousb.sys (OPTO ELECTRONICS CO.,LTD.)
DRV - (seehcri) – C:\WINDOWS\system32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (nvsmu) – C:\WINDOWS\system32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (irsir) – C:\WINDOWS\system32\drivers\irsir.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" = http://www.questscan.com/?prt=QstscanPB&am…s={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co.uk/search?q={searchTe…z=1I7GGIT_en-GB
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2724386
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com//?search={s…mp;a=NWgrARojZv
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.16: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
[2012/02/26 18:58:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ATHLON\Application Data\Mozilla\Extensions
O1 HOSTS File: ([2012/06/09 11:22:48 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe File not found
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\windows\System32\nwiz.exe ()
O4 - HKLM..\Run: [update SN] C:\WINDOWS\system32\update SN\update.exe (Katherina Walensky)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [update SN] C:\WINDOWS\system32\update SN\update.exe (Katherina Walensky)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
O4 - Startup: C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe (Katherina Walensky)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\windows\system32\update SN\update.exe (Katherina Walensky)
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\windows\system32\update SN\update.exe (Katherina Walensky)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\ATHLON\My Documents\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8585828F-C44E-4AF0-8896-249AB8F8B799}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\ATHLON\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\ATHLON\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/06/24 21:51:02 | 000,596,992 | —- | C] (OldTimer Tools) – C:\Documents and Settings\ATHLON\Desktop\OTL.exe
[2012/06/24 21:50:43 | 000,000,000 | —D | C] – C:\windows\LastGood
[2012/06/20 22:05:28 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/06/20 22:04:45 | 004,563,905 | R— | C] (Swearware) – C:\Documents and Settings\ATHLON\Desktop\ComboFix.exe
[2012/06/14 20:49:23 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\ATHLON\Desktop\aswMBR.exe
[2012/06/13 22:25:52 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\windows\System32\dllcache\jsdbgui.dll
[2012/06/13 22:24:57 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\ATHLON\Desktop\dds.scr
[2012/06/10 14:00:35 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/06/10 14:00:24 | 000,000,000 | —D | C] – C:\windows\setupupd
[2012/06/10 13:40:24 | 000,000,000 | —D | C] – C:\windows\setup.pss
[2012/06/10 12:11:06 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/06/10 12:08:45 | 000,000,000 | R–D | C] – C:\Documents and Settings\ATHLON\Start Menu\Programs\Administrative Tools
[2012/06/09 11:19:59 | 000,000,000 | —D | C] – C:\windows\temp
[2012/06/09 11:05:27 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/09 11:05:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Favorites
[2012/05/29 21:08:38 | 000,000,000 | —D | C] – C:\Program Files\Hijack This
[2012/05/29 20:14:07 | 000,463,914 | —- | C] (Katherina Walensky) – C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe
[2009/08/08 15:57:40 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\ATHLON\Application Data\pcouffin.sys
[5 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/06/24 21:56:00 | 000,000,424 | -H– | M] () – C:\windows\tasks\User_Feed_Synchronization-{D6CFB8DA-62F7-4937-9105-DA5C4CED8DE0}.job
[2012/06/24 21:52:54 | 000,433,176 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/06/24 21:52:54 | 000,068,006 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/06/24 21:51:03 | 000,596,992 | —- | M] (OldTimer Tools) – C:\Documents and Settings\ATHLON\Desktop\OTL.exe
[2012/06/24 21:48:39 | 000,000,882 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/24 21:48:26 | 000,002,422 | —- | M] () – C:\windows\System32\wpa.dbl
[2012/06/24 21:48:22 | 000,002,048 | –S- | M] () – C:\windows\bootstat.dat
[2012/06/20 22:15:05 | 938,819,584 | —- | M] () – C:\windows\MEMORY.DMP
[2012/06/20 22:05:01 | 004,563,905 | R— | M] (Swearware) – C:\Documents and Settings\ATHLON\Desktop\ComboFix.exe
[2012/06/20 22:02:47 | 000,002,528 | —- | M] () – C:\Documents and Settings\ATHLON\Application Data\$_hpcst$.hpc
[2012/06/17 20:28:04 | 000,000,886 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/14 22:07:22 | 000,000,512 | —- | M] () – C:\Documents and Settings\ATHLON\Desktop\MBR.dat
[2012/06/14 20:51:26 | 000,103,032 | —- | M] () – C:\windows\System32\FNTCACHE.DAT
[2012/06/14 20:49:44 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\ATHLON\Desktop\aswMBR.exe
[2012/06/13 22:49:40 | 000,001,374 | —- | M] () – C:\windows\imsins.BAK
[2012/06/13 22:25:02 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\ATHLON\Desktop\dds.scr
[2012/06/10 13:35:00 | 000,000,868 | —- | M] () – C:\windows\tasks\Google Software Updater.job
[2012/06/10 12:56:51 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerApp.exe
[2012/06/10 12:56:51 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2012/06/10 12:49:21 | 000,002,577 | —- | M] () – C:\windows\System32\CONFIG.NT
[2012/06/09 11:22:48 | 000,000,027 | —- | M] () – C:\windows\System32\drivers\etc\hosts
[2012/06/02 15:19:44 | 000,022,040 | —- | M] (Microsoft Corporation) – C:\windows\System32\wucltui.dll.mui
[2012/06/02 15:19:38 | 000,329,240 | —- | M] (Microsoft Corporation) – C:\windows\System32\wucltui.dll
[2012/06/02 15:19:38 | 000,329,240 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wucltui.dll
[2012/06/02 15:19:38 | 000,219,160 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wuaucpl.cpl
[2012/06/02 15:19:38 | 000,210,968 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wuweb.dll
[2012/06/02 15:19:34 | 000,097,304 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\cdm.dll
[2012/06/02 15:19:34 | 000,097,304 | —- | M] (Microsoft Corporation) – C:\windows\System32\cdm.dll
[2012/06/02 15:19:34 | 000,053,784 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wuauclt.exe
[2012/06/02 15:19:34 | 000,015,384 | —- | M] (Microsoft Corporation) – C:\windows\System32\wuapi.dll.mui
[2012/06/02 15:19:24 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\windows\System32\wuapi.dll
[2012/06/02 15:19:24 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wuapi.dll
[2012/06/02 15:19:18 | 001,933,848 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\wuaueng.dll
[2012/06/02 15:18:58 | 000,275,696 | —- | M] (Microsoft Corporation) – C:\windows\System32\mucltui.dll
[2012/06/02 15:18:58 | 000,017,136 | —- | M] (Microsoft Corporation) – C:\windows\System32\mucltui.dll.mui
[2012/05/31 14:22:09 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\windows\System32\dllcache\crypt32.dll
[5 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/20 22:02:47 | 000,002,528 | —- | C] () – C:\Documents and Settings\ATHLON\Application Data\$_hpcst$.hpc
[2012/06/14 22:07:22 | 000,000,512 | —- | C] () – C:\Documents and Settings\ATHLON\Desktop\MBR.dat
[2012/06/10 14:00:49 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/06/09 11:05:43 | 000,256,000 | —- | C] () – C:\windows\PEV.exe
[2012/06/09 11:05:43 | 000,208,896 | —- | C] () – C:\windows\MBR.exe
[2012/05/29 20:14:07 | 000,001,837 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
[2012/05/29 20:14:07 | 000,001,808 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012/02/15 23:13:27 | 000,003,072 | —- | C] () – C:\windows\System32\iacenc.dll
[2012/02/14 18:46:50 | 000,000,078 | —- | C] () – C:\windows\Hotkey.INI
[2011/04/25 16:40:15 | 000,057,344 | —- | C] () – C:\windows\System32\PyWinTypes21.dll
[2011/04/25 16:40:14 | 000,290,919 | —- | C] () – C:\windows\System32\pythoncom21.dll
[2011/04/25 16:38:16 | 000,096,768 | —- | C] () – C:\windows\SlantAdj.dll
[2011/04/25 16:38:16 | 000,003,136 | —- | C] () – C:\windows\Ade001.bin
[2011/04/25 16:38:16 | 000,000,072 | —- | C] () – C:\windows\System32\epDPE.ini
[2011/03/07 17:44:26 | 000,110,592 | —- | C] () – C:\windows\System32\FsUsbExDevice.Dll
[2011/03/07 17:44:26 | 000,036,608 | —- | C] () – C:\windows\System32\FsUsbExDisk.Sys
[2010/07/31 15:21:26 | 000,098,304 | —- | C] () – C:\windows\System32\a_jumtmp.dll
[2009/08/08 15:57:40 | 000,087,608 | —- | C] () – C:\Documents and Settings\ATHLON\Application Data\inst.exe
[2009/08/08 15:57:40 | 000,007,887 | —- | C] () – C:\Documents and Settings\ATHLON\Application Data\pcouffin.cat
[2009/08/08 15:57:40 | 000,001,144 | —- | C] () – C:\Documents and Settings\ATHLON\Application Data\pcouffin.inf
[2009/06/19 11:30:43 | 000,000,473 | —- | C] () – C:\Program Files\Shortcut to dvdSanta.lnk
[2009/04/20 18:39:53 | 000,051,712 | —- | C] () – C:\Documents and Settings\ATHLON\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/01/10 19:23:51 | 000,019,046 | -H– | C] () – C:\Documents and Settings\ATHLON\Application Data\logs.dat
========== LOP Check ==========
[2012/02/26 18:59:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\!SASCORE
[2010/06/08 17:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2012/02/26 18:59:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2012/02/26 18:59:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2012/02/26 18:59:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM
[2012/02/26 18:59:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM(2)
[2012/02/26 18:59:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail
[2012/02/26 18:59:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail(2)
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Photo Notifier and Animation Creator
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickClick
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2012/02/26 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpeedMaxPc
[2011/10/20 16:40:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2012/02/26 18:59:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\AJ SQUARE INC
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\AVGTOOLBAR
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Canneverbe Limited
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/05/19 07:35:21 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\dclogs
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\DriverCure
[2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\EPSON
[2012/02/26 18:59:16 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Image Zone Express
[2012/02/26 18:59:16 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\IronCode
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\PC Suite
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Printer Info Cache
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Samsung
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Skinux
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Sony
[2012/02/26 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\SpeedMaxPc
[2012/02/26 18:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Uniblue
[2012/05/05 15:49:06 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\uTorrent
[2012/02/26 18:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\uTorrent(2)
[2012/02/26 18:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\Vso
[2012/05/16 21:42:08 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\YourFileDownloader
[2012/06/24 21:56:00 | 000,000,424 | -H– | M] () – C:\windows\Tasks\User_Feed_Synchronization-{D6CFB8DA-62F7-4937-9105-DA5C4CED8DE0}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\ATHLON\My Documents\SetupDl.exe:SummaryInformation
< End of report >
Second lot of results from Extras.txt
B
:-)
—
OTL Extras logfile created on: 24/06/2012 21:52:36 - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Documents and Settings\ATHLON\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
895.23 Mb Total Physical Memory | 495.28 Mb Available Physical Memory | 55.32% Memory free
2.12 Gb Paging File | 1.81 Gb Available in Paging File | 85.30% Paging File free
Paging file location(s): c:\pagefile.sys 1344 2688 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 274.63 Gb Free Space | 92.13% Space Free | Partition Type: NTFS
Computer Name: ATHLON-0E1DCF7F | User Name: ATHLON | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"ANTIVIRUSDISABLENOTIFY" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"enablefirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"13533:TCP" = 13533:TCP:*:Enabled:BitComet 13533 TCP
"13533:UDP" = 13533:UDP:*:Enabled:BitComet 13533 UDP
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"enablefirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
"C:\Program Files\SUPERAntiSpyware\RUNSAS.EXE" = C:\Program Files\SUPERAntiSpyware\RUNSAS.EXE:*:Enabled:SUPERAntiSpyware Alternate Start
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server – (PeeringPortal)
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server – (PeeringPortal)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{190C7419-C254-408e-81F8-BE11FCD72A1F}" = dj_sf_software
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{47499FAF-B116-4b14-B07F-DB2C3087A06C}" = D4200_Help
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{58535A90-1788-44f5-80BB-CFF62D9CE6D5}" = HP Deskjet 8.0 Software
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}" = fflink
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{6C11D561-620B-47DA-A693-4C597F3CDF40}" = EPSON Smart Panel
"{6C5D7191-140A-11D6-B5A0-0050DA208A93}" = ArcSoft PhotoImpression
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{788A0222-5690-4212-AA9C-C48FD0E1C9AE}" = Photo Notifier and Animation Creator
"{79D78DC9-96A2-426e-B705-A1EE9536D18B}" = D4200
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{870815CA-6B60-47B6-88DD-A67F42D2F03E}" = GPL MPEG-1/2 DirectShow Decoder Filter
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A3EABC0-CA06-11D4-BF77-00104B130C19}" = EPSON TWAIN 5
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B69CC1A5-0404-11D6-ABCB-005004C21D30}" = EPSON Copy Utility
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BBF71276-E8DF-4D5E-8869-3397BF04CF1C}" = ArcSoft PhotoImpression 5
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C7E154EF-D5EC-4da4-9D00-43B85967B120}" = dj_sf_ProductContext
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E42E07F5-5A90-4BA9-B55A-79FCF9EAF9B5}" = STK02N 2.3
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{E7946996-87C1-447B-AF8F-D8EC94F18842}" = Samsung PC Studio
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F327A8F7-00C6-4491-9782-1DFFBB0594A2}" = dj_sf_software_req
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"ContextAdvisor" = ContextAdvisor
"dvdSanta 3.44 - Create Your Own DVD Movies!_is1" = dvdSanta 3.44
"EPSON Photo Print" = EPSON Photo Print
"GearDrivers" = GearDrivers
"Google Updater" = Google Updater
"GSpot" = GSpot Codec Information Appliance
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla ActiveX Control v1.7.12" = Mozilla ActiveX Control v1.7.12
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator
"Rapport_msi" = Rapport
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile Modem Device" = Samsung Mobile Modem Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
"VLC media player" = VideoLAN VLC media player 0.8.6d
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"X-OOM Movie Clone 3" = X-OOM Movie Clone 3 uninstall
"XP Codec Pack" = XP Codec Pack
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 19/05/2012 03:25:07 | Computer Name = ATHLON-0E1DCF7F | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 09/06/2012 06:15:02 | Computer Name = ATHLON-0E1DCF7F | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved
Error - 09/06/2012 06:30:41 | Computer Name = ATHLON-0E1DCF7F | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 09/06/2012 06:30:41 | Computer Name = ATHLON-0E1DCF7F | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x24087c1e.
Error - 10/06/2012 07:23:03 | Computer Name = ATHLON-0E1DCF7F | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established
Error - 10/06/2012 07:28:18 | Computer Name = ATHLON-0E1DCF7F | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x24087c1e.
Error - 10/06/2012 07:45:12 | Computer Name = ATHLON-0E1DCF7F | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 10/06/2012 08:08:18 | Computer Name = ATHLON-0E1DCF7F | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module , version 0.0.0.0, fault address 0x00000000.
Error - 10/06/2012 08:57:25 | Computer Name = ATHLON-0E1DCF7F | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 20/06/2012 17:16:01 | Computer Name = ATHLON-0E1DCF7F | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x24017c1e.
[ System Events ]
Error - 17/06/2012 15:06:10 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd SASKUTIL
Error - 20/06/2012 16:55:52 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 20/06/2012 16:55:52 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd SASKUTIL
Error - 20/06/2012 17:15:22 | Computer Name = ATHLON-0E1DCF7F | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort2, did not respond within the timeout
period.
Error - 20/06/2012 17:17:22 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 20/06/2012 17:17:22 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd SASKUTIL
Error - 24/06/2012 16:48:47 | Computer Name = ATHLON-0E1DCF7F | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort2, did not respond within the timeout
period.
Error - 24/06/2012 16:49:11 | Computer Name = ATHLON-0E1DCF7F | Source = System Error | ID = 1003
Description = Error code 00000019, parameter1 00000020, parameter2 84018000, parameter3
84018418, parameter4 1a830000.
Error - 24/06/2012 16:50:05 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 24/06/2012 16:50:05 | Computer Name = ATHLON-0E1DCF7F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd SASKUTIL
< End of report >
- Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL
:OTL IE - HKCU\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" = http://www.questscan.com/?prt=QstscanPB&am…s={searchTerms} IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2724386 IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com//?search={s…mp;a=NWgrARojZv O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL File not found O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL File not found O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe File not found O4 - HKLM..\Run: [NPSStartup] File not found O4 - HKLM..\Run: [update SN] C:\WINDOWS\system32\update SN\update.exe (Katherina Walensky) O4 - HKCU..\Run: [update SN] C:\WINDOWS\system32\update SN\update.exe (Katherina Walensky) O4 - Startup: C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe (Katherina Walensky) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\windows\system32\update SN\update.exe (Katherina Walensky) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\windows\system32\update SN\update.exe (Katherina Walensky) O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\ATHLON\My Documents\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 File not found O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20) [2012/05/29 20:14:07 | 000,463,914 | —- | C] (Katherina Walensky) – C:\Documents and Settings\ATHLON\Start Menu\Programs\Startup\updat.exe [2012/02/26 18:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\AVGTOOLBAR [2012/05/05 15:49:06 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\uTorrent [2012/02/26 18:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\ATHLON\Application Data\uTorrent(2) @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\ATHLON\My Documents\SetupDl.exe:SummaryInformation :Commands [purity] [emptytemp] [start explorer] [Reboot] - Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then post the resultant log and give me an update as to how things are running now.
If you need help please start a new thread.
New members follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI