Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
2 Pages V   1 2 >  
Closed TopicStart new topic
Google Redirections & Cannot Access McAfee Website [Solved]
nrummel
post Oct 27 2009, 09:16 AM
Post #1


Member
**
Posts: 13
OS: Windows 2000



I use firefox, and it often closes with an error and makes me restart it. Also, about half of the time when I click on a link, it takes me to the wrong webpage. I just recently tried to go to McAfee's website, but could not get there because an error would come up on the page saying it couldn't access the website. When looking around online to find a fix, I found a post on this website by a person with the exact same problem (same topic title). I just ran rootrepeal like they did, and I've attached the report. What now? Please help me! Thanks in advance.

ps - just yesterday I got a virus or something that kept having a "Safety Center" window pop that looked like a windows icon, telling me something was wrong and to do certain things. I ran malwarbytes and deleted the files, but I'm not sure I completely removed it... also, I've had another virus in the past that was windows police (I think that's what it was called) and I run my virus scan an remove it, but it still comes back occasionally. Not sure if these are related to the original problem, but would appreciate help with them too. My computer is sick!
Attached File(s)
Attached File  rootrepeal.txt ( 41.31K ) Number of downloads: 30
 
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 27 2009, 09:16 AM
Post #2


GeekU Teacher
Group Icon
Posts: 35,111
From: Dublin
OS: XP



hi

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  1. If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  2. During the download, rename Combofix to Combo-Fix as follows:





  3. It is important you rename Combofix during the download, but not after.
  4. Please do not rename Combofix to other names, but only to the one indicated.
  5. Close any open browsers.
  6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------
  7. Double click on combo-Fix.exe & follow the prompts.
  8. When finished, it will produce a report for you.
  9. Please post the "C:\Combo-Fix.txt" for further review.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
Go to the top of the page
 
+Quote Post
nrummel
post Oct 27 2009, 08:29 PM
Post #3


Member
**
Posts: 13
OS: Windows 2000



ComboFix 09-10-26.06 - Nick Rummel 10/27/2009 17:35.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.347 [GMT -7:00]
Running from: c:\documents and settings\Nick Rummel\Desktop\Combo-Fix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Nick Rummel\nah_tbrp.exe
c:\program files\Mozilla Firefox\chrome\amba.jar
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\kb913800.exe
c:\windows\ofx.icn
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\system32\bennuar.old
c:\windows\system32\bincd32.dat
c:\windows\system32\dmibsctw.ini
c:\windows\system32\drivers\svchost.exe
c:\windows\system32\htpsojmm.ini
c:\windows\system32\idfxcutw.ini
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\kycnnjqd.ini
c:\windows\system32\mvtinywq.ini
c:\windows\system32\schtml
c:\windows\system32\schtml\dbsinit.exe
c:\windows\system32\schtml\images\i1.gif
c:\windows\system32\schtml\images\i2.gif
c:\windows\system32\schtml\images\i3.gif
c:\windows\system32\schtml\images\j1.gif
c:\windows\system32\schtml\images\j2.gif
c:\windows\system32\schtml\images\j3.gif
c:\windows\system32\schtml\images\jj1.gif
c:\windows\system32\schtml\images\jj2.gif
c:\windows\system32\schtml\images\jj3.gif
c:\windows\system32\schtml\images\l1.gif
c:\windows\system32\schtml\images\l2.gif
c:\windows\system32\schtml\images\l3.gif
c:\windows\system32\schtml\images\pix.gif
c:\windows\system32\schtml\images\t1.gif
c:\windows\system32\schtml\images\t2.gif
c:\windows\system32\schtml\images\up1.gif
c:\windows\system32\schtml\images\up2.gif
c:\windows\system32\schtml\images\w1.gif
c:\windows\system32\schtml\images\w11.gif
c:\windows\system32\schtml\images\w2.gif
c:\windows\system32\schtml\images\w3.gif
c:\windows\system32\schtml\images\w3.jpg
c:\windows\system32\schtml\images\word.doc
c:\windows\system32\schtml\images\wt1.gif
c:\windows\system32\schtml\images\wt2.gif
c:\windows\system32\schtml\images\wt3.gif
c:\windows\system32\schtml\wispex.html
c:\windows\system32\sonhelp.htm
c:\windows\system32\sxubvvbn.ini
c:\windows\system32\sysnet.dat
c:\windows\system32\TAdgQtwa.ini
c:\windows\system32\TAdgQtwa.ini2
c:\windows\system32\tctumxfs.ini
c:\windows\system32\torsxadm.ini
c:\windows\system32\wispex.html
c:\windows\system32\XbaIRXbc.ini
c:\windows\system32\xcgmsqlj.ini
D:\AUTORUN.INF

Infected copy of c:\windows\system32\drivers\vaxscsi.sys was found and disinfected
Restored copy from - Kitty ate it tongue.gif
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ANTIPPRO2009_100
-------\Legacy_NWCWORKSTATION
-------\Service_AntipPro2009_100
-------\Service_NWCWorkstation


((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 )))))))))))))))))))))))))))))))
.

2009-12-06 04:33 . 2009-12-06 04:33 -------- dc----w- c:\windows\system32\XPSViewer
2009-12-06 04:31 . 2009-12-06 04:31 -------- dc----w- c:\program files\Reference Assemblies
2009-12-06 04:29 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\xpsshhdr.dll
2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-12-06 04:29 . 2008-07-06 12:06 117760 -c----w- c:\windows\system32\prntvpt.dll
2009-12-06 04:29 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\xpssvcs.dll
2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-12-06 04:28 . 2009-08-06 03:54 -------- dc----w- c:\windows\SxsCaPendDel
2009-10-26 23:34 . 2006-03-03 15:07 143360 -c--a-w- c:\windows\system32\dunzip32.dll
2009-10-26 01:59 . 2007-11-22 13:44 33832 -c--a-w- c:\windows\system32\drivers\mferkdk.sys
2009-10-26 01:59 . 2007-12-02 19:51 40488 -c--a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-10-26 01:59 . 2007-11-22 13:44 35240 -c--a-w- c:\windows\system32\drivers\mfebopk.sys
2009-10-26 01:59 . 2007-11-22 13:44 79304 -c--a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-10-26 01:59 . 2007-11-22 13:44 201320 -c--a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-26 01:59 . 2007-07-13 13:20 113952 -c--a-w- c:\windows\system32\drivers\Mpfp.sys
2009-10-26 01:57 . 2009-10-26 01:58 -------- dc----w- c:\program files\McAfee.com
2009-10-26 01:25 . 2009-10-26 01:37 -------- dc----w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\AskToolbar
2009-10-23 06:49 . 2009-10-23 06:49 -------- dc----w- c:\program files\Ask.com
2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\Common Files\DVDVideoSoft
2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\DVDVideoSoft
2009-10-21 23:40 . 2009-10-21 23:40 -------- dc----w- C:\EmergencyUtils
2009-10-15 04:30 . 2009-10-28 01:40 -------- dc--a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-15 04:00 . 2009-10-20 01:31 58 -c--a-w- c:\windows\wp4.dat
2009-10-15 04:00 . 2009-10-20 01:31 1 -c--a-w- c:\windows\wp3.dat
2009-10-04 01:12 . 2009-10-04 01:12 -------- dc----w- c:\program files\iPod
2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\program files\iTunes
2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-01 22:35 . 2009-10-01 22:35 287080 -c--a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-06 04:32 . 2008-01-11 18:01 -------- dc----w- c:\program files\MSBuild
2009-10-28 01:43 . 2008-08-08 04:17 -------- dc----w- c:\program files\Lx_cats
2009-10-28 01:39 . 2006-09-05 23:32 -------- dc----w- c:\program files\Dl_cats
2009-10-28 01:34 . 2009-09-09 02:26 -------- dc----w- c:\program files\Common Files\Akamai
2009-10-28 01:31 . 2007-03-24 18:30 -------- dc----w- c:\program files\Symantec AntiVirus
2009-10-28 00:24 . 2008-06-09 21:11 -------- dc----w- c:\program files\McAfee
2009-10-27 05:42 . 2007-08-31 00:39 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Skype
2009-10-27 05:17 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-10-26 23:41 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-26 01:59 . 2008-06-09 21:12 -------- dc----w- c:\program files\Common Files\McAfee
2009-10-23 21:20 . 2007-05-17 18:06 -------- dc-h--w- c:\documents and settings\Nick Rummel\Application Data\Move Networks
2009-10-23 07:12 . 2008-02-11 02:48 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks
2009-10-16 17:37 . 2006-10-12 19:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\dvdcss
2009-10-04 01:12 . 2007-07-01 16:27 -------- dc----w- c:\program files\Common Files\Apple
2009-10-04 00:53 . 2007-12-10 02:00 -------- dc----w- c:\program files\Bonjour
2009-10-04 00:52 . 2007-07-16 02:03 -------- dc----w- c:\program files\QuickTime
2009-09-24 04:46 . 2008-05-20 03:28 -------- dc----w- c:\program files\AFT software
2009-09-24 04:46 . 2008-05-14 06:06 796672 -c--a-w- c:\windows\GPInstall.exe
2009-09-16 23:19 . 2009-09-16 23:19 -------- dc----w- c:\documents and settings\LocalService\Application Data\McAfee
2009-09-15 00:45 . 2009-09-15 00:40 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks 2009
2009-09-15 00:02 . 2009-09-15 00:02 3026 -c--a-w- c:\windows\system32\drivers\hwinterface.sys
2009-09-15 00:02 . 2006-09-05 23:14 152872 -c--a-w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 14:18 . 2005-08-16 09:18 136192 -c--a-w- c:\windows\system32\msv1_0.dll
2009-09-11 06:18 . 2009-09-11 03:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\IM
2009-09-11 06:09 . 2008-01-11 17:48 -------- dc----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-11 06:05 . 2008-02-11 02:18 -------- dc----w- c:\program files\Common Files\SolidWorks Shared
2009-09-11 05:59 . 2009-09-11 05:58 -------- dc----w- c:\program files\AGEIA Technologies
2009-09-11 05:58 . 2009-02-25 01:24 -------- dc----w- c:\documents and settings\All Users\Application Data\SolidWorks
2009-09-11 05:52 . 2009-09-11 05:52 -------- dc----w- c:\program files\MSECache
2009-09-11 05:48 . 2009-09-11 05:47 -------- dc----w- c:\program files\Microsoft Visual Studio 8
2009-09-11 03:26 . 2009-09-11 03:25 -------- dc----w- c:\program files\Common Files\SolidWorks Installation Manager
2009-09-10 07:25 . 2008-01-18 06:30 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Autodesk
2009-09-10 07:23 . 2009-09-09 06:24 -------- dc----w- c:\documents and settings\All Users\Application Data\Autodesk
2009-09-09 06:40 . 2009-09-09 06:18 -------- dc----w- c:\program files\Autodesk
2009-09-09 06:38 . 2008-01-18 06:25 -------- dc----w- c:\program files\Common Files\Autodesk Shared
2009-09-09 06:25 . 2009-09-09 06:24 -------- dc----w- c:\program files\DWG TrueView 2010
2009-09-09 06:13 . 2006-08-28 06:28 -------- dc-h--w- c:\program files\InstallShield Installation Information
2009-09-04 21:03 . 2005-08-16 09:18 58880 -c--a-w- c:\windows\system32\msasn1.dll
2009-09-01 05:59 . 2009-09-01 05:05 -------- dc----w- c:\program files\Common Files\LogiShrd
2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logishrd
2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logitech
2009-09-01 05:04 . 2009-09-01 01:00 -------- dc----w- c:\program files\Logitech
2009-09-01 04:06 . 2009-04-07 05:02 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-29 07:36 . 2005-08-16 09:18 832512 -c--a-w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2005-08-16 09:18 78336 -c--a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2005-08-16 09:18 17408 -c----w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2005-08-16 09:19 247326 -c--a-w- c:\windows\system32\strmdll.dll
2009-08-25 05:59 . 2006-09-22 02:21 3766 -csha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-25 05:59 . 2006-09-22 02:21 88 -csh--r- c:\windows\system32\68430E414D.sys
2009-08-07 02:24 . 2005-08-16 09:40 327896 -c--a-w- c:\windows\system32\wucltui.dll
2009-08-07 02:24 . 2005-08-16 09:40 209632 -c--a-w- c:\windows\system32\wuweb.dll
2009-08-07 02:24 . 2005-08-16 09:40 35552 -c--a-w- c:\windows\system32\wups.dll
2009-08-07 02:24 . 2005-05-26 11:16 44768 -c--a-w- c:\windows\system32\wups2.dll
2009-08-07 02:24 . 2005-08-16 09:40 53472 -c--a-w- c:\windows\system32\wuauclt.exe
2009-08-07 02:24 . 2005-08-16 09:18 96480 -c--a-w- c:\windows\system32\cdm.dll
2009-08-07 02:23 . 2005-08-16 09:40 575704 -c--a-w- c:\windows\system32\wuapi.dll
2009-08-07 02:23 . 2005-08-16 09:40 1929952 -c--a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2005-08-16 09:18 204800 -c--a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 2005-08-16 09:18 2145280 -c--a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-04 03:59 2023936 -c--a-w- c:\windows\system32\ntkrnlpa.exe
2006-12-07 01:49 . 2006-12-07 01:49 592 -c--a-w- c:\program files\Opera.lnk
2006-09-06 01:35 . 2006-09-06 01:35 1626 -c--a-w- c:\program files\QuickTime Player.lnk
2006-09-06 01:14 . 2006-09-06 01:14 841 -c--a-w- c:\program files\Ad-Aware SE Personal.lnk
2006-09-05 23:34 . 2006-09-05 23:34 1753 -c--a-w- c:\program files\Dell Printer Supplies - Inkjet.lnk
2006-09-05 23:01 . 2006-09-05 23:01 786 -c--a-w- c:\program files\Windows Media Player.lnk
2006-08-29 15:54 . 2006-08-29 15:54 1752 -c--a-w- c:\program files\main.ini
2006-08-28 06:56 . 2006-08-28 06:56 1967 -c--a-w- c:\program files\Internet Service Offers.lnk
2006-08-28 06:56 . 2006-08-28 06:56 1965 -c--a-w- c:\program files\Games, Music, & Photos.lnk
2006-08-28 06:56 . 2006-08-28 06:56 1958 -c--a-w- c:\program files\Documentation & Support.lnk
2006-08-28 06:45 . 2006-08-28 06:45 1661 -c--a-w- c:\program files\Trend Micro PC-cillin Internet Security 12.lnk
2005-08-16 09:52 . 2006-09-05 23:01 1298 -c--a-w- c:\program files\Media Center.lnk
2005-10-12 22:04 . 2005-10-12 22:04 131072 -c--a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 17:48 . 2007-02-08 17:48 133920 -c--a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-06-17 00:22 1144712 -c--a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-07 68856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-14 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-14 118784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2007-04-10 4376328]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-05 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-12-04 185896]
"Dell QuickSet"="c:\progra~1\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-10 270336]
"realteks"="c:\documents and settings\Nick Rummel\Application Data\Google\tncfc7316459.exe" [2009-07-15 0]
"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]
"lxcemon.exe"="c:\program files\Lexmark 4300 Series\lxcemon.exe" [2005-08-02 192512]
"EzPrint"="c:\program files\Lexmark 4300 Series\ezprint.exe" [2005-07-26 94208]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 488984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 774168]
"SolidWorks_CheckForUpdates"="c:\program files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe" [2009-03-20 7308584]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-25 282624]
"WD Button Manager"="WDBtnMgr.exe" - c:\windows\system32\WDBtnMgr.exe [2009-06-11 364544]

c:\documents and settings\Nick Rummel\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
WD Anywhere Backup Launcher.lnk - c:\documents and settings\Nick Rummel\Application Data\Microsoft\Installer\{B9A81070-616D-4E93-BE02-CEE651343204}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe [2008-2-13 17542]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-27 24576]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2006-3-26 257752]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= c:\windows\system32\onhelp.htm
FriendlyName= tets

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-09-03 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-09-03 18:40 352256 -c--a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Nick Rummel\\My Documents\\My Completed Downloads\\eclipse-cpp-europa-win32\\eclipse\\eclipse.exe"=
"c:\\Program Files\\Java\\jdk1.5.0_09\\jre\\bin\\java.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"=
"c:\\Program Files\\National Instruments\\Shared\\Example Finder\\1.0\\BIN\\NIExampleFinder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [9/14/2009 5:02 PM 3026]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [10/10/2006 12:53 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 11:39 AM 55024]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/16/2005 2:18 AM 14336]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [6/9/2008 2:12 PM 92296]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/18/2009 10:14 PM 102448]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 4:51 PM 4096]
S2 DellBIOS;DellBIOS;\??\c:\windows\DellBIOS.Sys --> c:\windows\DellBIOS.Sys [?]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe --> h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe [?]
S3 EraserUtilDrvI9;EraserUtilDrvI9;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [4/6/2009 10:03 PM 38496]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [8/6/2009 7:06 PM 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [8/6/2009 7:06 PM 8320]
S3 PAC207;CIF USB Camera;c:\windows\system32\drivers\PFC027.SYS [1/2/2009 1:15 PM 505984]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/27/2006 8:33 PM 116464]
S3 TBU11;Turtle Beach USB MIDI 1x1 Driver;c:\windows\system32\drivers\tbu11.sys [8/4/2007 2:26 PM 13824]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808]

--- Other Services/Drivers In Memory ---

*Deregistered* - mbr

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ilitteul
.
Contents of the 'Scheduled Tasks' folder

2009-10-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-10-26 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 20:32]

2009-10-26 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 20:32]

2009-10-28 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-06-17 00:22]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Nick Rummel\Application Data\Mozilla\Firefox\Profiles\8j7bdunq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: XUL Cache: {69718F4B-3565-4D65-B418-A321269E8B74} - c:\documents and settings\Nick Rummel\Local Settings\Application Data\{69718F4B-3565-4D65-B418-A321269E8B74}\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

BHO-{CD292324-974F-4224-B904-98B907348B5B} - c:\progra~1\NY-YAN~1.NET\Toolbar\Toolbar.dll
Toolbar-{CD292324-974F-4224-B904-98B907348B5B} - c:\progra~1\NY-YAN~1.NET\Toolbar\Toolbar.dll
WebBrowser-{CD292324-974F-4224-B904-98B907348B5B} - c:\progra~1\NY-YAN~1.NET\Toolbar\Toolbar.dll
HKU-Default-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
AddRemove-EZJava - c:\program files\ezjava\bin\ezjavauninstl.exe
AddRemove-myTunes Redux_is1 - c:\program files\myTunes Redux\unins000.exe
AddRemove-Win Police Pro - c:\program files\Windows Police Pro\AntiSpyware_Uninstall.exe
AddRemove-{B3B4E8E4-E2A4-11D6-8D31-00105A629F49} - c:\program files\eMedia Guitar Basics\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-27 18:38
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1313456098-3368236134-1419899362-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:5f,bd,1d,4e,48,20,11,db,c5,d2,3d,f5,fd,a2,c5,27,c8,7c,f3,0c,b0,8c,65,
e7,a0,af,e6,ea,11,15,15,45,ed,f1,e1,34,d6,32,85,f7,f5,d5,9c,cd,1f,a4,98,68,\
"??"=hex:47,b8,eb,31,6d,80,25,0b,86,7e,89,00,84,30,b1,12

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ }*Ć]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(948)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(652)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\IME\SPGRMR.DLL
c:\windows\system32\msi.dll
c:\progra~1\COMMON~1\Stardock\MCPCore.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKeeper.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lkcitdl.exe
c:\windows\system32\lkads.exe
c:\windows\system32\lktsrv.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\National Instruments\MAX\nimxs.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\program files\National Instruments\Shared\Security\nidmsrv.exe
c:\combo-fix\CF446.exe
c:\windows\system32\nisvcloc.exe
c:\program files\National Instruments\Shared\Tagger\tagsrv.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\fxssvc.exe
c:\windows\system32\dllhost.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\windows\system32\dlcccoms.exe
c:\windows\eHome\ehmsas.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\windows\system32\lxcecoms.exe
c:\program files\Java\jre6\bin\jucheck.exe
c:\program files\Common Files\LogiShrd\LComMgr\LVComSX.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\COMMON~1\LogiShrd\LComMgr\LVComSX.exe
c:\program files\Windows Desktop Search\WindowsSearchIndexer.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Windows Desktop Search\WindowsSearchFilter.exe
c:\combo-fix\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-28 19:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-28 02:24

Pre-Run: 3,992,514,560 bytes free
Post-Run: 4,620,140,544 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 2FBAF55F116B31951B5A26D9EADE2FFC
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 28 2009, 06:01 AM
Post #4


GeekU Teacher
Group Icon
Posts: 35,111
From: Dublin
OS: XP



hi


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
File::
c:\windows\wp4.dat
c:\windows\wp3.dat

NetSvc::
ilitteul
KillAll::


Folder::

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Go to the top of the page
 
+Quote Post
nrummel
post Oct 28 2009, 10:22 AM
Post #5


Member
**
Posts: 13
OS: Windows 2000



ComboFix 09-10-27.07 - Nick Rummel 10/28/2009 8:08.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.426 [GMT -7:00]
Running from: c:\documents and settings\Nick Rummel\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Nick Rummel\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

FILE ::
"c:\windows\wp3.dat"
"c:\windows\wp4.dat"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\wp3.dat
c:\windows\wp4.dat

Infected copy of c:\windows\system32\drivers\vaxscsi.sys was found and disinfected
Restored copy from - Kitty ate it tongue.gif
.
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 )))))))))))))))))))))))))))))))
.

2009-12-06 04:33 . 2009-12-06 04:33 -------- dc----w- c:\windows\system32\XPSViewer
2009-12-06 04:31 . 2009-12-06 04:31 -------- dc----w- c:\program files\Reference Assemblies
2009-12-06 04:29 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\xpsshhdr.dll
2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-12-06 04:29 . 2008-07-06 12:06 117760 -c----w- c:\windows\system32\prntvpt.dll
2009-12-06 04:29 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\xpssvcs.dll
2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-12-06 04:28 . 2009-08-06 03:54 -------- dc----w- c:\windows\SxsCaPendDel
2009-10-28 14:55 . 2009-10-28 14:56 -------- dc----w- C:\Combo-Fix
2009-10-26 23:34 . 2006-03-03 15:07 143360 -c--a-w- c:\windows\system32\dunzip32.dll
2009-10-26 01:59 . 2007-11-22 13:44 33832 -c--a-w- c:\windows\system32\drivers\mferkdk.sys
2009-10-26 01:59 . 2007-12-02 19:51 40488 -c--a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-10-26 01:59 . 2007-11-22 13:44 35240 -c--a-w- c:\windows\system32\drivers\mfebopk.sys
2009-10-26 01:59 . 2007-11-22 13:44 79304 -c--a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-10-26 01:59 . 2007-11-22 13:44 201320 -c--a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-26 01:59 . 2007-07-13 13:20 113952 -c--a-w- c:\windows\system32\drivers\Mpfp.sys
2009-10-26 01:57 . 2009-10-26 01:58 -------- dc----w- c:\program files\McAfee.com
2009-10-26 01:25 . 2009-10-26 01:37 -------- dc----w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\AskToolbar
2009-10-23 06:49 . 2009-10-23 06:49 -------- dc----w- c:\program files\Ask.com
2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\Common Files\DVDVideoSoft
2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\DVDVideoSoft
2009-10-21 23:40 . 2009-10-21 23:40 -------- dc----w- C:\EmergencyUtils
2009-10-15 04:30 . 2009-10-28 07:32 -------- dc--a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-04 01:12 . 2009-10-04 01:12 -------- dc----w- c:\program files\iPod
2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\program files\iTunes
2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-01 22:35 . 2009-10-01 22:35 287080 -c--a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-06 04:32 . 2008-01-11 18:01 -------- dc----w- c:\program files\MSBuild
2009-10-28 15:28 . 2009-09-09 02:26 -------- dc----w- c:\program files\Common Files\Akamai
2009-10-28 15:04 . 2008-06-09 21:11 -------- dc----w- c:\program files\McAfee
2009-10-28 06:27 . 2007-08-31 00:39 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Skype
2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\program files\Common Files\Symantec Shared
2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\program files\Symantec
2009-10-28 04:02 . 2007-03-24 18:30 -------- dc----w- c:\program files\Symantec AntiVirus
2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-28 01:46 . 2009-09-11 03:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\IM
2009-10-28 01:43 . 2008-08-08 04:17 -------- dc----w- c:\program files\Lx_cats
2009-10-28 01:39 . 2006-09-05 23:32 -------- dc----w- c:\program files\Dl_cats
2009-10-27 05:17 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-10-26 23:41 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-26 01:59 . 2008-06-09 21:12 -------- dc----w- c:\program files\Common Files\McAfee
2009-10-23 21:20 . 2007-05-17 18:06 -------- dc-h--w- c:\documents and settings\Nick Rummel\Application Data\Move Networks
2009-10-23 07:12 . 2008-02-11 02:48 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks
2009-10-16 17:37 . 2006-10-12 19:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\dvdcss
2009-10-04 01:12 . 2007-07-01 16:27 -------- dc----w- c:\program files\Common Files\Apple
2009-10-04 00:53 . 2007-12-10 02:00 -------- dc----w- c:\program files\Bonjour
2009-10-04 00:52 . 2007-07-16 02:03 -------- dc----w- c:\program files\QuickTime
2009-09-24 04:46 . 2008-05-20 03:28 -------- dc----w- c:\program files\AFT software
2009-09-24 04:46 . 2008-05-14 06:06 796672 -c--a-w- c:\windows\GPInstall.exe
2009-09-16 23:19 . 2009-09-16 23:19 -------- dc----w- c:\documents and settings\LocalService\Application Data\McAfee
2009-09-15 00:45 . 2009-09-15 00:40 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks 2009
2009-09-15 00:02 . 2009-09-15 00:02 3026 -c--a-w- c:\windows\system32\drivers\hwinterface.sys
2009-09-15 00:02 . 2006-09-05 23:14 152872 -c--a-w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 14:18 . 2005-08-16 09:18 136192 -c--a-w- c:\windows\system32\msv1_0.dll
2009-09-11 06:09 . 2008-01-11 17:48 -------- dc----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-11 06:05 . 2008-02-11 02:18 -------- dc----w- c:\program files\Common Files\SolidWorks Shared
2009-09-11 05:59 . 2009-09-11 05:58 -------- dc----w- c:\program files\AGEIA Technologies
2009-09-11 05:58 . 2009-02-25 01:24 -------- dc----w- c:\documents and settings\All Users\Application Data\SolidWorks
2009-09-11 05:52 . 2009-09-11 05:52 -------- dc----w- c:\program files\MSECache
2009-09-11 05:48 . 2009-09-11 05:47 -------- dc----w- c:\program files\Microsoft Visual Studio 8
2009-09-11 03:26 . 2009-09-11 03:25 -------- dc----w- c:\program files\Common Files\SolidWorks Installation Manager
2009-09-10 07:25 . 2008-01-18 06:30 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Autodesk
2009-09-10 07:23 . 2009-09-09 06:24 -------- dc----w- c:\documents and settings\All Users\Application Data\Autodesk
2009-09-09 06:40 . 2009-09-09 06:18 -------- dc----w- c:\program files\Autodesk
2009-09-09 06:38 . 2008-01-18 06:25 -------- dc----w- c:\program files\Common Files\Autodesk Shared
2009-09-09 06:25 . 2009-09-09 06:24 -------- dc----w- c:\program files\DWG TrueView 2010
2009-09-09 06:13 . 2006-08-28 06:28 -------- dc-h--w- c:\program files\InstallShield Installation Information
2009-09-04 21:03 . 2005-08-16 09:18 58880 -c--a-w- c:\windows\system32\msasn1.dll
2009-09-01 05:59 . 2009-09-01 05:05 -------- dc----w- c:\program files\Common Files\LogiShrd
2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logishrd
2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logitech
2009-09-01 05:04 . 2009-09-01 01:00 -------- dc----w- c:\program files\Logitech
2009-09-01 04:06 . 2009-04-07 05:02 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-29 07:36 . 2005-08-16 09:18 832512 -c--a-w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2005-08-16 09:18 78336 -c--a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2005-08-16 09:18 17408 -c----w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2005-08-16 09:19 247326 -c--a-w- c:\windows\system32\strmdll.dll
2009-08-25 05:59 . 2006-09-22 02:21 3766 -csha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-25 05:59 . 2006-09-22 02:21 88 -csh--r- c:\windows\system32\68430E414D.sys
2009-08-07 02:24 . 2005-08-16 09:40 327896 -c--a-w- c:\windows\system32\wucltui.dll
2009-08-07 02:24 . 2005-08-16 09:40 209632 -c--a-w- c:\windows\system32\wuweb.dll
2009-08-07 02:24 . 2005-08-16 09:40 35552 -c--a-w- c:\windows\system32\wups.dll
2009-08-07 02:24 . 2005-05-26 11:16 44768 -c--a-w- c:\windows\system32\wups2.dll
2009-08-07 02:24 . 2005-08-16 09:40 53472 -c--a-w- c:\windows\system32\wuauclt.exe
2009-08-07 02:24 . 2005-08-16 09:18 96480 -c--a-w- c:\windows\system32\cdm.dll
2009-08-07 02:23 . 2005-08-16 09:40 575704 -c--a-w- c:\windows\system32\wuapi.dll
2009-08-07 02:23 . 2005-08-16 09:40 1929952 -c--a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2005-08-16 09:18 204800 -c--a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 2005-08-16 09:18 2145280 -c--a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-04 03:59 2023936 -c--a-w- c:\windows\system32\ntkrnlpa.exe
2006-12-07 01:49 . 2006-12-07 01:49 592 -c--a-w- c:\program files\Opera.lnk
2006-09-06 01:35 . 2006-09-06 01:35 1626 -c--a-w- c:\program files\QuickTime Player.lnk
2006-09-06 01:14 . 2006-09-06 01:14 841 -c--a-w- c:\program files\Ad-Aware SE Personal.lnk
2006-09-05 23:34 . 2006-09-05 23:34 1753 -c--a-w- c:\program files\Dell Printer Supplies - Inkjet.lnk
2006-09-05 23:01 . 2006-09-05 23:01 786 -c--a-w- c:\program files\Windows Media Player.lnk
2006-08-29 15:54 . 2006-08-29 15:54 1752 -c--a-w- c:\program files\main.ini
2006-08-28 06:56 . 2006-08-28 06:56 1967 -c--a-w- c:\program files\Internet Service Offers.lnk
2006-08-28 06:56 . 2006-08-28 06:56 1965 -c--a-w- c:\program files\Games, Music, & Photos.lnk
2006-08-28 06:56 . 2006-08-28 06:56 1958 -c--a-w- c:\program files\Documentation & Support.lnk
2006-08-28 06:45 . 2006-08-28 06:45 1661 -c--a-w- c:\program files\Trend Micro PC-cillin Internet Security 12.lnk
2005-08-16 09:52 . 2006-09-05 23:01 1298 -c--a-w- c:\program files\Media Center.lnk
2005-10-12 22:04 . 2005-10-12 22:04 131072 -c--a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 17:48 . 2007-02-08 17:48 133920 -c--a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-10-28_01.43.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-28 15:27 . 2009-10-28 15:27 16384 c:\windows\Temp\Perflib_Perfdata_8d0.dat
+ 2009-10-28 15:27 . 2009-10-28 15:27 16384 c:\windows\Temp\Perflib_Perfdata_724.dat
+ 2006-09-05 22:48 . 2009-10-28 14:49 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-09-05 22:48 . 2009-10-27 18:58 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-28 04:26 . 2009-10-28 14:49 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2006-09-05 22:48 . 2009-10-27 18:58 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-06-17 00:22 1144712 -c--a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-07 68856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-14 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-14 118784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2007-04-10 4376328]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-05 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-12-04 185896]
"Dell QuickSet"="c:\progra~1\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-10 270336]
"realteks"="c:\documents and settings\Nick Rummel\Application Data\Google\tncfc7316459.exe" [2009-07-15 0]
"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]
"lxcemon.exe"="c:\program files\Lexmark 4300 Series\lxcemon.exe" [2005-08-02 192512]
"EzPrint"="c:\program files\Lexmark 4300 Series\ezprint.exe" [2005-07-26 94208]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 488984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 774168]
"SolidWorks_CheckForUpdates"="c:\program files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe" [2009-03-20 7308584]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-25 282624]
"WD Button Manager"="WDBtnMgr.exe" - c:\windows\system32\WDBtnMgr.exe [2009-06-11 364544]

c:\documents and settings\Nick Rummel\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
WD Anywhere Backup Launcher.lnk - c:\documents and settings\Nick Rummel\Application Data\Microsoft\Installer\{B9A81070-616D-4E93-BE02-CEE651343204}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe [2008-2-13 17542]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-27 24576]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2006-3-26 257752]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= c:\windows\system32\onhelp.htm
FriendlyName= tets

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-09-03 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-09-03 18:40 352256 -c--a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Nick Rummel\\My Documents\\My Completed Downloads\\eclipse-cpp-europa-win32\\eclipse\\eclipse.exe"=
"c:\\Program Files\\Java\\jdk1.5.0_09\\jre\\bin\\java.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"=
"c:\\Program Files\\National Instruments\\Shared\\Example Finder\\1.0\\BIN\\NIExampleFinder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [9/14/2009 5:02 PM 3026]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [10/10/2006 12:53 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 11:39 AM 55024]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/16/2005 2:18 AM 14336]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [6/9/2008 2:12 PM 92296]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 4:51 PM 4096]
S2 DellBIOS;DellBIOS;\??\c:\windows\DellBIOS.Sys --> c:\windows\DellBIOS.Sys [?]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe --> h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe [?]
S3 EraserUtilDrvI9;EraserUtilDrvI9;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [4/6/2009 10:03 PM 38496]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [8/6/2009 7:06 PM 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [8/6/2009 7:06 PM 8320]
S3 PAC207;CIF USB Camera;c:\windows\system32\drivers\PFC027.SYS [1/2/2009 1:15 PM 505984]
S3 TBU11;Turtle Beach USB MIDI 1x1 Driver;c:\windows\system32\drivers\tbu11.sys [8/4/2007 2:26 PM 13824]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808]

--- Other Services/Drivers In Memory ---

*Deregistered* - mbr

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder

2009-10-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-10-26 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 20:32]

2009-10-26 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 20:32]

2009-10-28 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-06-17 00:22]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Nick Rummel\Application Data\Mozilla\Firefox\Profiles\8j7bdunq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: XUL Cache: {69718F4B-3565-4D65-B418-A321269E8B74} - c:\documents and settings\Nick Rummel\Local Settings\Application Data\{69718F4B-3565-4D65-B418-A321269E8B74}\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

Notify-NavLogon - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-28 08:30
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spmo.sys >>UNKNOWN [0x87386938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

atapi.sys @ 0x0 0x0 bytes

\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF7351B40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF7351B40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF7351B40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF7351B40 atapi.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xF7351B40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF7351B40 atapi.sys
\Driver\atapi IRP hooks detected !

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1313456098-3368236134-1419899362-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:5f,bd,1d,4e,48,20,11,db,c5,d2,3d,f5,fd,a2,c5,27,c8,7c,f3,0c,b0,8c,65,
e7,a0,af,e6,ea,11,15,15,45,ed,f1,e1,34,d6,32,85,f7,f5,d5,9c,cd,1f,a4,98,68,\
"??"=hex:47,b8,eb,31,6d,80,25,0b,86,7e,89,00,84,30,b1,12

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ }*Ć]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(928)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(684)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\progra~1\COMMON~1\Stardock\MCPCore.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\IME\SPGRMR.DLL
c:\windows\system32\msi.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKeeper.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lkcitdl.exe
c:\windows\system32\lkads.exe
c:\windows\system32\lktsrv.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\National Instruments\MAX\nimxs.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\program files\National Instruments\Shared\Security\nidmsrv.exe
c:\windows\system32\nisvcloc.exe
c:\program files\National Instruments\Shared\Tagger\tagsrv.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\combo-fix32337c\CF7410.exe
c:\progra~1\mcafee\msc\mcuimgr.exe
c:\windows\eHome\ehmsas.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\windows\system32\dlcccoms.exe
c:\windows\system32\lxcecoms.exe
c:\program files\Windows Desktop Search\WindowsSearchIndexer.exe
c:\program files\Common Files\LogiShrd\LComMgr\LVComSX.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\combo-fix32337c\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-28 8:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-28 15:49
ComboFix2.txt 2009-10-28 02:25

Pre-Run: 4,682,420,224 bytes free
Post-Run: 4,666,454,016 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - F95482F0853CF5FAAC3F0CE4B586DF7A
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 28 2009, 11:37 AM
Post #6


GeekU Teacher
Group Icon
Posts: 35,111
From: Dublin
OS: XP



hi

Please download OTM
  • Save it to your desktop.
  • Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    CODE
    :Processes

    :Services

    :Reg
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\drivers\\svchost.exe"=-

    :Files

    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM and reboot your PC.

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised by a trained Security Analyst

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is Unchecked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.



Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %SYSTEMDRIVE%\*.exe
    %SYSTEMDRIVE%\eventlog.dll /s /md5
    %SYSTEMDRIVE%\scecli.dll /s /md5
    %SYSTEMDRIVE%\netlogon.dll /s /md5
    %SYSTEMDRIVE%\cngaudit.dll /s /md5
    %SYSTEMDRIVE%\sceclt.dll /s /md5
    %SYSTEMDRIVE%\ntelogon.dll /s /md5
    %SYSTEMDRIVE%\logevent.dll /s /md5
    %SYSTEMDRIVE%\iaStor.sys /s /md5
    %SYSTEMDRIVE%\nvstor.sys /s /md5
    %SYSTEMDRIVE%\atapi.sys /s /md5
    %SYSTEMDRIVE%\IdeChnDr.sys /s /md5
    %SYSTEMDRIVE%\viasraid.sys /s /md5
    %SYSTEMDRIVE%\AGP440.sys /s /md5
    %SYSTEMDRIVE%\vaxscsi.sys /s /md5


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time

Go to the top of the page
 
+Quote Post
nrummel
post Oct 28 2009, 04:57 PM
Post #7


Member
**
Posts: 13
OS: Windows 2000



All processes killed
========== PROCESSES ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List not found.
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 390354 bytes
->FireFox cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes

User: Nick Rummel
->Temp folder emptied: 308607 bytes
File delete failed. C:\Documents and Settings\Nick Rummel\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 7627069 bytes
->Java cache emptied: 58142092 bytes
->FireFox cache emptied: 60803493 bytes
->Google Chrome cache emptied: 594288 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 5221905 bytes
Windows Temp folder emptied: 664 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 127.00 mb


OTM by OldTimer - Version 3.0.0.6 log created on 10282009_154208

Files moved on Reboot...

Registry entries deleted on Reboot...
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 28 2009, 06:12 PM
Post #8


GeekU Teacher
Group Icon
Posts: 35,111
From: Dublin
OS: XP



the other logs too
Go to the top of the page
 
+Quote Post
nrummel
post Oct 29 2009, 09:21 AM
Post #9


Member
**
Posts: 13
OS: Windows 2000



I've ran gmer.exe twice now, and both times, after a couple of hours, my comp freezes and I can't do anything.
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 29 2009, 09:27 AM
Post #10


GeekU Teacher
Group Icon
Posts: 35,111
From: Dublin
OS: XP



how about OTL
Go to the top of the page
 
+Quote Post
nrummel
post Oct 29 2009, 04:56 PM
Post #11


Member
**
Posts: 13
OS: Windows 2000



OTL logfile created on: 10/29/2009 8:50:57 AM - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Documents and Settings\Nick Rummel\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.37 Mb Total Physical Memory | 332.24 Mb Available Physical Memory | 32.75% Memory free
2.38 Gb Paging File | 1.46 Gb Available in Paging File | 61.19% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 4.27 Gb Free Space | 11.47% Space Free | Partition Type: NTFS
Drive D: | 12.27 Gb Total Space | 12.03 Gb Free Space | 98.03% Space Free | Partition Type: NTFS
Drive E: | 82.04 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NRUMMEL
Current User Name: Nick Rummel
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2009/10/29 08:50:28 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTL.exe
PRC - [2009/09/21 16:36:12 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/09/16 14:48:40 | 00,092,296 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2009/09/05 01:54:42 | 00,417,792 | ---- | M] (Apple Inc.) -- C:\Program Files\QuickTime\QTTask.exe
PRC - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/08/26 22:18:44 | 00,634,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\internet explorer\iexplore.exe
PRC - [2009/08/04 06:26:44 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/06/10 23:43:26 | 00,364,544 | ---- | M] (Western Digital Technologies, Inc.) -- C:\WINDOWS\System32\WDBtnMgr.exe
PRC - [2009/06/04 21:58:37 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/06/04 21:58:08 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/05/21 10:55:32 | 00,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/03/19 19:30:12 | 07,308,584 | ---- | M] (Dassault Systčmes SolidWorks Corp.) -- C:\Program Files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe
PRC - [2009/02/06 03:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/08/13 18:32:40 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/08/08 05:11:12 | 00,490,952 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\daemon.exe
PRC - [2008/06/14 10:41:54 | 00,781,288 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\MSC\mcupdmgr.exe
PRC - [2008/04/13 17:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe
PRC - [2008/04/13 17:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008/04/06 21:43:14 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/01/25 01:38:12 | 02,458,128 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2008/01/09 16:50:22 | 00,767,976 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2007/12/11 12:33:42 | 00,358,224 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2007/12/05 10:04:10 | 00,695,624 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe
PRC - [2007/11/26 10:46:14 | 00,023,880 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSK\MskSrver.exe
PRC - [2007/11/13 13:16:26 | 00,359,248 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\MSC\mcupdui.exe
PRC - [2007/11/01 23:32:00 | 00,866,640 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\MSC\mcshell.exe
PRC - [2007/11/01 19:12:38 | 00,582,992 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2007/11/01 19:12:38 | 00,265,040 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\MSC\mcuimgr.exe
PRC - [2007/07/24 12:02:14 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe
PRC - [2007/07/18 15:54:42 | 00,856,864 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MPFSrv.exe
PRC - [2007/03/15 11:09:36 | 00,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2007/03/10 13:43:52 | 00,270,336 | ---- | M] () -- C:\WINDOWS\tsnpstd3.exe
PRC - [2007/02/22 08:46:24 | 00,012,696 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\MAX\nimxs.exe
PRC - [2007/02/21 17:15:52 | 00,056,096 | ---- | M] (National Instruments Corp.) -- C:\WINDOWS\System32\nisvcloc.exe
PRC - [2007/02/14 22:54:06 | 00,207,648 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
PRC - [2007/02/14 22:49:16 | 00,064,288 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lktsrv.exe
PRC - [2007/02/14 22:48:56 | 00,056,096 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lkads.exe
PRC - [2007/02/08 01:13:48 | 00,774,168 | ---- | M] () -- C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
PRC - [2007/02/08 01:12:48 | 00,488,984 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2007/02/08 01:12:20 | 00,230,936 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
PRC - [2007/02/06 22:47:46 | 00,703,264 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
PRC - [2007/02/06 17:43:26 | 00,252,704 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
PRC - [2007/01/22 11:38:44 | 00,695,136 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lkcitdl.exe
PRC - [2006/12/03 21:41:37 | 00,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2006/11/03 09:01:16 | 00,319,488 | ---- | M] (PixArt Imaging Incorporation) -- C:\WINDOWS\PixArt\PAC207\Monitor.exe
PRC - [2006/10/27 00:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2006/10/09 17:16:56 | 00,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRecvr.exe
PRC - [2006/09/19 08:07:28 | 00,827,392 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe
PRC - [2006/05/01 07:34:00 | 00,262,217 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
PRC - [2006/05/01 07:28:26 | 00,602,182 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
PRC - [2006/05/01 07:28:06 | 00,667,718 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
PRC - [2006/05/01 07:26:14 | 00,397,381 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2006/05/01 07:22:42 | 00,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2006/05/01 07:20:52 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2006/05/01 07:20:26 | 00,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2006/04/06 12:58:52 | 01,032,192 | ---- | M] (Dell Inc) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2006/04/06 12:57:54 | 00,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
PRC - [2006/03/26 23:44:08 | 00,257,752 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2006/03/26 23:44:08 | 00,221,400 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
PRC - [2006/03/26 23:44:06 | 00,159,960 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
PRC - [2006/03/24 21:30:44 | 00,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2006/03/20 18:34:50 | 00,213,936 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
PRC - [2006/03/08 16:48:02 | 00,761,947 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2005/12/13 21:45:00 | 00,118,784 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxpers.exe
PRC - [2005/12/13 21:41:08 | 00,077,824 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\hkcmd.exe
PRC - [2005/12/09 18:29:52 | 00,049,152 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
PRC - [2005/10/27 21:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\System32\dlcccoms.exe
PRC - [2005/10/21 00:40:26 | 00,430,080 | ---- | M] (Dell) -- C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
PRC - [2005/09/29 12:01:14 | 00,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehtray.exe
PRC - [2005/08/05 11:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehSched.exe
PRC - [2005/08/05 11:56:28 | 00,046,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehmsas.exe
PRC - [2005/08/05 11:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe
PRC - [2005/08/02 10:45:16 | 00,192,512 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark 4300 Series\lxcemon.exe
PRC - [2005/07/26 05:17:18 | 00,094,208 | ---- | M] (Lexmark International Inc.) -- C:\Program Files\Lexmark 4300 Series\ezprint.exe
PRC - [2005/07/06 03:14:12 | 00,471,040 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\lxcecoms.exe
PRC - [2005/05/03 22:04:28 | 09,150,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
PRC - [2005/05/03 20:07:32 | 00,081,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
PRC - [2005/04/01 10:51:48 | 00,217,600 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
PRC - [2004/12/05 23:05:00 | 00,127,035 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfswctrl.exe
PRC - [2003/10/29 00:06:00 | 00,024,576 | ---- | M] (BVRP Software) -- C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2003/09/10 00:24:00 | 00,020,480 | ---- | M] () -- C:\Program Files\NetWaiting\netWaiting.exe
PRC - [2003/06/19 21:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2002/06/18 14:04:54 | 00,503,808 | ---- | M] () -- C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
PRC - [2002/06/18 03:37:22 | 01,515,566 | ---- | M] (The MathWorks Inc.) -- c:\matlab6p5\bin\win32\matlab.exe

========== Win32 Services (SafeList) ==========

SRV - File not found -- -- (CoordinatorServiceHost [On_Demand | Stopped])
SRV - [2009/10/26 17:20:13 | 02,309,520 | ---- | M] () -- c:\program files\common files\akamai\rswin_3600.dll -- (Akamai [Auto | Running])
SRV - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009/09/16 14:48:40 | 00,092,296 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service [Auto | Running])
SRV - [2009/09/10 23:08:41 | 00,079,360 | ---- | M] (SolidWorks) -- C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service [On_Demand | Stopped])
SRV - [2009/09/08 23:40:01 | 00,651,720 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2009/07/09 23:52:28 | 00,316,312 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\Temp\0164771256828787mcinst.exe -- (0164771256828787mcinstcleanup [Auto | Stopped])
SRV - [2009/06/04 21:58:08 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2009/06/02 23:29:36 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/08/13 18:32:40 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter [Auto | Running])
SRV - [2008/07/29 22:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/07/25 12:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/25 12:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/04/13 17:12:35 | 00,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\skeys.exe -- (SerialKeys [On_Demand | Stopped])
SRV - [2008/04/13 17:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008/01/25 01:38:12 | 02,458,128 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc [Auto | Running])
SRV - [2008/01/17 23:49:20 | 00,079,360 | ---- | M] (Autodesk) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service [On_Demand | Stopped])
SRV - [2008/01/09 16:50:22 | 00,767,976 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc [Auto | Running])
SRV - [2007/12/11 12:33:42 | 00,358,224 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy [Auto | Running])
SRV - [2007/12/05 10:04:10 | 00,695,624 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon [On_Demand | Running])
SRV - [2007/11/26 10:46:14 | 00,023,880 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSK\MskSrver.exe -- (MSK80Service [Auto | Running])
SRV - [2007/11/07 09:35:40 | 00,378,184 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS [On_Demand | Stopped])
SRV - [2007/07/24 12:02:14 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield [Unknown | Running])
SRV - [2007/07/18 15:54:42 | 00,856,864 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService [Auto | Running])
SRV - [2007/03/07 15:47:46 | 00,076,848 | ---- | M] () -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService [On_Demand | Stopped])
SRV - [2007/02/22 08:46:24 | 00,012,696 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\MAX\nimxs.exe -- (mxssvr [Auto | Running])
SRV - [2007/02/21 17:15:52 | 00,056,096 | ---- | M] (National Instruments Corp.) -- C:\WINDOWS\System32\nisvcloc.exe -- (niSvcLoc [Auto | Running])
SRV - [2007/02/14 22:54:06 | 00,207,648 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService [Auto | Running])
SRV - [2007/02/14 22:49:16 | 00,064,288 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lktsrv.exe -- (lkTimeSync [Auto | Running])
SRV - [2007/02/14 22:48:56 | 00,056,096 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lkads.exe -- (lkClassAds [Auto | Running])
SRV - [2007/02/06 22:47:46 | 00,703,264 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe -- (NITaggerService [Auto | Running])
SRV - [2007/01/29 15:19:48 | 01,007,616 | ---- | M] (Macrovision Corporation) -- C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe -- (NILM License Manager [On_Demand | Stopped])
SRV - [2007/01/22 11:38:44 | 00,695,136 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lkcitdl.exe -- (LkCitadelServer [Auto | Running])
SRV - [2006/10/27 00:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2006/10/26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006/10/18 21:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2006/10/09 17:16:56 | 00,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRecvr.exe -- (ehRecvr [Auto | Running])
SRV - [2006/09/02 16:36:33 | 02,528,960 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE -- (LiveUpdate [On_Demand | Stopped])
SRV - [2006/05/01 07:34:00 | 00,262,217 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe -- (WLANKEEPER [Auto | Running])
SRV - [2006/05/01 07:22:42 | 00,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor [Auto | Running])
SRV - [2006/05/01 07:20:52 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng [Auto | Running])
SRV - [2006/05/01 07:20:26 | 00,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc [Auto | Running])
SRV - [2006/04/06 12:57:54 | 00,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe -- (NICCONFIGSVC [Auto | Running])
SRV - [2005/10/27 21:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\System32\dlcccoms.exe -- (dlcc_device [On_Demand | Running])
SRV - [2005/09/23 07:01:16 | 02,799,808 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon80 [Disabled | Stopped])
SRV - [2005/08/05 11:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehSched.exe -- (ehSched [Auto | Running])
SRV - [2005/08/05 11:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe -- (McrdSvc [Auto | Running])
SRV - [2005/07/06 03:14:12 | 00,471,040 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\lxcecoms.exe -- (lxce_device [On_Demand | Running])
SRV - [2005/05/03 22:04:28 | 09,150,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe -- (MSSQL$MICROSOFTSMLBIZ [Auto | Running])
SRV - [2005/05/03 20:50:28 | 00,073,728 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe -- (MSSQLServerADHelper [On_Demand | Stopped])
SRV - [2005/05/03 19:42:56 | 00,323,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE -- (SQLAgent$MICROSOFTSMLBIZ [On_Demand | Stopped])
SRV - [2005/04/01 10:51:48 | 00,217,600 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe -- (StarWindService [Auto | Running])
SRV - [2004/12/02 08:28:32 | 00,098,304 | ---- | M] (OPC Foundation) -- C:\WINDOWS\System32\OpcEnum.exe -- (OpcEnum [On_Demand | Stopped])
SRV - [2004/10/22 03:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2004/08/10 02:11:50 | 00,085,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mhn.dll -- (MHN [On_Demand | Stopped])
SRV - [2003/06/19 21:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
SRV - [2002/06/18 14:04:54 | 00,503,808 | ---- | M] () -- C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe -- (matlabserver [Auto | Running])

========== Modules (SafeList) ==========

MOD - [2009/10/29 08:50:28 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTL.exe
MOD - [2009/10/06 11:42:48 | 00,014,544 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2008/04/13 17:12:51 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
MOD - [2008/04/13 17:12:00 | 00,025,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mslbui.dll
MOD - [2006/04/06 12:59:08 | 00,073,728 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
MOD - [2005/12/13 21:39:58 | 00,073,728 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\hccutils.DLL

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.msn.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.0.6
FF - prefs.js..extensions.enabledItems: multipletab@piro.sakura.ne.jp:0.4.2009073101
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.3.1
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.1.07282009_url_fix
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.6.15
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.6
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.2.20080717
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.2.1
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0
FF - prefs.js..extensions.enabledItems: {69718F4B-3565-4D65-B418-A321269E8B74}:1.0
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:7
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - prefs.js..extensions.enabledItems: {3fb63340-652a-11dd-ad8b-0800200c9a66}:2.1
FF - prefs.js..extensions.enabledItems: {47d1d620-5e5b-11da-8cd6-0800200c9a66}:2.0
FF - prefs.js..extensions.enabledItems: {7779C76B-0B5B-42be-BDDD-114CDDEC6A73}:1.0
FF - prefs.js..extensions.enabledItems: {961408A3-C970-4577-970A-D97C29839A67}:1.3.0


FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2009/10/27 17:23:35 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{69718F4B-3565-4D65-B418-A321269E8B74}: C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\{69718F4B-3565-4D65-B418-A321269E8B74}\ [2009/04/02 13:17:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/06/04 21:58:10 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 03:01:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/28 21:59:35 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/28 21:59:45 | 00,000,000 | ---D | M]

[2008/09/21 11:18:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Extensions
[2008/09/21 11:18:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/10/23 14:51:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions
[2009/09/02 17:07:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/12/10 00:40:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/10/21 23:58:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{3fb63340-652a-11dd-ad8b-0800200c9a66}
[2009/10/22 00:04:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
[2009/10/21 22:56:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2009/10/21 23:46:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{47d1d620-5e5b-11da-8cd6-0800200c9a66}
[2009/06/04 22:00:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/10/22 00:35:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{7779C76B-0B5B-42be-BDDD-114CDDEC6A73}
[2009/10/22 00:31:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{961408A3-C970-4577-970A-D97C29839A67}
[2009/10/21 22:56:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/10/22 00:04:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2009/10/21 22:56:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\elemhidehelper@adblockplus.org
[2009/10/21 22:48:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\multipletab@piro.sakura.ne.jp
[2009/10/21 22:56:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\personas@christopher.beard
[2009/10/21 22:56:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\SkipScreen@SkipScreen
[2009/10/22 00:35:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\staged-xpis
[2009/04/05 09:21:31 | 00,001,739 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Application Data\Mozilla\FireFox\Profiles\8j7bdunq.default\searchplugins\aim-search.xml
[2008/02/22 19:42:27 | 00,001,877 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Application Data\Mozilla\FireFox\Profiles\8j7bdunq.default\searchplugins\aolsearch.xml
[2009/02/24 17:42:01 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Application Data\Mozilla\FireFox\Profiles\8j7bdunq.default\searchplugins\daemon-search.xml
[2007/10/15 19:41:06 | 00,002,386 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Application Data\Mozilla\FireFox\Profiles\8j7bdunq.default\searchplugins\siteadvisor.xml
[2009/10/26 22:20:30 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2006/09/05 18:41:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/08/04 06:26:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/08/30 17:38:57 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2007/04/15 01:37:09 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2007/08/18 18:14:54 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2007/10/29 22:21:11 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/08/21 11:15:30 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/08/04 06:26:42 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/04 06:26:43 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2006/07/28 08:32:54 | 00,049,152 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2009/06/04 21:56:37 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2007/04/22 17:02:18 | 00,717,312 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2008/09/26 09:40:34 | 00,053,248 | ---- | M] (AOL LLC) -- C:\Program Files\mozilla firefox\plugins\npdnu.dll
[2009/03/12 15:16:54 | 00,155,648 | ---- | M] (Dassault Systčmes SolidWorks Corp.) -- C:\Program Files\mozilla firefox\plugins\npEModelPlugin.dll
[2006/10/30 12:47:52 | 01,380,656 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2005/10/12 15:04:02 | 00,020,480 | ---- | M] (National Instruments) -- C:\Program Files\mozilla firefox\plugins\NPLV80Win32.dll
[2007/02/08 10:48:16 | 00,028,448 | ---- | M] (National Instruments) -- C:\Program Files\mozilla firefox\plugins\NPLV82Win32.dll
[2006/11/21 10:43:42 | 00,114,688 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npmozax.dll
[2007/07/29 09:02:09 | 00,284,248 | ---- | M] (Musicnotes, Inc.) -- C:\Program Files\mozilla firefox\plugins\npmusicn.dll
[2009/08/04 06:26:48 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2003/07/14 20:56:52 | 00,013,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2006/12/18 04:18:30 | 00,077,824 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/12/03 21:41:52 | 00,144,984 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2009/10/28 21:59:42 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/10/28 21:59:43 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/10/28 21:59:43 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/10/28 21:59:43 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/10/28 21:59:44 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/10/28 21:59:44 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/10/28 21:59:45 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2006/12/03 21:42:01 | 00,024,576 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2006/12/03 21:41:45 | 00,081,920 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2007/11/01 20:59:39 | 04,100,096 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npsibelius.dll
[2005/08/09 11:42:53 | 00,057,344 | ---- | M] (America Online, Inc.) -- C:\Program Files\mozilla firefox\plugins\npunagi2.dll
[2007/03/09 16:16:44 | 00,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
[2009/03/26 11:56:22 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/26 11:56:22 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/26 11:56:22 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/26 11:56:22 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/26 11:56:22 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/26 11:56:22 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/26 11:56:22 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (dsWebAllowBHO Class) - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll (Microsoft Corporation)
O2 - BHO: (McAfee Phishing Filter) - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\Program Files\McAfee\MSK\mcapbho.dll ()
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (CleanMyPCPopupBlocker Class) - {7A9BC6B1-7F27-47c6-A66D-13582E81E537} - C:\Program Files\CleanMyPC Popup Blocker\CleanBHO.dll (CleanMyPC Software)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (CleanMyPC Toolbar) - {04164EC4-1E48-4279-818E-3721931E7636} - C:\Program Files\CleanMyPC Popup Blocker\CleanBar.dll (CleanMyPC Software)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\System32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [DLCCCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.DLL ()
O4 - HKLM..\Run: [dlccmon.exe] C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [DVDLauncher] C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 4300 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files\Lexmark Fax Solutions\fm3032.exe ()
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam10\QuickCam10.exe ()
O4 - HKLM..\Run: [LXCECATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.DLL ()
O4 - HKLM..\Run: [lxcemon.exe] C:\Program Files\Lexmark 4300 Series\lxcemon.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [realteks] C:\Documents and Settings\Nick Rummel\Application Data\Google\tncfc7316459.exe ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()
O4 - HKLM..\Run: [SolidWorks_CheckForUpdates] C:\Program Files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe (Dassault Systčmes SolidWorks Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe ()
O4 - HKLM..\Run: [WD Button Manager] C:\WINDOWS\System32\WDBtnMgr.exe (Western Digital Technologies, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe ()
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Nick Rummel\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Nick Rummel\Start Menu\Programs\Startup\WD Anywhere Backup Launcher.lnk = C:\Documents and Settings\Nick Rummel\Application Data\Microsoft\Installer\{B9A81070-616D-4E93-BE02-CEE651343204}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab (StagingUI Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file://C:\Program Files\Chessmaster Challenge\Images\stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab (ZoneBuddy Class)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab (ZonePAChat Object)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo...toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} http://zone.msn.com/bingame/zpagames/zpa_txhe.cab50108.cab (ZPA_TexasHoldem Object)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file://C:\Program Files\Chessmaster Challenge\Images\armhelper.ocx (ArmHelper Control)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab41227.cab (StadiumProxy Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.94.156.1 68.94.157.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\Program Files\Common Files\Stardock\MCPCore.dll (Stardock)
O24 - Desktop Components:0 (tets) - C:\WINDOWS\system32\onhelp.htm
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 02:43:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/02/14 12:27:46 | 00,000,000 | ---D | M] - D:\autorun -- [ NTFS ]
O32 - AutoRun File - [2006/12/15 13:32:12 | 00,000,047 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{1a517000-d909-11dc-8eee-0015c5a935eb}\Shell\AutoRun\command - "" = H:\wd_windows_tools\WDEULA.exe -- File not found
O33 - MountPoints2\{4669c37e-c3dd-11de-8fa7-0015c5a935eb}\Shell - "" = AutoRun
O33 - MountPoints2\{4669c37e-c3dd-11de-8fa7-0015c5a935eb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4669c37e-c3dd-11de-8fa7-0015c5a935eb}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: MHN - C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)


SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootMin: mcmscsvc - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SafeBootMin: MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootNet: mcmscsvc - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SafeBootNet: MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SafeBootNet: MpfService - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error.
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {1BC46932-21B2-4130-86E0-B4EB4F7A7A7B} - Microsoft .NET Framework 1.0 Hotfix (KB887998)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 10.1.3
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 10.1.3
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error.
ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error.
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {407408d4-94ed-4d86-ab69-a7f649d112ee} - %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection QuickLaunchShortcut 640 %systemroot%\inf\mcdftreg.inf
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {75AE7B1B-AA9C-C4FE-93D3-454016F08DA4} - Vector Graphics Rendering (VML)
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {88D28416-AE72-24C6-D586-3A1757EB53C4} - Microsoft .NET Framework 1.0 Hotfix (KB887998)
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {BDE0FA43-6952-4BA8-8C58-09AF690F88E1} - Microsoft .NET Framework 1.0 Hotfix (KB930494)
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CD13081A-6FF9-21B7-6133-A4CAECD56D8C} - Browser Customizations
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297)
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E8BB293C-33AB-AD4A-8F4C-861EC8B07069} - Browser Customizations
ActiveX: {E8EA5BD6-D931-4001-ABF6-81BAA500360A} - Microsoft .NET Framework 1.0 Hotfix (KB953295)
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EA29D410-CE41-4953-A862-2DE706A1DAD7} - Microsoft .NET Framework 1.0 Service Pack 3
ActiveX: {FDC11A6F-17D1-48f9-9EA3-9051954BAA24} - .NET Framework
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: KB910393 - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\EasyCDBlock.inf,PerUserInstall

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

========== Files/Folders - Created Within 14 Days ==========

[2009/10/25 18:25:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\AskToolbar
[2009/10/22 23:48:09 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft
[2009/10/22 23:49:15 | 00,000,000 | ---D | C] -- C:\Program Files\Ask.com
[2009/10/22 23:48:08 | 00,000,000 | ---D | C] -- C:\Program Files\DVDVideoSoft
[2009/10/25 18:57:29 | 00,000,000 | ---D | C] -- C:\Program Files\McAfee.com
[2009/12/05 21:31:43 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/10/29 08:20:21 | 00,000,000 | ---D | C] -- C:\Program Files\SiteAdvisor
[2009/12/05 21:33:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/12/05 21:28:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
[2009/10/29 08:50:28 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTL.exe
[2009/10/29 08:06:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2009/10/28 15:42:08 | 00,000,000 | ---D | C] -- C:\_OTM
[2009/10/28 15:40:45 | 00,408,064 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTM.exe
[2009/10/28 07:55:39 | 00,000,000 | ---D | C] -- C:\Combo-Fix
[2009/10/27 17:05:57 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/10/27 16:48:36 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/10/27 16:48:34 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/10/27 16:48:33 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/10/27 16:48:33 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/10/27 16:44:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/10/27 08:50:04 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/10/26 17:19:37 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\Nick Rummel\Desktop\RootRepeal.exe
[2009/10/26 16:34:20 | 00,143,360 | ---- | C] (Inner Media, Inc.) -- C:\WINDOWS\System32\dunzip32.dll
[2009/10/25 18:59:54 | 00,033,832 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdk.sys
[2009/10/25 18:59:43 | 00,040,488 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfesmfk.sys
[2009/10/25 18:59:40 | 00,035,240 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfebopk.sys
[2009/10/25 18:59:38 | 00,079,304 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys
[2009/10/25 18:59:37 | 00,201,320 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys
[2009/10/25 18:59:20 | 00,113,952 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\Mpfp.sys
[2009/10/22 23:48:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Nick Rummel\My Documents\DVDVideoSoft
[2009/10/22 23:44:37 | 10,984,941 | ---- | C] (DVDVideoSoft Limited. ) -- C:\Documents and Settings\Nick Rummel\Desktop\FreeVideoFlipAndRotate.exe
[2009/10/21 22:45:25 | 08,067,224 | ---- | C] (Mozilla) -- C:\Documents and Settings\Nick Rummel\Desktop\Firefox Setup 3.5.3.exe
[2009/10/21 16:40:00 | 00,000,000 | ---D | C] -- C:\EmergencyUtils
[2009/10/21 16:39:34 | 00,032,768 | ---- | C] (Doug Knox) -- C:\Documents and Settings\Nick Rummel\Desktop\xp_emergencyutil.exe
[2009/06/03 20:21:01 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
[2009/06/03 20:21:00 | 00,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2009/06/03 20:21:00 | 00,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
[2009/06/03 20:21:00 | 00,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll
[2007/08/02 15:20:28 | 00,220,184 | ---- | C] ( ) -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\Interop.Microsoft.Office.Core.dll
[2007/02/24 21:45:58 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Nick Rummel\Application Data\pcouffin.sys
[2006/08/27 22:59:50 | 01,183,744 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccserv.dll
[2006/08/27 22:59:50 | 01,134,592 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccusb1.dll
[2006/08/27 22:59:50 | 00,774,144 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcchbn3.dll
[2006/08/27 22:59:50 | 00,704,512 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcccomc.dll
[2006/08/27 22:59:50 | 00,638,976 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccpmui.dll
[2006/08/27 22:59:50 | 00,483,328 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcclmpm.dll
[2006/08/27 22:59:50 | 00,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcccomm.dll
[2006/08/27 22:59:50 | 00,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccprox.dll
[2006/08/27 22:59:50 | 00,114,688 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccpplc.dll
[2005/12/13 18:12:34 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\stdole.dll

========== Files - Modified Within 14 Days ==========

[2009/10/29 08:50:28 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTL.exe
[2009/10/29 08:01:03 | 00,000,246 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2009/10/29 07:59:40 | 00,002,479 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Start Menu\Programs\Startup\WD Anywhere Backup Launcher.lnk
[2009/10/29 07:59:10 | 00,012,859 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF
[2009/10/29 07:57:55 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/29 07:40:59 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/29 07:40:55 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/29 07:40:53 | 10,637,14816 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/28 23:48:24 | 00,223,744 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/28 19:15:52 | 00,021,430 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\Finances.xlsx
[2009/10/28 18:29:33 | 00,000,165 | -H-- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\~$Finances.xlsx
[2009/10/28 15:58:33 | 00,282,833 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\gmer.zip
[2009/10/28 15:40:46 | 00,408,064 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTM.exe
[2009/10/28 08:39:32 | 00,000,157 | ---- | M] () -- C:\WINDOWS\matlab.ini
[2009/10/28 08:30:52 | 00,000,246 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/10/28 08:29:59 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/10/27 17:06:28 | 00,000,279 | RHS- | M] () -- C:\boot.ini
[2009/10/26 17:22:26 | 00,464,491 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\RootRepeal.zip
[2009/10/26 17:19:56 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\settings.dat
[2009/10/26 16:40:14 | 00,000,666 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee EasyNetwork.lnk
[2009/10/26 16:40:10 | 00,000,671 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2009/10/25 18:58:23 | 00,000,352 | ---- | M] () -- C:\WINDOWS\tasks\McDefragTask.job
[2009/10/25 18:58:21 | 00,000,344 | ---- | M] () -- C:\WINDOWS\tasks\McQcTask.job
[2009/10/25 06:11:34 | 00,077,312 | ---- | M] () -- C:\WINDOWS\MBR.exe
[2009/10/24 18:59:05 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/23 00:11:25 | 00,002,199 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SolidWorks 2009 SP3.0.lnk
[2009/10/22 23:48:33 | 00,000,892 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\DVDVideoSoft Free Studio.lnk
[2009/10/22 23:46:31 | 10,984,941 | ---- | M] (DVDVideoSoft Limited. ) -- C:\Documents and Settings\Nick Rummel\Desktop\FreeVideoFlipAndRotate.exe
[2009/10/21 22:48:02 | 08,067,224 | ---- | M] (Mozilla) -- C:\Documents and Settings\Nick Rummel\Desktop\Firefox Setup 3.5.3.exe
[2009/10/21 16:39:03 | 00,007,875 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\xp_emergencyutil.zip
[2009/10/16 13:22:44 | 00,291,328 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\gmer.exe

========== Files - No Company Name ==========
[2009/10/28 18:29:33 | 00,000,165 | -H-- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\~$Finances.xlsx
[2009/10/28 15:58:52 | 00,291,328 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\gmer.exe
[2009/10/28 15:58:31 | 00,282,833 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\gmer.zip
[2009/10/27 17:06:28 | 00,000,209 | ---- | C] () -- C:\Boot.bak
[2009/10/27 17:06:05 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/10/27 16:48:36 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2009/10/27 16:48:34 | 00,236,544 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/10/27 16:48:34 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/10/27 16:48:34 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/10/27 16:48:33 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/10/26 17:19:56 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\settings.dat
[2009/10/26 17:15:28 | 00,464,491 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\RootRepeal.zip
[2009/10/26 16:41:14 | 00,012,859 | ---- | C] () -- C:\WINDOWS\System32\Config.MPF
[2009/10/26 16:40:14 | 00,000,666 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee EasyNetwork.lnk
[2009/10/26 16:40:10 | 00,000,671 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2009/10/25 18:58:23 | 00,000,352 | ---- | C] () -- C:\WINDOWS\tasks\McDefragTask.job
[2009/10/25 18:58:21 | 00,000,344 | ---- | C] () -- C:\WINDOWS\tasks\McQcTask.job
[2009/10/22 23:49:27 | 00,000,246 | ---- | C] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2009/10/22 23:48:33 | 00,000,892 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\DVDVideoSoft Free Studio.lnk
[2009/10/21 16:39:01 | 00,007,875 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\xp_emergencyutil.zip
[2009/08/31 22:07:42 | 00,050,127 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/07/22 16:25:23 | 00,005,652 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2009/06/25 15:11:20 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\LXPMONUI.DLL
[2009/06/25 15:11:19 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXPRMON.DLL
[2009/06/24 13:50:49 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2009/06/03 20:21:04 | 00,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
[2009/06/03 20:21:03 | 00,003,968 | ---- | C] () -- C:\WINDOWS\System32\drivers\DeNoise.sys
[2009/04/02 13:21:57 | 00,004,536 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\DB475BB5-9A3E-4DE9-BD7D-189CA7F82FD2.txt
[2009/01/02 13:15:10 | 00,000,518 | ---- | C] () -- C:\WINDOWS\System32\SP207.INI
[2008/09/17 21:34:02 | 00,148,992 | ---- | C] () -- C:\WINDOWS\System32\mllink5.dll
[2008/09/17 21:34:02 | 00,000,019 | ---- | C] () -- C:\WINDOWS\exlink.ini
[2008/03/18 12:07:35 | 00,903,168 | ---- | C] () -- C:\WINDOWS\System32\mitmdl30.dll
[2008/03/18 12:07:34 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwpg60n.dll
[2008/03/18 12:07:34 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwmf60n.dll
[2008/03/18 12:07:33 | 00,110,080 | ---- | C] () -- C:\WINDOWS\System32\lfpng60n.dll
[2008/03/18 12:07:33 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\lftif60n.dll
[2008/03/18 12:07:33 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\lfpcx60n.dll
[2008/03/18 12:07:33 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfpct60n.dll
[2008/03/18 12:07:33 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\lfpsd60n.dll
[2008/03/18 12:07:33 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\lftga60n.dll
[2008/03/18 12:07:33 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\lfmsp60n.dll
[2008/03/18 12:07:32 | 00,176,128 | ---- | C] () -- C:\WINDOWS\System32\lffax60n.dll
[2008/03/18 12:07:32 | 00,141,824 | ---- | C] () -- C:\WINDOWS\System32\lfcmp60n.dll
[2008/03/18 12:07:32 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfeps60n.dll
[2008/03/18 12:07:32 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\lfbmp60n.dll
[2008/03/18 12:07:32 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\lfmac60n.dll
[2008/02/11 18:30:49 | 00,000,000 | ---- | C] () -- C:\WINDOWS\eDrawingOfficeAutomator.INI
[2008/01/21 15:05:42 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iplayer.INI
[2007/08/04 15:23:47 | 00,000,040 | ---- | C] () -- C:\WINDOWS\musicstr.ini
[2007/08/04 14:26:24 | 00,000,514 | ---- | C] () -- C:\WINDOWS\teachpno.ini
[2007/04/13 15:09:08 | 02,067,140 | R--- | C] () -- C:\WINDOWS\System32\avcodec.dll
[2007/04/13 00:01:49 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/04/12 23:58:40 | 00,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/04/07 02:25:46 | 00,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2007/03/24 13:36:17 | 00,223,128 | ---- | C] () -- C:\WINDOWS\System32\drivers\vaxscsi.sys
[2007/02/27 20:35:55 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007/02/24 21:48:26 | 00,000,014 | ---- | C] () -- C:\WINDOWS\System32\systeminfo3.dll
[2007/02/24 21:46:19 | 00,000,033 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\pcouffin.log
[2007/02/24 21:45:58 | 00,081,920 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\ezpinst.exe
[2007/02/24 21:45:58 | 00,007,176 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\pcouffin.cat
[2007/02/24 21:45:58 | 00,001,144 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\pcouffin.inf
[2007/02/24 21:34:29 | 00,000,040 | -HS- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\.zreglib
[2007/02/22 11:19:06 | 00,052,000 | ---- | C] () -- C:\WINDOWS\System32\nipcload.dll
[2007/02/21 19:30:50 | 00,000,244 | ---- | C] () -- C:\WINDOWS\System32\nirpc.ini
[2007/02/21 10:00:00 | 00,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\cvintdrv.sys
[2007/02/06 17:45:04 | 00,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/06 17:42:40 | 01,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2006/12/31 20:23:50 | 00,000,956 | R--- | C] () -- C:\WINDOWS\System32\iconcfg.ini
[2006/12/07 10:10:37 | 00,000,004 | ---- | C] () -- C:\WINDOWS\info147.sys
[2006/12/06 18:49:46 | 00,000,592 | ---- | C] () -- C:\Program Files\Opera.lnk
[2006/12/04 20:02:26 | 01,580,176 | -H-- | C] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\IconCache.db
[2006/12/03 21:45:25 | 00,000,050 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006/10/16 17:36:29 | 00,000,021 | ---- | C] () -- C:\WINDOWS\WB.ini
[2006/10/16 16:53:59 | 00,005,127 | ---- | C] () -- C:\WINDOWS\langorig.ini
[2006/10/16 16:53:18 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\wbload.dll
[2006/10/16 16:48:52 | 00,000,027 | ---- | C] () -- C:\WINDOWS\SDAddressBox16827d0561119.ini
[2006/10/16 16:45:44 | 00,000,027 | ---- | C] () -- C:\WINDOWS\SDAddressBox1633cb8581916.ini
[2006/10/16 16:42:27 | 00,007,852 | ---- | C] () -- C:\WINDOWS\System32\mcdmsg7.dll
[2006/09/21 19:21:52 | 00,003,766 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/09/21 19:21:52 | 00,000,088 | RHS- | C] () -- C:\WINDOWS\System32\68430E414D.sys
[2006/09/08 15:26:05 | 00,000,157 | ---- | C] () -- C:\WINDOWS\matlab.ini
[2006/09/05 23:05:35 | 00,002,516 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/09/05 22:40:11 | 00,223,744 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/05 18:44:35 | 00,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/09/05 18:35:14 | 00,001,626 | ---- | C] () -- C:\Program Files\QuickTime Player.lnk
[2006/09/05 18:19:36 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/09/05 18:14:15 | 00,000,841 | ---- | C] () -- C:\Program Files\Ad-Aware SE Personal.lnk
[2006/09/05 16:34:00 | 00,001,753 | ---- | C] () -- C:\Program Files\Dell Printer Supplies - Inkjet.lnk
[2006/09/05 16:14:59 | 00,152,872 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2006/09/05 16:01:52 | 00,000,786 | ---- | C] () -- C:\Program Files\Windows Media Player.lnk
[2006/09/05 16:01:46 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\desktop.ini
[2006/09/05 16:01:45 | 00,001,298 | ---- | C] () -- C:\Program Files\Media Center.lnk
[2006/09/05 16:01:44 | 00,000,134 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\fusioncache.dat
[2006/08/29 08:54:33 | 00,001,752 | ---- | C] () -- C:\Program Files\main.ini
[2006/08/27 23:59:40 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/08/27 23:56:37 | 00,001,967 | ---- | C] () -- C:\Program Files\Internet Service Offers.lnk
[2006/08/27 23:56:14 | 00,001,965 | ---- | C] () -- C:\Program Files\Games, Music, & Photos.lnk
[2006/08/27 23:56:06 | 00,001,958 | ---- | C] () -- C:\Program Files\Documentation & Support.lnk
[2006/08/27 23:51:09 | 00,000,413 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/08/27 23:45:13 | 00,001,661 | ---- | C] () -- C:\Program Files\Trend Micro PC-cillin Internet Security 12.lnk
[2006/08/27 23:39:50 | 00,712,704 | ---- | C] () -- C:\WINDOWS\System32\DellSystemRestore.dll
[2006/08/27 23:36:41 | 00,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/08/27 23:31:45 | 00,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/08/27 22:59:50 | 00,430,080 | ---- | C] () -- C:\WINDOWS\System32\dlccutil.dll
[2006/08/27 22:59:50 | 00,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlccinsb.dll
[2006/08/27 22:59:50 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\dlccins.dll
[2006/08/27 22:59:50 | 00,131,072 | ---- | C] () -- C:\WINDOWS\System32\dlccjswr.dll
[2006/08/27 22:59:50 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\dlccinsr.dll
[2006/08/27 22:59:50 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\dlcccub.dll
[2006/08/27 22:59:50 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\dlcccu.dll
[2006/08/27 22:59:50 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlccvs.dll
[2006/08/27 22:59:50 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\dlcccur.dll
[2006/08/27 22:59:48 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\dlcccfg.dll
[2006/08/27 22:59:14 | 00,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2006/08/27 22:58:48 | 00,000,391 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/06/13 17:35:32 | 00,053,760 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2005/08/16 02:37:24 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 02:33:24 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2005/08/16 02:18:43 | 00,001,204 | ---- | C] () -- C:\WINDOWS\win.ini
[2005/08/16 02:18:41 | 00,000,246 | ---- | C] () -- C:\WINDOWS\system.ini
[2005/08/05 12:01:54 | 00,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 12:00:16 | 00,000,611 | ---- | C] () -- C:\WINDOWS\System32\dlccplc.ini
[2005/07/14 01:15:30 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcevs.dll
[2005/06/10 10:00:00 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\cviUSI.dll
[2003/01/30 07:04:00 | 00,618,496 | ---- | C] () -- C:\WINDOWS\System32\stlpmt45.dll
[2002/02/15 10:29:02 | 00,000,172 | ---- | C] () -- C:\WINDOWS\recorsta.ini
[2000/01/06 17:00:00 | 00,026,672 | ---- | C] () -- C:\WINDOWS\System32\procsvr.drv
[2000/01/06 17:00:00 | 00,026,672 | ---- | C] () -- C:\WINDOWS\sysltime.dll

========== LOP Check ==========

[2009/10/14 21:30:26 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/03/21 20:06:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/10/03 18:13:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/17 19:34:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{7D4B3D1D-104E-4507-9123-568BC721B7E2}
[2009/04/18 20:30:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/05 09:09:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2009/09/10 00:23:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2008/02/26 01:24:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dell
[2008/08/07 21:20:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FaxCtr
[2007/12/09 19:05:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2009/08/06 19:03:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2007/05/01 01:27:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intel
[2009/08/31 22:05:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Logishrd
[2008/05/13 11:30:07 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Memeo
[2007/09/22 08:37:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/05/23 20:44:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\National Instruments
[2009/08/06 19:10:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2006/10/02 19:19:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2009/02/23 10:28:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SITEguard
[2006/10/02 22:32:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SkillJam
[2009/09/10 22:58:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SolidWorks
[2009/02/23 11:38:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2008/01/10 00:34:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/10/28 20:35:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/17 19:34:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Transparent
[2006/12/12 01:49:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2009/07/29 11:10:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/02/13 15:14:55 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\WD
[2009/10/26 22:18:07 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Nick Rummel\Application Data
[2007/04/15 01:29:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\.gaim
[2006/09/05 18:50:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\acccore
[2009/02/24 17:02:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\advantage
[2006/12/31 16:59:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\ArcSoft
[2009/09/10 00:25:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Autodesk
[2008/11/15 21:53:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\BitTorrent
[2007/11/20 22:08:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Chessmaster Challenge
[2006/09/21 19:22:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Corel Photo Album
[2007/02/24 21:29:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\CyberLink
[2009/02/24 17:31:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\DAEMON Tools
[2009/02/24 17:01:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\DAEMON Tools Pro
[2009/10/16 10:37:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\dvdcss
[2008/02/11 18:29:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\DWGeditor
[2008/08/08 11:13:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\FaxCtr
[2007/09/29 12:04:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Gizmoz
[2009/10/29 07:59:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\IM
[2007/05/01 01:27:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Intel
[2006/12/31 20:14:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Leadertech
[2009/04/07 01:21:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\lrfmenuz
[2006/09/08 15:26:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\MathWorks
[2009/10/23 14:20:34 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Move Networks
[2007/04/30 16:38:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\MSNInstaller
[2006/12/09 13:15:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\NY-Yankees.net Toolbar
[2006/12/06 18:50:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Opera
[2008/09/05 00:37:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Prism
[2007/05/17 17:11:46 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SecuROM
[2009/02/21 16:21:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\sldIM
[2007/02/24 21:36:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SlySoft
[2009/10/23 00:12:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SolidWorks
[2009/09/14 17:45:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SolidWorks 2009
[2007/11/20 21:51:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SpinTop
[2007/05/19 17:42:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SystemRequirementsLab
[2008/12/17 02:03:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\U3
[2007/02/28 23:16:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Vso
[2009/10/24 18:59:05 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/10 03:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/10/25 18:58:23 | 00,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\McDefragTask.job
[2009/10/25 18:58:21 | 00,000,344 | ---- | M] () -- C:\WINDOWS\Tasks\McQcTask.job
[2009/10/29 07:40:59 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/10/29 08:01:03 | 00,000,246 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
[eventlog.dll : MD5=82B24CB70E5944E6E34662205A2A5B78] -> [2004/08/10 03:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) -- C:\i386\eventlog.dll
[1 C:\i386\*.tmp files]
[EventLog.dll : MD5=1363337A5301619F00F8033835EF30E9] -> [1999/10/03 20:38:26 | 00,017,408 | ---- | M] () -- C:\MATLAB6p5\sys\perl\win32\site\lib\auto\Win32\EventLog\EventLog.dll
[eventlog.dll : MD5=82B24CB70E5944E6E34662205A2A5B78] -> [2004/08/10 03:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[eventlog.dll : MD5=6D4FEB43EE538FC5428CC7F0565AA656] -> [2008/04/13 17:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[eventlog.dll : MD5=6D4FEB43EE538FC5428CC7F0565AA656] -> [2008/04/13 17:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[eventlog.dll : MD5=6D4FEB43EE538FC5428CC7F0565AA656] -> [2008/04/13 17:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\eventlog.dll

< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[scecli.dll : MD5=0F78E27F563F2AAF74B91A49E2ABF19A] -> [2004/08/10 03:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) -- C:\i386\scecli.dll
[1 C:\i386\*.tmp files]
[scecli.dll : MD5=0F78E27F563F2AAF74B91A49E2ABF19A] -> [2004/08/10 03:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[scecli.dll : MD5=A86BB5E61BF3E39B62AB4C7E7085A084] -> [2008/04/13 17:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ERDNT\cache\scecli.dll
[scecli.dll : MD5=A86BB5E61BF3E39B62AB4C7E7085A084] -> [2008/04/13 17:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[scecli.dll : MD5=A86BB5E61BF3E39B62AB4C7E7085A084] -> [2008/04/13 17:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\scecli.dll

< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[netlogon.dll : MD5=96353FCECBA774BB8DA74A1C6507015A] -> [2004/08/10 03:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) -- C:\i386\netlogon.dll
[1 C:\i386\*.tmp files]
[netlogon.dll : MD5=96353FCECBA774BB8DA74A1C6507015A] -> [2004/08/10 03:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[netlogon.dll : MD5=1B7F071C51B77C272875C3A23E1E4550] -> [2008/04/13 17:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[netlogon.dll : MD5=1B7F071C51B77C272875C3A23E1E4550] -> [2008/04/13 17:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[netlogon.dll : MD5=1B7F071C51B77C272875C3A23E1E4550] -> [2008/04/13 17:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\netlogon.dll

< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >

< %SYSTEMDRIVE%\sceclt.dll /s /md5 >

< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >

< %SYSTEMDRIVE%\logevent.dll /s /md5 >

< %SYSTEMDRIVE%\iaStor.sys /s /md5 >

< %SYSTEMDRIVE%\nvstor.sys /s /md5 >

< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[atapi.sys : MD5=CDFE4411A69C224BD1D11B2DA92DAC51] -> [2004/08/03 20:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) -- C:\i386\atapi.sys
[1 C:\i386\*.tmp files]
[atapi.sys : MD5=CDFE4411A69C224BD1D11B2DA92DAC51] -> [2004/08/03 20:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[atapi.sys : MD5=9F3A2F5AA6875C72BF062C712CFA2674] -> [2008/04/13 11:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[atapi.sys : MD5=9F3A2F5AA6875C72BF062C712CFA2674] -> [2008/04/13 11:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\atapi.sys
[atapi.sys : MD5=CDFE4411A69C224BD1D11B2DA92DAC51] -> [2004/08/03 20:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys

< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >

< %SYSTEMDRIVE%\viasraid.sys /s /md5 >

< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[AGP440.SYS : MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB] -> [2004/08/03 21:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\i386\AGP440.SYS
[1 C:\i386\*.tmp files]
[agp440.sys : MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB] -> [2004/08/03 21:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[agp440.sys : MD5=08FD04AA961BDC77FB983F328334E3D7] -> [2008/04/13 11:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ERDNT\cache\agp440.sys
[agp440.sys : MD5=08FD04AA961BDC77FB983F328334E3D7] -> [2008/04/13 11:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[agp440.sys : MD5=08FD04AA961BDC77FB983F328334E3D7] -> [2008/04/13 11:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\agp440.sys

< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
C:\WINDOWS\system32\drivers\ -> C:\WINDOWS\System32\drivers -> [2009/10/29 09:00:33 | 00,000,000 | ---D | M]
[vaxscsi.sys : Unable to obtain MD5 ] -> [2007/03/24 13:36:17 | 00,223,128 | ---- | M] () -- C:\WINDOWS\System32\drivers\vaxscsi.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 61 bytes -> C:\Documents and Settings\All Users\Application Data\Symantec\hpc:468323563
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844

========== Files - Unicode (All) ==========
[2009/02/16 00:49:22 | 00,000,000 | ---D | M](C:\DoC?) -- C:\DoCԱ
[2009/02/16 00:49:21 | 00,000,000 | ---D | C](C:\DoC?) -- C:\DoCԱ
< End of report >
Go to the top of the page
 
+Quote Post
nrummel
post Oct 29 2009, 04:58 PM
Post #12


Member
**
Posts: 13
OS: Windows 2000



OTL Extras logfile created on: 10/29/2009 8:51:00 AM - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Documents and Settings\Nick Rummel\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.37 Mb Total Physical Memory | 332.24 Mb Available Physical Memory | 32.75% Memory free
2.38 Gb Paging File | 1.46 Gb Available in Paging File | 61.19% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 4.27 Gb Free Space | 11.47% Space Free | Partition Type: NTFS
Drive D: | 12.27 Gb Total Space | 12.03 Gb Free Space | 98.03% Space Free | Partition Type: NTFS
Drive E: | 82.04 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NRUMMEL
Current User Name: Nick Rummel
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Key error. File not found
.cmd [@ = cmdfile] -- Reg Error: Key error. File not found
.com [@ = ComFile] -- Reg Error: Key error. File not found
.exe [@ = exefile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.vbs [@ = VBSFile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MI1933~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost -- File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\DC++\DCPlusPlus.exe" = C:\Program Files\DC++\DCPlusPlus.exe:*:Enabled:DC++ -- ()
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- (AOL LLC)
"C:\Program Files\DAP\DAP.exe" = C:\Program Files\DAP\DAP.exe:*:Enabled:Download Accelerator Plus (DAP) -- (Speedbit Ltd.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Documents and Settings\Nick Rummel\My Documents\My Completed Downloads\eclipse-cpp-europa-win32\eclipse\eclipse.exe" = C:\Documents and Settings\Nick Rummel\My Documents\My Completed Downloads\eclipse-cpp-europa-win32\eclipse\eclipse.exe:*:Enabled:eclipse -- ()
"C:\Program Files\Java\jdk1.5.0_09\jre\bin\java.exe" = C:\Program Files\Java\jdk1.5.0_09\jre\bin\java.exe:*:Enabled:Java™ 2 Platform Standard Edition binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\Program Files\National Instruments\LabVIEW 8.2\LabVIEW.exe" = C:\Program Files\National Instruments\LabVIEW 8.2\LabVIEW.exe:*:Enabled:LabVIEW 8.2.1 Development System -- (National Instruments Corporation)
"C:\Program Files\National Instruments\Shared\Example Finder\1.0\BIN\NIExampleFinder.exe" = C:\Program Files\National Instruments\Shared\Example Finder\1.0\BIN\NIExampleFinder.exe:*:Enabled:NIExampleFinder -- (National Instruments)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost -- File not found
"C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe" = C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater -- (Nokia Corporation)
"C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe" = C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process -- (Nokia Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath -- (Skype Technologies S.A.)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent -- (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{047DB692-BBD4-4768-91CC-ABD418B494B8}" = NI USI 1.4.1
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{05A5B86B-7A8F-44B6-A43C-3B953E69F004}" = NI LabVIEW 8.2.1 Resource
"{066A1255-1299-4EBA-B9B3-FA7FB14F92E4}" = CIF USB Camera
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{071ED036-038F-4F6C-8188-B5E02602C8AD}" = NI LabVIEW MAX XML
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0EC523EE-3D9F-415C-8D30-95F973D53D87}" = NI LabVIEW Real-Time Error Dialog
"{0ECB59D5-A3FC-4D61-AD3B-6CE679B3F852}" = Java DB 10.2.2.0
"{0EE24AF8-91DD-49C0-B50E-1986F67D2BE3}" = NI Instrument IO Assistant for LabVIEW 8.2
"{10560CCA-BCF6-47B0-A0BA-FB6E134A0AD7}" = NI LabVIEW 8.2.1 License
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1B140425-1EA0-4AB8-BB31-1830C4A0A1F2}" = DWGeditor
"{1BCEA516-B4C5-4B2D-BFA0-AB7910BAD862}" = Adobe ExtendScript Toolkit 2
"{1C478488-78AD-4E94-B200-A10EC530A4E9}" = NI LabVIEW Broker
"{1D476EFD-93EF-4E01-9505-C98FF606DF61}" = NI LabVIEW 8.2.1 Instr.lib
"{1FB138CC-5503-4B4A-BC42-81E9C1FF26EE}" = Autodesk Inventor Content Center Libraries 2010 (Desktop Content)
"{200FF4D5-1784-437A-A547-BFA7D735A5EB}" = Recording Station
"{20969065-2AFF-4711-96F9-5D724007ACE4}" = NI LabVIEW 8.2.1 User.lib
"{20F0F67B-CB0F-4C85-B6F2-133D9CB70614}" = Samsung PC Studio
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{28FF0691-1440-452D-96EB-269AA7A2F5A4}" = NI LabVIEW 8.2 Device Detection and Deployment Support
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2D2F7B3E-E0B7-444A-81F5-C45C63500FDB}" = NI MXS
"{31274293-6159-4F39-B8D1-86279091DE49}" = NI LabWindows/CVI Code Generator
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0150090}" = J2SE Development Kit 5.0 Update 9
"{32A3A4F4-B792-11D6-A78A-00B0D0160020}" = Java™ SE Development Kit 6 Update 2
"{33983300-C53D-4AC3-A7F9-6634E651D993}" = NI Measurement & Automation Explorer 4.2
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{35727E31-5D78-478A-B418-7E9A82729DB2}" = SolidWorks 2009 SP03
"{36A998F0-C15C-4AFD-BCAE-1C0577CCA29A}" = NI DataSocket 4.4.0
"{3A5A79C7-E7A5-4E18-9BC2-872D0BD38C58}" = NI LabVIEW 8.2.1 Examples
"{3C782FEB-BC17-4CE1-8DD4-830C4DB2F1FC}" = NI LabVIEW 8.2.1 Templates
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3EE80F80-3CB1-4C9E-830C-1DABB2E76AFA}" = NI LabVIEW 8.2.1 gMath
"{3F358B78-C154-46DF-8423-023729B42795}" = NI Example Finder 8.2
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4159DD60-49C1-4323-A1A5-FB060CBA35C5}" = NI Measurement Studio Recipe Processor
"{452B119A-4D74-4FBB-A9A9-FD4D12F9B780}" = NI LabVIEW 8.2.1 WWW
"{45C69E1F-D33F-413A-B8CF-FE8483219FFB}" = NI LabVIEW 8.2.1 Project
"{45FA54F6-8574-49D2-9E2D-0BDDE6237822}" = NI LabVIEW Run-Time Engine 8.2.1
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{4F66ADD6-FC65-4A55-92A7-1D35E5E7D59D}" = NI LabVIEW 8.2 Help
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{52969324-463B-4643-BF36-854BE2BECB89}" = Autodesk Inventor 2010 English Language Pack
"{52D02A2B-03D2-4E34-A358-DC5D951FD296}" = Nokia Connectivity Cable Driver
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{54B5C1CD-CD34-4F0B-B995-9D42AE3EA190}" = NI Variable Manager
"{5535426F-E814-4B34-9B36-726E9DBEB7A7}" = NI Logos 4.7
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{55D9E026-DCB0-46FF-B60A-68B972228CF6}" = Autodesk Design Review 2010
"{55DA893C-8337-4EEB-B0E5-009C6BB425E3}" = NI Remote Provider for MAX
"{57700DD3-0C10-4CE6-95BA-630284EE2CB1}" = NI License Manager
"{5783F2D7-8028-0409-0000-0060B0CE6BBA}" = DWG TrueView 2010
"{5A9F6AE3-85D6-4411-B707-29A85F6E274F}" = NI Remote PXI Provider for MAX
"{5B641F4F-A9A7-49A7-917E-EB1E1F5626E1}" = NI LabVIEW 8.2 MeasAppChm File
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.5
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{65F1EE0F-F9D2-45E1-8E14-2EBFF34E90A0}" = NI LVBrokerAux8.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7
"{6D2737AE-8898-4BE1-AE46-555B7DB540A8}" = NI MDF Support
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{736175D8-263C-436E-B654-EF99B2F0C8BA}" = NI-RPC 3.3.1f0 for Phar Lap ETS
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{78231F18-FD98-4B03-A932-DE9329594D08}" = NI TDMS
"{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam
"{7D26E5EA-63A2-4C4B-BE97-446404685C59}" = NI LabVIEW 8.2.1 CINtools
"{7D3E7FA0-F95A-4942-B188-56582CE0C7CC}" = NI Software Provider for MAX
"{7E3668CB-1228-416E-B721-C2FA3247B985}" = NI LabVIEW Real-Time FIFO for Runtime
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{7F4DD591-1400-0409-0000-7107D70F3DB4}" = Autodesk Inventor 2010
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{80BA07B3-537F-4189-92F7-26E2BA76095A}" = SolidWorks eDrawings 2009
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{86F908CA-B1B4-476B-B8EB-7FC1D32C7A05}" = NI OPC Support
"{873258AA-8BEA-4B76-B158-F42A7FE304BB}" = NI LabVIEW 8.2.1 Simulation
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B073FE8-ED47-439E-94A9-68C1B8242FC1}" = NI-RPC 3.3.1f0
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{911F2BEE-4919-4BA3-A097-B014070FD738}" = NI Assistant Framework LabVIEW Code Generator 8.0
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{94721EA3-7EA6-43EA-B99C-A5D0E3C66240}" = 924PLC32
"{94F8151E-1946-4D81-9FBF-E167DF25954A}" = NI LabVIEW Run-Time Engine 8.0
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{98618CFE-CACD-48C4-85EA-F9197FFEDD0C}" = NI Assistant Framework LabVIEW Code Generator 6.1
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9D65A47A-0929-4C50-A3BD-3AF59DA38ED8}" = NI LabVIEW 8.2.1 iMath
"{9E0AE153-88DC-428B-99EB-6A3D984230B8}" = NI LabWindows/CVI 7.1.1 Run Time Engine
"{9FBEC876-60EB-4BAC-BF51-E7EF29C1D71A}" = NI Assistant Framework LabVIEW Code Generator 8.2
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{AA11363D-DF31-419C-961D-D8A5F148651D}" = NI LabVIEW Deployable License 8.2
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC1D71B5-B622-40D2-979A-BA55261A86EB}" = NI LabVIEW 8.2.1 Applibs
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B306061F-9083-4DAB-9809-C4DDAF319273}" = NI LabVIEW 8.2.1 Menus
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B51CC1CD-5828-4441-9C8F-7659ACF1BF65}" = NI LabVIEW 8.2.1 VI.lib
"{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B84F8170-2D08-438A-A307-F23C4EA95430}" = NI LabVIEW 8.2 Help File
"{B9A81070-616D-4E93-BE02-CEE651343204}" = WD Anywhere Backup
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BA68600E-96D9-4E92-80F2-26B9681B5A63}" = Microsoft Office Outlook 2003 with Business Contact Manager Update
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{BFAA820A-C7D8-42AE-A3BA-CE118F3F0802}" = NI Service Locator
"{BFEA2222-557D-4F0D-B1AE-64EECBCA2747}" = NI VC2005MSMs x86
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C19781D2-3D75-4245-9CFC-CAE37CCA8A40}" = Samsung PC Studio
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C5253437-5F29-44D3-9665-1AB316A11850}" = NI Variable Engine LabVIEW 8.2.1 Support
"{C532C3FA-4241-4521-9FAC-1FA20BAE36B6}" = NI Variable Engine
"{C6B62A71-A0E5-4D3A-9EFC-05A8A7C31337}" = BASIC Stamp Editor v2.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D2EB6337-42E5-4D6E-B01F-2FF9E30F4A06}" = NI Web Pipeline
"{D481EA96-2313-4A7C-98EE-710D1AF884AC}" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"{D504303A-717D-414C-BA9F-FE01093E2EF8}" = Adobe Setup
"{D6FAEBB1-90E0-4CF8-9A41-9087E6789D11}" = NI EULA Depot
"{D89EEEA4-78D7-4533-AEF4-D7918EF359D2}" = NI LabVIEW 8.2 Manuals
"{D9529709-28B0-4DA1-8749-8924C11AAFF2}" = NI Registration Wizard
"{D96D5628-9EAB-4F43-ADC9-3A9A77DAB3DD}" = NI MAX LabVIEW Support
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DB2C5648-700D-4AEF-83E1-70C72F0C34FA}" = NI Math Kernel Libraries
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DEC25D81-2317-47F6-8B26-D54A939DA1EE}" = NI LabVIEW C Interface
"{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}" = Search Assist
"{E064390A-2F64-4195-9A55-30D4B20B865A}" = WDCSAM Driver
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E4198521-8BA7-45FE-B16D-6B192EB5798F}" = NI Portable Configuration
"{E42BD75A-FC23-4E3F-9F91-2658334C644F}" = Internet Service Offers Launcher
"{E5B1DA8B-D2C2-4E4F-82CF-28C169FD4598}" = NI Assistant Framework LabVIEW Code Generator 7.1
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E80BEC94-A496-4CE6-89B5-08922D1CCD84}" = BASIC Stamp Editor v2.3.9
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E8991297-B702-44AA-ABAA-02C12045D8E9}" = NI Uninstaller
"{E8C06CB3-5DB2-4689-B1DC-4A0220DEA96C}" = Consumer Complete Care Services Agreement
"{E9BC36C5-6265-4FE6-B7D2-11C0474DA681}" = NI LabVIEW 8.2.1 Activity
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{EB9E7F70-8F2E-412A-A182-FAC85345FDCC}" = NI Assistant Framework LabVIEW Code Generator 7.0
"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = GE MiniCam Pro
"{EFD09F8C-6F4C-416C-B1FD-047D452556DC}" = NI-DAQmx - LabVIEW shared documentation
"{F06DCD6F-171E-4D51-942D-348D1829F6EE}" = NI LabVIEW 8.2.1
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F5A51F25-F1F4-419F-8888-22A768CFE3C2}" = NI Logos LabVIEW 8.2 Support
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}" = Nokia Software Updater
"{F9F3C962-A2E6-49D1-BF34-7A6D2023D2CE}" = NI Help Assistant
"{FBC11FAF-CC2E-4614-A6C5-D5DDDE276572}" = NI LVBrokerAux 8.2.1
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FD1F0BFE-E5D9-4116-90C3-78999D61EF12}" = NI Assistant Framework
"{FD9E03B5-AEEA-4D59-B512-6CE4AA0281D4}" = Byki
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"00BD1CD47675C125126C80095FCC12CFA4D311DB" = Windows Driver Package - FTDI CDM Driver Package (06/27/2007 2.02.04)
"126C456AE165F5E8391AB722C9C16C4D76981DEA" = Windows Driver Package - Intel net (03/13/2008 11.5.1.15)
"18FF359AE500F8C84B16BD7C8065F75AFEAE4CDF" = Windows Driver Package - Intel (w29n51) net (10/25/2006 9.0.4.26)
"2DA959FE3D6F0F5BC313481E72071D510DD786FB" = Windows Driver Package - Intel (w29n51) net (12/19/2007 9.0.4.39)
"8A1D0449E9CBCC93DCB0CF47934D695423632CA7" = Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM (12/05/2006 1.0.0007.0)
"A106663FD3361BDFACB045D83EBA03858EB1E411" = Windows Driver Package - FTDI CDM Driver Package (03/13/2008 2.04.06)
"A622B79B943ECA1F0AECF1FF5BE13D458F345EBB" = Windows Driver Package - FTDI CDM Driver Package (06/27/2007 2.02.04)
"Absolute Fretboard Trainer PRO" = Absolute Fretboard Trainer PRO
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe_5bc0f8414ec36c555a3e7e5ec2e225e" = Adobe ExtendScript Toolkit 2
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"AIM_6" = AIM 6
"Akamai" = Akamai NetSession Interface
"Autodesk Design Review 2010" = Autodesk Design Review 2010
"Autodesk Inventor 2010" = Autodesk Inventor Professional 2010
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"Byki Express" = Byki Express
"CleanMyPC Popup Blocker" = CleanMyPC Popup Blocker
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"D4DEFCEEE19FBF84C44EE0E5CF3716D67F3A4261" = Windows Driver Package - Intel (NETw4x32) net (03/13/2008 11.5.1.15)
"DC++" = DC++ 0.667
"Dell Game Console" = Dell Game Console
"Dell Photo AIO Printer 924" = Dell Photo AIO Printer 924
"Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP)
"DWG TrueView 2010" = DWG TrueView 2010
"EES - Engineering Equation Solver (Limited Academic Version)" = EES - Engineering Equation Solver (Limited Academic Version)
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"ENTERPRISER" = Microsoft Office Enterprise 2007
"F2F24872454C7CAEAABD8BB063F70FBEFF01989D" = Windows Driver Package - FTDI CDM Driver Package (03/13/2008 2.04.06)
"FF9C6C89964495D9F1AC86587EF985784D8AD152" = Windows Driver Package - Intel (NETw3x32) net (10/17/2006 10.5.1.72)
"Free Video Flip and Rotate_is1" = Free Video Flip and Rotate version 1.5
"GENEUIDE" = USB Storage Driver
"GTK 2.0" = GTK+ Runtime 2.6.9 rev a (remove only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{200FF4D5-1784-437A-A547-BFA7D735A5EB}" = Recording Station
"InterActual Player" = InterActual Player
"Java Platform, Enterprise Edition 5 SDK" = Java Platform, Enterprise Edition 5 SDK
"Lexmark 4300 Series" = Lexmark 4300 Series
"Lexmark Fax Solutions" = Lexmark Fax Solutions
"LiveUpdate" = LiveUpdate 3.1 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Matlab 6.5" = MATLAB 6.5
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual Studio 2005 Tools for Applications - ENU" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NI Uninstaller" = National Instruments Software
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa 3" = Picasa 3
"Prism_is1" = Prism 0.8
"ProInst" = Intel® PROSet/Wireless Software
"QcDrv" = Logitech® Camera Driver
"RealPlayer 6.0" = RealPlayer
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"Sibelius Scorch Plugin" = Sibelius Scorch Plugin
"SkillJam SecurePlayer" = Secure Game Player
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SolidWorks Installation Manager 20090-40300-1100-200" = SolidWorks 2009 SP03
"ST6UNST #1" = Advanced Control Shareware Version
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"Uninstall_is1" = Uninstall 1.0.0.1
"Video Converter 3" = Video Converter 3
"VLC media player" = VideoLAN VLC media player 0.8.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"InstallShield_{B9A81070-616D-4E93-BE02-CEE651343204}" = WD Anywhere Backup
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/27/2009 11:32:39 PM | Computer Name = NRUMMEL | Source = Application Error | ID = 1000
Description = Faulting application skypepm.exe, version 1.5.0.3, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 10/27/2009 11:34:41 PM | Computer Name = NRUMMEL | Source = Application Error | ID = 1000
Description = Faulting application skype.exe, version 3.5.0.229, faulting module
, version 0.0.0.0, fault address 0x00000000.

Error - 10/27/2009 11:35:51 PM | Computer Name = NRUMMEL | Source = Application Error | ID = 1000
Description = Faulting application skypepm.exe, version 1.5.0.3, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 10/27/2009 11:45:34 PM | Computer Name = NRUMMEL | Source = Symantec AntiVirus | ID = 16711725
Description =

Error - 10/27/2009 11:50:58 PM | Computer Name = NRUMMEL | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/28/2009 3:35:06 AM | Computer Name = NRUMMEL | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 memeolauncher.exe, P2 2.0.0.0, P3 46b24a74,
P4 system.configuration, P5 2.0.0.0, P6 4889de74, P7 277, P8 14, P9 ioibmurhynrxkw0zxkyrvfn0boyyufow,
P10 NIL.

Error - 10/28/2009 11:36:46 AM | Computer Name = NRUMMEL | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 memeolauncher.exe, P2 2.0.0.0, P3 46b24a74,
P4 system.configuration, P5 2.0.0.0, P6 4889de74, P7 277, P8 14, P9 ioibmurhynrxkw0zxkyrvfn0boyyufow,
P10 NIL.

Error - 10/28/2009 12:49:17 PM | Computer Name = NRUMMEL | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 memeolauncher.exe, P2 2.0.0.0, P3 46b24a74,
P4 system.configuration, P5 2.0.0.0, P6 4889de74, P7 277, P8 14, P9 ioibmurhynrxkw0zxkyrvfn0boyyufow,
P10 NIL.

Error - 10/28/2009 6:55:00 PM | Computer Name = NRUMMEL | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 memeolauncher.exe, P2 2.0.0.0, P3 46b24a74,
P4 system.configuration, P5 2.0.0.0, P6 4889de74, P7 277, P8 14, P9 ioibmurhynrxkw0zxkyrvfn0boyyufow,
P10 NIL.

Error - 10/29/2009 11:01:07 AM | Computer Name = NRUMMEL | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 memeolauncher.exe, P2 2.0.0.0, P3 46b24a74,
P4 system.configuration, P5 2.0.0.0, P6 4889de74, P7 277, P8 14, P9 ioibmurhynrxkw0zxkyrvfn0boyyufow,
P10 NIL.

[ OSession Events ]
Error - 12/1/2008 8:50:51 PM | Computer Name = NRUMMEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 332
seconds with 300 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 10/1/2009 6:52:24 PM | Computer Name = NRUMMEL | Source = Service Control Manager | ID = 7034
Description = The SupportSoft Sprocket Service (dellsupportcenter) service terminated
unexpectedly. It has done this 1 time(s).

Error - 10/2/2009 9:51:07 PM | Computer Name = NRUMMEL | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the wscsvc service.

Error - 10/3/2009 12:40:42 PM | Computer Name = NRUMMEL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to
connect.

Error - 10/3/2009 12:40:43 PM | Computer Name = NRUMMEL | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service LiveUpdate
with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}

Error - 10/3/2009 12:40:46 PM | Computer Name = NRUMMEL | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%1053

Error - 10/3/2009 12:41:56 PM | Computer Name = NRUMMEL | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.100 for the Network Card with network
address 0018DE0DD791 has been denied by the DHCP server 172.16.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 10/3/2009 4:06:19 PM | Computer Name = NRUMMEL | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 10/3/2009 4:06:19 PM | Computer Name = NRUMMEL | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 10/3/2009 9:53:19 PM | Computer Name = NRUMMEL | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 10/3/2009 9:53:19 PM | Computer Name = NRUMMEL | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.


< End of report >
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 29 2009, 05:10 PM
Post #13


GeekU Teacher
Group Icon
Posts: 35,111
From: Dublin
OS: XP



hi

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).




1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
File::
SRPeek::
C:\WINDOWS\System32\drivers\vaxscsi.sys

Mia::
C:\WINDOWS\System32\drivers\vaxscsi.sys
Folder::

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    CODE
    :OTL
    O24 - Desktop Components:0 (tets) - C:\WINDOWS\system32\onhelp.htm
    O32 - AutoRun File - [2007/02/14 12:27:46 | 00,000,000 | ---D | M] - D:\autorun -- [ NTFS ]
    O32 - AutoRun File - [2006/12/15 13:32:12 | 00,000,047 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
    O33 - MountPoints2\{1a517000-d909-11dc-8eee-0015c5a935eb}\Shell\AutoRun\command - "" = H:\wd_windows_tools\WDEULA.exe -- File not found
    O33 - MountPoints2\{4669c37e-c3dd-11de-8fa7-0015c5a935eb}\Shell - "" = AutoRun
    O33 - MountPoints2\{4669c37e-c3dd-11de-8fa7-0015c5a935eb}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{4669c37e-c3dd-11de-8fa7-0015c5a935eb}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found

    :Services

    :Reg

    :Files

    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Go to the top of the page
 
+Quote Post
nrummel
post Oct 30 2009, 12:34 AM
Post #14


Member
**
Posts: 13
OS: Windows 2000



GooredFix by jpshortstuff (24.09.09.1)
Log created at 23:33 on 29/10/2009 (Nick Rummel)
Firefox version 3.0.13 (en-US)

========== GooredScan ==========

Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{69718F4B-3565-4D65-B418-A321269E8B74} -> Success!
Deleting C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\{69718F4B-3565-4D65-B418-A321269E8B74} -> Success!

========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{3112ca9c-de6d-4884-a869-9855de68056c} [01:41 06/09/2006]
{972ce4c6-7e08-4474-a285-3208198ce6fd} [05:48 16/04/2009]
{B13721C7-F507-4982-B2E5-502A71474FED} [00:38 31/08/2007]
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [08:37 15/04/2007]
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [01:14 19/08/2007]
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [05:21 30/10/2007]
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [18:15 21/08/2008]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{B7082FAA-CB62-4872-9106-E42DD88EDE45}"="C:\Program Files\McAfee\SiteAdvisor" [21:12 09/06/2008]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [04:58 05/06/2009]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [04:35 06/12/2009]

-=E.O.F=-
Go to the top of the page
 
+Quote Post
nrummel
post Oct 30 2009, 01:27 AM
Post #15


Member
**
Posts: 13
OS: Windows 2000



ComboFix 09-10-28.08 - Nick Rummel 10/29/2009 23:58.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.434 [GMT -7:00]
Running from: c:\documents and settings\Nick Rummel\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Nick Rummel\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

Infected copy of c:\windows\system32\drivers\vaxscsi.sys was found and disinfected
Restored copy from - Kitty ate it tongue.gif
.
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-30 )))))))))))))))))))))))))))))))
.

2009-12-06 04:33 . 2009-12-06 04:33 -------- dc----w- c:\windows\system32\XPSViewer
2009-12-06 04:31 . 2009-12-06 04:31 -------- dc----w- c:\program files\Reference Assemblies
2009-12-06 04:29 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\xpsshhdr.dll
2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-12-06 04:29 . 2008-07-06 12:06 117760 -c----w- c:\windows\system32\prntvpt.dll
2009-12-06 04:29 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\xpssvcs.dll
2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-12-06 04:28 . 2009-08-06 03:54 -------- dc----w- c:\windows\SxsCaPendDel
2009-10-29 15:20 . 2009-10-29 15:20 -------- dc----w- c:\program files\SiteAdvisor
2009-10-28 22:42 . 2009-10-28 22:42 -------- dc----w- C:\_OTM
2009-10-28 14:55 . 2009-10-28 14:56 -------- dc----w- C:\Combo-Fix
2009-10-26 23:34 . 2006-03-03 15:07 143360 -c--a-w- c:\windows\system32\dunzip32.dll
2009-10-26 01:59 . 2009-09-16 17:22 34248 -c--a-w- c:\windows\system32\drivers\mferkdk.sys
2009-10-26 01:59 . 2009-09-16 17:22 40552 -c--a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-10-26 01:59 . 2009-09-16 17:22 35272 -c--a-w- c:\windows\system32\drivers\mfebopk.sys
2009-10-26 01:59 . 2009-09-16 17:22 79816 -c--a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-10-26 01:59 . 2009-09-16 17:22 214664 -c--a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-26 01:59 . 2009-07-16 19:32 120136 -c--a-w- c:\windows\system32\drivers\Mpfp.sys
2009-10-26 01:57 . 2009-10-26 01:58 -------- dc----w- c:\program files\McAfee.com
2009-10-26 01:25 . 2009-10-26 01:37 -------- dc----w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\AskToolbar
2009-10-23 06:49 . 2009-10-23 06:49 -------- dc----w- c:\program files\Ask.com
2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\Common Files\DVDVideoSoft
2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\DVDVideoSoft
2009-10-21 23:40 . 2009-10-21 23:40 -------- dc----w- C:\EmergencyUtils
2009-10-15 04:30 . 2009-10-29 03:35 -------- dc--a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-04 01:12 . 2009-10-04 01:12 -------- dc----w- c:\program files\iPod
2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\program files\iTunes
2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-01 22:35 . 2009-10-01 22:35 287080 -c--a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-06 04:32 . 2008-01-11 18:01 -------- dc----w- c:\program files\MSBuild
2009-10-30 06:52 . 2009-09-09 02:26 -------- dc----w- c:\program files\Common Files\Akamai
2009-10-30 06:27 . 2007-08-31 00:39 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Skype
2009-10-30 02:44 . 2008-06-09 21:11 -------- dc----w- c:\program files\McAfee
2009-10-30 02:32 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-29 14:59 . 2009-09-11 03:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\IM
2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\program files\Common Files\Symantec Shared
2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\program files\Symantec
2009-10-28 04:02 . 2007-03-24 18:30 -------- dc----w- c:\program files\Symantec AntiVirus
2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-28 01:43 . 2008-08-08 04:17 -------- dc----w- c:\program files\Lx_cats
2009-10-28 01:39 . 2006-09-05 23:32 -------- dc----w- c:\program files\Dl_cats
2009-10-27 05:17 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-10-26 01:59 . 2008-06-09 21:12 -------- dc----w- c:\program files\Common Files\McAfee
2009-10-23 21:20 . 2007-05-17 18:06 -------- dc-h--w- c:\documents and settings\Nick Rummel\Application Data\Move Networks
2009-10-23 07:12 . 2008-02-11 02:48 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks
2009-10-16 17:37 . 2006-10-12 19:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\dvdcss
2009-10-04 01:12 . 2007-07-01 16:27 -------- dc----w- c:\program files\Common Files\Apple
2009-10-04 00:53 . 2007-12-10 02:00 -------- dc----w- c:\program files\Bonjour
2009-10-04 00:52 . 2007-07-16 02:03 -------- dc----w- c:\program files\QuickTime
2009-09-24 04:46 . 2008-05-20 03:28 -------- dc----w- c:\program files\AFT software
2009-09-24 04:46 . 2008-05-14 06:06 796672 -c--a-w- c:\windows\GPInstall.exe
2009-09-16 23:19 . 2009-09-16 23:19 -------- dc----w- c:\documents and settings\LocalService\Application Data\McAfee
2009-09-15 00:45 . 2009-09-15 00:40 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks 2009
2009-09-15 00:02 . 2009-09-15 00:02 3026 -c--a-w- c:\windows\system32\drivers\hwinterface.sys
2009-09-15 00:02 . 2006-09-05 23:14 152872 -c--a-w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 14:18 . 2005-08-16 09:18 136192 -c--a-w- c:\windows\system32\msv1_0.dll
2009-09-11 06:09 . 2008-01-11 17:48 -------- dc----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-11 06:05 . 2008-02-11 02:18 -------- dc----w- c:\program files\Common Files\SolidWorks Shared
2009-09-11 05:59 . 2009-09-11 05:58 -------- dc----w- c:\program files\AGEIA Technologies
2009-09-11 05:58 . 2009-02-25 01:24 -------- dc----w- c:\documents and settings\All Users\Application Data\SolidWorks
2009-09-11 05:52 . 2009-09-11 05:52 -------- dc----w- c:\program files\MSECache
2009-09-11 05:48 . 2009-09-11 05:47 -------- dc----w- c:\program files\Microsoft Visual Studio 8
2009-09-11 03:26 . 2009-09-11 03:25 -------- dc----w- c:\program files\Common Files\SolidWorks Installation Manager
2009-09-10 07:25 . 2008-01-18 06:30 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Autodesk
2009-09-10 07:23 . 2009-09-09 06:24 -------- dc----w- c:\documents and settings\All Users\Application Data\Autodesk
2009-09-09 06:40 . 2009-09-09 06:18 -------- dc----w- c:\program files\Autodesk
2009-09-09 06:38 . 2008-01-18 06:25 -------- dc----w- c:\program files\Common Files\Autodesk Shared
2009-09-09 06:25 . 2009-09-09 06:24 -------- dc----w- c:\program files\DWG TrueView 2010
2009-09-09 06:13 . 2006-08-28 06:28 -------- dc-h--w- c:\program files\InstallShield Installation Information
2009-09-04 21:03 . 2005-08-16 09:18 58880 -c--a-w- c:\windows\system32\msasn1.dll
2009-09-01 05:59 . 2009-09-01 05:05 -------- dc----w- c:\program files\Common Files\LogiShrd
2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logishrd
2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logitech
2009-09-01 05:04 . 2009-09-01 01:00 -------- dc----w- c:\program files\Logitech
2009-09-01 04:06 . 2009-04-07 05:02 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-29 07:36 . 2005-08-16 09:18 832512 -c----w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2005-08-16 09:18 78336 -c--a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2005-08-16 09:18 17408 -c----w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2005-08-16 09:19 247326 -c--a-w- c:\windows\system32\strmdll.dll
2009-08-25 05:59 . 2006-09-22 02:21 3766 -csha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-25 05:59 . 2006-09-22 02:21 88 -csh--r- c:\windows\system32\68430E414D.sys
2009-08-07 02:24 . 2005-08-16 09:40 327896 -c--a-w- c:\windows\system32\wucltui.dll
2009-08-07 02:24 . 2005-08-16 09:40 209632 -c--a-w- c:\windows\system32\wuweb.dll
2009-08-07 02:24 . 2005-08-16 09:40 35552 -c--a-w- c:\windows\system32\wups.dll
2009-08-07 02:24 . 2005-05-26 11:16 44768 -c--a-w- c:\windows\system32\wups2.dll
2009-08-07 02:24 . 2005-08-16 09:40 53472 -c----w- c:\windows\system32\wuauclt.exe
2009-08-07 02:24 . 2005-08-16 09:18 96480 -c--a-w- c:\windows\system32\cdm.dll
2009-08-07 02:23 . 2005-08-16 09:40 575704 -c--a-w- c:\windows\system32\wuapi.dll
2009-08-07 02:23 . 2005-08-16 09:40 1929952 -c--a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2005-08-16 09:18 204800 -c--a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 2005-08-16 09:18 2145280 -c----w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-04 03:59 2023936 -c----w- c:\windows\system32\ntkrnlpa.exe
2006-12-07 01:49 . 2006-12-07 01:49 592 -c--a-w- c:\program files\Opera.lnk
2006-09-06 01:35 . 2006-09-06 01:35 1626 -c--a-w- c:\program files\QuickTime Player.lnk
2006-09-06 01:14 . 2006-09-06 01:14 841 -c--a-w- c:\program files\Ad-Aware SE Personal.lnk
2006-09-05 23:34 . 2006-09-05 23:34 1753 -c--a-w- c:\program files\Dell Printer Supplies - Inkjet.lnk
2006-09-05 23:01 . 2006-09-05 23:01 786 -c--a-w- c:\program files\Windows Media Player.lnk
2006-08-29 15:54 . 2006-08-29 15:54 1752 -c--a-w- c:\program files\main.ini
2006-08-28 06:56 . 2006-08-28 06:56 1967 -c--a-w- c:\program files\Internet Service Offers.lnk
2006-08-28 06:56 . 2006-08-28 06:56 1965 -c--a-w- c:\program files\Games, Music, & Photos.lnk
2006-08-28 06:56 . 2006-08-28 06:56 1958 -c--a-w- c:\program files\Documentation & Support.lnk
2006-08-28 06:45 . 2006-08-28 06:45 1661 -c--a-w- c:\program files\Trend Micro PC-cillin Internet Security 12.lnk
2005-08-16 09:52 . 2006-09-05 23:01 1298 -c--a-w- c:\program files\Media Center.lnk
2005-10-12 22:04 . 2005-10-12 22:04 131072 -c--a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 17:48 . 2007-02-08 17:48 133920 -c--a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
.

(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))

[-] !HASH: COULD NOT OPEN FILE !!!!! 223128 c:\windows\system32\drivers\vaxscsi.sys
[7] 92CEBC2BC7BE2C8D49391B365569F306 223128 \RP108\A0053002.sys
[7] 92CEBC2BC7BE2C8D49391B365569F306 223128 \RP110\A0057657.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-10-28_01.43.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-30 06:52 . 2009-10-30 06:52 16384 c:\windows\Temp\Perflib_Perfdata_930.dat
+ 2009-10-28 22:34 . 2009-10-30 07:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-09-05 22:48 . 2009-10-30 07:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-09-05 22:48 . 2009-10-27 18:58 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-09-05 22:48 . 2009-10-27 18:58 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-10-28 22:34 . 2009-10-30 07:05 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-10-29 16:15 . 2009-10-29 16:15 20480 c:\windows\assembly\GAC\ArbusApplicationController\1.0.3093.38280__da57d5d39b1d6dd8\ArbusApplicationController.dll
+ 2009-10-29 16:15 . 2009-10-29 16:15 20480 c:\windows\assembly\GAC\Arbus.Interfacing.Library\1.0.4.0__2be3a081d8c94867\Arbus.Interfacing.Library.dll
+ 2009-10-29 16:12 . 2009-10-29 16:12 152872 c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
+ 2009-10-29 16:15 . 2009-10-29 16:15 126976 c:\windows\assembly\GAC\Arbus.Common\2.2.4.3__14cac4d33a885ed2\Arbus.Common.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-06-17 00:22 1144712 -c--a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-07 68856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-14 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-14 118784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-05 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-12-04 185896]
"Dell QuickSet"="c:\progra~1\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-10 270336]
"realteks"="c:\documents and settings\Nick Rummel\Application Data\Google\tncfc7316459.exe" [2009-07-15 0]
"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]
"lxcemon.exe"="c:\program files\Lexmark 4300 Series\lxcemon.exe" [2005-08-02 192512]
"EzPrint"="c:\program files\Lexmark 4300 Series\ezprint.exe" [2005-07-26 94208]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 488984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 774168]
"SolidWorks_CheckForUpdates"="c:\program files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe" [2009-03-20 7308584]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-25 282624]
"WD Button Manager"="WDBtnMgr.exe" - c:\windows\system32\WDBtnMgr.exe [2009-06-11 364544]

c:\documents and settings\Nick Rummel\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
WD Anywhere Backup Launcher.lnk - c:\documents and settings\Nick Rummel\Application Data\Microsoft\Installer\{B9A81070-616D-4E93-BE02-CEE651343204}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe [2008-2-13 17542]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-27 24576]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2006-3-26 257752]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= c:\windows\system32\onhelp.htm
FriendlyName= tets

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-09-03 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-09-03 18:40 352256 -c--a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Nick Rummel\\My Documents\\My Completed Downloads\\eclipse-cpp-europa-win32\\eclipse\\eclipse.exe"=
"c:\\Program Files\\Java\\jdk1.5.0_09\\jre\\bin\\java.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"=
"c:\\Program Files\\National Instruments\\Shared\\Example Finder\\1.0\\BIN\\NIExampleFinder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [9/14/2009 5:02 PM 3026]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [10/10/2006 12:53 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 11:39 AM 55024]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/16/2005 2:18 AM 14336]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [6/9/2008 2:12 PM 92296]
S2 DellBIOS;DellBIOS;\??\c:\windows\DellBIOS.Sys --> c:\windows\DellBIOS.Sys [?]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe --> h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe [?]
S3 EraserUtilDrvI9;EraserUtilDrvI9;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [4/6/2009 10:03 PM 38496]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [8/6/2009 7:06 PM 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [8/6/2009 7:06 PM 8320]
S3 PAC207;CIF USB Camera;c:\windows\system32\drivers\PFC027.SYS [1/2/2009 1:15 PM 505984]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 4:51 PM 4096]
S3 TBU11;Turtle Beach USB MIDI 1x1 Driver;c:\windows\system32\drivers\tbu11.sys [8/4/2007 2:26 PM 13824]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808]

--- Other Services/Drivers In Memory ---

*Deregistered* - mbr

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder

2009-10-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-10-26 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 19:22]

2009-10-26 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 19:22]

2009-10-30 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-06-17 00:22]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Nick Rummel\Application Data\Mozilla\Firefox\Profiles\8j7bdunq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-30 00:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1313456098-3368236134-1419899362-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:5f,bd,1d,4e,48,20,11,db,c5,d2,3d,f5,fd,a2,c5,27,c8,7c,f3,0c,b0,8c,65,
e7,a0,af,e6,ea,11,15,15,45,ed,f1,e1,34,d6,32,85,f7,f5,d5,9c,cd,1f,a4,98,68,\
"??"=hex:47,b8,eb,31,6d,80,25,0b,86,7e,89,00,84,30,b1,12

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ }*Ć]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(920)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2009-10-30 0:24
ComboFix-quarantined-files.txt 2009-10-30 07:23
ComboFix2.txt 2009-10-28 15:49
ComboFix3.txt 2009-10-28 02:25

Pre-Run: 4,422,221,824 bytes free
Post-Run: 4,450,861,056 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 63469C5B76BCA8F6D45A4118BE830513
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 21st November 2009 - 07:06 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising