Google Redirections & Cannot Access McAfee Website [Solved] |
![]() ![]() |
Google Redirections & Cannot Access McAfee Website [Solved] |
Oct 27 2009, 09:16 AM
Post
#1
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows 2000 |
I use firefox, and it often closes with an error and makes me restart it. Also, about half of the time when I click on a link, it takes me to the wrong webpage. I just recently tried to go to McAfee's website, but could not get there because an error would come up on the page saying it couldn't access the website. When looking around online to find a fix, I found a post on this website by a person with the exact same problem (same topic title). I just ran rootrepeal like they did, and I've attached the report. What now? Please help me! Thanks in advance.
ps - just yesterday I got a virus or something that kept having a "Safety Center" window pop that looked like a windows icon, telling me something was wrong and to do certain things. I ran malwarbytes and deleted the files, but I'm not sure I completely removed it... also, I've had another virus in the past that was windows police (I think that's what it was called) and I run my virus scan an remove it, but it still comes back occasionally. Not sure if these are related to the original problem, but would appreciate help with them too. My computer is sick!
Attached File(s)
|
|
|
Oct 27 2009, 09:16 AM
Post
#2
|
|
![]() GeekU Teacher Posts: 35,111 From: Dublin OS: XP |
hi
Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall** |
|
|
Oct 27 2009, 08:29 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows 2000 |
ComboFix 09-10-26.06 - Nick Rummel 10/27/2009 17:35.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.347 [GMT -7:00] Running from: c:\documents and settings\Nick Rummel\Desktop\Combo-Fix.exe AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Nick Rummel\nah_tbrp.exe c:\program files\Mozilla Firefox\chrome\amba.jar c:\windows\Downloaded Program Files\IDropPTB.dll c:\windows\Downloaded Program Files\popcaploader.inf c:\windows\kb913800.exe c:\windows\ofx.icn c:\windows\ppp3.dat c:\windows\ppp4.dat c:\windows\system32\bennuar.old c:\windows\system32\bincd32.dat c:\windows\system32\dmibsctw.ini c:\windows\system32\drivers\svchost.exe c:\windows\system32\htpsojmm.ini c:\windows\system32\idfxcutw.ini c:\windows\system32\images c:\windows\system32\images\i1.gif c:\windows\system32\images\i2.gif c:\windows\system32\images\i3.gif c:\windows\system32\images\j1.gif c:\windows\system32\images\j2.gif c:\windows\system32\images\j3.gif c:\windows\system32\images\jj1.gif c:\windows\system32\images\jj2.gif c:\windows\system32\images\jj3.gif c:\windows\system32\images\l1.gif c:\windows\system32\images\l2.gif c:\windows\system32\images\l3.gif c:\windows\system32\images\pix.gif c:\windows\system32\images\t1.gif c:\windows\system32\images\t2.gif c:\windows\system32\images\up1.gif c:\windows\system32\images\up2.gif c:\windows\system32\images\w1.gif c:\windows\system32\images\w11.gif c:\windows\system32\images\w2.gif c:\windows\system32\images\w3.gif c:\windows\system32\images\w3.jpg c:\windows\system32\images\wt1.gif c:\windows\system32\images\wt2.gif c:\windows\system32\images\wt3.gif c:\windows\system32\kycnnjqd.ini c:\windows\system32\mvtinywq.ini c:\windows\system32\schtml c:\windows\system32\schtml\dbsinit.exe c:\windows\system32\schtml\images\i1.gif c:\windows\system32\schtml\images\i2.gif c:\windows\system32\schtml\images\i3.gif c:\windows\system32\schtml\images\j1.gif c:\windows\system32\schtml\images\j2.gif c:\windows\system32\schtml\images\j3.gif c:\windows\system32\schtml\images\jj1.gif c:\windows\system32\schtml\images\jj2.gif c:\windows\system32\schtml\images\jj3.gif c:\windows\system32\schtml\images\l1.gif c:\windows\system32\schtml\images\l2.gif c:\windows\system32\schtml\images\l3.gif c:\windows\system32\schtml\images\pix.gif c:\windows\system32\schtml\images\t1.gif c:\windows\system32\schtml\images\t2.gif c:\windows\system32\schtml\images\up1.gif c:\windows\system32\schtml\images\up2.gif c:\windows\system32\schtml\images\w1.gif c:\windows\system32\schtml\images\w11.gif c:\windows\system32\schtml\images\w2.gif c:\windows\system32\schtml\images\w3.gif c:\windows\system32\schtml\images\w3.jpg c:\windows\system32\schtml\images\word.doc c:\windows\system32\schtml\images\wt1.gif c:\windows\system32\schtml\images\wt2.gif c:\windows\system32\schtml\images\wt3.gif c:\windows\system32\schtml\wispex.html c:\windows\system32\sonhelp.htm c:\windows\system32\sxubvvbn.ini c:\windows\system32\sysnet.dat c:\windows\system32\TAdgQtwa.ini c:\windows\system32\TAdgQtwa.ini2 c:\windows\system32\tctumxfs.ini c:\windows\system32\torsxadm.ini c:\windows\system32\wispex.html c:\windows\system32\XbaIRXbc.ini c:\windows\system32\xcgmsqlj.ini D:\AUTORUN.INF Infected copy of c:\windows\system32\drivers\vaxscsi.sys was found and disinfected Restored copy from - Kitty ate it . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ANTIPPRO2009_100 -------\Legacy_NWCWORKSTATION -------\Service_AntipPro2009_100 -------\Service_NWCWorkstation ((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 ))))))))))))))))))))))))))))))) . 2009-12-06 04:33 . 2009-12-06 04:33 -------- dc----w- c:\windows\system32\XPSViewer 2009-12-06 04:31 . 2009-12-06 04:31 -------- dc----w- c:\program files\Reference Assemblies 2009-12-06 04:29 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\xpsshhdr.dll 2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll 2009-12-06 04:29 . 2008-07-06 12:06 117760 -c----w- c:\windows\system32\prntvpt.dll 2009-12-06 04:29 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\xpssvcs.dll 2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll 2009-12-06 04:28 . 2009-08-06 03:54 -------- dc----w- c:\windows\SxsCaPendDel 2009-10-26 23:34 . 2006-03-03 15:07 143360 -c--a-w- c:\windows\system32\dunzip32.dll 2009-10-26 01:59 . 2007-11-22 13:44 33832 -c--a-w- c:\windows\system32\drivers\mferkdk.sys 2009-10-26 01:59 . 2007-12-02 19:51 40488 -c--a-w- c:\windows\system32\drivers\mfesmfk.sys 2009-10-26 01:59 . 2007-11-22 13:44 35240 -c--a-w- c:\windows\system32\drivers\mfebopk.sys 2009-10-26 01:59 . 2007-11-22 13:44 79304 -c--a-w- c:\windows\system32\drivers\mfeavfk.sys 2009-10-26 01:59 . 2007-11-22 13:44 201320 -c--a-w- c:\windows\system32\drivers\mfehidk.sys 2009-10-26 01:59 . 2007-07-13 13:20 113952 -c--a-w- c:\windows\system32\drivers\Mpfp.sys 2009-10-26 01:57 . 2009-10-26 01:58 -------- dc----w- c:\program files\McAfee.com 2009-10-26 01:25 . 2009-10-26 01:37 -------- dc----w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\AskToolbar 2009-10-23 06:49 . 2009-10-23 06:49 -------- dc----w- c:\program files\Ask.com 2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\Common Files\DVDVideoSoft 2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\DVDVideoSoft 2009-10-21 23:40 . 2009-10-21 23:40 -------- dc----w- C:\EmergencyUtils 2009-10-15 04:30 . 2009-10-28 01:40 -------- dc--a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-10-15 04:00 . 2009-10-20 01:31 58 -c--a-w- c:\windows\wp4.dat 2009-10-15 04:00 . 2009-10-20 01:31 1 -c--a-w- c:\windows\wp3.dat 2009-10-04 01:12 . 2009-10-04 01:12 -------- dc----w- c:\program files\iPod 2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\program files\iTunes 2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-10-01 22:35 . 2009-10-01 22:35 287080 -c--a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-06 04:32 . 2008-01-11 18:01 -------- dc----w- c:\program files\MSBuild 2009-10-28 01:43 . 2008-08-08 04:17 -------- dc----w- c:\program files\Lx_cats 2009-10-28 01:39 . 2006-09-05 23:32 -------- dc----w- c:\program files\Dl_cats 2009-10-28 01:34 . 2009-09-09 02:26 -------- dc----w- c:\program files\Common Files\Akamai 2009-10-28 01:31 . 2007-03-24 18:30 -------- dc----w- c:\program files\Symantec AntiVirus 2009-10-28 00:24 . 2008-06-09 21:11 -------- dc----w- c:\program files\McAfee 2009-10-27 05:42 . 2007-08-31 00:39 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Skype 2009-10-27 05:17 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\SiteAdvisor 2009-10-26 23:41 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\McAfee 2009-10-26 01:59 . 2008-06-09 21:12 -------- dc----w- c:\program files\Common Files\McAfee 2009-10-23 21:20 . 2007-05-17 18:06 -------- dc-h--w- c:\documents and settings\Nick Rummel\Application Data\Move Networks 2009-10-23 07:12 . 2008-02-11 02:48 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks 2009-10-16 17:37 . 2006-10-12 19:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\dvdcss 2009-10-04 01:12 . 2007-07-01 16:27 -------- dc----w- c:\program files\Common Files\Apple 2009-10-04 00:53 . 2007-12-10 02:00 -------- dc----w- c:\program files\Bonjour 2009-10-04 00:52 . 2007-07-16 02:03 -------- dc----w- c:\program files\QuickTime 2009-09-24 04:46 . 2008-05-20 03:28 -------- dc----w- c:\program files\AFT software 2009-09-24 04:46 . 2008-05-14 06:06 796672 -c--a-w- c:\windows\GPInstall.exe 2009-09-16 23:19 . 2009-09-16 23:19 -------- dc----w- c:\documents and settings\LocalService\Application Data\McAfee 2009-09-15 00:45 . 2009-09-15 00:40 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks 2009 2009-09-15 00:02 . 2009-09-15 00:02 3026 -c--a-w- c:\windows\system32\drivers\hwinterface.sys 2009-09-15 00:02 . 2006-09-05 23:14 152872 -c--a-w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-11 14:18 . 2005-08-16 09:18 136192 -c--a-w- c:\windows\system32\msv1_0.dll 2009-09-11 06:18 . 2009-09-11 03:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\IM 2009-09-11 06:09 . 2008-01-11 17:48 -------- dc----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-09-11 06:05 . 2008-02-11 02:18 -------- dc----w- c:\program files\Common Files\SolidWorks Shared 2009-09-11 05:59 . 2009-09-11 05:58 -------- dc----w- c:\program files\AGEIA Technologies 2009-09-11 05:58 . 2009-02-25 01:24 -------- dc----w- c:\documents and settings\All Users\Application Data\SolidWorks 2009-09-11 05:52 . 2009-09-11 05:52 -------- dc----w- c:\program files\MSECache 2009-09-11 05:48 . 2009-09-11 05:47 -------- dc----w- c:\program files\Microsoft Visual Studio 8 2009-09-11 03:26 . 2009-09-11 03:25 -------- dc----w- c:\program files\Common Files\SolidWorks Installation Manager 2009-09-10 07:25 . 2008-01-18 06:30 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Autodesk 2009-09-10 07:23 . 2009-09-09 06:24 -------- dc----w- c:\documents and settings\All Users\Application Data\Autodesk 2009-09-09 06:40 . 2009-09-09 06:18 -------- dc----w- c:\program files\Autodesk 2009-09-09 06:38 . 2008-01-18 06:25 -------- dc----w- c:\program files\Common Files\Autodesk Shared 2009-09-09 06:25 . 2009-09-09 06:24 -------- dc----w- c:\program files\DWG TrueView 2010 2009-09-09 06:13 . 2006-08-28 06:28 -------- dc-h--w- c:\program files\InstallShield Installation Information 2009-09-04 21:03 . 2005-08-16 09:18 58880 -c--a-w- c:\windows\system32\msasn1.dll 2009-09-01 05:59 . 2009-09-01 05:05 -------- dc----w- c:\program files\Common Files\LogiShrd 2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logishrd 2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logitech 2009-09-01 05:04 . 2009-09-01 01:00 -------- dc----w- c:\program files\Logitech 2009-09-01 04:06 . 2009-04-07 05:02 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware 2009-08-29 07:36 . 2005-08-16 09:18 832512 -c--a-w- c:\windows\system32\wininet.dll 2009-08-29 07:36 . 2005-08-16 09:18 78336 -c--a-w- c:\windows\system32\ieencode.dll 2009-08-29 07:36 . 2005-08-16 09:18 17408 -c----w- c:\windows\system32\corpol.dll 2009-08-26 08:00 . 2005-08-16 09:19 247326 -c--a-w- c:\windows\system32\strmdll.dll 2009-08-25 05:59 . 2006-09-22 02:21 3766 -csha-w- c:\windows\system32\KGyGaAvL.sys 2009-08-25 05:59 . 2006-09-22 02:21 88 -csh--r- c:\windows\system32\68430E414D.sys 2009-08-07 02:24 . 2005-08-16 09:40 327896 -c--a-w- c:\windows\system32\wucltui.dll 2009-08-07 02:24 . 2005-08-16 09:40 209632 -c--a-w- c:\windows\system32\wuweb.dll 2009-08-07 02:24 . 2005-08-16 09:40 35552 -c--a-w- c:\windows\system32\wups.dll 2009-08-07 02:24 . 2005-05-26 11:16 44768 -c--a-w- c:\windows\system32\wups2.dll 2009-08-07 02:24 . 2005-08-16 09:40 53472 -c--a-w- c:\windows\system32\wuauclt.exe 2009-08-07 02:24 . 2005-08-16 09:18 96480 -c--a-w- c:\windows\system32\cdm.dll 2009-08-07 02:23 . 2005-08-16 09:40 575704 -c--a-w- c:\windows\system32\wuapi.dll 2009-08-07 02:23 . 2005-08-16 09:40 1929952 -c--a-w- c:\windows\system32\wuaueng.dll 2009-08-05 09:01 . 2005-08-16 09:18 204800 -c--a-w- c:\windows\system32\mswebdvd.dll 2009-08-04 15:13 . 2005-08-16 09:18 2145280 -c--a-w- c:\windows\system32\ntoskrnl.exe 2009-08-04 14:20 . 2004-08-04 03:59 2023936 -c--a-w- c:\windows\system32\ntkrnlpa.exe 2006-12-07 01:49 . 2006-12-07 01:49 592 -c--a-w- c:\program files\Opera.lnk 2006-09-06 01:35 . 2006-09-06 01:35 1626 -c--a-w- c:\program files\QuickTime Player.lnk 2006-09-06 01:14 . 2006-09-06 01:14 841 -c--a-w- c:\program files\Ad-Aware SE Personal.lnk 2006-09-05 23:34 . 2006-09-05 23:34 1753 -c--a-w- c:\program files\Dell Printer Supplies - Inkjet.lnk 2006-09-05 23:01 . 2006-09-05 23:01 786 -c--a-w- c:\program files\Windows Media Player.lnk 2006-08-29 15:54 . 2006-08-29 15:54 1752 -c--a-w- c:\program files\main.ini 2006-08-28 06:56 . 2006-08-28 06:56 1967 -c--a-w- c:\program files\Internet Service Offers.lnk 2006-08-28 06:56 . 2006-08-28 06:56 1965 -c--a-w- c:\program files\Games, Music, & Photos.lnk 2006-08-28 06:56 . 2006-08-28 06:56 1958 -c--a-w- c:\program files\Documentation & Support.lnk 2006-08-28 06:45 . 2006-08-28 06:45 1661 -c--a-w- c:\program files\Trend Micro PC-cillin Internet Security 12.lnk 2005-08-16 09:52 . 2006-09-05 23:01 1298 -c--a-w- c:\program files\Media Center.lnk 2005-10-12 22:04 . 2005-10-12 22:04 131072 -c--a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll 2007-02-08 17:48 . 2007-02-08 17:48 133920 -c--a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2009-06-17 00:22 1144712 -c--a-w- c:\program files\Ask.com\GenericAskToolbar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712] [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712] [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176] "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-07 68856] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-14 98304] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-14 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-14 118784] "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718] "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960] "DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728] "dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080] "DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2007-04-10 4376328] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-05 148888] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-12-04 185896] "Dell QuickSet"="c:\progra~1\Dell\QuickSet\quickset.exe" [2006-04-06 1032192] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392] "tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-10 270336] "realteks"="c:\documents and settings\Nick Rummel\Application Data\Google\tncfc7316459.exe" [2009-07-15 0] "LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728] "lxcemon.exe"="c:\program files\Lexmark 4300 Series\lxcemon.exe" [2005-08-02 192512] "EzPrint"="c:\program files\Lexmark 4300 Series\ezprint.exe" [2005-07-26 94208] "FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008] "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 488984] "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 774168] "SolidWorks_CheckForUpdates"="c:\program files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe" [2009-03-20 7308584] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992] "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-25 282624] "WD Button Manager"="WDBtnMgr.exe" - c:\windows\system32\WDBtnMgr.exe [2009-06-11 364544] c:\documents and settings\Nick Rummel\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632] WD Anywhere Backup Launcher.lnk - c:\documents and settings\Nick Rummel\Application Data\Microsoft\Installer\{B9A81070-616D-4E93-BE02-CEE651343204}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe [2008-2-13 17542] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696] Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-27 24576] Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920] Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2006-3-26 257752] [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] Source= c:\windows\system32\onhelp.htm FriendlyName= tets [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-09-03 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-09-03 18:40 352256 -c--a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ \0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\DC++\\DCPlusPlus.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\DAP\\DAP.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Documents and Settings\\Nick Rummel\\My Documents\\My Completed Downloads\\eclipse-cpp-europa-win32\\eclipse\\eclipse.exe"= "c:\\Program Files\\Java\\jdk1.5.0_09\\jre\\bin\\java.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"= "c:\\Program Files\\National Instruments\\Shared\\Example Finder\\1.0\\BIN\\NIExampleFinder.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "%windir%\\system32\\drivers\\svchost.exe"= "c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"= "c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [9/14/2009 5:02 PM 3026] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [10/10/2006 12:53 PM 8944] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 11:39 AM 55024] R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/16/2005 2:18 AM 14336] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [6/9/2008 2:12 PM 92296] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/18/2009 10:14 PM 102448] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 4:51 PM 4096] S2 DellBIOS;DellBIOS;\??\c:\windows\DellBIOS.Sys --> c:\windows\DellBIOS.Sys [?] S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe --> h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe [?] S3 EraserUtilDrvI9;EraserUtilDrvI9;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys [?] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [4/6/2009 10:03 PM 38496] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [8/6/2009 7:06 PM 136704] S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [8/6/2009 7:06 PM 8320] S3 PAC207;CIF USB Camera;c:\windows\system32\drivers\PFC027.SYS [1/2/2009 1:15 PM 505984] S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/27/2006 8:33 PM 116464] S3 TBU11;Turtle Beach USB MIDI 1x1 Driver;c:\windows\system32\drivers\tbu11.sys [8/4/2007 2:26 PM 13824] S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808] --- Other Services/Drivers In Memory --- *Deregistered* - mbr [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ilitteul . Contents of the 'Scheduled Tasks' folder 2009-10-25 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34] 2009-10-26 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 20:32] 2009-10-26 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 20:32] 2009-10-28 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job - c:\program files\Ask.com\UpdateTask.exe [2009-06-17 00:22] . . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm IE: &Download with &DAP - c:\program files\DAP\dapextie.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Nick Rummel\Application Data\Mozilla\Firefox\Profiles\8j7bdunq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/ FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071503000010.dll FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071505000010.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - HiddenExtension: XUL Cache: {69718F4B-3565-4D65-B418-A321269E8B74} - c:\documents and settings\Nick Rummel\Local Settings\Application Data\{69718F4B-3565-4D65-B418-A321269E8B74}\ FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true. - - - - ORPHANS REMOVED - - - - BHO-{CD292324-974F-4224-B904-98B907348B5B} - c:\progra~1\NY-YAN~1.NET\Toolbar\Toolbar.dll Toolbar-{CD292324-974F-4224-B904-98B907348B5B} - c:\progra~1\NY-YAN~1.NET\Toolbar\Toolbar.dll WebBrowser-{CD292324-974F-4224-B904-98B907348B5B} - c:\progra~1\NY-YAN~1.NET\Toolbar\Toolbar.dll HKU-Default-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe AddRemove-EZJava - c:\program files\ezjava\bin\ezjavauninstl.exe AddRemove-myTunes Redux_is1 - c:\program files\myTunes Redux\unins000.exe AddRemove-Win Police Pro - c:\program files\Windows Police Pro\AntiSpyware_Uninstall.exe AddRemove-{B3B4E8E4-E2A4-11D6-8D31-00105A629F49} - c:\program files\eMedia Guitar Basics\Uninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-27 18:38 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1313456098-3368236134-1419899362-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:5f,bd,1d,4e,48,20,11,db,c5,d2,3d,f5,fd,a2,c5,27,c8,7c,f3,0c,b0,8c,65, e7,a0,af,e6,ea,11,15,15,45,ed,f1,e1,34,d6,32,85,f7,f5,d5,9c,cd,1f,a4,98,68,\ "??"=hex:47,b8,eb,31,6d,80,25,0b,86,7e,89,00,84,30,b1,12 [HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ }*Ć] "Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(948) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(652) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\mshtml.dll c:\windows\IME\SPGRMR.DLL c:\windows\system32\msi.dll c:\progra~1\COMMON~1\Stardock\MCPCore.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\S24EvMon.exe c:\program files\Intel\Wireless\Bin\WLKeeper.exe c:\program files\Common Files\Symantec Shared\ccSetMgr.exe c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Symantec AntiVirus\DefWatch.exe c:\windows\eHome\ehRecvr.exe c:\windows\eHome\ehSched.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\lkcitdl.exe c:\windows\system32\lkads.exe c:\windows\system32\lktsrv.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\progra~1\mcafee.com\agent\mcagent.exe c:\progra~1\McAfee\VIRUSS~1\mcshield.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\McAfee\MPF\MPFSrv.exe c:\program files\McAfee\MSK\MskSrver.exe c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe c:\program files\National Instruments\MAX\nimxs.exe c:\program files\Dell\QuickSet\NICCONFIGSVC.exe c:\program files\National Instruments\Shared\Security\nidmsrv.exe c:\combo-fix\CF446.exe c:\windows\system32\nisvcloc.exe c:\program files\National Instruments\Shared\Tagger\tagsrv.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe c:\program files\Symantec AntiVirus\Rtvscan.exe c:\windows\ehome\mcrdsvc.exe c:\windows\system32\fxssvc.exe c:\windows\system32\dllhost.exe c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe c:\windows\system32\dlcccoms.exe c:\windows\eHome\ehmsas.exe c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe c:\windows\system32\lxcecoms.exe c:\program files\Java\jre6\bin\jucheck.exe c:\program files\Common Files\LogiShrd\LComMgr\LVComSX.exe c:\program files\iPod\bin\iPodService.exe c:\progra~1\COMMON~1\LogiShrd\LComMgr\LVComSX.exe c:\program files\Windows Desktop Search\WindowsSearchIndexer.exe c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe c:\program files\Windows Desktop Search\WindowsSearchFilter.exe c:\combo-fix\PEV.cfxxe . ************************************************************************** . Completion time: 2009-10-28 19:25 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-28 02:24 Pre-Run: 3,992,514,560 bytes free Post-Run: 4,620,140,544 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4 - - End Of File - - 2FBAF55F116B31951B5A26D9EADE2FFC |
|
|
Oct 28 2009, 06:01 AM
Post
#4
|
|
![]() GeekU Teacher Posts: 35,111 From: Dublin OS: XP |
hi
1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: QUOTE File:: c:\windows\wp4.dat c:\windows\wp3.dat NetSvc:: ilitteul KillAll:: Folder:: Registry:: Driver:: Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. |
|
|
Oct 28 2009, 10:22 AM
Post
#5
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows 2000 |
ComboFix 09-10-27.07 - Nick Rummel 10/28/2009 8:08.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.426 [GMT -7:00] Running from: c:\documents and settings\Nick Rummel\Desktop\Combo-Fix.exe Command switches used :: c:\documents and settings\Nick Rummel\Desktop\CFScript.txt AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} FILE :: "c:\windows\wp3.dat" "c:\windows\wp4.dat" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\wp3.dat c:\windows\wp4.dat Infected copy of c:\windows\system32\drivers\vaxscsi.sys was found and disinfected Restored copy from - Kitty ate it . ((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 ))))))))))))))))))))))))))))))) . 2009-12-06 04:33 . 2009-12-06 04:33 -------- dc----w- c:\windows\system32\XPSViewer 2009-12-06 04:31 . 2009-12-06 04:31 -------- dc----w- c:\program files\Reference Assemblies 2009-12-06 04:29 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\xpsshhdr.dll 2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll 2009-12-06 04:29 . 2008-07-06 12:06 117760 -c----w- c:\windows\system32\prntvpt.dll 2009-12-06 04:29 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\xpssvcs.dll 2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll 2009-12-06 04:28 . 2009-08-06 03:54 -------- dc----w- c:\windows\SxsCaPendDel 2009-10-28 14:55 . 2009-10-28 14:56 -------- dc----w- C:\Combo-Fix 2009-10-26 23:34 . 2006-03-03 15:07 143360 -c--a-w- c:\windows\system32\dunzip32.dll 2009-10-26 01:59 . 2007-11-22 13:44 33832 -c--a-w- c:\windows\system32\drivers\mferkdk.sys 2009-10-26 01:59 . 2007-12-02 19:51 40488 -c--a-w- c:\windows\system32\drivers\mfesmfk.sys 2009-10-26 01:59 . 2007-11-22 13:44 35240 -c--a-w- c:\windows\system32\drivers\mfebopk.sys 2009-10-26 01:59 . 2007-11-22 13:44 79304 -c--a-w- c:\windows\system32\drivers\mfeavfk.sys 2009-10-26 01:59 . 2007-11-22 13:44 201320 -c--a-w- c:\windows\system32\drivers\mfehidk.sys 2009-10-26 01:59 . 2007-07-13 13:20 113952 -c--a-w- c:\windows\system32\drivers\Mpfp.sys 2009-10-26 01:57 . 2009-10-26 01:58 -------- dc----w- c:\program files\McAfee.com 2009-10-26 01:25 . 2009-10-26 01:37 -------- dc----w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\AskToolbar 2009-10-23 06:49 . 2009-10-23 06:49 -------- dc----w- c:\program files\Ask.com 2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\Common Files\DVDVideoSoft 2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\DVDVideoSoft 2009-10-21 23:40 . 2009-10-21 23:40 -------- dc----w- C:\EmergencyUtils 2009-10-15 04:30 . 2009-10-28 07:32 -------- dc--a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-10-04 01:12 . 2009-10-04 01:12 -------- dc----w- c:\program files\iPod 2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\program files\iTunes 2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-10-01 22:35 . 2009-10-01 22:35 287080 -c--a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-06 04:32 . 2008-01-11 18:01 -------- dc----w- c:\program files\MSBuild 2009-10-28 15:28 . 2009-09-09 02:26 -------- dc----w- c:\program files\Common Files\Akamai 2009-10-28 15:04 . 2008-06-09 21:11 -------- dc----w- c:\program files\McAfee 2009-10-28 06:27 . 2007-08-31 00:39 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Skype 2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\program files\Common Files\Symantec Shared 2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\program files\Symantec 2009-10-28 04:02 . 2007-03-24 18:30 -------- dc----w- c:\program files\Symantec AntiVirus 2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\documents and settings\All Users\Application Data\Symantec 2009-10-28 01:46 . 2009-09-11 03:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\IM 2009-10-28 01:43 . 2008-08-08 04:17 -------- dc----w- c:\program files\Lx_cats 2009-10-28 01:39 . 2006-09-05 23:32 -------- dc----w- c:\program files\Dl_cats 2009-10-27 05:17 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\SiteAdvisor 2009-10-26 23:41 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\McAfee 2009-10-26 01:59 . 2008-06-09 21:12 -------- dc----w- c:\program files\Common Files\McAfee 2009-10-23 21:20 . 2007-05-17 18:06 -------- dc-h--w- c:\documents and settings\Nick Rummel\Application Data\Move Networks 2009-10-23 07:12 . 2008-02-11 02:48 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks 2009-10-16 17:37 . 2006-10-12 19:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\dvdcss 2009-10-04 01:12 . 2007-07-01 16:27 -------- dc----w- c:\program files\Common Files\Apple 2009-10-04 00:53 . 2007-12-10 02:00 -------- dc----w- c:\program files\Bonjour 2009-10-04 00:52 . 2007-07-16 02:03 -------- dc----w- c:\program files\QuickTime 2009-09-24 04:46 . 2008-05-20 03:28 -------- dc----w- c:\program files\AFT software 2009-09-24 04:46 . 2008-05-14 06:06 796672 -c--a-w- c:\windows\GPInstall.exe 2009-09-16 23:19 . 2009-09-16 23:19 -------- dc----w- c:\documents and settings\LocalService\Application Data\McAfee 2009-09-15 00:45 . 2009-09-15 00:40 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks 2009 2009-09-15 00:02 . 2009-09-15 00:02 3026 -c--a-w- c:\windows\system32\drivers\hwinterface.sys 2009-09-15 00:02 . 2006-09-05 23:14 152872 -c--a-w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-11 14:18 . 2005-08-16 09:18 136192 -c--a-w- c:\windows\system32\msv1_0.dll 2009-09-11 06:09 . 2008-01-11 17:48 -------- dc----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-09-11 06:05 . 2008-02-11 02:18 -------- dc----w- c:\program files\Common Files\SolidWorks Shared 2009-09-11 05:59 . 2009-09-11 05:58 -------- dc----w- c:\program files\AGEIA Technologies 2009-09-11 05:58 . 2009-02-25 01:24 -------- dc----w- c:\documents and settings\All Users\Application Data\SolidWorks 2009-09-11 05:52 . 2009-09-11 05:52 -------- dc----w- c:\program files\MSECache 2009-09-11 05:48 . 2009-09-11 05:47 -------- dc----w- c:\program files\Microsoft Visual Studio 8 2009-09-11 03:26 . 2009-09-11 03:25 -------- dc----w- c:\program files\Common Files\SolidWorks Installation Manager 2009-09-10 07:25 . 2008-01-18 06:30 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Autodesk 2009-09-10 07:23 . 2009-09-09 06:24 -------- dc----w- c:\documents and settings\All Users\Application Data\Autodesk 2009-09-09 06:40 . 2009-09-09 06:18 -------- dc----w- c:\program files\Autodesk 2009-09-09 06:38 . 2008-01-18 06:25 -------- dc----w- c:\program files\Common Files\Autodesk Shared 2009-09-09 06:25 . 2009-09-09 06:24 -------- dc----w- c:\program files\DWG TrueView 2010 2009-09-09 06:13 . 2006-08-28 06:28 -------- dc-h--w- c:\program files\InstallShield Installation Information 2009-09-04 21:03 . 2005-08-16 09:18 58880 -c--a-w- c:\windows\system32\msasn1.dll 2009-09-01 05:59 . 2009-09-01 05:05 -------- dc----w- c:\program files\Common Files\LogiShrd 2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logishrd 2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logitech 2009-09-01 05:04 . 2009-09-01 01:00 -------- dc----w- c:\program files\Logitech 2009-09-01 04:06 . 2009-04-07 05:02 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware 2009-08-29 07:36 . 2005-08-16 09:18 832512 -c--a-w- c:\windows\system32\wininet.dll 2009-08-29 07:36 . 2005-08-16 09:18 78336 -c--a-w- c:\windows\system32\ieencode.dll 2009-08-29 07:36 . 2005-08-16 09:18 17408 -c----w- c:\windows\system32\corpol.dll 2009-08-26 08:00 . 2005-08-16 09:19 247326 -c--a-w- c:\windows\system32\strmdll.dll 2009-08-25 05:59 . 2006-09-22 02:21 3766 -csha-w- c:\windows\system32\KGyGaAvL.sys 2009-08-25 05:59 . 2006-09-22 02:21 88 -csh--r- c:\windows\system32\68430E414D.sys 2009-08-07 02:24 . 2005-08-16 09:40 327896 -c--a-w- c:\windows\system32\wucltui.dll 2009-08-07 02:24 . 2005-08-16 09:40 209632 -c--a-w- c:\windows\system32\wuweb.dll 2009-08-07 02:24 . 2005-08-16 09:40 35552 -c--a-w- c:\windows\system32\wups.dll 2009-08-07 02:24 . 2005-05-26 11:16 44768 -c--a-w- c:\windows\system32\wups2.dll 2009-08-07 02:24 . 2005-08-16 09:40 53472 -c--a-w- c:\windows\system32\wuauclt.exe 2009-08-07 02:24 . 2005-08-16 09:18 96480 -c--a-w- c:\windows\system32\cdm.dll 2009-08-07 02:23 . 2005-08-16 09:40 575704 -c--a-w- c:\windows\system32\wuapi.dll 2009-08-07 02:23 . 2005-08-16 09:40 1929952 -c--a-w- c:\windows\system32\wuaueng.dll 2009-08-05 09:01 . 2005-08-16 09:18 204800 -c--a-w- c:\windows\system32\mswebdvd.dll 2009-08-04 15:13 . 2005-08-16 09:18 2145280 -c--a-w- c:\windows\system32\ntoskrnl.exe 2009-08-04 14:20 . 2004-08-04 03:59 2023936 -c--a-w- c:\windows\system32\ntkrnlpa.exe 2006-12-07 01:49 . 2006-12-07 01:49 592 -c--a-w- c:\program files\Opera.lnk 2006-09-06 01:35 . 2006-09-06 01:35 1626 -c--a-w- c:\program files\QuickTime Player.lnk 2006-09-06 01:14 . 2006-09-06 01:14 841 -c--a-w- c:\program files\Ad-Aware SE Personal.lnk 2006-09-05 23:34 . 2006-09-05 23:34 1753 -c--a-w- c:\program files\Dell Printer Supplies - Inkjet.lnk 2006-09-05 23:01 . 2006-09-05 23:01 786 -c--a-w- c:\program files\Windows Media Player.lnk 2006-08-29 15:54 . 2006-08-29 15:54 1752 -c--a-w- c:\program files\main.ini 2006-08-28 06:56 . 2006-08-28 06:56 1967 -c--a-w- c:\program files\Internet Service Offers.lnk 2006-08-28 06:56 . 2006-08-28 06:56 1965 -c--a-w- c:\program files\Games, Music, & Photos.lnk 2006-08-28 06:56 . 2006-08-28 06:56 1958 -c--a-w- c:\program files\Documentation & Support.lnk 2006-08-28 06:45 . 2006-08-28 06:45 1661 -c--a-w- c:\program files\Trend Micro PC-cillin Internet Security 12.lnk 2005-08-16 09:52 . 2006-09-05 23:01 1298 -c--a-w- c:\program files\Media Center.lnk 2005-10-12 22:04 . 2005-10-12 22:04 131072 -c--a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll 2007-02-08 17:48 . 2007-02-08 17:48 133920 -c--a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll . ((((((((((((((((((((((((((((( SnapShot@2009-10-28_01.43.18 ))))))))))))))))))))))))))))))))))))))))) . + 2009-10-28 15:27 . 2009-10-28 15:27 16384 c:\windows\Temp\Perflib_Perfdata_8d0.dat + 2009-10-28 15:27 . 2009-10-28 15:27 16384 c:\windows\Temp\Perflib_Perfdata_724.dat + 2006-09-05 22:48 . 2009-10-28 14:49 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2006-09-05 22:48 . 2009-10-27 18:58 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2009-10-28 04:26 . 2009-10-28 14:49 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat - 2006-09-05 22:48 . 2009-10-27 18:58 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2009-06-17 00:22 1144712 -c--a-w- c:\program files\Ask.com\GenericAskToolbar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712] [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712] [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176] "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-07 68856] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-14 98304] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-14 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-14 118784] "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718] "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960] "DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728] "dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080] "DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2007-04-10 4376328] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-05 148888] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-12-04 185896] "Dell QuickSet"="c:\progra~1\Dell\QuickSet\quickset.exe" [2006-04-06 1032192] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392] "tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-10 270336] "realteks"="c:\documents and settings\Nick Rummel\Application Data\Google\tncfc7316459.exe" [2009-07-15 0] "LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728] "lxcemon.exe"="c:\program files\Lexmark 4300 Series\lxcemon.exe" [2005-08-02 192512] "EzPrint"="c:\program files\Lexmark 4300 Series\ezprint.exe" [2005-07-26 94208] "FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008] "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 488984] "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 774168] "SolidWorks_CheckForUpdates"="c:\program files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe" [2009-03-20 7308584] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992] "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-25 282624] "WD Button Manager"="WDBtnMgr.exe" - c:\windows\system32\WDBtnMgr.exe [2009-06-11 364544] c:\documents and settings\Nick Rummel\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632] WD Anywhere Backup Launcher.lnk - c:\documents and settings\Nick Rummel\Application Data\Microsoft\Installer\{B9A81070-616D-4E93-BE02-CEE651343204}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe [2008-2-13 17542] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696] Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-27 24576] Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920] Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2006-3-26 257752] [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] Source= c:\windows\system32\onhelp.htm FriendlyName= tets [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-09-03 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-09-03 18:40 352256 -c--a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ \0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\DC++\\DCPlusPlus.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\DAP\\DAP.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Documents and Settings\\Nick Rummel\\My Documents\\My Completed Downloads\\eclipse-cpp-europa-win32\\eclipse\\eclipse.exe"= "c:\\Program Files\\Java\\jdk1.5.0_09\\jre\\bin\\java.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"= "c:\\Program Files\\National Instruments\\Shared\\Example Finder\\1.0\\BIN\\NIExampleFinder.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "%windir%\\system32\\drivers\\svchost.exe"= "c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"= "c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [9/14/2009 5:02 PM 3026] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [10/10/2006 12:53 PM 8944] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 11:39 AM 55024] R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/16/2005 2:18 AM 14336] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [6/9/2008 2:12 PM 92296] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 4:51 PM 4096] S2 DellBIOS;DellBIOS;\??\c:\windows\DellBIOS.Sys --> c:\windows\DellBIOS.Sys [?] S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe --> h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe [?] S3 EraserUtilDrvI9;EraserUtilDrvI9;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys [?] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [4/6/2009 10:03 PM 38496] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [8/6/2009 7:06 PM 136704] S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [8/6/2009 7:06 PM 8320] S3 PAC207;CIF USB Camera;c:\windows\system32\drivers\PFC027.SYS [1/2/2009 1:15 PM 505984] S3 TBU11;Turtle Beach USB MIDI 1x1 Driver;c:\windows\system32\drivers\tbu11.sys [8/4/2007 2:26 PM 13824] S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808] --- Other Services/Drivers In Memory --- *Deregistered* - mbr [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder 2009-10-25 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34] 2009-10-26 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 20:32] 2009-10-26 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 20:32] 2009-10-28 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job - c:\program files\Ask.com\UpdateTask.exe [2009-06-17 00:22] . . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm IE: &Download with &DAP - c:\program files\DAP\dapextie.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Nick Rummel\Application Data\Mozilla\Firefox\Profiles\8j7bdunq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/ FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071503000010.dll FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071505000010.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - HiddenExtension: XUL Cache: {69718F4B-3565-4D65-B418-A321269E8B74} - c:\documents and settings\Nick Rummel\Local Settings\Application Data\{69718F4B-3565-4D65-B418-A321269E8B74}\ FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true. - - - - ORPHANS REMOVED - - - - Notify-NavLogon - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-28 08:30 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spmo.sys >>UNKNOWN [0x87386938]<< kernel: MBR read successfully user & kernel MBR OK Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net atapi.sys @ 0x0 0x0 bytes \Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF7351B40 atapi.sys \Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF7351B40 atapi.sys \Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF7351B40 atapi.sys \Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF7351B40 atapi.sys \Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xF7351B40 atapi.sys \Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF7351B40 atapi.sys \Driver\atapi IRP hooks detected ! ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1313456098-3368236134-1419899362-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:5f,bd,1d,4e,48,20,11,db,c5,d2,3d,f5,fd,a2,c5,27,c8,7c,f3,0c,b0,8c,65, e7,a0,af,e6,ea,11,15,15,45,ed,f1,e1,34,d6,32,85,f7,f5,d5,9c,cd,1f,a4,98,68,\ "??"=hex:47,b8,eb,31,6d,80,25,0b,86,7e,89,00,84,30,b1,12 [HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ }*Ć] "Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(928) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(684) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\mshtml.dll c:\progra~1\COMMON~1\Stardock\MCPCore.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\IME\SPGRMR.DLL c:\windows\system32\msi.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\S24EvMon.exe c:\program files\Intel\Wireless\Bin\WLKeeper.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\eHome\ehRecvr.exe c:\windows\eHome\ehSched.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\lkcitdl.exe c:\windows\system32\lkads.exe c:\windows\system32\lktsrv.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\progra~1\McAfee\VIRUSS~1\mcshield.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\McAfee\MPF\MPFSrv.exe c:\program files\McAfee\MSK\MskSrver.exe c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe c:\program files\National Instruments\MAX\nimxs.exe c:\program files\Dell\QuickSet\NICCONFIGSVC.exe c:\program files\National Instruments\Shared\Security\nidmsrv.exe c:\windows\system32\nisvcloc.exe c:\program files\National Instruments\Shared\Tagger\tagsrv.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe c:\windows\ehome\mcrdsvc.exe c:\windows\system32\dllhost.exe c:\progra~1\mcafee.com\agent\mcagent.exe c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe c:\combo-fix32337c\CF7410.exe c:\progra~1\mcafee\msc\mcuimgr.exe c:\windows\eHome\ehmsas.exe c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe c:\windows\system32\dlcccoms.exe c:\windows\system32\lxcecoms.exe c:\program files\Windows Desktop Search\WindowsSearchIndexer.exe c:\program files\Common Files\LogiShrd\LComMgr\LVComSX.exe c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe c:\combo-fix32337c\PEV.cfxxe . ************************************************************************** . Completion time: 2009-10-28 8:49 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-28 15:49 ComboFix2.txt 2009-10-28 02:25 Pre-Run: 4,682,420,224 bytes free Post-Run: 4,666,454,016 bytes free Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4 - - End Of File - - F95482F0853CF5FAAC3F0CE4B586DF7A |
|
|
Oct 28 2009, 11:37 AM
Post
#6
|
|
![]() GeekU Teacher Posts: 35,111 From: Dublin OS: XP |
hi
Please download OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post. Download the GMER Rootkit Scanner. Unzip it to your Desktop. Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan. Double-click gmer.exe. The program will begin to run. **Caution** These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised by a trained Security Analyst If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Post the contents of GMER.txt in your next reply. Download OTL to your Desktop
|
|
|
Oct 28 2009, 04:57 PM
Post
#7
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows 2000 |
All processes killed
========== PROCESSES ========== ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List not found. ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 390354 bytes ->FireFox cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32835 bytes User: Nick Rummel ->Temp folder emptied: 308607 bytes File delete failed. C:\Documents and Settings\Nick Rummel\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 7627069 bytes ->Java cache emptied: 58142092 bytes ->FireFox cache emptied: 60803493 bytes ->Google Chrome cache emptied: 594288 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 5221905 bytes Windows Temp folder emptied: 664 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 127.00 mb OTM by OldTimer - Version 3.0.0.6 log created on 10282009_154208 Files moved on Reboot... Registry entries deleted on Reboot... |
|
|
Oct 28 2009, 06:12 PM
Post
#8
|
|
![]() GeekU Teacher Posts: 35,111 From: Dublin OS: XP |
the other logs too
|
|
|
Oct 29 2009, 09:21 AM
Post
#9
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows 2000 |
I've ran gmer.exe twice now, and both times, after a couple of hours, my comp freezes and I can't do anything.
|
|
|
Oct 29 2009, 09:27 AM
Post
#10
|
|
![]() GeekU Teacher Posts: 35,111 From: Dublin OS: XP |
how about OTL
|
|
|
Oct 29 2009, 04:56 PM
Post
#11
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows 2000 |
OTL logfile created on: 10/29/2009 8:50:57 AM - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Documents and Settings\Nick Rummel\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1014.37 Mb Total Physical Memory | 332.24 Mb Available Physical Memory | 32.75% Memory free 2.38 Gb Paging File | 1.46 Gb Available in Paging File | 61.19% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 37.24 Gb Total Space | 4.27 Gb Free Space | 11.47% Space Free | Partition Type: NTFS Drive D: | 12.27 Gb Total Space | 12.03 Gb Free Space | 98.03% Space Free | Partition Type: NTFS Drive E: | 82.04 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: NRUMMEL Current User Name: Nick Rummel Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan ========== Processes (SafeList) ========== PRC - [2009/10/29 08:50:28 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTL.exe PRC - [2009/09/21 16:36:12 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe PRC - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe PRC - [2009/09/16 14:48:40 | 00,092,296 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe PRC - [2009/09/05 01:54:42 | 00,417,792 | ---- | M] (Apple Inc.) -- C:\Program Files\QuickTime\QTTask.exe PRC - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe PRC - [2009/08/26 22:18:44 | 00,634,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\internet explorer\iexplore.exe PRC - [2009/08/04 06:26:44 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009/06/10 23:43:26 | 00,364,544 | ---- | M] (Western Digital Technologies, Inc.) -- C:\WINDOWS\System32\WDBtnMgr.exe PRC - [2009/06/04 21:58:37 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe PRC - [2009/06/04 21:58:08 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe PRC - [2009/05/21 10:55:32 | 00,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe PRC - [2009/03/19 19:30:12 | 07,308,584 | ---- | M] (Dassault Systčmes SolidWorks Corp.) -- C:\Program Files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe PRC - [2009/02/06 03:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe PRC - [2008/08/13 18:32:40 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe PRC - [2008/08/08 05:11:12 | 00,490,952 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\daemon.exe PRC - [2008/06/14 10:41:54 | 00,781,288 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\MSC\mcupdmgr.exe PRC - [2008/04/13 17:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe PRC - [2008/04/13 17:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE PRC - [2008/04/06 21:43:14 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe PRC - [2008/01/25 01:38:12 | 02,458,128 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe PRC - [2008/01/09 16:50:22 | 00,767,976 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe PRC - [2007/12/11 12:33:42 | 00,358,224 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe PRC - [2007/12/05 10:04:10 | 00,695,624 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe PRC - [2007/11/26 10:46:14 | 00,023,880 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSK\MskSrver.exe PRC - [2007/11/13 13:16:26 | 00,359,248 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\MSC\mcupdui.exe PRC - [2007/11/01 23:32:00 | 00,866,640 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\MSC\mcshell.exe PRC - [2007/11/01 19:12:38 | 00,582,992 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee.com\Agent\mcagent.exe PRC - [2007/11/01 19:12:38 | 00,265,040 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\MSC\mcuimgr.exe PRC - [2007/07/24 12:02:14 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe PRC - [2007/07/18 15:54:42 | 00,856,864 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MPFSrv.exe PRC - [2007/03/15 11:09:36 | 00,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe PRC - [2007/03/10 13:43:52 | 00,270,336 | ---- | M] () -- C:\WINDOWS\tsnpstd3.exe PRC - [2007/02/22 08:46:24 | 00,012,696 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\MAX\nimxs.exe PRC - [2007/02/21 17:15:52 | 00,056,096 | ---- | M] (National Instruments Corp.) -- C:\WINDOWS\System32\nisvcloc.exe PRC - [2007/02/14 22:54:06 | 00,207,648 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe PRC - [2007/02/14 22:49:16 | 00,064,288 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lktsrv.exe PRC - [2007/02/14 22:48:56 | 00,056,096 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lkads.exe PRC - [2007/02/08 01:13:48 | 00,774,168 | ---- | M] () -- C:\Program Files\Logitech\QuickCam10\QuickCam10.exe PRC - [2007/02/08 01:12:48 | 00,488,984 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe PRC - [2007/02/08 01:12:20 | 00,230,936 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe PRC - [2007/02/06 22:47:46 | 00,703,264 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe PRC - [2007/02/06 17:43:26 | 00,252,704 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe PRC - [2007/01/22 11:38:44 | 00,695,136 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lkcitdl.exe PRC - [2006/12/03 21:41:37 | 00,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe PRC - [2006/11/03 09:01:16 | 00,319,488 | ---- | M] (PixArt Imaging Incorporation) -- C:\WINDOWS\PixArt\PAC207\Monitor.exe PRC - [2006/10/27 00:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe PRC - [2006/10/09 17:16:56 | 00,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRecvr.exe PRC - [2006/09/19 08:07:28 | 00,827,392 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe PRC - [2006/05/01 07:34:00 | 00,262,217 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe PRC - [2006/05/01 07:28:26 | 00,602,182 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe PRC - [2006/05/01 07:28:06 | 00,667,718 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe PRC - [2006/05/01 07:26:14 | 00,397,381 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe PRC - [2006/05/01 07:22:42 | 00,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe PRC - [2006/05/01 07:20:52 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe PRC - [2006/05/01 07:20:26 | 00,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe PRC - [2006/04/06 12:58:52 | 01,032,192 | ---- | M] (Dell Inc) -- C:\Program Files\Dell\QuickSet\quickset.exe PRC - [2006/04/06 12:57:54 | 00,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe PRC - [2006/03/26 23:44:08 | 00,257,752 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe PRC - [2006/03/26 23:44:08 | 00,221,400 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe PRC - [2006/03/26 23:44:06 | 00,159,960 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe PRC - [2006/03/24 21:30:44 | 00,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe PRC - [2006/03/20 18:34:50 | 00,213,936 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe PRC - [2006/03/08 16:48:02 | 00,761,947 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe PRC - [2005/12/13 21:45:00 | 00,118,784 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxpers.exe PRC - [2005/12/13 21:41:08 | 00,077,824 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\hkcmd.exe PRC - [2005/12/09 18:29:52 | 00,049,152 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe PRC - [2005/10/27 21:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\System32\dlcccoms.exe PRC - [2005/10/21 00:40:26 | 00,430,080 | ---- | M] (Dell) -- C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe PRC - [2005/09/29 12:01:14 | 00,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehtray.exe PRC - [2005/08/05 11:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehSched.exe PRC - [2005/08/05 11:56:28 | 00,046,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehmsas.exe PRC - [2005/08/05 11:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe PRC - [2005/08/02 10:45:16 | 00,192,512 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark 4300 Series\lxcemon.exe PRC - [2005/07/26 05:17:18 | 00,094,208 | ---- | M] (Lexmark International Inc.) -- C:\Program Files\Lexmark 4300 Series\ezprint.exe PRC - [2005/07/06 03:14:12 | 00,471,040 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\lxcecoms.exe PRC - [2005/05/03 22:04:28 | 09,150,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe PRC - [2005/05/03 20:07:32 | 00,081,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe PRC - [2005/04/01 10:51:48 | 00,217,600 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe PRC - [2004/12/05 23:05:00 | 00,127,035 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfswctrl.exe PRC - [2003/10/29 00:06:00 | 00,024,576 | ---- | M] (BVRP Software) -- C:\Program Files\Digital Line Detect\DLG.exe PRC - [2003/09/10 00:24:00 | 00,020,480 | ---- | M] () -- C:\Program Files\NetWaiting\netWaiting.exe PRC - [2003/06/19 21:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE PRC - [2002/06/18 14:04:54 | 00,503,808 | ---- | M] () -- C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe PRC - [2002/06/18 03:37:22 | 01,515,566 | ---- | M] (The MathWorks Inc.) -- c:\matlab6p5\bin\win32\matlab.exe ========== Win32 Services (SafeList) ========== SRV - File not found -- -- (CoordinatorServiceHost [On_Demand | Stopped]) SRV - [2009/10/26 17:20:13 | 02,309,520 | ---- | M] () -- c:\program files\common files\akamai\rswin_3600.dll -- (Akamai [Auto | Running]) SRV - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running]) SRV - [2009/09/16 14:48:40 | 00,092,296 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service [Auto | Running]) SRV - [2009/09/10 23:08:41 | 00,079,360 | ---- | M] (SolidWorks) -- C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service [On_Demand | Stopped]) SRV - [2009/09/08 23:40:01 | 00,651,720 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped]) SRV - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running]) SRV - [2009/07/09 23:52:28 | 00,316,312 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\Temp\0164771256828787mcinst.exe -- (0164771256828787mcinstcleanup [Auto | Stopped]) SRV - [2009/06/04 21:58:08 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running]) SRV - [2009/06/02 23:29:36 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped]) SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running]) SRV - [2008/08/13 18:32:40 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter [Auto | Running]) SRV - [2008/07/29 22:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped]) SRV - [2008/07/25 12:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) SRV - [2008/07/25 12:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) SRV - [2008/04/13 17:12:35 | 00,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\skeys.exe -- (SerialKeys [On_Demand | Stopped]) SRV - [2008/04/13 17:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running]) SRV - [2008/01/25 01:38:12 | 02,458,128 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc [Auto | Running]) SRV - [2008/01/17 23:49:20 | 00,079,360 | ---- | M] (Autodesk) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service [On_Demand | Stopped]) SRV - [2008/01/09 16:50:22 | 00,767,976 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc [Auto | Running]) SRV - [2007/12/11 12:33:42 | 00,358,224 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy [Auto | Running]) SRV - [2007/12/05 10:04:10 | 00,695,624 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon [On_Demand | Running]) SRV - [2007/11/26 10:46:14 | 00,023,880 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSK\MskSrver.exe -- (MSK80Service [Auto | Running]) SRV - [2007/11/07 09:35:40 | 00,378,184 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS [On_Demand | Stopped]) SRV - [2007/07/24 12:02:14 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield [Unknown | Running]) SRV - [2007/07/18 15:54:42 | 00,856,864 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService [Auto | Running]) SRV - [2007/03/07 15:47:46 | 00,076,848 | ---- | M] () -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService [On_Demand | Stopped]) SRV - [2007/02/22 08:46:24 | 00,012,696 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\MAX\nimxs.exe -- (mxssvr [Auto | Running]) SRV - [2007/02/21 17:15:52 | 00,056,096 | ---- | M] (National Instruments Corp.) -- C:\WINDOWS\System32\nisvcloc.exe -- (niSvcLoc [Auto | Running]) SRV - [2007/02/14 22:54:06 | 00,207,648 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService [Auto | Running]) SRV - [2007/02/14 22:49:16 | 00,064,288 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lktsrv.exe -- (lkTimeSync [Auto | Running]) SRV - [2007/02/14 22:48:56 | 00,056,096 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lkads.exe -- (lkClassAds [Auto | Running]) SRV - [2007/02/06 22:47:46 | 00,703,264 | ---- | M] (National Instruments, Inc.) -- C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe -- (NITaggerService [Auto | Running]) SRV - [2007/01/29 15:19:48 | 01,007,616 | ---- | M] (Macrovision Corporation) -- C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe -- (NILM License Manager [On_Demand | Stopped]) SRV - [2007/01/22 11:38:44 | 00,695,136 | ---- | M] (National Instruments, Inc.) -- C:\WINDOWS\System32\lkcitdl.exe -- (LkCitadelServer [Auto | Running]) SRV - [2006/10/27 00:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped]) SRV - [2006/10/26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped]) SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) SRV - [2006/10/18 21:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped]) SRV - [2006/10/09 17:16:56 | 00,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRecvr.exe -- (ehRecvr [Auto | Running]) SRV - [2006/09/02 16:36:33 | 02,528,960 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE -- (LiveUpdate [On_Demand | Stopped]) SRV - [2006/05/01 07:34:00 | 00,262,217 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe -- (WLANKEEPER [Auto | Running]) SRV - [2006/05/01 07:22:42 | 00,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor [Auto | Running]) SRV - [2006/05/01 07:20:52 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng [Auto | Running]) SRV - [2006/05/01 07:20:26 | 00,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc [Auto | Running]) SRV - [2006/04/06 12:57:54 | 00,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe -- (NICCONFIGSVC [Auto | Running]) SRV - [2005/10/27 21:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\System32\dlcccoms.exe -- (dlcc_device [On_Demand | Running]) SRV - [2005/09/23 07:01:16 | 02,799,808 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon80 [Disabled | Stopped]) SRV - [2005/08/05 11:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehSched.exe -- (ehSched [Auto | Running]) SRV - [2005/08/05 11:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe -- (McrdSvc [Auto | Running]) SRV - [2005/07/06 03:14:12 | 00,471,040 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\lxcecoms.exe -- (lxce_device [On_Demand | Running]) SRV - [2005/05/03 22:04:28 | 09,150,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe -- (MSSQL$MICROSOFTSMLBIZ [Auto | Running]) SRV - [2005/05/03 20:50:28 | 00,073,728 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe -- (MSSQLServerADHelper [On_Demand | Stopped]) SRV - [2005/05/03 19:42:56 | 00,323,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE -- (SQLAgent$MICROSOFTSMLBIZ [On_Demand | Stopped]) SRV - [2005/04/01 10:51:48 | 00,217,600 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe -- (StarWindService [Auto | Running]) SRV - [2004/12/02 08:28:32 | 00,098,304 | ---- | M] (OPC Foundation) -- C:\WINDOWS\System32\OpcEnum.exe -- (OpcEnum [On_Demand | Stopped]) SRV - [2004/10/22 03:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped]) SRV - [2004/08/10 02:11:50 | 00,085,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mhn.dll -- (MHN [On_Demand | Stopped]) SRV - [2003/06/19 21:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running]) SRV - [2002/06/18 14:04:54 | 00,503,808 | ---- | M] () -- C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe -- (matlabserver [Auto | Running]) ========== Modules (SafeList) ========== MOD - [2009/10/29 08:50:28 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTL.exe MOD - [2009/10/06 11:42:48 | 00,014,544 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll MOD - [2008/04/13 17:12:51 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll MOD - [2008/04/13 17:12:00 | 00,025,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mslbui.dll MOD - [2006/04/06 12:59:08 | 00,073,728 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll MOD - [2005/12/13 21:39:58 | 00,073,728 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\hccutils.DLL ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/ IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "http://www.msn.com/" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07 FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.0.6 FF - prefs.js..extensions.enabledItems: multipletab@piro.sakura.ne.jp:0.4.2009073101 FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.3.1 FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.1.07282009_url_fix FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1 FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.6.15 FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.6 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.2.20080717 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1 FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.2.1 FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0 FF - prefs.js..extensions.enabledItems: {69718F4B-3565-4D65-B418-A321269E8B74}:1.0 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:7 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13 FF - prefs.js..extensions.enabledItems: {3fb63340-652a-11dd-ad8b-0800200c9a66}:2.1 FF - prefs.js..extensions.enabledItems: {47d1d620-5e5b-11da-8cd6-0800200c9a66}:2.0 FF - prefs.js..extensions.enabledItems: {7779C76B-0B5B-42be-BDDD-114CDDEC6A73}:1.0 FF - prefs.js..extensions.enabledItems: {961408A3-C970-4577-970A-D97C29839A67}:1.3.0 FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2009/10/27 17:23:35 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{69718F4B-3565-4D65-B418-A321269E8B74}: C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\{69718F4B-3565-4D65-B418-A321269E8B74}\ [2009/04/02 13:17:40 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/06/04 21:58:10 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 03:01:04 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/28 21:59:35 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/28 21:59:45 | 00,000,000 | ---D | M] [2008/09/21 11:18:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Extensions [2008/09/21 11:18:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/10/23 14:51:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions [2009/09/02 17:07:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2008/12/10 00:40:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/10/21 23:58:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{3fb63340-652a-11dd-ad8b-0800200c9a66} [2009/10/22 00:04:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593} [2009/10/21 22:56:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8} [2009/10/21 23:46:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{47d1d620-5e5b-11da-8cd6-0800200c9a66} [2009/06/04 22:00:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2009/10/22 00:35:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{7779C76B-0B5B-42be-BDDD-114CDDEC6A73} [2009/10/22 00:31:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{961408A3-C970-4577-970A-D97C29839A67} [2009/10/21 22:56:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009/10/22 00:04:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} [2009/10/21 22:56:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\elemhidehelper@adblockplus.org [2009/10/21 22:48:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\multipletab@piro.sakura.ne.jp [2009/10/21 22:56:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\personas@christopher.beard [2009/10/21 22:56:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\SkipScreen@SkipScreen [2009/10/22 00:35:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\mozilla\Firefox\Profiles\8j7bdunq.default\extensions\staged-xpis [2009/04/05 09:21:31 | 00,001,739 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Application Data\Mozilla\FireFox\Profiles\8j7bdunq.default\searchplugins\aim-search.xml [2008/02/22 19:42:27 | 00,001,877 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Application Data\Mozilla\FireFox\Profiles\8j7bdunq.default\searchplugins\aolsearch.xml [2009/02/24 17:42:01 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Application Data\Mozilla\FireFox\Profiles\8j7bdunq.default\searchplugins\daemon-search.xml [2007/10/15 19:41:06 | 00,002,386 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Application Data\Mozilla\FireFox\Profiles\8j7bdunq.default\searchplugins\siteadvisor.xml [2009/10/26 22:20:30 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2006/09/05 18:41:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/08/04 06:26:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2007/08/30 17:38:57 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} [2007/04/15 01:37:09 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [2007/08/18 18:14:54 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [2007/10/29 22:21:11 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2008/08/21 11:15:30 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [2009/08/04 06:26:42 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/08/04 06:26:43 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2006/07/28 08:32:54 | 00,049,152 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll [2009/06/04 21:56:37 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll [2007/04/22 17:02:18 | 00,717,312 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll [2008/09/26 09:40:34 | 00,053,248 | ---- | M] (AOL LLC) -- C:\Program Files\mozilla firefox\plugins\npdnu.dll [2009/03/12 15:16:54 | 00,155,648 | ---- | M] (Dassault Systčmes SolidWorks Corp.) -- C:\Program Files\mozilla firefox\plugins\npEModelPlugin.dll [2006/10/30 12:47:52 | 01,380,656 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll [2005/10/12 15:04:02 | 00,020,480 | ---- | M] (National Instruments) -- C:\Program Files\mozilla firefox\plugins\NPLV80Win32.dll [2007/02/08 10:48:16 | 00,028,448 | ---- | M] (National Instruments) -- C:\Program Files\mozilla firefox\plugins\NPLV82Win32.dll [2006/11/21 10:43:42 | 00,114,688 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npmozax.dll [2007/07/29 09:02:09 | 00,284,248 | ---- | M] (Musicnotes, Inc.) -- C:\Program Files\mozilla firefox\plugins\npmusicn.dll [2009/08/04 06:26:48 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2003/07/14 20:56:52 | 00,013,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL [2006/12/18 04:18:30 | 00,077,824 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2006/12/03 21:41:52 | 00,144,984 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2009/10/28 21:59:42 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2009/10/28 21:59:43 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2009/10/28 21:59:43 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2009/10/28 21:59:43 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2009/10/28 21:59:44 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2009/10/28 21:59:44 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2009/10/28 21:59:45 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2006/12/03 21:42:01 | 00,024,576 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprjplug.dll [2006/12/03 21:41:45 | 00,081,920 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll [2007/11/01 20:59:39 | 04,100,096 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npsibelius.dll [2005/08/09 11:42:53 | 00,057,344 | ---- | M] (America Online, Inc.) -- C:\Program Files\mozilla firefox\plugins\npunagi2.dll [2007/03/09 16:16:44 | 00,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll [2009/03/26 11:56:22 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/03/26 11:56:22 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/03/26 11:56:22 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/03/26 11:56:22 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/03/26 11:56:22 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/03/26 11:56:22 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2009/03/26 11:56:22 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (dsWebAllowBHO Class) - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll (Microsoft Corporation) O2 - BHO: (McAfee Phishing Filter) - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\Program Files\McAfee\MSK\mcapbho.dll () O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\dla\tfswshx.dll (Sonic Solutions) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O2 - BHO: (CleanMyPCPopupBlocker Class) - {7A9BC6B1-7F27-47c6-A66D-13582E81E537} - C:\Program Files\CleanMyPC Popup Blocker\CleanBHO.dll (CleanMyPC Software) O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.) O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.) O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O3 - HKLM\..\Toolbar: (CleanMyPC Toolbar) - {04164EC4-1E48-4279-818E-3721931E7636} - C:\Program Files\CleanMyPC Popup Blocker\CleanBar.dll (CleanMyPC Software) O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com) O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com) O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc) O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.) O4 - HKLM..\Run: [dla] C:\WINDOWS\System32\dla\tfswctrl.exe (Sonic Solutions) O4 - HKLM..\Run: [DLCCCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.DLL () O4 - HKLM..\Run: [dlccmon.exe] C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell) O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( ) O4 - HKLM..\Run: [DVDLauncher] C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.) O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation) O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 4300 Series\ezprint.exe (Lexmark International Inc.) O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files\Lexmark Fax Solutions\fm3032.exe () O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation) O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation) O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation) O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation) O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation) O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation) O4 - HKLM..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation) O4 - HKLM..\Run: [ISUSPM Startup] c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation) O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation) O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.) O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam10\QuickCam10.exe () O4 - HKLM..\Run: [LXCECATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.DLL () O4 - HKLM..\Run: [lxcemon.exe] C:\Program Files\Lexmark 4300 Series\lxcemon.exe (Lexmark International, Inc.) O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.) O4 - HKLM..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation) O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.) O4 - HKLM..\Run: [realteks] C:\Documents and Settings\Nick Rummel\Application Data\Google\tncfc7316459.exe () O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.) O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe () O4 - HKLM..\Run: [SolidWorks_CheckForUpdates] C:\Program Files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe (Dassault Systčmes SolidWorks Corp.) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe () O4 - HKLM..\Run: [WD Button Manager] C:\WINDOWS\System32\WDBtnMgr.exe (Western Digital Technologies, Inc.) O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd) O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.) O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.) O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe () O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\Nick Rummel\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\Nick Rummel\Start Menu\Programs\Startup\WD Anywhere Backup Launcher.lnk = C:\Documents and Settings\Nick Rummel\Application Data\Microsoft\Installer\{B9A81070-616D-4E93-BE02-CEE651343204}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm () O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm () O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm () O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab (StagingUI Object) O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file://C:\Program Files\Chessmaster Challenge\Images\stg_drm.ocx (SpinTop DRM Control) O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support) O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab (ZoneBuddy Class) O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab (ZonePAChat Object) O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo...toUploader3.cab (Facebook Photo Uploader 4 Control) O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} http://zone.msn.com/bingame/zpagames/zpa_txhe.cab50108.cab (ZPA_TexasHoldem Object) O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab (MSN Games - Installer) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_06) O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_09) O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_11) O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_01) O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_02) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file://C:\Program Files\Chessmaster Challenge\Images\armhelper.ocx (ArmHelper Control) O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab41227.cab (StadiumProxy Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.94.156.1 68.94.157.1 O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation) O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\Program Files\Common Files\Stardock\MCPCore.dll (Stardock) O24 - Desktop Components:0 (tets) - C:\WINDOWS\system32\onhelp.htm O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005/08/16 02:43:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2007/02/14 12:27:46 | 00,000,000 | ---D | M] - D:\autorun -- [ NTFS ] O32 - AutoRun File - [2006/12/15 13:32:12 | 00,000,047 | R--- | M] () - E:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{1a517000-d909-11dc-8eee-0015c5a935eb}\Shell\AutoRun\command - "" = H:\wd_windows_tools\WDEULA.exe -- File not found O33 - MountPoints2\{4669c37e-c3dd-11de-8fa7-0015c5a935eb}\Shell - "" = AutoRun O33 - MountPoints2\{4669c37e-c3dd-11de-8fa7-0015c5a935eb}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{4669c37e-c3dd-11de-8fa7-0015c5a935eb}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found O35 - comfile [open] -- "%1" %* File not found O35 - exefile [open] -- "%1" %* File not found NetSvcs: 6to4 - Service key not found. File not found NetSvcs: Ias - Service key not found. File not found NetSvcs: Iprip - Service key not found. File not found NetSvcs: Irmon - Service key not found. File not found NetSvcs: NWCWorkstation - Service key not found. File not found NetSvcs: Nwsapagent - Service key not found. File not found NetSvcs: WmdmPmSp - Service key not found. File not found NetSvcs: MHN - C:\WINDOWS\System32\mhn.dll (Microsoft Corporation) NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SafeBootMin: mcmscsvc - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.) SafeBootMin: MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.) SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vds - Service SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SafeBootNet: mcmscsvc - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.) SafeBootNet: MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.) SafeBootNet: MpfService - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.) SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error. ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML) ActiveX: {1BC46932-21B2-4130-86E0-B4EB4F7A7A7B} - Microsoft .NET Framework 1.0 Hotfix (KB887998) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 10.1.3 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 10.1.3 ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error. ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error. ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {407408d4-94ed-4d86-ab69-a7f649d112ee} - %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection QuickLaunchShortcut 640 %systemroot%\inf\mcdftreg.inf ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7 ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders ActiveX: {75AE7B1B-AA9C-C4FE-93D3-454016F08DA4} - Vector Graphics Rendering (VML) ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {88D28416-AE72-24C6-D586-3A1757EB53C4} - Microsoft .NET Framework 1.0 Hotfix (KB887998) ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework ActiveX: {BDE0FA43-6952-4BA8-8C58-09AF690F88E1} - Microsoft .NET Framework 1.0 Hotfix (KB930494) ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler ActiveX: {CD13081A-6FF9-21B7-6133-A4CAECD56D8C} - Browser Customizations ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297) ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E8BB293C-33AB-AD4A-8F4C-861EC8B07069} - Browser Customizations ActiveX: {E8EA5BD6-D931-4001-ABF6-81BAA500360A} - Microsoft .NET Framework 1.0 Hotfix (KB953295) ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {EA29D410-CE41-4953-A862-2DE706A1DAD7} - Microsoft .NET Framework 1.0 Service Pack 3 ActiveX: {FDC11A6F-17D1-48f9-9EA3-9051954BAA24} - .NET Framework ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE ActiveX: KB910393 - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\EasyCDBlock.inf,PerUserInstall Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: MSVideo8 - C:\WINDOWS\System32\VfWWDM32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.) Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) ========== Files/Folders - Created Within 14 Days ========== [2009/10/25 18:25:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\AskToolbar [2009/10/22 23:48:09 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft [2009/10/22 23:49:15 | 00,000,000 | ---D | C] -- C:\Program Files\Ask.com [2009/10/22 23:48:08 | 00,000,000 | ---D | C] -- C:\Program Files\DVDVideoSoft [2009/10/25 18:57:29 | 00,000,000 | ---D | C] -- C:\Program Files\McAfee.com [2009/12/05 21:31:43 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies [2009/10/29 08:20:21 | 00,000,000 | ---D | C] -- C:\Program Files\SiteAdvisor [2009/12/05 21:33:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer [2009/12/05 21:28:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel [2009/10/29 08:50:28 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTL.exe [2009/10/29 08:06:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood [2009/10/28 15:42:08 | 00,000,000 | ---D | C] -- C:\_OTM [2009/10/28 15:40:45 | 00,408,064 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTM.exe [2009/10/28 07:55:39 | 00,000,000 | ---D | C] -- C:\Combo-Fix [2009/10/27 17:05:57 | 00,000,000 | RHSD | C] -- C:\cmdcons [2009/10/27 16:48:36 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2009/10/27 16:48:34 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2009/10/27 16:48:33 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2009/10/27 16:48:33 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2009/10/27 16:44:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2009/10/27 08:50:04 | 00,000,000 | ---D | C] -- C:\Qoobox [2009/10/26 17:19:37 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\Nick Rummel\Desktop\RootRepeal.exe [2009/10/26 16:34:20 | 00,143,360 | ---- | C] (Inner Media, Inc.) -- C:\WINDOWS\System32\dunzip32.dll [2009/10/25 18:59:54 | 00,033,832 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdk.sys [2009/10/25 18:59:43 | 00,040,488 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfesmfk.sys [2009/10/25 18:59:40 | 00,035,240 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfebopk.sys [2009/10/25 18:59:38 | 00,079,304 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys [2009/10/25 18:59:37 | 00,201,320 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys [2009/10/25 18:59:20 | 00,113,952 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\Mpfp.sys [2009/10/22 23:48:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Nick Rummel\My Documents\DVDVideoSoft [2009/10/22 23:44:37 | 10,984,941 | ---- | C] (DVDVideoSoft Limited. ) -- C:\Documents and Settings\Nick Rummel\Desktop\FreeVideoFlipAndRotate.exe [2009/10/21 22:45:25 | 08,067,224 | ---- | C] (Mozilla) -- C:\Documents and Settings\Nick Rummel\Desktop\Firefox Setup 3.5.3.exe [2009/10/21 16:40:00 | 00,000,000 | ---D | C] -- C:\EmergencyUtils [2009/10/21 16:39:34 | 00,032,768 | ---- | C] (Doug Knox) -- C:\Documents and Settings\Nick Rummel\Desktop\xp_emergencyutil.exe [2009/06/03 20:21:01 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll [2009/06/03 20:21:00 | 00,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll [2009/06/03 20:21:00 | 00,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll [2009/06/03 20:21:00 | 00,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll [2007/08/02 15:20:28 | 00,220,184 | ---- | C] ( ) -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\Interop.Microsoft.Office.Core.dll [2007/02/24 21:45:58 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Nick Rummel\Application Data\pcouffin.sys [2006/08/27 22:59:50 | 01,183,744 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccserv.dll [2006/08/27 22:59:50 | 01,134,592 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccusb1.dll [2006/08/27 22:59:50 | 00,774,144 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcchbn3.dll [2006/08/27 22:59:50 | 00,704,512 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcccomc.dll [2006/08/27 22:59:50 | 00,638,976 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccpmui.dll [2006/08/27 22:59:50 | 00,483,328 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcclmpm.dll [2006/08/27 22:59:50 | 00,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcccomm.dll [2006/08/27 22:59:50 | 00,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccprox.dll [2006/08/27 22:59:50 | 00,114,688 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccpplc.dll [2005/12/13 18:12:34 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\stdole.dll ========== Files - Modified Within 14 Days ========== [2009/10/29 08:50:28 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTL.exe [2009/10/29 08:01:03 | 00,000,246 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job [2009/10/29 07:59:40 | 00,002,479 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Start Menu\Programs\Startup\WD Anywhere Backup Launcher.lnk [2009/10/29 07:59:10 | 00,012,859 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF [2009/10/29 07:57:55 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/10/29 07:40:59 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/10/29 07:40:55 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/10/29 07:40:53 | 10,637,14816 | -HS- | M] () -- C:\hiberfil.sys [2009/10/28 23:48:24 | 00,223,744 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/10/28 19:15:52 | 00,021,430 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\Finances.xlsx [2009/10/28 18:29:33 | 00,000,165 | -H-- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\~$Finances.xlsx [2009/10/28 15:58:33 | 00,282,833 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\gmer.zip [2009/10/28 15:40:46 | 00,408,064 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Nick Rummel\Desktop\OTM.exe [2009/10/28 08:39:32 | 00,000,157 | ---- | M] () -- C:\WINDOWS\matlab.ini [2009/10/28 08:30:52 | 00,000,246 | ---- | M] () -- C:\WINDOWS\system.ini [2009/10/28 08:29:59 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2009/10/27 17:06:28 | 00,000,279 | RHS- | M] () -- C:\boot.ini [2009/10/26 17:22:26 | 00,464,491 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\RootRepeal.zip [2009/10/26 17:19:56 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\settings.dat [2009/10/26 16:40:14 | 00,000,666 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee EasyNetwork.lnk [2009/10/26 16:40:10 | 00,000,671 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk [2009/10/25 18:58:23 | 00,000,352 | ---- | M] () -- C:\WINDOWS\tasks\McDefragTask.job [2009/10/25 18:58:21 | 00,000,344 | ---- | M] () -- C:\WINDOWS\tasks\McQcTask.job [2009/10/25 06:11:34 | 00,077,312 | ---- | M] () -- C:\WINDOWS\MBR.exe [2009/10/24 18:59:05 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2009/10/23 00:11:25 | 00,002,199 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SolidWorks 2009 SP3.0.lnk [2009/10/22 23:48:33 | 00,000,892 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\DVDVideoSoft Free Studio.lnk [2009/10/22 23:46:31 | 10,984,941 | ---- | M] (DVDVideoSoft Limited. ) -- C:\Documents and Settings\Nick Rummel\Desktop\FreeVideoFlipAndRotate.exe [2009/10/21 22:48:02 | 08,067,224 | ---- | M] (Mozilla) -- C:\Documents and Settings\Nick Rummel\Desktop\Firefox Setup 3.5.3.exe [2009/10/21 16:39:03 | 00,007,875 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\xp_emergencyutil.zip [2009/10/16 13:22:44 | 00,291,328 | ---- | M] () -- C:\Documents and Settings\Nick Rummel\Desktop\gmer.exe ========== Files - No Company Name ========== [2009/10/28 18:29:33 | 00,000,165 | -H-- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\~$Finances.xlsx [2009/10/28 15:58:52 | 00,291,328 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\gmer.exe [2009/10/28 15:58:31 | 00,282,833 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\gmer.zip [2009/10/27 17:06:28 | 00,000,209 | ---- | C] () -- C:\Boot.bak [2009/10/27 17:06:05 | 00,260,272 | ---- | C] () -- C:\cmldr [2009/10/27 16:48:36 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe [2009/10/27 16:48:34 | 00,236,544 | ---- | C] () -- C:\WINDOWS\PEV.exe [2009/10/27 16:48:34 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2009/10/27 16:48:34 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2009/10/27 16:48:33 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2009/10/26 17:19:56 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\settings.dat [2009/10/26 17:15:28 | 00,464,491 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\RootRepeal.zip [2009/10/26 16:41:14 | 00,012,859 | ---- | C] () -- C:\WINDOWS\System32\Config.MPF [2009/10/26 16:40:14 | 00,000,666 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee EasyNetwork.lnk [2009/10/26 16:40:10 | 00,000,671 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk [2009/10/25 18:58:23 | 00,000,352 | ---- | C] () -- C:\WINDOWS\tasks\McDefragTask.job [2009/10/25 18:58:21 | 00,000,344 | ---- | C] () -- C:\WINDOWS\tasks\McQcTask.job [2009/10/22 23:49:27 | 00,000,246 | ---- | C] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job [2009/10/22 23:48:33 | 00,000,892 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\DVDVideoSoft Free Studio.lnk [2009/10/21 16:39:01 | 00,007,875 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Desktop\xp_emergencyutil.zip [2009/08/31 22:07:42 | 00,050,127 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini [2009/07/22 16:25:23 | 00,005,652 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys [2009/06/25 15:11:20 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\LXPMONUI.DLL [2009/06/25 15:11:19 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXPRMON.DLL [2009/06/24 13:50:49 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI [2009/06/03 20:21:04 | 00,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini [2009/06/03 20:21:03 | 00,003,968 | ---- | C] () -- C:\WINDOWS\System32\drivers\DeNoise.sys [2009/04/02 13:21:57 | 00,004,536 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\DB475BB5-9A3E-4DE9-BD7D-189CA7F82FD2.txt [2009/01/02 13:15:10 | 00,000,518 | ---- | C] () -- C:\WINDOWS\System32\SP207.INI [2008/09/17 21:34:02 | 00,148,992 | ---- | C] () -- C:\WINDOWS\System32\mllink5.dll [2008/09/17 21:34:02 | 00,000,019 | ---- | C] () -- C:\WINDOWS\exlink.ini [2008/03/18 12:07:35 | 00,903,168 | ---- | C] () -- C:\WINDOWS\System32\mitmdl30.dll [2008/03/18 12:07:34 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwpg60n.dll [2008/03/18 12:07:34 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwmf60n.dll [2008/03/18 12:07:33 | 00,110,080 | ---- | C] () -- C:\WINDOWS\System32\lfpng60n.dll [2008/03/18 12:07:33 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\lftif60n.dll [2008/03/18 12:07:33 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\lfpcx60n.dll [2008/03/18 12:07:33 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfpct60n.dll [2008/03/18 12:07:33 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\lfpsd60n.dll [2008/03/18 12:07:33 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\lftga60n.dll [2008/03/18 12:07:33 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\lfmsp60n.dll [2008/03/18 12:07:32 | 00,176,128 | ---- | C] () -- C:\WINDOWS\System32\lffax60n.dll [2008/03/18 12:07:32 | 00,141,824 | ---- | C] () -- C:\WINDOWS\System32\lfcmp60n.dll [2008/03/18 12:07:32 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfeps60n.dll [2008/03/18 12:07:32 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\lfbmp60n.dll [2008/03/18 12:07:32 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\lfmac60n.dll [2008/02/11 18:30:49 | 00,000,000 | ---- | C] () -- C:\WINDOWS\eDrawingOfficeAutomator.INI [2008/01/21 15:05:42 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iplayer.INI [2007/08/04 15:23:47 | 00,000,040 | ---- | C] () -- C:\WINDOWS\musicstr.ini [2007/08/04 14:26:24 | 00,000,514 | ---- | C] () -- C:\WINDOWS\teachpno.ini [2007/04/13 15:09:08 | 02,067,140 | R--- | C] () -- C:\WINDOWS\System32\avcodec.dll [2007/04/13 00:01:49 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt [2007/04/12 23:58:40 | 00,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys [2007/04/07 02:25:46 | 00,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI [2007/03/24 13:36:17 | 00,223,128 | ---- | C] () -- C:\WINDOWS\System32\drivers\vaxscsi.sys [2007/02/27 20:35:55 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys [2007/02/24 21:48:26 | 00,000,014 | ---- | C] () -- C:\WINDOWS\System32\systeminfo3.dll [2007/02/24 21:46:19 | 00,000,033 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\pcouffin.log [2007/02/24 21:45:58 | 00,081,920 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\ezpinst.exe [2007/02/24 21:45:58 | 00,007,176 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\pcouffin.cat [2007/02/24 21:45:58 | 00,001,144 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\pcouffin.inf [2007/02/24 21:34:29 | 00,000,040 | -HS- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\.zreglib [2007/02/22 11:19:06 | 00,052,000 | ---- | C] () -- C:\WINDOWS\System32\nipcload.dll [2007/02/21 19:30:50 | 00,000,244 | ---- | C] () -- C:\WINDOWS\System32\nirpc.ini [2007/02/21 10:00:00 | 00,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\cvintdrv.sys [2007/02/06 17:45:04 | 00,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys [2007/02/06 17:42:40 | 01,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys [2006/12/31 20:23:50 | 00,000,956 | R--- | C] () -- C:\WINDOWS\System32\iconcfg.ini [2006/12/07 10:10:37 | 00,000,004 | ---- | C] () -- C:\WINDOWS\info147.sys [2006/12/06 18:49:46 | 00,000,592 | ---- | C] () -- C:\Program Files\Opera.lnk [2006/12/04 20:02:26 | 01,580,176 | -H-- | C] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\IconCache.db [2006/12/03 21:45:25 | 00,000,050 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2006/10/16 17:36:29 | 00,000,021 | ---- | C] () -- C:\WINDOWS\WB.ini [2006/10/16 16:53:59 | 00,005,127 | ---- | C] () -- C:\WINDOWS\langorig.ini [2006/10/16 16:53:18 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\wbload.dll [2006/10/16 16:48:52 | 00,000,027 | ---- | C] () -- C:\WINDOWS\SDAddressBox16827d0561119.ini [2006/10/16 16:45:44 | 00,000,027 | ---- | C] () -- C:\WINDOWS\SDAddressBox1633cb8581916.ini [2006/10/16 16:42:27 | 00,007,852 | ---- | C] () -- C:\WINDOWS\System32\mcdmsg7.dll [2006/09/21 19:21:52 | 00,003,766 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys [2006/09/21 19:21:52 | 00,000,088 | RHS- | C] () -- C:\WINDOWS\System32\68430E414D.sys [2006/09/08 15:26:05 | 00,000,157 | ---- | C] () -- C:\WINDOWS\matlab.ini [2006/09/05 23:05:35 | 00,002,516 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache [2006/09/05 22:40:11 | 00,223,744 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2006/09/05 18:44:35 | 00,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini [2006/09/05 18:35:14 | 00,001,626 | ---- | C] () -- C:\Program Files\QuickTime Player.lnk [2006/09/05 18:19:36 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini [2006/09/05 18:14:15 | 00,000,841 | ---- | C] () -- C:\Program Files\Ad-Aware SE Personal.lnk [2006/09/05 16:34:00 | 00,001,753 | ---- | C] () -- C:\Program Files\Dell Printer Supplies - Inkjet.lnk [2006/09/05 16:14:59 | 00,152,872 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT [2006/09/05 16:01:52 | 00,000,786 | ---- | C] () -- C:\Program Files\Windows Media Player.lnk [2006/09/05 16:01:46 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Nick Rummel\Application Data\desktop.ini [2006/09/05 16:01:45 | 00,001,298 | ---- | C] () -- C:\Program Files\Media Center.lnk [2006/09/05 16:01:44 | 00,000,134 | ---- | C] () -- C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\fusioncache.dat [2006/08/29 08:54:33 | 00,001,752 | ---- | C] () -- C:\Program Files\main.ini [2006/08/27 23:59:40 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2006/08/27 23:56:37 | 00,001,967 | ---- | C] () -- C:\Program Files\Internet Service Offers.lnk [2006/08/27 23:56:14 | 00,001,965 | ---- | C] () -- C:\Program Files\Games, Music, & Photos.lnk [2006/08/27 23:56:06 | 00,001,958 | ---- | C] () -- C:\Program Files\Documentation & Support.lnk [2006/08/27 23:51:09 | 00,000,413 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2006/08/27 23:45:13 | 00,001,661 | ---- | C] () -- C:\Program Files\Trend Micro PC-cillin Internet Security 12.lnk [2006/08/27 23:39:50 | 00,712,704 | ---- | C] () -- C:\WINDOWS\System32\DellSystemRestore.dll [2006/08/27 23:36:41 | 00,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini [2006/08/27 23:31:45 | 00,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare [2006/08/27 22:59:50 | 00,430,080 | ---- | C] () -- C:\WINDOWS\System32\dlccutil.dll [2006/08/27 22:59:50 | 00,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlccinsb.dll [2006/08/27 22:59:50 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\dlccins.dll [2006/08/27 22:59:50 | 00,131,072 | ---- | C] () -- C:\WINDOWS\System32\dlccjswr.dll [2006/08/27 22:59:50 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\dlccinsr.dll [2006/08/27 22:59:50 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\dlcccub.dll [2006/08/27 22:59:50 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\dlcccu.dll [2006/08/27 22:59:50 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlccvs.dll [2006/08/27 22:59:50 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\dlcccur.dll [2006/08/27 22:59:48 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\dlcccfg.dll [2006/08/27 22:59:14 | 00,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll [2006/08/27 22:58:48 | 00,000,391 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI [2006/06/13 17:35:32 | 00,053,760 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll [2005/08/16 02:37:24 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini [2005/08/16 02:33:24 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini [2005/08/16 02:18:43 | 00,001,204 | ---- | C] () -- C:\WINDOWS\win.ini [2005/08/16 02:18:41 | 00,000,246 | ---- | C] () -- C:\WINDOWS\system.ini [2005/08/05 12:01:54 | 00,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2005/08/02 12:00:16 | 00,000,611 | ---- | C] () -- C:\WINDOWS\System32\dlccplc.ini [2005/07/14 01:15:30 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcevs.dll [2005/06/10 10:00:00 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\cviUSI.dll [2003/01/30 07:04:00 | 00,618,496 | ---- | C] () -- C:\WINDOWS\System32\stlpmt45.dll [2002/02/15 10:29:02 | 00,000,172 | ---- | C] () -- C:\WINDOWS\recorsta.ini [2000/01/06 17:00:00 | 00,026,672 | ---- | C] () -- C:\WINDOWS\System32\procsvr.drv [2000/01/06 17:00:00 | 00,026,672 | ---- | C] () -- C:\WINDOWS\sysltime.dll ========== LOP Check ========== [2009/10/14 21:30:26 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data [2009/03/21 20:06:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3} [2009/10/03 18:13:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} [2009/08/17 19:34:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{7D4B3D1D-104E-4507-9123-568BC721B7E2} [2009/04/18 20:30:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} [2009/04/05 09:09:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore [2009/09/10 00:23:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk [2008/02/26 01:24:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dell [2008/08/07 21:20:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FaxCtr [2007/12/09 19:05:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet [2009/08/06 19:03:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations [2007/05/01 01:27:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intel [2009/08/31 22:05:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Logishrd [2008/05/13 11:30:07 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Memeo [2007/09/22 08:37:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Musicnotes [2008/05/23 20:44:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\National Instruments [2009/08/06 19:10:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia [2006/10/02 19:19:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap [2009/02/23 10:28:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SITEguard [2006/10/02 22:32:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SkillJam [2009/09/10 22:58:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SolidWorks [2009/02/23 11:38:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla! [2008/01/10 00:34:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft [2009/10/28 20:35:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2009/08/17 19:34:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Transparent [2006/12/12 01:49:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia [2009/07/29 11:10:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint [2008/02/13 15:14:55 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\WD [2009/10/26 22:18:07 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Nick Rummel\Application Data [2007/04/15 01:29:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\.gaim [2006/09/05 18:50:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\acccore [2009/02/24 17:02:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\advantage [2006/12/31 16:59:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\ArcSoft [2009/09/10 00:25:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Autodesk [2008/11/15 21:53:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\BitTorrent [2007/11/20 22:08:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Chessmaster Challenge [2006/09/21 19:22:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Corel Photo Album [2007/02/24 21:29:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\CyberLink [2009/02/24 17:31:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\DAEMON Tools [2009/02/24 17:01:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\DAEMON Tools Pro [2009/10/16 10:37:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\dvdcss [2008/02/11 18:29:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\DWGeditor [2008/08/08 11:13:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\FaxCtr [2007/09/29 12:04:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Gizmoz [2009/10/29 07:59:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\IM [2007/05/01 01:27:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Intel [2006/12/31 20:14:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Leadertech [2009/04/07 01:21:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\lrfmenuz [2006/09/08 15:26:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\MathWorks [2009/10/23 14:20:34 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Move Networks [2007/04/30 16:38:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\MSNInstaller [2006/12/09 13:15:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\NY-Yankees.net Toolbar [2006/12/06 18:50:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Opera [2008/09/05 00:37:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Prism [2007/05/17 17:11:46 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SecuROM [2009/02/21 16:21:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\sldIM [2007/02/24 21:36:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SlySoft [2009/10/23 00:12:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SolidWorks [2009/09/14 17:45:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SolidWorks 2009 [2007/11/20 21:51:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SpinTop [2007/05/19 17:42:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\SystemRequirementsLab [2008/12/17 02:03:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\U3 [2007/02/28 23:16:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Nick Rummel\Application Data\Vso [2009/10/24 18:59:05 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job [2004/08/10 03:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini [2009/10/25 18:58:23 | 00,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\McDefragTask.job [2009/10/25 18:58:21 | 00,000,344 | ---- | M] () -- C:\WINDOWS\Tasks\McQcTask.job [2009/10/29 07:40:59 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT [2009/10/29 08:01:03 | 00,000,246 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < %SYSTEMDRIVE%\eventlog.dll /s /md5 > [eventlog.dll : MD5=82B24CB70E5944E6E34662205A2A5B78] -> [2004/08/10 03:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) -- C:\i386\eventlog.dll [1 C:\i386\*.tmp files] [EventLog.dll : MD5=1363337A5301619F00F8033835EF30E9] -> [1999/10/03 20:38:26 | 00,017,408 | ---- | M] () -- C:\MATLAB6p5\sys\perl\win32\site\lib\auto\Win32\EventLog\EventLog.dll [eventlog.dll : MD5=82B24CB70E5944E6E34662205A2A5B78] -> [2004/08/10 03:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll [eventlog.dll : MD5=6D4FEB43EE538FC5428CC7F0565AA656] -> [2008/04/13 17:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ERDNT\cache\eventlog.dll [eventlog.dll : MD5=6D4FEB43EE538FC5428CC7F0565AA656] -> [2008/04/13 17:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll [eventlog.dll : MD5=6D4FEB43EE538FC5428CC7F0565AA656] -> [2008/04/13 17:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\eventlog.dll < %SYSTEMDRIVE%\scecli.dll /s /md5 > [scecli.dll : MD5=0F78E27F563F2AAF74B91A49E2ABF19A] -> [2004/08/10 03:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) -- C:\i386\scecli.dll [1 C:\i386\*.tmp files] [scecli.dll : MD5=0F78E27F563F2AAF74B91A49E2ABF19A] -> [2004/08/10 03:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll [scecli.dll : MD5=A86BB5E61BF3E39B62AB4C7E7085A084] -> [2008/04/13 17:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ERDNT\cache\scecli.dll [scecli.dll : MD5=A86BB5E61BF3E39B62AB4C7E7085A084] -> [2008/04/13 17:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll [scecli.dll : MD5=A86BB5E61BF3E39B62AB4C7E7085A084] -> [2008/04/13 17:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\scecli.dll < %SYSTEMDRIVE%\netlogon.dll /s /md5 > [netlogon.dll : MD5=96353FCECBA774BB8DA74A1C6507015A] -> [2004/08/10 03:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) -- C:\i386\netlogon.dll [1 C:\i386\*.tmp files] [netlogon.dll : MD5=96353FCECBA774BB8DA74A1C6507015A] -> [2004/08/10 03:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll [netlogon.dll : MD5=1B7F071C51B77C272875C3A23E1E4550] -> [2008/04/13 17:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ERDNT\cache\netlogon.dll [netlogon.dll : MD5=1B7F071C51B77C272875C3A23E1E4550] -> [2008/04/13 17:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll [netlogon.dll : MD5=1B7F071C51B77C272875C3A23E1E4550] -> [2008/04/13 17:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\netlogon.dll < %SYSTEMDRIVE%\cngaudit.dll /s /md5 > < %SYSTEMDRIVE%\sceclt.dll /s /md5 > < %SYSTEMDRIVE%\ntelogon.dll /s /md5 > < %SYSTEMDRIVE%\logevent.dll /s /md5 > < %SYSTEMDRIVE%\iaStor.sys /s /md5 > < %SYSTEMDRIVE%\nvstor.sys /s /md5 > < %SYSTEMDRIVE%\atapi.sys /s /md5 > [atapi.sys : MD5=CDFE4411A69C224BD1D11B2DA92DAC51] -> [2004/08/03 20:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) -- C:\i386\atapi.sys [1 C:\i386\*.tmp files] [atapi.sys : MD5=CDFE4411A69C224BD1D11B2DA92DAC51] -> [2004/08/03 20:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys [atapi.sys : MD5=9F3A2F5AA6875C72BF062C712CFA2674] -> [2008/04/13 11:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys [atapi.sys : MD5=9F3A2F5AA6875C72BF062C712CFA2674] -> [2008/04/13 11:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\atapi.sys [atapi.sys : MD5=CDFE4411A69C224BD1D11B2DA92DAC51] -> [2004/08/03 20:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys < %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 > < %SYSTEMDRIVE%\viasraid.sys /s /md5 > < %SYSTEMDRIVE%\AGP440.sys /s /md5 > [AGP440.SYS : MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB] -> [2004/08/03 21:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\i386\AGP440.SYS [1 C:\i386\*.tmp files] [agp440.sys : MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB] -> [2004/08/03 21:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys [agp440.sys : MD5=08FD04AA961BDC77FB983F328334E3D7] -> [2008/04/13 11:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ERDNT\cache\agp440.sys [agp440.sys : MD5=08FD04AA961BDC77FB983F328334E3D7] -> [2008/04/13 11:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys [agp440.sys : MD5=08FD04AA961BDC77FB983F328334E3D7] -> [2008/04/13 11:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\agp440.sys < %SYSTEMDRIVE%\vaxscsi.sys /s /md5 > C:\WINDOWS\system32\drivers\ -> C:\WINDOWS\System32\drivers -> [2009/10/29 09:00:33 | 00,000,000 | ---D | M] [vaxscsi.sys : Unable to obtain MD5 ] -> [2007/03/24 13:36:17 | 00,223,128 | ---- | M] () -- C:\WINDOWS\System32\drivers\vaxscsi.sys ========== Alternate Data Streams ========== @Alternate Data Stream - 61 bytes -> C:\Documents and Settings\All Users\Application Data\Symantec\hpc:468323563 @Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844 ========== Files - Unicode (All) ========== [2009/02/16 00:49:22 | 00,000,000 | ---D | M](C:\DoC?) -- C:\DoCԱ [2009/02/16 00:49:21 | 00,000,000 | ---D | C](C:\DoC?) -- C:\DoCԱ < End of report > |
|
|
Oct 29 2009, 04:58 PM
Post
#12
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows 2000 |
OTL Extras logfile created on: 10/29/2009 8:51:00 AM - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Documents and Settings\Nick Rummel\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1014.37 Mb Total Physical Memory | 332.24 Mb Available Physical Memory | 32.75% Memory free 2.38 Gb Paging File | 1.46 Gb Available in Paging File | 61.19% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 37.24 Gb Total Space | 4.27 Gb Free Space | 11.47% Space Free | Partition Type: NTFS Drive D: | 12.27 Gb Total Space | 12.03 Gb Free Space | 98.03% Space Free | Partition Type: NTFS Drive E: | 82.04 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: NRUMMEL Current User Name: Nick Rummel Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation) .html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .bat [@ = batfile] -- Reg Error: Key error. File not found .cmd [@ = cmdfile] -- Reg Error: Key error. File not found .com [@ = ComFile] -- Reg Error: Key error. File not found .exe [@ = exefile] -- Reg Error: Key error. File not found .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) .vbs [@ = VBSFile] -- Reg Error: Key error. File not found ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found chm.file [open] -- "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MI1933~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost -- File not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\DC++\DCPlusPlus.exe" = C:\Program Files\DC++\DCPlusPlus.exe:*:Enabled:DC++ -- () "C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- (AOL LLC) "C:\Program Files\DAP\DAP.exe" = C:\Program Files\DAP\DAP.exe:*:Enabled:Download Accelerator Plus (DAP) -- (Speedbit Ltd.) "C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation) "C:\Documents and Settings\Nick Rummel\My Documents\My Completed Downloads\eclipse-cpp-europa-win32\eclipse\eclipse.exe" = C:\Documents and Settings\Nick Rummel\My Documents\My Completed Downloads\eclipse-cpp-europa-win32\eclipse\eclipse.exe:*:Enabled:eclipse -- () "C:\Program Files\Java\jdk1.5.0_09\jre\bin\java.exe" = C:\Program Files\Java\jdk1.5.0_09\jre\bin\java.exe:*:Enabled:Java 2 Platform Standard Edition binary -- (Sun Microsystems, Inc.) "C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC) "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation) "C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- (Microsoft Corporation) "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation) "C:\Program Files\National Instruments\LabVIEW 8.2\LabVIEW.exe" = C:\Program Files\National Instruments\LabVIEW 8.2\LabVIEW.exe:*:Enabled:LabVIEW 8.2.1 Development System -- (National Instruments Corporation) "C:\Program Files\National Instruments\Shared\Example Finder\1.0\BIN\NIExampleFinder.exe" = C:\Program Files\National Instruments\Shared\Example Finder\1.0\BIN\NIExampleFinder.exe:*:Enabled:NIExampleFinder -- (National Instruments) "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation) "%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost -- File not found "C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe" = C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater -- (Nokia Corporation) "C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe" = C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process -- (Nokia Corporation) "C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.) "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.) "C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath -- (Skype Technologies S.A.) "C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent -- (McAfee, Inc.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{047DB692-BBD4-4768-91CC-ABD418B494B8}" = NI USI 1.4.1 "{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3 "{05A5B86B-7A8F-44B6-A43C-3B953E69F004}" = NI LabVIEW 8.2.1 Resource "{066A1255-1299-4EBA-B9B3-FA7FB14F92E4}" = CIF USB Camera "{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO "{071ED036-038F-4F6C-8188-B5E02602C8AD}" = NI LabVIEW MAX XML "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting "{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics "{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support "{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0 "{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView "{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE "{0EC523EE-3D9F-415C-8D30-95F973D53D87}" = NI LabVIEW Real-Time Error Dialog "{0ECB59D5-A3FC-4D61-AD3B-6CE679B3F852}" = Java DB 10.2.2.0 "{0EE24AF8-91DD-49C0-B50E-1986F67D2BE3}" = NI Instrument IO Assistant for LabVIEW 8.2 "{10560CCA-BCF6-47B0-A0BA-FB6E134A0AD7}" = NI LabVIEW 8.2.1 License "{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin "{1B140425-1EA0-4AB8-BB31-1830C4A0A1F2}" = DWGeditor "{1BCEA516-B4C5-4B2D-BFA0-AB7910BAD862}" = Adobe ExtendScript Toolkit 2 "{1C478488-78AD-4E94-B200-A10EC530A4E9}" = NI LabVIEW Broker "{1D476EFD-93EF-4E01-9505-C98FF606DF61}" = NI LabVIEW 8.2.1 Instr.lib "{1FB138CC-5503-4B4A-BC42-81E9C1FF26EE}" = Autodesk Inventor Content Center Libraries 2010 (Desktop Content) "{200FF4D5-1784-437A-A547-BFA7D735A5EB}" = Recording Station "{20969065-2AFF-4711-96F9-5D724007ACE4}" = NI LabVIEW 8.2.1 User.lib "{20F0F67B-CB0F-4C85-B6F2-133D9CB70614}" = Samsung PC Studio "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java 6 Update 13 "{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs "{28FF0691-1440-452D-96EB-269AA7A2F5A4}" = NI LabVIEW 8.2 Device Detection and Deployment Support "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3 "{2D2F7B3E-E0B7-444A-81F5-C45C63500FDB}" = NI MXS "{31274293-6159-4F39-B8D1-86279091DE49}" = NI LabWindows/CVI Code Generator "{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6 "{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9 "{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11 "{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java SE Runtime Environment 6 Update 1 "{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java 6 Update 2 "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7 "{32A3A4F4-B792-11D6-A78A-00B0D0150090}" = J2SE Development Kit 5.0 Update 9 "{32A3A4F4-B792-11D6-A78A-00B0D0160020}" = Java SE Development Kit 6 Update 2 "{33983300-C53D-4AC3-A7F9-6634E651D993}" = NI Measurement & Automation Explorer 4.2 "{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision "{35727E31-5D78-478A-B418-7E9A82729DB2}" = SolidWorks 2009 SP03 "{36A998F0-C15C-4AFD-BCAE-1C0577CCA29A}" = NI DataSocket 4.4.0 "{3A5A79C7-E7A5-4E18-9BC2-872D0BD38C58}" = NI LabVIEW 8.2.1 Examples "{3C782FEB-BC17-4CE1-8DD4-830C4DB2F1FC}" = NI LabVIEW 8.2.1 Templates "{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA "{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant "{3EE80F80-3CB1-4C9E-830C-1DABB2E76AFA}" = NI LabVIEW 8.2.1 gMath "{3F358B78-C154-46DF-8423-023729B42795}" = NI Example Finder 8.2 "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{4159DD60-49C1-4323-A1A5-FB060CBA35C5}" = NI Measurement Studio Recipe Processor "{452B119A-4D74-4FBB-A9A9-FD4D12F9B780}" = NI LabVIEW 8.2.1 WWW "{45C69E1F-D33F-413A-B8CF-FE8483219FFB}" = NI LabVIEW 8.2.1 Project "{45FA54F6-8574-49D2-9E2D-0BDDE6237822}" = NI LabVIEW Run-Time Engine 8.2.1 "{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon "{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell "{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement "{4F66ADD6-FC65-4A55-92A7-1D35E5E7D59D}" = NI LabVIEW 8.2 Help "{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings "{52969324-463B-4643-BF36-854BE2BECB89}" = Autodesk Inventor 2010 English Language Pack "{52D02A2B-03D2-4E34-A358-DC5D951FD296}" = Nokia Connectivity Cable Driver "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3 "{54B5C1CD-CD34-4F0B-B995-9D42AE3EA190}" = NI Variable Manager "{5535426F-E814-4B34-9B36-726E9DBEB7A7}" = NI Logos 4.7 "{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01) "{55D9E026-DCB0-46FF-B60A-68B972228CF6}" = Autodesk Design Review 2010 "{55DA893C-8337-4EEB-B0E5-009C6BB425E3}" = NI Remote Provider for MAX "{57700DD3-0C10-4CE6-95BA-630284EE2CB1}" = NI License Manager "{5783F2D7-8028-0409-0000-0060B0CE6BBA}" = DWG TrueView 2010 "{5A9F6AE3-85D6-4411-B707-29A85F6E274F}" = NI Remote PXI Provider for MAX "{5B641F4F-A9A7-49A7-917E-EB1E1F5626E1}" = NI LabVIEW 8.2 MeasAppChm File "{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.5 "{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon "{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI "{65F1EE0F-F9D2-45E1-8E14-2EBFF34E90A0}" = NI LVBrokerAux8.0 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7 "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All "{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7 "{6D2737AE-8898-4BE1-AE46-555B7DB540A8}" = NI MDF Support "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works "{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal "{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{736175D8-263C-436E-B654-EF99B2F0C8BA}" = NI-RPC 3.3.1f0 for Phar Lap ETS "{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore "{78231F18-FD98-4B03-A932-DE9329594D08}" = NI TDMS "{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam "{7D26E5EA-63A2-4C4B-BE97-446404685C59}" = NI LabVIEW 8.2.1 CINtools "{7D3E7FA0-F95A-4942-B188-56582CE0C7CC}" = NI Software Provider for MAX "{7E3668CB-1228-416E-B721-C2FA3247B985}" = NI LabVIEW Real-Time FIFO for Runtime "{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport "{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper "{7F4DD591-1400-0409-0000-7107D70F3DB4}" = Autodesk Inventor 2010 "{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3 "{80BA07B3-537F-4189-92F7-26E2BA76095A}" = SolidWorks eDrawings 2009 "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{86F908CA-B1B4-476B-B8EB-7FC1D32C7A05}" = NI OPC Support "{873258AA-8BEA-4B76-B158-F42A7FE304BB}" = NI LabVIEW 8.2.1 Simulation "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver "{8B073FE8-ED47-439E-94A9-68C1B8242FC1}" = NI-RPC 3.3.1f0 "{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3 "{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12 "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003 "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3 "{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003 "{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz "{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{911F2BEE-4919-4BA3-A097-B014070FD738}" = NI Assistant Framework LabVIEW Code Generator 8.0 "{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig "{94721EA3-7EA6-43EA-B99C-A5D0E3C66240}" = 924PLC32 "{94F8151E-1946-4D81-9FBF-E167DF25954A}" = NI LabVIEW Run-Time Engine 8.0 "{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings "{98618CFE-CACD-48C4-85EA-F9197FFEDD0C}" = NI Assistant Framework LabVIEW Code Generator 6.1 "{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3 "{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML "{9D65A47A-0929-4C50-A3BD-3AF59DA38ED8}" = NI LabVIEW 8.2.1 iMath "{9E0AE153-88DC-428B-99EB-6A3D984230B8}" = NI LabWindows/CVI 7.1.1 Run Time Engine "{9FBEC876-60EB-4BAC-BF51-E7EF29C1D71A}" = NI Assistant Framework LabVIEW Code Generator 8.2 "{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime "{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU "{AA11363D-DF31-419C-961D-D8A5F148651D}" = NI LabVIEW Deployable License 8.2 "{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support "{AC1D71B5-B622-40D2-979A-BA55261A86EB}" = NI LabVIEW 8.2.1 Applibs "{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings "{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0 "{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher "{B306061F-9083-4DAB-9809-C4DDAF319273}" = NI LabVIEW 8.2.1 Menus "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0 "{B51CC1CD-5828-4441-9C8F-7659ACF1BF65}" = NI LabVIEW 8.2.1 VI.lib "{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{B84F8170-2D08-438A-A307-F23C4EA95430}" = NI LabVIEW 8.2 Help File "{B9A81070-616D-4E93-BE02-CEE651343204}" = WD Anywhere Backup "{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3 "{BA68600E-96D9-4E92-80F2-26B9681B5A63}" = Microsoft Office Outlook 2003 with Business Contact Manager Update "{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component "{BFAA820A-C7D8-42AE-A3BA-CE118F3F0802}" = NI Service Locator "{BFEA2222-557D-4F0D-B1AE-64EECBCA2747}" = NI VC2005MSMs x86 "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C19781D2-3D75-4245-9CFC-CAE37CCA8A40}" = Samsung PC Studio "{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet "{C5253437-5F29-44D3-9665-1AB316A11850}" = NI Variable Engine LabVIEW 8.2.1 Support "{C532C3FA-4241-4521-9FAC-1FA20BAE36B6}" = NI Variable Engine "{C6B62A71-A0E5-4D3A-9EFC-05A8A7C31337}" = BASIC Stamp Editor v2.0 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client "{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files "{D2EB6337-42E5-4D6E-B01F-2FF9E30F4A06}" = NI Web Pipeline "{D481EA96-2313-4A7C-98EE-710D1AF884AC}" = Microsoft Visual Studio 2005 Tools for Applications - ENU "{D504303A-717D-414C-BA9F-FE01093E2EF8}" = Adobe Setup "{D6FAEBB1-90E0-4CF8-9A41-9087E6789D11}" = NI EULA Depot "{D89EEEA4-78D7-4533-AEF4-D7918EF359D2}" = NI LabVIEW 8.2 Manuals "{D9529709-28B0-4DA1-8749-8924C11AAFF2}" = NI Registration Wizard "{D96D5628-9EAB-4F43-ADC9-3A9A77DAB3DD}" = NI MAX LabVIEW Support "{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes "{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings "{DB2C5648-700D-4AEF-83E1-70C72F0C34FA}" = NI Math Kernel Libraries "{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings "{DEC25D81-2317-47F6-8B26-D54A939DA1EE}" = NI LabVIEW C Interface "{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}" = Search Assist "{E064390A-2F64-4195-9A55-30D4B20B865A}" = WDCSAM Driver "{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ) "{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software) "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E4198521-8BA7-45FE-B16D-6B192EB5798F}" = NI Portable Configuration "{E42BD75A-FC23-4E3F-9F91-2658334C644F}" = Internet Service Offers Launcher "{E5B1DA8B-D2C2-4E4F-82CF-28C169FD4598}" = NI Assistant Framework LabVIEW Code Generator 7.1 "{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3 "{E80BEC94-A496-4CE6-89B5-08922D1CCD84}" = BASIC Stamp Editor v2.3.9 "{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore "{E8991297-B702-44AA-ABAA-02C12045D8E9}" = NI Uninstaller "{E8C06CB3-5DB2-4689-B1DC-4A0220DEA96C}" = Consumer Complete Care Services Agreement "{E9BC36C5-6265-4FE6-B7D2-11C0474DA681}" = NI LabVIEW 8.2.1 Activity "{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator "{EB9E7F70-8F2E-412A-A182-FAC85345FDCC}" = NI Assistant Framework LabVIEW Code Generator 7.0 "{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = GE MiniCam Pro "{EFD09F8C-6F4C-416C-B1FD-047D452556DC}" = NI-DAQmx - LabVIEW shared documentation "{F06DCD6F-171E-4D51-942D-348D1829F6EE}" = NI LabVIEW 8.2.1 "{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse "{F5A51F25-F1F4-419F-8888-22A768CFE3C2}" = NI Logos LabVIEW 8.2 Support "{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi "{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}" = Nokia Software Updater "{F9F3C962-A2E6-49D1-BF34-7A6D2023D2CE}" = NI Help Assistant "{FBC11FAF-CC2E-4614-A6C5-D5DDDE276572}" = NI LVBrokerAux 8.2.1 "{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe "{FD1F0BFE-E5D9-4116-90C3-78999D61EF12}" = NI Assistant Framework "{FD9E03B5-AEEA-4D59-B512-6CE4AA0281D4}" = Byki "{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup "00BD1CD47675C125126C80095FCC12CFA4D311DB" = Windows Driver Package - FTDI CDM Driver Package (06/27/2007 2.02.04) "126C456AE165F5E8391AB722C9C16C4D76981DEA" = Windows Driver Package - Intel net (03/13/2008 11.5.1.15) "18FF359AE500F8C84B16BD7C8065F75AFEAE4CDF" = Windows Driver Package - Intel (w29n51) net (10/25/2006 9.0.4.26) "2DA959FE3D6F0F5BC313481E72071D510DD786FB" = Windows Driver Package - Intel (w29n51) net (12/19/2007 9.0.4.39) "8A1D0449E9CBCC93DCB0CF47934D695423632CA7" = Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM (12/05/2006 1.0.0007.0) "A106663FD3361BDFACB045D83EBA03858EB1E411" = Windows Driver Package - FTDI CDM Driver Package (03/13/2008 2.04.06) "A622B79B943ECA1F0AECF1FF5BE13D458F345EBB" = Windows Driver Package - FTDI CDM Driver Package (06/27/2007 2.02.04) "Absolute Fretboard Trainer PRO" = Absolute Fretboard Trainer PRO "Ad-Aware SE Personal" = Ad-Aware SE Personal "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player "Adobe_5bc0f8414ec36c555a3e7e5ec2e225e" = Adobe ExtendScript Toolkit 2 "Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3 "AIM_6" = AIM 6 "Akamai" = Akamai NetSession Interface "Autodesk Design Review 2010" = Autodesk Design Review 2010 "Autodesk Inventor 2010" = Autodesk Inventor Professional 2010 "B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto "Byki Express" = Byki Express "CleanMyPC Popup Blocker" = CleanMyPC Popup Blocker "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem "D4DEFCEEE19FBF84C44EE0E5CF3716D67F3A4261" = Windows Driver Package - Intel (NETw4x32) net (03/13/2008 11.5.1.15) "DC++" = DC++ 0.667 "Dell Game Console" = Dell Game Console "Dell Photo AIO Printer 924" = Dell Photo AIO Printer 924 "Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP) "DWG TrueView 2010" = DWG TrueView 2010 "EES - Engineering Equation Solver (Limited Academic Version)" = EES - Engineering Equation Solver (Limited Academic Version) "EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] "ENTERPRISER" = Microsoft Office Enterprise 2007 "F2F24872454C7CAEAABD8BB063F70FBEFF01989D" = Windows Driver Package - FTDI CDM Driver Package (03/13/2008 2.04.06) "FF9C6C89964495D9F1AC86587EF985784D8AD152" = Windows Driver Package - Intel (NETw3x32) net (10/17/2006 10.5.1.72) "Free Video Flip and Rotate_is1" = Free Video Flip and Rotate version 1.5 "GENEUIDE" = USB Storage Driver "GTK 2.0" = GTK+ Runtime 2.6.9 rev a (remove only) "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "InstallShield_{200FF4D5-1784-437A-A547-BFA7D735A5EB}" = Recording Station "InterActual Player" = InterActual Player "Java Platform, Enterprise Edition 5 SDK" = Java Platform, Enterprise Edition 5 SDK "Lexmark 4300 Series" = Lexmark 4300 Series "Lexmark Fax Solutions" = Lexmark Fax Solutions "LiveUpdate" = LiveUpdate 3.1 (Symantec Corporation) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Matlab 6.5" = MATLAB 6.5 "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft Visual Studio 2005 Tools for Applications - ENU" = Microsoft Visual Studio 2005 Tools for Applications - ENU "Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13) "MSC" = McAfee SecurityCenter "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "NI Uninstaller" = National Instruments Software "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "Picasa 3" = Picasa 3 "Prism_is1" = Prism 0.8 "ProInst" = Intel® PROSet/Wireless Software "QcDrv" = Logitech® Camera Driver "RealPlayer 6.0" = RealPlayer "SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set "Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software "SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software "SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software "Sibelius Scorch Plugin" = Sibelius Scorch Plugin "SkillJam SecurePlayer" = Secure Game Player "SoftwareUpdUtility" = Download Updater (AOL LLC) "SolidWorks Installation Manager 20090-40300-1100-200" = SolidWorks 2009 SP03 "ST6UNST #1" = Advanced Control Shareware Version "StreetPlugin" = Learn2 Player (Uninstall Only) "SynTPDeinstKey" = Synaptics Pointing Device Driver "SystemRequirementsLab" = System Requirements Lab "Uninstall_is1" = Uninstall 1.0.0.1 "Video Converter 3" = Video Converter 3 "VLC media player" = VideoLAN VLC media player 0.8.5 "Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 "WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = WinRAR archiver "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "InstallShield_{B9A81070-616D-4E93-BE02-CEE651343204}" = WD Anywhere Backup "Move Media Player" = Move Media Player ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 10/27/2009 11:32:39 PM | Computer Name = NRUMMEL | Source = Application Error | ID = 1000 Description = Faulting application skypepm.exe, version 1.5.0.3, faulting module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb. Error - 10/27/2009 11:34:41 PM | Computer Name = NRUMMEL | Source = Application Error | ID = 1000 Description = Faulting application skype.exe, version 3.5.0.229, faulting module , version 0.0.0.0, fault address 0x00000000. Error - 10/27/2009 11:35:51 PM | Computer Name = NRUMMEL | Source = Application Error | ID = 1000 Description = Faulting application skypepm.exe, version 1.5.0.3, faulting module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb. Error - 10/27/2009 11:45:34 PM | Computer Name = NRUMMEL | Source = Symantec AntiVirus | ID = 16711725 Description = Error - 10/27/2009 11:50:58 PM | Computer Name = NRUMMEL | Source = Application Hang | ID = 1002 Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 10/28/2009 3:35:06 AM | Computer Name = NRUMMEL | Source = .NET Runtime 2.0 Error Reporting | ID = 5000 Description = EventType clr20r3, P1 memeolauncher.exe, P2 2.0.0.0, P3 46b24a74, P4 system.configuration, P5 2.0.0.0, P6 4889de74, P7 277, P8 14, P9 ioibmurhynrxkw0zxkyrvfn0boyyufow, P10 NIL. Error - 10/28/2009 11:36:46 AM | Computer Name = NRUMMEL | Source = .NET Runtime 2.0 Error Reporting | ID = 5000 Description = EventType clr20r3, P1 memeolauncher.exe, P2 2.0.0.0, P3 46b24a74, P4 system.configuration, P5 2.0.0.0, P6 4889de74, P7 277, P8 14, P9 ioibmurhynrxkw0zxkyrvfn0boyyufow, P10 NIL. Error - 10/28/2009 12:49:17 PM | Computer Name = NRUMMEL | Source = .NET Runtime 2.0 Error Reporting | ID = 5000 Description = EventType clr20r3, P1 memeolauncher.exe, P2 2.0.0.0, P3 46b24a74, P4 system.configuration, P5 2.0.0.0, P6 4889de74, P7 277, P8 14, P9 ioibmurhynrxkw0zxkyrvfn0boyyufow, P10 NIL. Error - 10/28/2009 6:55:00 PM | Computer Name = NRUMMEL | Source = .NET Runtime 2.0 Error Reporting | ID = 5000 Description = EventType clr20r3, P1 memeolauncher.exe, P2 2.0.0.0, P3 46b24a74, P4 system.configuration, P5 2.0.0.0, P6 4889de74, P7 277, P8 14, P9 ioibmurhynrxkw0zxkyrvfn0boyyufow, P10 NIL. Error - 10/29/2009 11:01:07 AM | Computer Name = NRUMMEL | Source = .NET Runtime 2.0 Error Reporting | ID = 5000 Description = EventType clr20r3, P1 memeolauncher.exe, P2 2.0.0.0, P3 46b24a74, P4 system.configuration, P5 2.0.0.0, P6 4889de74, P7 277, P8 14, P9 ioibmurhynrxkw0zxkyrvfn0boyyufow, P10 NIL. [ OSession Events ] Error - 12/1/2008 8:50:51 PM | Computer Name = NRUMMEL | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 332 seconds with 300 seconds of active time. This session ended with a crash. [ System Events ] Error - 10/1/2009 6:52:24 PM | Computer Name = NRUMMEL | Source = Service Control Manager | ID = 7034 Description = The SupportSoft Sprocket Service (dellsupportcenter) service terminated unexpectedly. It has done this 1 time(s). Error - 10/2/2009 9:51:07 PM | Computer Name = NRUMMEL | Source = Service Control Manager | ID = 7011 Description = Timeout (30000 milliseconds) waiting for a transaction response from the wscsvc service. Error - 10/3/2009 12:40:42 PM | Computer Name = NRUMMEL | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect. Error - 10/3/2009 12:40:43 PM | Computer Name = NRUMMEL | Source = DCOM | ID = 10005 Description = DCOM got error "%1053" attempting to start the service LiveUpdate with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435} Error - 10/3/2009 12:40:46 PM | Computer Name = NRUMMEL | Source = Service Control Manager | ID = 7000 Description = The LiveUpdate service failed to start due to the following error: %%1053 Error - 10/3/2009 12:41:56 PM | Computer Name = NRUMMEL | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.2.100 for the Network Card with network address 0018DE0DD791 has been denied by the DHCP server 172.16.0.1 (The DHCP Server sent a DHCPNACK message). Error - 10/3/2009 4:06:19 PM | Computer Name = NRUMMEL | Source = W32Time | ID = 39452689 Description = Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) Error - 10/3/2009 4:06:19 PM | Computer Name = NRUMMEL | Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Error - 10/3/2009 9:53:19 PM | Computer Name = NRUMMEL | Source = W32Time | ID = 39452689 Description = Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) Error - 10/3/2009 9:53:19 PM | Computer Name = NRUMMEL | Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. < End of report > |
|
|
Oct 29 2009, 05:10 PM
Post
#13
|
|
![]() GeekU Teacher Posts: 35,111 From: Dublin OS: XP |
hi
Please download GooredFix from one of the locations below and save it to your Desktop Download Mirror #1 Download Mirror #2
1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: QUOTE File:: SRPeek:: C:\WINDOWS\System32\drivers\vaxscsi.sys Mia:: C:\WINDOWS\System32\drivers\vaxscsi.sys Folder:: Registry:: Driver:: Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. Run OTL
|
|
|
Oct 30 2009, 12:34 AM
Post
#14
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows 2000 |
GooredFix by jpshortstuff (24.09.09.1)
Log created at 23:33 on 29/10/2009 (Nick Rummel) Firefox version 3.0.13 (en-US) ========== GooredScan ========== Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{69718F4B-3565-4D65-B418-A321269E8B74} -> Success! Deleting C:\Documents and Settings\Nick Rummel\Local Settings\Application Data\{69718F4B-3565-4D65-B418-A321269E8B74} -> Success! ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {3112ca9c-de6d-4884-a869-9855de68056c} [01:41 06/09/2006] {972ce4c6-7e08-4474-a285-3208198ce6fd} [05:48 16/04/2009] {B13721C7-F507-4982-B2E5-502A71474FED} [00:38 31/08/2007] {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [08:37 15/04/2007] {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [01:14 19/08/2007] {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [05:21 30/10/2007] {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [18:15 21/08/2008] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{B7082FAA-CB62-4872-9106-E42DD88EDE45}"="C:\Program Files\McAfee\SiteAdvisor" [21:12 09/06/2008] "jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [04:58 05/06/2009] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [04:35 06/12/2009] -=E.O.F=- |
|
|
Oct 30 2009, 01:27 AM
Post
#15
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows 2000 |
ComboFix 09-10-28.08 - Nick Rummel 10/29/2009 23:58.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.434 [GMT -7:00] Running from: c:\documents and settings\Nick Rummel\Desktop\Combo-Fix.exe Command switches used :: c:\documents and settings\Nick Rummel\Desktop\CFScript.txt AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . Infected copy of c:\windows\system32\drivers\vaxscsi.sys was found and disinfected Restored copy from - Kitty ate it . ((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-30 ))))))))))))))))))))))))))))))) . 2009-12-06 04:33 . 2009-12-06 04:33 -------- dc----w- c:\windows\system32\XPSViewer 2009-12-06 04:31 . 2009-12-06 04:31 -------- dc----w- c:\program files\Reference Assemblies 2009-12-06 04:29 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\xpsshhdr.dll 2009-12-06 04:29 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll 2009-12-06 04:29 . 2008-07-06 12:06 117760 -c----w- c:\windows\system32\prntvpt.dll 2009-12-06 04:29 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\xpssvcs.dll 2009-12-06 04:29 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll 2009-12-06 04:28 . 2009-08-06 03:54 -------- dc----w- c:\windows\SxsCaPendDel 2009-10-29 15:20 . 2009-10-29 15:20 -------- dc----w- c:\program files\SiteAdvisor 2009-10-28 22:42 . 2009-10-28 22:42 -------- dc----w- C:\_OTM 2009-10-28 14:55 . 2009-10-28 14:56 -------- dc----w- C:\Combo-Fix 2009-10-26 23:34 . 2006-03-03 15:07 143360 -c--a-w- c:\windows\system32\dunzip32.dll 2009-10-26 01:59 . 2009-09-16 17:22 34248 -c--a-w- c:\windows\system32\drivers\mferkdk.sys 2009-10-26 01:59 . 2009-09-16 17:22 40552 -c--a-w- c:\windows\system32\drivers\mfesmfk.sys 2009-10-26 01:59 . 2009-09-16 17:22 35272 -c--a-w- c:\windows\system32\drivers\mfebopk.sys 2009-10-26 01:59 . 2009-09-16 17:22 79816 -c--a-w- c:\windows\system32\drivers\mfeavfk.sys 2009-10-26 01:59 . 2009-09-16 17:22 214664 -c--a-w- c:\windows\system32\drivers\mfehidk.sys 2009-10-26 01:59 . 2009-07-16 19:32 120136 -c--a-w- c:\windows\system32\drivers\Mpfp.sys 2009-10-26 01:57 . 2009-10-26 01:58 -------- dc----w- c:\program files\McAfee.com 2009-10-26 01:25 . 2009-10-26 01:37 -------- dc----w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\AskToolbar 2009-10-23 06:49 . 2009-10-23 06:49 -------- dc----w- c:\program files\Ask.com 2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\Common Files\DVDVideoSoft 2009-10-23 06:48 . 2009-10-23 06:48 -------- dc----w- c:\program files\DVDVideoSoft 2009-10-21 23:40 . 2009-10-21 23:40 -------- dc----w- C:\EmergencyUtils 2009-10-15 04:30 . 2009-10-29 03:35 -------- dc--a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-10-04 01:12 . 2009-10-04 01:12 -------- dc----w- c:\program files\iPod 2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\program files\iTunes 2009-10-04 01:11 . 2009-10-04 01:13 -------- dc----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-10-01 22:35 . 2009-10-01 22:35 287080 -c--a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-06 04:32 . 2008-01-11 18:01 -------- dc----w- c:\program files\MSBuild 2009-10-30 06:52 . 2009-09-09 02:26 -------- dc----w- c:\program files\Common Files\Akamai 2009-10-30 06:27 . 2007-08-31 00:39 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Skype 2009-10-30 02:44 . 2008-06-09 21:11 -------- dc----w- c:\program files\McAfee 2009-10-30 02:32 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\McAfee 2009-10-29 14:59 . 2009-09-11 03:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\IM 2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\program files\Common Files\Symantec Shared 2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\program files\Symantec 2009-10-28 04:02 . 2007-03-24 18:30 -------- dc----w- c:\program files\Symantec AntiVirus 2009-10-28 04:02 . 2006-08-28 06:38 -------- dc----w- c:\documents and settings\All Users\Application Data\Symantec 2009-10-28 01:43 . 2008-08-08 04:17 -------- dc----w- c:\program files\Lx_cats 2009-10-28 01:39 . 2006-09-05 23:32 -------- dc----w- c:\program files\Dl_cats 2009-10-27 05:17 . 2007-10-16 00:40 -------- dc----w- c:\documents and settings\All Users\Application Data\SiteAdvisor 2009-10-26 01:59 . 2008-06-09 21:12 -------- dc----w- c:\program files\Common Files\McAfee 2009-10-23 21:20 . 2007-05-17 18:06 -------- dc-h--w- c:\documents and settings\Nick Rummel\Application Data\Move Networks 2009-10-23 07:12 . 2008-02-11 02:48 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks 2009-10-16 17:37 . 2006-10-12 19:19 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\dvdcss 2009-10-04 01:12 . 2007-07-01 16:27 -------- dc----w- c:\program files\Common Files\Apple 2009-10-04 00:53 . 2007-12-10 02:00 -------- dc----w- c:\program files\Bonjour 2009-10-04 00:52 . 2007-07-16 02:03 -------- dc----w- c:\program files\QuickTime 2009-09-24 04:46 . 2008-05-20 03:28 -------- dc----w- c:\program files\AFT software 2009-09-24 04:46 . 2008-05-14 06:06 796672 -c--a-w- c:\windows\GPInstall.exe 2009-09-16 23:19 . 2009-09-16 23:19 -------- dc----w- c:\documents and settings\LocalService\Application Data\McAfee 2009-09-15 00:45 . 2009-09-15 00:40 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\SolidWorks 2009 2009-09-15 00:02 . 2009-09-15 00:02 3026 -c--a-w- c:\windows\system32\drivers\hwinterface.sys 2009-09-15 00:02 . 2006-09-05 23:14 152872 -c--a-w- c:\documents and settings\Nick Rummel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-11 14:18 . 2005-08-16 09:18 136192 -c--a-w- c:\windows\system32\msv1_0.dll 2009-09-11 06:09 . 2008-01-11 17:48 -------- dc----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-09-11 06:05 . 2008-02-11 02:18 -------- dc----w- c:\program files\Common Files\SolidWorks Shared 2009-09-11 05:59 . 2009-09-11 05:58 -------- dc----w- c:\program files\AGEIA Technologies 2009-09-11 05:58 . 2009-02-25 01:24 -------- dc----w- c:\documents and settings\All Users\Application Data\SolidWorks 2009-09-11 05:52 . 2009-09-11 05:52 -------- dc----w- c:\program files\MSECache 2009-09-11 05:48 . 2009-09-11 05:47 -------- dc----w- c:\program files\Microsoft Visual Studio 8 2009-09-11 03:26 . 2009-09-11 03:25 -------- dc----w- c:\program files\Common Files\SolidWorks Installation Manager 2009-09-10 07:25 . 2008-01-18 06:30 -------- dc----w- c:\documents and settings\Nick Rummel\Application Data\Autodesk 2009-09-10 07:23 . 2009-09-09 06:24 -------- dc----w- c:\documents and settings\All Users\Application Data\Autodesk 2009-09-09 06:40 . 2009-09-09 06:18 -------- dc----w- c:\program files\Autodesk 2009-09-09 06:38 . 2008-01-18 06:25 -------- dc----w- c:\program files\Common Files\Autodesk Shared 2009-09-09 06:25 . 2009-09-09 06:24 -------- dc----w- c:\program files\DWG TrueView 2010 2009-09-09 06:13 . 2006-08-28 06:28 -------- dc-h--w- c:\program files\InstallShield Installation Information 2009-09-04 21:03 . 2005-08-16 09:18 58880 -c--a-w- c:\windows\system32\msasn1.dll 2009-09-01 05:59 . 2009-09-01 05:05 -------- dc----w- c:\program files\Common Files\LogiShrd 2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logishrd 2009-09-01 05:05 . 2009-09-01 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Logitech 2009-09-01 05:04 . 2009-09-01 01:00 -------- dc----w- c:\program files\Logitech 2009-09-01 04:06 . 2009-04-07 05:02 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware 2009-08-29 07:36 . 2005-08-16 09:18 832512 -c----w- c:\windows\system32\wininet.dll 2009-08-29 07:36 . 2005-08-16 09:18 78336 -c--a-w- c:\windows\system32\ieencode.dll 2009-08-29 07:36 . 2005-08-16 09:18 17408 -c----w- c:\windows\system32\corpol.dll 2009-08-26 08:00 . 2005-08-16 09:19 247326 -c--a-w- c:\windows\system32\strmdll.dll 2009-08-25 05:59 . 2006-09-22 02:21 3766 -csha-w- c:\windows\system32\KGyGaAvL.sys 2009-08-25 05:59 . 2006-09-22 02:21 88 -csh--r- c:\windows\system32\68430E414D.sys 2009-08-07 02:24 . 2005-08-16 09:40 327896 -c--a-w- c:\windows\system32\wucltui.dll 2009-08-07 02:24 . 2005-08-16 09:40 209632 -c--a-w- c:\windows\system32\wuweb.dll 2009-08-07 02:24 . 2005-08-16 09:40 35552 -c--a-w- c:\windows\system32\wups.dll 2009-08-07 02:24 . 2005-05-26 11:16 44768 -c--a-w- c:\windows\system32\wups2.dll 2009-08-07 02:24 . 2005-08-16 09:40 53472 -c----w- c:\windows\system32\wuauclt.exe 2009-08-07 02:24 . 2005-08-16 09:18 96480 -c--a-w- c:\windows\system32\cdm.dll 2009-08-07 02:23 . 2005-08-16 09:40 575704 -c--a-w- c:\windows\system32\wuapi.dll 2009-08-07 02:23 . 2005-08-16 09:40 1929952 -c--a-w- c:\windows\system32\wuaueng.dll 2009-08-05 09:01 . 2005-08-16 09:18 204800 -c--a-w- c:\windows\system32\mswebdvd.dll 2009-08-04 15:13 . 2005-08-16 09:18 2145280 -c----w- c:\windows\system32\ntoskrnl.exe 2009-08-04 14:20 . 2004-08-04 03:59 2023936 -c----w- c:\windows\system32\ntkrnlpa.exe 2006-12-07 01:49 . 2006-12-07 01:49 592 -c--a-w- c:\program files\Opera.lnk 2006-09-06 01:35 . 2006-09-06 01:35 1626 -c--a-w- c:\program files\QuickTime Player.lnk 2006-09-06 01:14 . 2006-09-06 01:14 841 -c--a-w- c:\program files\Ad-Aware SE Personal.lnk 2006-09-05 23:34 . 2006-09-05 23:34 1753 -c--a-w- c:\program files\Dell Printer Supplies - Inkjet.lnk 2006-09-05 23:01 . 2006-09-05 23:01 786 -c--a-w- c:\program files\Windows Media Player.lnk 2006-08-29 15:54 . 2006-08-29 15:54 1752 -c--a-w- c:\program files\main.ini 2006-08-28 06:56 . 2006-08-28 06:56 1967 -c--a-w- c:\program files\Internet Service Offers.lnk 2006-08-28 06:56 . 2006-08-28 06:56 1965 -c--a-w- c:\program files\Games, Music, & Photos.lnk 2006-08-28 06:56 . 2006-08-28 06:56 1958 -c--a-w- c:\program files\Documentation & Support.lnk 2006-08-28 06:45 . 2006-08-28 06:45 1661 -c--a-w- c:\program files\Trend Micro PC-cillin Internet Security 12.lnk 2005-08-16 09:52 . 2006-09-05 23:01 1298 -c--a-w- c:\program files\Media Center.lnk 2005-10-12 22:04 . 2005-10-12 22:04 131072 -c--a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll 2007-02-08 17:48 . 2007-02-08 17:48 133920 -c--a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll . (((((((((((((((((((((((((((((((((((((((((( SR_Search )))))))))))))))))))))))))))))))))))))))))))))))))))))))) [-] !HASH: COULD NOT OPEN FILE !!!!! 223128 c:\windows\system32\drivers\vaxscsi.sys [7] 92CEBC2BC7BE2C8D49391B365569F306 223128 \RP108\A0053002.sys [7] 92CEBC2BC7BE2C8D49391B365569F306 223128 \RP110\A0057657.sys . ((((((((((((((((((((((((((((( SnapShot@2009-10-28_01.43.18 ))))))))))))))))))))))))))))))))))))))))) . + 2009-10-30 06:52 . 2009-10-30 06:52 16384 c:\windows\Temp\Perflib_Perfdata_930.dat + 2009-10-28 22:34 . 2009-10-30 07:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2006-09-05 22:48 . 2009-10-30 07:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2006-09-05 22:48 . 2009-10-27 18:58 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2006-09-05 22:48 . 2009-10-27 18:58 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2009-10-28 22:34 . 2009-10-30 07:05 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2009-10-29 16:15 . 2009-10-29 16:15 20480 c:\windows\assembly\GAC\ArbusApplicationController\1.0.3093.38280__da57d5d39b1d6dd8\ArbusApplicationController.dll + 2009-10-29 16:15 . 2009-10-29 16:15 20480 c:\windows\assembly\GAC\Arbus.Interfacing.Library\1.0.4.0__2be3a081d8c94867\Arbus.Interfacing.Library.dll + 2009-10-29 16:12 . 2009-10-29 16:12 152872 c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT + 2009-10-29 16:15 . 2009-10-29 16:15 126976 c:\windows\assembly\GAC\Arbus.Common\2.2.4.3__14cac4d33a885ed2\Arbus.Common.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2009-06-17 00:22 1144712 -c--a-w- c:\program files\Ask.com\GenericAskToolbar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712] [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712] [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-07 68856] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-14 98304] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-14 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-14 118784] "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718] "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960] "DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728] "dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-05 148888] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-12-04 185896] "Dell QuickSet"="c:\progra~1\Dell\QuickSet\quickset.exe" [2006-04-06 1032192] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392] "tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-10 270336] "realteks"="c:\documents and settings\Nick Rummel\Application Data\Google\tncfc7316459.exe" [2009-07-15 0] "LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728] "lxcemon.exe"="c:\program files\Lexmark 4300 Series\lxcemon.exe" [2005-08-02 192512] "EzPrint"="c:\program files\Lexmark 4300 Series\ezprint.exe" [2005-07-26 94208] "FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008] "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 488984] "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 774168] "SolidWorks_CheckForUpdates"="c:\program files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe" [2009-03-20 7308584] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328] "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-25 282624] "WD Button Manager"="WDBtnMgr.exe" - c:\windows\system32\WDBtnMgr.exe [2009-06-11 364544] c:\documents and settings\Nick Rummel\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632] WD Anywhere Backup Launcher.lnk - c:\documents and settings\Nick Rummel\Application Data\Microsoft\Installer\{B9A81070-616D-4E93-BE02-CEE651343204}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe [2008-2-13 17542] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696] Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-27 24576] Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920] Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2006-3-26 257752] [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] Source= c:\windows\system32\onhelp.htm FriendlyName= tets [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-09-03 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-09-03 18:40 352256 -c--a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ \0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\DC++\\DCPlusPlus.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\DAP\\DAP.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Documents and Settings\\Nick Rummel\\My Documents\\My Completed Downloads\\eclipse-cpp-europa-win32\\eclipse\\eclipse.exe"= "c:\\Program Files\\Java\\jdk1.5.0_09\\jre\\bin\\java.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"= "c:\\Program Files\\National Instruments\\Shared\\Example Finder\\1.0\\BIN\\NIExampleFinder.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "%windir%\\system32\\drivers\\svchost.exe"= "c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"= "c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [9/14/2009 5:02 PM 3026] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [10/10/2006 12:53 PM 8944] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 11:39 AM 55024] R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/16/2005 2:18 AM 14336] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [6/9/2008 2:12 PM 92296] S2 DellBIOS;DellBIOS;\??\c:\windows\DellBIOS.Sys --> c:\windows\DellBIOS.Sys [?] S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe --> h:\downloads\School\SolidWorks\swScheduler\DTSCoordinatorService.exe [?] S3 EraserUtilDrvI9;EraserUtilDrvI9;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys [?] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [4/6/2009 10:03 PM 38496] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [8/6/2009 7:06 PM 136704] S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [8/6/2009 7:06 PM 8320] S3 PAC207;CIF USB Camera;c:\windows\system32\drivers\PFC027.SYS [1/2/2009 1:15 PM 505984] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 4:51 PM 4096] S3 TBU11;Turtle Beach USB MIDI 1x1 Driver;c:\windows\system32\drivers\tbu11.sys [8/4/2007 2:26 PM 13824] S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808] --- Other Services/Drivers In Memory --- *Deregistered* - mbr [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder 2009-10-25 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34] 2009-10-26 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 19:22] 2009-10-26 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-26 19:22] 2009-10-30 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job - c:\program files\Ask.com\UpdateTask.exe [2009-06-17 00:22] . . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm IE: &Download with &DAP - c:\program files\DAP\dapextie.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Nick Rummel\Application Data\Mozilla\Firefox\Profiles\8j7bdunq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/ FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071503000010.dll FF - plugin: c:\documents and settings\Nick Rummel\Application Data\Move Networks\plugins\npqmp071505000010.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true. ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-30 00:15 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1313456098-3368236134-1419899362-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:5f,bd,1d,4e,48,20,11,db,c5,d2,3d,f5,fd,a2,c5,27,c8,7c,f3,0c,b0,8c,65, e7,a0,af,e6,ea,11,15,15,45,ed,f1,e1,34,d6,32,85,f7,f5,d5,9c,cd,1f,a4,98,68,\ "??"=hex:47,b8,eb,31,6d,80,25,0b,86,7e,89,00,84,30,b1,12 [HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ }*Ć] "Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(920) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll . Completion time: 2009-10-30 0:24 ComboFix-quarantined-files.txt 2009-10-30 07:23 ComboFix2.txt 2009-10-28 15:49 ComboFix3.txt 2009-10-28 02:25 Pre-Run: 4,422,221,824 bytes free Post-Run: 4,450,861,056 bytes free Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4 - - End Of File - - 63469C5B76BCA8F6D45A4118BE830513 |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
3 / 237 | 26th January 2009 - 11:22 AM gravelkm started - last by handhfan |
|||||
![]() |
31 / 1,488 | 3rd June 2009 - 02:36 PM SyedT started - last by Rorschach112 |
|||||
![]() |
12 / 979 | 24th May 2009 - 02:28 AM NHCAB1020 started - last by CatByte |
|||||
![]() |
19 / 544 | 12th August 2009 - 07:17 AM pericles81 started - last by Rorschach112 |
|||||
|
Time is now: 21st November 2009 - 07:06 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising