Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
2 Pages V   1 2 >  
Closed TopicStart new topic
Help With Google Redirect Problem [Closed] [Solved]
PA Jeeper
post Aug 18 2009, 06:22 PM
Post #1


New Member
*
Posts: 9
OS: WinXP



A family friend caught some nasty malware on their PC, below is the HijackThis log. Google's search is useless as it just goes to a page cannot be displayed or sometimes redirects you to coupon mountain for example.

They at first tried to go back with a system restore which did not work. Then they tried their macafee antivirus, malware bytes and even spybot search and destroy which nothing worked either. Thanks for taking your time to help!



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:04:27 PM, on 8/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 64.86.17.32 google.ae
O1 - Hosts: 64.86.17.32 google.as
O1 - Hosts: 64.86.17.32 google.at
O1 - Hosts: 64.86.17.32 google.az
O1 - Hosts: 64.86.17.32 google.ba
O1 - Hosts: 64.86.17.32 google.be
O1 - Hosts: 64.86.17.32 google.bg
O1 - Hosts: 64.86.17.32 google.bs
O1 - Hosts: 64.86.17.32 google.ca
O1 - Hosts: 64.86.17.32 google.cd
O1 - Hosts: 64.86.17.32 google.com.gh
O1 - Hosts: 64.86.17.32 google.com.hk
O1 - Hosts: 64.86.17.32 google.com.jm
O1 - Hosts: 64.86.17.32 google.com.mx
O1 - Hosts: 64.86.17.32 google.com.my
O1 - Hosts: 64.86.17.32 google.com.na
O1 - Hosts: 64.86.17.32 google.com.nf
O1 - Hosts: 64.86.17.32 google.com.ng
O1 - Hosts: 64.86.17.32 google.ch
O1 - Hosts: 64.86.17.32 google.com.np
O1 - Hosts: 64.86.17.32 google.com.pr
O1 - Hosts: 64.86.17.32 google.com.qa
O1 - Hosts: 64.86.17.32 google.com.sg
O1 - Hosts: 64.86.17.32 google.com.tj
O1 - Hosts: 64.86.17.32 google.com.tw
O1 - Hosts: 64.86.17.32 google.dj
O1 - Hosts: 64.86.17.32 google.de
O1 - Hosts: 64.86.17.32 google.dk
O1 - Hosts: 64.86.17.32 google.dm
O1 - Hosts: 64.86.17.32 google.ee
O1 - Hosts: 64.86.17.32 google.fi
O1 - Hosts: 64.86.17.32 google.fm
O1 - Hosts: 64.86.17.32 google.fr
O1 - Hosts: 64.86.17.32 google.ge
O1 - Hosts: 64.86.17.32 google.gg
O1 - Hosts: 64.86.17.32 google.gm
O1 - Hosts: 64.86.17.32 google.gr
O1 - Hosts: 64.86.17.32 google.ht
O1 - Hosts: 64.86.17.32 google.ie
O1 - Hosts: 64.86.17.32 google.im
O1 - Hosts: 64.86.17.32 google.in
O1 - Hosts: 64.86.17.32 google.it
O1 - Hosts: 64.86.17.32 google.ki
O1 - Hosts: 64.86.17.32 google.la
O1 - Hosts: 64.86.17.32 google.li
O1 - Hosts: 64.86.17.32 google.lv
O1 - Hosts: 64.86.17.32 google.ma
O1 - Hosts: 64.86.17.32 google.ms
O1 - Hosts: 64.86.17.32 google.mu
O1 - Hosts: 64.86.17.32 google.mw
O1 - Hosts: 64.86.17.32 google.nl
O1 - Hosts: 64.86.17.32 google.no
O1 - Hosts: 64.86.17.32 google.nr
O1 - Hosts: 64.86.17.32 google.nu
O1 - Hosts: 64.86.17.32 google.pl
O1 - Hosts: 64.86.17.32 google.pn
O1 - Hosts: 64.86.17.32 google.pt
O1 - Hosts: 64.86.17.32 google.ro
O1 - Hosts: 64.86.17.32 google.ru
O1 - Hosts: 64.86.17.32 google.rw
O1 - Hosts: 64.86.17.32 google.sc
O1 - Hosts: 64.86.17.32 google.se
O1 - Hosts: 64.86.17.32 google.sh
O1 - Hosts: 64.86.17.32 google.si
O1 - Hosts: 64.86.17.32 google.sm
O1 - Hosts: 64.86.17.32 google.sn
O1 - Hosts: 64.86.17.32 google.st
O1 - Hosts: 64.86.17.32 google.tl
O1 - Hosts: 64.86.17.32 google.tm
O1 - Hosts: 64.86.17.32 google.tt
O1 - Hosts: 64.86.17.32 google.us
O1 - Hosts: 64.86.17.32 google.vu
O1 - Hosts: 64.86.17.32 google.ws
O1 - Hosts: 64.86.17.32 google.co.ck
O1 - Hosts: 64.86.17.32 google.co.id
O1 - Hosts: 64.86.17.32 google.co.il
O1 - Hosts: 64.86.17.32 google.co.in
O1 - Hosts: 64.86.17.32 google.co.jp
O1 - Hosts: 64.86.17.32 google.co.kr
O1 - Hosts: 64.86.17.32 google.co.ls
O1 - Hosts: 64.86.17.32 google.co.ma
O1 - Hosts: 64.86.17.32 google.co.nz
O1 - Hosts: 64.86.17.32 google.co.tz
O1 - Hosts: 64.86.17.32 google.co.ug
O1 - Hosts: 64.86.17.32 google.co.uk
O1 - Hosts: 64.86.17.32 google.co.za
O1 - Hosts: 64.86.17.32 google.co.zm
O1 - Hosts: 64.86.17.32 google.com
O1 - Hosts: 64.86.17.32 google.com.af
O1 - Hosts: 64.86.17.32 google.com.ag
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~4.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; yie8)" -"http://www.freeplaynow.com/online-games/play/1308/kol-off-road.html"
O4 - Global Startup: Run Google Web Accelerator.lnk = C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://co.schuylkill.pa.us/_applets/smsx.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 14176 bytes
Go to the top of the page
 
+Quote Post
handhfan
post Aug 18 2009, 08:59 PM
Post #2


GeekU Moderator
Group Icon
Posts: 8,651
From: Massachusetts
OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC



Hello, PA Jeeper, and welcome to GeeksToGo!

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    CODE
    :dir
    C:\WINDOWS\system32\drivers\etc

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Go to the top of the page
 
+Quote Post
PA Jeeper
post Aug 20 2009, 02:34 PM
Post #3


New Member
*
Posts: 9
OS: WinXP



SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 16:18 on 20/08/2009 by Administrator (Administrator - Elevation successful)

========== dir ==========

C:\WINDOWS\system32\drivers - Parameters: "(none)"

---Files---
1394bus.sys --a--- 53376 bytes [06:10 04/08/2004] [18:46 13/04/2008]
ABP480N5.SYS --a--- 23552 bytes [09:45 21/06/2006] [03:52 18/08/2001]
acpi.sys --a--- 187776 bytes [06:07 04/08/2004] [18:36 13/04/2008]
acpiec.sys --a--- 11648 bytes [20:57 17/08/2001] [19:00 10/08/2004]
adpu160m.sys --a--- 101888 bytes [09:38 21/06/2006] [04:07 18/08/2001]
adv01nt5.dll ------ 4255 bytes [23:03 22/08/2008] [00:11 14/04/2008]
adv02nt5.dll ------ 3967 bytes [23:03 22/08/2008] [00:11 14/04/2008]
adv05nt5.dll ------ 3615 bytes [23:03 22/08/2008] [00:11 14/04/2008]
adv07nt5.dll ------ 3647 bytes [23:03 22/08/2008] [00:11 14/04/2008]
adv08nt5.dll ------ 3135 bytes [23:03 22/08/2008] [00:11 14/04/2008]
adv09nt5.dll ------ 3711 bytes [23:03 22/08/2008] [00:11 14/04/2008]
adv11nt5.dll ------ 3775 bytes [23:03 22/08/2008] [00:11 14/04/2008]
aec.sys --a--- 142592 bytes [08:06 21/06/2006] [16:39 13/04/2008]
afd.sys --a--- 138496 bytes [09:23 17/06/2006] [10:04 14/08/2008]
agp440.sys --a--- 42368 bytes [09:33 21/06/2006] [18:36 13/04/2008]
agpcpq.sys --a--- 44928 bytes [09:35 21/06/2006] [18:36 13/04/2008]
aha154x.sys --a--- 12800 bytes [09:37 21/06/2006] [03:52 18/08/2001]
aic78u2.sys --a--- 55168 bytes [09:38 21/06/2006] [04:07 18/08/2001]
aic78xx.sys --a--- 56960 bytes [09:39 21/06/2006] [04:07 18/08/2001]
aliide.sys --a--- 5248 bytes [09:46 21/06/2006] [03:51 18/08/2001]
alim1541.sys --a--- 42752 bytes [09:32 21/06/2006] [18:36 13/04/2008]
amdagp.sys --a--- 43008 bytes [09:32 21/06/2006] [18:36 13/04/2008]
amdk6.sys --a--- 37376 bytes [05:59 04/08/2004] [18:31 13/04/2008]
amdk7.sys --a--- 37760 bytes [05:59 04/08/2004] [18:31 13/04/2008]
amsint.sys --a--- 12032 bytes [09:45 21/06/2006] [03:52 18/08/2001]
arp1394.sys --a--- 60800 bytes [05:58 04/08/2004] [18:51 13/04/2008]
asc.sys --a--- 26496 bytes [09:44 21/06/2006] [03:52 18/08/2001]
asc3350p.sys --a--- 22400 bytes [09:45 21/06/2006] [03:52 18/08/2001]
asc3550.sys --a--- 14848 bytes [09:44 21/06/2006] [03:51 18/08/2001]
asyncmac.sys --a--- 14336 bytes [09:23 17/06/2006] [18:57 13/04/2008]
atapi.sys --a--- 96512 bytes [05:59 04/08/2004] [18:40 13/04/2008]
ati1btxx.sys ------ 56623 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati1mdxx.sys ------ 11615 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati1pdxx.sys ------ 12047 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati1raxx.sys ------ 30671 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati1rvxx.sys ------ 63663 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati1snxx.sys ------ 26367 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati1ttxx.sys ------ 21343 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati1tuxx.sys ------ 36463 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati1xbxx.sys ------ 29455 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati1xsxx.sys ------ 34735 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati2erec.dll --a--- 49152 bytes [02:37 19/09/2006] [01:15 09/05/2007]
ati2mtaa.sys ------ 327040 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ati2mtag.sys --a--- 2164736 bytes [02:37 19/09/2006] [01:58 09/05/2007]
AtiHdAud.sys --a--- 84992 bytes [16:44 28/12/2006] [16:44 28/12/2006]
AtiHdmi.sys --a--- 84992 bytes [23:40 20/07/2007] [23:40 20/07/2007]
atinbtxx.sys ------ 57856 bytes [23:03 22/08/2008] [02:29 04/08/2004]
atinmdxx.sys ------ 13824 bytes [23:03 22/08/2008] [02:29 04/08/2004]
atinpdxx.sys ------ 14336 bytes [23:03 22/08/2008] [02:29 04/08/2004]
atinraxx.sys ------ 52224 bytes [23:03 22/08/2008] [02:29 04/08/2004]
atinrvxx.sys ------ 104960 bytes [23:03 22/08/2008] [02:29 04/08/2004]
atinsnxx.sys ------ 28672 bytes [23:03 22/08/2008] [02:29 04/08/2004]
atinttxx.sys ------ 13824 bytes [23:03 22/08/2008] [02:29 04/08/2004]
atintuxx.sys ------ 73216 bytes [23:03 22/08/2008] [02:29 04/08/2004]
atinxbxx.sys ------ 31744 bytes [23:03 22/08/2008] [02:29 04/08/2004]
atinxsxx.sys ------ 63488 bytes [23:03 22/08/2008] [02:29 04/08/2004]
ativcaxx.cpa --a--- 1311202 bytes [02:37 19/09/2006] [12:19 18/04/2007]
ativcaxx.vp --a--- 929 bytes [02:37 19/09/2006] [12:19 18/04/2007]
ativckxx.vp --a--- 2096 bytes [02:37 19/09/2006] [21:26 23/08/2006]
ativdkxx.vp --a--- 2096 bytes [12:19 18/04/2007] [12:19 18/04/2007]
ativmc20.cod ------ 64352 bytes [23:03 22/08/2008] [15:36 17/07/2004]
ativvpxx.vp --a--- 43104 bytes [02:37 19/09/2006] [03:28 09/05/2007]
atmarpc.sys --a--- 59904 bytes [09:23 17/06/2006] [18:51 13/04/2008]
atmepvc.sys --a--- 31360 bytes [09:23 17/06/2006] [19:00 10/08/2004]
atmlane.sys --a--- 55808 bytes [09:23 17/06/2006] [18:51 13/04/2008]
atmuni.sys --a--- 352256 bytes [09:23 17/06/2006] [19:00 10/08/2004]
atv01nt5.dll ------ 21183 bytes [23:03 22/08/2008] [00:11 14/04/2008]
atv02nt5.dll ------ 11359 bytes [23:03 22/08/2008] [00:11 14/04/2008]
atv04nt5.dll ------ 25471 bytes [23:03 22/08/2008] [00:11 14/04/2008]
atv06nt5.dll ------ 14143 bytes [23:03 22/08/2008] [00:11 14/04/2008]
atv10nt5.dll ------ 17279 bytes [23:03 22/08/2008] [00:11 14/04/2008]
audstub.sys --a--- 3072 bytes [02:34 17/06/2006] [20:59 17/08/2001]
battc.sys --a--- 14208 bytes [02:32 17/06/2006] [18:36 13/04/2008]
beep.sys --a--- 4224 bytes [09:23 17/06/2006] [19:00 10/08/2004]
bridge.sys --a--- 71552 bytes [09:23 17/06/2006] [18:53 13/04/2008]
bthenum.sys ------ 17024 bytes [23:03 22/08/2008] [18:46 13/04/2008]
bthmodem.sys ------ 37888 bytes [23:03 22/08/2008] [18:46 13/04/2008]
bthpan.sys ------ 101120 bytes [23:03 22/08/2008] [18:51 13/04/2008]
bthport.sys ------ 272128 bytes [15:01 11/06/2008] [11:05 13/06/2008]
bthprint.sys ------ 36480 bytes [23:03 22/08/2008] [18:46 13/04/2008]
bthusb.sys ------ 18944 bytes [23:03 22/08/2008] [18:46 13/04/2008]
cbidf2k.sys --a--- 13952 bytes [20:52 17/08/2001] [03:52 18/08/2001]
cd20xrnt.sys --a--- 7680 bytes [09:44 21/06/2006] [03:52 18/08/2001]
cdaudio.sys --a--- 18688 bytes [20:52 17/08/2001] [19:00 10/08/2004]
cdfs.sys --a--- 63744 bytes [09:23 17/06/2006] [19:14 13/04/2008]
cdr4_xp.sys --a--- 2432 bytes [07:00 24/07/2006] [07:00 24/07/2006]
cdralw2k.sys --a--- 2560 bytes [07:00 24/07/2006] [07:00 24/07/2006]
cdrom.sys --a--- 62976 bytes [05:59 04/08/2004] [18:40 13/04/2008]
ch7xxnt5.dll ------ 15423 bytes [23:03 22/08/2008] [00:11 14/04/2008]
cinemst2.sys --a--- 262528 bytes [21:02 17/08/2001] [19:00 10/08/2004]
classpnp.sys --a--- 49536 bytes [09:23 17/06/2006] [19:16 13/04/2008]
cmbatt.sys --a--- 13952 bytes [02:32 17/06/2006] [18:36 13/04/2008]
cmdide.sys --a--- 6656 bytes [09:46 21/06/2006] [03:51 18/08/2001]
compbatt.sys --a--- 10240 bytes [02:32 17/06/2006] [18:36 13/04/2008]
cpqarray.sys --a--- 14976 bytes [09:40 21/06/2006] [03:52 18/08/2001]
cpqdap01.sys --a--- 11776 bytes [20:24 17/08/2001] [19:00 10/08/2004]
crusoe.sys --a--- 36736 bytes [05:59 04/08/2004] [18:31 13/04/2008]
cxthsfs2.cty ------ 129045 bytes [23:04 22/08/2008] [02:55 18/07/2004]
dac2w2k.sys --a--- 179584 bytes [09:44 21/06/2006] [03:52 18/08/2001]
dac960nt.sys --a--- 14720 bytes [09:44 21/06/2006] [03:52 18/08/2001]
disk.sys --a--- 36352 bytes [05:59 04/08/2004] [18:40 13/04/2008]
diskdump.sys --a--- 14208 bytes [09:23 17/06/2006] [18:40 13/04/2008]
DLACDBHM.SYS --a--- 12920 bytes [01:19 25/06/2008] [13:45 15/09/2006]
DLARTL_M.SYS --a--- 28184 bytes [01:19 25/06/2008] [13:45 15/09/2006]
dmboot.sys --a--- 799744 bytes [09:23 17/06/2006] [18:44 13/04/2008]
dmio.sys --a--- 153344 bytes [09:23 17/06/2006] [18:44 13/04/2008]
dmload.sys --a--- 5888 bytes [09:23 17/06/2006] [19:00 10/08/2004]
dmusic.sys --a--- 52864 bytes [03:26 19/09/2006] [18:45 13/04/2008]
dpti2o.sys --a--- 20192 bytes [09:39 21/06/2006] [04:07 18/08/2001]
drmk.sys --a--- 60160 bytes [03:26 19/09/2006] [18:45 13/04/2008]
drmkaud.sys --a--- 2944 bytes [03:26 19/09/2006] [18:45 13/04/2008]
DRVMCDB.SYS --a--- 99816 bytes [01:19 25/06/2008] [12:22 25/10/2006]
DRVNDDM.SYS --a--- 51768 bytes [01:19 25/06/2008] [13:42 15/09/2006]
dxapi.sys --a--- 10496 bytes [09:23 17/06/2006] [19:00 10/08/2004]
dxg.sys --a--- 71168 bytes [06:00 04/08/2004] [18:38 13/04/2008]
dxgthk.sys --a--- 3328 bytes [09:23 17/06/2006] [19:00 10/08/2004]
enum1394.sys --a--- 6400 bytes [02:33 17/06/2006] [20:46 17/08/2001]
fastfat.sys --a--- 143744 bytes [09:23 17/06/2006] [19:14 13/04/2008]
fdc.sys --a--- 27392 bytes [05:59 04/08/2004] [18:40 13/04/2008]
fips.sys --a--- 44544 bytes [09:23 17/06/2006] [18:33 13/04/2008]
flpydisk.sys --a--- 20480 bytes [05:59 04/08/2004] [18:40 13/04/2008]
fltmgr.sys --a--- 129792 bytes [09:38 17/06/2006] [18:32 13/04/2008]
fsvga.sys --a--- 12160 bytes [20:57 17/08/2001] [19:00 10/08/2004]
fs_rec.sys --a--- 7936 bytes [09:23 17/06/2006] [19:00 10/08/2004]
ftdisk.sys --a--- 125056 bytes [20:52 17/08/2001] [03:52 18/08/2001]
gagp30kx.sys ------ 46464 bytes [23:04 22/08/2008] [18:36 13/04/2008]
GEARAspiWDM.sys --a--- 15464 bytes [01:18 15/11/2008] [18:12 17/04/2008]
gm.dls --a--- 3440660 bytes [09:23 17/06/2006] [19:00 10/08/2004]
gmreadme.txt --a--- 646 bytes [09:23 17/06/2006] [19:00 10/08/2004]
hdaudbus.sys --a--- 144384 bytes [00:07 08/01/2005] [16:36 13/04/2008]
Hdaudio.sys --a--- 145920 bytes [00:07 08/01/2005] [00:07 08/01/2005]
hidbth.sys ------ 25600 bytes [23:04 22/08/2008] [18:46 13/04/2008]
hidclass.sys --a--- 36864 bytes [06:08 04/08/2004] [18:45 13/04/2008]
hidir.sys ------ 19200 bytes [04:34 19/06/2006] [18:45 13/04/2008]
hidparse.sys --a--- 24960 bytes [06:08 04/08/2004] [18:45 13/04/2008]
hidusb.sys --a--- 10368 bytes [07:57 21/06/2006] [18:45 13/04/2008]
hpn.sys --a--- 25952 bytes [09:41 21/06/2006] [04:07 18/08/2001]
HPZid412.sys -ra--- 49664 bytes [01:09 26/02/2008] [00:04 13/04/2006]
HPZipr12.sys -ra--- 16496 bytes [01:09 26/02/2008] [00:04 13/04/2006]
HPZius12.sys --a--- 21568 bytes [00:04 13/04/2006] [00:04 13/04/2006]
hsfbs2s2.sys ------ 220032 bytes [23:04 22/08/2008] [02:41 04/08/2004]
hsfcxts2.sys ------ 685056 bytes [23:04 22/08/2008] [02:41 04/08/2004]
hsfdpsp2.sys ------ 1041536 bytes [23:04 22/08/2008] [02:41 04/08/2004]
HSFHWBS2.sys --a--- 221440 bytes [02:55 19/09/2006] [16:50 17/03/2005]
HSFProf.cty --a--- 133221 bytes [02:55 19/09/2006] [03:29 17/03/2005]
HSF_CNXT.sys --a--- 705280 bytes [02:55 19/09/2006] [16:50 17/03/2005]
HSF_DPV.sys --a--- 1033600 bytes [02:55 19/09/2006] [16:51 17/03/2005]
http.sys --a--- 264832 bytes [06:00 04/08/2004] [18:53 13/04/2008]
i2omgmt.sys --a--- 8576 bytes [09:43 21/06/2006] [18:41 13/04/2008]
i2omp.sys --a--- 18560 bytes [09:43 21/06/2006] [18:41 13/04/2008]
i8042prt.sys --a--- 52480 bytes [06:14 04/08/2004] [19:18 13/04/2008]
imapi.sys --a--- 42112 bytes [06:00 04/08/2004] [18:40 13/04/2008]
ini910u.sys --a--- 16000 bytes [09:45 21/06/2006] [03:52 18/08/2001]
intelide.sys --a--- 5504 bytes [02:33 17/06/2006] [18:40 13/04/2008]
intelppm.sys --a--- 36352 bytes [05:59 04/08/2004] [18:31 13/04/2008]
ip6fw.sys --a--- 36608 bytes [09:23 17/06/2006] [18:53 13/04/2008]
ipfltdrv.sys --a--- 32896 bytes [09:23 17/06/2006] [19:00 10/08/2004]
ipinip.sys --a--- 20864 bytes [09:23 17/06/2006] [18:57 13/04/2008]
ipnat.sys --a--- 152832 bytes [09:23 17/06/2006] [18:57 13/04/2008]
ipsec.sys --a--- 75264 bytes [09:23 17/06/2006] [19:19 13/04/2008]
irbus.sys ------ 46592 bytes [04:34 19/06/2006] [18:45 13/04/2008]
irenum.sys --a--- 11264 bytes [02:31 17/06/2006] [18:54 13/04/2008]
isapnp.sys --a--- 37248 bytes [20:58 17/08/2001] [18:36 13/04/2008]
kbdclass.sys --a--- 24576 bytes [05:58 04/08/2004] [18:39 13/04/2008]
kbdhid.sys --a--- 14592 bytes [07:57 21/06/2006] [18:39 13/04/2008]
kmixer.sys --a--- 172416 bytes [03:26 19/09/2006] [18:45 13/04/2008]
ks.sys --a--- 141056 bytes [06:15 04/08/2004] [19:16 13/04/2008]
ksecdd.sys --a--- 92928 bytes [09:23 17/06/2006] [11:18 24/06/2009]
mbam.sys --a--- 19096 bytes [01:54 13/08/2009] [17:36 03/08/2009]
mbamswissarmy.sys --a--- 38160 bytes [01:54 13/08/2009] [17:36 03/08/2009]
mcd.sys --a--- 7680 bytes [09:23 17/06/2006] [19:00 10/08/2004]
mdmxsdk.sys --a--- 13059 bytes [02:55 19/09/2006] [19:04 17/03/2004]
mf.sys --a--- 63744 bytes [06:07 04/08/2004] [18:36 13/04/2008]
mfeavfk.sys --a--- 79880 bytes [23:16 07/02/2007] [15:06 25/03/2009]
mfebopk.sys --a--- 35272 bytes [23:16 07/02/2007] [15:06 25/03/2009]
mfehidk.sys --a--- 214024 bytes [23:16 07/02/2007] [15:06 25/03/2009]
mferkdk.sys --a--- 34216 bytes [23:16 07/02/2007] [15:05 25/03/2009]
mfesmfk.sys --a--- 40552 bytes [23:16 07/02/2007] [15:06 25/03/2009]
mhndrv.sys --a--- 11008 bytes [09:36 17/06/2006] [17:45 10/08/2004]
mnmdd.sys --a--- 4224 bytes [09:24 17/06/2006] [19:00 10/08/2004]
modem.sys --a--- 30080 bytes [06:08 04/08/2004] [19:00 13/04/2008]
mouclass.sys --a--- 23040 bytes [05:58 04/08/2004] [18:39 13/04/2008]
mouhid.sys --a--- 12160 bytes [07:57 21/06/2006] [03:48 18/08/2001]
mountmgr.sys --a--- 42368 bytes [09:23 17/06/2006] [18:39 13/04/2008]
Mpfp.sys --a--- 120136 bytes [23:16 07/02/2007] [17:08 23/10/2008]
mqac.sys --a--- 92544 bytes [09:23 17/06/2006] [18:39 13/04/2008]
mraid35x.sys --a--- 17280 bytes [09:40 21/06/2006] [03:52 18/08/2001]
mrxdav.sys --a--- 180608 bytes [09:23 17/06/2006] [18:32 13/04/2008]
mrxsmb.sys --a--- 455296 bytes [09:23 17/06/2006] [11:21 24/10/2008]
msfs.sys --a--- 19072 bytes [09:23 17/06/2006] [18:32 13/04/2008]
msgpc.sys --a--- 35072 bytes [09:23 17/06/2006] [18:56 13/04/2008]
mskssrv.sys --a--- 7552 bytes [03:26 19/09/2006] [18:39 13/04/2008]
mspclock.sys --a--- 5376 bytes [03:26 19/09/2006] [18:39 13/04/2008]
mspqm.sys --a--- 4992 bytes [03:26 19/09/2006] [18:39 13/04/2008]
mssmbios.sys --a--- 15488 bytes [06:07 04/08/2004] [18:36 13/04/2008]
mtlmnt5.sys ------ 126686 bytes [23:04 22/08/2008] [02:41 04/08/2004]
mtlstrm.sys ------ 1309184 bytes [23:04 22/08/2008] [02:41 04/08/2004]
mtxparhm.sys ------ 452736 bytes [23:04 22/08/2008] [02:29 04/08/2004]
mup.sys --a--- 105344 bytes [09:23 17/06/2006] [19:17 13/04/2008]
mutohpen.sys ------ 12672 bytes [23:04 22/08/2008] [18:43 13/04/2008]
ndis.sys --a--- 182656 bytes [09:23 17/06/2006] [19:20 13/04/2008]
ndistapi.sys --a--- 10112 bytes [09:23 17/06/2006] [18:57 13/04/2008]
ndisuio.sys --a--- 14592 bytes [06:03 04/08/2004] [18:55 13/04/2008]
ndiswan.sys --a--- 91520 bytes [09:23 17/06/2006] [19:20 13/04/2008]
ndproxy.sys --a--- 40576 bytes [09:23 17/06/2006] [18:57 13/04/2008]
netbios.sys --a--- 34688 bytes [09:23 17/06/2006] [18:56 13/04/2008]
netbt.sys --a--- 162816 bytes [09:23 17/06/2006] [19:21 13/04/2008]
netwlan5.img ------ 67866 bytes [23:04 22/08/2008] [15:35 17/07/2004]
nic1394.sys --a--- 61824 bytes [05:58 04/08/2004] [18:51 13/04/2008]
nikedrv.sys --a--- 12032 bytes [20:24 17/08/2001] [19:00 10/08/2004]
nmnt.sys --a--- 40320 bytes [09:23 17/06/2006] [18:53 13/04/2008]
npfs.sys --a--- 30848 bytes [09:23 17/06/2006] [18:32 13/04/2008]
ntfs.sys --a--- 574976 bytes [09:23 17/06/2006] [19:15 13/04/2008]
ntmtlfax.sys ------ 180360 bytes [23:04 22/08/2008] [02:41 04/08/2004]
null.sys --a--- 2944 bytes [09:23 17/06/2006] [19:00 10/08/2004]
nv4_mini.sys ------ 1897408 bytes [23:04 22/08/2008] [02:29 04/08/2004]
nwlnkflt.sys --a--- 12416 bytes [09:23 17/06/2006] [19:00 10/08/2004]
nwlnkfwd.sys --a--- 32512 bytes [09:23 17/06/2006] [19:00 10/08/2004]
nwlnkipx.sys --a--- 88320 bytes [09:23 17/06/2006] [18:56 13/04/2008]
nwlnknb.sys --a--- 63232 bytes [09:23 17/06/2006] [19:00 10/08/2004]
nwlnkspx.sys --a--- 55936 bytes [09:23 17/06/2006] [19:00 10/08/2004]
nwrdr.sys --a--- 163584 bytes [09:23 17/06/2006] [18:34 13/04/2008]
ohci1394.sys --a--- 61696 bytes [06:10 04/08/2004] [18:46 13/04/2008]
oprghdlr.sys --a--- 3456 bytes [20:57 17/08/2001] [19:00 10/08/2004]
p3.sys --a--- 42752 bytes [05:59 04/08/2004] [18:31 13/04/2008]
parport.sys --a--- 80128 bytes [05:59 04/08/2004] [18:40 13/04/2008]
partmgr.sys --a--- 19712 bytes [09:23 17/06/2006] [18:40 13/04/2008]
parvdm.sys --a--- 6784 bytes [09:23 17/06/2006] [19:00 10/08/2004]
pci.sys --a--- 68224 bytes [06:07 04/08/2004] [18:36 13/04/2008]
pciide.sys --a--- 3328 bytes [20:51 17/08/2001] [17:51 17/08/2001]
pciidex.sys --a--- 24960 bytes [05:59 04/08/2004] [18:40 13/04/2008]
pcmcia.sys --a--- 120192 bytes [06:07 04/08/2004] [18:36 13/04/2008]
perc2.sys --a--- 27296 bytes [09:40 21/06/2006] [04:07 18/08/2001]
perc2hib.sys --a--- 5504 bytes [09:41 21/06/2006] [04:07 18/08/2001]
portcls.sys --a--- 136960 bytes [17:58 16/03/2004] [17:58 16/03/2004]
processr.sys --a--- 35840 bytes [05:59 04/08/2004] [18:31 13/04/2008]
psched.sys --a--- 69120 bytes [09:23 17/06/2006] [18:56 13/04/2008]
ptilink.sys --a--- 17792 bytes [09:23 17/06/2006] [19:00 10/08/2004]
pxhelp20.sys --a--- 36560 bytes [07:00 09/08/2006] [07:00 09/08/2006]
ql1080.sys --a--- 40320 bytes [09:42 21/06/2006] [03:52 18/08/2001]
ql10wnt.sys --a--- 33152 bytes [09:42 21/06/2006] [03:52 18/08/2001]
ql12160.sys --a--- 45312 bytes [09:42 21/06/2006] [03:52 18/08/2001]
ql1240.sys --a--- 40448 bytes [09:42 21/06/2006] [03:52 18/08/2001]
ql1280.sys --a--- 49024 bytes [09:42 21/06/2006] [03:52 18/08/2001]
rasacd.sys --a--- 8832 bytes [09:23 17/06/2006] [19:00 10/08/2004]
rasl2tp.sys --a--- 51328 bytes [09:23 17/06/2006] [19:19 13/04/2008]
raspppoe.sys --a--- 41472 bytes [09:23 17/06/2006] [18:57 13/04/2008]
raspptp.sys --a--- 48384 bytes [09:23 17/06/2006] [19:19 13/04/2008]
raspti.sys --a--- 16512 bytes [09:23 17/06/2006] [19:00 10/08/2004]
rawwan.sys --a--- 34432 bytes [09:23 17/06/2006] [19:00 10/08/2004]
rdbss.sys --a--- 175744 bytes [09:23 17/06/2006] [19:28 13/04/2008]
rdpcdd.sys --a--- 4224 bytes [09:23 17/06/2006] [19:00 10/08/2004]
rdpdr.sys --a--- 196224 bytes [09:35 17/06/2006] [18:32 13/04/2008]
rdpwd.sys --a--- 139656 bytes [09:35 17/06/2006] [00:13 14/04/2008]
recagent.sys ------ 13776 bytes [23:04 22/08/2008] [02:41 04/08/2004]
redbook.sys --a--- 57600 bytes [02:33 17/06/2006] [18:40 13/04/2008]
rfcomm.sys ------ 59136 bytes [23:04 22/08/2008] [18:46 13/04/2008]
rio8drv.sys --a--- 12032 bytes [20:24 17/08/2001] [19:00 10/08/2004]
riodrv.sys --a--- 12032 bytes [20:24 17/08/2001] [19:00 10/08/2004]
rmcast.sys --a--- 203136 bytes [09:23 17/06/2006] [14:02 08/05/2008]
rndismp.sys --a--- 30592 bytes [09:23 17/06/2006] [18:56 13/04/2008]
rndismpx.sys ------ 30592 bytes [23:04 22/08/2008] [18:56 13/04/2008]
rootmdm.sys --a--- 5888 bytes [09:23 17/06/2006] [19:00 10/08/2004]
RtkHDAud.Sys --a--- 4137984 bytes [03:25 19/09/2006] [01:13 14/01/2006]
Rtlnicxp.sys --a--- 70144 bytes [02:55 19/09/2006] [04:14 14/04/2004]
RxFilter.sys --a--- 50688 bytes [16:19 02/12/2006] [16:19 02/12/2006]
s3gnbm.sys ------ 166912 bytes [23:04 22/08/2008] [02:29 04/08/2004]
scsiport.sys --a--- 96384 bytes [05:59 04/08/2004] [18:40 13/04/2008]
sdbus.sys --a--- 79232 bytes [06:07 04/08/2004] [18:36 13/04/2008]
secdrv.sys --a--- 20480 bytes [09:23 17/06/2006] [10:25 13/11/2007]
serenum.sys --a--- 15744 bytes [05:59 04/08/2004] [18:40 13/04/2008]
serial.sys --a--- 64512 bytes [06:15 04/08/2004] [19:15 13/04/2008]
sffdisk.sys --a--- 11904 bytes [05:59 04/08/2004] [18:40 13/04/2008]
sffp_mmc.sys ------ 10240 bytes [23:04 22/08/2008] [18:40 13/04/2008]
sffp_sd.sys --a--- 11008 bytes [05:59 04/08/2004] [18:40 13/04/2008]
sfloppy.sys --a--- 11392 bytes [05:59 04/08/2004] [18:40 13/04/2008]
siint5.dll ------ 3901 bytes [23:04 22/08/2008] [00:12 14/04/2008]
sisagp.sys --a--- 40960 bytes [09:36 21/06/2006] [18:36 13/04/2008]
slnt7554.sys ------ 129535 bytes [23:04 22/08/2008] [02:41 04/08/2004]
slntamr.sys ------ 404990 bytes [23:04 22/08/2008] [02:41 04/08/2004]
slnthal.sys ------ 95424 bytes [23:04 22/08/2008] [02:41 04/08/2004]
slwdmsup.sys ------ 13240 bytes [23:04 22/08/2008] [02:41 04/08/2004]
smbali.sys ------ 5888 bytes [23:04 22/08/2008] [18:36 13/04/2008]
smclib.sys --a--- 14592 bytes [09:23 17/06/2006] [19:00 10/08/2004]
sonydcam.sys --a--- 25344 bytes [06:09 04/08/2004] [18:46 13/04/2008]
sparrow.sys --a--- 19072 bytes [09:37 21/06/2006] [04:07 18/08/2001]
splitter.sys --a--- 6272 bytes [03:26 19/09/2006] [18:45 13/04/2008]
sr.sys --a--- 73472 bytes [09:38 17/06/2006] [18:36 13/04/2008]
srv.sys --a--- 333952 bytes [09:23 17/06/2006] [10:57 11/12/2008]
stream.sys --a--- 49408 bytes [06:08 04/08/2004] [18:45 13/04/2008]
swenum.sys --a--- 4352 bytes [05:58 04/08/2004] [18:39 13/04/2008]
swmidi.sys --a--- 56576 bytes [03:26 19/09/2006] [18:45 13/04/2008]
symc810.sys --a--- 16256 bytes [09:42 21/06/2006] [04:07 18/08/2001]
symc8xx.sys --a--- 32640 bytes [09:41 21/06/2006] [04:07 18/08/2001]
sym_hi.sys --a--- 28384 bytes [09:40 21/06/2006] [04:07 18/08/2001]
sym_u3.sys --a--- 30688 bytes [09:42 21/06/2006] [04:07 18/08/2001]
sysaudio.sys --a--- 60800 bytes [03:26 19/09/2006] [19:15 13/04/2008]
tape.sys --a--- 14976 bytes [09:23 17/06/2006] [18:40 13/04/2008]
tcpip.sys --a--- 361600 bytes [09:23 17/06/2006] [11:51 20/06/2008]
tcpip6.sys --a--- 225856 bytes [09:23 17/06/2006] [11:08 20/06/2008]
tdi.sys --a--- 19072 bytes [09:23 17/06/2006] [19:00 13/04/2008]
tdpipe.sys --a--- 12040 bytes [09:35 17/06/2006] [00:13 14/04/2008]
tdtcp.sys --a--- 21896 bytes [09:35 17/06/2006] [00:13 14/04/2008]
termdd.sys --a--- 40840 bytes [09:35 17/06/2006] [00:13 14/04/2008]
tosdvd.sys --a--- 51712 bytes [21:01 17/08/2001] [19:00 10/08/2004]
toside.sys --a--- 4992 bytes [09:48 21/06/2006] [03:51 18/08/2001]
tsbvcap.sys --a--- 21376 bytes [21:06 17/08/2001] [19:00 10/08/2004]
tunmp.sys --a--- 12288 bytes [06:03 04/08/2004] [18:56 13/04/2008]
uagp35.sys ------ 44672 bytes [23:05 22/08/2008] [18:36 13/04/2008]
udfs.sys --a--- 66048 bytes [09:23 17/06/2006] [18:32 13/04/2008]
ultra.sys --a--- 36736 bytes [09:45 21/06/2006] [03:52 18/08/2001]
update.sys --a--- 384768 bytes [09:24 17/06/2006] [18:39 13/04/2008]
usb8023.sys --a--- 12800 bytes [09:23 17/06/2006] [18:56 13/04/2008]
usb8023x.sys ------ 12800 bytes [23:05 22/08/2008] [18:56 13/04/2008]
usbcamd.sys --a--- 25600 bytes [21:03 17/08/2001] [18:45 13/04/2008]
usbcamd2.sys --a--- 25728 bytes [21:03 17/08/2001] [18:45 13/04/2008]
usbccgp.sys --a--- 32128 bytes [07:57 21/06/2006] [18:45 13/04/2008]
usbd.sys --a--- 4736 bytes [21:03 17/08/2001] [19:00 10/08/2004]
usbehci.sys --a--- 30208 bytes [06:08 04/08/2004] [18:45 13/04/2008]
usbhub.sys --a--- 59520 bytes [06:08 04/08/2004] [18:45 13/04/2008]
usbintel.sys --a--- 15872 bytes [06:08 04/08/2004] [18:45 13/04/2008]
usbohci.sys --a--- 17152 bytes [02:58 19/09/2006] [18:45 13/04/2008]
usbport.sys --a--- 143872 bytes [06:08 04/08/2004] [18:45 13/04/2008]
usbprint.sys --a--- 25856 bytes [23:18 30/09/2006] [18:47 13/04/2008]
usbscan.sys --a--- 15104 bytes [23:23 30/09/2006] [18:45 13/04/2008]
usbstor.sys --a--- 26368 bytes [06:08 04/08/2004] [18:45 13/04/2008]
usbuhci.sys --a--- 20608 bytes [06:08 04/08/2004] [18:45 13/04/2008]
usbvideo.sys ------ 121984 bytes [23:05 22/08/2008] [18:46 13/04/2008]
vchnt5.dll ------ 11325 bytes [23:05 22/08/2008] [00:12 14/04/2008]
vdmindvd.sys --a--- 58112 bytes [21:02 17/08/2001] [19:00 10/08/2004]
vga.sys --a--- 20992 bytes [09:23 17/06/2006] [18:44 13/04/2008]
viaagp.sys --a--- 42240 bytes [09:37 21/06/2006] [18:36 13/04/2008]
viaide.sys --a--- 5376 bytes [09:47 21/06/2006] [18:40 13/04/2008]
videoprt.sys --a--- 81664 bytes [09:23 17/06/2006] [18:44 13/04/2008]
volsnap.sys --a--- 52352 bytes [09:23 17/06/2006] [18:41 13/04/2008]
wacompen.sys ------ 14208 bytes [23:05 22/08/2008] [18:43 13/04/2008]
wadv07nt.sys ------ 11807 bytes [23:05 22/08/2008] [02:29 04/08/2004]
wadv08nt.sys ------ 11295 bytes [23:05 22/08/2008] [02:29 04/08/2004]
wadv09nt.sys ------ 11871 bytes [23:05 22/08/2008] [02:29 04/08/2004]
wadv11nt.sys ------ 11935 bytes [23:05 22/08/2008] [02:29 04/08/2004]
wanarp.sys --a--- 34560 bytes [09:23 17/06/2006] [18:57 13/04/2008]
watv06nt.sys ------ 22271 bytes [23:05 22/08/2008] [02:29 04/08/2004]
watv10nt.sys ------ 25471 bytes [23:05 22/08/2008] [02:29 04/08/2004]
wdmaud.sys --a--- 83072 bytes [03:26 19/09/2006] [19:17 13/04/2008]
wmilib.sys --a--- 4352 bytes [09:23 17/06/2006] [19:00 10/08/2004]
wpdusb.sys --a--- 38528 bytes [09:23 17/06/2006] [01:00 19/10/2006]
ws2ifsl.sys --a--- 12032 bytes [09:23 17/06/2006] [19:00 10/08/2004]
WudfPf.sys ------ 77568 bytes [23:55 28/09/2006] [23:55 28/09/2006]
WudfRd.sys ------ 82944 bytes [00:00 29/09/2006] [00:00 29/09/2006]

---Folders---
disdn d----- [02:26 17/06/2006]
etc d----- [02:26 17/06/2006]
NSS d----- [22:01 17/07/2009]
UMDF d----- [17:39 09/01/2007]

-=End Of File=-
Go to the top of the page
 
+Quote Post
handhfan
post Aug 20 2009, 03:48 PM
Post #4


GeekU Moderator
Group Icon
Posts: 8,651
From: Massachusetts
OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC



Make sure you copy everything in the box. It looks like you only did C:\WINDOWS\system32\drivers instead of C:\Windows\system32\drivers\etc . whistling.gif

Let's try it again, as I need to see what's in this folder. smile.gif

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    CODE
    :dir
    C:\WINDOWS\system32\drivers\etc
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Go to the top of the page
 
+Quote Post
PA Jeeper
post Aug 20 2009, 04:21 PM
Post #5


New Member
*
Posts: 9
OS: WinXP



SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 16:21 on 20/08/2009 by Administrator (Administrator - Elevation successful)

========== dir ==========

C:\WINDOWS\system32\drivers\etc - Parameters: "(none)"

---Files---
hosts -rahs- 6946 bytes [09:23 17/06/2006] [20:38 11/08/2009]
lmhosts.sam --a--- 3683 bytes [09:23 17/06/2006] [19:00 10/08/2004]
networks --a--- 407 bytes [09:23 17/06/2006] [19:00 10/08/2004]
protocol --a--- 799 bytes [09:23 17/06/2006] [19:00 10/08/2004]
services --a--- 7116 bytes [09:23 17/06/2006] [19:00 10/08/2004]

---Folders---
None found.

-=End Of File=-
Go to the top of the page
 
+Quote Post
handhfan
post Aug 20 2009, 04:24 PM
Post #6


GeekU Moderator
Group Icon
Posts: 8,651
From: Massachusetts
OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC



Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 64.86.17.32 google.ae
O1 - Hosts: 64.86.17.32 google.as
O1 - Hosts: 64.86.17.32 google.at
O1 - Hosts: 64.86.17.32 google.az
O1 - Hosts: 64.86.17.32 google.ba
O1 - Hosts: 64.86.17.32 google.be
O1 - Hosts: 64.86.17.32 google.bg
O1 - Hosts: 64.86.17.32 google.bs
O1 - Hosts: 64.86.17.32 google.ca
O1 - Hosts: 64.86.17.32 google.cd
O1 - Hosts: 64.86.17.32 google.com.gh
O1 - Hosts: 64.86.17.32 google.com.hk
O1 - Hosts: 64.86.17.32 google.com.jm
O1 - Hosts: 64.86.17.32 google.com.mx
O1 - Hosts: 64.86.17.32 google.com.my
O1 - Hosts: 64.86.17.32 google.com.na
O1 - Hosts: 64.86.17.32 google.com.nf
O1 - Hosts: 64.86.17.32 google.com.ng
O1 - Hosts: 64.86.17.32 google.ch
O1 - Hosts: 64.86.17.32 google.com.np
O1 - Hosts: 64.86.17.32 google.com.pr
O1 - Hosts: 64.86.17.32 google.com.qa
O1 - Hosts: 64.86.17.32 google.com.sg
O1 - Hosts: 64.86.17.32 google.com.tj
O1 - Hosts: 64.86.17.32 google.com.tw
O1 - Hosts: 64.86.17.32 google.dj
O1 - Hosts: 64.86.17.32 google.de
O1 - Hosts: 64.86.17.32 google.dk
O1 - Hosts: 64.86.17.32 google.dm
O1 - Hosts: 64.86.17.32 google.ee
O1 - Hosts: 64.86.17.32 google.fi
O1 - Hosts: 64.86.17.32 google.fm
O1 - Hosts: 64.86.17.32 google.fr
O1 - Hosts: 64.86.17.32 google.ge
O1 - Hosts: 64.86.17.32 google.gg
O1 - Hosts: 64.86.17.32 google.gm
O1 - Hosts: 64.86.17.32 google.gr
O1 - Hosts: 64.86.17.32 google.ht
O1 - Hosts: 64.86.17.32 google.ie
O1 - Hosts: 64.86.17.32 google.im
O1 - Hosts: 64.86.17.32 google.in
O1 - Hosts: 64.86.17.32 google.it
O1 - Hosts: 64.86.17.32 google.ki
O1 - Hosts: 64.86.17.32 google.la
O1 - Hosts: 64.86.17.32 google.li
O1 - Hosts: 64.86.17.32 google.lv
O1 - Hosts: 64.86.17.32 google.ma
O1 - Hosts: 64.86.17.32 google.ms
O1 - Hosts: 64.86.17.32 google.mu
O1 - Hosts: 64.86.17.32 google.mw
O1 - Hosts: 64.86.17.32 google.nl
O1 - Hosts: 64.86.17.32 google.no
O1 - Hosts: 64.86.17.32 google.nr
O1 - Hosts: 64.86.17.32 google.nu
O1 - Hosts: 64.86.17.32 google.pl
O1 - Hosts: 64.86.17.32 google.pn
O1 - Hosts: 64.86.17.32 google.pt
O1 - Hosts: 64.86.17.32 google.ro
O1 - Hosts: 64.86.17.32 google.ru
O1 - Hosts: 64.86.17.32 google.rw
O1 - Hosts: 64.86.17.32 google.sc
O1 - Hosts: 64.86.17.32 google.se
O1 - Hosts: 64.86.17.32 google.sh
O1 - Hosts: 64.86.17.32 google.si
O1 - Hosts: 64.86.17.32 google.sm
O1 - Hosts: 64.86.17.32 google.sn
O1 - Hosts: 64.86.17.32 google.st
O1 - Hosts: 64.86.17.32 google.tl
O1 - Hosts: 64.86.17.32 google.tm
O1 - Hosts: 64.86.17.32 google.tt
O1 - Hosts: 64.86.17.32 google.us
O1 - Hosts: 64.86.17.32 google.vu
O1 - Hosts: 64.86.17.32 google.ws
O1 - Hosts: 64.86.17.32 google.co.ck
O1 - Hosts: 64.86.17.32 google.co.id
O1 - Hosts: 64.86.17.32 google.co.il
O1 - Hosts: 64.86.17.32 google.co.in
O1 - Hosts: 64.86.17.32 google.co.jp
O1 - Hosts: 64.86.17.32 google.co.kr
O1 - Hosts: 64.86.17.32 google.co.ls
O1 - Hosts: 64.86.17.32 google.co.ma
O1 - Hosts: 64.86.17.32 google.co.nz
O1 - Hosts: 64.86.17.32 google.co.tz
O1 - Hosts: 64.86.17.32 google.co.ug
O1 - Hosts: 64.86.17.32 google.co.uk
O1 - Hosts: 64.86.17.32 google.co.za
O1 - Hosts: 64.86.17.32 google.co.zm
O1 - Hosts: 64.86.17.32 google.com
O1 - Hosts: 64.86.17.32 google.com.af
O1 - Hosts: 64.86.17.32 google.com.ag
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

  • Download OTL to your desktop.
  • Open OTL. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Change the Standard Registry and Extra Registry options to Use Safelist.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.




Go to the top of the page
 
+Quote Post
handhfan
post Aug 24 2009, 07:24 AM
Post #7


GeekU Moderator
Group Icon
Posts: 8,651
From: Massachusetts
OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC



Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post
handhfan
post Sep 29 2009, 07:58 PM
Post #8


GeekU Moderator
Group Icon
Posts: 8,651
From: Massachusetts
OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC



Topic reopened at the user's request.

Please post the OTL log in your next reply.
Go to the top of the page
 
+Quote Post
PA Jeeper
post Sep 30 2009, 01:08 PM
Post #9


New Member
*
Posts: 9
OS: WinXP



OTL logfile created on: 9/30/2009 2:49:47 PM - Run 1
OTL by OldTimer - Version 3.0.16.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 74.20% Memory free
2.41 Gb Paging File | 1.96 Gb Available in Paging File | 81.13% Paging File free
Paging file location(s): C:\pagefile.sys 576 1152 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.53 Gb Total Space | 129.72 Gb Free Space | 87.34% Space Free | Partition Type: NTFS
Drive D: | 4.84 Gb Total Space | 3.40 Gb Free Space | 70.25% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADJP
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\WINDOWS\zHotkey.exe ()
PRC - C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
PRC - C:\WINDOWS\System32\HPZipm12.exe (HP)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [Auto | Running]) -- C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) -- C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (getPlus® Helper [On_Demand | Stopped]) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (gusvc [On_Demand | Stopped]) -- File not found
SRV - (helpsvc [On_Demand | Stopped]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (McAfee SiteAdvisor Service [Auto | Running]) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (mcmscsvc [Auto | Running]) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Disabled | Stopped]) -- c:\program files\common files\mcafee\mna\mcnasvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McrdSvc [On_Demand | Stopped]) -- C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (McShield [Unknown | Running]) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [Disabled | Stopped]) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MHN [On_Demand | Stopped]) -- C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (MpfService [Auto | Running]) -- C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (MSK80Service [Auto | Running]) -- C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (PrismXL [Auto | Running]) -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (Roxio UPnP Renderer 9 [On_Demand | Stopped]) -- C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe (Sonic Solutions)
SRV - (Roxio Upnp Server 9 [Auto | Stopped]) -- C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe (Sonic Solutions)
SRV - (RoxMediaDB9 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (stllssvr [On_Demand | Stopped]) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (YahooAUService [Auto | Running]) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (CmdIde [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DLABMFSM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLABOIOM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLACDBHM [System | Running]) -- C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Roxio)
DRV - (DLADResM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLADResM.SYS (Roxio)
DRV - (DLAIFS_M [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAOPIOM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLAPoolM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLARTL_M [System | Running]) -- C:\WINDOWS\System32\Drivers\DLARTL_M.SYS (Roxio)
DRV - (DLAUDFAM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAUDF_M [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DRVMCDB [Boot | Running]) -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DRVNDDM [Auto | Running]) -- C:\WINDOWS\System32\Drivers\DRVNDDM.SYS (Roxio)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HdAudAddService [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\AtiHdAud.sys (ATI Research Inc.)
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HPZid412 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWBS2 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mfeavfk [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) -- C:\WINDOWS\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (MPFP [System | Running]) -- C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (mraid35x [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RTL8023xp [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (RxFilter [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\RxFilter.sys (Sonic Solutions)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (symc810 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (ultra [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe...-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2
FF - prefs.js..network.proxy.autoconfig_url: "http://localhost:9100/proxy.pac"
FF - prefs.js..network.proxy.type: 2

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2009/08/30 17:16:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 15:37:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/25 16:10:15 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/18 16:46:19 | 00,000,000 | ---D | M]

[2009/06/09 19:43:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions
[2009/06/09 19:43:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/09 19:43:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\0n6re0oi.default\extensions
[2009/09/30 14:37:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\0n6re0oi.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/30 14:37:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\0n6re0oi.default\extensions\staged-xpis
[2009/08/18 16:46:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/08/18 16:46:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/30 07:26:53 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/07/30 07:26:54 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/30 07:26:55 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/07/30 03:24:20 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/07/30 03:24:20 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/07/30 03:24:20 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/07/30 03:24:20 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/07/30 03:24:20 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/07/30 03:24:20 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/07/30 03:24:20 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

Hosts file not found
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [Power2GoExpress] File not found
O4 - HKCU..\Run: [PowerBar] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~4.EXE -Update -1103472 -Mozilla\4.0 ( File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: schuylkill.pa.us ([co] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} https://co.schuylkill.pa.us/_applets/smsx.cab (MeadCo ScriptX)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/3/9...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.229.54.212 207.44.96.129 24.229.54.220
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/06/17 05:41:16 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 00,000,053 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/09/30 14:42:51 | 00,518,144 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/09/30 14:40:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\backups
[2009/09/21 19:15:05 | 21,459,64032 | -HS- | C] () -- C:\hiberfil.sys
[2009/09/21 18:33:07 | 00,009,936 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\livelog-2009-09-21.html
[2009/09/15 12:52:26 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Backhoe Work Act Towing Inc- change.doc
[2009/09/10 06:25:30 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\triedit.dll
[2009/09/09 20:08:33 | 00,066,048 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Urination record.doc
[2009/09/07 08:42:09 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Churp.doc
[2009/09/06 15:48:54 | 00,025,088 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Dakota towing letter.doc
[2009/09/06 13:37:23 | 00,020,992 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Start Up For JD 310 A.doc
[2008/11/18 18:54:31 | 00,000,032 | ---- | C] () -- C:\WINDOWS\CD_Start.INI
[2008/06/24 21:19:45 | 00,056,056 | ---- | C] () -- C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/03/23 12:18:20 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2008/02/25 21:09:04 | 00,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2008/01/12 10:16:11 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2007/04/18 19:50:31 | 00,000,228 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/01/18 20:29:00 | 00,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2007/01/17 13:57:34 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/12/13 23:01:36 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/12/13 23:01:36 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2006/09/30 19:22:25 | 00,000,171 | ---- | C] () -- C:\WINDOWS\EPSON CX3200 Installer.ini
[2006/09/18 23:29:09 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\jesterss.dll
[2006/09/18 23:27:39 | 00,532,544 | ---- | C] () -- C:\WINDOWS\PIC.dll
[2006/09/18 23:27:39 | 00,024,576 | ---- | C] () -- C:\WINDOWS\HKNTDLL.dll
[2006/09/18 23:27:39 | 00,011,776 | ---- | C] () -- C:\WINDOWS\HIDMNT.dll
[2006/09/18 23:26:34 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006/09/18 23:10:14 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/09/18 23:10:12 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2006/06/21 05:48:15 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/06/17 05:24:58 | 00,001,252 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/06/17 05:24:57 | 00,000,519 | ---- | C] () -- C:\WINDOWS\System32\emver.ini
[2006/06/17 05:23:30 | 00,000,663 | ---- | C] () -- C:\WINDOWS\win.ini
[2006/06/17 05:23:29 | 00,000,282 | ---- | C] () -- C:\WINDOWS\system.ini
[2005/08/06 00:01:54 | 00,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2001/07/07 04:00:00 | 00,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[1998/08/16 05:00:00 | 00,004,096 | ---- | C] () -- C:\WINDOWS\System32\sysres.dll

========== Files - Modified Within 30 Days ==========

[2 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/09/30 14:36:52 | 00,018,249 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF
[2009/09/30 14:36:46 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/09/30 14:36:13 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/09/30 14:36:11 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/09/30 14:36:06 | 21,459,64032 | -HS- | M] () -- C:\hiberfil.sys
[2009/09/30 14:35:00 | 05,564,424 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2009/09/30 14:10:20 | 00,518,144 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/09/24 15:55:13 | 00,000,273 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Login Facebook.url
[2009/09/24 15:54:05 | 00,000,347 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Sign in to Yahoo!.url
[2009/09/24 15:51:23 | 00,000,574 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Administrator.job
[2009/09/22 17:34:52 | 00,000,156 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\KD RADIO - Listen to Oldies Music Live.url
[2009/09/21 19:33:03 | 00,001,687 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\.googlewebacchosts
[2009/09/21 19:29:07 | 00,000,207 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\TAX SIGN IN.url
[2009/09/21 19:16:04 | 00,080,816 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/09/21 18:33:07 | 00,009,936 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\livelog-2009-09-21.html
[2009/09/19 14:29:17 | 00,296,456 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/15 12:52:26 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Backhoe Work Act Towing Inc- change.doc
[2009/09/10 10:19:11 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/09/09 20:08:33 | 00,066,048 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Urination record.doc
[2009/09/07 08:42:10 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Churp.doc
[2009/09/06 15:48:54 | 00,025,088 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Dakota towing letter.doc
[2009/09/06 13:37:23 | 00,020,992 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Start Up For JD 310 A.doc

========== LOP Check ==========

[2009/08/21 07:28:47 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Administrator\Application Data
[2007/05/02 11:29:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ArcSoft
[2007/11/05 19:20:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ATI
[2008/05/13 18:58:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\CyberLink
[2008/03/23 12:22:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\EPSON
[2009/08/21 07:28:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Juniper Networks
[2006/09/18 23:30:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Leadertech
[2008/04/12 01:34:16 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Administrator\Application Data\Move Networks
[2007/09/05 20:03:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\muvee Technologies
[2006/09/30 20:01:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Nikon
[2007/02/04 19:46:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\OfficeUpdate12
[2007/12/25 07:41:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PlayFirst
[2007/04/18 19:55:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Roxio
[2006/09/18 23:28:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SampleView
[2008/03/23 13:54:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Snapfish
[2006/09/18 23:28:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
[2009/08/14 21:24:53 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/11/14 21:18:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/08/11 17:05:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\25be383
[2006/11/21 19:41:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink
[2006/09/30 20:00:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2009/06/02 22:18:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2008/12/26 12:10:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2007/09/05 20:02:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2006/10/18 19:26:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2008/03/23 12:26:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Netscape Internet Service
[2009/07/17 18:01:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Norton
[2009/07/17 18:00:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2007/12/25 07:41:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2006/06/19 02:36:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Prism Deploy
[2006/09/18 23:29:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pure Networks
[2008/06/24 21:13:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Roxio
[2007/12/25 07:34:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2006/09/30 20:00:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2004/08/10 15:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2007/02/07 19:16:09 | 00,000,366 | ---- | M] () -- C:\WINDOWS\Tasks\McDefragTask.job
[2007/02/07 19:16:07 | 00,000,368 | ---- | M] () -- C:\WINDOWS\Tasks\McQcTask.job
[2009/09/24 15:51:23 | 00,000,574 | ---- | M] () -- C:\WINDOWS\Tasks\Norton Security Scan for Administrator.job
[2009/09/30 14:36:13 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


< End of report >

OTL Extras logfile created on: 9/30/2009 2:49:47 PM - Run 1
OTL by OldTimer - Version 3.0.16.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 74.20% Memory free
2.41 Gb Paging File | 1.96 Gb Available in Paging File | 81.13% Paging File free
Paging file location(s): C:\pagefile.sys 576 1152 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.53 Gb Total Space | 129.72 Gb Free Space | 87.34% Space Free | Partition Type: NTFS
Drive D: | 4.84 Gb Total Space | 3.40 Gb Free Space | 70.25% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADJP
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{03F596E7-711E-BCBC-6B12-14BCC34E94AE}" = Catalyst Control Center Localization Chinese Traditional
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{081FFC02-C2C2-8157-3F3A-E772835376F1}" = CCC Help Dutch
"{0E87AD02-59C2-F13A-914A-43CE9F154D95}" = CCC Help Turkish
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite Gateway
"{1850E857-8835-F1CD-EB74-28BC21F5C6E4}" = Catalyst Control Center Localization Danish
"{1B443E79-20A3-C4B8-9DF0-7AD70D5A7E34}" = Catalyst Control Center Localization Hungarian
"{1CC48EE1-F92D-71E9-06FD-EE1B5B97B326}" = CCC Help Swedish
"{1D02EDFD-67FD-FA26-7A2A-8522FDFBECE7}" = Catalyst Control Center Localization Swedish
"{1EBB57D4-63FF-87CC-A0F0-D73982CF6008}" = Adobe Media Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Solution
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{33629605-2892-154A-0719-74091EE602F1}" = CCC Help Danish
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{3A3032B5-C663-C601-AF40-D585C51C26CD}" = ccc-core-preinstall
"{3B9FE165-BB44-0AC1-338A-119C21E88FD0}" = CCC Help Norwegian
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 4.0
"{49E91FA4-087A-0FC2-2A48-86065EA45096}" = CCC Help Hungarian
"{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875}" = Digital Media Reader
"{623BA40F-FFFA-27FF-EE41-0F4037E04B53}" = Catalyst Control Center Graphics Previews Common
"{6599091B-D42D-4765-ABC3-8B25E844C746}" = Roxio Easy CD and DVD Burning
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6E66ECBD-FCA7-4AE1-A8C5-1CA78BEEB057}" = Multimedia Keyboard Driver
"{6EFC747C-B951-F9FE-1D7F-BF9EB99444BC}" = Catalyst Control Center Localization Japanese
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{77762C94-FACB-14D8-6B43-DBDB419AD540}" = Catalyst Control Center Localization Chinese Standard
"{778DB177-6611-BC09-8CC2-B7A0EC30B076}" = Catalyst Control Center Localization Norwegian
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7936AE92-BD48-D07E-C687-8B7EE1E2F2C5}" = CCC Help English
"{7CC619F6-3DD1-1E27-2789-BCCE64F28724}" = CCC Help Finnish
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{902ED1EB-C24C-00E8-18F2-C1FAC5F380FE}" = Catalyst Control Center Localization German
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{93BC4F0B-6B0D-6BB9-23E5-4D91ADECC363}" = Catalyst Control Center Localization Finnish
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9A2AF890-B0CD-43DC-85F6-AA0B51024DFF}" = ATI MCE Transcode
"{A22DD1EF-D1D3-2009-DFA5-52D4F9ECD336}" = Catalyst Control Center Graphics Full Existing
"{A2DA1463-0397-1703-1D23-1CE48DB236FF}" = CCC Help Spanish
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A806431C-A9EE-8DDC-14D3-908E5EABE028}" = CCC Help Thai
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABBA1CDA-0826-5C45-7ADA-B677D385BA61}" = Catalyst Control Center Localization French
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{AD15EF2D-3038-89DB-E876-16E6101B5918}" = CCC Help Korean
"{AEE3D6B4-62F9-9F66-657F-C5EADCB0B7A2}" = Catalyst Control Center Localization Korean
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B552A92D-E9BA-CECC-3E97-6B275C997F66}" = CCC Help German
"{B7061B68-7640-054B-6875-D2BD074B679F}" = Catalyst Control Center Graphics Full New
"{BADD04E1-85EF-9972-1C12-3D3257E237EA}" = CCC Help Portuguese
"{BCBF5D26-6288-1FF3-8AB3-C7F858B4A898}" = Skins
"{BE890EBA-271D-026F-6A06-49469530D78C}" = CCC Help Chinese Traditional
"{BF1A08B5-F846-38D3-7DA8-21796E2C8095}" = Catalyst Control Center Localization Greek
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4D4B939-2766-D52B-A5ED-2BD426EE8087}" = CCC Help Italian
"{C4DBF000-0E59-52B8-CEE8-04B8B3039FBF}" = Catalyst Control Center Localization Dutch
"{C7AE268E-9E3B-0291-D74B-A50D0F5DA400}" = Catalyst Control Center Localization Russian
"{C8D63234-A10F-EE16-2D78-9D1D71645A87}" = Catalyst Control Center Localization Turkish
"{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}" = AVIVO Codecs
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC50BEF5-B911-CF7A-F2A6-3963769ECE42}" = Catalyst Control Center Localization Polish
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{CF549873-2182-882D-A27A-E55ACC0825A9}" = CCC Help Russian
"{D0096C8C-DCFE-8FE7-8B6F-594C80D43965}" = Catalyst Control Center Localization Thai
"{D3689FCD-5DB8-F5B2-1C69-F6D799E973BB}" = CCC Help Japanese
"{D72E5EFB-CAB3-B938-81ED-677A8F9C0626}" = Catalyst Control Center Localization Portuguese
"{D8AB452C-45E8-C9C7-697D-CCA5DEFC65B1}" = ccc-core-static
"{D9FCE352-5F94-F52E-A828-39A1BD0557FF}" = Catalyst Control Center Localization Spanish
"{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}" = iTunes
"{E01804E2-2A96-4260-A0B9-3D769A054EB2}" = CCC Help Polish
"{E6288060-F5BF-0A24-66FA-251577BA1C7E}" = CCC Help Greek
"{ECEB1B9A-0598-251B-23D3-D1BBD4C8039F}" = CCC Help Czech
"{ED482774-626B-0FF4-A1D2-3A3271F204BF}" = Catalyst Control Center Localization Italian
"{EF865AFD-8C56-F6C4-C368-488558FE2213}" = CCC Help French
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2122DC5-0173-66AF-7AD3-D7E8A15721F1}" = Catalyst Control Center Core Implementation
"{F616831C-9B21-25B7-B9E9-FABA07FE3CB8}" = Catalyst Control Center Graphics Light
"{F825F00F-F776-F25C-B908-998BA4C3AE0A}" = CCC Help Chinese Standard
"{F85B4F16-DD73-5244-A93B-E557AD1825C3}" = ccc-utility
"{FBD7EACA-2E2F-694D-5EA9-28E34BE664AF}" = Catalyst Control Center Localization Czech
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200014F1" = Soft Data Fax Modem with SmartCP
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875}" = Digital Media Reader
"LimeWire" = LimeWire 4.18.8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Uninstall Utility" = McAfee Uninstall Wizard
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.2)" = Mozilla Firefox (3.5.2)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Norton PC Checkup" = Norton PC Checkup
"NSS" = Norton Security Scan
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Networks_Cache_Cleaner 6.3.0" = Juniper Networks Cache Cleaner 6.3.0
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Neoteris_Host_Checker" = Juniper Networks Host Checker

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/30/2009 2:26:53 PM | Computer Name = ADJP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 9/30/2009 2:26:53 PM | Computer Name = ADJP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 9/30/2009 2:26:53 PM | Computer Name = ADJP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 9/30/2009 2:26:57 PM | Computer Name = ADJP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 9/30/2009 2:26:57 PM | Computer Name = ADJP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 9/30/2009 2:26:57 PM | Computer Name = ADJP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 9/30/2009 2:36:22 PM | Computer Name = ADJP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 9/30/2009 2:36:22 PM | Computer Name = ADJP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 9/30/2009 2:36:22 PM | Computer Name = ADJP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 9/30/2009 2:36:22 PM | Computer Name = ADJP | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

[ System Events ]
Error - 9/29/2009 4:50:27 PM | Computer Name = ADJP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 9/29/2009 4:50:28 PM | Computer Name = ADJP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 9/29/2009 7:25:56 PM | Computer Name = ADJP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 9/29/2009 7:25:58 PM | Computer Name = ADJP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 9/30/2009 2:28:56 PM | Computer Name = ADJP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 9/30/2009 2:28:57 PM | Computer Name = ADJP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 9/30/2009 2:38:29 PM | Computer Name = ADJP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 9/30/2009 2:38:31 PM | Computer Name = ADJP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 9/30/2009 2:42:13 PM | Computer Name = ADJP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 9/30/2009 2:42:15 PM | Computer Name = ADJP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}


< End of report >

Attached File  OTL.Txt ( 76.21K ) Number of downloads: 6

Attached File  Extras.Txt ( 40.5K ) Number of downloads: 7
Go to the top of the page
 
+Quote Post
handhfan
post Sep 30 2009, 09:12 PM
Post #10


GeekU Moderator
Group Icon
Posts: 8,651
From: Massachusetts
OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC



Download the HostsXpert 3.7 - Hosts File Manager.
  • Unzip HostsXpert 3.7 - Hosts File Manager to a convenient folder such as C:\HostsXpert
  • Click HostsXpert.exe to Run HostsXpert 3.7 - Hosts File Manager from its new home
  • Click "Make Hosts Writable?" in the upper right corner (If available).
  • Click Restore Microsoft's Hosts file and then click OK.
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.


Please scan with OTL again and post the log here. smile.gif

Are you still being redirected?
Go to the top of the page
 
+Quote Post
PA Jeeper
post Oct 2 2009, 11:51 PM
Post #11


New Member
*
Posts: 9
OS: WinXP



I got some time after work tonight and did as instructed with HostsXpert but received a critical error when OTL was close to finishing the scan, I uploaded a screenshot below of the error. I also just uploaded the OTL and OTL Extras log files as well as after all was done I ran HijackThis again (uploaded its new log too). I then surfed the internet for roughly 20-30 minutes, using Googles search and did not get redirected once.


Attached File  OTL.Txt ( 77.15K ) Number of downloads: 6

Attached File  Extras.Txt ( 40.38K ) Number of downloads: 6

Attached File  New_HijackThis.txt ( 9.4K ) Number of downloads: 6

Attached Image
Go to the top of the page
 
+Quote Post
handhfan
post Oct 3 2009, 04:32 AM
Post #12


GeekU Moderator
Group Icon
Posts: 8,651
From: Massachusetts
OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC



Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 16.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u16-windows-i586.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u16-windows-i586.exe and select "Run as an Administrator.")


Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.

3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report... at the bottom.
  • Click the Save report... button.



  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply along with a new OTL log.
Go to the top of the page
 
+Quote Post
PA Jeeper
post Oct 4 2009, 06:52 PM
Post #13


New Member
*
Posts: 9
OS: WinXP



Attached File  KasReport.txt ( 861bytes ) Number of downloads: 7

Attached File  OTL.Txt ( 79.13K ) Number of downloads: 36

Attached File  Extras.Txt ( 39.04K ) Number of downloads: 6
Go to the top of the page
 
+Quote Post
handhfan
post Oct 5 2009, 11:11 AM
Post #14


GeekU Moderator
Group Icon
Posts: 8,651
From: Massachusetts
OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC



Is your computer running better now?
Go to the top of the page
 
+Quote Post
PA Jeeper
post Oct 5 2009, 04:48 PM
Post #15


New Member
*
Posts: 9
OS: WinXP



I did surf the net the other day for a while on that pc and did not notice any redirects. Now from this report from the Kaspersky online scanner I believe that its virus free.

After I cycle System Restores, I will most likely I will put on either Avast or AVG free edition for them as their McAfee subscription ran out. They had a few different anti-spyware on here, so I will most likely keep just the Spybot S&D along with the Malwarebytes. Then put on the free ZoneAlarm personal firewall too.

Out of the two free antiviruses which one is better? Lastly, is there anything else I am missing? Thank you so much for all your help!
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 21st November 2009 - 06:21 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising