Internet explorer, Msn messenger, adobe reader error message and shutd, I am getting error message from multiple programs and they shut down |
![]() ![]() |
Internet explorer, Msn messenger, adobe reader error message and shutd, I am getting error message from multiple programs and they shut down |
Aug 5 2009, 04:47 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 14 OS: Windows XP |
Even my At&t internet security anti virus scanner can't complete scan before getting an error message and shutting down. Please help anyway possible thank you.
|
|
|
Aug 9 2009, 05:15 PM
Post
#2
|
|
![]() Trusted Helper Posts: 8,065 OS: XP Pro |
Hello The Boy Wonder,
See if you can run this: Please download and save SysProt AntiRootkit to your Desktop.
|
|
|
Aug 10 2009, 07:00 AM
Post
#3
|
|
|
Member ![]() ![]() Posts: 14 OS: Windows XP |
SysProt AntiRootkit v1.0.1.0
by swatkat ****************************************************************************************** ****************************************************************************************** Process: Name: [System Idle Process] PID: 0 Hidden: No Window Visible: No Name: System PID: 4 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\smss.exe PID: 1272 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\csrss.exe PID: 1328 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\winlogon.exe PID: 1352 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 1400 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\lsass.exe PID: 1412 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\ibmpmsvc.exe PID: 1580 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\ati2evxx.exe PID: 1620 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1632 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1720 Hidden: No Window Visible: No Name: C:\Program Files\Windows Defender\MsMpEng.exe PID: 1760 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1800 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1892 Hidden: No Window Visible: No Name: C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe PID: 1940 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\S24EvMon.exe PID: 1996 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 220 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 312 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\spoolsv.exe PID: 756 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 832 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe PID: 892 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 956 Hidden: No Window Visible: No Name: C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe PID: 980 Hidden: No Window Visible: No Name: C:\Program Files\Java\jre6\bin\jqs.exe PID: 1020 Hidden: No Window Visible: No Name: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe PID: 1048 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE PID: 1084 Hidden: No Window Visible: No Name: C:\Program Files\Raxco\PerfectDisk\PDAgent.exe PID: 1112 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\QCONSVC.EXE PID: 1168 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\RegSrvc.exe PID: 1200 Hidden: No Window Visible: No Name: C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe PID: 1236 Hidden: No Window Visible: No Name: C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe PID: 1264 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\TpKmpSvc.exe PID: 1324 Hidden: No Window Visible: No Name: C:\Program Files\Zune\ZuneNss.exe PID: 212 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\alg.exe PID: 2300 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\wscntfy.exe PID: 3408 Hidden: No Window Visible: No Name: C:\WINDOWS\explorer.exe PID: 3572 Hidden: No Window Visible: No Name: C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe PID: 640 Hidden: No Window Visible: No Name: C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe PID: 652 Hidden: No Window Visible: No Name: C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe PID: 1404 Hidden: No Window Visible: No Name: C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe PID: 864 Hidden: No Window Visible: No Name: C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe PID: 2212 Hidden: No Window Visible: No Name: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe PID: 2236 Hidden: No Window Visible: No Name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe PID: 2260 Hidden: No Window Visible: No Name: C:\Program Files\Network Associates\Common Framework\UdaterUI.exe PID: 2276 Hidden: No Window Visible: No Name: C:\Program Files\Network Associates\Common Framework\Mctray.exe PID: 2364 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\dla\tfswctrl.exe PID: 192 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\rundll32.exe PID: 2628 Hidden: No Window Visible: No Name: C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe PID: 2804 Hidden: No Window Visible: No Name: C:\WINDOWS\AGRSMMSG.exe PID: 2928 Hidden: No Window Visible: No Name: C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLICON.EXE PID: 3052 Hidden: No Window Visible: No Name: C:\Program Files\Zune\ZuneLauncher.exe PID: 3072 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Real\Update_OB\realsched.exe PID: 3088 Hidden: No Window Visible: No Name: C:\Program Files\PowerISO\PWRISOVM.EXE PID: 3400 Hidden: No Window Visible: No Name: C:\Program Files\Windows Defender\MSASCui.exe PID: 3420 Hidden: No Window Visible: No Name: C:\Program Files\Java\jre6\bin\jusched.exe PID: 3448 Hidden: No Window Visible: No Name: C:\Program Files\AT&T\Internet Security Wizard\ISW.exe PID: 3512 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\ctfmon.exe PID: 2508 Hidden: No Window Visible: No Name: C:\Documents and Settings\ddemp912\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe PID: 392 Hidden: No Window Visible: No Name: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe PID: 400 Hidden: No Window Visible: No Name: C:\Program Files\Digital Line Detect\DLG.exe PID: 1768 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\wuauclt.exe PID: 3296 Hidden: No Window Visible: No Name: C:\Program Files\Mozilla Firefox\firefox.exe PID: 2896 Hidden: No Window Visible: No Name: C:\Program Files\MSN Messenger\usnsvc.exe PID: 3004 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\taskmgr.exe PID: 3148 Hidden: No Window Visible: Yes Name: C:\Documents and Settings\ddemp912\Desktop\SysProt\SysProt\SysProt.exe PID: 1872 Hidden: No Window Visible: Yes ****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \??\C:\Documents and Settings\ddemp912\Desktop\SysProt\SysProt\SysProtDrv.sys Service Name: SysProtDrv.sys Module Base: F5BFA000 Module End: F5C05000 Hidden: No Module Name: \windows\system32\ntoskrnl.exe Service Name: --- Module Base: 804D7000 Module End: 806EB580 Hidden: No Module Name: \windows\system32\hal.dll Service Name: --- Module Base: 806EC000 Module End: 806FFD80 Hidden: No Module Name: \windows\system32\KDCOM.DLL Service Name: --- Module Base: F7CCC000 Module End: F7CCE000 Hidden: No Module Name: \windows\system32\BOOTVID.dll Service Name: --- Module Base: F7BDC000 Module End: F7BDF000 Hidden: No Module Name: C:\windows\system32\drivers\ACPI.sys Service Name: ACPI Module Base: F777D000 Module End: F77AB000 Hidden: No Module Name: \windows\System32\DRIVERS\WMILIB.SYS Service Name: --- Module Base: F7CCE000 Module End: F7CD0000 Hidden: No Module Name: C:\windows\system32\drivers\pci.sys Service Name: PCI Module Base: F776C000 Module End: F777D000 Hidden: No Module Name: C:\windows\system32\drivers\isapnp.sys Service Name: isapnp Module Base: F77CC000 Module End: F77D5000 Hidden: No Module Name: C:\windows\system32\drivers\ohci1394.sys Service Name: ohci1394 Module Base: F77DC000 Module End: F77EB000 Hidden: No Module Name: \windows\System32\DRIVERS\1394BUS.SYS Service Name: --- Module Base: F77EC000 Module End: F77F9000 Hidden: No Module Name: C:\windows\system32\drivers\compbatt.sys Service Name: Compbatt Module Base: F7BE0000 Module End: F7BE3000 Hidden: No Module Name: \windows\System32\DRIVERS\BATTC.SYS Service Name: BattC Module Base: F7BE4000 Module End: F7BE8000 Hidden: No Module Name: C:\windows\system32\drivers\PCIIde.sys Service Name: PCIIde Module Base: F7D94000 Module End: F7D95000 Hidden: No Module Name: \windows\System32\Drivers\PCIIDEX.SYS Service Name: --- Module Base: F7A4C000 Module End: F7A53000 Hidden: No Module Name: C:\windows\system32\drivers\intelide.sys Service Name: IntelIde Module Base: F7CD0000 Module End: F7CD2000 Hidden: No Module Name: C:\windows\system32\drivers\pcmcia.sys Service Name: Pcmcia Module Base: F774E000 Module End: F776C000 Hidden: No Module Name: C:\windows\system32\drivers\MountMgr.sys Service Name: MountMgr Module Base: F77FC000 Module End: F7807000 Hidden: No Module Name: C:\windows\system32\drivers\ftdisk.sys Service Name: Disk Module Base: F772F000 Module End: F774E000 Hidden: No Module Name: C:\windows\system32\drivers\ACPIEC.sys Service Name: ACPIEC Module Base: F7BE8000 Module End: F7BEB000 Hidden: No Module Name: \windows\System32\DRIVERS\OPRGHDLR.SYS Service Name: --- Module Base: F7D95000 Module End: F7D96000 Hidden: No Module Name: C:\windows\system32\drivers\PartMgr.sys Service Name: PartMgr Module Base: F7A54000 Module End: F7A59000 Hidden: No Module Name: C:\windows\system32\drivers\VolSnap.sys Service Name: VolSnap Module Base: F780C000 Module End: F7819000 Hidden: No Module Name: C:\windows\system32\drivers\atapi.sys Service Name: atapi Module Base: F7717000 Module End: F772F000 Hidden: No Module Name: C:\windows\system32\drivers\disk.sys Service Name: --- Module Base: F781C000 Module End: F7825000 Hidden: No Module Name: \windows\System32\DRIVERS\CLASSPNP.SYS Service Name: --- Module Base: F782C000 Module End: F7839000 Hidden: No Module Name: C:\windows\system32\drivers\fltmgr.sys Service Name: FltMgr Module Base: F76F7000 Module End: F7717000 Hidden: No Module Name: C:\windows\system32\drivers\sr.sys Service Name: sr Module Base: F76E5000 Module End: F76F7000 Hidden: No Module Name: C:\windows\system32\drivers\PCTCore.sys Service Name: PCTCore Module Base: F76C2000 Module End: F76E5000 Hidden: No Module Name: C:\windows\system32\drivers\PxHelp20.sys Service Name: PxHelp20 Module Base: F783C000 Module End: F7845000 Hidden: No Module Name: C:\windows\system32\drivers\drvmcdb.sys Service Name: drvmcdb Module Base: F76AD000 Module End: F76C2000 Hidden: No Module Name: C:\windows\system32\drivers\KSecDD.sys Service Name: KSecDD Module Base: F7696000 Module End: F76AD000 Hidden: No Module Name: C:\windows\system32\drivers\WudfPf.sys Service Name: WudfPf Module Base: F7683000 Module End: F7696000 Hidden: No Module Name: C:\windows\system32\drivers\DefragFS.sys Service Name: DefragFS Module Base: F7670000 Module End: F7683000 Hidden: No Module Name: C:\windows\system32\drivers\Ntfs.sys Service Name: Ntfs Module Base: F75E3000 Module End: F7670000 Hidden: No Module Name: C:\windows\system32\drivers\NDIS.sys Service Name: NDIS Module Base: F75B6000 Module End: F75E3000 Hidden: No Module Name: C:\windows\system32\drivers\Mup.sys Service Name: Mup Module Base: F759B000 Module End: F75B6000 Hidden: No Module Name: C:\windows\system32\drivers\agp440.sys Service Name: agp440 Module Base: F784C000 Module End: F7857000 Hidden: No Module Name: C:\windows\System32\DRIVERS\intelppm.sys Service Name: intelppm Module Base: F6D52000 Module End: F6D5B000 Hidden: No Module Name: C:\windows\System32\DRIVERS\ati2mtag.sys Service Name: ati2mtag Module Base: F6AE7000 Module End: F6BA7000 Hidden: No Module Name: C:\windows\System32\DRIVERS\VIDEOPRT.SYS Service Name: --- Module Base: F6AD3000 Module End: F6AE7000 Hidden: No Module Name: C:\windows\System32\DRIVERS\usbuhci.sys Service Name: usbuhci Module Base: F7AFC000 Module End: F7B01000 Hidden: No Module Name: C:\windows\System32\DRIVERS\USBPORT.SYS Service Name: --- Module Base: F6AB0000 Module End: F6AD3000 Hidden: No Module Name: C:\windows\System32\DRIVERS\usbehci.sys Service Name: usbehci Module Base: F7B04000 Module End: F7B0B000 Hidden: No Module Name: C:\windows\System32\DRIVERS\w70n51.sys Service Name: w70n51 Module Base: F6851000 Module End: F6AB0000 Hidden: No Module Name: C:\windows\System32\DRIVERS\nic1394.sys Service Name: NIC1394 Module Base: F6D32000 Module End: F6D42000 Hidden: No Module Name: C:\windows\System32\DRIVERS\e100b325.sys Service Name: E100B Module Base: F682D000 Module End: F6851000 Hidden: No Module Name: C:\windows\System32\DRIVERS\i8042prt.sys Service Name: i8042prt Module Base: F6D22000 Module End: F6D2F000 Hidden: No Module Name: C:\windows\System32\Drivers\TfKbMon.sys Service Name: TfKbMon Module Base: F7B0C000 Module End: F7B14000 Hidden: No Module Name: C:\windows\System32\DRIVERS\kbdclass.sys Service Name: Kbdclass Module Base: F7B14000 Module End: F7B1A000 Hidden: No Module Name: C:\windows\System32\DRIVERS\SynTP.sys Service Name: SynTP Module Base: F67EB000 Module End: F682D000 Hidden: No Module Name: C:\windows\System32\DRIVERS\USBD.SYS Service Name: --- Module Base: F7CF8000 Module End: F7CFA000 Hidden: No Module Name: C:\windows\System32\DRIVERS\mouclass.sys Service Name: Mouclass Module Base: F7B1C000 Module End: F7B22000 Hidden: No Module Name: C:\windows\System32\DRIVERS\fdc.sys Service Name: Fdc Module Base: F7B24000 Module End: F7B2B000 Hidden: No Module Name: C:\windows\System32\DRIVERS\serial.sys Service Name: Serial Module Base: F6D12000 Module End: F6D22000 Hidden: No Module Name: C:\windows\System32\DRIVERS\serenum.sys Service Name: serenum Module Base: F7CC0000 Module End: F7CC4000 Hidden: No Module Name: C:\windows\System32\DRIVERS\parport.sys Service Name: Parport Module Base: F67D7000 Module End: F67EB000 Hidden: No Module Name: C:\windows\System32\DRIVERS\nscirda.sys Service Name: irda Module Base: F7B2C000 Module End: F7B33000 Hidden: No Module Name: C:\windows\System32\DRIVERS\irenum.sys Service Name: IRENUM Module Base: F7CC4000 Module End: F7CC7000 Hidden: No Module Name: C:\windows\System32\DRIVERS\CmBatt.sys Service Name: CmBatt Module Base: F7566000 Module End: F756A000 Hidden: No Module Name: C:\windows\System32\DRIVERS\ibmpmdrv.sys Service Name: IBMPMDRV Module Base: F7B34000 Module End: F7B3B000 Hidden: No Module Name: C:\windows\System32\DRIVERS\imapi.sys Service Name: Imapi Module Base: F6D02000 Module End: F6D0D000 Hidden: No Module Name: C:\windows\system32\drivers\sscdbhk5.sys Service Name: sscdbhk5 Module Base: F7CFA000 Module End: F7CFC000 Hidden: No Module Name: C:\windows\System32\DRIVERS\cdrom.sys Service Name: Cdrom Module Base: F788C000 Module End: F7899000 Hidden: No Module Name: C:\windows\System32\DRIVERS\redbook.sys Service Name: redbook Module Base: F789C000 Module End: F78AB000 Hidden: No Module Name: C:\windows\System32\DRIVERS\ks.sys Service Name: --- Module Base: F67B4000 Module End: F67D7000 Hidden: No Module Name: C:\windows\system32\drivers\smwdm.sys Service Name: smwdm Module Base: F6726000 Module End: F67B4000 Hidden: No Module Name: C:\windows\system32\drivers\portcls.sys Service Name: --- Module Base: F6702000 Module End: F6726000 Hidden: No Module Name: C:\windows\system32\drivers\drmk.sys Service Name: --- Module Base: F78AC000 Module End: F78BB000 Hidden: No Module Name: C:\windows\system32\drivers\aeaudio.sys Service Name: aeaudio Module Base: F66EA000 Module End: F6702000 Hidden: No Module Name: C:\windows\System32\DRIVERS\AGRSM.sys Service Name: AgereSoftModem Module Base: F65C5000 Module End: F66EA000 Hidden: No Module Name: C:\windows\System32\Drivers\Modem.SYS Service Name: Modem Module Base: F7B3C000 Module End: F7B44000 Hidden: No Module Name: C:\windows\System32\DRIVERS\audstub.sys Service Name: audstub Module Base: F7F1E000 Module End: F7F1F000 Hidden: No Module Name: C:\windows\System32\DRIVERS\rasirda.sys Service Name: Rasirda Module Base: F7B44000 Module End: F7B49000 Hidden: No Module Name: C:\windows\System32\DRIVERS\TDI.SYS Service Name: --- Module Base: F7B4C000 Module End: F7B51000 Hidden: No Module Name: C:\windows\System32\DRIVERS\rasl2tp.sys Service Name: Rasl2tp Module Base: F78BC000 Module End: F78C9000 Hidden: No Module Name: C:\windows\System32\DRIVERS\ndistapi.sys Service Name: NdisTapi Module Base: F7552000 Module End: F7555000 Hidden: No Module Name: C:\windows\System32\DRIVERS\ndiswan.sys Service Name: NdisWan Module Base: F65AE000 Module End: F65C5000 Hidden: No Module Name: C:\windows\System32\DRIVERS\raspppoe.sys Service Name: RasPppoe Module Base: F78CC000 Module End: F78D7000 Hidden: No Module Name: C:\windows\System32\DRIVERS\raspptp.sys Service Name: PptpMiniport Module Base: F78DC000 Module End: F78E8000 Hidden: No Module Name: C:\windows\System32\DRIVERS\psched.sys Service Name: PSched Module Base: F659D000 Module End: F65AE000 Hidden: No Module Name: C:\windows\System32\DRIVERS\msgpc.sys Service Name: Gpc Module Base: F78EC000 Module End: F78F5000 Hidden: No Module Name: C:\windows\System32\DRIVERS\ptilink.sys Service Name: Ptilink Module Base: F7B54000 Module End: F7B59000 Hidden: No Module Name: C:\windows\System32\DRIVERS\raspti.sys Service Name: Raspti Module Base: F7B5C000 Module End: F7B61000 Hidden: No Module Name: C:\windows\system32\DRIVERS\rp_skt32.sys Service Name: RPSKT Module Base: F78FC000 Module End: F7908000 Hidden: No Module Name: C:\windows\System32\DRIVERS\rdpdr.sys Service Name: rdpdr Module Base: F589D000 Module End: F58CE000 Hidden: No Module Name: C:\windows\System32\DRIVERS\termdd.sys Service Name: TermDD Module Base: F791C000 Module End: F7926000 Hidden: No Module Name: C:\windows\system32\DRIVERS\rp_pkt32.sys Service Name: RPPKT Module Base: F792C000 Module End: F793A000 Hidden: No Module Name: C:\windows\System32\DRIVERS\swenum.sys Service Name: swenum Module Base: F7D00000 Module End: F7D02000 Hidden: No Module Name: C:\windows\System32\DRIVERS\update.sys Service Name: Update Module Base: F5844000 Module End: F589D000 Hidden: No Module Name: C:\windows\System32\DRIVERS\mssmbios.sys Service Name: mssmbios Module Base: F6BBF000 Module End: F6BC3000 Hidden: No Module Name: C:\windows\System32\Drivers\NDProxy.SYS Service Name: NDProxy Module Base: F794C000 Module End: F7956000 Hidden: No Module Name: C:\windows\System32\DRIVERS\usbhub.sys Service Name: usbhub Module Base: F797C000 Module End: F798B000 Hidden: No Module Name: C:\windows\system32\DRIVERS\65644179.sys Service Name: is-RV7HUdrv Module Base: EB6CC000 Module End: EB6F4000 Hidden: No Module Name: C:\windows\System32\Drivers\Fs_Rec.SYS Service Name: Fs_Rec Module Base: F7D0A000 Module End: F7D0C000 Hidden: No Module Name: C:\windows\System32\Drivers\Null.SYS Service Name: Null Module Base: F7EE2000 Module End: F7EE3000 Hidden: No Module Name: C:\windows\System32\Drivers\Beep.SYS Service Name: Beep Module Base: F7D0C000 Module End: F7D0E000 Hidden: No Module Name: C:\windows\system32\drivers\ssrtln.sys Service Name: ssrtln Module Base: F7B8C000 Module End: F7B92000 Hidden: No Module Name: C:\windows\System32\drivers\vga.sys Service Name: VgaSave Module Base: F7B94000 Module End: F7B9A000 Hidden: No Module Name: C:\windows\System32\Drivers\mnmdd.SYS Service Name: mnmdd Module Base: F7D0E000 Module End: F7D10000 Hidden: No Module Name: C:\windows\System32\DRIVERS\RDPCDD.sys Service Name: RDPCDD Module Base: F7D10000 Module End: F7D12000 Hidden: No Module Name: C:\windows\System32\Drivers\Msfs.SYS Service Name: Msfs Module Base: F7B9C000 Module End: F7BA1000 Hidden: No Module Name: C:\windows\System32\Drivers\Npfs.SYS Service Name: Npfs Module Base: F7BA4000 Module End: F7BAC000 Hidden: No Module Name: C:\windows\System32\DRIVERS\rasacd.sys Service Name: RasAcd Module Base: F7C94000 Module End: F7C97000 Hidden: No Module Name: C:\windows\System32\DRIVERS\ipsec.sys Service Name: IPSec Module Base: EB699000 Module End: EB6AC000 Hidden: No Module Name: C:\windows\System32\DRIVERS\tcpip.sys Service Name: Tcpip Module Base: EB641000 Module End: EB699000 Hidden: No Module Name: C:\windows\System32\DRIVERS\netbt.sys Service Name: NetBT Module Base: EB619000 Module End: EB641000 Hidden: No Module Name: C:\windows\System32\drivers\afd.sys Service Name: AFD Module Base: EB5F7000 Module End: EB619000 Hidden: No Module Name: C:\windows\System32\DRIVERS\netbios.sys Service Name: NetBIOS Module Base: F799C000 Module End: F79A5000 Hidden: No Module Name: C:\windows\System32\Drivers\StarOpen.SYS Service Name: StarOpen Module Base: F7BAC000 Module End: F7BB2000 Hidden: No Module Name: C:\windows\System32\drivers\TSMAPIP.SYS Service Name: TSMAPIP Module Base: F7BB4000 Module End: F7BBA000 Hidden: No Module Name: C:\windows\System32\drivers\Tppwr.sys Service Name: TPPWR Module Base: F7BBC000 Module End: F7BC4000 Hidden: No Module Name: C:\windows\System32\Drivers\TPHKDRV.SYS Service Name: TPHKDRV Module Base: F7C98000 Module End: F7C9C000 Hidden: No Module Name: C:\windows\System32\drivers\TDSMAPI.SYS Service Name: TDSMAPI Module Base: F7BC4000 Module End: F7BCA000 Hidden: No Module Name: C:\windows\System32\drivers\Smapint.sys Service Name: Smapint Module Base: F7BCC000 Module End: F7BD4000 Hidden: No Module Name: C:\windows\System32\Drivers\SCDEmu.SYS Service Name: SCDEmu Module Base: F79BC000 Module End: F79C9000 Hidden: No Module Name: C:\windows\System32\DRIVERS\rdbss.sys Service Name: Rdbss Module Base: EB584000 Module End: EB5AF000 Hidden: No Module Name: C:\windows\System32\DRIVERS\mrxsmb.sys Service Name: MRxSmb Module Base: EB515000 Module End: EB584000 Hidden: No Module Name: C:\windows\System32\drivers\IBMBLDID.SYS Service Name: IBMTPCHK Module Base: F7EF6000 Module End: F7EF7000 Hidden: No Module Name: C:\windows\System32\Drivers\Fips.SYS Service Name: Fips Module Base: F79CC000 Module End: F79D5000 Hidden: No Module Name: C:\windows\System32\DRIVERS\ipnat.sys Service Name: IpNat Module Base: EB4D4000 Module End: EB4F5000 Hidden: No Module Name: C:\windows\System32\DRIVERS\wanarp.sys Service Name: Wanarp Module Base: F79DC000 Module End: F79E5000 Hidden: No Module Name: C:\windows\System32\DRIVERS\arp1394.sys Service Name: Arp1394 Module Base: F79EC000 Module End: F79FB000 Hidden: No Module Name: C:\windows\System32\drivers\ANC.SYS Service Name: ANC Module Base: F582C000 Module End: F582F000 Hidden: No Module Name: C:\windows\System32\Drivers\Cdfs.SYS Service Name: Cdfs Module Base: F787C000 Module End: F788C000 Hidden: No Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: --- Module Base: EB494000 Module End: EB4AC000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS Service Name: --- Module Base: F7D22000 Module End: F7D24000 Hidden: Yes Module Name: C:\windows\System32\drivers\Dxapi.sys Service Name: --- Module Base: F7C74000 Module End: F7C77000 Hidden: No Module Name: C:\windows\System32\watchdog.sys Service Name: --- Module Base: F7A84000 Module End: F7A89000 Hidden: No Module Name: C:\windows\System32\drivers\dxgthk.sys Service Name: --- Module Base: F7E5C000 Module End: F7E5D000 Hidden: No Module Name: C:\windows\system32\drivers\drvnddm.sys Service Name: drvnddm Module Base: F7A1C000 Module End: F7A26000 Hidden: No Module Name: C:\windows\system32\dla\tfsndres.sys Service Name: tfsndres Module Base: F7F0A000 Module End: F7F0B000 Hidden: No Module Name: C:\windows\system32\dla\tfsnifs.sys Service Name: tfsnifs Module Base: EB33F000 Module End: EB354000 Hidden: No Module Name: C:\windows\system32\dla\tfsnopio.sys Service Name: tfsnopio Module Base: F7C60000 Module End: F7C64000 Hidden: No Module Name: C:\windows\system32\dla\tfsnpool.sys Service Name: tfsnpool Module Base: F7D4C000 Module End: F7D4E000 Hidden: No Module Name: C:\windows\system32\dla\tfsnboio.sys Service Name: tfsnboio Module Base: F7AD4000 Module End: F7ADB000 Hidden: No Module Name: C:\windows\system32\dla\tfsncofs.sys Service Name: tfsncofs Module Base: EB45C000 Module End: EB465000 Hidden: No Module Name: C:\windows\system32\dla\tfsndrct.sys Service Name: tfsndrct Module Base: F7E05000 Module End: F7E06000 Hidden: No Module Name: C:\windows\system32\dla\tfsnudf.sys Service Name: tfsnudf Module Base: EB327000 Module End: EB33F000 Hidden: No Module Name: C:\windows\system32\dla\tfsnudfa.sys Service Name: tfsnudfa Module Base: EB30E000 Module End: EB327000 Hidden: No Module Name: C:\windows\System32\DRIVERS\AegisP.sys Service Name: AegisP Module Base: EB232000 Module End: EB236000 Hidden: No Module Name: C:\windows\System32\DRIVERS\irda.sys Service Name: --- Module Base: EB118000 Module End: EB12E000 Hidden: No Module Name: C:\windows\System32\DRIVERS\s24trans.sys Service Name: s24trans Module Base: EB1DE000 Module End: EB1E1000 Hidden: No Module Name: C:\windows\System32\DRIVERS\ndisuio.sys Service Name: Ndisuio Module Base: EB1DA000 Module End: EB1DE000 Hidden: No Module Name: C:\windows\System32\DRIVERS\mrxdav.sys Service Name: MRxDAV Module Base: F6521000 Module End: F654D000 Hidden: No Module Name: C:\windows\System32\Drivers\ParVdm.SYS Service Name: ParVdm Module Base: F7D5A000 Module End: F7D5C000 Hidden: No Module Name: C:\windows\system32\DRIVERS\css-dvp.sys Service Name: CSS DVP Module Base: F642D000 Module End: F64F9000 Hidden: No Module Name: C:\windows\System32\Drivers\Fastfat.SYS Service Name: Fastfat Module Base: F640A000 Module End: F642D000 Hidden: No Module Name: \??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS Service Name: EGATHDRV Module Base: F7D5E000 Module End: F7D60000 Hidden: No Module Name: C:\windows\System32\Drivers\HTTP.sys Service Name: HTTP Module Base: F63A1000 Module End: F63E2000 Hidden: No Module Name: C:\windows\System32\DRIVERS\srv.sys Service Name: Srv Module Base: F625F000 Module End: F62B1000 Hidden: No Module Name: C:\windows\System32\DRIVERS\mdmxsdk.sys Service Name: mdmxsdk Module Base: F6402000 Module End: F6405000 Hidden: No Module Name: \??\C:\WINDOWS\system32\drivers\PMEMNT.SYS Service Name: PMEM Module Base: F7D66000 Module End: F7D68000 Hidden: No Module Name: C:\windows\system32\drivers\wdmaud.sys Service Name: wdmaud Module Base: F5C0A000 Module End: F5C1F000 Hidden: No Module Name: C:\windows\system32\drivers\sysaudio.sys Service Name: sysaudio Module Base: F5E3F000 Module End: F5E4E000 Hidden: No Module Name: C:\windows\system32\drivers\kmixer.sys Service Name: kmixer Module Base: F72BF000 Module End: F72EA000 Hidden: No ****************************************************************************************** ****************************************************************************************** SSDT: Function Name: ZwCreateKey Address: F76DA514 Driver Base: F76C2000 Driver End: F76E5000 Driver Name: PCTCore.sys Function Name: ZwCreateProcess Address: F76C9282 Driver Base: F76C2000 Driver End: F76E5000 Driver Name: PCTCore.sys Function Name: ZwCreateProcessEx Address: F76C9474 Driver Base: F76C2000 Driver End: F76E5000 Driver Name: PCTCore.sys Function Name: ZwDeleteKey Address: F76DAD00 Driver Base: F76C2000 Driver End: F76E5000 Driver Name: PCTCore.sys Function Name: ZwDeleteValueKey Address: F76DAFB8 Driver Base: F76C2000 Driver End: F76E5000 Driver Name: PCTCore.sys Function Name: ZwOpenKey Address: F76D93FA Driver Base: F76C2000 Driver End: F76E5000 Driver Name: PCTCore.sys Function Name: ZwRenameKey Address: F76DB422 Driver Base: F76C2000 Driver End: F76E5000 Driver Name: PCTCore.sys Function Name: ZwSetValueKey Address: F76DA7D8 Driver Base: F76C2000 Driver End: F76E5000 Driver Name: PCTCore.sys Function Name: ZwTerminateProcess Address: F76C8F32 Driver Base: F76C2000 Driver End: F76E5000 Driver Name: PCTCore.sys ****************************************************************************************** ****************************************************************************************** Kernel Hooks: Hooked Function: ZwWriteFile At Address: 805771C5 Jump To: 83282EEC Module Name: _unknown_ Hooked Function: ZwSetSystemInformation At Address: 805A26F4 Jump To: 8333A6A4 Module Name: _unknown_ Hooked Function: ZwSetInformationFile At Address: 80576F1C Jump To: 8333CADC Module Name: _unknown_ Hooked Function: ZwDuplicateObject At Address: 80572BA6 Jump To: 83234EEC Module Name: _unknown_ Hooked Function: ZwCreateSection At Address: 8056469B Jump To: 832C3EEC Module Name: _unknown_ Hooked Function: KdEnteredDebugger At Address: 80552C70 Jump To: 80D5992F Module Name: _unknown_ Hooked Function: KdDebuggerNotPresent At Address: 80552C70 Jump To: 80D5992F Module Name: _unknown_ Hooked Function: KdDebuggerEnabled At Address: 80552C70 Jump To: 80D5992F Module Name: _unknown_ ****************************************************************************************** ****************************************************************************************** No IRP Hooks found ****************************************************************************************** ****************************************************************************************** Ports: Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:1321 Remote Address: 149.68.62.4:HTTP Type: TCP Process: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe State: SYN_SENT Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:NETBIOS-SSN Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: INFORMAT-V9QY5S:5152 Remote Address: LOCALHOST:1098 Type: TCP Process: C:\Program Files\Java\jre6\bin\jqs.exe State: CLOSE_WAIT Local Address: INFORMAT-V9QY5S:5152 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Java\jre6\bin\jqs.exe State: LISTENING Local Address: INFORMAT-V9QY5S:1088 Remote Address: LOCALHOST:1087 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: INFORMAT-V9QY5S:1087 Remote Address: LOCALHOST:1088 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: INFORMAT-V9QY5S:1083 Remote Address: LOCALHOST:1082 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: INFORMAT-V9QY5S:1082 Remote Address: LOCALHOST:1083 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: INFORMAT-V9QY5S:1028 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\alg.exe State: LISTENING Local Address: INFORMAT-V9QY5S:10244 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Zune\ZuneNss.exe State: LISTENING Local Address: INFORMAT-V9QY5S:8081 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe State: LISTENING Local Address: INFORMAT-V9QY5S:2869 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\svchost.exe State: LISTENING Local Address: INFORMAT-V9QY5S:MICROSOFT-DS Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: INFORMAT-V9QY5S:EPMAP Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\svchost.exe State: LISTENING Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:138 Remote Address: NA Type: UDP Process: System State: NA Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:NETBIOS-NS Remote Address: NA Type: UDP Process: System State: NA Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: INFORMAT-V9QY5S:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: INFORMAT-V9QY5S:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: INFORMAT-V9QY5S:8082 Remote Address: NA Type: UDP Process: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe State: NA Local Address: INFORMAT-V9QY5S:8081 Remote Address: NA Type: UDP Process: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe State: NA Local Address: INFORMAT-V9QY5S:4500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: INFORMAT-V9QY5S:500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: INFORMAT-V9QY5S:MICROSOFT-DS Remote Address: NA Type: UDP Process: System State: NA ****************************************************************************************** ****************************************************************************************** Hidden files/folders: Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\0110333013 Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\110112008( Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\110112008( Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\1101120083 Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\24270_300x Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\cbajaxmoda Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\cbsalary_s Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\contentreq Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\DocumentDo Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\flashwrite Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\MicrosoftA Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\richtextco Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\shadowedp( Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\shadowedpo Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\SiteCataly Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\sitetempla Status: Hidden Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\sologig-de Status: Hidden Object: C:\System Volume Information\MountPointManagerRemoteDatabase Status: Access denied Object: C:\System Volume Information\tracking.log Status: Access denied Object: C:\System Volume Information\_restore{BF4D3E3A-A9CB-4D7C-BC12-7E6C6028C599} Status: Access denied |
|
|
Aug 10 2009, 12:10 PM
Post
#4
|
|
![]() Trusted Helper Posts: 8,065 OS: XP Pro |
Hello again The Boy Wonder,
Can you run these ones? You may have used Malwarebytes before. If you have, and still have it on your machine, please update and run. Post the scan report back here. If you do not have Malwarebytes please download from Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Next
So when you return please post
Note: Unless otherwise instructed always post the logs in the forum. If reports don't fit on one post. It might be necessary to break the logs up to get them on the forum. Just use as many posts as you need, that's fine. |
|
|
Aug 10 2009, 01:35 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 14 OS: Windows XP |
Malwarebytes' Anti-Malware 1.40
Database version: 2593 Windows 5.1.2600 Service Pack 2 8/10/2009 3:11:32 PM mbam-log-2009-08-10 (15-11-32).txt Scan type: Quick Scan Objects scanned: 97011 Time elapsed: 12 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ====================================================================================== OTL logfile created on: 8/10/2009 3:21:59 PM - Run 1 OTL by OldTimer - Version 3.0.10.5 Folder = C:\Documents and Settings\ddemp912\Desktop Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 382.92 Mb Total Physical Memory | 96.39 Mb Available Physical Memory | 25.17% Memory free 920.52 Mb Paging File | 430.43 Mb Available in Paging File | 46.76% Paging File free Paging file location(s): C:\pagefile.sys 576 1152 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 33.97 Gb Total Space | 7.88 Gb Free Space | 23.21% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: INFORMAT-V9QY5S Current User Name: ddemp912 Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\windows\System32\ibmpmsvc.exe () PRC - C:\windows\System32\Ati2evxx.exe () PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) PRC - C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe (AT&T) PRC - C:\windows\System32\S24EvMon.exe (Intel Corporation ) PRC - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe (Authentium, Inc.) PRC - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe (CA, Inc.) PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee, Inc.) PRC - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation) PRC - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe (Raxco Software, Inc.) PRC - C:\windows\System32\QCONSVC.EXE (IBM Corp.) PRC - C:\windows\System32\RegSrvc.exe (Intel Corporation) PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.) PRC - C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe (McAfee, Inc.) PRC - C:\windows\System32\TpKmpSVC.exe () PRC - C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation) PRC - C:\windows\System32\wscntfy.exe (Microsoft Corporation) PRC - C:\windows\Explorer.EXE (Microsoft Corporation) PRC - C:\Program Files\ThinkPad\Utilities\EzEjMnAp.Exe (IBM Corp.) PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe () PRC - C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe () PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe () PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe (IBM Corporation) PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.) PRC - C:\Program Files\Network Associates\Common Framework\UdaterUI.exe (McAfee, Inc.) PRC - C:\Program Files\Network Associates\Common Framework\McTray.exe (McAfee, Inc.) PRC - C:\windows\System32\dla\tfswctrl.exe (Sonic Solutions) PRC - C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe (Intel® Corporation) PRC - C:\windows\AGRSMMSG.exe (Agere Systems) PRC - C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE (IBM Corp.) PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation) PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.) PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\AT&T\Internet Security Wizard\ISW.exe (AT&T) PRC - C:\Documents and Settings\ddemp912\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe (Google Inc.) PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software) PRC - C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation) PRC - C:\windows\System32\taskmgr.exe (Microsoft Corporation) PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) PRC - C:\Documents and Settings\ddemp912\Desktop\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (ASKUpgrade [Auto | Stopped]) -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe () SRV - (aspnet_state [On_Demand | Stopped]) -- C:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation) SRV - (Ati HotKey Poller [Auto | Running]) -- C:\windows\System32\Ati2evxx.exe () SRV - (dvpapi [Auto | Running]) -- C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe (Authentium, Inc.) SRV - (helpsvc [Auto | Running]) -- C:\windows\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (IBMPMSVC [Auto | Running]) -- C:\windows\System32\ibmpmsvc.exe () SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation) SRV - (iPod Service [On_Demand | Stopped]) -- File not found SRV - (Irmon [Auto | Running]) -- C:\windows\System32\irmon.dll (Microsoft Corporation) SRV - (ITMRTSVC [Auto | Running]) -- C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe (CA, Inc.) SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) SRV - (McAfeeFramework [Auto | Running]) -- C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee, Inc.) SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation) SRV - (NetSvc [On_Demand | Stopped]) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation) SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) SRV - (PDAgent [Auto | Running]) -- C:\Program Files\Raxco\PerfectDisk\PDAgent.exe (Raxco Software, Inc.) SRV - (PDEngine [On_Demand | Stopped]) -- C:\Program Files\Raxco\PerfectDisk\PDEngine.exe (Raxco Software, Inc.) SRV - (QCONSVC [Auto | Running]) -- C:\windows\System32\QCONSVC.EXE (IBM Corp.) SRV - (RegSrvc [Auto | Running]) -- C:\windows\System32\RegSrvc.exe (Intel Corporation) SRV - (RPSUpdaterR [On_Demand | Stopped]) -- C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe (AT&T) SRV - (RP_FWS [Auto | Running]) -- C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe (AT&T) SRV - (S24EventMonitor [Auto | Running]) -- C:\windows\System32\S24EvMon.exe (Intel Corporation ) SRV - (sdAuxService [On_Demand | Stopped]) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools) SRV - (sdCoreService [On_Demand | Stopped]) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools) SRV - (SoundMAX Agent Service (default) [Auto | Running]) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.) SRV - (ThreatFire [Auto | Stopped]) -- File not found SRV - (TpKmpSVC [Auto | Running]) -- C:\windows\System32\TpKmpSVC.exe () SRV - (usnjsvc [On_Demand | Running]) -- C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation) SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) SRV - (ZuneNetworkSvc [Auto | Running]) -- C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (aeaudio [On_Demand | Running]) -- C:\windows\System32\drivers\aeaudio.sys (Andrea Electronics Corporation) DRV - (AegisP [Auto | Running]) -- C:\windows\System32\DRIVERS\AegisP.sys (Meetinghouse Data Communications) DRV - (AgereSoftModem [On_Demand | Running]) -- C:\windows\System32\DRIVERS\AGRSM.sys (Agere Systems) DRV - (AM5211 [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\am5211.sys () DRV - (ANC [System | Running]) -- C:\windows\System32\drivers\ANC.SYS (IBM Corp.) DRV - (ati2mtag [On_Demand | Running]) -- C:\windows\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.) DRV - (CSS DVP [Auto | Running]) -- C:\windows\System32\DRIVERS\css-dvp.sys (Authentium, Inc.) DRV - (DefragFS [Boot | Running]) -- C:\windows\System32\drivers\DefragFs.sys (Raxco Software, Inc.) DRV - (drvmcdb [Boot | Running]) -- C:\windows\system32\drivers\drvmcdb.sys (Sonic Solutions) DRV - (drvnddm [Auto | Running]) -- C:\windows\System32\drivers\drvnddm.sys (Sonic Solutions) DRV - (E1000 [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\e1000325.sys (Intel Corporation) DRV - (E100B [On_Demand | Running]) -- C:\windows\System32\DRIVERS\e100b325.sys (Intel Corporation) DRV - (EGATHDRV [Auto | Running]) -- C:\windows\System32\EGATHDRV.SYS (IBM Corporation) DRV - (ggflt [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\ggflt.sys (Sony Ericsson Mobile Communications) DRV - (ggsemc [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\ggsemc.sys (Sony Ericsson Mobile Communications) DRV - (gv3 [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\gv3.sys (Microsoft Corporation) DRV - (HSFHWICH [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.) DRV - (HSF_DP [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.) DRV - (ialm [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\ialmnt5.sys (Intel Corporation) DRV - (IBMPMDRV [On_Demand | Running]) -- C:\windows\System32\DRIVERS\ibmpmdrv.sys (IBM Corp.) DRV - (IBMTPCHK [System | Running]) -- C:\windows\System32\drivers\IBMBLDID.SYS () DRV - (is-RV7HUdrv [System | Running]) -- C:\windows\System32\DRIVERS\65644179.sys (Kaspersky Lab) DRV - (mdmxsdk [Auto | Running]) -- C:\windows\System32\DRIVERS\mdmxsdk.sys (Conexant) DRV - (NSCIRDA [On_Demand | Running]) -- C:\windows\System32\DRIVERS\nscirda.sys (National Semiconductor Corporation) DRV - (PCTCore [Boot | Running]) -- C:\windows\system32\drivers\PCTCore.sys (PC Tools) DRV - (PMEM [Auto | Running]) -- C:\windows\System32\drivers\PMEMNT.SYS (Microsoft Corporation) DRV - (Ptilink [On_Demand | Running]) -- C:\windows\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.) DRV - (PxHelp20 [Boot | Running]) -- C:\windows\System32\DRIVERS\PxHelp20.sys (Sonic Solutions) DRV - (QCNDISIF [On_Demand | Stopped]) -- C:\windows\System32\drivers\qcndisif.SYS (IBM Corporation.) DRV - (RPPKT [On_Demand | Running]) -- C:\windows\System32\DRIVERS\rp_pkt32.sys (Radialpoint, Inc.) DRV - (RPSKT [Auto | Running]) -- C:\windows\System32\DRIVERS\rp_skt32.sys (Radialpoint, Inc.) DRV - (s116bus [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\s116bus.sys (MCCI Corporation) DRV - (s116mdfl [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\s116mdfl.sys (MCCI Corporation) DRV - (s116mdm [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\s116mdm.sys (MCCI Corporation) DRV - (s116mgmt [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\s116mgmt.sys (MCCI Corporation) DRV - (s116obex [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\s116obex.sys (MCCI Corporation) DRV - (s24trans [Auto | Running]) -- C:\windows\System32\DRIVERS\s24trans.sys (Intel Corporation) DRV - (SCDEmu [System | Running]) -- C:\windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.) DRV - (Secdrv [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (Smapint [System | Running]) -- C:\windows\System32\drivers\Smapint.sys (Microsoft Corporation) DRV - (smwdm [On_Demand | Running]) -- C:\windows\System32\drivers\smwdm.sys (Analog Devices, Inc.) DRV - (sscdbhk5 [System | Running]) -- C:\windows\System32\drivers\sscdbhk5.sys (Sonic Solutions) DRV - (ssrtln [System | Running]) -- C:\windows\System32\drivers\ssrtln.sys (Sonic Solutions) DRV - (StarOpen [System | Running]) -- C:\windows\System32\drivers\StarOpen.sys () DRV - (SynTP [On_Demand | Running]) -- C:\windows\System32\DRIVERS\SynTP.sys (Synaptics, Inc.) DRV - (TDSMAPI [System | Running]) -- C:\windows\System32\drivers\TDSMAPI.SYS () DRV - (tfsnboio [Auto | Running]) -- C:\windows\System32\dla\tfsnboio.sys (Sonic Solutions) DRV - (tfsncofs [Auto | Running]) -- C:\windows\System32\dla\tfsncofs.sys (Sonic Solutions) DRV - (tfsndrct [Auto | Running]) -- C:\windows\System32\dla\tfsndrct.sys (Sonic Solutions) DRV - (tfsndres [Auto | Running]) -- C:\windows\System32\dla\tfsndres.sys (Sonic Solutions) DRV - (tfsnifs [Auto | Running]) -- C:\windows\System32\dla\tfsnifs.sys (Sonic Solutions) DRV - (tfsnopio [Auto | Running]) -- C:\windows\System32\dla\tfsnopio.sys (Sonic Solutions) DRV - (tfsnpool [Auto | Running]) -- C:\windows\System32\dla\tfsnpool.sys (Sonic Solutions) DRV - (tfsnudf [Auto | Running]) -- C:\windows\System32\dla\tfsnudf.sys (Sonic Solutions) DRV - (tfsnudfa [Auto | Running]) -- C:\windows\System32\dla\tfsnudfa.sys (Sonic Solutions) DRV - (Tp4Track [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\tp4track.sys (IBM Corporation) DRV - (TPHKDRV [System | Running]) -- C:\windows\System32\drivers\TPHKDRV.sys (IBM Corporation) DRV - (TPPWR [System | Running]) -- C:\windows\System32\drivers\Tppwr.sys (IBM Corp.) DRV - (TSMAPIP [System | Running]) -- C:\windows\System32\drivers\TSMAPIP.SYS () DRV - (TwoTrack [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\TwoTrack.sys (IBM Corporation) DRV - (w22n51 [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\w22n51.sys (Intel® Corporation) DRV - (w70n51 [On_Demand | Running]) -- C:\windows\System32\DRIVERS\w70n51.sys (Intel® Corporation) DRV - (winachsf [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.) DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) -- C:\windows\System32\drivers\ialmsbw.sys (Intel Corporation) DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) -- C:\windows\System32\drivers\ialmkchw.sys (Intel Corporation) DRV - ({E2B953A6-195A-44F9-9BA3-3D5F4E32BB55} [On_Demand | Stopped]) -- C:\windows\System32\drivers\wA301a.sys (Intel Corporation) DRV - (MBAMSwissArmy [On_Demand | Running]) -- C:\windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation) ========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://cpprod.stjohns.edu/cp/home/loginf IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\windows\System32\ieframe.dll (Microsoft Corporation) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = actsvr.comcastonline.com IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = actsvr.comcastonline.com:8100 ========== FireFox ========== FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.07103010 FF - prefs.js..extensions.enabledItems: foxmarks@kei.com:3.1.0 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13 FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/20 15:32:11 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/05 14:51:37 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/05 14:51:37 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Netscape 6 6.2.3\Extensions\\Components: C:\Program Files\Netscape\Netscape 6\Components [2008/08/17 12:34:27 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Netscape 6 6.2.3\Extensions\\Plugins: C:\Program Files\Netscape\Netscape 6\Plugins [2009/08/05 11:33:43 | 00,000,000 | ---D | M] [2008/09/26 13:34:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Extensions [2008/09/26 13:34:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/08/09 18:49:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions [2009/07/22 10:39:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2009/08/05 11:56:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} [2009/07/07 13:36:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions\foxmarks@kei.com [2008/11/07 00:17:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions\moveplayer@movenetworks.com [2008/08/12 20:21:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions\pbreak.br@gmail.com [2009/08/09 18:49:24 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/08/05 14:51:37 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2008/11/22 11:11:06 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} [2009/07/20 15:33:07 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [2009/08/05 14:50:03 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/08/05 14:50:04 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009/07/20 15:32:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll [2008/09/15 20:11:52 | 01,335,600 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll [2008/09/15 20:12:12 | 00,098,304 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll [2009/02/06 12:44:28 | 01,447,296 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll [2009/08/05 14:50:50 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2004/12/14 02:19:18 | 00,057,344 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2008/08/12 14:04:14 | 00,144,984 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2007/03/12 17:17:26 | 00,131,072 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2008/08/12 14:04:28 | 00,024,576 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprjplug.dll [2008/08/12 14:04:12 | 00,081,920 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll [2009/07/10 19:30:51 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/07/10 19:30:51 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/07/10 19:30:51 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/07/10 19:30:51 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/07/10 19:30:51 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/07/10 19:30:52 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml O1 HOSTS File: (27 bytes) - C:\windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com) O2 - BHO: (PopKill Class) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T\AT&T Internet Security Suite\pkR.dll (Radialpoint Inc.) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com) O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\windows\System32\browseui.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\windows\System32\browseui.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\windows\System32\SHELL32.dll (Microsoft Corporation) O4 - HKLM..\Run: [AGRSMMSG] C:\windows\AGRSMMSG.exe (Agere Systems) O4 - HKLM..\Run: [AT&T Internet Security Suite] C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe (AT&T) O4 - HKLM..\Run: [ATIModeChange] C:\windows\System32\Ati2mdxx.exe (ATI Technologies, Inc.) O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.) O4 - HKLM..\Run: [BMMGAG] C:\Program Files\ThinkPad\Utilities\PWRMONIT.DLL (IBM Corp.) O4 - HKLM..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE () O4 - HKLM..\Run: [BMMMONWND] C:\Program Files\ThinkPad\Utilities\BATINFEX.DLL () O4 - HKLM..\Run: [dla] C:\windows\System32\dla\tfswctrl.exe (Sonic Solutions) O4 - HKLM..\Run: [EZEJMNAP] C:\Program Files\ThinkPad\Utilities\EzEjMnAp.Exe (IBM Corp.) O4 - HKLM..\Run: [-FreedomNeedsReboot] C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe (AT&T) O4 - HKLM..\Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe (Intel Corporation) O4 - HKLM..\Run: [IgfxTray] C:\windows\System32\igfxtray.exe (Intel Corporation) O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation) O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation) O4 - HKLM..\Run: [ISW.exe] C:\Program Files\AT&T\Internet Security Wizard\ISW.exe (AT&T) O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\Network Associates\Common Framework\UdaterUI.exe (McAfee, Inc.) O4 - HKLM..\Run: [MSPY2002] C:\windows\System32\IME\PINTLGNT\ImScInst.exe () O4 - HKLM..\Run: [PHIME2002A] C:\windows\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [PHIME2002ASync] C:\windows\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe (Intel® Corporation) O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.) O4 - HKLM..\Run: [QCWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE (IBM Corp.) O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.) O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [TP4EX] C:\windows\System32\tp4ex.exe (IBM Corporation) O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe () O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (IBM Corp.) O4 - HKLM..\Run: [TPKMAPMN] C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe () O4 - HKLM..\Run: [TrackPointSrv] C:\windows\System32\tp4serv.exe (IBM Corporation) O4 - HKLM..\Run: [UC_Start] C:\Program Files\IBM\Updater\ucstartup.exe () O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation) O4 - HKCU..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe (Microsoft Corporation) O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\ddemp912\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.) O4 - HKCU..\Run: [MsnMsgr] C:\Program Files\MSN Messenger\MsnMsgr.Exe (Microsoft Corporation) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software) O4 - Startup: C:\Documents and Settings\ddemp912\Start Menu\Programs\Startup\is-RV7HU.lnk = C:\Documents and Settings\ddemp912\My Documents\Downloads\Virus Removal Tool\is-RV7HU\startup.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonType = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars) O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.) O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe (PokerStars) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\windows\System32\winrnr.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\windows\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\windows\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\windows\System32\mswsock.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} https://www-3.ibm.com/pc/support/access/sdc...ad/tgctlins.cab (Reg Error: Key error.) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support) O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine) O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} file://C:\Program Files\Support.com\Bin\IBMAccessSupport\common\install\ibmegath.cab (IBM Access Support) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14) O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/...8146.5184143518 (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.4.1/...all-141-win.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E598AC61-4C6F-4F4D-877F-FAC49CA91FA3} file://C:\Program Files\Support.com\Bin\IBMAccessSupport\common\install\AcpControl.cab (acpRunner Class) O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\windows\System32\msvidctl.dll (Microsoft Corporation) O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\windows\System32\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation) O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\windows\System32\inetcomm.dll (Microsoft Corporation) O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\windows\System32\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\windows\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\windows\System32\msvidctl.dll (Microsoft Corporation) O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\windows\System32\wiascr.dll (Microsoft Corporation) O18 - Protocol\Filter: - application/octet-stream - C:\windows\System32\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter: - application/x-complus - C:\windows\System32\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter: - application/x-msdownload - C:\windows\System32\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter: - Class Install Handler - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Filter: - deflate - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Filter: - gzip - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Filter: - lzdhtml - C:\windows\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Filter: - text/webviewhtml - C:\windows\System32\SHELL32.dll (Microsoft Corporation) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\Explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: GinaDLL - (QConGina.dll) - C:\windows\System32\QConGina.dll (IBM Corp.) O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\windows\System32\logonui.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\windows\System32\shell32.dll (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\windows\System32\sysdm.cpl (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - File not found O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\windows\System32\crypt32.dll (Microsoft Corporation) O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\windows\System32\cryptnet.dll (Microsoft Corporation) O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\windows\System32\cscdll.dll (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\windows\System32\igfxsrvc.dll (Intel Corporation) O20 - Winlogon\Notify\QConGina: DllName - QConGina.dll - C:\windows\System32\QConGina.dll (IBM Corp.) O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\windows\System32\wlnotify.dll (Microsoft Corporation) O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\windows\System32\wlnotify.dll (Microsoft Corporation) O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\windows\System32\sclgntfy.dll (Microsoft Corporation) O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\windows\System32\WlNotify.dll (Microsoft Corporation) O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\windows\System32\wlnotify.dll (Microsoft Corporation) O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\windows\System32\WgaLogon.dll (Microsoft Corporation) O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\windows\System32\wlnotify.dll (Microsoft Corporation) O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\windows\System32\SHELL32.dll (Microsoft Corporation) O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\windows\System32\SHELL32.dll (Microsoft Corporation) O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\windows\System32\stobject.dll (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\System32\webcheck.dll (Microsoft Corporation) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\System32\WPDShServiceObj.dll (Microsoft Corporation) O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\windows\System32\browseui.dll (Microsoft Corporation) O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\windows\System32\browseui.dll (Microsoft Corporation) O24 - Desktop Components:0 (My Current Home Page) - About:Home O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\windows\System32\ntsd.exe (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\windows\System32\shell32.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\windows\System32\msapsspc.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (schannel.dll) - C:\windows\System32\schannel.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (digest.dll) - C:\windows\System32\digest.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\windows\System32\msnsspc.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (msv1_0) - C:\windows\System32\msv1_0.dll (Microsoft Corporation) O30 - LSA: Security Packages - (kerberos) - C:\windows\System32\kerberos.dll (Microsoft Corporation) O30 - LSA: Security Packages - (msv1_0) - C:\windows\System32\msv1_0.dll (Microsoft Corporation) O30 - LSA: Security Packages - (schannel) - C:\windows\System32\schannel.dll (Microsoft Corporation) O30 - LSA: Security Packages - (wdigest) - C:\windows\System32\wdigest.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (PDBoot.exe) - C:\windows\System32\PDBoot.exe (Raxco Software, Inc.) O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\windows\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found ========== Files/Folders - Created Within 30 Days ========== [1 C:\windows\System32\*.tmp files] [4 C:\windows\*.tmp files] [1 C:\Documents and Settings\ddemp912\Desktop\*.tmp files] [2009/08/10 14:48:53 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ddemp912\Desktop\OTL.exe [2009/08/10 14:44:55 | 03,942,048 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\ddemp912\Desktop\mbam-setup(2).exe [2009/08/10 08:48:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\SysProt [2009/08/10 08:47:19 | 00,355,033 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\SysProt.zip [2009/08/10 08:21:56 | 00,000,000 | ---D | C] -- C:\windows\LastGood [2009/08/06 19:34:20 | 24,438,882 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part3.mp3 [2009/08/06 19:31:09 | 46,963,614 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part2.mp3 [2009/08/06 13:37:27 | 00,024,985 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\(Demonoid.com)-TTC_VIDEO_Building_Great_Sentences_Exploring_the_Writer's_Craft_6049219.7142.torrent [2009/08/06 12:53:44 | 89,472,770 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part1.mp3 [2009/08/05 15:56:28 | 00,000,000 | ---D | C] -- C:\windows\System32\NtmsData [2009/08/05 13:39:32 | 00,000,000 | ---D | C] -- C:\Program Files\AVG [2009/08/05 13:39:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8 [2009/08/05 12:57:43 | 00,006,741 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\AVG_Anti_Virus_8_5_392_Build_1598_Multi_-[[Demonoid.com]]_6049219.7142.torrent [2009/08/05 12:20:29 | 66,248,382 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\av-i386&ids-cumul.zip [2009/08/05 12:08:13 | 00,003,254 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\x-Demonoid.com-x_[SteeP]_Kaspersky_Internet_Security_Anti_Virus_2010_Keys_[29_July_2009]_6049219.7142.torrent [2009/08/05 11:56:38 | 00,000,000 | ---D | C] -- C:\Program Files\AskBarDis [2009/08/05 11:55:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Application Data\uTorrent [2009/08/05 11:55:36 | 00,018,943 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\x-Demonoid.com-x_Insanity_Nutrition_Guide_6049219.7142.torrent [2009/08/05 11:33:44 | 00,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2009/08/05 11:33:44 | 00,001,740 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 7.0.lnk [2009/08/05 11:33:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe [2009/08/05 11:31:31 | 00,000,000 | -HSD | C] -- C:\Config.Msi [2009/08/05 10:27:10 | 00,000,000 | -H-D | C] -- C:\windows\PIF [2009/08/05 09:57:39 | 00,055,296 | ---- | C] (Radialpoint, Inc.) -- C:\windows\System32\drivers\rp_skt32.sys [2009/08/05 09:56:47 | 00,048,384 | ---- | C] (Radialpoint, Inc.) -- C:\windows\System32\drivers\rp_pkt32.sys [2009/08/05 09:55:57 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Authentium [2009/08/05 09:54:57 | 00,000,000 | ---D | C] -- C:\Program Files\Raxco [2009/08/05 09:54:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Raxco [2009/08/05 09:53:48 | 00,000,000 | ---D | C] -- C:\Program Files\CA [2009/08/05 09:53:38 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Scanner [2009/08/05 09:52:02 | 00,001,882 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AT&T Internet Security Suite.lnk [2009/08/05 09:48:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Application Data\AT&T [2009/08/05 09:46:06 | 00,000,000 | ---D | C] -- C:\Program Files\AT&T [2009/08/05 09:41:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AT&T [2009/08/05 09:40:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Application Data\InstallShield [2009/08/05 09:38:05 | 36,484,960 | ---- | C] (AT&T) -- C:\Documents and Settings\ddemp912\Desktop\bellsouthconsumersetup.exe [2009/08/05 02:00:13 | 00,000,268 | -H-- | C] () -- C:\sqmdata07.sqm [2009/08/05 02:00:13 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt07.sqm [2009/08/04 17:37:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\screenwriting.info [2009/08/04 10:57:45 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\instructions.doc [2009/08/04 08:17:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Motive [2009/08/03 23:53:49 | 00,000,268 | -H-- | C] () -- C:\sqmdata06.sqm [2009/08/03 23:53:49 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt06.sqm [2009/07/30 04:36:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\digitalStatement [2009/07/30 04:16:33 | 00,030,256 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\digitalStatement.zip [2009/07/30 03:17:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\derekj [2009/07/30 02:55:00 | 00,639,364 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\derekj.zip [2009/07/29 19:40:54 | 00,035,840 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Resume for guy.doc [2009/07/29 17:34:52 | 00,024,368 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Free_The_Future_of_a_Radical_Price_Chris_Anderson__-Demonoid.com-__6049219.7142.torrent [2009/07/27 14:33:26 | 00,027,136 | ---- | C] () -- C:\Documents and Settings\ddemp912\My Documents\character research.doc [2009/07/27 13:54:48 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\ddemp912\My Documents\address.doc [2009/07/26 17:22:36 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\ddemp912\My Documents\~$bsite info.doc [2009/07/26 17:22:34 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\ddemp912\My Documents\Website info.doc [2009/07/23 01:53:20 | 00,031,008 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\_=Demonoid.com=_-Paul_Janka_Beyond_the_Digits_(PUA)_6049219.7142.torrent [2009/07/22 11:41:50 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\This is Fixcast.doc [2009/07/21 13:29:21 | 00,000,000 | -HSD | C] -- C:\RECYCLER [2009/07/21 08:34:45 | 03,012,768 | ---- | C] (Javacool Software LLC ) -- C:\Documents and Settings\ddemp912\Desktop\spywareblastersetup42.exe [2009/07/21 08:23:11 | 60,857,536 | ---- | C] (Lavasoft ) -- C:\Documents and Settings\ddemp912\Desktop\Ad-AwareAE.exe [2009/07/21 08:16:08 | 00,000,933 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Spybot - Search & Destroy.lnk [2009/07/21 08:15:54 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy [2009/07/21 08:15:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy [2009/07/21 08:13:21 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\ddemp912\Desktop\spybotsd162.exe [2009/07/20 15:52:08 | 62,246,944 | -HS- | C] () -- C:\windows\System32\drivers\fidbox.dat [2009/07/20 15:52:08 | 00,713,468 | -HS- | C] () -- C:\windows\System32\drivers\fidbox.idx [2009/07/20 15:32:57 | 00,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\javacpl.cpl [2009/07/20 15:32:55 | 00,148,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\javaws.exe [2009/07/20 15:32:55 | 00,144,792 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\javaw.exe [2009/07/20 15:32:55 | 00,144,792 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\java.exe [2009/07/20 14:53:21 | 16,254,360 | ---- | C] (Sun Microsystems, Inc.) -- C:\Documents and Settings\ddemp912\Desktop\jre-6u14-windows-i586.exe [2009/07/20 13:29:02 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\HijackThis.lnk [2009/07/20 13:29:02 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro [2009/07/20 13:27:36 | 00,045,056 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\ComboFix 09.doc [2009/07/20 13:25:35 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\ddemp912\Desktop\HJTInstall.exe [2009/07/20 12:54:00 | 03,146,921 | R--- | C] () -- C:\Documents and Settings\ddemp912\Desktop\ComboFix.exe [2009/07/20 11:39:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Application Data\Malwarebytes [2009/07/20 11:38:46 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2009/07/20 11:38:38 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys [2009/07/20 11:38:35 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys [2009/07/20 11:38:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2009/07/20 11:38:34 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009/07/20 11:34:58 | 03,775,176 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\ddemp912\Desktop\mbam-setup.exe [2009/07/20 02:57:03 | 00,000,268 | -H-- | C] () -- C:\sqmdata05.sqm [2009/07/20 02:57:03 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt05.sqm [2009/07/14 23:57:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\The Final Mixtape Michael Jackson 45 Years Of Classical Music [2009/07/14 23:56:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\Forever King - Thisis50 [2009/07/14 23:55:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\50 Cent - War Angel LP - Thisis50 [2009/07/14 23:12:58 | 97,564,603 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\The Final Mixtape Michael Jackson 45 Years Of Classical Music.zip [2009/07/14 22:58:27 | 75,470,934 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Forever King - Thisis50.zip [2009/07/14 22:46:07 | 45,737,079 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\50 Cent - War Angel LP - Thisis50.zip [2009/07/14 00:30:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Local Settings\Application Data\PCHealth [2009/07/06 18:35:41 | 00,000,118 | ---- | C] () -- C:\windows\System32\MRT.INI [2008/11/22 12:14:04 | 00,021,840 | ---- | C] () -- C:\windows\System32\SIntfNT.dll [2008/11/22 12:14:04 | 00,017,212 | ---- | C] () -- C:\windows\System32\SIntf32.dll [2008/11/22 12:14:04 | 00,012,067 | ---- | C] () -- C:\windows\System32\SIntf16.dll [2008/09/15 20:14:24 | 03,596,288 | ---- | C] () -- C:\windows\System32\qt-dx331.dll [2008/09/15 20:12:02 | 00,000,416 | ---- | C] () -- C:\windows\System32\dtu100.dll.manifest [2008/09/15 20:12:02 | 00,000,416 | ---- | C] () -- C:\windows\System32\dpl100.dll.manifest [2008/09/15 20:11:10 | 00,012,288 | ---- | C] () -- C:\windows\System32\DivXWMPExtType.dll [2007/02/20 14:07:56 | 00,005,632 | R--- | C] () -- C:\windows\System32\drivers\StarOpen.sys [2007/02/07 17:53:45 | 00,000,280 | ---- | C] () -- C:\windows\System32\epoPGPsdk.dll.sig [2004/09/06 03:13:30 | 00,045,124 | ---- | C] () -- C:\windows\System32\LsaWrApi.dll [2004/09/06 03:04:12 | 00,225,349 | ---- | C] () -- C:\windows\System32\C1XStngs.dll [2004/06/30 10:02:30 | 00,363,520 | ---- | C] () -- C:\windows\System32\psisdecd.dll [2004/06/30 09:51:47 | 00,330,368 | ---- | C] () -- C:\windows\System32\drivers\am5211.sys [2004/06/30 09:51:47 | 00,330,368 | ---- | C] () -- C:\windows\System32\am5211.sys [2004/06/30 09:48:24 | 00,122,880 | ---- | C] () -- C:\windows\System32\tp4uires.dll [2004/06/30 09:48:01 | 00,131,072 | ---- | C] () -- C:\windows\System32\e1000msg.dll [2004/05/25 14:57:06 | 00,012,288 | ---- | C] () -- C:\windows\System32\e100bmsg.dll [2004/05/25 14:56:44 | 00,049,152 | ---- | C] () -- C:\windows\System32\tpinspm.dll [2004/03/18 12:55:48 | 00,000,000 | ---- | C] () -- C:\windows\System32\px.ini [2004/01/20 17:28:20 | 00,143,360 | ---- | C] () -- C:\windows\System32\AIBMRUNL.dll [2003/07/16 23:56:21 | 00,000,024 | ---- | C] () -- C:\windows\winamp.ini [2003/07/16 05:45:17 | 00,000,061 | ---- | C] () -- C:\windows\smscfg.ini [2003/06/22 17:55:38 | 00,000,000 | ---- | C] () -- C:\windows\netscape.INI [2003/06/22 14:50:49 | 00,000,376 | ---- | C] () -- C:\windows\ODBC.INI [2003/06/22 12:37:25 | 00,000,750 | ---- | C] () -- C:\windows\wininit.ini [2003/06/22 11:48:35 | 00,008,831 | ---- | C] () -- C:\windows\System32\drivers\TDSMAPI.SYS [2003/06/22 11:47:58 | 00,061,440 | ---- | C] () -- C:\windows\System32\FPCALL.dll [2003/06/22 11:47:44 | 00,007,168 | ---- | C] () -- C:\windows\System32\drivers\TSMAPIP.SYS [2003/06/22 11:46:21 | 00,002,295 | ---- | C] () -- C:\windows\System32\drivers\IBMBLDID.SYS [2003/06/22 05:04:06 | 00,051,979 | ---- | C] () -- C:\windows\System32\SynUnst.ini [2003/06/22 05:04:05 | 00,007,052 | ---- | C] () -- C:\windows\System32\SynTPEnh.ini [2003/06/22 05:03:47 | 00,077,824 | ---- | C] () -- C:\windows\System32\SynTPCoI.dll [2003/06/22 05:03:46 | 00,111,035 | ---- | C] () -- C:\windows\System32\SynTP.ini [2003/06/22 05:03:40 | 00,002,813 | ---- | C] () -- C:\windows\System32\IBM_DP.ini [2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\windows\System32\OUTLPERF.INI [2002/12/02 15:57:00 | 00,651,264 | ---- | C] () -- C:\windows\System32\libeay32.dll [2002/12/02 15:57:00 | 00,147,456 | ---- | C] () -- C:\windows\System32\ssleay32.dll [2002/08/29 08:00:00 | 00,000,813 | ---- | C] () -- C:\windows\win.ini [2002/08/29 08:00:00 | 00,000,227 | ---- | C] () -- C:\windows\system.ini ========== Files - Modified Within 30 Days ========== [1 C:\windows\System32\*.tmp files] [4 C:\windows\*.tmp files] [5 C:\Documents and Settings\ddemp912\My Documents\*.tmp files] [1 C:\Documents and Settings\ddemp912\Desktop\*.tmp files] [2009/08/10 15:22:03 | 62,246,944 | -HS- | M] () -- C:\windows\System32\drivers\fidbox.dat [2009/08/10 14:48:23 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ddemp912\Desktop\OTL.exe [2009/08/10 14:46:55 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2009/08/10 14:45:31 | 03,942,048 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\ddemp912\Desktop\mbam-setup(2).exe [2009/08/10 14:40:10 | 00,000,990 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032UA.job [2009/08/10 08:47:50 | 00,355,033 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\SysProt.zip [2009/08/10 08:15:33 | 00,000,330 | -H-- | M] () -- C:\windows\tasks\MP Scheduled Scan.job [2009/08/10 08:12:41 | 00,002,206 | ---- | M] () -- C:\windows\System32\wpa.dbl [2009/08/10 08:12:02 | 00,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT [2009/08/10 08:11:50 | 00,002,048 | --S- | M] () -- C:\windows\bootstat.dat [2009/08/10 02:02:57 | 00,713,468 | -HS- | M] () -- C:\windows\System32\drivers\fidbox.idx [2009/08/09 19:40:08 | 00,000,938 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032Core.job [2009/08/06 19:38:42 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\instructions.doc [2009/08/06 19:37:01 | 24,438,882 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part3.mp3 [2009/08/06 19:36:29 | 46,963,614 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part2.mp3 [2009/08/06 13:37:34 | 00,024,985 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\(Demonoid.com)-TTC_VIDEO_Building_Great_Sentences_Exploring_the_Writer's_Craft_6049219.7142.torrent [2009/08/06 13:03:33 | 89,472,770 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part1.mp3 [2009/08/05 18:41:20 | 00,000,583 | ---- | M] () -- C:\Documents and Settings\ddemp912\My Documents\My Sharing Folders.lnk [2009/08/05 12:57:47 | 00,006,741 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\AVG_Anti_Virus_8_5_392_Build_1598_Multi_-[[Demonoid.com]]_6049219.7142.torrent [2009/08/05 12:28:42 | 66,248,382 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\av-i386&ids-cumul.zip [2009/08/05 12:08:14 | 00,003,254 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\x-Demonoid.com-x_[SteeP]_Kaspersky_Internet_Security_Anti_Virus_2010_Keys_[29_July_2009]_6049219.7142.torrent [2009/08/05 11:55:40 | 00,018,943 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\x-Demonoid.com-x_Insanity_Nutrition_Guide_6049219.7142.torrent [2009/08/05 11:33:44 | 00,001,757 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2009/08/05 11:33:44 | 00,001,740 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 7.0.lnk [2009/08/05 09:52:02 | 00,001,882 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AT&T Internet Security Suite.lnk [2009/08/05 09:39:31 | 36,484,960 | ---- | M] (AT&T) -- C:\Documents and Settings\ddemp912\Desktop\bellsouthconsumersetup.exe [2009/08/05 02:00:13 | 00,000,268 | -H-- | M] () -- C:\sqmdata07.sqm [2009/08/05 02:00:13 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm [2009/08/03 23:53:49 | 00,000,268 | -H-- | M] () -- C:\sqmdata06.sqm [2009/08/03 23:53:49 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm [2009/08/03 13:36:28 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys [2009/08/03 13:36:06 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys [2009/08/02 23:43:56 | 00,080,384 | ---- | M] () -- C:\Documents and Settings\ddemp912\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/07/30 04:16:48 | 00,030,256 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\digitalStatement.zip [2009/07/30 02:55:31 | 00,639,364 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\derekj.zip [2009/07/29 19:40:55 | 00,035,840 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Resume for guy.doc [2009/07/29 17:35:34 | 00,024,368 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Free_The_Future_of_a_Radical_Price_Chris_Anderson__-Demonoid.com-__6049219.7142.torrent [2009/07/27 14:33:27 | 00,027,136 | ---- | M] () -- C:\Documents and Settings\ddemp912\My Documents\character research.doc [2009/07/27 13:54:49 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\ddemp912\My Documents\address.doc [2009/07/26 17:59:36 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\ddemp912\My Documents\Website info.doc [2009/07/26 17:22:36 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\ddemp912\My Documents\~$bsite info.doc [2009/07/23 01:53:55 | 00,031,008 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\_=Demonoid.com=_-Paul_Janka_Beyond_the_Digits_(PUA)_6049219.7142.torrent [2009/07/22 12:14:18 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\This is Fixcast.doc [2009/07/21 08:36:09 | 03,012,768 | ---- | M] (Javacool Software LLC ) -- C:\Documents and Settings\ddemp912\Desktop\spywareblastersetup42.exe [2009/07/21 08:33:37 | 60,857,536 | ---- | M] (Lavasoft ) -- C:\Documents and Settings\ddemp912\Desktop\Ad-AwareAE.exe [2009/07/21 08:16:08 | 00,000,933 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Spybot - Search & Destroy.lnk [2009/07/21 08:14:22 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\ddemp912\Desktop\spybotsd162.exe [2009/07/20 15:32:08 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\javaws.exe [2009/07/20 15:32:07 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\javaw.exe [2009/07/20 15:32:07 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\java.exe [2009/07/20 15:32:07 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\javacpl.cpl [2009/07/20 15:32:05 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\deploytk.dll [2009/07/20 14:53:52 | 16,254,360 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\ddemp912\Desktop\jre-6u14-windows-i586.exe [2009/07/20 13:29:02 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\HijackThis.lnk [2009/07/20 13:27:37 | 00,045,056 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\ComboFix 09.doc [2009/07/20 13:25:38 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\ddemp912\Desktop\HJTInstall.exe [2009/07/20 13:14:31 | 00,000,227 | ---- | M] () -- C:\windows\system.ini [2009/07/20 12:54:07 | 03,146,921 | R--- | M] () -- C:\Documents and Settings\ddemp912\Desktop\ComboFix.exe [2009/07/20 11:35:43 | 03,775,176 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\ddemp912\Desktop\mbam-setup.exe [2009/07/20 02:57:03 | 00,000,268 | -H-- | M] () -- C:\sqmdata05.sqm [2009/07/20 02:57:03 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm [2009/07/15 16:56:50 | 00,001,374 | ---- | M] () -- C:\windows\imsins.BAK [2009/07/15 16:48:59 | 00,000,118 | ---- | M] () -- C:\windows\System32\MRT.INI [2009/07/14 23:34:08 | 97,564,603 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\The Final Mixtape Michael Jackson 45 Years Of Classical Music.zip [2009/07/14 23:10:19 | 75,470,934 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Forever King - Thisis50.zip [2009/07/14 22:55:51 | 45,737,079 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\50 Cent - War Angel LP - Thisis50.zip ========== LOP Check ========== [2009/08/05 18:25:48 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data [2009/08/05 09:51:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AT&T [2004/05/26 09:47:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ibm [2009/08/04 08:17:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive [2008/10/13 19:50:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Network Associates [2008/09/17 03:51:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PAS [2009/07/06 17:45:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2009/08/05 11:55:58 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\ddemp912\Application Data [2004/07/06 08:53:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\Aim [2009/08/05 10:30:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\AT&T [2007/02/23 18:59:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\Azureus [2004/07/06 08:53:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\IBM [2004/07/06 08:53:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\InterVideo [2004/07/06 08:53:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\Leadertech [2008/11/08 01:17:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\Move Networks [2009/01/15 21:26:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\MXSkypeRec [2007/02/07 16:09:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\U3 [2009/08/06 19:40:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\uTorrent [2004/07/06 08:53:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\VERITAS [2002/08/29 08:00:00 | 00,000,065 | RH-- | M] () -- C:\windows\Tasks\desktop.ini [2009/08/09 19:40:08 | 00,000,938 | ---- | M] () -- C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032Core.job [2009/08/10 14:40:10 | 00,000,990 | ---- | M] () -- C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032UA.job [2009/08/10 08:15:33 | 00,000,330 | -H-- | M] () -- C:\windows\Tasks\MP Scheduled Scan.job [2009/08/10 08:12:02 | 00,000,006 | -H-- | M] () -- C:\windows\Tasks\SA.DAT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4BF2F6B5 @Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29 @Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 < End of report > ============================================================================================== OTL Extras logfile created on: 8/10/2009 3:21:59 PM - Run 1 OTL by OldTimer - Version 3.0.10.5 Folder = C:\Documents and Settings\ddemp912\Desktop Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 382.92 Mb Total Physical Memory | 96.39 Mb Available Physical Memory | 25.17% Memory free 920.52 Mb Paging File | 430.43 Mb Available in Paging File | 46.76% Paging File free Paging file location(s): C:\pagefile.sys 576 1152 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 33.97 Gb Total Space | 7.88 Gb Free Space | 23.21% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: INFORMAT-V9QY5S Current User Name: ddemp912 Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service "10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service "10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service "139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- (Microsoft Corporation) "C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation) "C:\Program Files\Trillian\trillian.exe" = C:\Program Files\Trillian\trillian.exe:*:Disabled:Trillian -- (Cerulean Studios) "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:uTorrent -- (BitTorrent, Inc.) "C:\Program Files\Sony Ericsson\Update Service\Update Service.exe" = C:\Program Files\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service -- () "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- (Microsoft Corporation) "C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation) "C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\English\setup.exe" = C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\English\setup.exe:*:Enabled:Kaspersky Anti-Virus 2009 Setup -- (Kaspersky Lab) "C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.) "C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0345520E-2A04-4A36-BC31-353AE87A6092}" = RPS Diagnostic Utility "{0818687F-F41F-496D-9D6D-DB98F147FC62}" = RPS Firewall "{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager "{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel "{0EFB66FE-E184-4D90-9B7C-429EA238E59D}" = Messageware Plus Pack Spell Check Component "{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = IBM DLA "{16906D21-0656-4F8B-9A01-C3D24B5401FC}" = Intel® PROSet for Wired Connections "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{1ACE3F9D-CDA4-4F39-9605-334CF37A1579}" = Authentium AntiVirus SDK - 2 "{1E164156-3FA1-4389-9B0B-28E88B879639}" = RPS AsRealtime "{1E4913E1-1554-4B0C-9F69-82CD62E46DA7}" = Messageware Plus Pack Compress Attachments "{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = IBM ThinkPad Keyboard Customizer Utility "{212F5777-1190-4DEF-8E4D-6B2F313B45E7}" = PerfectDisk "{22B71A00-4DED-11D4-A5E5-0004AC564F43}" = IBM Access Connections "{25B3E8D2-7597-4F38-8840-AFDD019E99E3}" = MELL Upgrading to Microsoft® Office 2003 Collection "{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java 6 Update 14 "{295F5142-A223-4164-9A6D-6683C08409FC}" = RPS RpsCore "{2F4BFC9D-17D7-447A-AEA2-467892D876B3}" = RPS App Detector "{310F26F3-C769-48E5-BD0D-53D4366C34CD}" = RPS PopupBlocker "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3DE72179-FEF4-4846-BF82-62CBFC61F8D7}" = RPS Performance Tool "{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HydraVision "{4AA73DA8-8D69-44ED-B5D7-CB815C81F83E}" = RPS Zip "{537654FC-556A-4992-BF3D-ADC05E7009DC}" = RPS AntiFraud "{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger "{58A2663B-56DC-488F-8E29-D44C6DE053B5}" = RPS Security Cleanup "{58BAA8D0-404E-4585-9FD3-ED1BB72AC2EE}" = Adobe Flash Player 9 ActiveX "{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8 "{5DFDEAAA-E050-482E-A5B6-138CAE53F7BF}" = Radialpoint Security Services "{5E863175-E85D-44A6-8968-82507D34AE7F}" = QuickTime "{5F35CC11-438E-403B-9863-05AADC7BC713}" = MELL Microsoft® Office Standard Edition 2003 Collection "{67D7BC74-E8DF-4811-9B41-6023A8C9BB3F}" = Intel® Sebring API "{6C72E14A-C1F3-45E5-8810-83CE3C19ED63}" = IBM 32-bit Runtime Environment for Java 2, v1.4.1 "{6CE96A14-61E2-48CC-837E-22710A953ADE}" = IBM Themes "{6DC0CBB2-F919-4bdd-A608-E8FE35E03237}" = MX Skype Recorder v3.9.2 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{7D11FED9-4214-40A6-A6CA-3CFBAC20DA36}" = RPS Burn "{82512BC9-BD5D-4C50-BE4D-B98E7DF78687}" = IBM ThinkPad UltraNav Wizard "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8D815BF3-2399-459C-B121-49373FEFB9E8}" = IBM Update Connector "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{904847DA-FBC0-4726-BE73-830FCB9D4E8A}" = RPS Backup "{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD "{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = IBM RecordNow! "{99E6E9E1-BBCD-4294-93C6-08537A9E92CB}" = RPS AntiSpyware "{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}" = IBM 11b/g Wireless LAN Mini PCI Adapter and Applications "{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender "{A260B422-70E1-41E2-957D-F76FA21266D5}" = Apple Software Update "{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0 "{AC82BF06-223B-42AA-A89F-2D3BCD247366}" = RPS Privacy Manager "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B554158F-E72C-402C-98A6-9EDF215DB4DB}" = Messageware Plus Pack English Dictionary "{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{BAF99E78-879B-4811-BFEF-3CC7057BC00D}" = RPS Ad Blocker "{BD560699-45B7-4029-8417-C645E8A3D746}" = Messageware Plus Pack Thesaurus "{C365ACC1-D32A-4552-A246-38DE4EF40DC6}" = Messageware Plus Pack Base Component "{C869F4FF-E5FF-4FBB-9A31-33C23605E170}" = PPSDKRedistributables "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{D7DF917E-C963-42B4-AD48-837ACA6D8859}" = AT&T Internet Security Suite "{E5E7B0D0-20E1-4B1A-B8C9-B9E2B93DE1DE}" = RPS ParentalControl "{E85A45C2-290F-4C4A-9363-B6399EE648A9}" = RPS AntiVirus "{EA664480-3844-11D5-8C25-444553540000}" = IBM TrackPoint Accessibility Features "{EC6AF20D-4376-4070-BEE4-D3A0DFF7E140}" = Access IBM "{ED55BFEF-90F3-4926-9536-D94FDBBF65DC}" = Zune "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard "A3AB947F7D490EEA2162B4CAEA69D887C7EBFE3C" = Windows Driver Package - Microsoft WPD (8/28/2006 1.0.0.2) "ABC Amber LIT Converter" = ABC Amber LIT Converter "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Agere Systems Soft Modem" = Agere Systems AC'97 Modem "All ATI Software" = ATI - Software Uninstall Utility "AOL Instant Messenger" = AOL Instant Messenger "Ask Toolbar_is1" = Ask Toolbar "ATI Display Driver" = ATI Display Driver "Audacity_is1" = Audacity 1.2.6 "CDisplay_is1" = CDisplay 1.8 "CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014" = IBM Integrated 56K Modem "ComcastHSI" = Comcast High-Speed Internet Install Wizard "Diablo II" = Diablo II "EasyEject Utility" = IBM ThinkPad EasyEject Utility "GTK 2.0" = GTK+ Runtime 2.12.1 rev b (remove only) "HijackThis" = HijackThis 2.0.2 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "InstallShield_{6C72E14A-C1F3-45E5-8810-83CE3C19ED63}" = IBM 32-bit Runtime Environment for Java 2, v1.4.1 "IsoBuster_is1" = IsoBuster 2.4 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "Netscape 6 (6.2.3)" = Netscape 6 (6.2.3) "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "PC Satellite TV_is1" = Satellite TV for PC "Podcast Studio" = Podcast Studio "PokerStars" = PokerStars "PokerStars.net" = PokerStars.net "Power Features" = IBM ThinkPad Battery MaxiMiser and Power Management Features "Power Management Driver" = IBM ThinkPad Power Management Driver "PowerISO" = PowerISO "Presentation Director" = IBM ThinkPad Presentation Director "PROSet" = Intel® PRO Network Adapters and Drivers "RadialpointClientGateway_is1" = AT&T Internet Security Wizard 1.5.11 "RealPlayer 6.0" = RealPlayer "Shockwave" = Shockwave "ShockwaveFlash" = Adobe Flash Player 9 ActiveX "Spyware Doctor" = Spyware Doctor 6.0 "Super Video Converter_is1" = Super Video Converter 5.7.2 "SynTPDeinstKey" = IBM ThinkPad UltraNav Driver "ThinkPad Configuration" = IBM ThinkPad Configuration "ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier "ThinkPadSoftwareInstaller" = ThinkPad Software Installer "TrackPoint" = IBM TrackPoint Support "Trillian" = Trillian "Update Service" = Update Service "VLC media player" = VideoLAN VLC media player 0.8.6 "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 2 "WinRAR archiver" = WinRAR archiver "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Extras" = Yahoo! Browser Services "Yahoo! Mail" = Yahoo! Internet Mail "YInstHelper" = Yahoo! Install Manager ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 8/6/2009 1:40:05 AM | Computer Name = INFORMAT-V9QY5S | Source = Google Update | ID = 20 Description = Error - 8/7/2009 8:16:03 AM | Computer Name = INFORMAT-V9QY5S | Source = Google Update | ID = 20 Description = Error - 8/7/2009 9:03:11 AM | Computer Name = INFORMAT-V9QY5S | Source = Windows Live Messenger | ID = 1000 Description = Error - 8/9/2009 1:23:09 AM | Computer Name = INFORMAT-V9QY5S | Source = Application Error | ID = 1005 Description = Windows cannot access the file C:\WINDOWS\system32\mshtml.dll for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program Microsoft ® HTML Viewer because of this error. Program: Microsoft ® HTML Viewer File: C:\WINDOWS\system32\mshtml.dll The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: C000009C Disk type: 3 Error - 8/9/2009 1:23:47 AM | Computer Name = INFORMAT-V9QY5S | Source = Application Error | ID = 1000 Description = Faulting application ZuneSetup.exe, version 1.0.5341.0, faulting module mshtml.dll, version 8.0.6001.18783, fault address 0x003834dc. Error - 8/9/2009 10:03:05 AM | Computer Name = INFORMAT-V9QY5S | Source = Application Error | ID = 1005 Description = Windows cannot access the file C:\WINDOWS\system32\mshtml.dll for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program Microsoft ® HTML Viewer because of this error. Program: Microsoft ® HTML Viewer File: C:\WINDOWS\system32\mshtml.dll The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: C000009C Disk type: 3 Error - 8/9/2009 10:04:12 AM | Computer Name = INFORMAT-V9QY5S | Source = Application Error | ID = 1000 Description = Faulting application AcroRd32.exe, version 7.0.0.0, faulting module mshtml.dll, version 8.0.6001.18783, fault address 0x003834dc. Error - 8/9/2009 10:06:04 AM | Computer Name = INFORMAT-V9QY5S | Source = Windows Live Messenger | ID = 1000 Description = Error - 8/9/2009 6:33:36 PM | Computer Name = INFORMAT-V9QY5S | Source = Windows Live Messenger | ID = 1000 Description = Error - 8/10/2009 8:39:21 AM | Computer Name = INFORMAT-V9QY5S | Source = Windows Live Messenger | ID = 1000 Description = [ System Events ] Error - 8/10/2009 8:23:13 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151 Description = The device, \Device\Harddisk0\D, has a bad block. Error - 8/10/2009 8:24:40 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151 Description = The device, \Device\Harddisk0\D, has a bad block. Error - 8/10/2009 8:24:44 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151 Description = The device, \Device\Harddisk0\D, has a bad block. Error - 8/10/2009 8:24:49 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151 Description = The device, \Device\Harddisk0\D, has a bad block. Error - 8/10/2009 8:24:53 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151 Description = The device, \Device\Harddisk0\D, has a bad block. Error - 8/10/2009 8:38:49 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151 Description = The device, \Device\Harddisk0\D, has a bad block. Error - 8/10/2009 8:39:13 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151 Description = The device, \Device\Harddisk0\D, has a bad block. Error - 8/10/2009 3:05:45 PM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151 Description = The device, \Device\Harddisk0\D, has a bad block. Error - 8/10/2009 3:05:46 PM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151 Description = The device, \Device\Harddisk0\D, has a bad block. Error - 8/10/2009 3:05:57 PM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151 Description = The device, \Device\Harddisk0\D, has a bad block. < End of report > |
|
|
Aug 10 2009, 02:51 PM
Post
#6
|
|
![]() Trusted Helper Posts: 8,065 OS: XP Pro |
Hello The Boy Wonder,
Your Adobe Acrobat Reader is out of date. Older versions are vunerable to attack. Please go to the link below to update. http://www.adobe.com/products/acrobat/readstep2.html Now Please run OTL.exe
Next Please download ComboFix from one of these locations: NOTE: If you are guest watching this topic. ComboFix is a very powerful tool. The disclaimer clearly states that you should not use it without supervision. There is good reason for this as ComboFix can, and sometimes does, run into conflict on a computer and render it unusable. Link 1 Link 2 Link 3 * IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply. So when you return please post
|
|
|
Aug 10 2009, 05:03 PM
Post
#7
|
|
|
Member ![]() ![]() Posts: 14 OS: Windows XP |
All processes killed
========== PROCESSES ========== ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully. C:\Program Files\AskBarDis\bar\bin\askBar.dll unregistered successfully. C:\Program Files\AskBarDis\bar\bin\askBar.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}\ not found. File C:\Program Files\AskBarDis\bar\bin\askBar.dll not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: admin User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: All Users User: ddemp912 ->Temp folder emptied: 203601049 bytes ->Temporary Internet Files folder emptied: 26035522 bytes ->Java cache emptied: 18970031 bytes ->FireFox cache emptied: 62444421 bytes ->Google Chrome cache emptied: 17552682 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 8675529 bytes User: NetworkService ->Temp folder emptied: 69906 bytes ->Temporary Internet Files folder emptied: 32902 bytes %systemdrive% .tmp files removed: 0 bytes C:\windows\msdownld.tmp folder deleted successfully. %systemroot% .tmp files removed: 1119318 bytes %systemroot%\System32 .tmp files removed: 2577 bytes Windows Temp folder emptied: 1954265 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 324.69 mb OTL by OldTimer - Version 3.0.10.5 log created on 08102009_184710 Files\Folders moved on Reboot... Registry entries deleted on Reboot... Working on ComboFix now |
|
|
Aug 10 2009, 05:30 PM
Post
#8
|
|
![]() Trusted Helper Posts: 8,065 OS: XP Pro |
|
|
|
Aug 10 2009, 05:50 PM
Post
#9
|
|
|
Member ![]() ![]() Posts: 14 OS: Windows XP |
ComboFix 09-08-10.01 - ddemp912 08/10/2009 19:22.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.383.111 [GMT -4:00] Running from: c:\documents and settings\ddemp912\Desktop\ComboFixtwo.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2009-07-10 to 2009-08-10 ))))))))))))))))))))))))))))))) . 2009-08-10 22:47 . 2009-08-10 22:47 -------- d-----w- C:\_OTL 2009-08-05 19:56 . 2009-08-05 19:58 -------- d-----w- c:\windows\system32\NtmsData 2009-08-05 17:39 . 2009-08-05 17:39 -------- d-----w- c:\program files\AVG 2009-08-05 17:39 . 2009-08-05 22:25 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8 2009-08-05 15:56 . 2009-08-05 15:56 -------- d-----w- c:\program files\AskBarDis 2009-08-05 15:55 . 2009-08-06 23:40 -------- d-----w- c:\documents and settings\ddemp912\Application Data\uTorrent 2009-08-05 14:27 . 2009-08-05 14:27 -------- d--h--w- c:\windows\PIF 2009-08-05 13:57 . 2007-03-06 17:24 55296 ----a-w- c:\windows\system32\drivers\rp_skt32.sys 2009-08-05 13:56 . 2007-04-19 15:24 48384 ----a-w- c:\windows\system32\drivers\rp_pkt32.sys 2009-08-05 13:55 . 2009-08-05 13:55 -------- d-----w- c:\program files\Common Files\Authentium 2009-08-05 13:54 . 2009-08-05 13:54 -------- d-----w- c:\program files\Raxco 2009-08-05 13:54 . 2009-08-05 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco 2009-08-05 13:53 . 2009-08-05 13:53 -------- d-----w- c:\program files\CA 2009-08-05 13:53 . 2009-08-05 14:28 -------- d-----w- c:\program files\Common Files\Scanner 2009-08-05 13:48 . 2009-08-05 14:30 -------- d-----w- c:\documents and settings\ddemp912\Application Data\AT&T 2009-08-05 13:46 . 2009-08-05 13:51 -------- d-----w- c:\program files\AT&T 2009-08-05 13:41 . 2009-08-05 13:51 -------- d-----w- c:\documents and settings\All Users\Application Data\AT&T 2009-08-05 13:40 . 2009-08-05 13:40 -------- d-----w- c:\documents and settings\ddemp912\Application Data\InstallShield 2009-08-04 12:17 . 2009-08-04 12:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive 2009-07-21 12:15 . 2009-07-21 12:36 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-07-21 12:15 . 2009-07-21 12:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-07-20 19:52 . 2009-08-10 23:36 64131104 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-07-20 17:29 . 2009-07-20 17:29 -------- d-----w- c:\program files\Trend Micro 2009-07-20 15:39 . 2009-07-20 15:39 -------- d-----w- c:\documents and settings\ddemp912\Application Data\Malwarebytes 2009-07-20 15:38 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-20 15:38 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-07-20 15:38 . 2009-07-20 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-07-20 15:38 . 2009-08-10 18:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-07-14 04:30 . 2009-07-14 04:30 -------- d-----w- c:\documents and settings\ddemp912\Local Settings\Application Data\PCHealth 2009-07-12 22:52 . 2009-07-12 22:52 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-08-10 22:50 . 2009-07-20 19:52 736556 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-08-10 21:18 . 2003-07-01 21:03 -------- d-----w- c:\program files\Common Files\Adobe 2009-08-10 20:23 . 2007-02-08 00:09 -------- d-----w- c:\program files\Trillian 2009-08-09 16:57 . 2008-10-06 02:30 -------- d-----w- c:\program files\PokerStars 2009-08-07 21:20 . 2008-09-18 19:27 -------- d-----w- c:\documents and settings\ddemp912\Application Data\Skype 2009-08-07 20:08 . 2008-09-18 19:30 -------- d-----w- c:\documents and settings\ddemp912\Application Data\skypePM 2009-08-05 15:35 . 2007-02-07 20:04 -------- d-----w- c:\documents and settings\ddemp912\Application Data\AdobeUM 2009-08-05 13:42 . 2003-06-22 15:44 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-07-20 19:47 . 2008-10-13 23:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-07-20 19:32 . 2008-10-14 01:30 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-07-20 19:31 . 2007-02-23 21:58 -------- d-----w- c:\program files\Java 2009-07-07 19:24 . 2008-08-11 03:55 -------- d-----w- c:\program files\Microsoft Silverlight 2009-07-07 18:57 . 2009-07-07 18:57 -------- d-----w- c:\program files\Windows Defender 2009-07-07 18:57 . 2009-07-07 18:49 -------- d-----w- c:\program files\Microsoft AntiSpyware 2009-07-07 17:28 . 2009-07-06 20:49 -------- d-----w- c:\program files\Google 2009-07-06 21:45 . 2008-09-22 08:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-07-06 20:54 . 2009-07-06 20:50 -------- d-----w- c:\program files\Spyware Doctor 2009-07-06 20:53 . 2009-07-06 20:50 -------- d-----w- c:\program files\Common Files\PC Tools 2009-07-06 20:50 . 2009-07-06 20:50 -------- d-----w- c:\documents and settings\ddemp912\Application Data\PC Tools 2009-07-06 20:50 . 2008-10-20 21:18 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools 2009-06-16 14:55 . 2002-08-29 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll 2009-06-16 14:55 . 2002-08-29 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll 2009-06-03 19:27 . 2005-08-30 14:14 1290752 ----a-w- c:\windows\system32\quartz.dll 2009-05-13 05:15 . 2006-06-23 16:33 915456 ----a-w- c:\windows\system32\wininet.dll 2008-09-27 04:22 . 2008-09-27 04:22 486128 ----a-w- c:\program files\ChromeSetup.exe 2008-08-12 07:52 . 2008-08-12 07:52 1827523 ----a-w- c:\program files\keyman_423_setup.exe 2008-04-24 17:31 . 2008-04-24 17:29 37986872 ----a-w- c:\program files\Update_Service_Setup-2.7.12.4.exe 2007-07-05 19:12 . 2007-07-05 19:12 5568552 ----a-w- c:\program files\ZuneSetup.exe 2007-04-25 22:34 . 2007-04-25 22:34 21822168 -c--a-w- c:\program files\AdbeRdr80_en_US.exe 2007-02-14 18:06 . 2007-02-14 18:06 5971432 ----a-w- c:\program files\Firefox Setup 2.0.0.1.exe 2007-02-08 00:09 . 2007-02-08 00:09 9000041 ----a-w- c:\program files\trillian-v3[1].1.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\documents and settings\ddemp912\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-27 133104] "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2003-12-25 208896] "TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2004-03-10 94208] "TPKMAPMN"="c:\program files\ThinkPad\Utilities\TpKmapMn.exe" [2003-10-23 32768] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-04-08 110592] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-04-08 512000] "McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UdaterUI.exe" [2006-11-17 136768] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-14 335872] "IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-05-26 155648] "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-05-26 118784] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-10-22 114741] "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592] "UC_Start"="c:\program files\IBM\Updater\\ucstartup.exe" [2003-09-30 36864] "BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2003-12-25 106496] "BMMLREF"="c:\program files\ThinkPad\Utilities\BMMLREF.EXE" [2003-12-25 20480] "BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2003-12-25 394752] "TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2003-10-24 897024] "PRONoMgrWired"="c:\program files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe" [2003-08-06 86016] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952] "IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2002-08-29 44032] "MSPY2002"="c:\windows\System32\IME\PINTLGNT\ImScInst.exe" [2002-08-29 59392] "PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-29 455168] "PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-29 455168] "QCWLIcon"="c:\progra~1\ThinkPad\CONNEC~1\QCWLIcon.exe" [2004-05-19 53248] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2006-10-31 20752] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-12 185896] "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-07-07 167936] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-20 148888] "ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816] "AT&T Internet Security Suite"="c:\program files\AT&T\AT&T Internet Security Suite\Rps.exe" [2007-06-28 310000] "-FreedomNeedsReboot"="c:\program files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 13552] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2002-09-04 53248] "ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-04 28672] "TrackPointSrv"="tp4serv.exe" - c:\windows\system32\tp4serv.exe [2003-11-13 94208] "AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-06-27 88363] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-5-26 24576] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "LogonType"= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoSMConfigurePrograms"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina] 2004-05-19 07:21 94208 ----a-w- c:\windows\system32\QConGina.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk * [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Trillian\\trillian.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/6/2009 4:51 PM 130936] R1 is-RV7HUdrv;is-RV7HUdrv;c:\windows\system32\drivers\65644179.sys [11/25/2008 8:22 PM 148496] R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [6/22/2003 11:45 AM 15360] S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?] S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?] S3 AM5211;11b/g Wireless LAN Mini PCI Adapter Service;c:\windows\system32\drivers\am5211.sys [6/30/2004 9:51 AM 330368] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [4/24/2008 1:40 PM 13352] S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.sys [6/1/2004 3:52 PM 12288] S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?] S3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [6/30/2004 9:48 AM 13904] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-08-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032Core.job - c:\documents and settings\ddemp912\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-27 04:22] 2009-08-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032UA.job - c:\documents and settings\ddemp912\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-27 04:22] 2009-08-10 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20] . - - - - ORPHANS REMOVED - - - - BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file) . ------- Supplementary Scan ------- . uStart Page = hxxp://cpprod.stjohns.edu/cp/home/loginf uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100 uInternet Settings,ProxyOverride = actsvr.comcastonline.com IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\ddemp912\Application Data\Mozilla\Firefox\Profiles\8sb8ahvo.default\ FF - plugin: c:\documents and settings\ddemp912\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-08-10 19:36 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1344) c:\windows\system32\QConGina.dll c:\progra~1\ThinkPad\CONNEC~1\Res\US\QGinaRes.dll . Completion time: 2009-08-10 19:44 ComboFix-quarantined-files.txt 2009-08-10 23:43 ComboFix2.txt 2009-07-20 17:22 Pre-Run: 8,370,053,120 bytes free Post-Run: 8,382,353,408 bytes free 207 --- E O F --- 2009-08-10 23:11 |
|
|
Aug 10 2009, 06:35 PM
Post
#10
|
|
![]() Trusted Helper Posts: 8,065 OS: XP Pro |
Well nothing showing there.
One thought did occurr to me. I wonder if Windows Defender is interrupting you anti-virus scan. I think it should have been turned off by At&t internet security anti virus but you never know. You could try check to see if it is turned off to see. How to turn Windows Defender on or off 1. Open Windows Defender by clicking the Start button , clicking All Programs, and then clicking Windows Defender. 2. Click Tools, and then click Options. 3. Under Administrator options, select or clear the Use Windows Defender check box, and then click Save. Administrator permission required. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. If those instructions are not appropriate for your version of Windows go to this link for instructions on how to enable/disable Windows Defender http://windowshelp.microsoft.com/Windows/e...1bf0dc1033.mspx Now One last check to make sure we haven't missed anything. Panda only works if you are using Internet Explorer. Please go HERE to run Panda's ActiveScan " Once you are on the Panda site click the Scan your PC button " A new window will open...click the Check Now button " Enter your Country " Enter your State/Province " Enter your e-mail address and click send " Select either Home User or Company " Click the big Scan Now button " If it wants to install an ActiveX component allow it " It will start downloading the files it requires for the scan (Note: It may take a couple of minutes) " When download is complete, click on My Computer to start the scan " When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report |
|
|
Aug 10 2009, 06:48 PM
Post
#11
|
|
|
Member ![]() ![]() Posts: 14 OS: Windows XP |
Internet Explorer still isn't responsive. Right after I opened it, it froze then the error message came up and it closed automatically. I have been using Firefox this whole time.
|
|
|
Aug 10 2009, 07:43 PM
Post
#12
|
|
![]() Trusted Helper Posts: 8,065 OS: XP Pro |
Okay it's a while since I checked PandaScan.
I have just been to the site and in the Help section they now say that you can use Firefox. Sooo go ahead and try it with Firefox. Should work. |
|
|
Aug 11 2009, 01:01 AM
Post
#13
|
|
|
Member ![]() ![]() Posts: 14 OS: Windows XP |
;***********************************************************************************************************************
************************************************************ ANALYSIS: 2009-08-11 02:56:13 PROTECTIONS: 1 MALWARE: 4 SUSPECTS: 3 ;*********************************************************************************************************************** ************************************************************ PROTECTIONS Description Version Active Updated ;======================================================================================================================= ============================================================ Windows Defender 1.1.4903.0 No No ;======================================================================================================================= ============================================================ MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;======================================================================================================================= ============================================================ 00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\Documents and Settings\ddemp912\Application Data\Mozilla\Profiles\default\p4bl1x2w.slt\cookies.txt[.bfast.com/] 00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Profiles\default\p4bl1x2w.slt\cookies.txt[.bfast.com/] 00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\Documents and Settings\Default User\Application Data\Mozilla\Profiles\default\p4bl1x2w.slt\cookies.txt[.bfast.com/] 00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\p4bl1x2w.slt\cookies.txt[.bfast.com/] 00207338 Cookie/Target TrackingCookie No 0 Yes No C:\Documents and Settings\ddemp912\Cookies\ddemp912@target[1].txt 00950035 Cookie/RegistryDefender TrackingCookie No 0 Yes No C:\Documents and Settings\ddemp912\Cookies\ddemp912@registrydefender[2].txt 03867692 Trj/Lineage.BZE Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{BF4D3E3A-A9CB-4D7C-BC12-7E6C6028C599}\RP20\A0019320.exe ;======================================================================================================================= ============================================================ SUSPECTS Sent Location ;======================================================================================================================= ============================================================ No C:\Program Files\ABC Amber LIT Converter\abclit.exe No C:\Program Files\InstallShield Installation Information\{D7DF917E-C963-42B4-AD48-837ACA6D8859}\RPS RpsCore.msi[unk_0078][zku_rsrc.dll] No C:\System Volume Information\_restore{BF4D3E3A-A9CB-4D7C-BC12-7E6C6028C599}\RP19\A0015154.rbf ;======================================================================================================================= ============================================================ VULNERABILITIES Id Severity Description ;======================================================================================================================= ============================================================ 120815 HIGH MS06-022 ;======================================================================================================================= ============================================================ |
|
|
Aug 11 2009, 01:03 AM
Post
#14
|
|
|
Member ![]() ![]() Posts: 14 OS: Windows XP |
repost* sorry
This post has been edited by The Boy Wonder: Aug 11 2009, 01:12 AM |
|
|
Aug 11 2009, 01:07 AM
Post
#15
|
|
|
Member ![]() ![]() Posts: 14 OS: Windows XP |
repost* sorry
This post has been edited by The Boy Wonder: Aug 11 2009, 01:13 AM |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
0 / 1,041 | 25th August 2007 - 06:29 PM redr00ster18 started - last by redr00ster18 |
|||||
![]() |
0 / 162 | 24th June 2009 - 04:37 PM tizzyloucat started - last by tizzyloucat |
|||||
![]() |
3 / 272 | 8th August 2009 - 05:50 PM nanacama started - last by rev_olie |
|||||
![]() |
0 / 202 | 5th September 2009 - 06:56 AM imon started - last by imon |
|||||
|
Time is now: 21st November 2009 - 03:53 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising