Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
2 Pages V   1 2 >  
Closed TopicStart new topic
Internet explorer, Msn messenger, adobe reader error message and shutd, I am getting error message from multiple programs and they shut down
The Boy Wonder
post Aug 5 2009, 04:47 PM
Post #1


Member
**
Posts: 14
OS: Windows XP



Even my At&t internet security anti virus scanner can't complete scan before getting an error message and shutting down. Please help anyway possible thank you.
Go to the top of the page
 
+Quote Post
emeraldnzl
post Aug 9 2009, 05:15 PM
Post #2


Trusted Helper
Group Icon
Posts: 8,065
OS: XP Pro



Hello The Boy Wonder,

See if you can run this:

Please download and save SysProt AntiRootkit to your Desktop.

  • double click the Zip file.
  • You should now have a folder with SysProt and some other files within it on your Desktop.
  • Double-click SysProt and you should see another small window with SysProt underneath it.
  • Double-click this and Wizard will appear to guide you through extracting the files.
  • Double-click the Sysprot folder
  • SysProt will appear with a red cross on black - double-click
  • a panel will appear with a number of tabs along the top
  • click on the Log tab and check all boxes except the one Hidden objects only
  • click the Creat Log button
  • it will scan...once finished a panel will appear
  • click on Scan all drives
  • A log will be created and saved automatically in the same folder.
  • Open the text file copy and paste the contents back here in the forum. Close any left open panels.
Go to the top of the page
 
+Quote Post
The Boy Wonder
post Aug 10 2009, 07:00 AM
Post #3


Member
**
Posts: 14
OS: Windows XP



SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No

Name: System
PID: 4
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\smss.exe
PID: 1272
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\csrss.exe
PID: 1328
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\winlogon.exe
PID: 1352
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\services.exe
PID: 1400
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\lsass.exe
PID: 1412
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\ibmpmsvc.exe
PID: 1580
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\ati2evxx.exe
PID: 1620
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1632
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1720
Hidden: No
Window Visible: No

Name: C:\Program Files\Windows Defender\MsMpEng.exe
PID: 1760
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1800
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1892
Hidden: No
Window Visible: No

Name: C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe
PID: 1940
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\S24EvMon.exe
PID: 1996
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 220
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 312
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\spoolsv.exe
PID: 756
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 832
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
PID: 892
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 956
Hidden: No
Window Visible: No

Name: C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
PID: 980
Hidden: No
Window Visible: No

Name: C:\Program Files\Java\jre6\bin\jqs.exe
PID: 1020
Hidden: No
Window Visible: No

Name: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
PID: 1048
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE
PID: 1084
Hidden: No
Window Visible: No

Name: C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
PID: 1112
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\QCONSVC.EXE
PID: 1168
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\RegSrvc.exe
PID: 1200
Hidden: No
Window Visible: No

Name: C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
PID: 1236
Hidden: No
Window Visible: No

Name: C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe
PID: 1264
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\TpKmpSvc.exe
PID: 1324
Hidden: No
Window Visible: No

Name: C:\Program Files\Zune\ZuneNss.exe
PID: 212
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\alg.exe
PID: 2300
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\wscntfy.exe
PID: 3408
Hidden: No
Window Visible: No

Name: C:\WINDOWS\explorer.exe
PID: 3572
Hidden: No
Window Visible: No

Name: C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
PID: 640
Hidden: No
Window Visible: No

Name: C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
PID: 652
Hidden: No
Window Visible: No

Name: C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
PID: 1404
Hidden: No
Window Visible: No

Name: C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
PID: 864
Hidden: No
Window Visible: No

Name: C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
PID: 2212
Hidden: No
Window Visible: No

Name: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PID: 2236
Hidden: No
Window Visible: No

Name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PID: 2260
Hidden: No
Window Visible: No

Name: C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
PID: 2276
Hidden: No
Window Visible: No

Name: C:\Program Files\Network Associates\Common Framework\Mctray.exe
PID: 2364
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\dla\tfswctrl.exe
PID: 192
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\rundll32.exe
PID: 2628
Hidden: No
Window Visible: No

Name: C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
PID: 2804
Hidden: No
Window Visible: No

Name: C:\WINDOWS\AGRSMMSG.exe
PID: 2928
Hidden: No
Window Visible: No

Name: C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLICON.EXE
PID: 3052
Hidden: No
Window Visible: No

Name: C:\Program Files\Zune\ZuneLauncher.exe
PID: 3072
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PID: 3088
Hidden: No
Window Visible: No

Name: C:\Program Files\PowerISO\PWRISOVM.EXE
PID: 3400
Hidden: No
Window Visible: No

Name: C:\Program Files\Windows Defender\MSASCui.exe
PID: 3420
Hidden: No
Window Visible: No

Name: C:\Program Files\Java\jre6\bin\jusched.exe
PID: 3448
Hidden: No
Window Visible: No

Name: C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
PID: 3512
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\ctfmon.exe
PID: 2508
Hidden: No
Window Visible: No

Name: C:\Documents and Settings\ddemp912\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
PID: 392
Hidden: No
Window Visible: No

Name: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PID: 400
Hidden: No
Window Visible: No

Name: C:\Program Files\Digital Line Detect\DLG.exe
PID: 1768
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\wuauclt.exe
PID: 3296
Hidden: No
Window Visible: No

Name: C:\Program Files\Mozilla Firefox\firefox.exe
PID: 2896
Hidden: No
Window Visible: No

Name: C:\Program Files\MSN Messenger\usnsvc.exe
PID: 3004
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\taskmgr.exe
PID: 3148
Hidden: No
Window Visible: Yes

Name: C:\Documents and Settings\ddemp912\Desktop\SysProt\SysProt\SysProt.exe
PID: 1872
Hidden: No
Window Visible: Yes

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \??\C:\Documents and Settings\ddemp912\Desktop\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: F5BFA000
Module End: F5C05000
Hidden: No

Module Name: \windows\system32\ntoskrnl.exe
Service Name: ---
Module Base: 804D7000
Module End: 806EB580
Hidden: No

Module Name: \windows\system32\hal.dll
Service Name: ---
Module Base: 806EC000
Module End: 806FFD80
Hidden: No

Module Name: \windows\system32\KDCOM.DLL
Service Name: ---
Module Base: F7CCC000
Module End: F7CCE000
Hidden: No

Module Name: \windows\system32\BOOTVID.dll
Service Name: ---
Module Base: F7BDC000
Module End: F7BDF000
Hidden: No

Module Name: C:\windows\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: F777D000
Module End: F77AB000
Hidden: No

Module Name: \windows\System32\DRIVERS\WMILIB.SYS
Service Name: ---
Module Base: F7CCE000
Module End: F7CD0000
Hidden: No

Module Name: C:\windows\system32\drivers\pci.sys
Service Name: PCI
Module Base: F776C000
Module End: F777D000
Hidden: No

Module Name: C:\windows\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: F77CC000
Module End: F77D5000
Hidden: No

Module Name: C:\windows\system32\drivers\ohci1394.sys
Service Name: ohci1394
Module Base: F77DC000
Module End: F77EB000
Hidden: No

Module Name: \windows\System32\DRIVERS\1394BUS.SYS
Service Name: ---
Module Base: F77EC000
Module End: F77F9000
Hidden: No

Module Name: C:\windows\system32\drivers\compbatt.sys
Service Name: Compbatt
Module Base: F7BE0000
Module End: F7BE3000
Hidden: No

Module Name: \windows\System32\DRIVERS\BATTC.SYS
Service Name: BattC
Module Base: F7BE4000
Module End: F7BE8000
Hidden: No

Module Name: C:\windows\system32\drivers\PCIIde.sys
Service Name: PCIIde
Module Base: F7D94000
Module End: F7D95000
Hidden: No

Module Name: \windows\System32\Drivers\PCIIDEX.SYS
Service Name: ---
Module Base: F7A4C000
Module End: F7A53000
Hidden: No

Module Name: C:\windows\system32\drivers\intelide.sys
Service Name: IntelIde
Module Base: F7CD0000
Module End: F7CD2000
Hidden: No

Module Name: C:\windows\system32\drivers\pcmcia.sys
Service Name: Pcmcia
Module Base: F774E000
Module End: F776C000
Hidden: No

Module Name: C:\windows\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: F77FC000
Module End: F7807000
Hidden: No

Module Name: C:\windows\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: F772F000
Module End: F774E000
Hidden: No

Module Name: C:\windows\system32\drivers\ACPIEC.sys
Service Name: ACPIEC
Module Base: F7BE8000
Module End: F7BEB000
Hidden: No

Module Name: \windows\System32\DRIVERS\OPRGHDLR.SYS
Service Name: ---
Module Base: F7D95000
Module End: F7D96000
Hidden: No

Module Name: C:\windows\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: F7A54000
Module End: F7A59000
Hidden: No

Module Name: C:\windows\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: F780C000
Module End: F7819000
Hidden: No

Module Name: C:\windows\system32\drivers\atapi.sys
Service Name: atapi
Module Base: F7717000
Module End: F772F000
Hidden: No

Module Name: C:\windows\system32\drivers\disk.sys
Service Name: ---
Module Base: F781C000
Module End: F7825000
Hidden: No

Module Name: \windows\System32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: F782C000
Module End: F7839000
Hidden: No

Module Name: C:\windows\system32\drivers\fltmgr.sys
Service Name: FltMgr
Module Base: F76F7000
Module End: F7717000
Hidden: No

Module Name: C:\windows\system32\drivers\sr.sys
Service Name: sr
Module Base: F76E5000
Module End: F76F7000
Hidden: No

Module Name: C:\windows\system32\drivers\PCTCore.sys
Service Name: PCTCore
Module Base: F76C2000
Module End: F76E5000
Hidden: No

Module Name: C:\windows\system32\drivers\PxHelp20.sys
Service Name: PxHelp20
Module Base: F783C000
Module End: F7845000
Hidden: No

Module Name: C:\windows\system32\drivers\drvmcdb.sys
Service Name: drvmcdb
Module Base: F76AD000
Module End: F76C2000
Hidden: No

Module Name: C:\windows\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: F7696000
Module End: F76AD000
Hidden: No

Module Name: C:\windows\system32\drivers\WudfPf.sys
Service Name: WudfPf
Module Base: F7683000
Module End: F7696000
Hidden: No

Module Name: C:\windows\system32\drivers\DefragFS.sys
Service Name: DefragFS
Module Base: F7670000
Module End: F7683000
Hidden: No

Module Name: C:\windows\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: F75E3000
Module End: F7670000
Hidden: No

Module Name: C:\windows\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: F75B6000
Module End: F75E3000
Hidden: No

Module Name: C:\windows\system32\drivers\Mup.sys
Service Name: Mup
Module Base: F759B000
Module End: F75B6000
Hidden: No

Module Name: C:\windows\system32\drivers\agp440.sys
Service Name: agp440
Module Base: F784C000
Module End: F7857000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: F6D52000
Module End: F6D5B000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\ati2mtag.sys
Service Name: ati2mtag
Module Base: F6AE7000
Module End: F6BA7000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: F6AD3000
Module End: F6AE7000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: F7AFC000
Module End: F7B01000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: F6AB0000
Module End: F6AD3000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: F7B04000
Module End: F7B0B000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\w70n51.sys
Service Name: w70n51
Module Base: F6851000
Module End: F6AB0000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\nic1394.sys
Service Name: NIC1394
Module Base: F6D32000
Module End: F6D42000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\e100b325.sys
Service Name: E100B
Module Base: F682D000
Module End: F6851000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\i8042prt.sys
Service Name: i8042prt
Module Base: F6D22000
Module End: F6D2F000
Hidden: No

Module Name: C:\windows\System32\Drivers\TfKbMon.sys
Service Name: TfKbMon
Module Base: F7B0C000
Module End: F7B14000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: F7B14000
Module End: F7B1A000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\SynTP.sys
Service Name: SynTP
Module Base: F67EB000
Module End: F682D000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: F7CF8000
Module End: F7CFA000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: F7B1C000
Module End: F7B22000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\fdc.sys
Service Name: Fdc
Module Base: F7B24000
Module End: F7B2B000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\serial.sys
Service Name: Serial
Module Base: F6D12000
Module End: F6D22000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\serenum.sys
Service Name: serenum
Module Base: F7CC0000
Module End: F7CC4000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\parport.sys
Service Name: Parport
Module Base: F67D7000
Module End: F67EB000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\nscirda.sys
Service Name: irda
Module Base: F7B2C000
Module End: F7B33000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\irenum.sys
Service Name: IRENUM
Module Base: F7CC4000
Module End: F7CC7000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\CmBatt.sys
Service Name: CmBatt
Module Base: F7566000
Module End: F756A000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\ibmpmdrv.sys
Service Name: IBMPMDRV
Module Base: F7B34000
Module End: F7B3B000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: F6D02000
Module End: F6D0D000
Hidden: No

Module Name: C:\windows\system32\drivers\sscdbhk5.sys
Service Name: sscdbhk5
Module Base: F7CFA000
Module End: F7CFC000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: F788C000
Module End: F7899000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: F789C000
Module End: F78AB000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\ks.sys
Service Name: ---
Module Base: F67B4000
Module End: F67D7000
Hidden: No

Module Name: C:\windows\system32\drivers\smwdm.sys
Service Name: smwdm
Module Base: F6726000
Module End: F67B4000
Hidden: No

Module Name: C:\windows\system32\drivers\portcls.sys
Service Name: ---
Module Base: F6702000
Module End: F6726000
Hidden: No

Module Name: C:\windows\system32\drivers\drmk.sys
Service Name: ---
Module Base: F78AC000
Module End: F78BB000
Hidden: No

Module Name: C:\windows\system32\drivers\aeaudio.sys
Service Name: aeaudio
Module Base: F66EA000
Module End: F6702000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\AGRSM.sys
Service Name: AgereSoftModem
Module Base: F65C5000
Module End: F66EA000
Hidden: No

Module Name: C:\windows\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: F7B3C000
Module End: F7B44000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: F7F1E000
Module End: F7F1F000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\rasirda.sys
Service Name: Rasirda
Module Base: F7B44000
Module End: F7B49000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: F7B4C000
Module End: F7B51000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: F78BC000
Module End: F78C9000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: F7552000
Module End: F7555000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: F65AE000
Module End: F65C5000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: F78CC000
Module End: F78D7000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: F78DC000
Module End: F78E8000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\psched.sys
Service Name: PSched
Module Base: F659D000
Module End: F65AE000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: F78EC000
Module End: F78F5000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: F7B54000
Module End: F7B59000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: F7B5C000
Module End: F7B61000
Hidden: No

Module Name: C:\windows\system32\DRIVERS\rp_skt32.sys
Service Name: RPSKT
Module Base: F78FC000
Module End: F7908000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\rdpdr.sys
Service Name: rdpdr
Module Base: F589D000
Module End: F58CE000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: F791C000
Module End: F7926000
Hidden: No

Module Name: C:\windows\system32\DRIVERS\rp_pkt32.sys
Service Name: RPPKT
Module Base: F792C000
Module End: F793A000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: F7D00000
Module End: F7D02000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\update.sys
Service Name: Update
Module Base: F5844000
Module End: F589D000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: F6BBF000
Module End: F6BC3000
Hidden: No

Module Name: C:\windows\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: F794C000
Module End: F7956000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: F797C000
Module End: F798B000
Hidden: No

Module Name: C:\windows\system32\DRIVERS\65644179.sys
Service Name: is-RV7HUdrv
Module Base: EB6CC000
Module End: EB6F4000
Hidden: No

Module Name: C:\windows\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: F7D0A000
Module End: F7D0C000
Hidden: No

Module Name: C:\windows\System32\Drivers\Null.SYS
Service Name: Null
Module Base: F7EE2000
Module End: F7EE3000
Hidden: No

Module Name: C:\windows\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: F7D0C000
Module End: F7D0E000
Hidden: No

Module Name: C:\windows\system32\drivers\ssrtln.sys
Service Name: ssrtln
Module Base: F7B8C000
Module End: F7B92000
Hidden: No

Module Name: C:\windows\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: F7B94000
Module End: F7B9A000
Hidden: No

Module Name: C:\windows\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: F7D0E000
Module End: F7D10000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: F7D10000
Module End: F7D12000
Hidden: No

Module Name: C:\windows\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: F7B9C000
Module End: F7BA1000
Hidden: No

Module Name: C:\windows\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: F7BA4000
Module End: F7BAC000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: F7C94000
Module End: F7C97000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: EB699000
Module End: EB6AC000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: EB641000
Module End: EB699000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: EB619000
Module End: EB641000
Hidden: No

Module Name: C:\windows\System32\drivers\afd.sys
Service Name: AFD
Module Base: EB5F7000
Module End: EB619000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: F799C000
Module End: F79A5000
Hidden: No

Module Name: C:\windows\System32\Drivers\StarOpen.SYS
Service Name: StarOpen
Module Base: F7BAC000
Module End: F7BB2000
Hidden: No

Module Name: C:\windows\System32\drivers\TSMAPIP.SYS
Service Name: TSMAPIP
Module Base: F7BB4000
Module End: F7BBA000
Hidden: No

Module Name: C:\windows\System32\drivers\Tppwr.sys
Service Name: TPPWR
Module Base: F7BBC000
Module End: F7BC4000
Hidden: No

Module Name: C:\windows\System32\Drivers\TPHKDRV.SYS
Service Name: TPHKDRV
Module Base: F7C98000
Module End: F7C9C000
Hidden: No

Module Name: C:\windows\System32\drivers\TDSMAPI.SYS
Service Name: TDSMAPI
Module Base: F7BC4000
Module End: F7BCA000
Hidden: No

Module Name: C:\windows\System32\drivers\Smapint.sys
Service Name: Smapint
Module Base: F7BCC000
Module End: F7BD4000
Hidden: No

Module Name: C:\windows\System32\Drivers\SCDEmu.SYS
Service Name: SCDEmu
Module Base: F79BC000
Module End: F79C9000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: EB584000
Module End: EB5AF000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: EB515000
Module End: EB584000
Hidden: No

Module Name: C:\windows\System32\drivers\IBMBLDID.SYS
Service Name: IBMTPCHK
Module Base: F7EF6000
Module End: F7EF7000
Hidden: No

Module Name: C:\windows\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: F79CC000
Module End: F79D5000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: EB4D4000
Module End: EB4F5000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: F79DC000
Module End: F79E5000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\arp1394.sys
Service Name: Arp1394
Module Base: F79EC000
Module End: F79FB000
Hidden: No

Module Name: C:\windows\System32\drivers\ANC.SYS
Service Name: ANC
Module Base: F582C000
Module End: F582F000
Hidden: No

Module Name: C:\windows\System32\Drivers\Cdfs.SYS
Service Name: Cdfs
Module Base: F787C000
Module End: F788C000
Hidden: No

Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: EB494000
Module End: EB4AC000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F7D22000
Module End: F7D24000
Hidden: Yes

Module Name: C:\windows\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: F7C74000
Module End: F7C77000
Hidden: No

Module Name: C:\windows\System32\watchdog.sys
Service Name: ---
Module Base: F7A84000
Module End: F7A89000
Hidden: No

Module Name: C:\windows\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: F7E5C000
Module End: F7E5D000
Hidden: No

Module Name: C:\windows\system32\drivers\drvnddm.sys
Service Name: drvnddm
Module Base: F7A1C000
Module End: F7A26000
Hidden: No

Module Name: C:\windows\system32\dla\tfsndres.sys
Service Name: tfsndres
Module Base: F7F0A000
Module End: F7F0B000
Hidden: No

Module Name: C:\windows\system32\dla\tfsnifs.sys
Service Name: tfsnifs
Module Base: EB33F000
Module End: EB354000
Hidden: No

Module Name: C:\windows\system32\dla\tfsnopio.sys
Service Name: tfsnopio
Module Base: F7C60000
Module End: F7C64000
Hidden: No

Module Name: C:\windows\system32\dla\tfsnpool.sys
Service Name: tfsnpool
Module Base: F7D4C000
Module End: F7D4E000
Hidden: No

Module Name: C:\windows\system32\dla\tfsnboio.sys
Service Name: tfsnboio
Module Base: F7AD4000
Module End: F7ADB000
Hidden: No

Module Name: C:\windows\system32\dla\tfsncofs.sys
Service Name: tfsncofs
Module Base: EB45C000
Module End: EB465000
Hidden: No

Module Name: C:\windows\system32\dla\tfsndrct.sys
Service Name: tfsndrct
Module Base: F7E05000
Module End: F7E06000
Hidden: No

Module Name: C:\windows\system32\dla\tfsnudf.sys
Service Name: tfsnudf
Module Base: EB327000
Module End: EB33F000
Hidden: No

Module Name: C:\windows\system32\dla\tfsnudfa.sys
Service Name: tfsnudfa
Module Base: EB30E000
Module End: EB327000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\AegisP.sys
Service Name: AegisP
Module Base: EB232000
Module End: EB236000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\irda.sys
Service Name: ---
Module Base: EB118000
Module End: EB12E000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\s24trans.sys
Service Name: s24trans
Module Base: EB1DE000
Module End: EB1E1000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: EB1DA000
Module End: EB1DE000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\mrxdav.sys
Service Name: MRxDAV
Module Base: F6521000
Module End: F654D000
Hidden: No

Module Name: C:\windows\System32\Drivers\ParVdm.SYS
Service Name: ParVdm
Module Base: F7D5A000
Module End: F7D5C000
Hidden: No

Module Name: C:\windows\system32\DRIVERS\css-dvp.sys
Service Name: CSS DVP
Module Base: F642D000
Module End: F64F9000
Hidden: No

Module Name: C:\windows\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: F640A000
Module End: F642D000
Hidden: No

Module Name: \??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS
Service Name: EGATHDRV
Module Base: F7D5E000
Module End: F7D60000
Hidden: No

Module Name: C:\windows\System32\Drivers\HTTP.sys
Service Name: HTTP
Module Base: F63A1000
Module End: F63E2000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\srv.sys
Service Name: Srv
Module Base: F625F000
Module End: F62B1000
Hidden: No

Module Name: C:\windows\System32\DRIVERS\mdmxsdk.sys
Service Name: mdmxsdk
Module Base: F6402000
Module End: F6405000
Hidden: No

Module Name: \??\C:\WINDOWS\system32\drivers\PMEMNT.SYS
Service Name: PMEM
Module Base: F7D66000
Module End: F7D68000
Hidden: No

Module Name: C:\windows\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: F5C0A000
Module End: F5C1F000
Hidden: No

Module Name: C:\windows\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: F5E3F000
Module End: F5E4E000
Hidden: No

Module Name: C:\windows\system32\drivers\kmixer.sys
Service Name: kmixer
Module Base: F72BF000
Module End: F72EA000
Hidden: No

******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwCreateKey
Address: F76DA514
Driver Base: F76C2000
Driver End: F76E5000
Driver Name: PCTCore.sys

Function Name: ZwCreateProcess
Address: F76C9282
Driver Base: F76C2000
Driver End: F76E5000
Driver Name: PCTCore.sys

Function Name: ZwCreateProcessEx
Address: F76C9474
Driver Base: F76C2000
Driver End: F76E5000
Driver Name: PCTCore.sys

Function Name: ZwDeleteKey
Address: F76DAD00
Driver Base: F76C2000
Driver End: F76E5000
Driver Name: PCTCore.sys

Function Name: ZwDeleteValueKey
Address: F76DAFB8
Driver Base: F76C2000
Driver End: F76E5000
Driver Name: PCTCore.sys

Function Name: ZwOpenKey
Address: F76D93FA
Driver Base: F76C2000
Driver End: F76E5000
Driver Name: PCTCore.sys

Function Name: ZwRenameKey
Address: F76DB422
Driver Base: F76C2000
Driver End: F76E5000
Driver Name: PCTCore.sys

Function Name: ZwSetValueKey
Address: F76DA7D8
Driver Base: F76C2000
Driver End: F76E5000
Driver Name: PCTCore.sys

Function Name: ZwTerminateProcess
Address: F76C8F32
Driver Base: F76C2000
Driver End: F76E5000
Driver Name: PCTCore.sys

******************************************************************************************
******************************************************************************************
Kernel Hooks:
Hooked Function: ZwWriteFile
At Address: 805771C5
Jump To: 83282EEC
Module Name: _unknown_

Hooked Function: ZwSetSystemInformation
At Address: 805A26F4
Jump To: 8333A6A4
Module Name: _unknown_

Hooked Function: ZwSetInformationFile
At Address: 80576F1C
Jump To: 8333CADC
Module Name: _unknown_

Hooked Function: ZwDuplicateObject
At Address: 80572BA6
Jump To: 83234EEC
Module Name: _unknown_

Hooked Function: ZwCreateSection
At Address: 8056469B
Jump To: 832C3EEC
Module Name: _unknown_

Hooked Function: KdEnteredDebugger
At Address: 80552C70
Jump To: 80D5992F
Module Name: _unknown_

Hooked Function: KdDebuggerNotPresent
At Address: 80552C70
Jump To: 80D5992F
Module Name: _unknown_

Hooked Function: KdDebuggerEnabled
At Address: 80552C70
Jump To: 80D5992F
Module Name: _unknown_

******************************************************************************************
******************************************************************************************
No IRP Hooks found

******************************************************************************************
******************************************************************************************
Ports:
Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:1321
Remote Address: 149.68.62.4:HTTP
Type: TCP
Process: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
State: SYN_SENT

Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: INFORMAT-V9QY5S:5152
Remote Address: LOCALHOST:1098
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: CLOSE_WAIT

Local Address: INFORMAT-V9QY5S:5152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: LISTENING

Local Address: INFORMAT-V9QY5S:1088
Remote Address: LOCALHOST:1087
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: INFORMAT-V9QY5S:1087
Remote Address: LOCALHOST:1088
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: INFORMAT-V9QY5S:1083
Remote Address: LOCALHOST:1082
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: INFORMAT-V9QY5S:1082
Remote Address: LOCALHOST:1083
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: INFORMAT-V9QY5S:1028
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\alg.exe
State: LISTENING

Local Address: INFORMAT-V9QY5S:10244
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Zune\ZuneNss.exe
State: LISTENING

Local Address: INFORMAT-V9QY5S:8081
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
State: LISTENING

Local Address: INFORMAT-V9QY5S:2869
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING

Local Address: INFORMAT-V9QY5S:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: INFORMAT-V9QY5S:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING

Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:138
Remote Address: NA
Type: UDP
Process: System
State: NA

Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA

Local Address: INFORMAT-V9QY5S.GATEWAY.2WIRE.NET:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: INFORMAT-V9QY5S:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: INFORMAT-V9QY5S:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: INFORMAT-V9QY5S:8082
Remote Address: NA
Type: UDP
Process: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
State: NA

Local Address: INFORMAT-V9QY5S:8081
Remote Address: NA
Type: UDP
Process: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
State: NA

Local Address: INFORMAT-V9QY5S:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA

Local Address: INFORMAT-V9QY5S:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA

Local Address: INFORMAT-V9QY5S:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\0110333013
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\110112008(
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\110112008(
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\1101120083
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\24270_300x
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\cbajaxmoda
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\cbsalary_s
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\contentreq
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\DocumentDo
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\flashwrite
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\MicrosoftA
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\richtextco
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\shadowedp(
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\shadowedpo
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\SiteCataly
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\sitetempla
Status: Hidden

Object: C:\Documents and Settings\ddemp912\My Documents\careers\Find Jobs - Entry Level Customer Service, Public Relation, Management Jobs in Mesquite, Garland, Plano, Dallas, Irving, Grapevine, Rowlett, Texas - Inner-Link Marketing Concepts, Inc_files\sologig-de
Status: Hidden

Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied

Object: C:\System Volume Information\tracking.log
Status: Access denied

Object: C:\System Volume Information\_restore{BF4D3E3A-A9CB-4D7C-BC12-7E6C6028C599}
Status: Access denied

Go to the top of the page
 
+Quote Post
emeraldnzl
post Aug 10 2009, 12:10 PM
Post #4


Trusted Helper
Group Icon
Posts: 8,065
OS: XP Pro



Hello again The Boy Wonder,

Can you run these ones?

You may have used Malwarebytes before. If you have, and still have it on your machine, please update and run. Post the scan report back here.

If you do not have Malwarebytes please download from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Next
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

So when you return please post
  • MBAM log
  • the two OTL logs - OTL.txt and Extras.txt



Note: Unless otherwise instructed always post the logs in the forum. If reports don't fit on one post. It might be necessary to break the logs up to get them on the forum. Just use as many posts as you need, that's fine. smile.gif
Go to the top of the page
 
+Quote Post
The Boy Wonder
post Aug 10 2009, 01:35 PM
Post #5


Member
**
Posts: 14
OS: Windows XP



Malwarebytes' Anti-Malware 1.40
Database version: 2593
Windows 5.1.2600 Service Pack 2

8/10/2009 3:11:32 PM
mbam-log-2009-08-10 (15-11-32).txt

Scan type: Quick Scan
Objects scanned: 97011
Time elapsed: 12 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
======================================================================================



OTL logfile created on: 8/10/2009 3:21:59 PM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Documents and Settings\ddemp912\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

382.92 Mb Total Physical Memory | 96.39 Mb Available Physical Memory | 25.17% Memory free
920.52 Mb Paging File | 430.43 Mb Available in Paging File | 46.76% Paging File free
Paging file location(s): C:\pagefile.sys 576 1152 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 33.97 Gb Total Space | 7.88 Gb Free Space | 23.21% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: INFORMAT-V9QY5S
Current User Name: ddemp912
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\windows\System32\ibmpmsvc.exe ()
PRC - C:\windows\System32\Ati2evxx.exe ()
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe (AT&T)
PRC - C:\windows\System32\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe (Authentium, Inc.)
PRC - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
PRC - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe (Raxco Software, Inc.)
PRC - C:\windows\System32\QCONSVC.EXE (IBM Corp.)
PRC - C:\windows\System32\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\windows\System32\TpKmpSVC.exe ()
PRC - C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
PRC - C:\windows\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\ThinkPad\Utilities\EzEjMnAp.Exe (IBM Corp.)
PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe ()
PRC - C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe ()
PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe ()
PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe (IBM Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\windows\System32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
PRC - C:\windows\AGRSMMSG.exe (Agere Systems)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE (IBM Corp.)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AT&T\Internet Security Wizard\ISW.exe (AT&T)
PRC - C:\Documents and Settings\ddemp912\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
PRC - C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
PRC - C:\windows\System32\taskmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Documents and Settings\ddemp912\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (ASKUpgrade [Auto | Stopped]) -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\windows\System32\Ati2evxx.exe ()
SRV - (dvpapi [Auto | Running]) -- C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe (Authentium, Inc.)
SRV - (helpsvc [Auto | Running]) -- C:\windows\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IBMPMSVC [Auto | Running]) -- C:\windows\System32\ibmpmsvc.exe ()
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) -- File not found
SRV - (Irmon [Auto | Running]) -- C:\windows\System32\irmon.dll (Microsoft Corporation)
SRV - (ITMRTSVC [Auto | Running]) -- C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (McAfeeFramework [Auto | Running]) -- C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
SRV - (NetSvc [On_Demand | Stopped]) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PDAgent [Auto | Running]) -- C:\Program Files\Raxco\PerfectDisk\PDAgent.exe (Raxco Software, Inc.)
SRV - (PDEngine [On_Demand | Stopped]) -- C:\Program Files\Raxco\PerfectDisk\PDEngine.exe (Raxco Software, Inc.)
SRV - (QCONSVC [Auto | Running]) -- C:\windows\System32\QCONSVC.EXE (IBM Corp.)
SRV - (RegSrvc [Auto | Running]) -- C:\windows\System32\RegSrvc.exe (Intel Corporation)
SRV - (RPSUpdaterR [On_Demand | Stopped]) -- C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe (AT&T)
SRV - (RP_FWS [Auto | Running]) -- C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe (AT&T)
SRV - (S24EventMonitor [Auto | Running]) -- C:\windows\System32\S24EvMon.exe (Intel Corporation )
SRV - (sdAuxService [On_Demand | Stopped]) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (sdCoreService [On_Demand | Stopped]) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (SoundMAX Agent Service (default) [Auto | Running]) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (ThreatFire [Auto | Stopped]) -- File not found
SRV - (TpKmpSVC [Auto | Running]) -- C:\windows\System32\TpKmpSVC.exe ()
SRV - (usnjsvc [On_Demand | Running]) -- C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc [Auto | Running]) -- C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Running]) -- C:\windows\System32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AegisP [Auto | Running]) -- C:\windows\System32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (AgereSoftModem [On_Demand | Running]) -- C:\windows\System32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (AM5211 [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\am5211.sys ()
DRV - (ANC [System | Running]) -- C:\windows\System32\drivers\ANC.SYS (IBM Corp.)
DRV - (ati2mtag [On_Demand | Running]) -- C:\windows\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (CSS DVP [Auto | Running]) -- C:\windows\System32\DRIVERS\css-dvp.sys (Authentium, Inc.)
DRV - (DefragFS [Boot | Running]) -- C:\windows\System32\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV - (drvmcdb [Boot | Running]) -- C:\windows\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) -- C:\windows\System32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (E1000 [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\e1000325.sys (Intel Corporation)
DRV - (E100B [On_Demand | Running]) -- C:\windows\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (EGATHDRV [Auto | Running]) -- C:\windows\System32\EGATHDRV.SYS (IBM Corporation)
DRV - (ggflt [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (ggsemc [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (gv3 [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\gv3.sys (Microsoft Corporation)
DRV - (HSFHWICH [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (IBMPMDRV [On_Demand | Running]) -- C:\windows\System32\DRIVERS\ibmpmdrv.sys (IBM Corp.)
DRV - (IBMTPCHK [System | Running]) -- C:\windows\System32\drivers\IBMBLDID.SYS ()
DRV - (is-RV7HUdrv [System | Running]) -- C:\windows\System32\DRIVERS\65644179.sys (Kaspersky Lab)
DRV - (mdmxsdk [Auto | Running]) -- C:\windows\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NSCIRDA [On_Demand | Running]) -- C:\windows\System32\DRIVERS\nscirda.sys (National Semiconductor Corporation)
DRV - (PCTCore [Boot | Running]) -- C:\windows\system32\drivers\PCTCore.sys (PC Tools)
DRV - (PMEM [Auto | Running]) -- C:\windows\System32\drivers\PMEMNT.SYS (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) -- C:\windows\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\windows\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (QCNDISIF [On_Demand | Stopped]) -- C:\windows\System32\drivers\qcndisif.SYS (IBM Corporation.)
DRV - (RPPKT [On_Demand | Running]) -- C:\windows\System32\DRIVERS\rp_pkt32.sys (Radialpoint, Inc.)
DRV - (RPSKT [Auto | Running]) -- C:\windows\System32\DRIVERS\rp_skt32.sys (Radialpoint, Inc.)
DRV - (s116bus [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\s116bus.sys (MCCI Corporation)
DRV - (s116mdfl [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\s116mdfl.sys (MCCI Corporation)
DRV - (s116mdm [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\s116mdm.sys (MCCI Corporation)
DRV - (s116mgmt [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\s116mgmt.sys (MCCI Corporation)
DRV - (s116obex [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\s116obex.sys (MCCI Corporation)
DRV - (s24trans [Auto | Running]) -- C:\windows\System32\DRIVERS\s24trans.sys (Intel Corporation)
DRV - (SCDEmu [System | Running]) -- C:\windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Smapint [System | Running]) -- C:\windows\System32\drivers\Smapint.sys (Microsoft Corporation)
DRV - (smwdm [On_Demand | Running]) -- C:\windows\System32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (sscdbhk5 [System | Running]) -- C:\windows\System32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) -- C:\windows\System32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (StarOpen [System | Running]) -- C:\windows\System32\drivers\StarOpen.sys ()
DRV - (SynTP [On_Demand | Running]) -- C:\windows\System32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (TDSMAPI [System | Running]) -- C:\windows\System32\drivers\TDSMAPI.SYS ()
DRV - (tfsnboio [Auto | Running]) -- C:\windows\System32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) -- C:\windows\System32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) -- C:\windows\System32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) -- C:\windows\System32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) -- C:\windows\System32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) -- C:\windows\System32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) -- C:\windows\System32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) -- C:\windows\System32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) -- C:\windows\System32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (Tp4Track [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\tp4track.sys (IBM Corporation)
DRV - (TPHKDRV [System | Running]) -- C:\windows\System32\drivers\TPHKDRV.sys (IBM Corporation)
DRV - (TPPWR [System | Running]) -- C:\windows\System32\drivers\Tppwr.sys (IBM Corp.)
DRV - (TSMAPIP [System | Running]) -- C:\windows\System32\drivers\TSMAPIP.SYS ()
DRV - (TwoTrack [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\TwoTrack.sys (IBM Corporation)
DRV - (w22n51 [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\w22n51.sys (Intel® Corporation)
DRV - (w70n51 [On_Demand | Running]) -- C:\windows\System32\DRIVERS\w70n51.sys (Intel® Corporation)
DRV - (winachsf [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) -- C:\windows\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) -- C:\windows\System32\drivers\ialmkchw.sys (Intel Corporation)
DRV - ({E2B953A6-195A-44F9-9BA3-3D5F4E32BB55} [On_Demand | Stopped]) -- C:\windows\System32\drivers\wA301a.sys (Intel Corporation)
DRV - (MBAMSwissArmy [On_Demand | Running]) -- C:\windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://cpprod.stjohns.edu/cp/home/loginf
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = actsvr.comcastonline.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = actsvr.comcastonline.com:8100

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: foxmarks@kei.com:3.1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/20 15:32:11 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/05 14:51:37 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/05 14:51:37 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape 6 6.2.3\Extensions\\Components: C:\Program Files\Netscape\Netscape 6\Components [2008/08/17 12:34:27 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape 6 6.2.3\Extensions\\Plugins: C:\Program Files\Netscape\Netscape 6\Plugins [2009/08/05 11:33:43 | 00,000,000 | ---D | M]

[2008/09/26 13:34:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Extensions
[2008/09/26 13:34:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/09 18:49:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions
[2009/07/22 10:39:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/08/05 11:56:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/07/07 13:36:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions\foxmarks@kei.com
[2008/11/07 00:17:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions\moveplayer@movenetworks.com
[2008/08/12 20:21:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\mozilla\Firefox\Profiles\8sb8ahvo.default\extensions\pbreak.br@gmail.com
[2009/08/09 18:49:24 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/08/05 14:51:37 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/11/22 11:11:06 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2009/07/20 15:33:07 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/08/05 14:50:03 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/05 14:50:04 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/20 15:32:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2008/09/15 20:11:52 | 01,335,600 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2008/09/15 20:12:12 | 00,098,304 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2009/02/06 12:44:28 | 01,447,296 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/08/05 14:50:50 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2004/12/14 02:19:18 | 00,057,344 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008/08/12 14:04:14 | 00,144,984 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2007/03/12 17:17:26 | 00,131,072 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2008/08/12 14:04:28 | 00,024,576 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2008/08/12 14:04:12 | 00,081,920 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2009/07/10 19:30:51 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/07/10 19:30:51 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/07/10 19:30:51 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/07/10 19:30:51 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/07/10 19:30:51 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/07/10 19:30:52 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml

O1 HOSTS File: (27 bytes) - C:\windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (PopKill Class) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T\AT&T Internet Security Suite\pkR.dll (Radialpoint Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\windows\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\windows\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\windows\System32\SHELL32.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AGRSMMSG] C:\windows\AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [AT&T Internet Security Suite] C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe (AT&T)
O4 - HKLM..\Run: [ATIModeChange] C:\windows\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [BMMGAG] C:\Program Files\ThinkPad\Utilities\PWRMONIT.DLL (IBM Corp.)
O4 - HKLM..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE ()
O4 - HKLM..\Run: [BMMMONWND] C:\Program Files\ThinkPad\Utilities\BATINFEX.DLL ()
O4 - HKLM..\Run: [dla] C:\windows\System32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [EZEJMNAP] C:\Program Files\ThinkPad\Utilities\EzEjMnAp.Exe (IBM Corp.)
O4 - HKLM..\Run: [-FreedomNeedsReboot] C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe (AT&T)
O4 - HKLM..\Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\windows\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ISW.exe] C:\Program Files\AT&T\Internet Security Wizard\ISW.exe (AT&T)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\Network Associates\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\windows\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\windows\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\windows\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [QCWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE (IBM Corp.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TP4EX] C:\windows\System32\tp4ex.exe (IBM Corporation)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe ()
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (IBM Corp.)
O4 - HKLM..\Run: [TPKMAPMN] C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe ()
O4 - HKLM..\Run: [TrackPointSrv] C:\windows\System32\tp4serv.exe (IBM Corporation)
O4 - HKLM..\Run: [UC_Start] C:\Program Files\IBM\Updater\ucstartup.exe ()
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\ddemp912\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [MsnMsgr] C:\Program Files\MSN Messenger\MsnMsgr.Exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\ddemp912\Start Menu\Programs\Startup\is-RV7HU.lnk = C:\Documents and Settings\ddemp912\My Documents\Downloads\Virus Removal Tool\is-RV7HU\startup.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonType = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\windows\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\windows\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\windows\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\windows\System32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} https://www-3.ibm.com/pc/support/access/sdc...ad/tgctlins.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} file://C:\Program Files\Support.com\Bin\IBMAccessSupport\common\install\ibmegath.cab (IBM Access Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/...8146.5184143518 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.4.1/...all-141-win.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E598AC61-4C6F-4F4D-877F-FAC49CA91FA3} file://C:\Program Files\Support.com\Bin\IBMAccessSupport\common\install\AcpControl.cab (acpRunner Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\windows\System32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\windows\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\windows\System32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\windows\System32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\windows\System32\SHELL32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (QConGina.dll) - C:\windows\System32\QConGina.dll (IBM Corp.)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\windows\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\windows\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\windows\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - File not found
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\windows\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\windows\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\windows\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\windows\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\QConGina: DllName - QConGina.dll - C:\windows\System32\QConGina.dll (IBM Corp.)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\windows\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\windows\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\windows\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\windows\System32\WlNotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\windows\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\windows\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\windows\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\windows\System32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\windows\System32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\windows\System32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\System32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\System32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\windows\System32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\windows\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\windows\System32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\windows\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\windows\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\windows\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\windows\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\windows\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\windows\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\windows\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\windows\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (PDBoot.exe) - C:\windows\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\windows\System32\*.tmp files]
[4 C:\windows\*.tmp files]
[1 C:\Documents and Settings\ddemp912\Desktop\*.tmp files]
[2009/08/10 14:48:53 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ddemp912\Desktop\OTL.exe
[2009/08/10 14:44:55 | 03,942,048 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\ddemp912\Desktop\mbam-setup(2).exe
[2009/08/10 08:48:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\SysProt
[2009/08/10 08:47:19 | 00,355,033 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\SysProt.zip
[2009/08/10 08:21:56 | 00,000,000 | ---D | C] -- C:\windows\LastGood
[2009/08/06 19:34:20 | 24,438,882 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part3.mp3
[2009/08/06 19:31:09 | 46,963,614 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part2.mp3
[2009/08/06 13:37:27 | 00,024,985 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\(Demonoid.com)-TTC_VIDEO_Building_Great_Sentences_Exploring_the_Writer's_Craft_6049219.7142.torrent
[2009/08/06 12:53:44 | 89,472,770 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part1.mp3
[2009/08/05 15:56:28 | 00,000,000 | ---D | C] -- C:\windows\System32\NtmsData
[2009/08/05 13:39:32 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/08/05 13:39:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2009/08/05 12:57:43 | 00,006,741 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\AVG_Anti_Virus_8_5_392_Build_1598_Multi_-[[Demonoid.com]]_6049219.7142.torrent
[2009/08/05 12:20:29 | 66,248,382 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\av-i386&ids-cumul.zip
[2009/08/05 12:08:13 | 00,003,254 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\x-Demonoid.com-x_[SteeP]_Kaspersky_Internet_Security_Anti_Virus_2010_Keys_[29_July_2009]_6049219.7142.torrent
[2009/08/05 11:56:38 | 00,000,000 | ---D | C] -- C:\Program Files\AskBarDis
[2009/08/05 11:55:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Application Data\uTorrent
[2009/08/05 11:55:36 | 00,018,943 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\x-Demonoid.com-x_Insanity_Nutrition_Guide_6049219.7142.torrent
[2009/08/05 11:33:44 | 00,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2009/08/05 11:33:44 | 00,001,740 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 7.0.lnk
[2009/08/05 11:33:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2009/08/05 11:31:31 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/08/05 10:27:10 | 00,000,000 | -H-D | C] -- C:\windows\PIF
[2009/08/05 09:57:39 | 00,055,296 | ---- | C] (Radialpoint, Inc.) -- C:\windows\System32\drivers\rp_skt32.sys
[2009/08/05 09:56:47 | 00,048,384 | ---- | C] (Radialpoint, Inc.) -- C:\windows\System32\drivers\rp_pkt32.sys
[2009/08/05 09:55:57 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Authentium
[2009/08/05 09:54:57 | 00,000,000 | ---D | C] -- C:\Program Files\Raxco
[2009/08/05 09:54:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Raxco
[2009/08/05 09:53:48 | 00,000,000 | ---D | C] -- C:\Program Files\CA
[2009/08/05 09:53:38 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Scanner
[2009/08/05 09:52:02 | 00,001,882 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AT&T Internet Security Suite.lnk
[2009/08/05 09:48:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Application Data\AT&T
[2009/08/05 09:46:06 | 00,000,000 | ---D | C] -- C:\Program Files\AT&T
[2009/08/05 09:41:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AT&T
[2009/08/05 09:40:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Application Data\InstallShield
[2009/08/05 09:38:05 | 36,484,960 | ---- | C] (AT&T) -- C:\Documents and Settings\ddemp912\Desktop\bellsouthconsumersetup.exe
[2009/08/05 02:00:13 | 00,000,268 | -H-- | C] () -- C:\sqmdata07.sqm
[2009/08/05 02:00:13 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt07.sqm
[2009/08/04 17:37:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\screenwriting.info
[2009/08/04 10:57:45 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\instructions.doc
[2009/08/04 08:17:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Motive
[2009/08/03 23:53:49 | 00,000,268 | -H-- | C] () -- C:\sqmdata06.sqm
[2009/08/03 23:53:49 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt06.sqm
[2009/07/30 04:36:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\digitalStatement
[2009/07/30 04:16:33 | 00,030,256 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\digitalStatement.zip
[2009/07/30 03:17:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\derekj
[2009/07/30 02:55:00 | 00,639,364 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\derekj.zip
[2009/07/29 19:40:54 | 00,035,840 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Resume for guy.doc
[2009/07/29 17:34:52 | 00,024,368 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Free_The_Future_of_a_Radical_Price_Chris_Anderson__-Demonoid.com-__6049219.7142.torrent
[2009/07/27 14:33:26 | 00,027,136 | ---- | C] () -- C:\Documents and Settings\ddemp912\My Documents\character research.doc
[2009/07/27 13:54:48 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\ddemp912\My Documents\address.doc
[2009/07/26 17:22:36 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\ddemp912\My Documents\~$bsite info.doc
[2009/07/26 17:22:34 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\ddemp912\My Documents\Website info.doc
[2009/07/23 01:53:20 | 00,031,008 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\_=Demonoid.com=_-Paul_Janka_Beyond_the_Digits_(PUA)_6049219.7142.torrent
[2009/07/22 11:41:50 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\This is Fixcast.doc
[2009/07/21 13:29:21 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/07/21 08:34:45 | 03,012,768 | ---- | C] (Javacool Software LLC ) -- C:\Documents and Settings\ddemp912\Desktop\spywareblastersetup42.exe
[2009/07/21 08:23:11 | 60,857,536 | ---- | C] (Lavasoft ) -- C:\Documents and Settings\ddemp912\Desktop\Ad-AwareAE.exe
[2009/07/21 08:16:08 | 00,000,933 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Spybot - Search & Destroy.lnk
[2009/07/21 08:15:54 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/07/21 08:15:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/07/21 08:13:21 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\ddemp912\Desktop\spybotsd162.exe
[2009/07/20 15:52:08 | 62,246,944 | -HS- | C] () -- C:\windows\System32\drivers\fidbox.dat
[2009/07/20 15:52:08 | 00,713,468 | -HS- | C] () -- C:\windows\System32\drivers\fidbox.idx
[2009/07/20 15:32:57 | 00,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\javacpl.cpl
[2009/07/20 15:32:55 | 00,148,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\javaws.exe
[2009/07/20 15:32:55 | 00,144,792 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\javaw.exe
[2009/07/20 15:32:55 | 00,144,792 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\java.exe
[2009/07/20 14:53:21 | 16,254,360 | ---- | C] (Sun Microsystems, Inc.) -- C:\Documents and Settings\ddemp912\Desktop\jre-6u14-windows-i586.exe
[2009/07/20 13:29:02 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\HijackThis.lnk
[2009/07/20 13:29:02 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/07/20 13:27:36 | 00,045,056 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\ComboFix 09.doc
[2009/07/20 13:25:35 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\ddemp912\Desktop\HJTInstall.exe
[2009/07/20 12:54:00 | 03,146,921 | R--- | C] () -- C:\Documents and Settings\ddemp912\Desktop\ComboFix.exe
[2009/07/20 11:39:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Application Data\Malwarebytes
[2009/07/20 11:38:46 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/20 11:38:38 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2009/07/20 11:38:35 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2009/07/20 11:38:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/07/20 11:38:34 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/20 11:34:58 | 03,775,176 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\ddemp912\Desktop\mbam-setup.exe
[2009/07/20 02:57:03 | 00,000,268 | -H-- | C] () -- C:\sqmdata05.sqm
[2009/07/20 02:57:03 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt05.sqm
[2009/07/14 23:57:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\The Final Mixtape Michael Jackson 45 Years Of Classical Music
[2009/07/14 23:56:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\Forever King - Thisis50
[2009/07/14 23:55:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Desktop\50 Cent - War Angel LP - Thisis50
[2009/07/14 23:12:58 | 97,564,603 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\The Final Mixtape Michael Jackson 45 Years Of Classical Music.zip
[2009/07/14 22:58:27 | 75,470,934 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\Forever King - Thisis50.zip
[2009/07/14 22:46:07 | 45,737,079 | ---- | C] () -- C:\Documents and Settings\ddemp912\Desktop\50 Cent - War Angel LP - Thisis50.zip
[2009/07/14 00:30:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ddemp912\Local Settings\Application Data\PCHealth
[2009/07/06 18:35:41 | 00,000,118 | ---- | C] () -- C:\windows\System32\MRT.INI
[2008/11/22 12:14:04 | 00,021,840 | ---- | C] () -- C:\windows\System32\SIntfNT.dll
[2008/11/22 12:14:04 | 00,017,212 | ---- | C] () -- C:\windows\System32\SIntf32.dll
[2008/11/22 12:14:04 | 00,012,067 | ---- | C] () -- C:\windows\System32\SIntf16.dll
[2008/09/15 20:14:24 | 03,596,288 | ---- | C] () -- C:\windows\System32\qt-dx331.dll
[2008/09/15 20:12:02 | 00,000,416 | ---- | C] () -- C:\windows\System32\dtu100.dll.manifest
[2008/09/15 20:12:02 | 00,000,416 | ---- | C] () -- C:\windows\System32\dpl100.dll.manifest
[2008/09/15 20:11:10 | 00,012,288 | ---- | C] () -- C:\windows\System32\DivXWMPExtType.dll
[2007/02/20 14:07:56 | 00,005,632 | R--- | C] () -- C:\windows\System32\drivers\StarOpen.sys
[2007/02/07 17:53:45 | 00,000,280 | ---- | C] () -- C:\windows\System32\epoPGPsdk.dll.sig
[2004/09/06 03:13:30 | 00,045,124 | ---- | C] () -- C:\windows\System32\LsaWrApi.dll
[2004/09/06 03:04:12 | 00,225,349 | ---- | C] () -- C:\windows\System32\C1XStngs.dll
[2004/06/30 10:02:30 | 00,363,520 | ---- | C] () -- C:\windows\System32\psisdecd.dll
[2004/06/30 09:51:47 | 00,330,368 | ---- | C] () -- C:\windows\System32\drivers\am5211.sys
[2004/06/30 09:51:47 | 00,330,368 | ---- | C] () -- C:\windows\System32\am5211.sys
[2004/06/30 09:48:24 | 00,122,880 | ---- | C] () -- C:\windows\System32\tp4uires.dll
[2004/06/30 09:48:01 | 00,131,072 | ---- | C] () -- C:\windows\System32\e1000msg.dll
[2004/05/25 14:57:06 | 00,012,288 | ---- | C] () -- C:\windows\System32\e100bmsg.dll
[2004/05/25 14:56:44 | 00,049,152 | ---- | C] () -- C:\windows\System32\tpinspm.dll
[2004/03/18 12:55:48 | 00,000,000 | ---- | C] () -- C:\windows\System32\px.ini
[2004/01/20 17:28:20 | 00,143,360 | ---- | C] () -- C:\windows\System32\AIBMRUNL.dll
[2003/07/16 23:56:21 | 00,000,024 | ---- | C] () -- C:\windows\winamp.ini
[2003/07/16 05:45:17 | 00,000,061 | ---- | C] () -- C:\windows\smscfg.ini
[2003/06/22 17:55:38 | 00,000,000 | ---- | C] () -- C:\windows\netscape.INI
[2003/06/22 14:50:49 | 00,000,376 | ---- | C] () -- C:\windows\ODBC.INI
[2003/06/22 12:37:25 | 00,000,750 | ---- | C] () -- C:\windows\wininit.ini
[2003/06/22 11:48:35 | 00,008,831 | ---- | C] () -- C:\windows\System32\drivers\TDSMAPI.SYS
[2003/06/22 11:47:58 | 00,061,440 | ---- | C] () -- C:\windows\System32\FPCALL.dll
[2003/06/22 11:47:44 | 00,007,168 | ---- | C] () -- C:\windows\System32\drivers\TSMAPIP.SYS
[2003/06/22 11:46:21 | 00,002,295 | ---- | C] () -- C:\windows\System32\drivers\IBMBLDID.SYS
[2003/06/22 05:04:06 | 00,051,979 | ---- | C] () -- C:\windows\System32\SynUnst.ini
[2003/06/22 05:04:05 | 00,007,052 | ---- | C] () -- C:\windows\System32\SynTPEnh.ini
[2003/06/22 05:03:47 | 00,077,824 | ---- | C] () -- C:\windows\System32\SynTPCoI.dll
[2003/06/22 05:03:46 | 00,111,035 | ---- | C] () -- C:\windows\System32\SynTP.ini
[2003/06/22 05:03:40 | 00,002,813 | ---- | C] () -- C:\windows\System32\IBM_DP.ini
[2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\windows\System32\OUTLPERF.INI
[2002/12/02 15:57:00 | 00,651,264 | ---- | C] () -- C:\windows\System32\libeay32.dll
[2002/12/02 15:57:00 | 00,147,456 | ---- | C] () -- C:\windows\System32\ssleay32.dll
[2002/08/29 08:00:00 | 00,000,813 | ---- | C] () -- C:\windows\win.ini
[2002/08/29 08:00:00 | 00,000,227 | ---- | C] () -- C:\windows\system.ini

========== Files - Modified Within 30 Days ==========

[1 C:\windows\System32\*.tmp files]
[4 C:\windows\*.tmp files]
[5 C:\Documents and Settings\ddemp912\My Documents\*.tmp files]
[1 C:\Documents and Settings\ddemp912\Desktop\*.tmp files]
[2009/08/10 15:22:03 | 62,246,944 | -HS- | M] () -- C:\windows\System32\drivers\fidbox.dat
[2009/08/10 14:48:23 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ddemp912\Desktop\OTL.exe
[2009/08/10 14:46:55 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/10 14:45:31 | 03,942,048 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\ddemp912\Desktop\mbam-setup(2).exe
[2009/08/10 14:40:10 | 00,000,990 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032UA.job
[2009/08/10 08:47:50 | 00,355,033 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\SysProt.zip
[2009/08/10 08:15:33 | 00,000,330 | -H-- | M] () -- C:\windows\tasks\MP Scheduled Scan.job
[2009/08/10 08:12:41 | 00,002,206 | ---- | M] () -- C:\windows\System32\wpa.dbl
[2009/08/10 08:12:02 | 00,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2009/08/10 08:11:50 | 00,002,048 | --S- | M] () -- C:\windows\bootstat.dat
[2009/08/10 02:02:57 | 00,713,468 | -HS- | M] () -- C:\windows\System32\drivers\fidbox.idx
[2009/08/09 19:40:08 | 00,000,938 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032Core.job
[2009/08/06 19:38:42 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\instructions.doc
[2009/08/06 19:37:01 | 24,438,882 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part3.mp3
[2009/08/06 19:36:29 | 46,963,614 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part2.mp3
[2009/08/06 13:37:34 | 00,024,985 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\(Demonoid.com)-TTC_VIDEO_Building_Great_Sentences_Exploring_the_Writer's_Craft_6049219.7142.torrent
[2009/08/06 13:03:33 | 89,472,770 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Lip Service Part1.mp3
[2009/08/05 18:41:20 | 00,000,583 | ---- | M] () -- C:\Documents and Settings\ddemp912\My Documents\My Sharing Folders.lnk
[2009/08/05 12:57:47 | 00,006,741 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\AVG_Anti_Virus_8_5_392_Build_1598_Multi_-[[Demonoid.com]]_6049219.7142.torrent
[2009/08/05 12:28:42 | 66,248,382 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\av-i386&ids-cumul.zip
[2009/08/05 12:08:14 | 00,003,254 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\x-Demonoid.com-x_[SteeP]_Kaspersky_Internet_Security_Anti_Virus_2010_Keys_[29_July_2009]_6049219.7142.torrent
[2009/08/05 11:55:40 | 00,018,943 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\x-Demonoid.com-x_Insanity_Nutrition_Guide_6049219.7142.torrent
[2009/08/05 11:33:44 | 00,001,757 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2009/08/05 11:33:44 | 00,001,740 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 7.0.lnk
[2009/08/05 09:52:02 | 00,001,882 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AT&T Internet Security Suite.lnk
[2009/08/05 09:39:31 | 36,484,960 | ---- | M] (AT&T) -- C:\Documents and Settings\ddemp912\Desktop\bellsouthconsumersetup.exe
[2009/08/05 02:00:13 | 00,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2009/08/05 02:00:13 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2009/08/03 23:53:49 | 00,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2009/08/03 23:53:49 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2009/08/03 13:36:28 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2009/08/02 23:43:56 | 00,080,384 | ---- | M] () -- C:\Documents and Settings\ddemp912\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/30 04:16:48 | 00,030,256 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\digitalStatement.zip
[2009/07/30 02:55:31 | 00,639,364 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\derekj.zip
[2009/07/29 19:40:55 | 00,035,840 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Resume for guy.doc
[2009/07/29 17:35:34 | 00,024,368 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Free_The_Future_of_a_Radical_Price_Chris_Anderson__-Demonoid.com-__6049219.7142.torrent
[2009/07/27 14:33:27 | 00,027,136 | ---- | M] () -- C:\Documents and Settings\ddemp912\My Documents\character research.doc
[2009/07/27 13:54:49 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\ddemp912\My Documents\address.doc
[2009/07/26 17:59:36 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\ddemp912\My Documents\Website info.doc
[2009/07/26 17:22:36 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\ddemp912\My Documents\~$bsite info.doc
[2009/07/23 01:53:55 | 00,031,008 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\_=Demonoid.com=_-Paul_Janka_Beyond_the_Digits_(PUA)_6049219.7142.torrent
[2009/07/22 12:14:18 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\This is Fixcast.doc
[2009/07/21 08:36:09 | 03,012,768 | ---- | M] (Javacool Software LLC ) -- C:\Documents and Settings\ddemp912\Desktop\spywareblastersetup42.exe
[2009/07/21 08:33:37 | 60,857,536 | ---- | M] (Lavasoft ) -- C:\Documents and Settings\ddemp912\Desktop\Ad-AwareAE.exe
[2009/07/21 08:16:08 | 00,000,933 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Spybot - Search & Destroy.lnk
[2009/07/21 08:14:22 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\ddemp912\Desktop\spybotsd162.exe
[2009/07/20 15:32:08 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\javaws.exe
[2009/07/20 15:32:07 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\javaw.exe
[2009/07/20 15:32:07 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\java.exe
[2009/07/20 15:32:07 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\javacpl.cpl
[2009/07/20 15:32:05 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\deploytk.dll
[2009/07/20 14:53:52 | 16,254,360 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\ddemp912\Desktop\jre-6u14-windows-i586.exe
[2009/07/20 13:29:02 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\HijackThis.lnk
[2009/07/20 13:27:37 | 00,045,056 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\ComboFix 09.doc
[2009/07/20 13:25:38 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\ddemp912\Desktop\HJTInstall.exe
[2009/07/20 13:14:31 | 00,000,227 | ---- | M] () -- C:\windows\system.ini
[2009/07/20 12:54:07 | 03,146,921 | R--- | M] () -- C:\Documents and Settings\ddemp912\Desktop\ComboFix.exe
[2009/07/20 11:35:43 | 03,775,176 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\ddemp912\Desktop\mbam-setup.exe
[2009/07/20 02:57:03 | 00,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2009/07/20 02:57:03 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2009/07/15 16:56:50 | 00,001,374 | ---- | M] () -- C:\windows\imsins.BAK
[2009/07/15 16:48:59 | 00,000,118 | ---- | M] () -- C:\windows\System32\MRT.INI
[2009/07/14 23:34:08 | 97,564,603 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\The Final Mixtape Michael Jackson 45 Years Of Classical Music.zip
[2009/07/14 23:10:19 | 75,470,934 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\Forever King - Thisis50.zip
[2009/07/14 22:55:51 | 45,737,079 | ---- | M] () -- C:\Documents and Settings\ddemp912\Desktop\50 Cent - War Angel LP - Thisis50.zip

========== LOP Check ==========

[2009/08/05 18:25:48 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/08/05 09:51:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AT&T
[2004/05/26 09:47:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ibm
[2009/08/04 08:17:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive
[2008/10/13 19:50:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Network Associates
[2008/09/17 03:51:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PAS
[2009/07/06 17:45:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/05 11:55:58 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\ddemp912\Application Data
[2004/07/06 08:53:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\Aim
[2009/08/05 10:30:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\AT&T
[2007/02/23 18:59:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\Azureus
[2004/07/06 08:53:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\IBM
[2004/07/06 08:53:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\InterVideo
[2004/07/06 08:53:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\Leadertech
[2008/11/08 01:17:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\Move Networks
[2009/01/15 21:26:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\MXSkypeRec
[2007/02/07 16:09:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\U3
[2009/08/06 19:40:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\uTorrent
[2004/07/06 08:53:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\ddemp912\Application Data\VERITAS
[2002/08/29 08:00:00 | 00,000,065 | RH-- | M] () -- C:\windows\Tasks\desktop.ini
[2009/08/09 19:40:08 | 00,000,938 | ---- | M] () -- C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032Core.job
[2009/08/10 14:40:10 | 00,000,990 | ---- | M] () -- C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032UA.job
[2009/08/10 08:15:33 | 00,000,330 | -H-- | M] () -- C:\windows\Tasks\MP Scheduled Scan.job
[2009/08/10 08:12:02 | 00,000,006 | -H-- | M] () -- C:\windows\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4BF2F6B5
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
==============================================================================================




OTL Extras logfile created on: 8/10/2009 3:21:59 PM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Documents and Settings\ddemp912\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

382.92 Mb Total Physical Memory | 96.39 Mb Available Physical Memory | 25.17% Memory free
920.52 Mb Paging File | 430.43 Mb Available in Paging File | 46.76% Paging File free
Paging file location(s): C:\pagefile.sys 576 1152 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 33.97 Gb Total Space | 7.88 Gb Free Space | 23.21% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: INFORMAT-V9QY5S
Current User Name: ddemp912
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] --

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service
"10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service
"10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
"C:\Program Files\Trillian\trillian.exe" = C:\Program Files\Trillian\trillian.exe:*:Disabled:Trillian -- (Cerulean Studios)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:uTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Sony Ericsson\Update Service\Update Service.exe" = C:\Program Files\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service -- ()
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)
"C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\English\setup.exe" = C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\English\setup.exe:*:Enabled:Kaspersky Anti-Virus 2009 Setup -- (Kaspersky Lab)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0345520E-2A04-4A36-BC31-353AE87A6092}" = RPS Diagnostic Utility
"{0818687F-F41F-496D-9D6D-DB98F147FC62}" = RPS Firewall
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0EFB66FE-E184-4D90-9B7C-429EA238E59D}" = Messageware Plus Pack Spell Check Component
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = IBM DLA
"{16906D21-0656-4F8B-9A01-C3D24B5401FC}" = Intel® PROSet for Wired Connections
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1ACE3F9D-CDA4-4F39-9605-334CF37A1579}" = Authentium AntiVirus SDK - 2
"{1E164156-3FA1-4389-9B0B-28E88B879639}" = RPS AsRealtime
"{1E4913E1-1554-4B0C-9F69-82CD62E46DA7}" = Messageware Plus Pack Compress Attachments
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = IBM ThinkPad Keyboard Customizer Utility
"{212F5777-1190-4DEF-8E4D-6B2F313B45E7}" = PerfectDisk
"{22B71A00-4DED-11D4-A5E5-0004AC564F43}" = IBM Access Connections
"{25B3E8D2-7597-4F38-8840-AFDD019E99E3}" = MELL Upgrading to Microsoft® Office 2003 Collection
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{295F5142-A223-4164-9A6D-6683C08409FC}" = RPS RpsCore
"{2F4BFC9D-17D7-447A-AEA2-467892D876B3}" = RPS App Detector
"{310F26F3-C769-48E5-BD0D-53D4366C34CD}" = RPS PopupBlocker
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3DE72179-FEF4-4846-BF82-62CBFC61F8D7}" = RPS Performance Tool
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HydraVision
"{4AA73DA8-8D69-44ED-B5D7-CB815C81F83E}" = RPS Zip
"{537654FC-556A-4992-BF3D-ADC05E7009DC}" = RPS AntiFraud
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{58A2663B-56DC-488F-8E29-D44C6DE053B5}" = RPS Security Cleanup
"{58BAA8D0-404E-4585-9FD3-ED1BB72AC2EE}" = Adobe Flash Player 9 ActiveX
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{5DFDEAAA-E050-482E-A5B6-138CAE53F7BF}" = Radialpoint Security Services
"{5E863175-E85D-44A6-8968-82507D34AE7F}" = QuickTime
"{5F35CC11-438E-403B-9863-05AADC7BC713}" = MELL Microsoft® Office Standard Edition 2003 Collection
"{67D7BC74-E8DF-4811-9B41-6023A8C9BB3F}" = Intel® Sebring API
"{6C72E14A-C1F3-45E5-8810-83CE3C19ED63}" = IBM 32-bit Runtime Environment for Java 2, v1.4.1
"{6CE96A14-61E2-48CC-837E-22710A953ADE}" = IBM Themes
"{6DC0CBB2-F919-4bdd-A608-E8FE35E03237}" = MX Skype Recorder v3.9.2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7D11FED9-4214-40A6-A6CA-3CFBAC20DA36}" = RPS Burn
"{82512BC9-BD5D-4C50-BE4D-B98E7DF78687}" = IBM ThinkPad UltraNav Wizard
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8D815BF3-2399-459C-B121-49373FEFB9E8}" = IBM Update Connector
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{904847DA-FBC0-4726-BE73-830FCB9D4E8A}" = RPS Backup
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = IBM RecordNow!
"{99E6E9E1-BBCD-4294-93C6-08537A9E92CB}" = RPS AntiSpyware
"{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}" = IBM 11b/g Wireless LAN Mini PCI Adapter and Applications
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A260B422-70E1-41E2-957D-F76FA21266D5}" = Apple Software Update
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AC82BF06-223B-42AA-A89F-2D3BCD247366}" = RPS Privacy Manager
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B554158F-E72C-402C-98A6-9EDF215DB4DB}" = Messageware Plus Pack English Dictionary
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BAF99E78-879B-4811-BFEF-3CC7057BC00D}" = RPS Ad Blocker
"{BD560699-45B7-4029-8417-C645E8A3D746}" = Messageware Plus Pack Thesaurus
"{C365ACC1-D32A-4552-A246-38DE4EF40DC6}" = Messageware Plus Pack Base Component
"{C869F4FF-E5FF-4FBB-9A31-33C23605E170}" = PPSDKRedistributables
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D7DF917E-C963-42B4-AD48-837ACA6D8859}" = AT&T Internet Security Suite
"{E5E7B0D0-20E1-4B1A-B8C9-B9E2B93DE1DE}" = RPS ParentalControl
"{E85A45C2-290F-4C4A-9363-B6399EE648A9}" = RPS AntiVirus
"{EA664480-3844-11D5-8C25-444553540000}" = IBM TrackPoint Accessibility Features
"{EC6AF20D-4376-4070-BEE4-D3A0DFF7E140}" = Access IBM
"{ED55BFEF-90F3-4926-9536-D94FDBBF65DC}" = Zune
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"A3AB947F7D490EEA2162B4CAEA69D887C7EBFE3C" = Windows Driver Package - Microsoft WPD (8/28/2006 1.0.0.2)
"ABC Amber LIT Converter" = ABC Amber LIT Converter
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems AC'97 Modem
"All ATI Software" = ATI - Software Uninstall Utility
"AOL Instant Messenger" = AOL Instant Messenger
"Ask Toolbar_is1" = Ask Toolbar
"ATI Display Driver" = ATI Display Driver
"Audacity_is1" = Audacity 1.2.6
"CDisplay_is1" = CDisplay 1.8
"CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014" = IBM Integrated 56K Modem
"ComcastHSI" = Comcast High-Speed Internet Install Wizard
"Diablo II" = Diablo II
"EasyEject Utility" = IBM ThinkPad EasyEject Utility
"GTK 2.0" = GTK+ Runtime 2.12.1 rev b (remove only)
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{6C72E14A-C1F3-45E5-8810-83CE3C19ED63}" = IBM 32-bit Runtime Environment for Java 2, v1.4.1
"IsoBuster_is1" = IsoBuster 2.4
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Netscape 6 (6.2.3)" = Netscape 6 (6.2.3)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PC Satellite TV_is1" = Satellite TV for PC
"Podcast Studio" = Podcast Studio
"PokerStars" = PokerStars
"PokerStars.net" = PokerStars.net
"Power Features" = IBM ThinkPad Battery MaxiMiser and Power Management Features
"Power Management Driver" = IBM ThinkPad Power Management Driver
"PowerISO" = PowerISO
"Presentation Director" = IBM ThinkPad Presentation Director
"PROSet" = Intel® PRO Network Adapters and Drivers
"RadialpointClientGateway_is1" = AT&T Internet Security Wizard 1.5.11
"RealPlayer 6.0" = RealPlayer
"Shockwave" = Shockwave
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Spyware Doctor" = Spyware Doctor 6.0
"Super Video Converter_is1" = Super Video Converter 5.7.2
"SynTPDeinstKey" = IBM ThinkPad UltraNav Driver
"ThinkPad Configuration" = IBM ThinkPad Configuration
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"ThinkPadSoftwareInstaller" = ThinkPad Software Installer
"TrackPoint" = IBM TrackPoint Support
"Trillian" = Trillian
"Update Service" = Update Service
"VLC media player" = VideoLAN VLC media player 0.8.6
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/6/2009 1:40:05 AM | Computer Name = INFORMAT-V9QY5S | Source = Google Update | ID = 20
Description =

Error - 8/7/2009 8:16:03 AM | Computer Name = INFORMAT-V9QY5S | Source = Google Update | ID = 20
Description =

Error - 8/7/2009 9:03:11 AM | Computer Name = INFORMAT-V9QY5S | Source = Windows Live Messenger | ID = 1000
Description =

Error - 8/9/2009 1:23:09 AM | Computer Name = INFORMAT-V9QY5S | Source = Application Error | ID = 1005
Description = Windows cannot access the file C:\WINDOWS\system32\mshtml.dll for
one of the following reasons: there is a problem with the network connection, the
disk that the file is stored on, or the storage drivers installed on this computer;
or the disk is missing. Windows closed the program Microsoft ® HTML Viewer because
of this error. Program: Microsoft ® HTML Viewer File: C:\WINDOWS\system32\mshtml.dll

The
error value is listed in the Additional Data section. User Action 1. Open the file
again. This situation might be a temporary problem that corrects itself when the
program runs again. 2. If the file still cannot be accessed and - It is on the network,
your network administrator should verify that there is not a problem with the network
and that the server can be contacted. - It is on a removable disk, for example,
a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3.
Check and repair the file system by running CHKDSK. To run CHKDSK, click Start,
click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F,
and then press ENTER. 4. If the problem persists, restore the file from a backup
copy. 5. Determine whether other files on the same disk can be opened. If not, the
disk might be damaged. If it is a hard disk, contact your administrator or computer
hardware vendor for further assistance. Additional Data Error value: C000009C Disk
type: 3

Error - 8/9/2009 1:23:47 AM | Computer Name = INFORMAT-V9QY5S | Source = Application Error | ID = 1000
Description = Faulting application ZuneSetup.exe, version 1.0.5341.0, faulting module
mshtml.dll, version 8.0.6001.18783, fault address 0x003834dc.

Error - 8/9/2009 10:03:05 AM | Computer Name = INFORMAT-V9QY5S | Source = Application Error | ID = 1005
Description = Windows cannot access the file C:\WINDOWS\system32\mshtml.dll for
one of the following reasons: there is a problem with the network connection, the
disk that the file is stored on, or the storage drivers installed on this computer;
or the disk is missing. Windows closed the program Microsoft ® HTML Viewer because
of this error. Program: Microsoft ® HTML Viewer File: C:\WINDOWS\system32\mshtml.dll

The
error value is listed in the Additional Data section. User Action 1. Open the file
again. This situation might be a temporary problem that corrects itself when the
program runs again. 2. If the file still cannot be accessed and - It is on the network,
your network administrator should verify that there is not a problem with the network
and that the server can be contacted. - It is on a removable disk, for example,
a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3.
Check and repair the file system by running CHKDSK. To run CHKDSK, click Start,
click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F,
and then press ENTER. 4. If the problem persists, restore the file from a backup
copy. 5. Determine whether other files on the same disk can be opened. If not, the
disk might be damaged. If it is a hard disk, contact your administrator or computer
hardware vendor for further assistance. Additional Data Error value: C000009C Disk
type: 3

Error - 8/9/2009 10:04:12 AM | Computer Name = INFORMAT-V9QY5S | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 7.0.0.0, faulting module
mshtml.dll, version 8.0.6001.18783, fault address 0x003834dc.

Error - 8/9/2009 10:06:04 AM | Computer Name = INFORMAT-V9QY5S | Source = Windows Live Messenger | ID = 1000
Description =

Error - 8/9/2009 6:33:36 PM | Computer Name = INFORMAT-V9QY5S | Source = Windows Live Messenger | ID = 1000
Description =

Error - 8/10/2009 8:39:21 AM | Computer Name = INFORMAT-V9QY5S | Source = Windows Live Messenger | ID = 1000
Description =

[ System Events ]
Error - 8/10/2009 8:23:13 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 8/10/2009 8:24:40 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 8/10/2009 8:24:44 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 8/10/2009 8:24:49 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 8/10/2009 8:24:53 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 8/10/2009 8:38:49 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 8/10/2009 8:39:13 AM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 8/10/2009 3:05:45 PM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 8/10/2009 3:05:46 PM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 8/10/2009 3:05:57 PM | Computer Name = INFORMAT-V9QY5S | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.


< End of report >
Go to the top of the page
 
+Quote Post
emeraldnzl
post Aug 10 2009, 02:51 PM
Post #6


Trusted Helper
Group Icon
Posts: 8,065
OS: XP Pro



Hello The Boy Wonder,

Your Adobe Acrobat Reader is out of date. Older versions are vunerable to attack.

Please go to the link below to update.

http://www.adobe.com/products/acrobat/readstep2.html

Now

Please run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    CODE
    :processes

    :OTL
    O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)

    :Services

    :Reg

    :Files

    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.

Next

Please download ComboFix from one of these locations:

NOTE: If you are guest watching this topic. ComboFix is a very powerful tool. The disclaimer clearly states that you should not use it without supervision. There is good reason for this as ComboFix can, and sometimes does, run into conflict on a computer and render it unusable.

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

So when you return please post
  • OTL fix results
  • ComboFix.txt
Go to the top of the page
 
+Quote Post
The Boy Wonder
post Aug 10 2009, 05:03 PM
Post #7


Member
**
Posts: 14
OS: Windows XP



All processes killed
========== PROCESSES ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully.
C:\Program Files\AskBarDis\bar\bin\askBar.dll unregistered successfully.
C:\Program Files\AskBarDis\bar\bin\askBar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}\ not found.
File C:\Program Files\AskBarDis\bar\bin\askBar.dll not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: admin

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: ddemp912
->Temp folder emptied: 203601049 bytes
->Temporary Internet Files folder emptied: 26035522 bytes
->Java cache emptied: 18970031 bytes
->FireFox cache emptied: 62444421 bytes
->Google Chrome cache emptied: 17552682 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 8675529 bytes

User: NetworkService
->Temp folder emptied: 69906 bytes
->Temporary Internet Files folder emptied: 32902 bytes

%systemdrive% .tmp files removed: 0 bytes
C:\windows\msdownld.tmp folder deleted successfully.
%systemroot% .tmp files removed: 1119318 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
Windows Temp folder emptied: 1954265 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 324.69 mb


OTL by OldTimer - Version 3.0.10.5 log created on 08102009_184710

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


Working on ComboFix now
Go to the top of the page
 
+Quote Post
emeraldnzl
post Aug 10 2009, 05:30 PM
Post #8


Trusted Helper
Group Icon
Posts: 8,065
OS: XP Pro



thumbsup.gif
Go to the top of the page
 
+Quote Post
The Boy Wonder
post Aug 10 2009, 05:50 PM
Post #9


Member
**
Posts: 14
OS: Windows XP



ComboFix 09-08-10.01 - ddemp912 08/10/2009 19:22.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.383.111 [GMT -4:00]
Running from: c:\documents and settings\ddemp912\Desktop\ComboFixtwo.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-07-10 to 2009-08-10 )))))))))))))))))))))))))))))))
.

2009-08-10 22:47 . 2009-08-10 22:47 -------- d-----w- C:\_OTL
2009-08-05 19:56 . 2009-08-05 19:58 -------- d-----w- c:\windows\system32\NtmsData
2009-08-05 17:39 . 2009-08-05 17:39 -------- d-----w- c:\program files\AVG
2009-08-05 17:39 . 2009-08-05 22:25 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-05 15:56 . 2009-08-05 15:56 -------- d-----w- c:\program files\AskBarDis
2009-08-05 15:55 . 2009-08-06 23:40 -------- d-----w- c:\documents and settings\ddemp912\Application Data\uTorrent
2009-08-05 14:27 . 2009-08-05 14:27 -------- d--h--w- c:\windows\PIF
2009-08-05 13:57 . 2007-03-06 17:24 55296 ----a-w- c:\windows\system32\drivers\rp_skt32.sys
2009-08-05 13:56 . 2007-04-19 15:24 48384 ----a-w- c:\windows\system32\drivers\rp_pkt32.sys
2009-08-05 13:55 . 2009-08-05 13:55 -------- d-----w- c:\program files\Common Files\Authentium
2009-08-05 13:54 . 2009-08-05 13:54 -------- d-----w- c:\program files\Raxco
2009-08-05 13:54 . 2009-08-05 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco
2009-08-05 13:53 . 2009-08-05 13:53 -------- d-----w- c:\program files\CA
2009-08-05 13:53 . 2009-08-05 14:28 -------- d-----w- c:\program files\Common Files\Scanner
2009-08-05 13:48 . 2009-08-05 14:30 -------- d-----w- c:\documents and settings\ddemp912\Application Data\AT&T
2009-08-05 13:46 . 2009-08-05 13:51 -------- d-----w- c:\program files\AT&T
2009-08-05 13:41 . 2009-08-05 13:51 -------- d-----w- c:\documents and settings\All Users\Application Data\AT&T
2009-08-05 13:40 . 2009-08-05 13:40 -------- d-----w- c:\documents and settings\ddemp912\Application Data\InstallShield
2009-08-04 12:17 . 2009-08-04 12:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive
2009-07-21 12:15 . 2009-07-21 12:36 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-21 12:15 . 2009-07-21 12:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-20 19:52 . 2009-08-10 23:36 64131104 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-20 17:29 . 2009-07-20 17:29 -------- d-----w- c:\program files\Trend Micro
2009-07-20 15:39 . 2009-07-20 15:39 -------- d-----w- c:\documents and settings\ddemp912\Application Data\Malwarebytes
2009-07-20 15:38 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-20 15:38 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-20 15:38 . 2009-07-20 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-20 15:38 . 2009-08-10 18:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-14 04:30 . 2009-07-14 04:30 -------- d-----w- c:\documents and settings\ddemp912\Local Settings\Application Data\PCHealth
2009-07-12 22:52 . 2009-07-12 22:52 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-10 22:50 . 2009-07-20 19:52 736556 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-10 21:18 . 2003-07-01 21:03 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-10 20:23 . 2007-02-08 00:09 -------- d-----w- c:\program files\Trillian
2009-08-09 16:57 . 2008-10-06 02:30 -------- d-----w- c:\program files\PokerStars
2009-08-07 21:20 . 2008-09-18 19:27 -------- d-----w- c:\documents and settings\ddemp912\Application Data\Skype
2009-08-07 20:08 . 2008-09-18 19:30 -------- d-----w- c:\documents and settings\ddemp912\Application Data\skypePM
2009-08-05 15:35 . 2007-02-07 20:04 -------- d-----w- c:\documents and settings\ddemp912\Application Data\AdobeUM
2009-08-05 13:42 . 2003-06-22 15:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-20 19:47 . 2008-10-13 23:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-20 19:32 . 2008-10-14 01:30 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-20 19:31 . 2007-02-23 21:58 -------- d-----w- c:\program files\Java
2009-07-07 19:24 . 2008-08-11 03:55 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-07 18:57 . 2009-07-07 18:57 -------- d-----w- c:\program files\Windows Defender
2009-07-07 18:57 . 2009-07-07 18:49 -------- d-----w- c:\program files\Microsoft AntiSpyware
2009-07-07 17:28 . 2009-07-06 20:49 -------- d-----w- c:\program files\Google
2009-07-06 21:45 . 2008-09-22 08:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-06 20:54 . 2009-07-06 20:50 -------- d-----w- c:\program files\Spyware Doctor
2009-07-06 20:53 . 2009-07-06 20:50 -------- d-----w- c:\program files\Common Files\PC Tools
2009-07-06 20:50 . 2009-07-06 20:50 -------- d-----w- c:\documents and settings\ddemp912\Application Data\PC Tools
2009-07-06 20:50 . 2008-10-20 21:18 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-06-16 14:55 . 2002-08-29 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2002-08-29 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:27 . 2005-08-30 14:14 1290752 ----a-w- c:\windows\system32\quartz.dll
2009-05-13 05:15 . 2006-06-23 16:33 915456 ----a-w- c:\windows\system32\wininet.dll
2008-09-27 04:22 . 2008-09-27 04:22 486128 ----a-w- c:\program files\ChromeSetup.exe
2008-08-12 07:52 . 2008-08-12 07:52 1827523 ----a-w- c:\program files\keyman_423_setup.exe
2008-04-24 17:31 . 2008-04-24 17:29 37986872 ----a-w- c:\program files\Update_Service_Setup-2.7.12.4.exe
2007-07-05 19:12 . 2007-07-05 19:12 5568552 ----a-w- c:\program files\ZuneSetup.exe
2007-04-25 22:34 . 2007-04-25 22:34 21822168 -c--a-w- c:\program files\AdbeRdr80_en_US.exe
2007-02-14 18:06 . 2007-02-14 18:06 5971432 ----a-w- c:\program files\Firefox Setup 2.0.0.1.exe
2007-02-08 00:09 . 2007-02-08 00:09 9000041 ----a-w- c:\program files\trillian-v3[1].1.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\ddemp912\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-27 133104]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2003-12-25 208896]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2004-03-10 94208]
"TPKMAPMN"="c:\program files\ThinkPad\Utilities\TpKmapMn.exe" [2003-10-23 32768]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-04-08 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-04-08 512000]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-14 335872]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-05-26 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-05-26 118784]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-10-22 114741]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"UC_Start"="c:\program files\IBM\Updater\\ucstartup.exe" [2003-09-30 36864]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2003-12-25 106496]
"BMMLREF"="c:\program files\ThinkPad\Utilities\BMMLREF.EXE" [2003-12-25 20480]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2003-12-25 394752]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2003-10-24 897024]
"PRONoMgrWired"="c:\program files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe" [2003-08-06 86016]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2002-08-29 44032]
"MSPY2002"="c:\windows\System32\IME\PINTLGNT\ImScInst.exe" [2002-08-29 59392]
"PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-29 455168]
"PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-29 455168]
"QCWLIcon"="c:\progra~1\ThinkPad\CONNEC~1\QCWLIcon.exe" [2004-05-19 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2006-10-31 20752]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-12 185896]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-07-07 167936]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-20 148888]
"ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
"AT&T Internet Security Suite"="c:\program files\AT&T\AT&T Internet Security Suite\Rps.exe" [2007-06-28 310000]
"-FreedomNeedsReboot"="c:\program files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 13552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2002-09-04 53248]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-04 28672]
"TrackPointSrv"="tp4serv.exe" - c:\windows\system32\tp4serv.exe [2003-11-13 94208]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-06-27 88363]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-5-26 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"LogonType"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina]
2004-05-19 07:21 94208 ----a-w- c:\windows\system32\QConGina.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/6/2009 4:51 PM 130936]
R1 is-RV7HUdrv;is-RV7HUdrv;c:\windows\system32\drivers\65644179.sys [11/25/2008 8:22 PM 148496]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [6/22/2003 11:45 AM 15360]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 AM5211;11b/g Wireless LAN Mini PCI Adapter Service;c:\windows\system32\drivers\am5211.sys [6/30/2004 9:51 AM 330368]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [4/24/2008 1:40 PM 13352]
S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.sys [6/1/2004 3:52 PM 12288]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
S3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [6/30/2004 9:48 AM 13904]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032Core.job
- c:\documents and settings\ddemp912\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-27 04:22]

2009-08-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2326532464-815924798-2332306161-1032UA.job
- c:\documents and settings\ddemp912\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-27 04:22]

2009-08-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://cpprod.stjohns.edu/cp/home/loginf
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = actsvr.comcastonline.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\ddemp912\Application Data\Mozilla\Firefox\Profiles\8sb8ahvo.default\
FF - plugin: c:\documents and settings\ddemp912\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-10 19:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1344)
c:\windows\system32\QConGina.dll
c:\progra~1\ThinkPad\CONNEC~1\Res\US\QGinaRes.dll
.
Completion time: 2009-08-10 19:44
ComboFix-quarantined-files.txt 2009-08-10 23:43
ComboFix2.txt 2009-07-20 17:22

Pre-Run: 8,370,053,120 bytes free
Post-Run: 8,382,353,408 bytes free

207 --- E O F --- 2009-08-10 23:11
Go to the top of the page
 
+Quote Post
emeraldnzl
post Aug 10 2009, 06:35 PM
Post #10


Trusted Helper
Group Icon
Posts: 8,065
OS: XP Pro



Well nothing showing there.

One thought did occurr to me. I wonder if Windows Defender is interrupting you anti-virus scan. I think it should have been turned off by At&t internet security anti virus but you never know. You could try check to see if it is turned off to see.

How to turn Windows Defender on or off

1. Open Windows Defender by clicking the Start button , clicking All Programs, and then clicking Windows Defender.

2. Click Tools, and then click Options.

3. Under Administrator options, select or clear the Use Windows Defender check box, and then click Save.

Administrator permission required. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

If those instructions are not appropriate for your version of Windows go to this link for instructions on how to enable/disable Windows Defender

http://windowshelp.microsoft.com/Windows/e...1bf0dc1033.mspx

Now

One last check to make sure we haven't missed anything.

Panda only works if you are using Internet Explorer.

Please go HERE to run Panda's ActiveScan
" Once you are on the Panda site click the Scan your PC button
" A new window will open...click the Check Now button
" Enter your Country
" Enter your State/Province
" Enter your e-mail address and click send
" Select either Home User or Company
" Click the big Scan Now button
" If it wants to install an ActiveX component allow it
" It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
" When download is complete, click on My Computer to start the scan
" When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
Go to the top of the page
 
+Quote Post
The Boy Wonder
post Aug 10 2009, 06:48 PM
Post #11


Member
**
Posts: 14
OS: Windows XP



Internet Explorer still isn't responsive. Right after I opened it, it froze then the error message came up and it closed automatically. I have been using Firefox this whole time.
Go to the top of the page
 
+Quote Post
emeraldnzl
post Aug 10 2009, 07:43 PM
Post #12


Trusted Helper
Group Icon
Posts: 8,065
OS: XP Pro



Okay it's a while since I checked PandaScan.

I have just been to the site and in the Help section they now say that you can use Firefox.

Sooo go ahead and try it with Firefox. Should work. smile.gif
Go to the top of the page
 
+Quote Post
The Boy Wonder
post Aug 11 2009, 01:01 AM
Post #13


Member
**
Posts: 14
OS: Windows XP



;***********************************************************************************************************************
************************************************************
ANALYSIS: 2009-08-11 02:56:13
PROTECTIONS: 1
MALWARE: 4
SUSPECTS: 3
;***********************************************************************************************************************
************************************************************
PROTECTIONS
Description Version Active Updated
;=======================================================================================================================
============================================================
Windows Defender 1.1.4903.0 No No
;=======================================================================================================================
============================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;=======================================================================================================================
============================================================
00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\Documents and Settings\ddemp912\Application Data\Mozilla\Profiles\default\p4bl1x2w.slt\cookies.txt[.bfast.com/]
00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Profiles\default\p4bl1x2w.slt\cookies.txt[.bfast.com/]
00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\Documents and Settings\Default User\Application Data\Mozilla\Profiles\default\p4bl1x2w.slt\cookies.txt[.bfast.com/]
00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\p4bl1x2w.slt\cookies.txt[.bfast.com/]
00207338 Cookie/Target TrackingCookie No 0 Yes No C:\Documents and Settings\ddemp912\Cookies\ddemp912@target[1].txt
00950035 Cookie/RegistryDefender TrackingCookie No 0 Yes No C:\Documents and Settings\ddemp912\Cookies\ddemp912@registrydefender[2].txt
03867692 Trj/Lineage.BZE Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{BF4D3E3A-A9CB-4D7C-BC12-7E6C6028C599}\RP20\A0019320.exe
;=======================================================================================================================
============================================================
SUSPECTS
Sent Location
;=======================================================================================================================
============================================================
No C:\Program Files\ABC Amber LIT Converter\abclit.exe
No C:\Program Files\InstallShield Installation Information\{D7DF917E-C963-42B4-AD48-837ACA6D8859}\RPS RpsCore.msi[unk_0078][zku_rsrc.dll]
No C:\System Volume Information\_restore{BF4D3E3A-A9CB-4D7C-BC12-7E6C6028C599}\RP19\A0015154.rbf
;=======================================================================================================================
============================================================
VULNERABILITIES
Id Severity Description
;=======================================================================================================================
============================================================
120815 HIGH MS06-022
;=======================================================================================================================
============================================================
Go to the top of the page
 
+Quote Post
The Boy Wonder
post Aug 11 2009, 01:03 AM
Post #14


Member
**
Posts: 14
OS: Windows XP



repost* sorry

This post has been edited by The Boy Wonder: Aug 11 2009, 01:12 AM
Go to the top of the page
 
+Quote Post
The Boy Wonder
post Aug 11 2009, 01:07 AM
Post #15


Member
**
Posts: 14
OS: Windows XP



repost* sorry

This post has been edited by The Boy Wonder: Aug 11 2009, 01:13 AM
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 21st November 2009 - 03:53 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising