Malware / Unknown cannot download photo's + Twitching [Solved], Google Toolbar disappeared , Freezes up ,Very Slow |
![]() ![]() |
Malware / Unknown cannot download photo's + Twitching [Solved], Google Toolbar disappeared , Freezes up ,Very Slow |
Jun 29 2009, 02:28 AM
Post
#1
|
|
|
Member ![]() ![]() Posts: 78 From: LOUISIANA OS: XP media |
Hi, My computer is very very slow and getting worse. I Had to use System Restore ( safe mode) after recieving the BD Screen 2x while windows tried to load.. I tried to load photos from my memory card to pc and nothing happened, I then opened Corel album 6, and tried to download from my camera, autoplay showed up in a box with a flashlight, it then disappeared. I tried again using the memory card only said No PC card!!! What.. .. My Google toolbar has disappeared, it is still in drop down list but it will not open. I tried all googles advice on toolbar, so far no good. I have run Malwarebytes, it is clean. My printer also printed some data in English with a single line of a foreign language on same paper. There are probably many more errors that I have not found. Help. I Appreciate any help. thanks
All this happened before I ran the Malware removal,now, I tried to download my photo's but nothing happened. The speed is slightly better, but still freezes up and causes long waits. There is also skaking or twitching of text and cursor, Google will still not work. Also on shut down grey boxes appear End Program Shellconhidden ?, and ccSvchost, both are gray boxes and appear every time. HELP !!! I also noticed on OLT that I have all the virus apps. I have ever tried, are these active even though i deleted then/ uninstalled them.. I Appreciate any help. thanks Page Size are now bigger than my screen !!!! HELP Malwarebytes' Anti-Malware 1.38 Database version: 2347 Windows 5.1.2600 Service Pack 3 Jun-28 11:21:54 PM mbam-log-2009-06-28 (23-21-54).txt Scan type: Quick Scan Objects scanned: 107043 Time elapsed: 9 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ROOTER LIST Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully ... . Windows XP . (5.1.2600) Service Pack 3 [32_bits] - x86 Family 15 Model 4 Stepping 4, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [SharedAccess] RUNNING (state:4) Windows Firewall -> Disabled ! . Internet Explorer 7.0.5730.11 . C:\ [Fixed-NTFS] .. ( Total:69 Go - Free:27 Go ) D:\ [CD_Rom] E:\ [CD_Rom] . Scan : 01:54.42 Path : C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\Rooter.exe User : mary shumate ( Administrator -> YES ) . ----------------------\\ Processes . Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (936) ______ \??\C:\WINDOWS\system32\csrss.exe (984) ______ \??\C:\WINDOWS\system32\winlogon.exe (1020) ______ C:\WINDOWS\system32\services.exe (1064) ______ C:\WINDOWS\system32\lsass.exe (1076) ______ C:\WINDOWS\system32\Ati2evxx.exe (1292) ______ C:\WINDOWS\system32\svchost.exe (1308) ______ C:\WINDOWS\system32\svchost.exe (1408) ______ C:\WINDOWS\System32\svchost.exe (1548) ______ C:\WINDOWS\system32\svchost.exe (1652) ______ C:\WINDOWS\system32\svchost.exe (1808) ______ C:\WINDOWS\system32\spoolsv.exe (2032) ______ C:\WINDOWS\Explorer.EXE (296) ______ C:\WINDOWS\stsystra.exe (492) ______ C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (636) ______ C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (644) ______ C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe (652) ______ C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (660) ______ C:\WINDOWS\ehome\ehtray.exe (680) ______ C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (696) ______ C:\WINDOWS\system32\dla\tfswctrl.exe (708) ______ C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe (720) ______ C:\Program Files\Real\RealPlayer\RealPlay.exe (796) ______ C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe (836) ______ C:\WINDOWS\system32\ctfmon.exe (892) ______ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (908) ______ C:\Program Files\FinePixViewer\QuickDCF.exe (1144) ______ C:\WINDOWS\system32\svchost.exe (1520) ______ C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe (1580) ______ C:\WINDOWS\eHome\ehRecvr.exe (1420) ______ C:\WINDOWS\eHome\ehSched.exe (1732) ______ C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe (1884) ______ C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (1968) ______ C:\WINDOWS\system32\svchost.exe (2052) ______ C:\WINDOWS\system32\UAService7.exe (2124) ______ C:\WINDOWS\ehome\mcrdsvc.exe (2316) ______ C:\WINDOWS\system32\svchost.exe (2808) ______ C:\WINDOWS\system32\dllhost.exe (2840) ______ C:\WINDOWS\System32\alg.exe (3168) ______ C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (3976) ______ C:\WINDOWS\eHome\ehmsas.exe (3308) ______ C:\PROGRA~1\MUSICM~1\Common\COMPON~1\MMCOMP~1.EXE (2676) ______ C:\Program Files\Internet Explorer\IEXPLORE.EXE (3556) ______ C:\WINDOWS\system32\wbem\wmiprvse.exe (284) ______ C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\Rooter.exe (1228) . ----------------------\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:57544704) \Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:57576960 | Length:74940526080) \Device\Harddisk0\Partition3 (Start_Offset:75006328320 | Length:4984519680) . ----------------------\\ Scheduled Tasks . C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\SA.DAT C:\WINDOWS\Tasks\Wise Disk Cleaner 4.job . ----------------------\\ Registry . . ----------------------\\ Files & Folders . C:\DOCUME~1\MARYSH~1.001\Favorites\CHRISTMAS\CHRISTMAS GAMES\The Twelve Days of Christmas - The Nutcracker Game.url ==> Cracks & Keygens <== . ----------------------\\ Scan completed at 01:55.36 . C:\Rooter$\Rooter_1.txt - (29/06/2009 | 01:55.36).c OLT LIST OTL logfile created on: Jun-29 2:02:14 AM - Run 1 OTL by OldTimer - Version 3.0.5.3 Folder = C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000409 | Country: United States | Language: ENU | Date Format: MMM-dd 510.09 Mb Total Physical Memory | 184.79 Mb Available Physical Memory | 36.23% Memory free 1.21 Gb Paging File | 0.92 Gb Available in Paging File | 75.72% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 69.79 Gb Total Space | 27.61 Gb Free Space | 39.56% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: D7J9CC91 Current User Name: mary shumate Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.) PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation) PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.) PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation) PRC - C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation) PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe (Musicmatch, Inc.) PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation) PRC - C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation) PRC - C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.) PRC - C:\WINDOWS\System32\dla\tfswctrl.exe (Sonic Solutions) PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe (Musicmatch, Inc.) PRC - C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.) PRC - C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe (Corel, Inc.) PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) PRC - C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD.) PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.) PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation) PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation) PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe (Intel Corporation) PRC - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation) PRC - C:\WINDOWS\System32\UAService7.exe (Sony DADC Austria AG.) PRC - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation) PRC - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation) PRC - C:\WINDOWS\eHome\ehmsas.exe (Microsoft Corporation) PRC - C:\Program Files\MUSICMATCH\Common\ComponentMgr\MMComponentMgr.exe (Musicmatch, Inc.) PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation) PRC - C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (AOL ACS [Auto | Running]) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.) SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation) SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.) SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\System32\ati2sgag.exe () SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (DSBrokerService [On_Demand | Stopped]) -- C:\Program Files\DellSupport\brkrsvc.exe () SRV - (ehRecvr [Auto | Running]) -- C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation) SRV - (ehSched [Auto | Running]) -- C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation) SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google) SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (IAANTMon [Auto | Running]) -- C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe (Intel Corporation) SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (McrdSvc [Auto | Running]) -- C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation) SRV - (MHN [On_Demand | Stopped]) -- C:\WINDOWS\System32\mhn.dll (Microsoft Corporation) SRV - (NetSvc [On_Demand | Stopped]) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation) SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (Norton Internet Security [Auto | Running]) -- C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation) SRV - (UMWdf [On_Demand | Stopped]) -- C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation) SRV - (UserAccess7 [Auto | Running]) -- C:\WINDOWS\System32\UAService7.exe (Sony DADC Austria AG.) ========== Driver Services (SafeList) ========== DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.) DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.) DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.) DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.) DRV - (ASCTRM [Auto | Running]) -- C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider) DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.) DRV - (BHDrvx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\BHDrvx86.sys (Symantec Corporation) DRV - (catchme [On_Demand | Stopped]) -- C:\WINDOWS\catchme.exe () DRV - (ccHP [System | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\ccHPx86.sys (Symantec Corporation) DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.) DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation) DRV - (drvmcdb [Boot | Running]) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions) DRV - (drvnddm [Auto | Running]) -- C:\WINDOWS\System32\drivers\drvnddm.sys (Sonic Solutions) DRV - (DSproct [On_Demand | Stopped]) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.) DRV - (dsunidrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\dsunidrv.sys (Gteko Ltd.) DRV - (E100B [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation) DRV - (e1express [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e1e5132.sys (Intel Corporation) DRV - (eeCtrl [System | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation) DRV - (EraserUtilRebootDrv [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation) DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider) DRV - (iastor [Boot | Running]) -- C:\WINDOWS\system32\drivers\iastor.sys (Intel Corporation) DRV - (IDSxpx86 [System | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090610.006\IDSxpx86.sys (Symantec Corporation) DRV - (IntelC51 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\IntelC51.sys (Intel Corporation) DRV - (IntelC52 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\IntelC52.sys (Intel Corporation) DRV - (IntelC53 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\IntelC53.sys (Intel Corporation) DRV - (MODEMCSA [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\MODEMCSA.sys (Microsoft Corporation) DRV - (mohfilt [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\mohfilt.sys (Intel Corporation) DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.) DRV - (NAVENG [On_Demand | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090628.022\NAVENG.SYS (Symantec Corporation) DRV - (NAVEX15 [On_Demand | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090628.022\NAVEX15.SYS (Symantec Corporation) DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation) DRV - (prodrv06 [System | Running]) -- C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology) DRV - (prohlp02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology) DRV - (prosync1 [Boot | Running]) -- C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology) DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.) DRV - (pxark [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\pxark.sys () DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation) DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation) DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation) DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (sfdrv01 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology) DRV - (sfhlp01 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology) DRV - (sfhlp02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology) DRV - (sfsync02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology) DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation) DRV - (SONYPVU1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS (Sony Corporation) DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.) DRV - (SRTSP [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\SRTSP.SYS (Symantec Corporation) DRV - (SRTSPX [System | Running]) -- C:\WINDOWS\System32\drivers\NIS\1005000.087\SRTSPX.SYS (Symantec Corporation) DRV - (sscdbhk5 [System | Running]) -- C:\WINDOWS\System32\drivers\sscdbhk5.sys (Sonic Solutions) DRV - (ssrtln [System | Running]) -- C:\WINDOWS\System32\drivers\ssrtln.sys (Sonic Solutions) DRV - (STHDA [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\sthda.sys (SigmaTel, Inc.) DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.) DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic) DRV - (SymEFA [Boot | Running]) -- C:\WINDOWS\system32\drivers\NIS\1005000.087\SYMEFA.SYS (Symantec Corporation) DRV - (SymEvent [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\SYMEVENT.SYS (Symantec Corporation) DRV - (SYMFW [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\SYMFW.SYS (Symantec Corporation) DRV - (SYMIDS [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\SYMIDS.SYS (Symantec Corporation) DRV - (SymIM [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\SymIM.sys (Symantec Corporation) DRV - (SymIMMP [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\SymIM.sys (Symantec Corporation) DRV - (SYMNDIS [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\SYMNDIS.SYS (Symantec Corporation) DRV - (SYMTDI [System | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\SYMTDI.SYS (Symantec Corporation) DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic) DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic) DRV - (tfsnboio [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnboio.sys (Sonic Solutions) DRV - (tfsncofs [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsncofs.sys (Sonic Solutions) DRV - (tfsndrct [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsndrct.sys (Sonic Solutions) DRV - (tfsndres [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsndres.sys (Sonic Solutions) DRV - (tfsnifs [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnifs.sys (Sonic Solutions) DRV - (tfsnopio [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnopio.sys (Sonic Solutions) DRV - (tfsnpool [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnpool.sys (Sonic Solutions) DRV - (tfsnudf [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnudf.sys (Sonic Solutions) DRV - (tfsnudfa [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnudfa.sys (Sonic Solutions) DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.) DRV - (wanatw [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.) DRV - (XPAD910 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\xpad910.sys (Compuware Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-06-27 16:43:23 | 00,000,000 | ---D | M] Hosts file not found O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation) O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL (Symantec Corporation) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.) O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation) O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.) O4 - HKLM..\Run: [BuildBU] c:\dell\bldbubg.exe () O4 - HKLM..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe (Corel, Inc.) O4 - HKLM..\Run: [dla] C:\WINDOWS\System32\dla\tfswctrl.exe (Sonic Solutions) O4 - HKLM..\Run: [DVDLauncher] C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.) O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation) O4 - HKLM..\Run: [Google Desktop Search] File not found O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation) O4 - HKLM..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation) O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation) O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation) O4 - HKLM..\Run: [KernelFaultCheck] File not found O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot.exe (Musicmatch, Inc.) O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.) O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.) O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe () O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKCU..\Run: [Uniblue RegistryBooster 2009] File not found O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.) O4 - Startup: C:\Documents and Settings\mary shumate.D7J9CC91.001\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe (Leader Technologies) O4 - Startup: C:\Documents and Settings\mary shumate.D7J9CC91.001\Start Menu\Programs\Startup\PowerReg Scheduler.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskmgr = 0 O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} http://www.worldwinner.com/games/v47/scrab...rabblecubes.cab (ScrabbleCubes Control) O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://mypoints.worldwinner.com/games/v47/...GamesLoader.cab (FunGamesLoader Object) O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} http://disney.go.com/pirates/online/testAc...OnlineGames.cab (Disney Online Games ActiveX Control) O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} http://www.worldwinner.com/games/v47/solit...litairerush.cab (SolitaireRush Control) O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx (get_atlcom Class) O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control) O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/...lscbase6662.cab (Windows Live Safety Center Base Module) O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control) O16 - DPF: {61900274-3323-4446-BDCD-91548D32AF1B} http://www.worldwinner.com/games/v56/spide...ersolitaire.cab (SpiderSolitaire Control) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1220142634718 (MUWebControl Class) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.) O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2_03) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control) O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} http://www.worldwinner.com/games/v67/swapit/swapit.cab (SwapIt Control) O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} http://www.worldwinner.com/games/v45/royal/royal.cab (Royal Control) O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab (MysteryPI Control) O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2_03) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object) O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe (Virtools WebPlayer Class) O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} http://www.worldwinner.com/games/v53/wwspades/wwspades.cab (WWSpades Control) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation) O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {AEA4DE5E-37ED-4A91-A883-6D8953A84614} - Reg Error: Key error. File not found O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005-08-16 05:43:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe -- File not found O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell - "" = AutoRun O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found ========== Files/Folders - Created Within 30 Days ========== [2009-06-29 02:01:35 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\OTL.exe [2009-06-29 01:53:51 | 00,173,119 | ---- | C] (Eric_71) -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\Rooter.exe [2009-06-28 22:15:54 | 05,409,834 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\AutoRuns.arn [2009-06-28 21:34:27 | 00,019,609 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-03.zip [2009-06-28 21:34:22 | 00,024,521 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-02.zip [2009-06-28 21:34:17 | 00,019,925 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-01.zip [2009-06-28 21:34:13 | 00,025,248 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini061109-01.zip [2009-06-28 21:34:07 | 00,015,623 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini052409-01.zip [2009-06-28 21:24:23 | 00,014,668 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini041109-01.zip [2009-06-27 01:26:58 | 00,000,250 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\How to troubleshoot hardware and software driver problems in Windows XP.url [2009-06-11 19:18:02 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe [2009-06-06 08:24:44 | 00,202,072 | R--- | C] (Coupons, Inc.) -- C:\WINDOWS\cpnprt2.cid [2009-06-06 08:24:38 | 00,202,072 | ---- | C] (Coupons, Inc.) -- C:\WINDOWS\System32\cpnprt2.cid [2008-11-12 20:11:51 | 00,000,043 | ---- | C] () -- C:\WINDOWS\juniordisplay.ini [2008-02-11 09:39:26 | 00,253,952 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLA.dll [2008-02-11 09:39:18 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLW.dll [2008-02-08 13:53:46 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerLang.dll [2008-02-04 18:08:59 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll [2007-12-08 17:10:16 | 00,010,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\pxark.sys [2007-07-27 14:49:02 | 00,225,355 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiW.dll [2007-07-27 14:49:02 | 00,196,683 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiA.dll [2007-05-15 12:38:48 | 00,000,653 | ---- | C] () -- C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini [2007-01-28 23:18:21 | 00,000,419 | ---- | C] () -- C:\WINDOWS\PCPHOTO.INI [2006-12-13 09:16:13 | 00,000,813 | ---- | C] () -- C:\WINDOWS\disney.ini [2006-08-27 17:12:05 | 00,000,191 | ---- | C] () -- C:\WINDOWS\QTW.INI [2006-08-11 17:04:13 | 00,000,068 | ---- | C] () -- C:\WINDOWS\TONKA_SR.INI [2006-08-08 12:27:50 | 00,000,523 | ---- | C] () -- C:\WINDOWS\TCII.ini [2006-08-07 16:29:18 | 00,176,128 | ---- | C] () -- C:\WINDOWS\System32\GGE910cp.dll [2006-07-28 12:51:31 | 00,000,377 | ---- | C] () -- C:\WINDOWS\SIERRA.INI [2006-07-26 15:22:42 | 00,000,058 | ---- | C] () -- C:\WINDOWS\Tonka_Raceway.INI [2006-07-25 21:43:27 | 00,000,078 | ---- | C] () -- C:\WINDOWS\TONKA.INI [2006-06-30 22:01:55 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI [2006-05-07 13:15:50 | 00,000,088 | RHS- | C] () -- C:\WINDOWS\System32\BFC9300558.sys [2006-02-22 14:57:37 | 00,006,686 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys [2006-02-22 14:57:37 | 00,000,152 | RHS- | C] () -- C:\WINDOWS\System32\580530C9BF.sys [2006-02-22 14:46:20 | 00,000,138 | ---- | C] () -- C:\WINDOWS\msfsetup.ini [2006-01-30 01:04:08 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2006-01-30 00:22:38 | 00,000,387 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI [2005-12-05 19:25:22 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\lnod32umc.dll [2005-12-05 12:37:10 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\lnod32upd.dll [2005-08-16 05:37:24 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini [2005-08-16 05:18:43 | 00,000,562 | ---- | C] () -- C:\WINDOWS\win.ini [2005-08-16 05:18:41 | 00,000,243 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI [2005-08-05 15:01:54 | 00,239,104 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2005-04-09 18:04:54 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini ========== Files - Modified Within 30 Days ========== [2009-06-29 02:01:56 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\OTL.exe [2009-06-29 01:54:15 | 00,173,119 | ---- | M] (Eric_71) -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\Rooter.exe [2009-06-29 01:51:27 | 00,002,100 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\My eBay.url [2009-06-29 01:48:55 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009-06-29 01:48:23 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009-06-29 01:48:20 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009-06-29 01:48:13 | 53,494,1696 | -HS- | M] () -- C:\hiberfil.sys [2009-06-28 22:27:07 | 01,593,120 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.dat [2009-06-28 22:27:07 | 00,150,428 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.idx [2009-06-28 22:27:06 | 00,519,788 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx [2009-06-28 22:27:05 | 38,730,528 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat [2009-06-28 22:15:57 | 05,409,834 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\AutoRuns.arn [2009-06-28 21:16:26 | 00,019,609 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-03.zip [2009-06-28 21:16:22 | 00,019,925 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-01.zip [2009-06-28 21:16:17 | 00,015,623 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini052409-01.zip [2009-06-28 21:16:09 | 00,024,521 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-02.zip [2009-06-28 21:16:04 | 00,025,248 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini061109-01.zip [2009-06-28 21:15:59 | 00,014,668 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini041109-01.zip [2009-06-28 19:44:18 | 00,000,250 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\How to troubleshoot hardware and software driver problems in Windows XP.url [2009-06-17 11:27:56 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009-06-17 11:27:44 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009-06-11 19:55:24 | 01,582,852 | -H-- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Local Settings\Application Data\IconCache.db [2009-06-11 19:37:18 | 00,197,752 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009-06-11 19:30:49 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2009-06-11 01:35:05 | 00,000,562 | ---- | M] () -- C:\WINDOWS\win.ini [2009-06-10 17:10:59 | 00,624,139 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\100_1262 (2) chair.jpg [2009-06-06 08:24:44 | 00,202,072 | R--- | M] (Coupons, Inc.) -- C:\WINDOWS\cpnprt2.cid [2009-06-06 08:24:38 | 00,202,072 | ---- | M] (Coupons, Inc.) -- C:\WINDOWS\System32\cpnprt2.cid [2009-06-01 11:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe [2009-05-30 15:50:41 | 00,001,495 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\BellSouth Webmail.url < End of report > OLT LIST EXTRA OTL Extras logfile created on: Jun-29 2:02:14 AM - Run 1 OTL by OldTimer - Version 3.0.5.3 Folder = C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000409 | Country: United States | Language: ENU | Date Format: MMM-dd 510.09 Mb Total Physical Memory | 184.79 Mb Available Physical Memory | 36.23% Memory free 1.21 Gb Paging File | 0.92 Gb Available in Paging File | 75.72% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 69.79 Gb Total Space | 27.61 Gb Free Space | 39.56% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: D7J9CC91 Current User Name: mary shumate Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 "AntiVirusDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL (America Online, Inc) C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL (America Online, Inc.) C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL (America Online, Inc.) %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL (America Online, Inc) C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL (America Online, Inc.) C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL (America Online, Inc.) C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation) %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation) C:\Program Files\TrackMania Sunrise\TmSunrise.exe:*:Disabled:TmSunrise () ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player "{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data "{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel "{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault "{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE "{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA "{14374619-0900-4056-BA06-C87C900AF9E6}" = QuickBooks Simple Start Special Edition "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.4.0 "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager "{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold "{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon "{4CEA6811-DFAD-4892-828D-49941FE3B779}" = Intel® PROSet for Wired Connections "{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver "{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}" = Medal of Honor Pacific Assault "{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool "{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver "{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5 "{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal "{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer "{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore "{7914BE1E-F186-4790-B8F4-9F63C52A41C1}" = Medal of Honor Allied Assault Spearhead "{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor "{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport "{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper "{7F34A21F-2DEB-4598-BB19-611D6BD24271}" = Managed DirectX (0900) "{823A68CC-3049-4A6B-8F63-7DC85E4BB1C9}" = Medal of Honor Allied Assault Breakthrough "{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox "{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU "{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio "{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1 "{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12 "{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU "{D3AA158A-9421-4883-8767-E771B0964A1D}" = ImageMixer VCD for FinePix "{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility "{D680C913-5955-469D-9D88-C1940F7506D6}" = RAW FILE CONVERTER LE "{E7E254C0-94AA-4B33-AF6D-5276A169A680}" = TONKA Search & Rescue 2 "{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player "12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player 11 "All ATI Software" = ATI - Software Uninstall Utility "America Online us" = America Online (Choose which version to remove) "AOL Connectivity Services" = AOL Connectivity Services "AOLCoach" = AOL Coach Version 1.0(Build:20040229.1 en) "ATI Display Driver" = ATI Display Driver "B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto "Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0 "Cars - Radiator Springs Adventures" = Cars - Radiator Springs Adventures "Coupon Printer for Windows4.0" = Coupon Printer for Windows "Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver "Dell Game Console" = Dell Game Console "Disney Pirates of the Caribbean Online" = Disney Pirates of the Caribbean Online "EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] "ERUNT_is1" = ERUNT 1.1j "EsetOnlineScanner" = ESET Online Scanner "ESPNMotion" = ESPNMotion "Game Elements GGE910 Wireless PC Control Pad" = Game Elements GGE910 Wireless PC Control Pad "Google Desktop" = Google Desktop "Heroes of the Pacific" = Heroes of the Pacific "HijackThis" = HijackThis 2.0.2 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem "Macromedia Shockwave Player" = Macromedia Shockwave Player "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Midtown Madness 1.0" = Microsoft Midtown Madness "Monster Truck Stunt Rally" = Monster Truck Stunt Rally "Motocross Madness 1.0" = Microsoft Motocross Madness "Motocross Madness 2" = Microsoft Motocross Madness 2 "MSNINST" = MSN "MWASPINT" = MicroStaff WINASPI NT "NASCAR Racing 1999 Edition" = NASCAR Racing 1999 Edition "NIS" = Norton Internet Security "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "PROSet" = Intel® PRO Network Connections Drivers "QuickTime" = QuickTime "RealPlayer 6.0" = RealPlayer Basic "Scholastic's I SPY Fantasy" = Scholastic's I SPY Fantasy "Scholastic's I SPY Junior" = Scholastic's I SPY Junior "Sierra Utilities" = Sierra Utilities "Sky Rangers Jet Simulator" = Sky Rangers Jet Simulator "Sky Rangers Simulator" = Sky Rangers Simulator "SpongeBob SquarePants Employee of the Month" = SpongeBob SquarePants Employee of the Month "StreetPlugin" = Learn2 Player (Uninstall Only) "TmSunrise_is1" = TrackMania Sunrise "Tonka Construction 2" = Tonka Construction 2 "TONKA Monster Trucks" = Uninstall TONKA Monster Trucks "Tonka Raceway" = Tonka Raceway "Tonka Search and Rescue" = Tonka Search and Rescue "TrackMania_is1" = TrackMania "WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell "WildTangent CDA" = WildTangent Web Driver "Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner "Windows Media Format Runtime" = Windows Media Format Runtime "Windows XP Service Pack" = Windows XP Service Pack 3 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - Jun-29 1:51:06 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041 Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration. Error - Jun-29 1:51:06 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041 Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration. Error - Jun-29 2:41:18 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041 Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration. Error - Jun-29 2:41:18 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041 Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration. Error - Jun-29 2:41:18 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041 Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration. Error - Jun-29 2:41:18 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041 Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration. Error - Jun-29 2:48:31 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041 Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration. Error - Jun-29 2:48:31 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041 Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration. Error - Jun-29 2:48:31 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041 Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration. Error - Jun-29 2:48:31 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041 Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration. [ System Events ] Error - Jun-11 9:01:01 PM | Computer Name = D7J9CC91 | Source = System Error | ID = 1003 Description = Error code 1000007e, parameter1 c0000005, parameter2 f73cff8f, parameter3 b81c9c20, parameter4 b81c991c. Error - Jun-20 6:01:53 PM | Computer Name = D7J9CC91 | Source = Print | ID = 6161 Description = The document mhtml:mid://00000020/ owned by mary shumate failed to print on printer HP DeskJet 930C/932C/935C. Data type: NT EMF 1.008. Size of the spool file in bytes: 4465372. Number of bytes printed: 1827028. Total number of pages in the document: 16. Number of pages printed: 1. Client machine: \\D7J9CC91. Win32 error code returned by the print processor: 0 (0x0). Error - Jun-26 6:17:03 PM | Computer Name = D7J9CC91 | Source = Print | ID = 6161 Description = The document SmartSource Coupon owned by mary shumate failed to print on printer HP DeskJet 930C/932C/935C. Data type: NT EMF 1.008. Size of the spool file in bytes: 0. Number of bytes printed: 0. Total number of pages in the document: 0. Number of pages printed: 0. Client machine: \\D7J9CC91. Win32 error code returned by the print processor: 259 (0x103). Error - Jun-26 6:24:14 PM | Computer Name = D7J9CC91 | Source = Print | ID = 6161 Description = The document SmartSource Coupon owned by mary shumate failed to print on printer HP DeskJet 930C/932C/935C. Data type: NT EMF 1.008. Size of the spool file in bytes: 0. Number of bytes printed: 0. Total number of pages in the document: 0. Number of pages printed: 0. Client machine: \\D7J9CC91. Win32 error code returned by the print processor: 259 (0x103). Error - Jun-27 2:05:42 AM | Computer Name = D7J9CC91 | Source = System Error | ID = 1003 Description = Error code 1000007e, parameter1 c0000005, parameter2 f82245ee, parameter3 b8035b30, parameter4 b803582c. Error - Jun-27 3:32:50 PM | Computer Name = D7J9CC91 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'EraserUtilRebootDrv.sys' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. Error - Jun-27 9:07:10 PM | Computer Name = D7J9CC91 | Source = System Error | ID = 1003 Description = Error code 1000007e, parameter1 c0000005, parameter2 f82245ee, parameter3 b80d5b30, parameter4 b80d582c. Error - Jun-28 5:00:01 PM | Computer Name = D7J9CC91 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'EraserUtilRebootDrv.sys' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. Error - Jun-28 11:28:39 PM | Computer Name = D7J9CC91 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'EraserUtilDrv10910.sys' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. Error - Jun-29 2:37:40 AM | Computer Name = D7J9CC91 | Source = Windows Update Agent | ID = 20 Description = Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 8 for Windows XP. < End of report > This post has been edited by jazzy56: Jun 29 2009, 03:30 PM |
|
|
Jul 2 2009, 05:19 PM
Post
#2
|
|
![]() Trusted Helper Posts: 7,986 OS: XP Pro |
Hello jazzy56,
Download the HostsXpert 4.2 - Hosts File Manager.
Next Please run OTL.exe
|
|
|
Jul 2 2009, 08:28 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 78 From: LOUISIANA OS: XP media |
I have downloaded HostsXpert 4.2 - Hosts File Manager but do not see file handling. Help I am a novice about this. thanks
|
|
|
Jul 2 2009, 08:47 PM
Post
#4
|
|
|
Member ![]() ![]() Posts: 78 From: LOUISIANA OS: XP media |
Log listed
All processes killed Error: Unable to interpret <CODE> in the current context! Error: Unable to interpret <:OTLI> in the current context! Error: Unable to interpret <PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)> in the current context! Error: Unable to interpret <O4 - HKLM..\Run: [] File not found> in the current context! Error: Unable to interpret <O4 - HKCU..\Run: [Uniblue RegistryBooster 2009] File not found> in the current context! Error: Unable to interpret <O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun> in the current context! Error: Unable to interpret <O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play> in the current context! Error: Unable to interpret <O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe -- File not found> in the current context! Error: Unable to interpret <O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell - "" = AutoRun> in the current context! Error: Unable to interpret <O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell\AutoRun - "" = Auto&Play> in the current context! Error: Unable to interpret <O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found> in the current context! Error: Unable to interpret <O33 - MountPoints2\F\Shell - "" = AutoRun> in the current context! Error: Unable to interpret <O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play> in the current context! Error: Unable to interpret <O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found> in the current context! ========== FILES ========== C:\DOCUME~1\MARYSH~1.001\Favorites\CHRISTMAS\CHRISTMAS GAMES\SAND CASTLE moved successfully. C:\DOCUME~1\MARYSH~1.001\Favorites\CHRISTMAS\CHRISTMAS GAMES moved successfully. C:\DOCUME~1\MARYSH~1.001\Favorites\CHRISTMAS moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: mary shumate ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: mary shumate.D7J9CC91 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: mary shumate.D7J9CC91.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: mary shumate.D7J9CC91.001 ->Temp folder emptied: 1803209 bytes ->Temporary Internet Files folder emptied: 23802846 bytes ->Java cache emptied: 13425364 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 82584 bytes RecycleBin emptied: 279 bytes Total Files Cleaned = 37.33 mb OTL by OldTimer - Version 3.0.6.2 log created on 07022009_213757 Files\Folders moved on Reboot... Registry entries deleted on Reboot... |
|
|
Jul 3 2009, 01:14 AM
Post
#5
|
|
![]() Trusted Helper Posts: 7,986 OS: XP Pro |
QUOTE I have downloaded HostsXpert 4.2 - Hosts File Manager but do not see file handling. Help I am a novice about this. thanks Not to worry. Leave that for now. Download Lop S&D by Eric_71 and save it to your desktop. Lop S&D will only run on Windows XP and Windows Vista Disable your antivirus and anti-malware programs so they do not interfere with the running of Lop S&D. You can usually do this via a right click on the System Tray icon.
|
|
|
Jul 3 2009, 10:46 AM
Post
#6
|
|
|
Member ![]() ![]() Posts: 78 From: LOUISIANA OS: XP media |
--------------------\\ Lop S&D 4.2.5-0 XP/Vista Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3 X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 2.80GHz ) BIOS : Phoenix ROM BIOS PLUS Version 1.10 A03 USER : mary shumate ( Administrator ) BOOT : Normal boot Antivirus : Norton Internet Security 16.2.0.7 (Not Activated) Firewall : Norton Internet Security 16.2.0.7 (Activated) C:\ (Local Disk) - NTFS - Total:69 Go (Free:28 Go) D:\ (CD or DVD) E:\ (CD or DVD) "C:\Lop SD" ( MAJ : 19-12-2008|23:40 ) Option : [2] ( Jul-03|11:29 ) \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX Deleted! - C:\DOCUME~1\MARYSH~1.001\Cookies\mary_shumate@advertising[1].txt Deleted! - C:\DOCUME~1\MARYSH~1.001\Cookies\mary_shumate@traveladvertising[1].txt - [ Hosts file ] .. Restored! \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ --------------------\\ Listing folders in APPLIC~1 [Jan-30|12:57:] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Corel [Jan-30|12:59:] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Google [Aug-16|05:50:] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities [Mar-16|07:55:] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft [Jan-30|12:43:] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sun [Mar-31|04:37:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {63A9FDE6-FCC7-4E26-A4CF-552A08431B32} [May-02|11:08:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe [Oct-09|11:34:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe(2) [Feb-20|10:00:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe(4) [Apr-12|08:26:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL [Mar-16|07:55:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> avg8 [Aug-16|09:54:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> DIGStream [Mar-16|05:57:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Downloaded Installations [Nov-06|01:39:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> FunGames [Jan-26|12:30:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google [Dec-10|03:46:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Grisoft [Apr-26|07:35:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> GTek [Jan-30|12:52:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield [Jan-30|12:51:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intuit [Aug-30|08:59:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes [Apr-10|05:25:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee [Apr-12|08:33:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com [Feb-20|10:04:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(2) [Feb-20|10:03:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(3) [Feb-20|10:01:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(4) [Feb-20|10:00:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(5) [Feb-20|09:58:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(6) [Feb-20|09:54:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(7) [Aug-29|08:05:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft [Feb-20|10:01:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> MVTLogs [Apr-10|05:39:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Norton [Apr-10|04:51:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> NortonInstaller [May-02|02:35:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> NOS [Feb-22|12:44:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PACE Anti-Piracy [Dec-10|03:13:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Prevx [Jan-30|12:50:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> QuickTime [Apr-02|09:05:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SingleClick Systems [Apr-26|05:58:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Support.com [Apr-10|05:40:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Symantec [Apr-19|10:42:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TEMP [May-14|02:30:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage [Jan-30|12:57:] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Corel [Jan-30|12:59:] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Google [Aug-16|05:50:] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities [Jan-30|12:49:] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft [Jan-30|12:43:] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Sun [Feb-22|01:57:] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> GTek [Feb-22|01:52:] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Macromedia [Mar-16|07:55:] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft [Feb-19|10:03:] C:\DOCUME~1\MARYSH~1\APPLIC~1\<DIR> Adobe [Jan-30|12:57:] C:\DOCUME~1\MARYSH~1\APPLIC~1\<DIR> Corel [Jan-30|12:54:] C:\DOCUME~1\MARYSH~1\APPLIC~1\<DIR> Gtek [Feb-19|09:38:] C:\DOCUME~1\MARYSH~1\APPLIC~1\<DIR> Macromedia [Feb-22|12:45:] C:\DOCUME~1\MARYSH~1\APPLIC~1\<DIR> Microsoft [Jan-30|12:57:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> Corel [Feb-21|04:57:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> Corel Photo Album [Feb-22|12:44:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> FUJIFILM [Jan-30|12:54:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> Gtek [Feb-21|05:25:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> Leadertech [Feb-22|12:44:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> Microsoft [Feb-21|06:00:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> PACE Anti-Piracy [Jan-30|12:57:] C:\DOCUME~1\MARYSH~1.000\APPLIC~1\<DIR> Corel [Jan-30|12:54:] C:\DOCUME~1\MARYSH~1.000\APPLIC~1\<DIR> Gtek [Feb-22|12:43:] C:\DOCUME~1\MARYSH~1.000\APPLIC~1\<DIR> Microsoft [Apr-30|11:31:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Adobe [Oct-09|11:34:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> AdobeUM [Apr-26|05:59:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> BellSouth [Dec-13|01:04:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Corel [Feb-22|03:03:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Corel Photo Album [Feb-22|04:02:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> FUJIFILM [Apr-10|05:32:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> GetRightToGo [Sep-14|12:07:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Google [Dec-10|03:46:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Grisoft [Apr-16|11:11:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Gtek [Mar-29|09:43:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Help [May-12|05:08:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Identities [Sep-09|05:10:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> InstallShield [Apr-18|05:31:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> IObit [Feb-24|04:29:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Leadertech [Apr-30|11:31:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Macromedia [Aug-30|08:59:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Malwarebytes [Feb-18|07:47:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> McAfee [Mar-16|07:55:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Microsoft [Dec-10|03:13:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> PrevxCSI [Sep-28|06:00:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Sonic [Aug-19|07:45:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Sony Corporation [Jan-30|12:43:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Sun [May-17|04:55:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> U3 [Mar-27|08:52:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Uniblue [Mar-30|05:46:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> wsInspector [Apr-18|05:31:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Yahoo! [Mar-16|07:55:] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft --------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks [Apr-19 11:33: AM][--a------] C:\WINDOWS\tasks\Wise Disk Cleaner 4.job [Jul-03 11:02: AM][--ah-----] C:\WINDOWS\tasks\SA.DAT [Aug-10 06:00: AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Listing Folders in C:\Program Files [May-02|11:09:] C:\Program Files\<DIR> Adobe [Aug-30|05:44:] C:\Program Files\<DIR> Alwil Software [Mar-17|01:20:] C:\Program Files\<DIR> America Online 9.0 [Mar-17|01:20:] C:\Program Files\<DIR> AOL Companion [Jun-11|07:17:] C:\Program Files\<DIR> ATI Technologies [Nov-05|10:57:] C:\Program Files\<DIR> Auran [Apr-26|05:59:] C:\Program Files\<DIR> BellSouth [Jan-11|10:54:] C:\Program Files\<DIR> Big Sky Software [Oct-09|11:30:] C:\Program Files\<DIR> Broderbund Software [May-02|11:08:] C:\Program Files\<DIR> Common Files [Oct-14|02:05:] C:\Program Files\<DIR> Corel [Jun-09|07:48:] C:\Program Files\<DIR> Coupons [Jan-30|12:48:] C:\Program Files\<DIR> CyberLink [Mar-12|06:01:] C:\Program Files\<DIR> Decookie [Mar-17|01:20:] C:\Program Files\<DIR> Dell [May-15|12:38:] C:\Program Files\<DIR> Dell Network Assistant [Oct-17|12:02:] C:\Program Files\<DIR> DellConnect [Apr-16|10:56:] C:\Program Files\<DIR> DellSupport [Apr-19|11:41:] C:\Program Files\<DIR> DIGStream [Oct-09|11:29:] C:\Program Files\<DIR> directx [Mar-15|02:51:] C:\Program Files\<DIR> Disney [Dec-13|09:17:] C:\Program Files\<DIR> Disney Interactive [Oct-09|11:34:] C:\Program Files\<DIR> DK Interactive Learning(2) [Aug-06|09:38:] C:\Program Files\<DIR> EA GAMES [Mar-24|06:47:] C:\Program Files\<DIR> EnglishOtto [Apr-18|09:23:] C:\Program Files\<DIR> Enlight [Jun-28|11:04:] C:\Program Files\<DIR> ERUNT [Jun-29|02:50:] C:\Program Files\<DIR> ESET [May-05|03:37:] C:\Program Files\<DIR> EsetOnlineScanner [Apr-19|11:41:] C:\Program Files\<DIR> ESPNMotion [Feb-22|02:44:] C:\Program Files\<DIR> FinePixViewer [Feb-22|12:44:] C:\Program Files\<DIR> FinePixViewer(2) [Nov-22|07:18:] C:\Program Files\<DIR> Fox [May-24|07:30:] C:\Program Files\<DIR> Game Elements [Mar-24|07:18:] C:\Program Files\<DIR> GemMaster [Jan-26|03:05:] C:\Program Files\<DIR> Google [Jan-30|12:59:] C:\Program Files\<DIR> GoogleAFE [May-03|11:08:] C:\Program Files\<DIR> Grisoft [Nov-05|10:58:] C:\Program Files\<DIR> Hasbro Interactive [Aug-27|05:23:] C:\Program Files\<DIR> IBM and Crayola [Oct-09|11:35:] C:\Program Files\<DIR> Infogrames Interactive [Jun-11|07:17:] C:\Program Files\<DIR> InstallShield Installation Information [Jan-30|12:48:] C:\Program Files\<DIR> Intel [Jun-12|11:45:] C:\Program Files\<DIR> Internet Explorer [Jan-30|12:51:] C:\Program Files\<DIR> Intuit [Apr-18|05:31:] C:\Program Files\<DIR> IObit [Apr-11|01:11:] C:\Program Files\<DIR> Java [Jan-30|12:50:] C:\Program Files\<DIR> Learn2.com [Dec-30|12:58:] C:\Program Files\<DIR> LEGO Media [Jun-28|11:10:] C:\Program Files\<DIR> Malwarebytes' Anti-Malware [Aug-06|10:06:] C:\Program Files\<DIR> Managed DirectX (0900) [Apr-10|05:24:] C:\Program Files\<DIR> McAfee [Apr-10|05:35:] C:\Program Files\<DIR> McAfee.com [Aug-31|10:18:] C:\Program Files\<DIR> Messenger [May-27|07:09:] C:\Program Files\<DIR> MFInstall [Aug-16|05:43:] C:\Program Files\<DIR> microsoft frontpage [Mar-29|04:25:] C:\Program Files\<DIR> Microsoft Games [Jan-30|12:49:] C:\Program Files\<DIR> Microsoft Plus! Digital Media Edition [Jan-30|12:49:] C:\Program Files\<DIR> Microsoft Plus! Photo Story 2 LE [Apr-19|11:41:] C:\Program Files\<DIR> Modem Helper [Jan-30|12:48:] C:\Program Files\<DIR> Modem On Hold [Apr-18|10:15:] C:\Program Files\<DIR> Monster Truck Stunt Rally [Aug-31|10:13:] C:\Program Files\<DIR> Movie Maker [Mar-28|08:26:] C:\Program Files\<DIR> MSBuild [Oct-04|01:34:] C:\Program Files\<DIR> MSN [Aug-16|05:37:] C:\Program Files\<DIR> MSN Gaming Zone [Nov-17|05:33:] C:\Program Files\<DIR> MSXML 4.0 [Jan-30|12:54:] C:\Program Files\<DIR> MUSICMATCH [Aug-31|10:10:] C:\Program Files\<DIR> NetMeeting [Oct-17|06:30:] C:\Program Files\<DIR> NetZeroInstallers [Apr-10|05:38:] C:\Program Files\<DIR> Norton Internet Security [Apr-11|09:58:] C:\Program Files\<DIR> Norton Support [Apr-10|05:31:] C:\Program Files\<DIR> NortonInstaller [May-02|02:35:] C:\Program Files\<DIR> NOS [Dec-01|01:55:] C:\Program Files\<DIR> Online Services [Aug-31|10:10:] C:\Program Files\<DIR> Outlook Express [Feb-21|02:06:] C:\Program Files\<DIR> PIXELA [Mar-15|10:54:] C:\Program Files\<DIR> PopCap Games [Feb-22|12:45:] C:\Program Files\<DIR> QuickTime [Jan-30|12:50:] C:\Program Files\<DIR> Real [Mar-28|08:26:] C:\Program Files\<DIR> Reference Assemblies [Feb-19|04:54:] C:\Program Files\<DIR> RegistryFix [Feb-22|02:43:] C:\Program Files\<DIR> REGSHAVE [Aug-16|09:58:] C:\Program Files\<DIR> RGB [Feb-23|02:59:] C:\Program Files\<DIR> Scholastic [Nov-19|09:14:] C:\Program Files\<DIR> Sierra On-Line [Jan-30|12:45:] C:\Program Files\<DIR> Sigmatel [Mar-17|01:21:] C:\Program Files\<DIR> SimTheme Park [Jan-30|12:52:] C:\Program Files\<DIR> Sonic [Aug-30|06:21:] C:\Program Files\<DIR> SpywareDetector [Mar-30|05:48:] C:\Program Files\<DIR> Startup Inspector for Windows [Apr-26|09:30:] C:\Program Files\<DIR> Support.com [Apr-23|06:38:] C:\Program Files\<DIR> Symantec [Feb-04|06:02:] C:\Program Files\<DIR> The Learning Company [Oct-09|11:29:] C:\Program Files\<DIR> THQ [Mar-30|05:51:] C:\Program Files\<DIR> TrackMania Sunrise [Mar-30|05:50:] C:\Program Files\<DIR> TrackMania Sunrise(2)(2) [Mar-30|05:50:] C:\Program Files\<DIR> TrackMania Sunrise(3) [Dec-09|06:13:] C:\Program Files\<DIR> Trend Micro [Nov-21|03:09:] C:\Program Files\<DIR> Ubisoft [Aug-28|11:45:] C:\Program Files\<DIR> Uninstall Information [Oct-09|11:29:] C:\Program Files\<DIR> ValuSoft [Apr-13|07:26:] C:\Program Files\<DIR> Virtools Web Player 3.5 [Jan-30|12:54:] C:\Program Files\<DIR> WebCyberCoach [Mar-12|05:11:] C:\Program Files\<DIR> WildTangent [Mar-16|12:08:] C:\Program Files\<DIR> Windows Live Safety Center [Dec-30|01:26:] C:\Program Files\<DIR> Windows Media Player [Aug-31|10:10:] C:\Program Files\<DIR> Windows NT [Aug-16|05:37:] C:\Program Files\<DIR> Windows Plus [Apr-10|05:38:] C:\Program Files\<DIR> Windows Sidebar [Feb-21|06:47:] C:\Program Files\<DIR> WindowsUpdate [Jan-30|12:53:] C:\Program Files\<DIR> WordPerfect Office 12 [Aug-16|05:43:] C:\Program Files\<DIR> xerox [Apr-19|10:09:] C:\Program Files\<DIR> Yahoo! [Jul-22|05:49:] C:\Program Files\<DIR> Zero G Registry --------------------\\ Listing Folders in C:\Program Files\Common Files [May-02|11:07:] C:\Program Files\Common Files\<DIR> Adobe [May-02|11:08:] C:\Program Files\Common Files\<DIR> Adobe AIR [Jan-30|12:51:] C:\Program Files\Common Files\<DIR> AnswerWorks 4.0 [Apr-12|08:31:] C:\Program Files\Common Files\<DIR> AOL [Apr-12|08:31:] C:\Program Files\Common Files\<DIR> aolshare [Jan-30|12:52:] C:\Program Files\Common Files\<DIR> Borland Shared [Oct-14|02:05:] C:\Program Files\Common Files\<DIR> Corel [Aug-30|08:04:] C:\Program Files\Common Files\<DIR> Download Manager [Apr-19|11:41:] C:\Program Files\Common Files\<DIR> EasyInfo [Jan-30|12:53:] C:\Program Files\Common Files\<DIR> InstallShield [Jan-30|12:51:] C:\Program Files\Common Files\<DIR> Intuit [Jan-30|12:42:] C:\Program Files\Common Files\<DIR> Java [Mar-10|03:28:] C:\Program Files\Common Files\<DIR> Microsoft Shared [Apr-26|09:30:] C:\Program Files\Common Files\<DIR> Motive [Aug-16|05:40:] C:\Program Files\Common Files\<DIR> MSSoap [Jan-30|12:50:] C:\Program Files\Common Files\<DIR> Nullsoft [Aug-16|05:33:] C:\Program Files\Common Files\<DIR> ODBC [Feb-21|05:57:] C:\Program Files\Common Files\<DIR> PACE Anti-Piracy [Apr-10|10:30:] C:\Program Files\Common Files\<DIR> ParetoLogic [Jan-30|12:50:] C:\Program Files\Common Files\<DIR> Real [Aug-16|05:40:] C:\Program Files\Common Files\<DIR> Services [Jan-30|12:52:] C:\Program Files\Common Files\<DIR> Sonic Shared [Aug-16|05:33:] C:\Program Files\Common Files\<DIR> SpeechEngines [Feb-22|02:36:] C:\Program Files\Common Files\<DIR> SWF Studio [Apr-10|05:46:] C:\Program Files\Common Files\<DIR> Symantec Shared [Aug-31|10:10:] C:\Program Files\Common Files\<DIR> System --------------------\\ Process ( 48 Processes ) ... OK ! --------------------\\ Searching with S_Lop No Lop folder found ! --------------------\\ Searching for Lop Files - Folders No Lop folder found ! --------------------\\ Searching within the Registry ..... OK ! --------------------\\ Checking the Hosts file Hosts file CLEAN --------------------\\ Searching for hidden files with Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-03 11:32:34 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 0 --------------------\\ Searching for other infections No other infections found ! [F:2][D:0]-> C:\DOCUME~1\MARYSH~1.001\LOCALS~1\Temp [F:1059][D:0]-> C:\DOCUME~1\MARYSH~1.001\Cookies [F:3149][D:4]-> C:\DOCUME~1\MARYSH~1.001\LOCALS~1\TEMPOR~1\content.IE5 1 - "C:\Lop SD\LopR_1.txt" - Jul-03|11:34 - Option : [2] --------------------\\ Scan completed at 11:34:42 This post has been edited by jazzy56: Jul 3 2009, 12:07 PM |
|
|
Jul 3 2009, 03:08 PM
Post
#7
|
|
![]() Trusted Helper Posts: 7,986 OS: XP Pro |
Hello jazzy56,
Please download ComboFix from one of these locations: NOTE: If you are guest watching this topic. ComboFix is a very powerful tool. The disclaimer clearly states that you should not use it without supervision. There is good reason for this as ComboFix can, and sometimes does, run into conflict on a computer and render it unusable. Link 1 Link 2 Link 3 * IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply. |
|
|
Jul 3 2009, 04:00 PM
Post
#8
|
|
|
Member ![]() ![]() Posts: 78 From: LOUISIANA OS: XP media |
Ran combo fix --- at the notepad screen a grey boz appeared --
cannot find the C: Docune~marysh~1-001\locals~temp\log b t.file Do you want to create a new folder yes No I said yes.. after 15 minutes with no sign of activity i had to push reset to close down. Do you want me to try again. Thank You |
|
|
Jul 3 2009, 04:25 PM
Post
#9
|
|
|
Member ![]() ![]() Posts: 78 From: LOUISIANA OS: XP media |
Was finally able to RUN COMBOFIX, Please find Log Below.
ComboFix 09-07-03.03 - mary shumate Jul-03 17:03.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.157 [GMT -5:00] Running from: c:\documents and settings\mary shumate.D7J9CC91.001\My Documents\ComboFix.exe AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} . ((((((((((((((((((((((((( Files Created from 2009-06-03 to 2009-07-03 ))))))))))))))))))))))))))))))) . 2009-07-03 16:15 . 2009-04-11 16:05 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\NAVENG.SYS 2009-07-03 16:15 . 2009-04-11 16:05 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\NAVEX15.SYS 2009-07-03 16:15 . 2009-04-11 16:05 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\NAVENG32.DLL 2009-07-03 16:15 . 2009-04-11 16:05 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\NAVEX32A.DLL 2009-07-03 16:14 . 2009-04-11 16:05 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\EECTRL.SYS 2009-07-03 16:14 . 2009-04-11 16:05 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\ECMSVR32.DLL 2009-07-03 16:14 . 2009-04-11 16:05 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\CCERASER.DLL 2009-07-03 16:14 . 2009-04-11 16:05 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\ERASER.SYS 2009-07-03 16:13 . 2009-07-03 16:34 -------- d-----w- C:\Lop SD 2009-07-03 02:37 . 2009-07-03 02:37 -------- d-----w- C:\_OTL 2009-07-03 02:31 . 2009-07-03 02:31 -------- d-----w- C:\HostsXpert 4.2 - Hosts File Manager 2009-07-03 02:30 . 2009-07-03 02:30 353485 ----a-w- C:\HostsXpert 4.2 -.zip 2009-07-03 02:24 . 2009-07-03 02:24 353485 ----a-w- C:\HostsXpert 4.2 - Hosts File Manager.zip 2009-07-02 14:02 . 2009-07-02 14:01 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-06-30 22:34 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll 2009-06-30 22:34 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys 2009-06-30 22:34 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys 2009-06-30 22:34 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll 2009-06-30 22:34 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys 2009-06-30 16:29 . 2009-06-30 16:29 152576 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\Sun\Java\jre1.6.0_12\lzma.dll 2009-06-29 19:50 . 2009-06-29 19:50 -------- d-----w- c:\program files\ESET 2009-06-27 20:48 . 2009-06-27 20:48 -------- d-----w- c:\windows\system32\wbem\Repository 2009-06-13 02:49 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\Scxpx86.dll 2009-06-13 02:49 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys 2009-06-13 02:49 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSvix86.sys 2009-06-13 02:49 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSxpx86.dll 2009-06-13 02:49 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSviA64.sys 2009-06-12 00:18 . 2006-02-10 02:05 520192 ------w- c:\windows\system32\ati2sgag.exe 2009-06-08 18:56 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\Scxpx86.dll 2009-06-08 18:56 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSXpx86.sys 2009-06-08 18:56 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSvix86.sys 2009-06-08 18:56 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSxpx86.dll 2009-06-08 18:56 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSviA64.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-02 13:59 . 2009-04-11 18:10 152576 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-06-29 04:10 . 2009-03-23 00:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-29 04:04 . 2009-05-02 20:54 -------- d-----w- c:\program files\ERUNT 2009-06-29 03:27 . 2009-04-10 15:11 1593120 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-06-29 03:27 . 2009-04-10 15:11 150428 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-06-29 03:27 . 2009-04-10 15:11 519788 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-06-29 03:27 . 2009-04-10 15:11 38730528 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-06-27 22:05 . 2009-03-30 23:59 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-06-17 16:27 . 2009-03-23 00:23 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-17 16:27 . 2009-03-23 00:23 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-12 00:17 . 2006-01-30 05:47 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-12 00:17 . 2006-01-30 05:48 -------- d-----w- c:\program files\ATI Technologies 2009-06-10 00:48 . 2008-06-12 00:02 -------- d-----w- c:\program files\Coupons 2009-05-25 00:30 . 2007-11-19 05:58 -------- d-----w- c:\program files\Game Elements 2009-05-22 23:18 . 2006-02-22 19:57 6686 --sha-w- c:\windows\system32\KGyGaAvL.sys 2009-05-22 23:18 . 2006-02-22 19:57 152 --sh--r- c:\windows\system32\580530C9BF.sys 2009-05-17 21:55 . 2009-05-17 21:55 -------- d-----w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\U3 2009-05-07 15:32 . 2005-08-16 10:18 345600 ----a-w- c:\windows\system32\localspl.dll 2009-05-05 20:37 . 2009-05-05 03:43 -------- d-----w- c:\program files\EsetOnlineScanner 2009-04-29 04:56 . 2005-08-16 10:18 827392 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:55 . 2009-05-02 23:39 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-04-17 12:26 . 2009-03-11 17:38 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2005-08-16 10:18 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-11 15:10 . 2009-04-10 22:39 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL 2009-04-11 15:10 . 2009-04-10 22:39 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2009-04-10 22:39 . 2009-04-10 22:39 1290584 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll 2009-04-10 22:39 . 2009-04-10 22:39 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll 2009-04-10 22:39 . 2009-04-10 22:39 800112 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll 2009-04-10 14:58 . 2006-02-22 20:03 43128 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2008-02-12 00:15 . 2006-05-07 18:15 88 --sh--r- c:\windows\system32\BFC9300558.sys . ((((((((((((((((((((((((((((( SnapShot@2009-07-03_21.33.25 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-03 21:51 . 2009-07-03 21:51 16384 c:\windows\Temp\Perflib_Perfdata_730.dat + 2009-07-03 21:51 . 2009-07-03 21:51 16384 c:\windows\Temp\Perflib_Perfdata_6e8.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-05 68856] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-30 98304] "REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248] "MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920] "IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-05 1838592] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035] "BuildBU"="c:\dell\bldbubg.exe" [2006-01-30 61440] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-02 148888] "RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-01-30 26112] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 106496] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968] c:\documents and settings\mary shumate.D7J9CC91.001\Start Menu\Programs\Startup\ PowerReg Scheduler V3.exe [2006-8-19 225280] PowerReg Scheduler.exe [2006-9-15 256000] c:\documents and settings\All Users\Start Menu\Programs\Startup\ America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-1-30 156784] Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe [2006-2-22 200704] QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "c:\\Program Files\\America Online 9.0\\waol.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"= R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [Apr-11 10:10 AM 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [Apr-11 10:09 AM 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [Apr-11 10:09 AM 482352] R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [Jun-30 5:34 PM 276344] R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [Apr-11 10:09 AM 115560] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [Jun-28 8:34 PM 101936] S0 xbdpv;xbdpv;c:\windows\system32\drivers\viwopzuv.sys --> c:\windows\system32\drivers\viwopzuv.sys [?] S3 papycpu;papycpu; [x] S3 pxark;pxark;c:\windows\system32\drivers\pxark.sys [Dec-08 5:10 PM 10624] S3 XPAD910;XPADFilter Service 910;c:\windows\system32\drivers\xpad910.sys [Aug-16 4:35 PM 29405] . - - - - ORPHANS REMOVED - - - - ShellExecuteHooks-{AEA4DE5E-37ED-4A91-A883-6D8953A84614} - (no file) . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uStart Page = hxxp://google.com/ uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/search?q=%s DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-03 17:16 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Norton Internet Security] "ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1016) c:\windows\system32\cscdll.dll . Completion time: 2009-07-03 17:22 ComboFix-quarantined-files.txt 2009-07-03 22:22 ComboFix2.txt 2009-07-03 21:39 Pre-Run: 30,148,526,080 bytes free Post-Run: 30,131,781,632 bytes free 171 --- E O F --- 2009-06-06 13:07 |
|
|
Jul 3 2009, 08:11 PM
Post
#10
|
|
![]() Trusted Helper Posts: 7,986 OS: XP Pro |
Hello jazzy56,
1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: QUOTE KillAll:: Driver:: xbdpv papycpu File:: c:\windows\system32\drivers\viwopzuv.sys Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it will produce a log for you at C:\ComboFix.txt. Please post that here for further review. |
|
|
Jul 3 2009, 09:40 PM
Post
#11
|
|
|
Member ![]() ![]() Posts: 78 From: LOUISIANA OS: XP media |
How do I disable Malwarebytes, Do you also mean to disable Internet Explorer.. How do I do that. Thank you
|
|
|
Jul 3 2009, 11:02 PM
Post
#12
|
|
|
Member ![]() ![]() Posts: 78 From: LOUISIANA OS: XP media |
Hello, Here is the log: I disabled Nortons Antivirus & spyware.
ComboFix 09-07-03.03 - mary shumate Jul-03 23:25.5 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.221 [GMT -5:00] Running from: c:\documents and settings\mary shumate.D7J9CC91.001\My Documents\ComboFix.exe Command switches used :: c:\documents and settings\mary shumate.D7J9CC91.001\Desktop\CFScript.txt AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} FILE :: "c:\windows\system32\drivers\viwopzuv.sys" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_papycpu -------\Service_xbdpv ((((((((((((((((((((((((( Files Created from 2009-06-04 to 2009-07-04 ))))))))))))))))))))))))))))))) . 2009-07-03 23:15 . 2009-04-11 16:05 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\NAVENG.SYS 2009-07-03 23:15 . 2009-04-11 16:05 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\NAVEX15.SYS 2009-07-03 23:15 . 2009-04-11 16:05 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\NAVENG32.DLL 2009-07-03 23:15 . 2009-04-11 16:05 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\NAVEX32A.DLL 2009-07-03 23:15 . 2009-04-11 16:05 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\EECTRL.SYS 2009-07-03 23:15 . 2009-04-11 16:05 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\ECMSVR32.DLL 2009-07-03 23:15 . 2009-04-11 16:05 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\CCERASER.DLL 2009-07-03 23:15 . 2009-04-11 16:05 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\ERASER.SYS 2009-07-03 16:13 . 2009-07-03 16:34 -------- d-----w- C:\Lop SD 2009-07-03 02:37 . 2009-07-03 02:37 -------- d-----w- C:\_OTL 2009-07-03 02:31 . 2009-07-03 02:31 -------- d-----w- C:\HostsXpert 4.2 - Hosts File Manager 2009-07-03 02:30 . 2009-07-03 02:30 353485 ----a-w- C:\HostsXpert 4.2 -.zip 2009-07-03 02:24 . 2009-07-03 02:24 353485 ----a-w- C:\HostsXpert 4.2 - Hosts File Manager.zip 2009-07-02 14:02 . 2009-07-02 14:01 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-06-30 22:34 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll 2009-06-30 22:34 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys 2009-06-30 22:34 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys 2009-06-30 22:34 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll 2009-06-30 22:34 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys 2009-06-30 16:29 . 2009-06-30 16:29 152576 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\Sun\Java\jre1.6.0_12\lzma.dll 2009-06-29 19:50 . 2009-06-29 19:50 -------- d-----w- c:\program files\ESET 2009-06-27 20:48 . 2009-06-27 20:48 -------- d-----w- c:\windows\system32\wbem\Repository 2009-06-13 02:49 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\Scxpx86.dll 2009-06-13 02:49 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys 2009-06-13 02:49 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSvix86.sys 2009-06-13 02:49 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSxpx86.dll 2009-06-13 02:49 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSviA64.sys 2009-06-12 00:18 . 2006-02-10 02:05 520192 ------w- c:\windows\system32\ati2sgag.exe 2009-06-08 18:56 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\Scxpx86.dll 2009-06-08 18:56 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSXpx86.sys 2009-06-08 18:56 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSvix86.sys 2009-06-08 18:56 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSxpx86.dll 2009-06-08 18:56 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSviA64.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-02 13:59 . 2009-04-11 18:10 152576 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-06-29 04:10 . 2009-03-23 00:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-29 04:04 . 2009-05-02 20:54 -------- d-----w- c:\program files\ERUNT 2009-06-29 03:27 . 2009-04-10 15:11 1593120 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-06-29 03:27 . 2009-04-10 15:11 150428 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-06-29 03:27 . 2009-04-10 15:11 519788 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-06-29 03:27 . 2009-04-10 15:11 38730528 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-06-27 22:05 . 2009-03-30 23:59 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-06-17 16:27 . 2009-03-23 00:23 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-17 16:27 . 2009-03-23 00:23 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-12 00:17 . 2006-01-30 05:47 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-12 00:17 . 2006-01-30 05:48 -------- d-----w- c:\program files\ATI Technologies 2009-06-10 00:48 . 2008-06-12 00:02 -------- d-----w- c:\program files\Coupons 2009-05-25 00:30 . 2007-11-19 05:58 -------- d-----w- c:\program files\Game Elements 2009-05-22 23:18 . 2006-02-22 19:57 6686 --sha-w- c:\windows\system32\KGyGaAvL.sys 2009-05-22 23:18 . 2006-02-22 19:57 152 --sh--r- c:\windows\system32\580530C9BF.sys 2009-05-17 21:55 . 2009-05-17 21:55 -------- d-----w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\U3 2009-05-07 15:32 . 2005-08-16 10:18 345600 ----a-w- c:\windows\system32\localspl.dll 2009-05-05 20:37 . 2009-05-05 03:43 -------- d-----w- c:\program files\EsetOnlineScanner 2009-04-29 04:56 . 2005-08-16 10:18 827392 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:55 . 2009-05-02 23:39 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-04-17 12:26 . 2009-03-11 17:38 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2005-08-16 10:18 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-11 15:10 . 2009-04-10 22:39 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL 2009-04-11 15:10 . 2009-04-10 22:39 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2009-04-10 22:39 . 2009-04-10 22:39 1290584 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll 2009-04-10 22:39 . 2009-04-10 22:39 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll 2009-04-10 22:39 . 2009-04-10 22:39 800112 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll 2009-04-10 14:58 . 2006-02-22 20:03 43128 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2008-02-12 00:15 . 2006-05-07 18:15 88 --sh--r- c:\windows\system32\BFC9300558.sys . ((((((((((((((((((((((((((((( SnapShot@2009-07-03_21.33.25 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-04 04:44 . 2009-07-04 04:44 16384 c:\windows\Temp\Perflib_Perfdata_69c.dat + 2009-07-04 04:44 . 2009-07-04 04:44 16384 c:\windows\Temp\Perflib_Perfdata_618.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-05 68856] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-30 98304] "REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248] "MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920] "IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-05 1838592] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035] "BuildBU"="c:\dell\bldbubg.exe" [2006-01-30 61440] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-02 148888] "RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-01-30 26112] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 106496] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968] c:\documents and settings\mary shumate.D7J9CC91.001\Start Menu\Programs\Startup\ PowerReg Scheduler V3.exe [2006-8-19 225280] PowerReg Scheduler.exe [2006-9-15 256000] c:\documents and settings\All Users\Start Menu\Programs\Startup\ America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-1-30 156784] Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe [2006-2-22 200704] QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "c:\\Program Files\\America Online 9.0\\waol.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"= R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [Apr-11 10:10 AM 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [Apr-11 10:09 AM 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [Apr-11 10:09 AM 482352] R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [Jun-30 5:34 PM 276344] R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [Apr-11 10:09 AM 115560] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [Jun-28 8:34 PM 101936] S3 pxark;pxark;c:\windows\system32\drivers\pxark.sys [Dec-08 5:10 PM 10624] S3 XPAD910;XPADFilter Service 910;c:\windows\system32\drivers\xpad910.sys [Aug-16 4:35 PM 29405] . - - - - ORPHANS REMOVED - - - - ShellExecuteHooks-{AEA4DE5E-37ED-4A91-A883-6D8953A84614} - (no file) . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uStart Page = hxxp://google.com/ uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/search?q=%s DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-03 23:44 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Norton Internet Security] "ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1" . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe c:\windows\ehome\ehrecvr.exe c:\windows\ehome\ehSched.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files\Java\jre6\bin\jqs.exe c:\progra~1\MUSICM~1\MUSICM~3\MMDiag.exe c:\program files\MUSICMATCH\Musicmatch Jukebox\mim.exe c:\windows\system32\UAService7.exe c:\windows\ehome\mcrdsvc.exe c:\windows\system32\dllhost.exe c:\windows\ehome\ehmsas.exe . ************************************************************************** . Completion time: 2009-07-04 23:57 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-04 04:56 ComboFix2.txt 2009-07-03 22:22 ComboFix3.txt 2009-07-03 21:39 Pre-Run: 30,297,505,792 bytes free Post-Run: 30,337,126,400 bytes free 193 --- E O F --- 2009-06-06 13:07 |
|
|
Jul 3 2009, 11:40 PM
Post
#13
|
|
![]() Trusted Helper Posts: 7,986 OS: XP Pro |
QUOTE How do I disable Malwarebytes, Do you also mean to disable Internet Explorer.. How do I do that. Thank you Malwarebytes (the free edition) is not a real time anti-malware program i.e. it is disabled unless you are running a scan with it. Internet Explorer is a browser not an anti-malware program. Now You have used Malwarebytes before. If you still have it on your machine please update and run. Post the scan report back here. If you no-longer have Malwarebytes please download from Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Next Kaspersky on line scanner is very thorough. It can take a long time and for periods may seem not to be working. Just be patient and let it do its job. Kaspersky works with Internet Explorer and Firefox 3. Go to Kaspersky website and perform an online antivirus scan. Note: you will need to turn off your security programs to allow Kaspersky to do its job.
So when you return please post
|
|
|
Jul 4 2009, 12:14 AM
Post
#14
|
|
|
Member ![]() ![]() Posts: 78 From: LOUISIANA OS: XP media |
Here is the MBAM log it was Clean However I have 68 infections in Quarantine from previous runs.. Can these be removed.?? Thank You Kapersky will follow as soon as I finish running it.
Malwarebytes' Anti-Malware 1.38 Database version: 2371 Windows 5.1.2600 Service Pack 3 Jul-04 1:06:24 AM mbam-log-2009-07-04 (01-06-24).txt Scan type: Quick Scan Objects scanned: 109351 Time elapsed: 6 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
Jul 4 2009, 12:22 AM
Post
#15
|
|
|
Member ![]() ![]() Posts: 78 From: LOUISIANA OS: XP media |
I cannot run Kapersky !!! A box appeared with this inside.
Starting Java applet has failed, please go online to use this program.. I am online with DSL. HELP !!!! I tried going to thier website , it said download java 1.5 or more, I downloaded Jave again and same thing applet has failed.. No change, I cannot run Kapersky. My apology for taking so much of your time. This post has been edited by jazzy56: Jul 4 2009, 12:54 AM |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
7 / 975 | 18th May 2009 - 10:47 AM doubleleo started - last by admin |
|||||
![]() |
16 / 397 | 23rd June 2009 - 10:29 AM logari started - last by Rorschach112 |
|||||
![]() |
19 / 544 | 1st September 2009 - 11:25 AM dogman2828 started - last by Essexboy |
|||||
![]() |
3 / 519 | 17th September 2009 - 12:27 AM duke2050 started - last by hammerman |
|||||
|
Time is now: 7th November 2009 - 03:29 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising