Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
   
4 Pages V   1 2 3 > »   
Closed TopicStart new topic
Malware / Unknown cannot download photo's + Twitching [Solved], Google Toolbar disappeared , Freezes up ,Very Slow
jazzy56
post Jun 29 2009, 02:28 AM
Post #1


Member
**
Posts: 78
From: LOUISIANA
OS: XP media



Hi, My computer is very very slow and getting worse. I Had to use System Restore ( safe mode) after recieving the BD Screen 2x while windows tried to load.. I tried to load photos from my memory card to pc and nothing happened, I then opened Corel album 6, and tried to download from my camera, autoplay showed up in a box with a flashlight, it then disappeared. I tried again using the memory card only said No PC card!!! What.. .. My Google toolbar has disappeared, it is still in drop down list but it will not open. I tried all googles advice on toolbar, so far no good. I have run Malwarebytes, it is clean. My printer also printed some data in English with a single line of a foreign language on same paper. There are probably many more errors that I have not found. Help. I Appreciate any help. thanks
All this happened before I ran the Malware removal,now, I tried to download my photo's but nothing happened. The speed is slightly better, but still freezes up and causes long waits. There is also skaking or twitching of text and cursor, Google will still not work. Also on shut down grey boxes appear End Program Shellconhidden ?, and ccSvchost, both are gray boxes and appear every time. HELP !!!

I also noticed on OLT that I have all the virus apps. I have ever tried, are these active even though i deleted then/ uninstalled them.. I Appreciate any help. thanks


Page Size are now bigger than my screen !!!! HELP


Malwarebytes' Anti-Malware 1.38
Database version: 2347
Windows 5.1.2600 Service Pack 3

Jun-28 11:21:54 PM
mbam-log-2009-06-28 (23-21-54).txt

Scan type: Quick Scan
Objects scanned: 107043
Time elapsed: 9 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



ROOTER LIST

Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows XP . (5.1.2600) Service Pack 3
[32_bits] - x86 Family 15 Model 4 Stepping 4, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Disabled !
.
Internet Explorer 7.0.5730.11
.
C:\ [Fixed-NTFS] .. ( Total:69 Go - Free:27 Go )
D:\ [CD_Rom]
E:\ [CD_Rom]
.
Scan : 01:54.42
Path : C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\Rooter.exe
User : mary shumate ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (936)
______ \??\C:\WINDOWS\system32\csrss.exe (984)
______ \??\C:\WINDOWS\system32\winlogon.exe (1020)
______ C:\WINDOWS\system32\services.exe (1064)
______ C:\WINDOWS\system32\lsass.exe (1076)
______ C:\WINDOWS\system32\Ati2evxx.exe (1292)
______ C:\WINDOWS\system32\svchost.exe (1308)
______ C:\WINDOWS\system32\svchost.exe (1408)
______ C:\WINDOWS\System32\svchost.exe (1548)
______ C:\WINDOWS\system32\svchost.exe (1652)
______ C:\WINDOWS\system32\svchost.exe (1808)
______ C:\WINDOWS\system32\spoolsv.exe (2032)
______ C:\WINDOWS\Explorer.EXE (296)
______ C:\WINDOWS\stsystra.exe (492)
______ C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (636)
______ C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (644)
______ C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe (652)
______ C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (660)
______ C:\WINDOWS\ehome\ehtray.exe (680)
______ C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (696)
______ C:\WINDOWS\system32\dla\tfswctrl.exe (708)
______ C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe (720)
______ C:\Program Files\Real\RealPlayer\RealPlay.exe (796)
______ C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe (836)
______ C:\WINDOWS\system32\ctfmon.exe (892)
______ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (908)
______ C:\Program Files\FinePixViewer\QuickDCF.exe (1144)
______ C:\WINDOWS\system32\svchost.exe (1520)
______ C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe (1580)
______ C:\WINDOWS\eHome\ehRecvr.exe (1420)
______ C:\WINDOWS\eHome\ehSched.exe (1732)
______ C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe (1884)
______ C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (1968)
______ C:\WINDOWS\system32\svchost.exe (2052)
______ C:\WINDOWS\system32\UAService7.exe (2124)
______ C:\WINDOWS\ehome\mcrdsvc.exe (2316)
______ C:\WINDOWS\system32\svchost.exe (2808)
______ C:\WINDOWS\system32\dllhost.exe (2840)
______ C:\WINDOWS\System32\alg.exe (3168)
______ C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (3976)
______ C:\WINDOWS\eHome\ehmsas.exe (3308)
______ C:\PROGRA~1\MUSICM~1\Common\COMPON~1\MMCOMP~1.EXE (2676)
______ C:\Program Files\Internet Explorer\IEXPLORE.EXE (3556)
______ C:\WINDOWS\system32\wbem\wmiprvse.exe (284)
______ C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\Rooter.exe (1228)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:57544704)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:57576960 | Length:74940526080)
\Device\Harddisk0\Partition3 (Start_Offset:75006328320 | Length:4984519680)
.
----------------------\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Tasks\Wise Disk Cleaner 4.job
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
C:\DOCUME~1\MARYSH~1.001\Favorites\CHRISTMAS\CHRISTMAS GAMES\The Twelve Days of Christmas - The Nutcracker Game.url
==> Cracks & Keygens <==
.
----------------------\\ Scan completed at 01:55.36
.
C:\Rooter$\Rooter_1.txt - (29/06/2009 | 01:55.36).c




OLT LIST



OTL logfile created on: Jun-29 2:02:14 AM - Run 1
OTL by OldTimer - Version 3.0.5.3 Folder = C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MMM-dd

510.09 Mb Total Physical Memory | 184.79 Mb Available Physical Memory | 36.23% Memory free
1.21 Gb Paging File | 0.92 Gb Available in Paging File | 75.72% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 27.61 Gb Free Space | 39.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D7J9CC91
Current User Name: mary shumate
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
PRC - C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
PRC - C:\WINDOWS\System32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe (Corel, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD.)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe (Intel Corporation)
PRC - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\System32\UAService7.exe (Sony DADC Austria AG.)
PRC - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\eHome\ehmsas.exe (Microsoft Corporation)
PRC - C:\Program Files\MUSICMATCH\Common\ComponentMgr\MMComponentMgr.exe (Musicmatch, Inc.)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AOL ACS [Auto | Running]) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DSBrokerService [On_Demand | Stopped]) -- C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ehRecvr [Auto | Running]) -- C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) -- C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IAANTMon [Auto | Running]) -- C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (McrdSvc [Auto | Running]) -- C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) -- C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (NetSvc [On_Demand | Stopped]) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (Norton Internet Security [Auto | Running]) -- C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation)
SRV - (UMWdf [On_Demand | Stopped]) -- C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
SRV - (UserAccess7 [Auto | Running]) -- C:\WINDOWS\System32\UAService7.exe (Sony DADC Austria AG.)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ASCTRM [Auto | Running]) -- C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (BHDrvx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\BHDrvx86.sys (Symantec Corporation)
DRV - (catchme [On_Demand | Stopped]) -- C:\WINDOWS\catchme.exe ()
DRV - (ccHP [System | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\ccHPx86.sys (Symantec Corporation)
DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (drvmcdb [Boot | Running]) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) -- C:\WINDOWS\System32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (DSproct [On_Demand | Stopped]) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (E100B [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (e1express [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e1e5132.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (iastor [Boot | Running]) -- C:\WINDOWS\system32\drivers\iastor.sys (Intel Corporation)
DRV - (IDSxpx86 [System | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090610.006\IDSxpx86.sys (Symantec Corporation)
DRV - (IntelC51 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (IntelC52 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC53 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (MODEMCSA [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (mohfilt [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (NAVENG [On_Demand | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090628.022\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090628.022\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (prodrv06 [System | Running]) -- C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (prohlp02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prosync1 [Boot | Running]) -- C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pxark [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\pxark.sys ()
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfdrv01 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp01 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (sfsync02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (SRTSP [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Running]) -- C:\WINDOWS\System32\drivers\NIS\1005000.087\SRTSPX.SYS (Symantec Corporation)
DRV - (sscdbhk5 [System | Running]) -- C:\WINDOWS\System32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) -- C:\WINDOWS\System32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (STHDA [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (SymEFA [Boot | Running]) -- C:\WINDOWS\system32\drivers\NIS\1005000.087\SYMEFA.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\SYMIDS.SYS (Symantec Corporation)
DRV - (SymIM [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SymIMMP [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) -- C:\WINDOWS\System32\Drivers\NIS\1005000.087\SYMTDI.SYS (Symantec Corporation)
DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (tfsnboio [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (wanatw [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (XPAD910 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\xpad910.sys (Compuware Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-06-27 16:43:23 | 00,000,000 | ---D | M]


Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [BuildBU] c:\dell\bldbubg.exe ()
O4 - HKLM..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe (Corel, Inc.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\System32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [DVDLauncher] C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Google Desktop Search] File not found
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ()
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Uniblue RegistryBooster 2009] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
O4 - Startup: C:\Documents and Settings\mary shumate.D7J9CC91.001\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe (Leader Technologies)
O4 - Startup: C:\Documents and Settings\mary shumate.D7J9CC91.001\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskmgr = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} http://www.worldwinner.com/games/v47/scrab...rabblecubes.cab (ScrabbleCubes Control)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://mypoints.worldwinner.com/games/v47/...GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} http://disney.go.com/pirates/online/testAc...OnlineGames.cab (Disney Online Games ActiveX Control)
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} http://www.worldwinner.com/games/v47/solit...litairerush.cab (SolitaireRush Control)
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx (get_atlcom Class)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/...lscbase6662.cab (Windows Live Safety Center Base Module)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {61900274-3323-4446-BDCD-91548D32AF1B} http://www.worldwinner.com/games/v56/spide...ersolitaire.cab (SpiderSolitaire Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1220142634718 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} http://www.worldwinner.com/games/v67/swapit/swapit.cab (SwapIt Control)
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} http://www.worldwinner.com/games/v45/royal/royal.cab (Royal Control)
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab (MysteryPI Control)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} http://www.worldwinner.com/games/v53/wwspades/wwspades.cab (WWSpades Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {AEA4DE5E-37ED-4A91-A883-6D8953A84614} - Reg Error: Key error. File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005-08-16 05:43:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe -- File not found
O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell - "" = AutoRun
O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009-06-29 02:01:35 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\OTL.exe
[2009-06-29 01:53:51 | 00,173,119 | ---- | C] (Eric_71) -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\Rooter.exe
[2009-06-28 22:15:54 | 05,409,834 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\AutoRuns.arn
[2009-06-28 21:34:27 | 00,019,609 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-03.zip
[2009-06-28 21:34:22 | 00,024,521 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-02.zip
[2009-06-28 21:34:17 | 00,019,925 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-01.zip
[2009-06-28 21:34:13 | 00,025,248 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini061109-01.zip
[2009-06-28 21:34:07 | 00,015,623 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini052409-01.zip
[2009-06-28 21:24:23 | 00,014,668 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini041109-01.zip
[2009-06-27 01:26:58 | 00,000,250 | ---- | C] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\How to troubleshoot hardware and software driver problems in Windows XP.url
[2009-06-11 19:18:02 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2009-06-06 08:24:44 | 00,202,072 | R--- | C] (Coupons, Inc.) -- C:\WINDOWS\cpnprt2.cid
[2009-06-06 08:24:38 | 00,202,072 | ---- | C] (Coupons, Inc.) -- C:\WINDOWS\System32\cpnprt2.cid
[2008-11-12 20:11:51 | 00,000,043 | ---- | C] () -- C:\WINDOWS\juniordisplay.ini
[2008-02-11 09:39:26 | 00,253,952 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008-02-11 09:39:18 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008-02-08 13:53:46 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerLang.dll
[2008-02-04 18:08:59 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2007-12-08 17:10:16 | 00,010,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\pxark.sys
[2007-07-27 14:49:02 | 00,225,355 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiW.dll
[2007-07-27 14:49:02 | 00,196,683 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiA.dll
[2007-05-15 12:38:48 | 00,000,653 | ---- | C] () -- C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2007-01-28 23:18:21 | 00,000,419 | ---- | C] () -- C:\WINDOWS\PCPHOTO.INI
[2006-12-13 09:16:13 | 00,000,813 | ---- | C] () -- C:\WINDOWS\disney.ini
[2006-08-27 17:12:05 | 00,000,191 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2006-08-11 17:04:13 | 00,000,068 | ---- | C] () -- C:\WINDOWS\TONKA_SR.INI
[2006-08-08 12:27:50 | 00,000,523 | ---- | C] () -- C:\WINDOWS\TCII.ini
[2006-08-07 16:29:18 | 00,176,128 | ---- | C] () -- C:\WINDOWS\System32\GGE910cp.dll
[2006-07-28 12:51:31 | 00,000,377 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2006-07-26 15:22:42 | 00,000,058 | ---- | C] () -- C:\WINDOWS\Tonka_Raceway.INI
[2006-07-25 21:43:27 | 00,000,078 | ---- | C] () -- C:\WINDOWS\TONKA.INI
[2006-06-30 22:01:55 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2006-05-07 13:15:50 | 00,000,088 | RHS- | C] () -- C:\WINDOWS\System32\BFC9300558.sys
[2006-02-22 14:57:37 | 00,006,686 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006-02-22 14:57:37 | 00,000,152 | RHS- | C] () -- C:\WINDOWS\System32\580530C9BF.sys
[2006-02-22 14:46:20 | 00,000,138 | ---- | C] () -- C:\WINDOWS\msfsetup.ini
[2006-01-30 01:04:08 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006-01-30 00:22:38 | 00,000,387 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005-12-05 19:25:22 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\lnod32umc.dll
[2005-12-05 12:37:10 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\lnod32upd.dll
[2005-08-16 05:37:24 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005-08-16 05:18:43 | 00,000,562 | ---- | C] () -- C:\WINDOWS\win.ini
[2005-08-16 05:18:41 | 00,000,243 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI
[2005-08-05 15:01:54 | 00,239,104 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005-04-09 18:04:54 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini

========== Files - Modified Within 30 Days ==========

[2009-06-29 02:01:56 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\OTL.exe
[2009-06-29 01:54:15 | 00,173,119 | ---- | M] (Eric_71) -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\Rooter.exe
[2009-06-29 01:51:27 | 00,002,100 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\My eBay.url
[2009-06-29 01:48:55 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-06-29 01:48:23 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-06-29 01:48:20 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-06-29 01:48:13 | 53,494,1696 | -HS- | M] () -- C:\hiberfil.sys
[2009-06-28 22:27:07 | 01,593,120 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2009-06-28 22:27:07 | 00,150,428 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.idx
[2009-06-28 22:27:06 | 00,519,788 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2009-06-28 22:27:05 | 38,730,528 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2009-06-28 22:15:57 | 05,409,834 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\AutoRuns.arn
[2009-06-28 21:16:26 | 00,019,609 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-03.zip
[2009-06-28 21:16:22 | 00,019,925 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-01.zip
[2009-06-28 21:16:17 | 00,015,623 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini052409-01.zip
[2009-06-28 21:16:09 | 00,024,521 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini062709-02.zip
[2009-06-28 21:16:04 | 00,025,248 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini061109-01.zip
[2009-06-28 21:15:59 | 00,014,668 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\Mini041109-01.zip
[2009-06-28 19:44:18 | 00,000,250 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop\How to troubleshoot hardware and software driver problems in Windows XP.url
[2009-06-17 11:27:56 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-06-17 11:27:44 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009-06-11 19:55:24 | 01,582,852 | -H-- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\Local Settings\Application Data\IconCache.db
[2009-06-11 19:37:18 | 00,197,752 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-06-11 19:30:49 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-06-11 01:35:05 | 00,000,562 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-06-10 17:10:59 | 00,624,139 | ---- | M] () -- C:\Documents and Settings\mary shumate.D7J9CC91.001\My Documents\100_1262 (2) chair.jpg
[2009-06-06 08:24:44 | 00,202,072 | R--- | M] (Coupons, Inc.) -- C:\WINDOWS\cpnprt2.cid
[2009-06-06 08:24:38 | 00,202,072 | ---- | M] (Coupons, Inc.) -- C:\WINDOWS\System32\cpnprt2.cid
[2009-06-01 11:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009-05-30 15:50:41 | 00,001,495 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\BellSouth Webmail.url
< End of report >



OLT LIST EXTRA

OTL Extras logfile created on: Jun-29 2:02:14 AM - Run 1
OTL by OldTimer - Version 3.0.5.3 Folder = C:\Documents and Settings\mary shumate.D7J9CC91.001\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MMM-dd

510.09 Mb Total Physical Memory | 184.79 Mb Available Physical Memory | 36.23% Memory free
1.21 Gb Paging File | 0.92 Gb Available in Paging File | 75.72% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 27.61 Gb Free Space | 39.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D7J9CC91
Current User Name: mary shumate
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL (America Online, Inc)
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL (America Online, Inc.)
C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL (America Online, Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL (America Online, Inc)
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL (America Online, Inc.)
C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL (America Online, Inc.)
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\TrackMania Sunrise\TmSunrise.exe:*:Disabled:TmSunrise ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{14374619-0900-4056-BA06-C87C900AF9E6}" = QuickBooks Simple Start Special Edition
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.4.0
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{4CEA6811-DFAD-4892-828D-49941FE3B779}" = Intel® PROSet for Wired Connections
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}" = Medal of Honor Pacific Assault™
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7914BE1E-F186-4790-B8F4-9F63C52A41C1}" = Medal of Honor Allied Assault™ Spearhead
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{7F34A21F-2DEB-4598-BB19-611D6BD24271}" = Managed DirectX (0900)
"{823A68CC-3049-4A6B-8F63-7DC85E4BB1C9}" = Medal of Honor Allied Assault™ Breakthrough
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D3AA158A-9421-4883-8767-E771B0964A1D}" = ImageMixer VCD for FinePix
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{D680C913-5955-469D-9D88-C1940F7506D6}" = RAW FILE CONVERTER LE
"{E7E254C0-94AA-4B33-AF6D-5276A169A680}" = TONKA Search & Rescue 2
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"All ATI Software" = ATI - Software Uninstall Utility
"America Online us" = America Online (Choose which version to remove)
"AOL Connectivity Services" = AOL Connectivity Services
"AOLCoach" = AOL Coach Version 1.0(Build:20040229.1 en)
"ATI Display Driver" = ATI Display Driver
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0
"Cars - Radiator Springs Adventures" = Cars - Radiator Springs Adventures
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Game Console" = Dell Game Console
"Disney Pirates of the Caribbean Online" = Disney Pirates of the Caribbean Online
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"ERUNT_is1" = ERUNT 1.1j
"EsetOnlineScanner" = ESET Online Scanner
"ESPNMotion" = ESPNMotion
"Game Elements GGE910 Wireless PC Control Pad" = Game Elements GGE910 Wireless PC Control Pad
"Google Desktop" = Google Desktop
"Heroes of the Pacific" = Heroes of the Pacific
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Midtown Madness 1.0" = Microsoft Midtown Madness
"Monster Truck Stunt Rally" = Monster Truck Stunt Rally
"Motocross Madness 1.0" = Microsoft Motocross Madness
"Motocross Madness 2" = Microsoft Motocross Madness 2
"MSNINST" = MSN
"MWASPINT" = MicroStaff WINASPI NT
"NASCAR Racing 1999 Edition" = NASCAR Racing 1999 Edition
"NIS" = Norton Internet Security
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Connections Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"Scholastic's I SPY Fantasy" = Scholastic's I SPY Fantasy
"Scholastic's I SPY Junior" = Scholastic's I SPY Junior
"Sierra Utilities" = Sierra Utilities
"Sky Rangers Jet Simulator" = Sky Rangers Jet Simulator
"Sky Rangers Simulator" = Sky Rangers Simulator
"SpongeBob SquarePants Employee of the Month" = SpongeBob SquarePants Employee of the Month
"StreetPlugin" = Learn2 Player (Uninstall Only)
"TmSunrise_is1" = TrackMania Sunrise
"Tonka Construction 2" = Tonka Construction 2
"TONKA Monster Trucks" = Uninstall TONKA Monster Trucks
"Tonka Raceway" = Tonka Raceway
"Tonka Search and Rescue" = Tonka Search and Rescue
"TrackMania_is1" = TrackMania
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WildTangent CDA" = WildTangent Web Driver
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - Jun-29 1:51:06 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - Jun-29 1:51:06 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - Jun-29 2:41:18 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - Jun-29 2:41:18 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - Jun-29 2:41:18 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - Jun-29 2:41:18 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - Jun-29 2:48:31 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - Jun-29 2:48:31 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - Jun-29 2:48:31 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - Jun-29 2:48:31 AM | Computer Name = D7J9CC91 | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

[ System Events ]
Error - Jun-11 9:01:01 PM | Computer Name = D7J9CC91 | Source = System Error | ID = 1003
Description = Error code 1000007e, parameter1 c0000005, parameter2 f73cff8f, parameter3
b81c9c20, parameter4 b81c991c.

Error - Jun-20 6:01:53 PM | Computer Name = D7J9CC91 | Source = Print | ID = 6161
Description = The document mhtml:mid://00000020/ owned by mary shumate failed to
print on printer HP DeskJet 930C/932C/935C. Data type: NT EMF 1.008. Size of the
spool file in bytes: 4465372. Number of bytes printed: 1827028. Total number of
pages in the document: 16. Number of pages printed: 1. Client machine: \\D7J9CC91.
Win32 error code returned by the print processor: 0 (0x0).

Error - Jun-26 6:17:03 PM | Computer Name = D7J9CC91 | Source = Print | ID = 6161
Description = The document SmartSource Coupon owned by mary shumate failed to print
on printer HP DeskJet 930C/932C/935C. Data type: NT EMF 1.008. Size of the spool
file in bytes: 0. Number of bytes printed: 0. Total number of pages in the document:
0. Number of pages printed: 0. Client machine: \\D7J9CC91. Win32 error code returned
by the print processor: 259 (0x103).

Error - Jun-26 6:24:14 PM | Computer Name = D7J9CC91 | Source = Print | ID = 6161
Description = The document SmartSource Coupon owned by mary shumate failed to print
on printer HP DeskJet 930C/932C/935C. Data type: NT EMF 1.008. Size of the spool
file in bytes: 0. Number of bytes printed: 0. Total number of pages in the document:
0. Number of pages printed: 0. Client machine: \\D7J9CC91. Win32 error code returned
by the print processor: 259 (0x103).

Error - Jun-27 2:05:42 AM | Computer Name = D7J9CC91 | Source = System Error | ID = 1003
Description = Error code 1000007e, parameter1 c0000005, parameter2 f82245ee, parameter3
b8035b30, parameter4 b803582c.

Error - Jun-27 3:32:50 PM | Computer Name = D7J9CC91 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000243'
while processing the file 'EraserUtilRebootDrv.sys' on the volume 'HarddiskVolume2'.
It has stopped monitoring the volume.

Error - Jun-27 9:07:10 PM | Computer Name = D7J9CC91 | Source = System Error | ID = 1003
Description = Error code 1000007e, parameter1 c0000005, parameter2 f82245ee, parameter3
b80d5b30, parameter4 b80d582c.

Error - Jun-28 5:00:01 PM | Computer Name = D7J9CC91 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000243'
while processing the file 'EraserUtilRebootDrv.sys' on the volume 'HarddiskVolume2'.
It has stopped monitoring the volume.

Error - Jun-28 11:28:39 PM | Computer Name = D7J9CC91 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000243'
while processing the file 'EraserUtilDrv10910.sys' on the volume 'HarddiskVolume2'.
It has stopped monitoring the volume.

Error - Jun-29 2:37:40 AM | Computer Name = D7J9CC91 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Internet Explorer 8 for Windows XP.


< End of report >

This post has been edited by jazzy56: Jun 29 2009, 03:30 PM
Go to the top of the page
 
+Quote Post
emeraldnzl
post Jul 2 2009, 05:19 PM
Post #2


Trusted Helper
Group Icon
Posts: 7,986
OS: XP Pro



Hello jazzy56,

Download the HostsXpert 4.2 - Hosts File Manager.
  • Unzip HostsXpert 4.2 - Hosts File Manager to a convenient folder such as C:\HostsXpert 4.2 - Hosts File Manager
  • Run HostsXpert 4.2 - Hosts File Manager from its new home
  • Click on "File Handling".
  • Click on "Restore MS Hosts File".
  • Click OK on the Confirmation box.
  • Click on "Make Read Only?"
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

Next

Please run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    CODE
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [] File not found
    O4 - HKCU..\Run: [Uniblue RegistryBooster 2009] File not found
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe -- File not found
    O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell - "" = AutoRun
    O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
    O33 - MountPoints2\F\Shell - "" = AutoRun
    O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found

    :Files
    C:\DOCUME~1\MARYSH~1.001\Favorites\CHRISTMAS

    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.


Go to the top of the page
 
+Quote Post
jazzy56
post Jul 2 2009, 08:28 PM
Post #3


Member
**
Posts: 78
From: LOUISIANA
OS: XP media



I have downloaded HostsXpert 4.2 - Hosts File Manager but do not see file handling. Help I am a novice about this. thanks
Go to the top of the page
 
+Quote Post
jazzy56
post Jul 2 2009, 08:47 PM
Post #4


Member
**
Posts: 78
From: LOUISIANA
OS: XP media



Log listed

All processes killed
Error: Unable to interpret <CODE> in the current context!
Error: Unable to interpret <:OTLI> in the current context!
Error: Unable to interpret <PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [] File not found> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [Uniblue RegistryBooster 2009] File not found> in the current context!
Error: Unable to interpret <O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun> in the current context!
Error: Unable to interpret <O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play> in the current context!
Error: Unable to interpret <O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe -- File not found> in the current context!
Error: Unable to interpret <O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell - "" = AutoRun> in the current context!
Error: Unable to interpret <O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell\AutoRun - "" = Auto&Play> in the current context!
Error: Unable to interpret <O33 - MountPoints2\{f93c6d66-4325-11de-ba16-00137208988b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found> in the current context!
Error: Unable to interpret <O33 - MountPoints2\F\Shell - "" = AutoRun> in the current context!
Error: Unable to interpret <O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play> in the current context!
Error: Unable to interpret <O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found> in the current context!
========== FILES ==========
C:\DOCUME~1\MARYSH~1.001\Favorites\CHRISTMAS\CHRISTMAS GAMES\SAND CASTLE moved successfully.
C:\DOCUME~1\MARYSH~1.001\Favorites\CHRISTMAS\CHRISTMAS GAMES moved successfully.
C:\DOCUME~1\MARYSH~1.001\Favorites\CHRISTMAS moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

User: mary shumate
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: mary shumate.D7J9CC91
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: mary shumate.D7J9CC91.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: mary shumate.D7J9CC91.001
->Temp folder emptied: 1803209 bytes
->Temporary Internet Files folder emptied: 23802846 bytes
->Java cache emptied: 13425364 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 82584 bytes

RecycleBin emptied: 279 bytes

Total Files Cleaned = 37.33 mb


OTL by OldTimer - Version 3.0.6.2 log created on 07022009_213757

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
Go to the top of the page
 
+Quote Post
emeraldnzl
post Jul 3 2009, 01:14 AM
Post #5


Trusted Helper
Group Icon
Posts: 7,986
OS: XP Pro



QUOTE
I have downloaded HostsXpert 4.2 - Hosts File Manager but do not see file handling. Help I am a novice about this. thanks


Not to worry. Leave that for now.

Download Lop S&D by Eric_71 and save it to your desktop.

Lop S&D will only run on Windows XP and Windows Vista

Disable your antivirus and anti-malware programs so they do not interfere with the running of Lop S&D. You can usually do this via a right click on the System Tray icon.
  • Double-click LopSD.exe
    If you are using Windows Vista, right-click on LopSD.exe icon and select 'Run as administrator' to perform this scan.
  • Choose the language by typing of the corresponding letter and press Enter
  • Click OK at the informative window
  • Type 2 to choose Option 2 (Fix + Hosts), then press Enter
  • Wait until the end of the scan
  • A report will be generated, post the contents of it in your next reply.
(Copy of the report can be found at this location: %SystemDrive%\lopR.txt, in most cases C:\lopR.txt)
Go to the top of the page
 
+Quote Post
jazzy56
post Jul 3 2009, 10:46 AM
Post #6


Member
**
Posts: 78
From: LOUISIANA
OS: XP media




--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 2.80GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A03
USER : mary shumate ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 16.2.0.7 (Not Activated)
Firewall : Norton Internet Security 16.2.0.7 (Activated)
C:\ (Local Disk) - NTFS - Total:69 Go (Free:28 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( Jul-03|11:29 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX

Deleted! - C:\DOCUME~1\MARYSH~1.001\Cookies\mary_shumate@advertising[1].txt
Deleted! - C:\DOCUME~1\MARYSH~1.001\Cookies\mary_shumate@traveladvertising[1].txt
-
[ Hosts file ] .. Restored!

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing folders in APPLIC~1

[Jan-30|12:57:] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Corel
[Jan-30|12:59:] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Google
[Aug-16|05:50:] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
[Mar-16|07:55:] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
[Jan-30|12:43:] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sun

[Mar-31|04:37:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[May-02|11:08:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[Oct-09|11:34:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe(2)
[Feb-20|10:00:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe(4)
[Apr-12|08:26:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL
[Mar-16|07:55:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> avg8
[Aug-16|09:54:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> DIGStream
[Mar-16|05:57:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Downloaded Installations
[Nov-06|01:39:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> FunGames
[Jan-26|12:30:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google
[Dec-10|03:46:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Grisoft
[Apr-26|07:35:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> GTek
[Jan-30|12:52:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield
[Jan-30|12:51:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intuit
[Aug-30|08:59:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes
[Apr-10|05:25:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee
[Apr-12|08:33:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com
[Feb-20|10:04:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(2)
[Feb-20|10:03:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(3)
[Feb-20|10:01:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(4)
[Feb-20|10:00:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(5)
[Feb-20|09:58:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(6)
[Feb-20|09:54:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall(7)
[Aug-29|08:05:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[Feb-20|10:01:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> MVTLogs
[Apr-10|05:39:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Norton
[Apr-10|04:51:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> NortonInstaller
[May-02|02:35:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> NOS
[Feb-22|12:44:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PACE Anti-Piracy
[Dec-10|03:13:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Prevx
[Jan-30|12:50:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> QuickTime
[Apr-02|09:05:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SingleClick Systems
[Apr-26|05:58:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Support.com
[Apr-10|05:40:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Symantec
[Apr-19|10:42:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TEMP
[May-14|02:30:] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage

[Jan-30|12:57:] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Corel
[Jan-30|12:59:] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Google
[Aug-16|05:50:] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities
[Jan-30|12:49:] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[Jan-30|12:43:] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Sun

[Feb-22|01:57:] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> GTek
[Feb-22|01:52:] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Macromedia
[Mar-16|07:55:] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft

[Feb-19|10:03:] C:\DOCUME~1\MARYSH~1\APPLIC~1\<DIR> Adobe
[Jan-30|12:57:] C:\DOCUME~1\MARYSH~1\APPLIC~1\<DIR> Corel
[Jan-30|12:54:] C:\DOCUME~1\MARYSH~1\APPLIC~1\<DIR> Gtek
[Feb-19|09:38:] C:\DOCUME~1\MARYSH~1\APPLIC~1\<DIR> Macromedia
[Feb-22|12:45:] C:\DOCUME~1\MARYSH~1\APPLIC~1\<DIR> Microsoft

[Jan-30|12:57:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> Corel
[Feb-21|04:57:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> Corel Photo Album
[Feb-22|12:44:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> FUJIFILM
[Jan-30|12:54:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> Gtek
[Feb-21|05:25:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> Leadertech
[Feb-22|12:44:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> Microsoft
[Feb-21|06:00:] C:\DOCUME~1\MARYSH~1.D7J\APPLIC~1\<DIR> PACE Anti-Piracy

[Jan-30|12:57:] C:\DOCUME~1\MARYSH~1.000\APPLIC~1\<DIR> Corel
[Jan-30|12:54:] C:\DOCUME~1\MARYSH~1.000\APPLIC~1\<DIR> Gtek
[Feb-22|12:43:] C:\DOCUME~1\MARYSH~1.000\APPLIC~1\<DIR> Microsoft

[Apr-30|11:31:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Adobe
[Oct-09|11:34:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> AdobeUM
[Apr-26|05:59:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> BellSouth
[Dec-13|01:04:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Corel
[Feb-22|03:03:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Corel Photo Album
[Feb-22|04:02:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> FUJIFILM
[Apr-10|05:32:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> GetRightToGo
[Sep-14|12:07:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Google
[Dec-10|03:46:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Grisoft
[Apr-16|11:11:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Gtek
[Mar-29|09:43:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Help
[May-12|05:08:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Identities
[Sep-09|05:10:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> InstallShield
[Apr-18|05:31:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> IObit
[Feb-24|04:29:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Leadertech
[Apr-30|11:31:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Macromedia
[Aug-30|08:59:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Malwarebytes
[Feb-18|07:47:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> McAfee
[Mar-16|07:55:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Microsoft
[Dec-10|03:13:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> PrevxCSI
[Sep-28|06:00:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Sonic
[Aug-19|07:45:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Sony Corporation
[Jan-30|12:43:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Sun
[May-17|04:55:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> U3
[Mar-27|08:52:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Uniblue
[Mar-30|05:46:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> wsInspector
[Apr-18|05:31:] C:\DOCUME~1\MARYSH~1.001\APPLIC~1\<DIR> Yahoo!

[Mar-16|07:55:] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft

--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[Apr-19 11:33: AM][--a------] C:\WINDOWS\tasks\Wise Disk Cleaner 4.job
[Jul-03 11:02: AM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[Aug-10 06:00: AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Program Files

[May-02|11:09:] C:\Program Files\<DIR> Adobe
[Aug-30|05:44:] C:\Program Files\<DIR> Alwil Software
[Mar-17|01:20:] C:\Program Files\<DIR> America Online 9.0
[Mar-17|01:20:] C:\Program Files\<DIR> AOL Companion
[Jun-11|07:17:] C:\Program Files\<DIR> ATI Technologies
[Nov-05|10:57:] C:\Program Files\<DIR> Auran
[Apr-26|05:59:] C:\Program Files\<DIR> BellSouth
[Jan-11|10:54:] C:\Program Files\<DIR> Big Sky Software
[Oct-09|11:30:] C:\Program Files\<DIR> Broderbund Software
[May-02|11:08:] C:\Program Files\<DIR> Common Files
[Oct-14|02:05:] C:\Program Files\<DIR> Corel
[Jun-09|07:48:] C:\Program Files\<DIR> Coupons
[Jan-30|12:48:] C:\Program Files\<DIR> CyberLink
[Mar-12|06:01:] C:\Program Files\<DIR> Decookie
[Mar-17|01:20:] C:\Program Files\<DIR> Dell
[May-15|12:38:] C:\Program Files\<DIR> Dell Network Assistant
[Oct-17|12:02:] C:\Program Files\<DIR> DellConnect
[Apr-16|10:56:] C:\Program Files\<DIR> DellSupport
[Apr-19|11:41:] C:\Program Files\<DIR> DIGStream
[Oct-09|11:29:] C:\Program Files\<DIR> directx
[Mar-15|02:51:] C:\Program Files\<DIR> Disney
[Dec-13|09:17:] C:\Program Files\<DIR> Disney Interactive
[Oct-09|11:34:] C:\Program Files\<DIR> DK Interactive Learning(2)
[Aug-06|09:38:] C:\Program Files\<DIR> EA GAMES
[Mar-24|06:47:] C:\Program Files\<DIR> EnglishOtto
[Apr-18|09:23:] C:\Program Files\<DIR> Enlight
[Jun-28|11:04:] C:\Program Files\<DIR> ERUNT
[Jun-29|02:50:] C:\Program Files\<DIR> ESET
[May-05|03:37:] C:\Program Files\<DIR> EsetOnlineScanner
[Apr-19|11:41:] C:\Program Files\<DIR> ESPNMotion
[Feb-22|02:44:] C:\Program Files\<DIR> FinePixViewer
[Feb-22|12:44:] C:\Program Files\<DIR> FinePixViewer(2)
[Nov-22|07:18:] C:\Program Files\<DIR> Fox
[May-24|07:30:] C:\Program Files\<DIR> Game Elements
[Mar-24|07:18:] C:\Program Files\<DIR> GemMaster
[Jan-26|03:05:] C:\Program Files\<DIR> Google
[Jan-30|12:59:] C:\Program Files\<DIR> GoogleAFE
[May-03|11:08:] C:\Program Files\<DIR> Grisoft
[Nov-05|10:58:] C:\Program Files\<DIR> Hasbro Interactive
[Aug-27|05:23:] C:\Program Files\<DIR> IBM and Crayola
[Oct-09|11:35:] C:\Program Files\<DIR> Infogrames Interactive
[Jun-11|07:17:] C:\Program Files\<DIR> InstallShield Installation Information
[Jan-30|12:48:] C:\Program Files\<DIR> Intel
[Jun-12|11:45:] C:\Program Files\<DIR> Internet Explorer
[Jan-30|12:51:] C:\Program Files\<DIR> Intuit
[Apr-18|05:31:] C:\Program Files\<DIR> IObit
[Apr-11|01:11:] C:\Program Files\<DIR> Java
[Jan-30|12:50:] C:\Program Files\<DIR> Learn2.com
[Dec-30|12:58:] C:\Program Files\<DIR> LEGO Media
[Jun-28|11:10:] C:\Program Files\<DIR> Malwarebytes' Anti-Malware
[Aug-06|10:06:] C:\Program Files\<DIR> Managed DirectX (0900)
[Apr-10|05:24:] C:\Program Files\<DIR> McAfee
[Apr-10|05:35:] C:\Program Files\<DIR> McAfee.com
[Aug-31|10:18:] C:\Program Files\<DIR> Messenger
[May-27|07:09:] C:\Program Files\<DIR> MFInstall
[Aug-16|05:43:] C:\Program Files\<DIR> microsoft frontpage
[Mar-29|04:25:] C:\Program Files\<DIR> Microsoft Games
[Jan-30|12:49:] C:\Program Files\<DIR> Microsoft Plus! Digital Media Edition
[Jan-30|12:49:] C:\Program Files\<DIR> Microsoft Plus! Photo Story 2 LE
[Apr-19|11:41:] C:\Program Files\<DIR> Modem Helper
[Jan-30|12:48:] C:\Program Files\<DIR> Modem On Hold
[Apr-18|10:15:] C:\Program Files\<DIR> Monster Truck Stunt Rally
[Aug-31|10:13:] C:\Program Files\<DIR> Movie Maker
[Mar-28|08:26:] C:\Program Files\<DIR> MSBuild
[Oct-04|01:34:] C:\Program Files\<DIR> MSN
[Aug-16|05:37:] C:\Program Files\<DIR> MSN Gaming Zone
[Nov-17|05:33:] C:\Program Files\<DIR> MSXML 4.0
[Jan-30|12:54:] C:\Program Files\<DIR> MUSICMATCH
[Aug-31|10:10:] C:\Program Files\<DIR> NetMeeting
[Oct-17|06:30:] C:\Program Files\<DIR> NetZeroInstallers
[Apr-10|05:38:] C:\Program Files\<DIR> Norton Internet Security
[Apr-11|09:58:] C:\Program Files\<DIR> Norton Support
[Apr-10|05:31:] C:\Program Files\<DIR> NortonInstaller
[May-02|02:35:] C:\Program Files\<DIR> NOS
[Dec-01|01:55:] C:\Program Files\<DIR> Online Services
[Aug-31|10:10:] C:\Program Files\<DIR> Outlook Express
[Feb-21|02:06:] C:\Program Files\<DIR> PIXELA
[Mar-15|10:54:] C:\Program Files\<DIR> PopCap Games
[Feb-22|12:45:] C:\Program Files\<DIR> QuickTime
[Jan-30|12:50:] C:\Program Files\<DIR> Real
[Mar-28|08:26:] C:\Program Files\<DIR> Reference Assemblies
[Feb-19|04:54:] C:\Program Files\<DIR> RegistryFix
[Feb-22|02:43:] C:\Program Files\<DIR> REGSHAVE
[Aug-16|09:58:] C:\Program Files\<DIR> RGB
[Feb-23|02:59:] C:\Program Files\<DIR> Scholastic
[Nov-19|09:14:] C:\Program Files\<DIR> Sierra On-Line
[Jan-30|12:45:] C:\Program Files\<DIR> Sigmatel
[Mar-17|01:21:] C:\Program Files\<DIR> SimTheme Park
[Jan-30|12:52:] C:\Program Files\<DIR> Sonic
[Aug-30|06:21:] C:\Program Files\<DIR> SpywareDetector
[Mar-30|05:48:] C:\Program Files\<DIR> Startup Inspector for Windows
[Apr-26|09:30:] C:\Program Files\<DIR> Support.com
[Apr-23|06:38:] C:\Program Files\<DIR> Symantec
[Feb-04|06:02:] C:\Program Files\<DIR> The Learning Company
[Oct-09|11:29:] C:\Program Files\<DIR> THQ
[Mar-30|05:51:] C:\Program Files\<DIR> TrackMania Sunrise
[Mar-30|05:50:] C:\Program Files\<DIR> TrackMania Sunrise(2)(2)
[Mar-30|05:50:] C:\Program Files\<DIR> TrackMania Sunrise(3)
[Dec-09|06:13:] C:\Program Files\<DIR> Trend Micro
[Nov-21|03:09:] C:\Program Files\<DIR> Ubisoft
[Aug-28|11:45:] C:\Program Files\<DIR> Uninstall Information
[Oct-09|11:29:] C:\Program Files\<DIR> ValuSoft
[Apr-13|07:26:] C:\Program Files\<DIR> Virtools Web Player 3.5
[Jan-30|12:54:] C:\Program Files\<DIR> WebCyberCoach
[Mar-12|05:11:] C:\Program Files\<DIR> WildTangent
[Mar-16|12:08:] C:\Program Files\<DIR> Windows Live Safety Center
[Dec-30|01:26:] C:\Program Files\<DIR> Windows Media Player
[Aug-31|10:10:] C:\Program Files\<DIR> Windows NT
[Aug-16|05:37:] C:\Program Files\<DIR> Windows Plus
[Apr-10|05:38:] C:\Program Files\<DIR> Windows Sidebar
[Feb-21|06:47:] C:\Program Files\<DIR> WindowsUpdate
[Jan-30|12:53:] C:\Program Files\<DIR> WordPerfect Office 12
[Aug-16|05:43:] C:\Program Files\<DIR> xerox
[Apr-19|10:09:] C:\Program Files\<DIR> Yahoo!
[Jul-22|05:49:] C:\Program Files\<DIR> Zero G Registry

--------------------\\ Listing Folders in C:\Program Files\Common Files

[May-02|11:07:] C:\Program Files\Common Files\<DIR> Adobe
[May-02|11:08:] C:\Program Files\Common Files\<DIR> Adobe AIR
[Jan-30|12:51:] C:\Program Files\Common Files\<DIR> AnswerWorks 4.0
[Apr-12|08:31:] C:\Program Files\Common Files\<DIR> AOL
[Apr-12|08:31:] C:\Program Files\Common Files\<DIR> aolshare
[Jan-30|12:52:] C:\Program Files\Common Files\<DIR> Borland Shared
[Oct-14|02:05:] C:\Program Files\Common Files\<DIR> Corel
[Aug-30|08:04:] C:\Program Files\Common Files\<DIR> Download Manager
[Apr-19|11:41:] C:\Program Files\Common Files\<DIR> EasyInfo
[Jan-30|12:53:] C:\Program Files\Common Files\<DIR> InstallShield
[Jan-30|12:51:] C:\Program Files\Common Files\<DIR> Intuit
[Jan-30|12:42:] C:\Program Files\Common Files\<DIR> Java
[Mar-10|03:28:] C:\Program Files\Common Files\<DIR> Microsoft Shared
[Apr-26|09:30:] C:\Program Files\Common Files\<DIR> Motive
[Aug-16|05:40:] C:\Program Files\Common Files\<DIR> MSSoap
[Jan-30|12:50:] C:\Program Files\Common Files\<DIR> Nullsoft
[Aug-16|05:33:] C:\Program Files\Common Files\<DIR> ODBC
[Feb-21|05:57:] C:\Program Files\Common Files\<DIR> PACE Anti-Piracy
[Apr-10|10:30:] C:\Program Files\Common Files\<DIR> ParetoLogic
[Jan-30|12:50:] C:\Program Files\Common Files\<DIR> Real
[Aug-16|05:40:] C:\Program Files\Common Files\<DIR> Services
[Jan-30|12:52:] C:\Program Files\Common Files\<DIR> Sonic Shared
[Aug-16|05:33:] C:\Program Files\Common Files\<DIR> SpeechEngines
[Feb-22|02:36:] C:\Program Files\Common Files\<DIR> SWF Studio
[Apr-10|05:46:] C:\Program Files\Common Files\<DIR> Symantec Shared
[Aug-31|10:10:] C:\Program Files\Common Files\<DIR> System

--------------------\\ Process

( 48 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-03 11:32:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Searching for other infections


No other infections found !

[F:2][D:0]-> C:\DOCUME~1\MARYSH~1.001\LOCALS~1\Temp
[F:1059][D:0]-> C:\DOCUME~1\MARYSH~1.001\Cookies
[F:3149][D:4]-> C:\DOCUME~1\MARYSH~1.001\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Jul-03|11:34 - Option : [2]

--------------------\\ Scan completed at 11:34:42


This post has been edited by jazzy56: Jul 3 2009, 12:07 PM
Go to the top of the page
 
+Quote Post
emeraldnzl
post Jul 3 2009, 03:08 PM
Post #7


Trusted Helper
Group Icon
Posts: 7,986
OS: XP Pro



Hello jazzy56,

Please download ComboFix from one of these locations:

NOTE: If you are guest watching this topic. ComboFix is a very powerful tool. The disclaimer clearly states that you should not use it without supervision. There is good reason for this as ComboFix can, and sometimes does, run into conflict on a computer and render it unusable.

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Go to the top of the page
 
+Quote Post
jazzy56
post Jul 3 2009, 04:00 PM
Post #8


Member
**
Posts: 78
From: LOUISIANA
OS: XP media



Ran combo fix --- at the notepad screen a grey boz appeared --

cannot find the C: Docune~marysh~1-001\locals~temp\log b t.file
Do you want to create a new folder
yes No

I said yes.. after 15 minutes with no sign of activity i had to push reset to close down. Do you want me to try again. Thank You
Go to the top of the page
 
+Quote Post
jazzy56
post Jul 3 2009, 04:25 PM
Post #9


Member
**
Posts: 78
From: LOUISIANA
OS: XP media



Was finally able to RUN COMBOFIX, Please find Log Below.

ComboFix 09-07-03.03 - mary shumate Jul-03 17:03.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.157 [GMT -5:00]
Running from: c:\documents and settings\mary shumate.D7J9CC91.001\My Documents\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((( Files Created from 2009-06-03 to 2009-07-03 )))))))))))))))))))))))))))))))
.

2009-07-03 16:15 . 2009-04-11 16:05 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\NAVENG.SYS
2009-07-03 16:15 . 2009-04-11 16:05 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\NAVEX15.SYS
2009-07-03 16:15 . 2009-04-11 16:05 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\NAVENG32.DLL
2009-07-03 16:15 . 2009-04-11 16:05 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\NAVEX32A.DLL
2009-07-03 16:14 . 2009-04-11 16:05 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\EECTRL.SYS
2009-07-03 16:14 . 2009-04-11 16:05 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\ECMSVR32.DLL
2009-07-03 16:14 . 2009-04-11 16:05 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\CCERASER.DLL
2009-07-03 16:14 . 2009-04-11 16:05 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.004\ERASER.SYS
2009-07-03 16:13 . 2009-07-03 16:34 -------- d-----w- C:\Lop SD
2009-07-03 02:37 . 2009-07-03 02:37 -------- d-----w- C:\_OTL
2009-07-03 02:31 . 2009-07-03 02:31 -------- d-----w- C:\HostsXpert 4.2 - Hosts File Manager
2009-07-03 02:30 . 2009-07-03 02:30 353485 ----a-w- C:\HostsXpert 4.2 -.zip
2009-07-03 02:24 . 2009-07-03 02:24 353485 ----a-w- C:\HostsXpert 4.2 - Hosts File Manager.zip
2009-07-02 14:02 . 2009-07-02 14:01 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-30 22:34 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll
2009-06-30 22:34 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys
2009-06-30 22:34 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys
2009-06-30 22:34 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll
2009-06-30 22:34 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys
2009-06-30 16:29 . 2009-06-30 16:29 152576 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-06-29 19:50 . 2009-06-29 19:50 -------- d-----w- c:\program files\ESET
2009-06-27 20:48 . 2009-06-27 20:48 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-13 02:49 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\Scxpx86.dll
2009-06-13 02:49 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys
2009-06-13 02:49 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSvix86.sys
2009-06-13 02:49 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSxpx86.dll
2009-06-13 02:49 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSviA64.sys
2009-06-12 00:18 . 2006-02-10 02:05 520192 ------w- c:\windows\system32\ati2sgag.exe
2009-06-08 18:56 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\Scxpx86.dll
2009-06-08 18:56 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSXpx86.sys
2009-06-08 18:56 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSvix86.sys
2009-06-08 18:56 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSxpx86.dll
2009-06-08 18:56 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-02 13:59 . 2009-04-11 18:10 152576 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-29 04:10 . 2009-03-23 00:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-29 04:04 . 2009-05-02 20:54 -------- d-----w- c:\program files\ERUNT
2009-06-29 03:27 . 2009-04-10 15:11 1593120 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-29 03:27 . 2009-04-10 15:11 150428 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-29 03:27 . 2009-04-10 15:11 519788 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-29 03:27 . 2009-04-10 15:11 38730528 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-27 22:05 . 2009-03-30 23:59 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 16:27 . 2009-03-23 00:23 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 16:27 . 2009-03-23 00:23 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-12 00:17 . 2006-01-30 05:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-12 00:17 . 2006-01-30 05:48 -------- d-----w- c:\program files\ATI Technologies
2009-06-10 00:48 . 2008-06-12 00:02 -------- d-----w- c:\program files\Coupons
2009-05-25 00:30 . 2007-11-19 05:58 -------- d-----w- c:\program files\Game Elements
2009-05-22 23:18 . 2006-02-22 19:57 6686 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-22 23:18 . 2006-02-22 19:57 152 --sh--r- c:\windows\system32\580530C9BF.sys
2009-05-17 21:55 . 2009-05-17 21:55 -------- d-----w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\U3
2009-05-07 15:32 . 2005-08-16 10:18 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-05 20:37 . 2009-05-05 03:43 -------- d-----w- c:\program files\EsetOnlineScanner
2009-04-29 04:56 . 2005-08-16 10:18 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2009-05-02 23:39 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2009-03-11 17:38 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2005-08-16 10:18 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-11 15:10 . 2009-04-10 22:39 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-04-11 15:10 . 2009-04-10 22:39 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-10 22:39 . 2009-04-10 22:39 1290584 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-04-10 22:39 . 2009-04-10 22:39 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-04-10 22:39 . 2009-04-10 22:39 800112 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-04-10 14:58 . 2006-02-22 20:03 43128 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-02-12 00:15 . 2006-05-07 18:15 88 --sh--r- c:\windows\system32\BFC9300558.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-07-03_21.33.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-03 21:51 . 2009-07-03 21:51 16384 c:\windows\Temp\Perflib_Perfdata_730.dat
+ 2009-07-03 21:51 . 2009-07-03 21:51 16384 c:\windows\Temp\Perflib_Perfdata_6e8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-05 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-30 98304]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-05 1838592]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"BuildBU"="c:\dell\bldbubg.exe" [2006-01-30 61440]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-02 148888]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-01-30 26112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 106496]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]

c:\documents and settings\mary shumate.D7J9CC91.001\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2006-8-19 225280]
PowerReg Scheduler.exe [2006-9-15 256000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-1-30 156784]
Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe [2006-2-22 200704]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [Apr-11 10:10 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [Apr-11 10:09 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [Apr-11 10:09 AM 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [Jun-30 5:34 PM 276344]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [Apr-11 10:09 AM 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [Jun-28 8:34 PM 101936]
S0 xbdpv;xbdpv;c:\windows\system32\drivers\viwopzuv.sys --> c:\windows\system32\drivers\viwopzuv.sys [?]
S3 papycpu;papycpu; [x]
S3 pxark;pxark;c:\windows\system32\drivers\pxark.sys [Dec-08 5:10 PM 10624]
S3 XPAD910;XPADFilter Service 910;c:\windows\system32\drivers\xpad910.sys [Aug-16 4:35 PM 29405]
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{AEA4DE5E-37ED-4A91-A883-6D8953A84614} - (no file)


.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://google.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-03 17:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1016)
c:\windows\system32\cscdll.dll
.
Completion time: 2009-07-03 17:22
ComboFix-quarantined-files.txt 2009-07-03 22:22
ComboFix2.txt 2009-07-03 21:39

Pre-Run: 30,148,526,080 bytes free
Post-Run: 30,131,781,632 bytes free

171 --- E O F --- 2009-06-06 13:07
Go to the top of the page
 
+Quote Post
emeraldnzl
post Jul 3 2009, 08:11 PM
Post #10


Trusted Helper
Group Icon
Posts: 7,986
OS: XP Pro



Hello jazzy56,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
KillAll::

Driver::
xbdpv
papycpu

File::
c:\windows\system32\drivers\viwopzuv.sys


Save this as CFScript.txt, in the same location as ComboFix.exe



Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it will produce a log for you at C:\ComboFix.txt. Please post that here for further review.

Go to the top of the page
 
+Quote Post
jazzy56
post Jul 3 2009, 09:40 PM
Post #11


Member
**
Posts: 78
From: LOUISIANA
OS: XP media



How do I disable Malwarebytes, Do you also mean to disable Internet Explorer.. How do I do that. Thank you
Go to the top of the page
 
+Quote Post
jazzy56
post Jul 3 2009, 11:02 PM
Post #12


Member
**
Posts: 78
From: LOUISIANA
OS: XP media



Hello, Here is the log: I disabled Nortons Antivirus & spyware.

ComboFix 09-07-03.03 - mary shumate Jul-03 23:25.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.221 [GMT -5:00]
Running from: c:\documents and settings\mary shumate.D7J9CC91.001\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\mary shumate.D7J9CC91.001\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

FILE ::
"c:\windows\system32\drivers\viwopzuv.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_papycpu
-------\Service_xbdpv


((((((((((((((((((((((((( Files Created from 2009-06-04 to 2009-07-04 )))))))))))))))))))))))))))))))
.

2009-07-03 23:15 . 2009-04-11 16:05 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\NAVENG.SYS
2009-07-03 23:15 . 2009-04-11 16:05 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\NAVEX15.SYS
2009-07-03 23:15 . 2009-04-11 16:05 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\NAVENG32.DLL
2009-07-03 23:15 . 2009-04-11 16:05 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\NAVEX32A.DLL
2009-07-03 23:15 . 2009-04-11 16:05 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\EECTRL.SYS
2009-07-03 23:15 . 2009-04-11 16:05 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\ECMSVR32.DLL
2009-07-03 23:15 . 2009-04-11 16:05 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\CCERASER.DLL
2009-07-03 23:15 . 2009-04-11 16:05 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090703.023\ERASER.SYS
2009-07-03 16:13 . 2009-07-03 16:34 -------- d-----w- C:\Lop SD
2009-07-03 02:37 . 2009-07-03 02:37 -------- d-----w- C:\_OTL
2009-07-03 02:31 . 2009-07-03 02:31 -------- d-----w- C:\HostsXpert 4.2 - Hosts File Manager
2009-07-03 02:30 . 2009-07-03 02:30 353485 ----a-w- C:\HostsXpert 4.2 -.zip
2009-07-03 02:24 . 2009-07-03 02:24 353485 ----a-w- C:\HostsXpert 4.2 - Hosts File Manager.zip
2009-07-02 14:02 . 2009-07-02 14:01 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-30 22:34 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll
2009-06-30 22:34 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys
2009-06-30 22:34 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys
2009-06-30 22:34 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll
2009-06-30 22:34 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys
2009-06-30 16:29 . 2009-06-30 16:29 152576 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-06-29 19:50 . 2009-06-29 19:50 -------- d-----w- c:\program files\ESET
2009-06-27 20:48 . 2009-06-27 20:48 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-13 02:49 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\Scxpx86.dll
2009-06-13 02:49 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys
2009-06-13 02:49 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSvix86.sys
2009-06-13 02:49 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSxpx86.dll
2009-06-13 02:49 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSviA64.sys
2009-06-12 00:18 . 2006-02-10 02:05 520192 ------w- c:\windows\system32\ati2sgag.exe
2009-06-08 18:56 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\Scxpx86.dll
2009-06-08 18:56 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSXpx86.sys
2009-06-08 18:56 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSvix86.sys
2009-06-08 18:56 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSxpx86.dll
2009-06-08 18:56 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-02 13:59 . 2009-04-11 18:10 152576 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-29 04:10 . 2009-03-23 00:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-29 04:04 . 2009-05-02 20:54 -------- d-----w- c:\program files\ERUNT
2009-06-29 03:27 . 2009-04-10 15:11 1593120 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-29 03:27 . 2009-04-10 15:11 150428 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-29 03:27 . 2009-04-10 15:11 519788 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-29 03:27 . 2009-04-10 15:11 38730528 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-27 22:05 . 2009-03-30 23:59 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 16:27 . 2009-03-23 00:23 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 16:27 . 2009-03-23 00:23 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-12 00:17 . 2006-01-30 05:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-12 00:17 . 2006-01-30 05:48 -------- d-----w- c:\program files\ATI Technologies
2009-06-10 00:48 . 2008-06-12 00:02 -------- d-----w- c:\program files\Coupons
2009-05-25 00:30 . 2007-11-19 05:58 -------- d-----w- c:\program files\Game Elements
2009-05-22 23:18 . 2006-02-22 19:57 6686 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-22 23:18 . 2006-02-22 19:57 152 --sh--r- c:\windows\system32\580530C9BF.sys
2009-05-17 21:55 . 2009-05-17 21:55 -------- d-----w- c:\documents and settings\mary shumate.D7J9CC91.001\Application Data\U3
2009-05-07 15:32 . 2005-08-16 10:18 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-05 20:37 . 2009-05-05 03:43 -------- d-----w- c:\program files\EsetOnlineScanner
2009-04-29 04:56 . 2005-08-16 10:18 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2009-05-02 23:39 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2009-03-11 17:38 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2005-08-16 10:18 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-11 15:10 . 2009-04-10 22:39 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-04-11 15:10 . 2009-04-10 22:39 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-10 22:39 . 2009-04-10 22:39 1290584 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-04-10 22:39 . 2009-04-10 22:39 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-04-10 22:39 . 2009-04-10 22:39 800112 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-04-10 14:58 . 2006-02-22 20:03 43128 ----a-w- c:\documents and settings\mary shumate.D7J9CC91.001\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-02-12 00:15 . 2006-05-07 18:15 88 --sh--r- c:\windows\system32\BFC9300558.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-07-03_21.33.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-04 04:44 . 2009-07-04 04:44 16384 c:\windows\Temp\Perflib_Perfdata_69c.dat
+ 2009-07-04 04:44 . 2009-07-04 04:44 16384 c:\windows\Temp\Perflib_Perfdata_618.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-05 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-30 98304]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-05 1838592]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"BuildBU"="c:\dell\bldbubg.exe" [2006-01-30 61440]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-02 148888]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-01-30 26112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 106496]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]

c:\documents and settings\mary shumate.D7J9CC91.001\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2006-8-19 225280]
PowerReg Scheduler.exe [2006-9-15 256000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-1-30 156784]
Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe [2006-2-22 200704]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [Apr-11 10:10 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [Apr-11 10:09 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [Apr-11 10:09 AM 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [Jun-30 5:34 PM 276344]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [Apr-11 10:09 AM 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [Jun-28 8:34 PM 101936]
S3 pxark;pxark;c:\windows\system32\drivers\pxark.sys [Dec-08 5:10 PM 10624]
S3 XPAD910;XPADFilter Service 910;c:\windows\system32\drivers\xpad910.sys [Aug-16 4:35 PM 29405]
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{AEA4DE5E-37ED-4A91-A883-6D8953A84614} - (no file)


.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://google.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-03 23:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\MUSICM~1\MUSICM~3\MMDiag.exe
c:\program files\MUSICMATCH\Musicmatch Jukebox\mim.exe
c:\windows\system32\UAService7.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2009-07-04 23:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-04 04:56
ComboFix2.txt 2009-07-03 22:22
ComboFix3.txt 2009-07-03 21:39

Pre-Run: 30,297,505,792 bytes free
Post-Run: 30,337,126,400 bytes free

193 --- E O F --- 2009-06-06 13:07
Go to the top of the page
 
+Quote Post
emeraldnzl
post Jul 3 2009, 11:40 PM
Post #13


Trusted Helper
Group Icon
Posts: 7,986
OS: XP Pro



QUOTE
How do I disable Malwarebytes, Do you also mean to disable Internet Explorer.. How do I do that. Thank you


Malwarebytes (the free edition) is not a real time anti-malware program i.e. it is disabled unless you are running a scan with it.

Internet Explorer is a browser not an anti-malware program.

Now

You have used Malwarebytes before. If you still have it on your machine please update and run. Post the scan report back here.

If you no-longer have Malwarebytes please download from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Next

Kaspersky on line scanner is very thorough. It can take a long time and for periods may seem not to be working. Just be patient and let it do its job.

Kaspersky works with Internet Explorer and Firefox 3.

Go to Kaspersky website and perform an online antivirus scan.

Note: you will need to turn off your security programs to allow Kaspersky to do its job.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start dowanloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Copy and paste that information in your next post.

So when you return please post
  • MBAM log
  • Kaspersky scan results
  • and tell me how your machine is performing now
Go to the top of the page
 
+Quote Post
jazzy56
post Jul 4 2009, 12:14 AM
Post #14


Member
**
Posts: 78
From: LOUISIANA
OS: XP media



Here is the MBAM log it was Clean However I have 68 infections in Quarantine from previous runs.. Can these be removed.?? Thank You Kapersky will follow as soon as I finish running it.

Malwarebytes' Anti-Malware 1.38
Database version: 2371
Windows 5.1.2600 Service Pack 3

Jul-04 1:06:24 AM
mbam-log-2009-07-04 (01-06-24).txt

Scan type: Quick Scan
Objects scanned: 109351
Time elapsed: 6 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Go to the top of the page
 
+Quote Post
jazzy56
post Jul 4 2009, 12:22 AM
Post #15


Member
**
Posts: 78
From: LOUISIANA
OS: XP media



I cannot run Kapersky !!! A box appeared with this inside.
Starting Java applet has failed, please go online to use this program.. I am online with DSL. HELP !!!!

I tried going to thier website , it said download java 1.5 or more, I downloaded Jave again and same thing applet has failed.. No change, I cannot run Kapersky. My apology for taking so much of your time.

This post has been edited by jazzy56: Jul 4 2009, 12:54 AM
Go to the top of the page
 
+Quote Post

4 Pages V   1 2 3 > » 
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 7th November 2009 - 03:29 PM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising