Rtvscan.exe uses 100% CPU and infected with Trojan.Vundo [Solved] |
![]() ![]() |
Rtvscan.exe uses 100% CPU and infected with Trojan.Vundo [Solved] |
Sep 27 2009, 11:16 PM
Post
#1
|
|
|
New Member ![]() Posts: 9 OS: XP |
Thank you for your help! I seem to have a cascading problem that is resulting in a constant 100% CPU usage and repeated infection with Trojan.Vundo.
Rtvscan.exe loads immediately upon boot and consumes between 50-100% of the CPU. I have run MBAM, Symantec AV, SpyBot Search & Destroy repeatedly. MBAM continues to find multiple instances of Trojan Vundo, but it reappears after rebooting. Symantec Quick Scan finds "tenedefi.dll" and attempts to remove it every time I reboot, bu it reappears. I have completed the Malware and Spyware Cleaning Guide. I could not run RootRepeal. When I try to run it I get an initialization screen and nothing else. It does not open no matter how long I wait. Here are the OTL and MBAM log files. ------------------------------------------------------------------------------------ OTL logfile created on: 9/27/2009 6:12:36 PM - Run 1 OTL by OldTimer - Version 3.0.16.0 Folder = C:\Documents and Settings\JD\My Documents\JD's Downloads Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.50 Gb Total Physical Memory | 0.41 Gb Available Physical Memory | 27.07% Memory free 2.11 Gb Paging File | 1.21 Gb Available in Paging File | 57.35% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 180.00 Gb Total Space | 34.27 Gb Free Space | 19.04% Space Free | Partition Type: NTFS Drive D: | 6.29 Gb Total Space | 1.12 Gb Free Space | 17.85% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: DESKTOP Current User Name: JD Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan ========== Processes (SafeList) ========== PRC - [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe PRC - [2005/01/03 06:40:42 | 00,854,528 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe PRC - [2006/03/07 13:03:02 | 00,169,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe PRC - [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe PRC - [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE PRC - [2006/03/07 13:02:34 | 00,192,160 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe PRC - [2009/01/29 15:40:22 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe PRC - [2009/06/30 09:11:00 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe PRC - [2008/09/16 12:03:18 | 00,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe PRC - [2009/05/29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe PRC - [2006/02/23 11:41:02 | 00,100,032 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe PRC - [2006/03/17 06:34:12 | 00,030,448 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe PRC - [2008/04/13 14:12:18 | 00,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehSched.exe PRC - [2009/05/01 14:35:54 | 00,181,544 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe PRC - [2005/02/02 16:44:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\HP\KBD\KBD.EXE PRC - [2004/11/03 21:10:00 | 00,344,064 | ---- | M] (ATI Technologies, Inc.) -- C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe PRC - [2003/08/14 14:11:32 | 00,139,264 | ---- | M] (Alcor Micro, Corp.) -- C:\Program Files\Multimedia Card Reader\shwicon2k.exe PRC - [2003/05/23 00:55:38 | 00,483,328 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\hphmon05.exe PRC - [2005/01/12 09:54:58 | 00,241,664 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe PRC - [2004/07/29 02:53:58 | 00,053,248 | ---- | M] (GEAR Software) -- C:\WINDOWS\System32\GEARSec.exe PRC - [2002/10/07 05:23:20 | 00,090,112 | ---- | M] () -- C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe PRC - [2006/03/17 06:34:30 | 00,124,656 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\VPTray.exe PRC - [2004/11/22 17:20:54 | 01,126,400 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe PRC - [2006/03/07 13:02:14 | 00,053,408 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe PRC - [2000/09/22 10:13:40 | 00,227,328 | ---- | M] (Visioneer Inc.) -- C:\Program Files\Visioneer\PaperPort\FBDirect.exe PRC - [2006/07/07 13:14:38 | 00,576,320 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliType Pro\itype.exe PRC - [2006/03/17 06:34:12 | 00,024,816 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DoScan.exe PRC - [2006/07/07 13:15:07 | 00,600,896 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliPoint\ipoint.exe PRC - [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe PRC - [2002/08/28 15:39:50 | 00,455,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE PRC - [2009/05/01 14:35:10 | 00,185,640 | ---- | M] (Seagate LLC) -- C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe PRC - [2009/09/08 21:09:42 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe PRC - [2007/09/26 23:23:28 | 02,211,840 | ---- | M] (Ziff-Davis Media, Inc.) -- C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe PRC - [2009/03/05 16:07:20 | 02,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe PRC - [2009/01/13 21:10:40 | 00,342,848 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\DNA\btdna.exe PRC - [2007/03/11 21:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe PRC - [2008/05/26 22:19:14 | 00,123,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe PRC - [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe PRC - [2005/08/07 18:54:00 | 00,167,936 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe PRC - [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe PRC - [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe PRC - [2006/03/17 06:34:20 | 01,799,408 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe PRC - [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe PRC - [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe PRC - [2001/05/01 17:06:22 | 00,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MsPMSPSv.exe PRC - [2004/11/22 17:04:14 | 01,273,856 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe PRC - [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe PRC - [2008/04/13 14:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe PRC - [2009/09/09 19:15:54 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2004/10/08 11:52:32 | 00,221,184 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\System32\LVComsX.exe PRC - [2009/09/27 18:09:56 | 00,518,144 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JD\My Documents\JD's Downloads\OTL.exe ========== Win32 Services (SafeList) ========== SRV - [2008/09/16 12:03:18 | 00,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0 [Auto | Running]) SRV - [2009/05/29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running]) SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) SRV - [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running]) SRV - [2004/11/03 21:10:00 | 00,516,096 | ---- | M] () -- C:\WINDOWS\System32\ati2sgag.exe -- (ATI Smart [Auto | Stopped]) SRV - [2006/02/23 11:41:02 | 00,100,032 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler [Auto | Running]) SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running]) SRV - [2006/03/07 13:02:34 | 00,192,160 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [Auto | Running]) SRV - [2006/03/07 13:03:02 | 00,169,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running]) SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) SRV - [2006/03/17 06:34:12 | 00,030,448 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running]) SRV - [2008/04/13 14:12:18 | 00,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehSched.exe -- (ehSched [Auto | Running]) SRV - [2008/10/16 21:11:00 | 00,651,720 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped]) SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped]) SRV - [2009/05/01 14:35:54 | 00,181,544 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service [Auto | Running]) SRV - [2004/07/29 02:53:58 | 00,053,248 | ---- | M] (GEAR Software) -- C:\WINDOWS\System32\GEARSec.exe -- (GEARSecurity [Auto | Running]) SRV - [2009/08/07 12:44:18 | 00,045,816 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper [On_Demand | Stopped]) SRV - [2009/01/29 15:40:22 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c9827bbeb07656 [Auto | Stopped]) SRV - [2007/01/03 15:40:21 | 00,136,120 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped]) SRV - [2008/04/13 14:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running]) SRV - [2007/05/16 22:13:44 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08 [On_Demand | Running]) SRV - [2007/05/16 22:13:44 | 00,131,072 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc [Auto | Running]) SRV - [2007/05/16 22:13:08 | 00,602,112 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL -- (HPSLPSVC [Auto | Running]) SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped]) SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped]) SRV - [2005/01/03 06:40:42 | 00,854,528 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv [Auto | Running]) SRV - [2008/10/10 05:45:26 | 00,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService [Auto | Stopped]) SRV - [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running]) SRV - [2009/09/27 10:42:25 | 01,028,432 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service [On_Demand | Stopped]) SRV - [2006/02/23 11:41:02 | 02,045,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -- (LiveUpdate [On_Demand | Stopped]) SRV - [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS [Auto | Running]) SRV - [2008/11/24 22:31:08 | 00,045,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper [Disabled | Stopped]) SRV - [2006/10/31 13:56:24 | 00,043,520 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\HPZinw12.dll -- (Net Driver HPZ12 [Auto | Running]) SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped]) SRV - [2004/11/22 17:04:14 | 01,273,856 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe -- (Norton Ghost [Auto | Running]) SRV - [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped]) SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) SRV - [2006/10/31 13:56:28 | 00,052,736 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\HPZipm12.dll -- (Pml Driver HPZ12 [Auto | Running]) SRV - [2005/08/07 18:54:00 | 00,167,936 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe -- (RichVideo [Auto | Running]) SRV - [2006/03/17 06:34:24 | 00,115,952 | ---- | M] (symantec) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam [On_Demand | Stopped]) SRV - [2006/01/24 20:06:58 | 00,214,720 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [On_Demand | Stopped]) SRV - [2006/02/06 12:50:24 | 01,160,848 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc [On_Demand | Stopped]) SRV - [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser [Auto | Running]) SRV - [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter [Auto | Running]) SRV - [2006/03/17 06:34:20 | 01,799,408 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus [Auto | Running]) SRV - [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running]) SRV - [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running]) SRV - [2001/05/01 17:06:22 | 00,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MsPMSPSv.exe -- (WMDM PMSP Service [Auto | Running]) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.google.com/" FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1 FF - prefs.js..extensions.enabledItems: 6 FF - prefs.js..extensions.enabledItems: 2 FF - prefs.js..extensions.enabledItems: 41 FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.96 FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5 FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.32.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1 FF - prefs.js..extensions.enabledItems: statusbar@toodledo.com:1.60 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3 FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/24 03:04:09 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2009/09/08 10:18:41 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/09 19:16:03 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/09/09 19:16:03 | 00,000,000 | ---D | M] [2008/06/18 18:29:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Extensions [2008/06/18 18:29:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/09/27 11:31:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions [2008/04/20 09:59:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{1AF3FC34-0725-4485-A939-6B40EB7CA96A} [2009/06/26 19:17:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009/05/02 11:19:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} [2009/08/16 20:53:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2009/03/20 17:12:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\statusbar@toodledo.com [2008/10/12 18:10:36 | 00,000,276 | ---- | M] () -- C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\searchplugins\search.xml [2009/09/27 11:31:13 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/09/09 19:16:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2007/12/11 19:32:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2009/09/09 19:15:53 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/09/09 19:15:53 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2008/03/19 19:23:20 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll [2008/09/03 14:11:24 | 00,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\mozilla firefox\plugins\npbittorrent.dll [2008/06/17 20:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll [2007/10/11 14:17:50 | 01,435,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll [2009/09/09 19:15:56 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2007/05/10 22:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2006/09/07 10:08:58 | 00,618,496 | ---- | M] (Pixami) -- C:\Program Files\mozilla firefox\plugins\NPPxIm.dll [2006/09/07 10:08:58 | 00,819,200 | ---- | M] (Pixami) -- C:\Program Files\mozilla firefox\plugins\NPPxPrn.dll [2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2007/12/25 00:02:38 | 00,024,673 | ---- | M] (Check Point Software Technologies Ltd.) -- C:\Program Files\mozilla firefox\plugins\NPZoneSB.dll [2009/08/07 12:44:18 | 00,030,400 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\mozilla firefox\plugins\np_gp.dll [2009/08/15 07:48:37 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/08/15 07:48:37 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/08/15 07:48:37 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/08/15 07:48:37 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/08/15 07:48:37 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/08/15 07:48:37 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2009/08/15 07:48:37 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (319151 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 10945 more lines... O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.) O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (SpywareBlock Class) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - Reg Error: Value error. File not found O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll (Google Inc.) O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found. O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.) O3 - HKLM\..\Toolbar: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company) O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found. O3 - HKCU\..\Toolbar\ShellBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.) O3 - HKCU\..\Toolbar\ShellBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company) O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company) O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.) O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.) O4 - HKLM..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe () O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) O4 - HKLM..\Run: [HP Component Manager] C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company) O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe (Hewlett-Packard) O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard) O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation) O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation) O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation) O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation) O4 - HKLM..\Run: [KBD] C:\HP\KBD\KBD.EXE (Hewlett-Packard Company) O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC) O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe () O4 - HKLM..\Run: [Norton Ghost 9.0] C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe (Symantec Corporation) O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [PP7600usb] C:\Program Files\Visioneer\PaperPort\FBDirect.exe (Visioneer Inc.) O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE () O4 - HKLM..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe (Alcor Micro, Corp.) O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation) O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD) O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKCU..\Run: [Startup Cop Pro Startup Launcher] C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe (Ziff-Davis Media, Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Zone Labs Security.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD) O4 - Startup: C:\Documents and Settings\JD\Start Menu\Programs\Startup\TempClean.bat () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0 O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O8 - Extra context menu item: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html () O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html () O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html () O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.) O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll (Google Inc.) O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html () O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html () O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html () O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html () O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html () O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html () O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: PokerTime.net Poker - {E28AB5C9-B58F-4512-AF80-29001BC5A29D} - C:\Program Files\PokerTimeGuestMPP\MPPoker.exe (Microgaming) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites) O15 - HKCU\..Trusted Domains: 69 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://activation.rr.com/install/download/tgctlcm.cab (Support.com Configuration Class) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object) O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} https://quicken.ehosts.net/netagent/objects/custappx3.CAB (eAssist NetAgent Customer ActiveX Control version 3) O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab (LSSupCtl Class) O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} http://asp.mathxl.com/wizmodules/testgen/i...GenXInstall.cab (TTestGenXInstallObject) O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine) O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://spaces.msn.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1231725258781 (MUWebControl Class) O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll (InstallHelper Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll (There Voice Trainer) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab (Pearson Installation Assistant 2) O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} http://download.zonelabs.com/bin/promotion...ctor/WebSWK.cab (WebSpyWareKiller Class) O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab (Anonymizer Anti-Spyware Scanner) O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} file://c:\Program Files\There\ThereClient\ThereLauncher.dll (There Launcher) O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse...pDownloader.cab (MsnMessengerSetupDownloadControl Class) O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} https://www-secure.symantec.com/techsupp/asa/SymAData.cab (ActiveDataInfo Class) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object) O16 - DPF: {D44C75D8-C827-473E-8F68-A77E42500782} http://www.samsphotoclub.com/upload/WebUploadClient.cab (Uploader Class) O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} http://asp.mathxl.com/books/_Players/EconPlayer.cab (Pearson MyEconLab Player Control) O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} http://216.249.24.60/code/iPIX-ImageWell-ipix.cab (iPIX Media Send Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.25.227.55 209.18.47.61 24.25.227.53 O18 - Protocol\Handler\bw+0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw+0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw-0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw00 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw00s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw-0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw10 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw10s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw20 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw20s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw30 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw30s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw40 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw40s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw50 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw50s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw60 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw60s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw70 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw70s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw80 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw80s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw90 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw90s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwa0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwa0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwb0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwb0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwc0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwc0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwd0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwd0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwe0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwe0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwf0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwf0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwg0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwg0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwh0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwh0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwi0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwi0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwj0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwj0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwk0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwk0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwl0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwl0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwm0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwm0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwn0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwn0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwo0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwo0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwp0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwp0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwq0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwq0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwr0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwr0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bws0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bws0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwt0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwt0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwu0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwu0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwv0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwv0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bww0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bww0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwx0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwx0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwy0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwy0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwz0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwz0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\offline-8876480 {9EB19210-0033-48C0-94F0-164D35CB93DB} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (c:\windows\system32\gisisema.dll) - C:\WINDOWS\System32\gisisema.dll File not found O20 - AppInit_DLLs: (c:\windows\system32\) - C:\WINDOWS\System32 [2009/09/27 17:57:52 | 00,000,000 | ---D | M] O20 - AppInit_DLLs: (c:\windows\system32\yudegoku.dll) - C:\WINDOWS\System32\yudegoku.dll File not found O20 - AppInit_DLLs: (tenedefi.dll) - C:\WINDOWS\System32\tenedefi.dll () O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.) O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation) O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\System32\NavLogon.dll (Symantec Corporation) O21 - SSODL: ganokiboy - {324fc3bb-4f3e-4c51-84b7-1689cfe42ed0} - C:\WINDOWS\System32\yudegoku.dll File not found O21 - SSODL: kawuhesud - {de4e9e38-28ca-4548-8ac1-ad002276dd90} - C:\WINDOWS\System32\gisisema.dll File not found O22 - SharedTaskScheduler: {324fc3bb-4f3e-4c51-84b7-1689cfe42ed0} - tokatiluy - C:\WINDOWS\System32\yudegoku.dll File not found O22 - SharedTaskScheduler: {de4e9e38-28ca-4548-8ac1-ad002276dd90} - tokatiluy - C:\WINDOWS\System32\gisisema.dll File not found O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2003/12/16 19:45:52 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2001/07/28 06:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ] O32 - AutoRun File - [2002/09/11 03:02:32 | 00,000,045 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ] O33 - MountPoints2\{391dd251-46bc-11dd-b7f4-000ea6c3bfc8}\Shell\AutoRun\command - "" = .\Encryption Tool\MaxtorEncryption.exe O33 - MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\AutoRun\command - "" = F:\PortableRoboForm.exe -- File not found O33 - MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\RoboForm2Go\command - "" = F:\PortableRoboForm.exe -- File not found O33 - MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\AutoRun\command - "" = J:\Autorun.exe -- File not found O33 - MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell00\Command - "" = J:\Autorun.exe -- File not found O33 - MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell01\Command - "" = J:\Autorun.exe -- File not found O33 - MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell02\Command - "" = J:\Autorun.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe () NetSvcs: 6to4 - Service key not found. File not found NetSvcs: Ias - Service key not found. File not found NetSvcs: Iprip - Service key not found. File not found NetSvcs: Irmon - Service key not found. File not found NetSvcs: NWCWorkstation - Service key not found. File not found NetSvcs: Nwsapagent - Service key not found. File not found NetSvcs: WmdmPmSp - Service key not found. File not found NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) ========== Files/Folders - Created Within 14 Days ========== [2009/09/27 17:57:55 | 16,099,45088 | -HS- | C] () -- C:\hiberfil.sys [2009/09/27 15:47:27 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2009/09/27 14:20:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2009/09/27 14:19:31 | 00,000,622 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk [2009/09/27 14:19:31 | 00,000,603 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\ERUNT.lnk [2009/09/27 14:19:29 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT [2009/09/27 13:10:24 | 00,000,000 | ---D | C] -- C:\VundoFix Backups [2009/09/27 13:02:28 | 00,001,559 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\CCleaner.lnk [2009/09/27 13:02:26 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner [2009/09/27 11:24:43 | 03,550,592 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\JD\Desktop\iexplore.exe [2009/09/25 05:56:21 | 00,000,095 | ---- | C] () -- C:\WINDOWS\wininit.ini ========== Files - Modified Within 14 Days ========== [2009/09/27 18:18:09 | 00,011,168 | -H-- | M] () -- C:\WINDOWS\System32\mehudebe [2009/09/27 18:17:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2009/09/27 18:04:46 | 00,350,197 | -H-- | M] () -- C:\WINDOWS\System32\vsconfig.xml [2009/09/27 17:58:44 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2009/09/27 17:58:43 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/09/27 17:58:00 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/09/27 17:57:55 | 16,099,45088 | -HS- | M] () -- C:\hiberfil.sys [2009/09/27 17:56:38 | 04,401,936 | -H-- | M] () -- C:\Documents and Settings\JD\Local Settings\Application Data\IconCache.db [2009/09/27 16:30:01 | 00,000,966 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job [2009/09/27 15:16:16 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/09/27 14:19:31 | 00,000,622 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk [2009/09/27 14:19:31 | 00,000,603 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\ERUNT.lnk [2009/09/27 13:02:28 | 00,001,559 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\CCleaner.lnk [2009/09/27 11:24:48 | 03,550,592 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\JD\Desktop\iexplore.exe [2009/09/27 10:43:19 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2009/09/27 09:30:00 | 00,000,914 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job [2009/09/27 04:00:15 | 00,000,804 | ---- | M] () -- C:\WINDOWS\tasks\Incremental Backup.job [2009/09/25 16:58:50 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk [2009/09/25 05:56:21 | 00,000,095 | ---- | M] () -- C:\WINDOWS\wininit.ini [2009/09/22 09:15:28 | 00,000,768 | ---- | M] () -- C:\WINDOWS\tasks\Media Backup Schedule.job [2009/09/18 15:35:23 | 00,002,272 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\Google Chrome.lnk [2009/09/14 15:27:52 | 00,000,832 | ---- | M] () -- C:\WINDOWS\tasks\Full Backups.job ========== LOP Check ========== [2009/09/27 11:42:58 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data [2009/03/27 19:12:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3} [2009/02/03 23:42:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} [2009/09/09 19:25:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} [2009/01/25 10:40:14 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800} [2009/04/09 19:04:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} [2005/04/10 06:27:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{A695AD8D-651B-4C8A-91DF-51F853449A57} [2004/12/29 19:20:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ahead [2008/04/20 14:23:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink [2007/12/31 14:24:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink [2008/10/17 18:50:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData [2008/10/17 17:36:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet [2009/01/24 17:26:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intuit [2007/10/01 16:43:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier [2003/12/16 23:06:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive [2006/01/05 10:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PureEdge [2005/03/10 15:28:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm [2003/12/16 19:51:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI [2009/09/01 22:35:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate [2005/09/19 20:49:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Support.com [2008/10/13 08:54:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2007/12/30 22:23:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tenebril [2005/11/26 13:07:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia [2004/12/30 14:55:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems [2008/11/14 22:02:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint [2009/06/08 17:58:13 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\JD\Application Data [2007/12/31 15:31:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\2K Games [2007/12/30 22:11:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\AccurateRip [2004/12/29 19:49:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Ahead [2007/12/01 14:33:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Amazon [2009/01/17 16:22:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Any Video Converter [2004/12/29 16:44:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\ArcSoft [2009/08/02 20:43:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\BitTorrent [2007/12/28 15:35:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\BookmarkBridge [2004/11/14 11:07:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Common Files [2008/04/20 14:23:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\CyberLink [2009/09/27 18:11:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\DNA [2009/08/03 05:11:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\DVD Flick [2009/06/11 19:56:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\dvdcss [2004/11/02 15:30:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\EuroTalk [2005/08/21 11:48:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\FotoWire [2008/06/29 19:22:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\gtk-2.0 [2007/11/25 15:09:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\interMute [2004/09/10 15:48:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\InterVideo [2008/07/22 18:02:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Intuit [2009/02/07 20:01:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\IObit [2008/01/05 15:59:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\iPhoneRingToneMaker [2004/11/02 12:45:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\IsolatedStorage [2006/10/14 20:15:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\LaCie [2007/01/26 17:21:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Leadertech [2008/12/16 20:26:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\LimeWire [2005/12/22 12:17:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Microgaming [2004/08/24 14:37:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Motive [2005/08/27 06:44:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Musicmatch [2007/07/27 22:45:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\NGC_IKTS [2005/12/24 11:01:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\OLYMPUS [2009/01/16 09:56:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PC Magazine Utilities [2008/10/17 18:52:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1 [2006/05/28 08:05:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Premiere [2006/01/05 10:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PureEdge [2007/12/13 22:26:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Roxio [2003/12/16 23:23:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\SampleView [2004/12/05 13:02:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\spweng [2007/12/30 22:23:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Tenebril [2009/09/21 21:20:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\U3 [2004/12/30 15:27:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Ulead Systems [2008/11/14 22:03:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Viewpoint [2009/05/13 06:36:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Windows Desktop Search [2009/06/08 17:58:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Windows Search [2009/09/27 10:43:19 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job [2009/09/10 18:03:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job [2003/07/30 09:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini [2009/09/14 15:27:52 | 00,000,832 | ---- | M] () -- C:\WINDOWS\Tasks\Full Backups.job [2009/09/27 17:58:44 | 00,000,882 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [2009/09/27 18:17:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [2009/09/27 09:30:00 | 00,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job [2009/09/27 16:30:01 | 00,000,966 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job [2009/09/27 04:00:15 | 00,000,804 | ---- | M] () -- C:\WINDOWS\Tasks\Incremental Backup.job [2009/09/22 09:15:28 | 00,000,768 | ---- | M] () -- C:\WINDOWS\Tasks\Media Backup Schedule.job [2009/09/27 17:58:43 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < %systemroot%\system32\eventlog.dll > [2008/04/13 14:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll < %systemroot%\system32\scecli.dll > [2008/04/13 14:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll < %systemroot%\netlogon.dll > < %systemroot%\system32\cngaudit.dll > < %systemroot%\system32\sceclt.dll > < %systemroot%\ntelogon.dll > < %systemroot%\system32\logevent.dll > ========== Alternate Data Streams ========== @Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:825D5945 < End of report > ----------------------------------------------------------------------------------- OTL Extras logfile created on: 9/27/2009 6:12:36 PM - Run 1 OTL by OldTimer - Version 3.0.16.0 Folder = C:\Documents and Settings\JD\My Documents\JD's Downloads Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.50 Gb Total Physical Memory | 0.41 Gb Available Physical Memory | 27.07% Memory free 2.11 Gb Paging File | 1.21 Gb Available in Paging File | 57.35% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 180.00 Gb Total Space | 34.27 Gb Free Space | 19.04% Space Free | Partition Type: NTFS Drive D: | 6.29 Gb Total Space | 1.12 Gb Free Space | 17.85% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: DESKTOP Current User Name: JD Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation) .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde File not found htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- Reg Error: Key error. http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" %* File not found txtfile [edit] -- Reg Error: Key error. Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusOverride" = 0 "FirewallOverride" = 0 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech) "C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 -- (Microsoft Corporation) "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation) "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger -- (Logitech) "C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 -- (Microsoft Corporation) "C:\WINDOWS\pchealth\helpctr\Binaries\helpctr.exe" = C:\WINDOWS\pchealth\helpctr\Binaries\helpctr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice -- (Microsoft Corporation) "C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe" = C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax -- (Intuit, Inc.) "C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager -- (Intuit, Inc.) "E:\setup\HPZNUI01.EXE" = E:\setup\HPZNUI01.EXE:*:Enabled:hpznui01.exe -- File not found "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe -- () "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard) "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe -- () "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe -- (Hewlett-Packard Co.) "C:\WINDOWS\system32\hpzipm12.exe" = C:\WINDOWS\system32\hpzipm12.exe:*:Enabled:hpzipm12 -- (HP) "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found "C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe" = C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 Gold -- (Firaxis Games) "C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe" = C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization 4: Warlords -- (Firaxis Games) "C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax -- (Intuit, Inc.) "C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager -- (Intuit, Inc.) "C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe" = C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe:*:Disabled:Adobe Photoshop Elements Media Server -- (Adobe Systems Incorporated) "C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.) "C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA -- (BitTorrent, Inc.) "C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.) "C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server -- (Intuit Inc.) "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation) "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.) "C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe" = C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe:*:Enabled:StartupCopPro -- (Ziff-Davis Media, Inc.) "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe:*:Enabled:zlclient -- (Check Point Software Technologies LTD) "C:\WINDOWS\system32\wscntfy.exe" = C:\WINDOWS\system32\wscntfy.exe:*:Enabled:wscntfy -- (Microsoft Corporation) "C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe" = C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe:*:Enabled:16496404 -- File not found "C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer -- (Microsoft Corporation) "C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe" = C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe:*:Enabled:14267034 -- File not found ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc "{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{086E6C0B-627B-4CC0-A87B-A0166260B15D}" = Business, Investment and Growth 2.0 "{092eeeee-9fdd-4895-a568-0818c96beb6c}" = AiO_Scan "{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager "{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics "{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel "{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support "{0D2E80C8-0875-43EB-9623-47118E2DFBCA}" = Quicken 2007 "{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp "{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up "{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1 "{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch "{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo "{145CACAF-9B34-41FC-BE49-7D510A253E78}" = Multimedia Card Reader "{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy "{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR "{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS "{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite "{21DAFB84-2421-488F-B17D-102FF53396AA}" = Ulead DVD Player "{231A1A09-FDF2-45F2-B3D1-964CECE372BC}" = Seagate Manager Installer "{2583DCD3-7A78-4F88-8F91-BBA5C7EB5444}" = Microsoft Broadband Networking "{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition "{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation "{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg "{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp "{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) "{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0 "{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}" = TurboTax ItsDeductible 2005 "{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan "{3207208B-A2E1-4326-95E8-6642443B1DD2}" = MUSICMATCH Media Center "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3 "{324CEC09-007A-48eb-90E0-9D42D4D5EB0A}" = NetDeviceManager "{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{36495C59-089C-49D1-BD15-9E5BD86DC9A1}" = ItsDeductible Express "{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel "{3C759736-8347-4031-BB9C-D75ADFE6B101}" = Norton Ghost 9.0 "{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics "{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10 "{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth "{405ABBEB-8DF1-4174-86C0-DCB5E1C78F14}" = NetDeviceManager "{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing "{4394DC3A-5DAC-4C80-A86E-FF462D0AD653}" = Windows 7 Upgrade Advisor Beta "{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer "{44B2E182-DD85-45FC-9F51-326B81D7C7F1}" = Fax "{45B6180B-DCAB-4093-8EE8-6164457517F0}" = Photosmart 140,240,7200,7600,7700,7900 Series "{46DDF76F-ACD4-42BC-B48F-B89C4EE2E1A9}" = Easy CD & DVD Creator 6 "{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply "{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0 "{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout "{4FB6F304-A91D-4919-98E5-D96E074EA9E5}" = SkinsHP1 "{53EF7D4D-374D-4E39-9859-5504A5352BD7}" = MCESleepTimerV2.0 "{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English) "{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport "{54e854d5-d5d4-452d-9c75-b39f5625b5fb}" = Readme "{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer "{5AA18C57-381C-4C99-8FE6-5EB1CB0A5BC0}" = ImageMixer "{5ADF6293-D60F-4425-AFA7-CEB820DB872B}" = QuickProjects "{5D7F0A0E-369E-46C0-9F99-FAB21A064781}" = HP Photo and Imaging 2.0 - Photosmart Cameras "{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG ODD Auto Firmware Update "{64FC0C98-B035-4530-B15D-3D30610B6DF1}" = HP Software Update "{66C018BD-6F16-4B32-B4CD-1DC1B21FBDFF}" = Zone Deluxe Games "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{6C117F31-28A8-4477-BE91-64AC0A2204AD}" = Microsoft IntelliPoint 6.01 "{6DD9963C-271A-4A14-82B0-4DC148C52E58}" = LaCie Backup Software v1.5.2042 "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder "{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2 "{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone "{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare "{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset "{757AD3D4-036B-42FA-B0A4-96BD6F4605A0}" = Ulead VideoStudio 7 SE DVD "{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland "{791B20D4-AE59-4DE9-B45F-BA01F3D0A493}" = ArcSoft ShowBiz 2 "{7A1F1E81-A017-43EE-8A24-E88878164C91}" = SeaWorld Adventure Parks Tycoon 3D "{7BBD57D6-09B1-4CC3-9664-A0D53EE25247}" = PSShortcutsP "{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English "{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder "{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine "{88F93347-0F9B-4FED-BA71-6C2A4CDFE61D}" = Ulead DVD MovieFactory 2 SE "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver "{8BABDC16-04D1-4263-B3E7-A9E5F33A5969}" = NGC: Investor's Key To Real Estate "{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update "{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox "{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12 "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90AD8C11-ED4A-4AE7-BB70-7740C452C999}" = Visual J# .NET Redistributable Package "{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player "{93F54611-2701-454e-94AB-623F458D9E6B}" = DeviceDiscovery "{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector "{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = RecordNow! "{961D35E8-D426-3E2E-8222-F4FFD9E104FD}" = Google Gears "{96976098-9527-41E4-837E-EAA1DBEADB54}" = TurboTax 2008 whiiper "{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime "{9F4EEA0C-7174-4BD3-89AF-7AB2F9F6AEDD}" = hpmdtab "{A011A1DC-7F1D-4EA8-BD11-0C5F9718E428}" = Symantec AntiVirus "{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime "{A1960A82-DB70-474D-A86B-FA74466103C6}" = Drivers Install For Linksys Easylink Advisor "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A363B66C-1547-47bf-90F0-3834E70A841A}" = CreativeProjects "{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime "{A53A1A49-C3EA-406c-B87C-8E02B622D605}" = C7200_doccd "{A9212616-FCA2-4173-BD99-5C741EB3A068}" = Ulead DVD PictureShow 2 SE "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2 "{AD13BFB0-FDD2-4AFA-A8AF-9F4A950D56B7}" = ArcSoft Camera Suite 1.3 "{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant "{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan "{AFBBF30D-ADA9-4313-464E-14458B6BE034}" = PhotoshopdotcomInspirationBrowser "{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006 "{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper "{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport "{B34E4B72-37C6-4f79-A5B3-008EEFC6EA8B}" = PS_AIO_02_Software_min "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B46AC30C-22D2-4610-B041-1DA7BB29EB57}" = HP Photosmart All-In-One Software 9.0 "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer "{B7E5D642-E74E-40a4-B5C7-6AB6EE916814}" = PS_AIO_02_ProductContext "{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master "{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5 "{BC10649A-983B-494e-AD1F-DE0BF717D701}" = PS_AIO_02_Software "{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter "{BD57EA4D-026E-4F08-9B93-080E282B81FE}" = iPod for Windows 2006-06-28 "{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client "{BD76AF27-5CD9-4848-87FC-12285A90AE6A}" = c7200_Help "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{c330461f-c4a9-4fc7-af5d-c158e0b56aa7}" = AiOSoftware "{C38BC5B7-62D3-4880-82DD-A4803FD81921}" = PhotoGallery "{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software "{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}" = Microsoft Plus! Digital Media Edition "{C9618743-1A5C-461E-91C4-E013A3D70F3C}" = Adobe® Photoshop® Album Starter Edition 3.0.1 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CB6075D9-F912-40AE-BEA6-E590DA24F16B}" = Adobe Photoshop Elements 7.0 "{CDF64407-E968-4AC8-8323-A1DDBE5A8D72}" = Quicken Home Inventory Manager "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}" = MSN Messenger 7.5 "{CECEB0FF-5C45-4b50-9A00-C596E36D88F4}" = C7200 "{CFD1B282-555D-494d-8231-4175C2AF08C2}" = PrintScreen "{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component "{D545BB81-DEB0-49f7-BE26-197BC31AAF57}" = SkinsHP2 "{D75915D3-6CFF-445F-A346-18ED6EF2F618}" = Microsoft IntelliType Pro 6.01 "{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware "{E0000600-0600-0600-0600-000000000600}" = ICS Viewer 6.0 "{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide® Viewer ActiveX Control Release 6.5 "{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01 "{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm "{E2750613-73F1-43B9-9B0B-387E5543971F}" = CD LabelMaker 5 "{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager "{E4ABB302-9D82-4D18-83D5-AD1DFE786AA8}" = Unload "{E56D39F8-2A9F-44B4-B068-A72E45A073E6}" = Safari "{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp "{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox "{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks "{EC2A8F27-4FBF-4E41-B27B-FE822511B761}" = iTunes "{ec7d7a6a-31cb-4810-826f-74171bef44f1}" = AIOMinimal "{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer "{F247869D-3643-4A9F-821B-3534145928E3}" = HPIZ311 "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}" = HP PSC & OfficeJet 3.0 "{F419D20A-7719-4639-8E30-C073A040D878}" = HP Deskjet Preloaded Printer Drivers "{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility "{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard "{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status "36317AE4-57EC-4F3E-B828-009A3DD96BE8" = Polar Bowler from Hewlett-Packard Desktops (remove only) "62067F4C-84A9-45B9-8573-B90468B0A3EF" = Orbital from Hewlett-Packard Desktops (remove only) "Abacast Client" = Abacast Client "Ad-Aware" = Ad-Aware "Adobe AIR" = Adobe AIR "Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Photoshop Elements 7" = Adobe Photoshop Elements 7.0 "Adobe Shockwave Player" = Adobe Shockwave Player 11 "Advanced SystemCare 3_is1" = Advanced SystemCare 3 "Age of Empires 2.0" = Microsoft Age of Empires II "All ATI Software" = ATI - Software Uninstall Utility "Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3 "Any Video Converter_is1" = Any Video Converter 2.6.7 "ATI Display Driver" = ATI Display Driver "Audacity_is1" = Audacity 1.2.6 "Avi2Dvd" = Avi2Dvd 0.4.5 beta "Avidemux 2.4" = Avidemux 2.4 "AviSynth" = AviSynth 2.5 "BackWeb-137903 Uninstaller" = Updates from HP "Bookmarkbridge" = BookmarkBridge 0.76 "CCleaner" = CCleaner (remove only) "Coupon Printer for Windows4.0" = Coupon Printer for Windows "dBpoweramp AAC Encoder" = dBpoweramp AAC Encoder "dBpoweramp m4a Codec" = dBpoweramp m4a Codec "dBpoweramp m4a Utilities" = dBpoweramp m4a Utilities "dBpoweramp Music Converter" = dBpoweramp Music Converter "DHCP Convertor" = DHCP Convertor "DVD Flick_is1" = DVD Flick "DVD Shrink_is1" = DVD Shrink 3.2 "EasyLinkAdvisor" = Linksys EasyLink Advisor 1.6 (0032) "ENTERPRISER" = Microsoft Office Enterprise 2007 "ERUNT_is1" = ERUNT 1.1j "EuroTalk Talk Now Plus!" = EuroTalk Talk Now Plus! "exPressit S.E. 3.0" = exPressit S.E. 3.0 "Free Video to iPhone Converter_is1" = Free Video to iPhone Converter version 2.1 "Guild Wars" = Guild Wars "HandBrake" = HandBrake 0.9.3 "HD Tune_is1" = HD Tune 2.55 "HP Imaging Device Functions" = HP Imaging Device Functions 9.0 "HP Instant Support" = HP Instant Support "HP Photo & Imaging" = HP Photo & Imaging 3.1 "HP Photosmart Essential" = HP Photosmart Essential 2.5 "HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0 "HPExtendedCapabilities" = HP Customer Participation Program 9.0 "HPOCR" = HP OCR Software 9.0 "HPTOOLKIT" = toolkit "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "iGolfNeo" = iGolf Neo Sync Application "iLyrics" = iTunes Lyrics Importer "InCD!UninstallKey" = InCD "InstallShield_{145CACAF-9B34-41FC-BE49-7D510A253E78}" = Multimedia Card Reader "InstallShield_{231A1A09-FDF2-45F2-B3D1-964CECE372BC}" = Seagate Manager Installer "InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10 "InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master "InstallShield_{BD57EA4D-026E-4F08-9B93-080E282B81FE}" = iPod for Windows 2006-06-28 "InterActual Player" = InterActual Player "IrfanView" = IrfanView (remove only) "ItsDeductible7" = ItsDeductible7 "JDiskReport 1.2.1" = JGoodies JDiskReport 1.2.1 "LaCie Device Updater" = LaCie Device Updater "LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation) "Logitech Print Service" = Logitech Print Service "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft SQL Server 2005" = Microsoft SQL Server 2005 "Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3) "MSN Music Assistant" = MSN Music Assistant "MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English) "MUSICMATCH Radio" = MUSICMATCH® MX Web Player "MWASPI" = MicroStaff WINASPI "Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition "NeroVision!UninstallKey" = NeroVision Express 3 "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "NMIX!UninstallKey" = NeroMIX "NMPUninstallKey" = Nero Media Player "NVEContent!UninstallKey" = NeroVision Express Content "NVIDIA" = "Paint Shop Pro 6.0" = Paint Shop Pro 6.0 (ESD) "Paint Shop Pro 6.02 Patch" = Paint Shop Pro 6.02 Patch "PC Magazine Defrag-A-File 2_is1" = PC Magazine Defrag-A-File 2.0.2 "PC Magazine Folders 2_is1" = PC Magazine Folders 2 "Pcsx2_is1" = Pcsx2 0.9.4 Watermoose "PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1" = Adobe Photoshop.com Inspiration Browser "Picasa2" = Picasa 2 "PokerTime.net Poker" = PokerTime.net Poker "PS2" = PS2 "Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions "Python 2.2.1" = Python 2.2.1 "QcDrv" = Logitech® Camera Driver "Quicken Legal Business Pro 2007" = Quicken Legal Business Pro 2007 "Railroad Tycoon II" = Railroad Tycoon II "RealAlt_is1" = Real Alternative 1.23 "Rosetta Stone 2.1.5.0A" = Rosetta Stone 2.1.5.0A "SereneScene Marine Aquarium 2" = SereneScene Marine Aquarium 2 "Sid Meier's Alpha Centauri" = Sid Meier's Alpha Centauri "SimCity 3000" = SimCity 3000 "SPSS for Windows Student Version 11.0" = SPSS 11.0 for Windows Student Version "Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4 "Startup Cop Pro_is1" = Startup Cop Pro 3.0 "TurboTax 2008" = TurboTax 2008 "TurboTax Premier 2003" = TurboTax Premier 2003 "TurboTax Premier 2004" = TurboTax Premier 2004 "TurboTax Premier 2005" = TurboTax Premier 2005 "TurboTax Premier 2007" = TurboTax Premier 2007 "TurboTax Premier Investments 2006" = TurboTax Premier Investments 2006 "tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine "Uninstall_is1" = Uninstall 1.0.0.1 "Viewpoint Manager" = Viewpoint Manager (Remove Only) "Visioneer 7600 Scanner Driver" = Visioneer 7600 Scanner Driver "Visioneer PaperPort 6.1" = Visioneer PaperPort 6.1 "VLC media player" = VLC media player 0.9.8a "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 "Windows Media Format Runtime" = Windows Media Format Runtime "Windows Media Player" = Windows Media Player 10 "Windows XP Service Pack" = Windows XP Service Pack 3 "Xfire" = Xfire (remove only) "ZoneAlarm" = ZoneAlarm "ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{55502C49-F061-428C-BF26-06ECDFB3AC29}" = Sid Meier's Civilization 4 Gold "AI RoboForm" = AI RoboForm "BitTorrent" = BitTorrent "BitTorrent DNA" = DNA "Google Chrome" = Google Chrome ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 9/27/2009 8:02:08 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 Description = Security Risk Found!Risk: Trojan.Vundo in File: Unavailable by: Invalid : (15) scan. Action: Delete failed. Action Description: The file was left unchanged. Error - 9/27/2009 10:06:35 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 Description = Security Risk Found!Risk: Trojan.Vundo in File: Unavailable by: Invalid : (15) scan. Action: Delete failed. Action Description: The file was left unchanged. Error - 9/27/2009 10:06:36 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 Description = Risk Found!Risk: Trojan.Vundo in File: c:\windows\system32\noyusoda.dll by: Invalid : (15) scan. Action: Delete succeeded. Action Description: The file was deleted successfully. Error - 9/27/2009 10:06:43 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711731 Description = Security Risk Found!Risk: Trojan.Vundo in File: Unavailable by: Invalid : (15) scan. Action: Delete failed : Leave Alone failed. Action Description: Error - 9/27/2009 10:07:05 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 Description = Security Risk Found!Risk: Trojan.Vundo in File: Unavailable by: Invalid : (15) scan. Action: Delete failed. Action Description: The file was left unchanged. Error - 9/27/2009 10:07:06 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 Description = Risk Found!Risk: Trojan.Vundo in File: c:\windows\system32\noyusoda.dll by: Invalid : (15) scan. Action: Delete succeeded. Action Description: The file was deleted successfully. Error - 9/27/2009 10:07:06 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 Description = Risk Found!Risk: Trojan.Vundo in File: c:\windows\system32\kesibahi.dll by: Invalid : (15) scan. Action: Delete succeeded. Action Description: The file was deleted successfully. Error - 9/27/2009 10:37:58 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 Description = Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\rundll32.exe by: Invalid : (15) scan. Action: Delete failed. Action Description: The file was left unchanged. Error - 9/27/2009 2:44:24 PM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 Description = Security Risk Found!Risk: Trojan.Vundo in File: Unavailable by: Invalid : (15) scan. Action: Delete failed. Action Description: The file was left unchanged. Error - 9/27/2009 2:44:24 PM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 Description = Risk Found!Risk: Trojan.Vundo in File: c:\windows\system32\noyusoda.dll by: Invalid : (15) scan. Action: Delete succeeded. Action Description: The file was deleted successfully. [ System Events ] Error - 8/23/2009 1:56:01 PM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 Description = The TrueVector Internet Monitor service failed to start due to the following error: %%1053 Error - 8/24/2009 11:24:31 PM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect. Error - 8/24/2009 11:24:31 PM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 Description = The TrueVector Internet Monitor service failed to start due to the following error: %%1053 Error - 8/27/2009 1:27:18 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect. Error - 8/27/2009 1:27:18 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 Description = The TrueVector Internet Monitor service failed to start due to the following error: %%1053 Error - 8/30/2009 12:43:18 AM | Computer Name = DESKTOP | Source = LDMS | ID = 16780230 Description = Unhandled exception, exception code=6B Error - 8/30/2009 1:19:10 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect. Error - 8/30/2009 1:19:10 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 Description = The TrueVector Internet Monitor service failed to start due to the following error: %%1053 Error - 8/30/2009 1:42:42 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect. Error - 8/30/2009 1:42:43 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 Description = The TrueVector Internet Monitor service failed to start due to the following error: %%1053 < End of report > ------------------------------------------------------------------------------------ Malwarebytes' Anti-Malware 1.41 Database version: 2866 Windows 5.1.2600 Service Pack 3 9/27/2009 3:09:18 PM mbam-log-2009-09-27 (15-09-18).txt Scan type: Quick Scan Objects scanned: 139641 Time elapsed: 33 minute(s), 10 second(s) Memory Processes Infected: 0 Memory Modules Infected: 3 Registry Keys Infected: 1 Registry Values Infected: 4 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 7 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: c:\WINDOWS\system32\borababu.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\tenedefi.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\derupili.dll (Trojan.Vundo) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{c3314a31-d91d-4cfb-9056-9f8e13893e00} (Trojan.Vundo.H) -> Delete on reboot. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wefowuwus (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{c3314a31-d91d-4cfb-9056-9f8e13893e00} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\juhovidag (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\10990154 (Rogue.Multiple) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\borababu.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\borababu.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\system32\borababu.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\tenedefi.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\derupili.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\reforola.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sepoyije.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tijawani.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tupemawu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. ------------------------------- Thanks again for your help. BuzzBoy |
|
|
Oct 3 2009, 10:21 AM
Post
#2
|
|
![]() Trusted Helper Posts: 1,499 From: UK OS: XP |
Hello BuzzBoy22 and welcome to GeeksToGo
I'm hammerman and I'm going to help you fix your problem. Sorry for the delay in replying. Before we begin, here are some guidelines which will help us both in fixing your problem.
As it's been a while since you posted your logs, let's get some fresh ones. Please follow these steps. -- Step 1 -- Run Malwarebytes' Anti-Malware.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly. -- Step 2 -- To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link. Download OTS to your Desktop
Please attach the log in your next post. To attach a file, do the following:
-- Step 3 -- Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop. Start the Sysprot.exe program.
|
|
|
Oct 3 2009, 05:00 PM
Post
#3
|
|
|
New Member ![]() Posts: 9 OS: XP |
hammerman,
Thanks for helping me out. I ran MBAM, OTS and SysProt, but SysProt did not appear to run correctly. After about 8 minutes of scanning, the system clock hung up, and the scan never gave me a "completed" message. I waited an hour for the scan to complete, but after that time there was no disk drive activity and the rest of the computer had hung up. There was a text file in the SysProt folder, and I have included it below, but I'm not confident in its completeness. Here are the log files: Malwarebytes' Anti-Malware 1.41 Database version: 2900 Windows 5.1.2600 Service Pack 3 10/3/2009 10:17:49 AM mbam-log-2009-10-03 (10-17-49).txt Scan type: Quick Scan Objects scanned: 140681 Time elapsed: 25 minute(s), 12 second(s) Memory Processes Infected: 0 Memory Modules Infected: 3 Registry Keys Infected: 1 Registry Values Infected: 4 Registry Data Items Infected: 3 Folders Infected: 3 Files Infected: 22 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\tehunevo.dll (Trojan.Vundo) -> Delete on reboot. c:\WINDOWS\system32\wobihasa.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\fedoniko.dll (Trojan.Vundo) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{d045846b-9cd4-48bf-b327-b0f6757c4d5f} (Trojan.Vundo.H) -> Delete on reboot. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wefowuwus (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{d045846b-9cd4-48bf-b327-b0f6757c4d5f} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\sebugeban (Trojan.Vundo.H) -> Delete on reboot. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\install (Rogue.SecurityTool) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\wobihasa.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\wobihasa.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Documents and Settings\All Users\Application Data\15637184 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\17270004 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\JD\Application Data\6802223407 (Rogue.SecurityTool) -> Quarantined and deleted successfully. Files Infected: c:\WINDOWS\system32\wobihasa.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\tehunevo.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\fedoniko.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\buloboti.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\derupili.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\foweriyo.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hizudenu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lahozunu.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\WINDOWS\system32\nawodope.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\nukatojo.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pobefoli.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\setevari.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tenedefi.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tigahifa.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wowuneha.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yetogusu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yolefode.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\15637184\15637184 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\17270004\17270004 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\JD\Application Data\6802223407\6802223407.bat (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Documents and Settings\JD\Application Data\6802223407\6802223407.cfg (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Documents and Settings\JD\Application Data\6802223407\6802223407.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully. --------------------------------------------------------------------------------
OTS.Txt ( 240.79K )
Number of downloads: 7-------------------------------------------------------------------------------- SysProt AntiRootkit v1.0.1.0 by swatkat ****************************************************************************************** ****************************************************************************************** Process: Name: [System Idle Process] PID: 0 Hidden: No Window Visible: No Name: System PID: 4 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\smss.exe PID: 760 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\csrss.exe PID: 888 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\winlogon.exe PID: 912 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 964 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\lsass.exe PID: 976 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\ati2evxx.exe PID: 1152 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1180 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1244 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1360 Hidden: No Window Visible: No Name: C:\Program Files\Ahead\InCD\InCDsrv.exe PID: 1388 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1568 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1648 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE PID: 1704 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE PID: 1984 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\spoolsv.exe PID: 316 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 552 Hidden: No Window Visible: No Name: C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe PID: 584 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe PID: 620 Hidden: No Window Visible: No Name: C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe PID: 848 Hidden: No Window Visible: No Name: C:\Program Files\Bonjour\mDNSResponder.exe PID: 200 Hidden: No Window Visible: No Name: C:\Program Files\Symantec AntiVirus\DefWatch.exe PID: 1332 Hidden: No Window Visible: No Name: C:\WINDOWS\eHome\ehsched.exe PID: 1540 Hidden: No Window Visible: No Name: C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe PID: 1588 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\gearsec.exe PID: 1760 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1836 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1888 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe PID: 1960 Hidden: No Window Visible: No Name: C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe PID: 2072 Hidden: No Window Visible: No Name: C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe PID: 2200 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 2384 Hidden: No Window Visible: No Name: C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe PID: 2424 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 2532 Hidden: No Window Visible: No Name: C:\Program Files\CyberLink\Shared Files\RichVideo.exe PID: 2644 Hidden: No Window Visible: No Name: C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe PID: 2740 Hidden: No Window Visible: No Name: C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe PID: 2804 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 2860 Hidden: No Window Visible: No Name: C:\Program Files\Symantec AntiVirus\Rtvscan.exe PID: 2952 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\wdfmgr.exe PID: 3072 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\MsPMSPSv.exe PID: 3332 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\searchindexer.exe PID: 3368 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\alg.exe PID: 3752 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\ati2evxx.exe PID: 2380 Hidden: No Window Visible: No Name: C:\WINDOWS\explorer.exe PID: 2888 Hidden: No Window Visible: No Name: C:\hp\KBD\kbd.exe PID: 3632 Hidden: No Window Visible: No Name: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe PID: 1444 Hidden: No Window Visible: No Name: C:\Program Files\Multimedia Card Reader\shwicon2k.exe PID: 3444 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\hphmon05.exe PID: 1396 Hidden: No Window Visible: No Name: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe PID: 1628 Hidden: No Window Visible: No Name: C:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe PID: 2216 Hidden: No Window Visible: No Name: C:\PROGRA~1\SYMANT~1\VPTray.exe PID: 2116 Hidden: No Window Visible: No Name: C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe PID: 2332 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE PID: 1380 Hidden: No Window Visible: No Name: C:\PROGRA~1\VISION~1\PAPERP~1\FBDirect.exe PID: 2464 Hidden: No Window Visible: No Name: C:\Program Files\Microsoft IntelliType Pro\itype.exe PID: 2636 Hidden: No Window Visible: No Name: C:\Program Files\Microsoft IntelliPoint\ipoint.exe PID: 2724 Hidden: No Window Visible: No Name: C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe PID: 2716 Hidden: No Window Visible: No Name: C:\Program Files\iTunes\iTunesHelper.exe PID: 3512 Hidden: No Window Visible: No Name: C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe PID: 3248 Hidden: No Window Visible: No Name: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe PID: 864 Hidden: No Window Visible: No Name: C:\Program Files\DNA\btdna.exe PID: 2060 Hidden: No Window Visible: No Name: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe PID: 4196 Hidden: No Window Visible: No Name: C:\Program Files\Windows Desktop Search\WindowsSearch.exe PID: 4204 Hidden: No Window Visible: No Name: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe PID: 4224 Hidden: No Window Visible: No Name: C:\Program Files\Symantec AntiVirus\DoScan.exe PID: 4412 Hidden: No Window Visible: No Name: C:\Program Files\iPod\bin\iPodService.exe PID: 5212 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\ZoneLabs\vsmon.exe PID: 5368 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 6140 Hidden: No Window Visible: No Name: C:\Documents and Settings\JD\Desktop\SysProt\SysProt\SysProt.exe PID: 4360 Hidden: No Window Visible: Yes ****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \??\C:\Documents and Settings\JD\Desktop\SysProt\SysProt\SysProtDrv.sys Service Name: SysProtDrv.sys Module Base: AB29E000 Module End: AB2A9000 Hidden: No Module Name: \WINDOWS\system32\ntoskrnl.exe Service Name: --- Module Base: 804D7000 Module End: 806FF000 Hidden: No Module Name: \WINDOWS\system32\hal.dll Service Name: --- Module Base: 806FF000 Module End: 8071FD00 Hidden: No Module Name: \WINDOWS\system32\KDCOM.DLL Service Name: --- Module Base: F7987000 Module End: F7989000 Hidden: No Module Name: \WINDOWS\system32\BOOTVID.dll Service Name: --- Module Base: F7897000 Module End: F789A000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ACPI.sys Service Name: ACPI Module Base: F75A8000 Module End: F75D6000 Hidden: No Module Name: \WINDOWS\System32\DRIVERS\WMILIB.SYS Service Name: --- Module Base: F7989000 Module End: F798B000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\pci.sys Service Name: PCI Module Base: F7597000 Module End: F75A8000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\isapnp.sys Service Name: isapnp Module Base: F75F7000 Module End: F7601000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\pciide.sys Service Name: PCIIde Module Base: F7A4F000 Module End: F7A50000 Hidden: No Module Name: \WINDOWS\System32\DRIVERS\PCIIDEX.SYS Service Name: --- Module Base: F7707000 Module End: F770E000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys Service Name: MountMgr Module Base: F7607000 Module End: F7612000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys Service Name: Disk Module Base: F74D8000 Module End: F74F7000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\dmload.sys Service Name: dmload Module Base: F798B000 Module End: F798D000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\dmio.sys Service Name: dmio Module Base: F74B2000 Module End: F74D8000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys Service Name: PartMgr Module Base: F770F000 Module End: F7714000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys Service Name: VolSnap Module Base: F7617000 Module End: F7624000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\atapi.sys Service Name: atapi Module Base: F749A000 Module End: F74B2000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\disk.sys Service Name: --- Module Base: F7627000 Module End: F7630000 Hidden: No Module Name: \WINDOWS\System32\DRIVERS\CLASSPNP.SYS Service Name: --- Module Base: F7637000 Module End: F7644000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\fltmgr.sys Service Name: FltMgr Module Base: F747A000 Module End: F749A000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\sr.sys Service Name: sr Module Base: F7468000 Module End: F747A000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Lbd.sys Service Name: Lbd Module Base: F7647000 Module End: F7656000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys Service Name: PxHelp20 Module Base: F7657000 Module End: F7660000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PQV2i.sys Service Name: PQV2i Module Base: F7452000 Module End: F7468000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys Service Name: KSecDD Module Base: F743B000 Module End: F7452000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys Service Name: Ntfs Module Base: F7B52000 Module End: F7BDF000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\NDIS.sys Service Name: NDIS Module Base: F740E000 Module End: F743B000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ppsio2.sys Service Name: ppsio2 Module Base: F789B000 Module End: F789E000 Hidden: No Module Name: srescan.sys Service Name: srescan Module Base: F7883000 Module End: F7897000 Hidden: Yes Module Name: C:\WINDOWS\system32\drivers\sbp2port.sys Service Name: sbp2port Module Base: F7667000 Module End: F7672000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ohci1394.sys Service Name: ohci1394 Module Base: F7677000 Module End: F7687000 Hidden: No Module Name: \WINDOWS\System32\DRIVERS\1394BUS.SYS Service Name: --- Module Base: F7687000 Module End: F7695000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Mup.sys Service Name: Mup Module Base: BAF46000 Module End: BAF60000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\agp440.sys Service Name: agp440 Module Base: F7697000 Module End: F76A2000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\intelppm.sys Service Name: intelppm Module Base: BAF90000 Module End: BAF99000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ati2mtag.sys Service Name: ati2mtag Module Base: BA026000 Module End: BA0FB000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS Service Name: --- Module Base: BA012000 Module End: BA026000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\usbuhci.sys Service Name: usbuhci Module Base: F7757000 Module End: F775D000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS Service Name: --- Module Base: B9FEE000 Module End: BA012000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\LaCieUSBFilter.sys Service Name: LaCieUSBFilter Module Base: BAF80000 Module End: BAF89000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS Service Name: --- Module Base: F79BB000 Module End: F79BD000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\usbehci.sys Service Name: usbehci Module Base: F775F000 Module End: F7767000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\cx88vid.sys Service Name: CX23880 Module Base: B9FBE000 Module End: B9FEE000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\STREAM.SYS Service Name: --- Module Base: BAF60000 Module End: BAF6D000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ks.sys Service Name: --- Module Base: B9F9B000 Module End: B9FBE000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\cx88enc.sys Service Name: CX88ENC Module Base: B9F52000 Module End: B9F9B000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys Service Name: ltmodem5 Module Base: B9EB7000 Module End: B9F52000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS Service Name: Modem Module Base: F7767000 Module End: F776F000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\LaCieFWFilter.sys Service Name: LaCieFWFilter Module Base: F776F000 Module End: F7777000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\R8139n51.SYS Service Name: rtl8139 Module Base: BA9CA000 Module End: BA9D6000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\serial.sys Service Name: Serial Module Base: BA9BA000 Module End: BA9CA000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\serenum.sys Service Name: serenum Module Base: BAED2000 Module End: BAED6000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\fdc.sys Service Name: Fdc Module Base: F7777000 Module End: F777E000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\parport.sys Service Name: Parport Module Base: B9EA3000 Module End: B9EB7000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\imapi.sys Service Name: Imapi Module Base: BA9AA000 Module End: BA9B5000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\cdrbsdrv.SYS Service Name: cdrbsdrv Module Base: BAECE000 Module End: BAED2000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\AFS2K.SYS Service Name: AFS2K Module Base: BA99A000 Module End: BA9A4000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\pfc.sys Service Name: pfc Module Base: BAECA000 Module End: BAECD000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\cdrom.sys Service Name: Cdrom Module Base: BA98A000 Module End: BA99A000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\redbook.sys Service Name: redbook Module Base: BA97A000 Module End: BA989000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\InCDPass.sys Service Name: InCDPass Module Base: F777F000 Module End: F7787000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\incdrm.SYS Service Name: incdrm Module Base: F7787000 Module End: F778E000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\pwd_2k.SYS Service Name: pwd_2k Module Base: B9E86000 Module End: B9EA3000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys Service Name: GEARAspiWDM Module Base: F77AF000 Module End: F77B5000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ALCXWDM.SYS Service Name: ALCXWDM Module Base: B9C59000 Module End: B9E86000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\portcls.sys Service Name: --- Module Base: B9C35000 Module End: B9C59000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\drmk.sys Service Name: --- Module Base: BA95A000 Module End: BA969000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\serscan.sys Service Name: StillCam Module Base: F79BD000 Module End: F79BF000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\audstub.sys Service Name: audstub Module Base: F7A9E000 Module End: F7A9F000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys Service Name: Rasl2tp Module Base: F7577000 Module End: F7584000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ndistapi.sys Service Name: NdisTapi Module Base: BAEB6000 Module End: BAEB9000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ndiswan.sys Service Name: NdisWan Module Base: B9C1E000 Module End: B9C35000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\raspppoe.sys Service Name: RasPppoe Module Base: F7567000 Module End: F7572000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\raspptp.sys Service Name: PptpMiniport Module Base: F7557000 Module End: F7563000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\TDI.SYS Service Name: --- Module Base: BA37B000 Module End: BA380000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\psched.sys Service Name: PSched Module Base: B9C0D000 Module End: B9C1E000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\msgpc.sys Service Name: Gpc Module Base: F7547000 Module End: F7550000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ptilink.sys Service Name: Ptilink Module Base: BA373000 Module End: BA378000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\raspti.sys Service Name: Raspti Module Base: BA36B000 Module End: BA370000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\rdpdr.sys Service Name: rdpdr Module Base: B9BB5000 Module End: B9BE5000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\termdd.sys Service Name: TermDD Module Base: F7537000 Module End: F7541000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\kbdclass.sys Service Name: Kbdclass Module Base: BA363000 Module End: BA369000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\mouclass.sys Service Name: Mouclass Module Base: BA35B000 Module End: BA361000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\swenum.sys Service Name: swenum Module Base: F79BF000 Module End: F79C1000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\update.sys Service Name: Update Module Base: B9AB7000 Module End: B9B15000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\mssmbios.sys Service Name: mssmbios Module Base: BAE9A000 Module End: BAE9E000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\dvd_2K.SYS Service Name: dvd_2K Module Base: BA353000 Module End: BA359000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS Service Name: NDProxy Module Base: BAFF0000 Module End: BAFFA000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\usbhub.sys Service Name: usbhub Module Base: BAFB0000 Module End: BAFBF000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\CX88TUNE.sys Service Name: CXTUNE Module Base: BA34B000 Module End: BA353000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\CX88XBARDUAL.sys Service Name: CX88XBAR Module Base: F79C5000 Module End: F79C7000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\nic1394.sys Service Name: NIC1394 Module Base: F76C7000 Module End: F76D7000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\flpydisk.sys Service Name: Flpydisk Module Base: BA343000 Module End: BA348000 Hidden: No Module Name: \??\C:\Program Files\Symantec AntiVirus\savrt.sys Service Name: SAVRT Module Base: AEE69000 Module End: AEEC1000 Hidden: No Module Name: \??\C:\Program Files\Symantec\SYMEVENT.SYS Service Name: SymEvent Module Base: AEE47000 Module End: AEE69000 Hidden: No Module Name: \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys Service Name: SAVRTPEL Module Base: AEE33000 Module End: AEE47000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\IrBus.sys Service Name: IrBus Module Base: BA94A000 Module End: BA956000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\usbccgp.sys Service Name: usbccgp Module Base: BA33B000 Module End: BA343000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\hidusb.sys Service Name: HidUsb Module Base: BAEDE000 Module End: BAEE1000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\HIDCLASS.SYS Service Name: --- Module Base: BA93A000 Module End: BA943000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\HIDPARSE.SYS Service Name: --- Module Base: BA333000 Module End: BA33A000 Hidden: No Module Name: \??\C:\WINDOWS\System32\Drivers\sunkfilt.sys Service Name: SunkFilt Module Base: F77DF000 Module End: F77E6000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS Service Name: USBSTOR Module Base: F778F000 Module End: F7796000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\hidir.sys Service Name: HidIr Module Base: F779F000 Module End: F77A4000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\kbdhid.sys Service Name: kbdhid Module Base: BAEDA000 Module End: BAEDE000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\mouhid.sys Service Name: mouhid Module Base: BAED6000 Module End: BAED9000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\NuidFltr.sys Service Name: NuidFltr Module Base: F77A7000 Module End: F77AE000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\WDFLDR.SYS Service Name: --- Module Base: F76D7000 Module End: F76E4000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\Wdf01000.sys Service Name: Wdf01000 Module Base: AED68000 Module End: AEDE3000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\point32.sys Service Name: Point32 Module Base: F77B7000 Module End: F77BD000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Cdr4_xp.SYS Service Name: Cdr4_xp Module Base: F7A59000 Module End: F7A5A000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Cdralw2k.SYS Service Name: Cdralw2k Module Base: F7A58000 Module End: F7A59000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS Service Name: Fs_Rec Module Base: F79D9000 Module End: F79DB000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Null.SYS Service Name: Null Module Base: BAB19000 Module End: BAB1A000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS Service Name: Beep Module Base: F79DB000 Module End: F79DD000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\vga.sys Service Name: VgaSave Module Base: F77CF000 Module End: F77D5000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS Service Name: mnmdd Module Base: F79DD000 Module End: F79DF000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys Service Name: RDPCDD Module Base: F79DF000 Module End: F79E1000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\cdudf_xp.SYS Service Name: cdudf_xp Module Base: AEBB2000 Module End: AEBF2000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\InCDrec.SYS Service Name: InCDrec Module Base: B9BE5000 Module End: B9BE8000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\InCDfs.SYS Service Name: InCDfs Module Base: AEB5F000 Module End: AEB78000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS Service Name: Msfs Module Base: F77D7000 Module End: F77DC000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS Service Name: Npfs Module Base: F77E7000 Module End: F77EF000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\UdfReadr_xp.SYS Service Name: UdfReadr_xp Module Base: AEB2A000 Module End: AEB5F000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\rasacd.sys Service Name: RasAcd Module Base: B8FB5000 Module End: B8FB8000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ipsec.sys Service Name: IPSec Module Base: AEADD000 Module End: AEAF0000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\tcpip.sys Service Name: Tcpip Module Base: AEA84000 Module End: AEADD000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ipnat.sys Service Name: IpNat Module Base: AEA5E000 Module End: AEA84000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\SYMTDI.SYS Service Name: SYMTDI Module Base: AEA23000 Module End: AEA5E000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\arp1394.sys Service Name: Arp1394 Module Base: F76F7000 Module End: F7706000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\netbt.sys Service Name: NetBT Module Base: AE9FB000 Module End: AEA23000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\wanarp.sys Service Name: Wanarp Module Base: F7587000 Module End: F7590000 Hidden: No Module Name: C:\WINDOWS\System32\vsdatant.sys Service Name: vsdatant Module Base: AE990000 Module End: AE9FB000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\ws2ifsl.sys Service Name: WS2IFSL Module Base: AEED9000 Module End: AEEDC000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\afd.sys Service Name: AFD Module Base: AE96E000 Module End: AE990000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\netbios.sys Service Name: NetBIOS Module Base: B9BA5000 Module End: B9BAE000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\rdbss.sys Service Name: Rdbss Module Base: AE943000 Module End: AE96E000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\PQIMount.SYS Service Name: PQIMount Module Base: B9B85000 Module End: B9B8E000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys Service Name: MRxSmb Module Base: AE883000 Module End: AE8F3000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS Service Name: Fips Module Base: B9B75000 Module End: B9B80000 Hidden: No Module Name: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys Service Name: eeCtrl Module Base: AE825000 Module End: AE883000 Hidden: No Module Name: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys Service Name: EraserUtilRebootDrv Module Base: AE808000 Module End: AE825000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS Service Name: Fastfat Module Base: AE76C000 Module End: AE790000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys Service Name: --- Module Base: AE7BC000 Module End: AE7BF000 Hidden: No Module Name: C:\WINDOWS\System32\watchdog.sys Service Name: --- Module Base: F77F7000 Module End: F77FC000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys Service Name: --- Module Base: BA0FC000 Module End: BA0FD000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\elagopro.sys Service Name: elagopro Module Base: F780F000 Module End: F7816000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ndisuio.sys Service Name: Ndisuio Module Base: AC568000 Module End: AC56C000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\mrxdav.sys Service Name: MRxDAV Module Base: AC19F000 Module End: AC1CC000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\ParVdm.SYS Service Name: ParVdm Module Base: F79E9000 Module End: F79EB000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\elaunidr.sys Service Name: elaunidr Module Base: F798D000 Module End: F798F000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\MASPINT.SYS Service Name: MASPINT Module Base: F79A9000 Module End: F79AB000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\srv.sys Service Name: Srv Module Base: ABD29000 Module End: ABD7B000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS Service Name: Cdfs Module Base: ABA57000 Module End: ABA67000 Hidden: No Module Name: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20091002.003\navex15.sys Service Name: NAVEX15 Module Base: AB60D000 Module End: AB74F000 Hidden: No Module Name: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20091002.003\naveng.sys Service Name: NAVENG Module Base: AB5F9000 Module End: AB60D000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys Service Name: wdmaud Module Base: AB42C000 Module End: AB441000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys Service Name: sysaudio Module Base: ABB47000 Module End: ABB56000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\DMusic.sys Service Name: DMusic Module Base: AB4F9000 Module End: AB506000 Hidden: Yes Module Name: C:\WINDOWS\system32\drivers\kmixer.sys Service Name: kmixer Module Base: AB3DE000 Module End: AB409000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\drmkaud.sys Service Name: drmkaud Module Base: F7AA6000 Module End: F7AA7000 Hidden: Yes Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys Service Name: HTTP Module Base: AB09D000 Module End: AB0DE000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\SYMREDRV.SYS Service Name: SYMREDRV Module Base: AAD7D000 Module End: AAD87000 Hidden: No ****************************************************************************************** ****************************************************************************************** SSDT: Function Name: ZwConnectPort Address: AE9B1FC0 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateFile Address: AE9AEC80 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateKey Address: AE9C9170 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreatePort Address: AE9B2580 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateProcess Address: AE9C6900 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateProcessEx Address: AE9C6B10 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateSection Address: AE9CAB10 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateWaitablePort Address: AE9B2670 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwDeleteFile Address: AE9AF210 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwDeleteKey Address: AE9C99F0 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwDeleteValueKey Address: AEE5ACB0 Driver Base: AEE47000 Driver End: AEE69000 Driver Name: \??\C:\Program Files\Symantec\SYMEVENT.SYS Function Name: ZwDuplicateObject Address: AE9C6280 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwLoadKey Address: AE9C9F10 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwLoadKey2 Address: AE9C9F90 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwOpenFile Address: AE9AF070 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwOpenProcess Address: AE9C8180 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwOpenThread Address: AE9C7F40 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwRenameKey Address: AE9CA6F0 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwReplaceKey Address: AE9CA150 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwRequestWaitReplyPort Address: AE9B1BE0 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwRestoreKey Address: AE9CA540 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwSecureConnectPort Address: AE9B2190 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwSetInformationFile Address: AE9AF440 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwSetValueKey Address: AEE5AF10 Driver Base: AEE47000 Driver End: AEE69000 Driver Name: \??\C:\Program Files\Symantec\SYMEVENT.SYS Function Name: ZwSystemDebugControl Address: AE9C7200 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwTerminateProcess Address: AE9C7080 Driver Base: AE990000 Driver End: AE9FB000 Driver Name: \SystemRoot\System32\vsdatant.sys ****************************************************************************************** ****************************************************************************************** Kernel Hooks: Hooked Function: PsGetProcessWin32WindowStation At Address: 804F41EC Jump To: FD806070 Module Name: _unknown_ Hooked Function: PsGetProcessJob At Address: 804F41EC Jump To: FD806070 Module Name: _unknown_ ****************************************************************************************** ****************************************************************************************** IRP Hooks: Hooked Module: C:\WINDOWS\System32\DRIVERS\tcpip.sys Hooked IRP: IRP_MJ_CREATE Jump To: AE9D6880 Hooking Module: C:\WINDOWS\System32\vsdatant.sys Hooked Module: C:\WINDOWS\System32\DRIVERS\tcpip.sys Hooked IRP: IRP_MJ_CLOSE Jump To: AE9D6880 Hooking Module: C:\WINDOWS\System32\vsdatant.sys Hooked Module: C:\WINDOWS\System32\DRIVERS\tcpip.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: AE9D6880 Hooking Module: C:\WINDOWS\System32\vsdatant.sys Hooked Module: C:\WINDOWS\System32\DRIVERS\tcpip.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: AE9D6880 Hooking Module: C:\WINDOWS\System32\vsdatant.sys Hooked Module: C:\WINDOWS\System32\DRIVERS\tcpip.sys Hooked IRP: IRP_MJ_CLEANUP Jump To: AE9D6880 Hooking Module: C:\WINDOWS\System32\vsdatant.sys ****************************************************************************************** ****************************************************************************************** Ports: Local Address: DESKTOP.HAWAII.RR.COM:139 Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: DESKTOP:27015 Remote Address: LOCALHOST:1041 Type: TCP Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe State: ESTABLISHED Local Address: DESKTOP:27015 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe State: LISTENING Local Address: DESKTOP:5354 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: LISTENING Local Address: DESKTOP:1041 Remote Address: LOCALHOST:27015 Type: TCP Process: C:\Program Files\iTunes\iTunesHelper.exe State: ESTABLISHED Local Address: DESKTOP:1039 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE State: LISTENING Local Address: DESKTOP:1027 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\alg.exe State: LISTENING Local Address: DESKTOP:14375 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\DNA\btdna.exe State: LISTENING Local Address: DESKTOP:2869 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\svchost.exe State: LISTENING Local Address: DESKTOP:445 Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: DESKTOP:135 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\svchost.exe State: LISTENING Local Address: DESKTOP.HAWAII.RR.COM:5353 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: DESKTOP.HAWAII.RR.COM:1900 Remote Address: NA Type: UDP Process: C:\Program Files\DNA\btdna.exe State: NA Local Address: DESKTOP.HAWAII.RR.COM:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: DESKTOP.HAWAII.RR.COM:138 Remote Address: NA Type: UDP Process: System State: NA Local Address: DESKTOP.HAWAII.RR.COM:137 Remote Address: NA Type: UDP Process: System State: NA Local Address: DESKTOP.HAWAII.RR.COM:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: DESKTOP:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: DESKTOP:1053 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: DESKTOP:1052 Remote Address: NA Type: UDP Process: C:\WINDOWS\explorer.exe State: NA Local Address: DESKTOP:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: DESKTOP:51082 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: DESKTOP:14375 Remote Address: NA Type: UDP Process: C:\Program Files\DNA\btdna.exe State: NA Local Address: DESKTOP:4500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: DESKTOP:1434 Remote Address: NA Type: UDP Process: C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe State: NA Local Address: DESKTOP:1025 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: DESKTOP:500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: DESKTOP:445 Remote Address: NA Type: UDP Process: System State: NA ****************************************************************************************** ****************************************************************************************** |
|
|
Oct 3 2009, 08:48 PM
Post
#4
|
|
![]() Trusted Helper Posts: 1,499 From: UK OS: XP |
Hello,
Please follow these steps. -- Step 1 -- I notice you are running one or more Peer-to-Peer (P2P) programs. The files shared by P2P programs are often infected with viruses and malware, even though they may appear to be legitimate. For this reason, I would recommend you uninstall them. If you decide to keep them, I ask that you do not use them while we are fixing your problem. An article indicating the Dangers of P2P can be found here -- Step 2 -- While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent malware removal tools from fixing certain things. Please disable TeaTimer for now until you are clean.
-- Step 3 -- Start OTS. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button. QUOTE [Kill All Processes] [Unregister Dlls] [Registry - Safe List] < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ YN -> {0A87E45F-537A-40B4-B812-E2544C21A09F} [HKLM] -> Reg Error: Value error. [SpywareBlock Class] < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar YN -> "" [HKLM] -> Reg Error: Key error. [Reg Error: Value error.] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run YY -> "wefowuwus" -> C:\WINDOWS\System32\wobihasa.DLL [Rundll32.exe "c:\windows\system32\wobihasa.dll",a] < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\Software\Microsoft\Internet Explorer\Extensions\ YN -> CmdMapping\\"{A75C6120-9B36-11d4-A3F0-009027427750}" [HKLM] -> [Reg Error: Key error.] < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls YY -> c:\windows\system32\gisisema.dll -> C:\WINDOWS\System32\gisisema.dll YY -> c:\windows\system32\yudegoku.dll -> C:\WINDOWS\System32\yudegoku.dll YY -> tehunevo.dll -> C:\WINDOWS\System32\tehunevo.dll YY -> c:\windows\system32\wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs < SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad YN -> "{324fc3bb-4f3e-4c51-84b7-1689cfe42ed0}" [HKLM] -> C:\WINDOWS\System32\yudegoku.dll [ganokiboy] YN -> "{de4e9e38-28ca-4548-8ac1-ad002276dd90}" [HKLM] -> C:\WINDOWS\System32\gisisema.dll [kawuhesud] YY -> "{d045846b-9cd4-48bf-b327-b0f6757c4d5f}" [HKLM] -> C:\WINDOWS\System32\wobihasa.dll [sebugeban] < SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler YN -> "{324fc3bb-4f3e-4c51-84b7-1689cfe42ed0}" [HKLM] -> C:\WINDOWS\System32\yudegoku.dll [tokatiluy] YY -> "{d045846b-9cd4-48bf-b327-b0f6757c4d5f}" [HKLM] -> C:\WINDOWS\System32\wobihasa.dll [mujuzedij] YN -> "{de4e9e38-28ca-4548-8ac1-ad002276dd90}" [HKLM] -> C:\WINDOWS\System32\gisisema.dll [tokatiluy] < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List YN -> "C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe" -> C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe [C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe:*:Enabled:14267034] YN -> "C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe" -> C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe [C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe:*:Enabled:16496404] YN -> "C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] YN -> "E:\setup\HPZNUI01.EXE" -> E:\setup\HPZNUI01.EXE [E:\setup\HPZNUI01.EXE:*:Enabled:hpznui01.exe] < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} -> YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\AutoRun\command -> YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\AutoRun\command\\"" -> J:\Autorun.exe [J:\Autorun.exe /run] YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} -> YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell00\Command -> YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell00\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /run] YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} -> YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell01\Command -> YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell01\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /action] YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} -> YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell02\Command -> YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell02\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /uninstall] [Files/Folders - Modified Within 30 Days] NY -> mehudebe -> C:\WINDOWS\System32\mehudebe NY -> wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll NY -> vokafifu.dll -> C:\WINDOWS\System32\vokafifu.dll NY -> famatoge.dll -> C:\WINDOWS\System32\famatoge.dll NY -> wayolelu.dll -> C:\WINDOWS\System32\wayolelu.dll [Files - No Company Name] NY -> wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll NY -> tehunevo.dll -> C:\WINDOWS\System32\tehunevo.dll NY -> fedoniko.dll -> C:\WINDOWS\System32\fedoniko.dll NY -> vokafifu.dll -> C:\WINDOWS\System32\vokafifu.dll NY -> famatoge.dll -> C:\WINDOWS\System32\famatoge.dll NY -> wayolelu.dll -> C:\WINDOWS\System32\wayolelu.dll [Custom Items] :files C:\Documents and Settings\All Users\Application Data\14267034 C:\Documents and Settings\All Users\Application Data\16496404 :end [Empty Temp Folders] [Start Explorer] [Reboot] The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here I will review the information when it comes back in. -- Step 4 -- Run Malwarebytes' Anti-Malware.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly. -- Step 5 -- Run OTL and select Minimal Output. Use the Quick Scan button to start a scan. Please post the OTL report in your reply. -- Step 6 -- Download the GMER Rootkit Scanner. Unzip it to your Desktop. Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan. Double-click gmer.exe. The program will begin to run. **Caution** These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised! If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Post the contents of GMER.txt in your next reply. Do you recognise this file? C:\Documents and Settings\JD\Start Menu\Programs\Startup\TempClean.bat |
|
|
Oct 4 2009, 08:18 AM
Post
#5
|
|
|
New Member ![]() Posts: 9 OS: XP |
hammerman,
For some reason Spybot Search and Destroy would hang ever time I clicked the "Resident" button, so I manually terminated TeaTimer after each reboot. The TempClean.bat file is a batch file I created a long time ago to delete temp files. Here are the log files: CODE OTS logfile created on: 10/3/2009 10:34:25 AM - Run 1 OTS by OldTimer - Version 3.0.20.1 Folder = C:\Documents and Settings\JD\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.50 Gb Total Physical Memory | 0.49 Gb Available Physical Memory | 32.45% Memory free 2.11 Gb Paging File | 1.28 Gb Available in Paging File | 60.66% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 180.00 Gb Total Space | 33.56 Gb Free Space | 18.65% Space Free | Partition Type: NTFS Drive D: | 6.29 Gb Total Space | 1.12 Gb Free Space | 17.85% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: DESKTOP Current User Name: JD Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days [Processes - Safe List] aluschedulersvc.exe -> C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -> [2006/02/23 11:41:02 | 00,100,032 | ---- | M] (Symantec Corporation) applemobiledeviceservice.exe -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/05/29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.) ati2evxx.exe -> C:\WINDOWS\System32\Ati2evxx.exe -> [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.) ati2evxx.exe -> C:\WINDOWS\System32\Ati2evxx.exe -> [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.) atiptaxx.exe -> C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe -> [2004/11/03 21:10:00 | 00,344,064 | ---- | M] (ATI Technologies, Inc.) btdna.exe -> C:\Program Files\DNA\btdna.exe -> [2009/01/13 21:10:40 | 00,342,848 | ---- | M] (BitTorrent, Inc.) ccapp.exe -> C:\Program Files\Common Files\Symantec Shared\ccApp.exe -> [2006/03/07 13:02:14 | 00,053,408 | ---- | M] (Symantec Corporation) ccevtmgr.exe -> C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -> [2006/03/07 13:02:34 | 00,192,160 | ---- | M] (Symantec Corporation) ccsetmgr.exe -> C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -> [2006/03/07 13:03:02 | 00,169,632 | ---- | M] (Symantec Corporation) defwatch.exe -> C:\Program Files\Symantec AntiVirus\DefWatch.exe -> [2006/03/17 06:34:12 | 00,030,448 | ---- | M] (Symantec Corporation) doscan.exe -> C:\Program Files\Symantec AntiVirus\DoScan.exe -> [2006/03/17 06:34:12 | 00,024,816 | ---- | M] (Symantec Corporation) ehsched.exe -> C:\WINDOWS\ehome\ehSched.exe -> [2008/04/13 14:12:18 | 00,084,992 | ---- | M] (Microsoft Corporation) explorer.exe -> C:\WINDOWS\Explorer.EXE -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) fbdirect.exe -> C:\Program Files\Visioneer\PaperPort\FBDirect.exe -> [2000/09/22 10:13:40 | 00,227,328 | ---- | M] (Visioneer Inc.) freeagentservice.exe -> C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -> [2009/05/01 14:35:54 | 00,181,544 | ---- | M] (Seagate Technology LLC) gearsec.exe -> C:\WINDOWS\System32\GEARSec.exe -> [2004/07/29 02:53:58 | 00,053,248 | ---- | M] (GEAR Software) googlecrashhandler.exe -> C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe -> [2009/06/30 09:11:00 | 00,133,104 | ---- | M] (Google Inc.) hpcmpmgr.exe -> C:\Program Files\HP\hpcoretech\hpcmpmgr.exe -> [2005/01/12 09:54:58 | 00,241,664 | ---- | M] (Hewlett-Packard Company) hphmon05.exe -> C:\WINDOWS\System32\hphmon05.exe -> [2003/05/23 00:55:38 | 00,483,328 | ---- | M] (Hewlett-Packard) hpqcmon.exe -> C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe -> [2002/10/07 05:23:20 | 00,090,112 | ---- | M] () hpqtra08.exe -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe -> [2007/03/11 21:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.) incdsrv.exe -> C:\Program Files\Ahead\InCD\InCDsrv.exe -> [2005/01/03 06:40:42 | 00,854,528 | ---- | M] (Nero AG) intuitupdateservice.exe -> C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -> [2008/10/10 05:45:26 | 00,013,088 | ---- | M] (Intuit Inc.) ipodservice.exe -> C:\Program Files\iPod\bin\iPodService.exe -> [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) ipoint.exe -> C:\Program Files\Microsoft IntelliPoint\ipoint.exe -> [2006/07/07 13:15:07 | 00,600,896 | ---- | M] (Microsoft Corporation) ituneshelper.exe -> C:\Program Files\iTunes\iTunesHelper.exe -> [2009/09/08 21:09:42 | 00,305,440 | ---- | M] (Apple Inc.) itype.exe -> C:\Program Files\Microsoft IntelliType Pro\itype.exe -> [2006/07/07 13:14:38 | 00,576,320 | ---- | M] (Microsoft Corporation) kbd.exe -> C:\HP\KBD\KBD.EXE -> [2005/02/02 16:44:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) mdnsresponder.exe -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) mspmspsv.exe -> C:\WINDOWS\System32\MsPMSPSv.exe -> [2001/05/01 17:06:22 | 00,053,248 | ---- | M] (Microsoft Corporation) ots.exe -> C:\Documents and Settings\JD\Desktop\OTS.exe -> [2009/10/03 10:31:02 | 00,519,680 | ---- | M] (OldTimer Tools) photoshopelementsfileagent.exe -> C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -> [2008/09/16 12:03:18 | 00,169,312 | ---- | M] (Adobe Systems Incorporated) pqv2isvc.exe -> C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe -> [2004/11/22 17:04:14 | 01,273,856 | ---- | M] (Symantec Corporation) richvideo.exe -> C:\Program Files\CyberLink\Shared Files\RichVideo.exe -> [2005/08/07 18:54:00 | 00,167,936 | ---- | M] () rtvscan.exe -> C:\Program Files\Symantec AntiVirus\Rtvscan.exe -> [2006/03/17 06:34:20 | 01,799,408 | ---- | M] (Symantec Corporation) shwicon2k.exe -> C:\Program Files\Multimedia Card Reader\shwicon2k.exe -> [2003/08/14 14:11:32 | 00,139,264 | ---- | M] (Alcor Micro, Corp.) sqlbrowser.exe -> C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -> [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) sqlservr.exe -> C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -> [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation) sqlwriter.exe -> C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -> [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) startupcoppro.exe -> C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe -> [2007/09/26 23:23:28 | 02,211,840 | ---- | M] (Ziff-Davis Media, Inc.) stxmenumgr.exe -> C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe -> [2009/05/01 14:35:10 | 00,185,640 | ---- | M] (Seagate LLC) teatimer.exe -> C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe -> [2009/03/05 16:07:20 | 02,260,480 | ---- | M] (Safer-Networking Ltd.) tintsetp.exe -> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE -> [2002/08/28 15:39:50 | 00,455,168 | ---- | M] (Microsoft Corporation) vptray.exe -> C:\Program Files\Symantec AntiVirus\VPTray.exe -> [2006/03/17 06:34:30 | 00,124,656 | ---- | M] (Symantec Corporation) vsmon.exe -> C:\WINDOWS\System32\ZoneLabs\vsmon.exe -> [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) wdfmgr.exe -> C:\WINDOWS\System32\wdfmgr.exe -> [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) windowssearch.exe -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe -> [2008/05/26 22:19:14 | 00,123,904 | ---- | M] (Microsoft Corporation) wscntfy.exe -> C:\WINDOWS\System32\wscntfy.exe -> [2008/04/13 14:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) zlclient.exe -> C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe -> [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) [Win32 Services - Safe List] (AdobeActiveFileMonitor7.0) Adobe Active File Monitor V7 [Win32_Own | Auto | Running] -> C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -> [2008/09/16 12:03:18 | 00,169,312 | ---- | M] (Adobe Systems Incorporated) (Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/05/29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.) (aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) (Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\Ati2evxx.exe -> [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.) (ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> C:\WINDOWS\System32\ati2sgag.exe -> [2004/11/03 21:10:00 | 00,516,096 | ---- | M] () (Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Win32_Own | Auto | Running] -> C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -> [2006/02/23 11:41:02 | 00,100,032 | ---- | M] (Symantec Corporation) (Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) (ccEvtMgr) Symantec Event Manager [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -> [2006/03/07 13:02:34 | 00,192,160 | ---- | M] (Symantec Corporation) (ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -> [2006/03/07 13:03:02 | 00,169,632 | ---- | M] (Symantec Corporation) (clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) (DefWatch) Symantec AntiVirus Definition Watcher [Win32_Own | Auto | Running] -> C:\Program Files\Symantec AntiVirus\DefWatch.exe -> [2006/03/17 06:34:12 | 00,030,448 | ---- | M] (Symantec Corporation) (ehSched) Media Center Scheduler Service [Win32_Own | Auto | Running] -> C:\WINDOWS\ehome\ehSched.exe -> [2008/04/13 14:12:18 | 00,084,992 | ---- | M] (Microsoft Corporation) (FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2008/10/16 21:11:00 | 00,651,720 | ---- | M] (Macrovision Europe Ltd.) (FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) (FreeAgentGoNext Service) Seagate Service [Win32_Own | Auto | Running] -> C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -> [2009/05/01 14:35:54 | 00,181,544 | ---- | M] (Seagate Technology LLC) (GEARSecurity) GEARSecurity [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\GEARSec.exe -> [2004/07/29 02:53:58 | 00,053,248 | ---- | M] (GEAR Software) (getPlusHelper) getPlus(R) Helper [Win32_Own | On_Demand | Stopped] -> C:\Program Files\NOS\bin\getPlus_Helper.dll -> [2009/08/07 12:44:18 | 00,045,816 | ---- | M] (NOS Microsystems Ltd.) (gupdate1c9827bbeb07656) Google Update Service (gupdate1c9827bbeb07656) [Win32_Own | Auto | Stopped] -> C:\Program Files\Google\Update\GoogleUpdate.exe -> [2009/01/29 15:40:22 | 00,133,104 | ---- | M] (Google Inc.) (gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2007/01/03 15:40:21 | 00,136,120 | ---- | M] (Google) (helpsvc) Help and Support [Win32_Shared | Auto | Running] -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/13 14:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) (hpqcxs08) hpqcxs08 [Win32_Shared | On_Demand | Running] -> C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -> [2007/05/16 22:13:44 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) (hpqddsvc) HP CUE DeviceDiscovery Service [Win32_Shared | Auto | Running] -> C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -> [2007/05/16 22:13:44 | 00,131,072 | ---- | M] (Hewlett-Packard Co.) (HPSLPSVC) HP Network Devices Support [Win32_Shared | Auto | Running] -> C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL -> [2007/05/16 22:13:08 | 00,602,112 | ---- | M] (Hewlett-Packard Co.) (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -> [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) (idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) (InCDsrv) InCD Helper [Win32_Own | Auto | Running] -> C:\Program Files\Ahead\InCD\InCDsrv.exe -> [2005/01/03 06:40:42 | 00,854,528 | ---- | M] (Nero AG) (IntuitUpdateService) Intuit Update Service [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -> [2008/10/10 05:45:26 | 00,013,088 | ---- | M] (Intuit Inc.) (iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> C:\Program Files\iPod\bin\iPodService.exe -> [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) (Lavasoft Ad-Aware Service) Lavasoft Ad-Aware Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -> [2009/09/27 10:42:25 | 01,028,432 | ---- | M] (Lavasoft) (LiveUpdate) LiveUpdate [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -> [2006/02/23 11:41:02 | 02,045,632 | ---- | M] (Symantec Corporation) (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) [Win32_Own | Auto | Running] -> C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -> [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation) (MSSQLServerADHelper) SQL Server Active Directory Helper [Win32_Own | Disabled | Stopped] -> C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -> [2008/11/24 22:31:08 | 00,045,408 | ---- | M] (Microsoft Corporation) (Net Driver HPZ12) Net Driver HPZ12 [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\HPZinw12.dll -> [2006/10/31 13:56:24 | 00,043,520 | ---- | M] (Hewlett-Packard) (NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) (Norton Ghost) Norton Ghost [Win32_Own | Auto | Running] -> C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe -> [2004/11/22 17:04:14 | 01,273,856 | ---- | M] (Symantec Corporation) (odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) (ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) (Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\HPZipm12.dll -> [2006/10/31 13:56:28 | 00,052,736 | ---- | M] (Hewlett-Packard) (RichVideo) Cyberlink RichVideo Service(CRVS) [Win32_Own | Auto | Running] -> C:\Program Files\CyberLink\Shared Files\RichVideo.exe -> [2005/08/07 18:54:00 | 00,167,936 | ---- | M] () (SavRoam) SavRoam [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Symantec AntiVirus\SavRoam.exe -> [2006/03/17 06:34:24 | 00,115,952 | ---- | M] (symantec) (SNDSrvc) Symantec Network Drivers Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -> [2006/01/24 20:06:58 | 00,214,720 | ---- | M] (Symantec Corporation) (SPBBCSvc) Symantec SPBBCSvc [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -> [2006/02/06 12:50:24 | 01,160,848 | ---- | M] (Symantec Corporation) (SQLBrowser) SQL Server Browser [Win32_Own | Auto | Running] -> C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -> [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) (SQLWriter) SQL Server VSS Writer [Win32_Own | Auto | Running] -> C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -> [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) (Symantec AntiVirus) Symantec AntiVirus [Win32_Own | Auto | Running] -> C:\Program Files\Symantec AntiVirus\Rtvscan.exe -> [2006/03/17 06:34:20 | 01,799,408 | ---- | M] (Symantec Corporation) (UMWdf) Windows User Mode Driver Framework [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\wdfmgr.exe -> [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) (vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\ZoneLabs\vsmon.exe -> [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) (WMDM PMSP Service) WMDM PMSP Service [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\MsPMSPSv.exe -> [2001/05/01 17:06:22 | 00,053,248 | ---- | M] (Microsoft Corporation) [Driver Services - Safe List] (61883) 61883 Unit Device [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\61883.sys -> [2008/04/13 08:46:20 | 00,048,128 | ---- | M] (Microsoft Corporation) (AFS2K) AFS2K [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\AFS2K.SYS -> [2004/08/04 15:49:09 | 00,043,672 | ---- | M] (Oak Technology Inc.) (ALCXSENS) Service for WDM 3D Audio Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\ALCXSENS.SYS -> [2004/02/17 00:49:14 | 00,391,424 | ---- | M] (Sensaura Ltd) (ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\ALCXWDM.SYS -> [2004/10/01 05:24:02 | 02,279,424 | ---- | M] (Realtek Semiconductor Corp.) (ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -> [2004/11/03 21:40:04 | 00,821,248 | ---- | M] (ATI Technologies Inc.) (Avc) AVC Device [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\avc.sys -> [2008/04/13 08:46:20 | 00,038,912 | ---- | M] (Microsoft Corporation) (Cdr4_xp) Cdr4_xp [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\cdr4_xp.sys -> [2006/10/04 16:42:42 | 00,002,432 | ---- | M] (Sonic Solutions) (Cdralw2k) Cdralw2k [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\cdralw2k.sys -> [2006/10/04 16:42:42 | 00,002,560 | ---- | M] (Sonic Solutions) (cdrbsdrv) cdrbsdrv [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\CDRBSDRV.SYS -> [2004/03/08 12:55:50 | 00,013,567 | ---- | M] (B.H.A Corporation) (cdudf_xp) cdudf_xp [File_System | System | Running] -> C:\WINDOWS\System32\drivers\Cdudf_xp.sys -> [2006/11/12 15:44:37 | 00,259,456 | ---- | M] (Roxio) (CX23880) Conexant 23880 Video Capture [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\cx88vid.sys -> [2003/12/10 18:40:06 | 00,193,408 | ---- | M] (Conexant Systems, Inc.) (CX88ENC) Conexant 2388x MPEG Encoder [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\cx88enc.sys -> [2003/12/10 18:40:02 | 00,295,552 | ---- | M] (Conexant Systems, Inc.) (CX88XBAR) Conexant 2388x Crossbar Dual Input [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\CX88XBARDUAL.sys -> [2003/12/10 18:40:08 | 00,007,040 | ---- | M] (Conexant Systems, Inc.) (CXTUNE) Conexant 2388x Tuner [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\CX88TUNE.sys -> [2003/12/10 18:40:04 | 00,030,080 | ---- | M] (Conexant Systems, Inc.) (dvd_2K) dvd_2K [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\Dvd_2k.sys -> [2003/07/18 17:25:16 | 00,021,993 | ---- | M] (Roxio) (eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -> [2009/08/26 22:00:00 | 00,371,248 | ---- | M] (Symantec Corporation) (elagopro) GoProto Protocol Driver for LELA [Kernel | Auto | Running] -> C:\WINDOWS\System32\DRIVERS\elagopro.sys -> [2007/03/22 12:57:14 | 00,028,672 | --S- | M] (Gteko Ltd.) (elaunidr) UniDriver for LELA [Kernel | Auto | Running] -> C:\WINDOWS\System32\DRIVERS\elaunidr.sys -> [2007/03/22 12:57:14 | 00,005,376 | --S- | M] (Gteko Ltd.) (EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> [2009/08/26 22:00:00 | 00,102,448 | ---- | M] (Symantec Corporation) (GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -> [2009/05/18 14:17:00 | 00,026,600 | ---- | M] (GEAR Software Inc.) (ialm) ialm [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\ialmnt5.sys -> [2003/10/08 16:11:20 | 00,093,979 | ---- | M] (Intel Corporation) (InCDfs) InCD File System [File_System | Disabled | Running] -> C:\WINDOWS\System32\drivers\InCDfs.sys -> [2005/01/03 06:33:44 | 00,099,456 | ---- | M] (Nero AG) (InCDPass) InCDPass [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\InCDPass.sys -> [2005/01/03 06:33:24 | 00,028,928 | ---- | M] (Nero AG) (incdrm) InCD Reader [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\InCDrm.sys -> [2005/01/03 06:33:18 | 00,027,776 | ---- | M] (Nero AG) (IrBus) Infrared bus filter driver for eHome remote controls [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\IrBus.sys -> [2008/04/13 08:45:34 | 00,046,592 | ---- | M] (Microsoft Corporation) (LaCieFWFilter) Silver 1394 Filter (1394 BUS Filter Driver) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\LaCieFWFilter.sys -> [2005/10/18 07:28:08 | 00,014,848 | ---- | M] (LaCie Group S.A.) (LaCieUSBFilter) Silver USB Filter (USB BUS Filter Driver) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\LaCieUSBFilter.sys -> [2005/10/19 08:34:02 | 00,015,872 | ---- | M] (LaCie Group) (Lbd) Lbd [File_System | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\Lbd.sys -> [2009/01/25 10:41:57 | 00,064,160 | ---- | M] (Lavasoft AB) (ltmodem5) Agere Modem Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys -> [2003/07/01 21:33:00 | 00,652,497 | ---- | M] (Agere Systems) (LVUSBSta) Logitech USB Monitor Filter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\lvusbsta.sys -> [2005/01/31 00:12:46 | 00,022,016 | R--- | M] (Logitech Inc.) (MASPINT) MASPINT [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\MASPINT.SYS -> [2000/03/29 12:11:20 | 00,008,096 | ---- | M] (MicroStaff Co.,Ltd.) (mmc_2K) mmc_2K [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\Mmc_2k.sys -> [2003/07/18 17:25:14 | 00,022,745 | ---- | M] (Roxio) (MN710-51) Microsoft(R) Wireless USB 2.0 Adapter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\MN710-51.sys -> [2004/01/07 10:04:00 | 00,339,520 | ---- | M] (GlobespanVirata, Inc.) (MSDV) Microsoft DV Camera and VCR [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\msdv.sys -> [2008/04/13 08:46:09 | 00,051,200 | ---- | M] (Microsoft Corporation) (NAVENG) NAVENG [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\VirusDefs\20091002.003\NAVENG.SYS -> [2009/08/26 22:00:00 | 00,084,912 | ---- | M] (Symantec Corporation) (NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\VirusDefs\20091002.003\NAVEX15.SYS -> [2009/08/26 22:00:00 | 01,323,568 | ---- | M] (Symantec Corporation) (NuidFltr) NUID filter driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\NuidFltr.sys -> [2009/05/09 01:14:20 | 00,014,736 | ---- | M] (Microsoft Corporation) (nv) nv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -> [2004/08/03 19:29:54 | 01,897,408 | ---- | M] (NVIDIA Corporation) (pepifilter) Volume Adapter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\lv302af.sys -> [2005/01/31 00:19:20 | 00,007,104 | R--- | M] (Logitech Inc.) (pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\pfc.sys -> [2002/10/01 04:22:32 | 00,009,856 | ---- | M] (Padus, Inc.) (PID_08A0) QuickCam IM(PID_08A0) [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\LV302AV.SYS -> [2005/01/31 00:26:06 | 00,912,768 | R--- | M] (Logitech Inc.) (PIXMCV) JVC Communication PIX-MCV Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\pixmcvc.sys -> [2002/09/28 04:08:08 | 00,032,000 | R--- | M] (Pixela) (PIXMCVA) JVC PIX-MCV Audio Capture [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\pixmcva.sys -> [2002/10/03 18:53:22 | 00,028,057 | R--- | M] (Pixela) (PIXMCVV) JVC PIX-MCV Video Capture [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\pixmcvv.sys -> [2002/11/28 00:16:36 | 00,021,081 | R--- | M] (Pixela) (Point32) Microsoft IntelliPoint Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\point32.sys -> [2006/06/29 22:51:21 | 00,021,760 | ---- | M] (Microsoft Corporation) (PQIMount) PQIMount [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\PQIMount.sys -> [2004/11/22 17:08:54 | 00,046,800 | ---- | M] (PowerQuest Corporation) (PQV2i) PQV2i [File_System | Boot | Running] -> C:\WINDOWS\System32\drivers\PQV2i.sys -> [2004/11/22 16:51:58 | 00,138,801 | ---- | M] (StorageCraft) (Ps2) Ps2 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\PS2.sys -> [2005/12/12 17:27:00 | 00,019,072 | ---- | M] (Hewlett-Packard Company) (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ptilink.sys -> [2003/07/30 02:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) (pwd_2k) pwd_2k [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\pwd_2K.sys -> [2003/07/18 17:25:10 | 00,118,409 | ---- | M] (Roxio) (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> C:\WINDOWS\System32\DRIVERS\PxHelp20.sys -> [2008/10/16 21:05:04 | 00,043,528 | ---- | M] (Sonic Solutions) (rtl8139) Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\R8139n51.SYS -> [2002/10/04 15:04:10 | 00,046,976 | ---- | M] (Realtek Semiconductor Corporation ) (SAVRT) SAVRT [Kernel | System | Running] -> C:\Program Files\Symantec AntiVirus\savrt.sys -> [2005/12/19 20:41:56 | 00,337,592 | ---- | M] (Symantec Corporation) (SAVRTPEL) SAVRTPEL [Kernel | System | Running] -> C:\Program Files\Symantec AntiVirus\Savrtpel.sys -> [2005/12/19 20:41:58 | 00,054,968 | ---- | M] (Symantec Corporation) (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\secdrv.sys -> [2007/11/13 00:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) (Ser2pl) Prolific2 Serial port driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\ser2pl.sys -> [2005/07/25 10:04:08 | 00,048,640 | ---- | M] (Prolific Technology Inc.) (SPBBCDrv) SPBBCDrv [Kernel | On_Demand | Stopped] -> C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -> [2006/02/06 12:50:22 | 00,389,776 | ---- | M] (Symantec Corporation) (srescan) srescan [Kernel | Boot | Running] -> C:\WINDOWS\system32\ZoneLabs\srescan.sys -> [2008/11/17 02:24:00 | 00,051,688 | ---- | M] (Check Point Software Technologies LTD) (StillCam) Still Serial Digital Camera Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\serscan.sys -> [2001/08/17 13:53:32 | 00,006,784 | ---- | M] (Microsoft Corporation) (SunkFilt) Alcor Micro Corp - 9360 [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\sunkfilt.sys -> [2003/08/13 15:50:36 | 00,039,648 | ---- | M] (Alcor Micro Corp.) (SymEvent) SymEvent [Kernel | Disabled | Running] -> C:\Program Files\Symantec\SYMEVENT.SYS -> [2006/01/31 13:29:20 | 00,107,696 | ---- | M] (Symantec Corporation) (SYMREDRV) SYMREDRV [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -> [2006/01/24 20:06:32 | 00,024,768 | ---- | M] (Symantec Corporation) (SYMTDI) SYMTDI [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\SYMTDI.SYS -> [2006/01/24 20:06:36 | 00,195,776 | ---- | M] (Symantec Corporation) (UdfReadr_xp) UdfReadr_xp [File_System | System | Running] -> C:\WINDOWS\System32\drivers\UdfReadr_xp.sys -> [2003/07/18 17:22:06 | 00,213,120 | ---- | M] (Roxio) (USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\usbaapl.sys -> [2009/08/28 19:42:52 | 00,040,448 | ---- | M] (Apple, Inc.) (usbaudio) USB Audio Driver (WDM) [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\usbaudio.sys -> [2008/04/13 08:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) (vsdatant) vsdatant [Kernel | System | Running] -> C:\WINDOWS\System32\vsdatant.sys -> [2009/02/16 00:10:26 | 00,353,672 | ---- | M] (Check Point Software Technologies LTD) ({6080A529-897E-4629-A488-ABA0C29B635E}) Intel(R) Graphics Platform (SoftBIOS) Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\ialmsbw.sys -> [2003/10/08 16:12:24 | 00,120,830 | ---- | M] (Intel Corporation) ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91}) Intel(R) Graphics Chipset (KCH) Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\ialmkchw.sys -> [2003/10/08 16:12:16 | 00,098,842 | ---- | M] (Intel Corporation) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> [binary data] -> HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://www.google.com/ie -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome -> HKEY_USERS\.DEFAULT\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\.DEFAULT\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\.DEFAULT\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ -> HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome -> HKEY_USERS\S-1-5-18\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-18\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-18\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ -> HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> HKEY_USERS\S-1-5-19\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome -> HKEY_USERS\S-1-5-19\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-19\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-19\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ -> HKEY_USERS\S-1-5-19\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> HKEY_USERS\S-1-5-20\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome -> HKEY_USERS\S-1-5-20\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-20\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-20\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ -> HKEY_USERS\S-1-5-20\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: Main\\"Search Page" -> http://www.google.com -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: Main\\"SearchMigratedDefaultName" -> Google -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: Main\\"SearchMigratedDefaultURL" -> http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: Main\\"Start Page" -> http://www.rr.com/ -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: SearchURL\\"" -> http://www.google.com/keyword/%s -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: "ProxyEnable" -> 0 -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: "ProxyOverride" -> localhost;*.local -> < FireFox Settings [Prefs.js] > -> C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\prefs.js -> browser.startup.homepage -> "http://www.google.com/" -> extensions.enabledItems -> {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1 -> extensions.enabledItems -> 6 -> extensions.enabledItems -> 2 -> extensions.enabledItems -> 41 -> extensions.enabledItems -> {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.96 -> extensions.enabledItems -> {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5 -> extensions.enabledItems -> {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.32.0 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 -> extensions.enabledItems -> {20a82645-c095-46ed-80e3-08825760534b}:1.1 -> extensions.enabledItems -> statusbar@toodledo.com:1.60 -> extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3 -> < FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla HKLM\software\mozilla\Firefox\Extensions -> -> HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/06/24 03:04:09 | 00,000,000 | ---D | M] HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8} -> C:\PROGRAM FILES\GOOGLE\GOOGLE GEARS\FIREFOX [C:\PROGRAM FILES\GOOGLE\GOOGLE GEARS\FIREFOX\] -> [2009/09/08 10:18:41 | 00,000,000 | ---D | M] HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions -> -> HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components -> C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/09/09 19:16:03 | 00,000,000 | ---D | M] HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/09/09 19:16:03 | 00,000,000 | ---D | M] < FireFox Extensions [User Folders] > -> -> C:\Documents and Settings\JD\Application Data\mozilla\Extensions -> [2008/06/18 18:29:12 | 00,000,000 | ---D | M] -> C:\Documents and Settings\JD\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2008/06/18 18:29:12 | 00,000,000 | ---D | M] -> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] () -> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{1AF3FC34-0725-4485-A939-6B40EB7CA96A} -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] () -> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] () -> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] () -> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] () -> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\statusbar@toodledo.com -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] () < FireFox SearchPlugins [User Folders] > -> C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\searchplugins\ -> C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\searchplugins -> [2008/10/12 18:10:36 | 00,000,000 | ---D | M] search.xml -> C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\searchplugins\search.xml -> [2008/10/12 18:10:36 | 00,000,276 | ---- | M] () < FireFox Extensions [Program Folders] > -> -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions -> [2009/09/09 19:16:03 | 10,776,568 | ---- | M] (Mozilla Foundation) -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/09/09 19:16:03 | 10,776,568 | ---- | M] (Mozilla Foundation) -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} -> [2009/09/09 19:16:03 | 10,776,568 | ---- | M] (Mozilla Foundation) < FireFox Components [Program Folders] > -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\components -> [2009/09/09 19:16:03 | 00,000,000 | ---D | M] browserdirprovider.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009/09/09 19:15:53 | 00,023,544 | ---- | M] (Mozilla Foundation) brwsrcmp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009/09/09 19:15:53 | 00,137,208 | ---- | M] (Mozilla Foundation) < FireFox Plugins [Program Folders] > -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins -> [2009/09/09 19:16:03 | 00,000,000 | ---D | M] np32dsw.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\np32dsw.dll -> [2008/03/19 19:23:20 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) npbittorrent.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npbittorrent.dll -> [2008/09/03 14:11:24 | 00,054,600 | ---- | M] (BitTorrent, Inc.) npCouponPrinter.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npCouponPrinter.dll -> [2008/06/17 20:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) npLegitCheckPlugin.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npLegitCheckPlugin.dll -> [2007/10/11 14:17:50 | 01,435,688 | ---- | M] (Microsoft Corporation) npnul32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009/09/09 19:15:56 | 00,065,016 | ---- | M] (mozilla.org) NPOFF12.DLL -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPOFF12.DLL -> [2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) nppdf32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\nppdf32.dll -> [2007/05/10 22:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) NPPxIm.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPPxIm.dll -> [2006/09/07 10:08:58 | 00,618,496 | ---- | M] (Pixami) NPPxPrn.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPPxPrn.dll -> [2006/09/07 10:08:58 | 00,819,200 | ---- | M] (Pixami) npqtplugin.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin.dll -> [2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.) npqtplugin2.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin2.dll -> [2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.) npqtplugin3.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin3.dll -> [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) npqtplugin4.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin4.dll -> [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) npqtplugin5.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin5.dll -> [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) npqtplugin6.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin6.dll -> [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) npqtplugin7.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin7.dll -> [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) NPZoneSB.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPZoneSB.dll -> [2007/12/25 00:02:38 | 00,024,673 | ---- | M] (Check Point Software Technologies Ltd.) np_gp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\np_gp.dll -> [2009/08/07 12:44:18 | 00,030,400 | ---- | M] (NOS Microsystems Ltd.) nsIQTScriptablePlugin.xpt -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\nsIQTScriptablePlugin.xpt -> [2007/05/22 18:16:49 | 00,002,394 | ---- | M] () QuickTimePlugin.class -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\QuickTimePlugin.cla -> [2009/09/09 19:02:21 | 00,004,208 | ---- | M] () ShockwavePlugin.class -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\ShockwavePlugin.cla -> [2008/03/19 18:33:36 | 00,001,144 | ---- | M] () < FireFox SearchPlugins [Program Folders] > -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins -> [2009/08/15 07:48:45 | 00,000,000 | ---D | M] amazondotcom.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\amazondotcom.xml -> [2009/08/15 07:48:37 | 00,001,394 | ---- | M] () answers.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\answers.xml -> [2009/08/15 07:48:37 | 00,002,193 | ---- | M] () creativecommons.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\creativecommons.xml -> [2009/08/15 07:48:37 | 00,001,534 | ---- | M] () eBay.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\eBay.xml -> [2009/08/15 07:48:37 | 00,002,344 | ---- | M] () google.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\google.xml -> [2009/08/15 07:48:37 | 00,002,371 | ---- | M] () wikipedia.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\wikipedia.xml -> [2009/08/15 07:48:37 | 00,001,178 | ---- | M] () yahoo.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\yahoo.xml -> [2009/08/15 07:48:37 | 00,000,792 | ---- | M] () < HOSTS File > (319151 bytes and 10989 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> First 25 entries... Reset Hosts 127.0.0.1 localhost 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1001namen.com 127.0.0.1 1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 100sexlinks.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {0347C33E-8762-4905-BF09-768834316C61} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [HP Print Enhancer] -> [2007/03/02 16:52:24 | 01,298,024 | R--- | M] (Hewlett-Packard Co.) {053F9267-DC04-4294-A72C-58F732D338C0} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [HP Print Clips] -> [2007/03/02 16:52:08 | 00,177,768 | R--- | M] (Hewlett-Packard Co.) {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 23:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated) {0A87E45F-537A-40B4-B812-E2544C21A09F} [HKLM] -> Reg Error: Value error. [SpywareBlock Class] -> File not found {53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> [2008/09/15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited) {724d43a9-0d85-11d4-9908-00400523e39a} [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll [Reg Error: Value error.] -> [2009/08/15 07:56:19 | 05,960,520 | ---- | M] (Siber Systems Inc.) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [SSVHelper Class] -> [2007/09/25 01:11:33 | 00,501,136 | ---- | M] (Sun Microsystems, Inc.) {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} [HKLM] -> C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll [Google Gears Helper] -> [2009/08/21 13:49:42 | 02,097,152 | ---- | M] (Google Inc.) < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "" [HKLM] -> Reg Error: Key error. [Reg Error: Value error.] -> File not found "{724d43a0-0d85-11d4-9908-00400523e39a}" [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll [&RoboForm] -> [2009/08/15 07:56:19 | 05,960,520 | ---- | M] (Siber Systems Inc.) "{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}" [HKLM] -> c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll [HP View] -> [2003/09/03 16:42:14 | 00,098,304 | ---- | M] (Hewlett-Packard Company) < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found ShellBrowser\\"{724D43A0-0D85-11D4-9908-00400523E39A}" [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll [&RoboForm] -> [2009/08/15 07:56:19 | 05,960,520 | ---- | M] (Siber Systems Inc.) ShellBrowser\\"{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}" [HKLM] -> c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll [HP View] -> [2003/09/03 16:42:14 | 00,098,304 | ---- | M] (Hewlett-Packard Company) WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> c:\program files\google\googletoolbar1.dll [&Google] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.) WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{724D43A0-0D85-11D4-9908-00400523E39A}" [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll [&RoboForm] -> [2009/08/15 07:56:19 | 05,960,520 | ---- | M] (Siber Systems Inc.) WebBrowser\\"{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}" [HKLM] -> c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll [HP View] -> [2003/09/03 16:42:14 | 00,098,304 | ---- | M] (Hewlett-Packard Company) < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "AppleSyncNotifier" -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe] -> [2009/08/13 15:51:42 | 00,177,440 | ---- | M] (Apple Inc.) "ATIPTA" -> C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] -> [2004/11/03 21:10:00 | 00,344,064 | ---- | M] (ATI Technologies, Inc.) "CamMonitor" -> c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe ["c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe"] -> [2002/10/07 05:23:20 | 00,090,112 | ---- | M] () "ccApp" -> C:\Program Files\Common Files\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> [2006/03/07 13:02:14 | 00,053,408 | ---- | M] (Symantec Corporation) "HP Component Manager" -> C:\Program Files\HP\hpcoretech\hpcmpmgr.exe ["C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"] -> [2005/01/12 09:54:58 | 00,241,664 | ---- | M] (Hewlett-Packard Company) "HPHmon05" -> C:\WINDOWS\System32\hphmon05.exe [C:\WINDOWS\System32\hphmon05.exe] -> [2003/05/23 00:55:38 | 00,483,328 | ---- | M] (Hewlett-Packard) "hpqSRMon" -> C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe] -> [2007/08/22 16:31:16 | 00,080,896 | ---- | M] (Hewlett-Packard) "IMEKRMIG6.1" -> C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE [C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE] -> [2003/07/30 09:00:00 | 00,044,032 | ---- | M] (Microsoft Corporation) "IMJPMIG8.1" -> C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE ["C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32] -> [2004/08/03 19:31:59 | 00,208,952 | ---- | M] (Microsoft Corporation) "IntelliPoint" -> C:\Program Files\Microsoft IntelliPoint\ipoint.exe ["C:\Program Files\Microsoft IntelliPoint\ipoint.exe"] -> [2006/07/07 13:15:07 | 00,600,896 | ---- | M] (Microsoft Corporation) "iTunesHelper" -> C:\Program Files\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2009/09/08 21:09:42 | 00,305,440 | ---- | M] (Apple Inc.) "itype" -> C:\Program Files\Microsoft IntelliType Pro\itype.exe ["C:\Program Files\Microsoft IntelliType Pro\itype.exe"] -> [2006/07/07 13:14:38 | 00,576,320 | ---- | M] (Microsoft Corporation) "KBD" -> C:\HP\KBD\KBD.EXE [C:\HP\KBD\KBD.EXE] -> [2005/02/02 16:44:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) "Malwarebytes Anti-Malware (reboot)" -> C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe ["C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript] -> [2009/09/10 14:53:56 | 01,312,080 | ---- | M] (Malwarebytes Corporation) "MaxMenuMgr" -> C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe ["C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"] -> [2009/05/01 14:35:10 | 00,185,640 | ---- | M] (Seagate LLC) "MSPY2002" -> C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe [C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC] -> [2002/08/28 15:39:06 | 00,059,392 | ---- | M] () "Norton Ghost 9.0" -> C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe ["C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe"] -> [2004/11/22 17:20:54 | 01,126,400 | ---- | M] (Symantec Corporation) "PHIME2002A" -> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] -> [2002/08/28 15:39:50 | 00,455,168 | ---- | M] (Microsoft Corporation) "PHIME2002ASync" -> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] -> [2002/08/28 15:39:50 | 00,455,168 | ---- | M] (Microsoft Corporation) "PP7600usb" -> C:\Program Files\Visioneer\PaperPort\FBDirect.exe [C:\PROGRA~1\VISION~1\PAPERP~1\FBDirect.exe] -> [2000/09/22 10:13:40 | 00,227,328 | ---- | M] (Visioneer Inc.) "Recguard" -> C:\WINDOWS\SMINST\RECGUARD.EXE [C:\WINDOWS\SMINST\RECGUARD.EXE] -> [2002/09/13 19:42:26 | 00,212,992 | ---- | M] () "Sunkist2k" -> C:\Program Files\Multimedia Card Reader\shwicon2k.exe ["C:\Program Files\Multimedia Card Reader\shwicon2k.exe"] -> [2003/08/14 14:11:32 | 00,139,264 | ---- | M] (Alcor Micro, Corp.) "vptray" -> C:\Program Files\Symantec AntiVirus\VPTray.exe [C:\PROGRA~1\SYMANT~1\VPTray.exe] -> [2006/03/17 06:34:30 | 00,124,656 | ---- | M] (Symantec Corporation) "wefowuwus" -> C:\WINDOWS\System32\wobihasa.DLL [Rundll32.exe "c:\windows\system32\wobihasa.dll",a] -> [2009/10/03 05:21:32 | 00,091,136 | ---- | M] () "ZoneAlarm Client" -> C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe ["C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"] -> [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) < Run [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "BitTorrent DNA" -> C:\Program Files\DNA\btdna.exe ["C:\Program Files\DNA\btdna.exe"] -> [2009/01/13 21:10:40 | 00,342,848 | ---- | M] (BitTorrent, Inc.) "SpybotSD TeaTimer" -> C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe] -> [2009/03/05 16:07:20 | 02,260,480 | ---- | M] (Safer-Networking Ltd.) "Startup Cop Pro Startup Launcher" -> C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe ["C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe" /startup] -> [2007/09/26 23:23:28 | 02,211,840 | ---- | M] (Ziff-Davis Media, Inc.) < Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> < Aimee Startup Folder > -> C:\Documents and Settings\Aimee\Start Menu\Programs\Startup -> < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe -> [2007/03/11 21:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.) C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe -> [2008/05/26 22:19:14 | 00,123,904 | ---- | M] (Microsoft Corporation) C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Zone Labs Security.lnk -> C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe -> [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) < Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup\AutoTBar.exe -> [2003/06/18 17:19:08 | 00,053,248 | ---- | M] () < JD Startup Folder > -> C:\Documents and Settings\JD\Start Menu\Programs\Startup -> -> C:\Documents and Settings\JD\Start Menu\Programs\Startup\TempClean.bat -> [2005/11/25 11:11:20 | 00,000,030 | ---- | M] () < Kids Startup Folder > -> C:\Documents and Settings\Kids\Start Menu\Programs\Startup -> < Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions \Infodelivery\Restrictions\\"NoUpdateCheck" -> [1] -> File not found HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main \Main\\"DisableFirstRunCustomize" -> [1] -> File not found < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoCDBurning" -> [0] -> File not found \\"LinkResolveIgnoreLinkInfo" -> [0] -> File not found \\"NoResolveSearch" -> [1] -> File not found \\"HonorAutoRunSetting" -> [1] -> File not found < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"dontdisplaylastusername" -> [0] -> File not found \\"legalnoticecaption" -> [] -> File not found \\"legalnoticetext" -> [] -> File not found \\"shutdownwithoutlogon" -> [1] -> File not found \\"undockwithoutlogon" -> [1] -> File not found \\"DisableTaskMgr" -> [0] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [149] -> File not found \\"CDRAutoRun" -> [0] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [149] -> File not found \\"CDRAutoRun" -> [0] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [149] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [149] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [149] -> File not found \\"LinkResolveIgnoreLinkInfo" -> [0] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"DisableTaskMgr" -> [0] -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xport to Microsoft Excel -> C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE [res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000] -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xport to Microsoft Excel -> C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE [res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000] -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\Software\Microsoft\Internet Explorer\MenuExt\ -> &Google Search -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.) &Translate English Word -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.) Backward Links -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.) Cached Snapshot of Page -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.) Customize Menu -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html [file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html] -> [2009/08/15 07:56:51 | 00,000,212 | ---- | M] () E&xport to Microsoft Excel -> C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000] -> [2009/05/04 08:40:04 | 18,333,536 | ---- | M] (Microsoft Corporation) Fill Forms -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html [file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html] -> [2009/08/15 07:56:51 | 00,000,206 | ---- | M] () Save Forms -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html [file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html] -> [2009/08/15 07:56:51 | 00,000,205 | ---- | M] () Similar Pages -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.) Translate Page into English -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.) < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll [Menu: Sun Java Console] -> [2007/09/25 01:11:34 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.) {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5}:{0B4350D1-055F-47A3-B112-5F2F2B0D6F08} [HKLM] -> C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll [Menu: &Gears Settings] -> [2009/08/21 13:49:42 | 02,097,152 | ---- | M] (Google Inc.) {320AF880-6646-11D3-ABEE-C5DBF3571F46}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html [Button: Fill Forms] -> [2009/08/15 07:56:51 | 00,000,206 | ---- | M] () {320AF880-6646-11D3-ABEE-C5DBF3571F46}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html [Menu: Fill Forms] -> [2009/08/15 07:56:51 | 00,000,206 | ---- | M] () {320AF880-6646-11D3-ABEE-C5DBF3571F49}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html [Button: Save] -> [2009/08/15 07:56:51 | 00,000,205 | ---- | M] () {320AF880-6646-11D3-ABEE-C5DBF3571F49}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html [Menu: Save Forms] -> [2009/08/15 07:56:51 | 00,000,205 | ---- | M] () {58ECB495-38F0-49cb-A538-10282ABF65E7}:{E763472E-A716-4CD9-89BD-DBDA6122F741} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll [Button: HP Clipbook] -> [2007/03/02 16:53:20 | 00,153,192 | R--- | M] (Hewlett-Packard Co.) {700259D7-1666-479a-93B1-3250410481E8}:{A93C41D8-01F8-4F8B-B14C-DE20B117E636} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll [Button: HP Smart Select] -> [2007/03/02 16:53:20 | 00,153,192 | R--- | M] (Hewlett-Packard Co.) {724d43aa-0d85-11d4-9908-00400523e39a}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html [Button: RoboForm] -> [2009/08/15 07:56:51 | 00,000,208 | ---- | M] () {724d43aa-0d85-11d4-9908-00400523e39a}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html [Menu: RoboForm Toolbar] -> [2009/08/15 07:56:51 | 00,000,208 | ---- | M] () {92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2009/03/06 04:04:56 | 00,039,464 | ---- | M] (Microsoft Corporation) {d81ca86b-ef63-42af-bee3-4502d9a03c2d}:http://wwws.musicmatch.com/mmz/openWebRadio.html [HKLM] -> [Button: MUSICMATCH MX Web Player] -> File not found {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2008/09/15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited) {E28AB5C9-B58F-4512-AF80-29001BC5A29D}:Exec [HKLM] -> C:\Program Files\PokerTimeGuestMPP\MPPoker.exe [Button: PokerTime.net Poker] -> [2005/10/07 14:38:16 | 00,049,213 | ---- | M] (Microgaming) {e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 08:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> [2007/09/25 01:11:34 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.) CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F46}" [HKLM] -> [Fill Forms] -> File not found CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F49}" [HKLM] -> [Save] -> File not found CmdMapping\\"{724d43aa-0d85-11d4-9908-00400523e39a}" [HKLM] -> [RoboForm] -> File not found CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2009/03/06 04:04:56 | 00,039,464 | ---- | M] (Microsoft Corporation) CmdMapping\\"{d81ca86b-ef63-42af-bee3-4502d9a03c2d}" [HKLM] -> C:\Program Files\MUSICMATCH\MUSICMATCH Media Center\MMRadioHostX.dll [MMRadioHostX Class] -> [2003/07/24 01:08:00 | 00,430,080 | ---- | M] (MUSICMATCH Inc) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> [2007/09/25 01:11:34 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.) CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F46}" [HKLM] -> [Fill Forms] -> File not found CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F49}" [HKLM] -> [Save] -> File not found CmdMapping\\"{724d43aa-0d85-11d4-9908-00400523e39a}" [HKLM] -> [RoboForm] -> File not found CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2009/03/06 04:04:56 | 00,039,464 | ---- | M] (Microsoft Corporation) CmdMapping\\"{d81ca86b-ef63-42af-bee3-4502d9a03c2d}" [HKLM] -> C:\Program Files\MUSICMATCH\MUSICMATCH Media Center\MMRadioHostX.dll [MMRadioHostX Class] -> [2003/07/24 01:08:00 | 00,430,080 | ---- | M] (MUSICMATCH Inc) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> [2007/09/25 01:11:34 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.) CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F46}" [HKLM] -> [Fill Forms] -> File not found CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F49}" [HKLM] -> [Save] -> File not found CmdMapping\\"{58ECB495-38F0-49cb-A538-10282ABF65E7}" [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll [HP Clipbook] -> [2007/03/02 16:53:20 | 00,153,192 | R--- | M] (Hewlett-Packard Co.) CmdMapping\\"{700259D7-1666-479a-93B1-3250410481E8}" [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll [HP Smart Select] -> [2007/03/02 16:53:20 | 00,153,192 | R--- | M] (Hewlett-Packard Co.) CmdMapping\\"{724d43aa-0d85-11d4-9908-00400523e39a}" [HKLM] -> [RoboForm] -> File not found CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2009/03/06 04:04:56 | 00,039,464 | ---- | M] (Microsoft Corporation) CmdMapping\\"{A75C6120-9B36-11d4-A3F0-009027427750}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{d81ca86b-ef63-42af-bee3-4502d9a03c2d}" [HKLM] -> C:\Program Files\MUSICMATCH\MUSICMATCH Media Center\MMRadioHostX.dll [MMRadioHostX Class] -> [2003/07/24 01:08:00 | 00,430,080 | ---- | M] (MUSICMATCH Inc) CmdMapping\\"{E28AB5C9-B58F-4512-AF80-29001BC5A29D}" [HKLM] -> C:\Program Files\PokerTimeGuestMPP\MPPoker.exe [PokerTime.net Poker] -> [2005/10/07 14:38:16 | 00,049,213 | ---- | M] (Microgaming) CmdMapping\\"{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}" [HKLM] -> [Messenger Class] -> File not found CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5692 domain(s) found. -> 58 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5691 domain(s) found. -> 57 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 66 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5691 domain(s) found. -> 57 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 66 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 30 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 30 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5837 domain(s) found. -> turbotax.com .[https] -> Trusted sites -> 69 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 66 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {01113300-3E00-11D2-8470-0060089874ED} [HKLM] -> http://activation.rr.com/install/download/tgctlcm.cab [Support.com Configuration Class] -> {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [HKLM] -> http://www.apple.com/qtactivex/qtplugin.cab [QuickTime Object] -> {1B9935E4-8A50-4DD8-BD09-A7518723BF97} [HKLM] -> https://quicken.ehosts.net/netagent/objects/custappx3.CAB [eAssist NetAgent Customer ActiveX Control version 3] -> {1F2F4C9E-6F09-47BC-970D-3C54734667FE} [HKLM] -> https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab [LSSupCtl Class] -> {37A273C2-5129-11D5-BF37-00A0CCE8754B} [HKLM] -> http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab [TTestGenXInstallObject] -> {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} [HKLM] -> http://office.microsoft.com/officeupdate/content/opuc.cab [Office Update Installation Engine] -> {4F1E5B1A-2A80-42CA-8532-2D05CB959537} [HKLM] -> http://spaces.msn.com//PhotoUpload/MsnPUpld.cab [MSN Photo Upload Tool] -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231725258781 [MUWebControl Class] -> {88D8E8B7-A33B-4417-A385-8373484D43ED} [HKLM] -> file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll [InstallHelper Class] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab [Java Plug-in 1.6.0_03] -> {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} [HKLM] -> file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll [There Voice Trainer] -> {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [Reg Error: Key error.] -> {95D88B35-A521-472B-A182-BB1A98356421} [HKLM] -> http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab [Pearson Installation Assistant 2] -> {99B6E512-3893-4155-9964-8EB8E06099CB} [HKLM] -> http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab [WebSpyWareKiller Class] -> {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} [HKLM] -> http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab [Anonymizer Anti-Spyware Scanner] -> {AAF421E6-7914-430A-9981-72B31AFF3BF4} [HKLM] -> file://c:\Program Files\There\ThereClient\ThereLauncher.dll [There Launcher] -> {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} [HKLM] -> http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab [MsnMessengerSetupDownloadControl Class] -> {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab [Java Plug-in 1.4.2] -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab [Java Plug-in 1.6.0_03] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab [Java Plug-in 1.6.0_03] -> {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} [HKLM] -> https://www-secure.symantec.com/techsupp/asa/SymAData.cab [ActiveDataInfo Class] -> {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] -> {D44C75D8-C827-473E-8F68-A77E42500782} [HKLM] -> http://www.samsphotoclub.com/upload/WebUploadClient.cab [Uploader Class] -> {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} [HKLM] -> http://asp.mathxl.com/books/_Players/EconPlayer.cab [Pearson MyEconLab Player Control] -> {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} [HKLM] -> http://216.249.24.60/code/iPIX-ImageWell-ipix.cab [iPIX Media Send Class] -> < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> DhcpNameServer -> 24.25.227.55 209.18.47.61 24.25.227.53 -> < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {1EA86FCF-F590-471F-B18E-5C5E04316610}\\DhcpNameServer -> 68.1.18.237 68.1.18.30 68.10.16.30 (Microsoft(R) Wireless USB 2.0 Adapter MN-710) -> {224C9E3D-B480-4131-B37B-D04AA84DE8DF}\\DhcpNameServer -> 24.25.227.55 209.18.47.61 24.25.227.53 (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {C8256A9A-78B4-4C7A-BC9D-4ED2E7C593DB}\\DhcpNameServer -> 68.1.18.237 68.1.18.30 68.10.16.30 (Microsoft(R) Wireless USB 2.0 Adapter MN-710) -> IE Styles -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> c:\windows\system32\gisisema.dll -> C:\WINDOWS\System32\gisisema.dll -> File not found c:\windows\system32\ -> C:\WINDOWS\System32 -> [2009/10/03 10:17:47 | 00,000,000 | ---D | M] c:\windows\system32\yudegoku.dll -> C:\WINDOWS\System32\yudegoku.dll -> File not found tehunevo.dll -> C:\WINDOWS\System32\tehunevo.dll -> [2009/07/02 17:22:59 | 00,052,224 | ---- | M] () c:\windows\system32\wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll -> [2009/10/03 05:21:32 | 00,091,136 | ---- | M] () *MultiFile Done* -> -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> Explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> AtiExtEvent -> C:\WINDOWS\System32\ati2evxx.dll -> [2004/11/03 21:38:16 | 00,090,112 | ---- | M] (ATI Technologies Inc.) igfxcui -> C:\WINDOWS\System32\igfxsrvc.dll -> [2003/10/02 19:18:52 | 00,319,488 | ---- | M] (Intel Corporation) NavLogon -> C:\WINDOWS\System32\NavLogon.dll -> [2006/03/17 06:34:36 | 00,043,760 | ---- | M] (Symantec Corporation) < SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad -> "{324fc3bb-4f3e-4c51-84b7-1689cfe42ed0}" [HKLM] -> C:\WINDOWS\System32\yudegoku.dll [ganokiboy] -> File not found "{de4e9e38-28ca-4548-8ac1-ad002276dd90}" [HKLM] -> C:\WINDOWS\System32\gisisema.dll [kawuhesud] -> File not found "{d045846b-9cd4-48bf-b327-b0f6757c4d5f}" [HKLM] -> C:\WINDOWS\System32\wobihasa.dll [sebugeban] -> [2009/10/03 05:21:32 | 00,091,136 | ---- | M] () < SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler -> "{324fc3bb-4f3e-4c51-84b7-1689cfe42ed0}" [HKLM] -> C:\WINDOWS\System32\yudegoku.dll [tokatiluy] -> File not found "{d045846b-9cd4-48bf-b327-b0f6757c4d5f}" [HKLM] -> C:\WINDOWS\System32\wobihasa.dll [mujuzedij] -> [2009/10/03 05:21:32 | 00,091,136 | ---- | M] () "{de4e9e38-28ca-4548-8ac1-ad002276dd90}" [HKLM] -> C:\WINDOWS\System32\gisisema.dll [tokatiluy] -> File not found < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> "{56F9679E-7826-4C84-81F3-532071A8BCC5}" [HKLM] -> C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [] -> [2009/05/24 22:41:34 | 00,304,128 | ---- | M] (Microsoft Corporation) < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 08:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 14:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" -> C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger] -> [2005/09/02 21:17:52 | 00,032,768 | ---- | M] (Logitech) "C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5] -> [2005/09/19 00:02:36 | 07,083,056 | ---- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 08:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 14:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) "C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe" -> C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe [C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe:*:Enabled:14267034] -> File not found "C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe" -> C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe [C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe:*:Enabled:16496404] -> File not found "C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe" -> C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe [C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 Gold] -> [2007/06/06 19:23:14 | 12,708,560 | ---- | M] (Firaxis Games) "C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe" -> C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe [C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization 4: Warlords] -> [2007/06/06 19:22:54 | 12,266,184 | ---- | M] (Firaxis Games) "C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe" -> C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe [C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe:*:Disabled:Adobe Photoshop Elements Media Server] -> [2008/09/16 12:03:34 | 02,954,592 | ---- | M] (Adobe Systems Incorporated) "C:\Program Files\BitTorrent\bittorrent.exe" -> C:\Program Files\BitTorrent\bittorrent.exe [C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent] -> [2008/12/16 10:16:10 | 00,637,232 | ---- | M] (BitTorrent, Inc.) "C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) "C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" -> C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server] -> [2008/10/10 05:45:26 | 00,013,088 | ---- | M] (Intuit Inc.) "C:\Program Files\DNA\btdna.exe" -> C:\Program Files\DNA\btdna.exe [C:\Program Files\DNA\btdna.exe:*:Enabled:DNA] -> [2009/01/13 21:10:40 | 00,342,848 | ---- | M] (BitTorrent, Inc.) "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe [C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe] -> [2007/05/13 23:47:50 | 00,075,352 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe [C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe] -> [2007/03/11 21:55:28 | 00,280,152 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe [C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe] -> [2007/03/11 21:55:28 | 00,053,248 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" -> C:\Program Files\HP\Digital Imaging\bin\hposid01.exe [C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe] -> [2007/05/13 23:47:50 | 00,108,120 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe [C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe] -> [2007/03/12 03:35:02 | 01,196,032 | ---- | M] (Hewlett-Packard) "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe [C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe] -> [2007/05/13 23:14:44 | 00,192,512 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe [C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe] -> [2007/03/12 03:35:02 | 00,249,856 | ---- | M] () "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe [C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe] -> [2007/03/11 21:32:42 | 00,151,552 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe] -> [2007/03/11 21:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe [C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe] -> [2007/03/11 21:55:28 | 00,476,760 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" -> C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe [C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe] -> [2003/07/02 08:06:42 | 00,364,544 | ---- | M] () "C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2009/09/08 21:09:38 | 10,309,408 | ---- | M] (Apple Inc.) "C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> File not found "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" -> C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger] -> [2005/09/02 21:17:52 | 00,032,768 | ---- | M] (Logitech) "C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" -> C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook] -> [2009/04/17 03:30:12 | 12,438,896 | ---- | M] (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5] -> [2005/09/19 00:02:36 | 07,083,056 | ---- | M] (Microsoft Corporation) "C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe" -> C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe [C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe:*:Enabled:StartupCopPro] -> [2007/09/26 23:23:28 | 02,211,840 | ---- | M] (Ziff-Davis Media, Inc.) "C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe" -> C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe [C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax] -> [2007/03/08 01:25:56 | 09,950,760 | ---- | M] (Intuit, Inc.) "C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe" -> C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe [C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager] -> [2007/02/19 13:06:50 | 03,679,784 | ---- | M] (Intuit, Inc.) "C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe" -> C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe [C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax] -> [2008/03/05 23:29:49 | 10,343,712 | ---- | M] (Intuit, Inc.) "C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe" -> C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe [C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager] -> [2007/10/22 18:56:52 | 03,597,600 | ---- | M] (Intuit, Inc.) "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" -> C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe:*:Enabled:zlclient] -> [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) "C:\WINDOWS\explorer.exe" -> C:\WINDOWS\explorer.exe [C:\WINDOWS\explorer.exe:*:Enabled:Explorer] -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) "C:\WINDOWS\pchealth\helpctr\Binaries\helpctr.exe" -> C:\WINDOWS\pchealth\helpctr\Binaries\helpctr.exe [C:\WINDOWS\pchealth\helpctr\Binaries\helpctr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice] -> [2008/04/13 14:12:21 | 00,769,024 | ---- | M] (Microsoft Corporation) "C:\WINDOWS\system32\hpzipm12.exe" -> C:\WINDOWS\System32\hpzipm12.exe [C:\WINDOWS\system32\hpzipm12.exe:*:Enabled:hpzipm12] -> [2003/05/16 15:54:34 | 00,065,795 | ---- | M] (HP) "C:\WINDOWS\system32\logonui.exe" -> C:\WINDOWS\System32\logonui.exe [C:\WINDOWS\system32\logonui.exe:*:Enabled:logonui] -> [2008/04/13 14:12:24 | 00,514,560 | ---- | M] (Microsoft Corporation) "C:\WINDOWS\system32\winlogon.exe" -> C:\WINDOWS\System32\winlogon.exe [C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon] -> [2008/04/13 14:12:39 | 00,507,904 | ---- | M] (Microsoft Corporation) "C:\WINDOWS\system32\wscntfy.exe" -> C:\WINDOWS\System32\wscntfy.exe [C:\WINDOWS\system32\wscntfy.exe:*:Enabled:wscntfy] -> [2008/04/13 14:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) "E:\setup\HPZNUI01.EXE" -> E:\setup\HPZNUI01.EXE [E:\setup\HPZNUI01.EXE:*:Enabled:hpznui01.exe] -> File not found < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM Driver -> "ImagePath" -> [System32\DRIVERS\cdrom.sys] -> File not found < Drives with AutoRun files > -> -> C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2003/12/16 19:45:52 | 00,000,000 | ---- | M] () D:\AUTOEXEC.BAT [] -> D:\AUTOEXEC.BAT [ FAT32 ] -> [2001/07/28 06:07:38 | 00,000,000 | -HS- | M] () D:\Autorun.inf [[AUTORUN] | OPEN=Info.exe folder.htt 480 480 | ] -> D:\Autorun.inf [ FAT32 ] -> [2002/09/11 03:02:32 | 00,000,045 | -HS- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> \{391dd251-46bc-11dd-b7f4-000ea6c3bfc8} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{391dd251-46bc-11dd-b7f4-000ea6c3bfc8}\Shell\AutoRun\command \{391dd251-46bc-11dd-b7f4-000ea6c3bfc8}\Shell\AutoRun\command\\"" -> [.\Encryption Tool\MaxtorEncryption.exe] -> File not found \{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\AutoRun\command \{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\AutoRun\command\\"" -> F:\PortableRoboForm.exe [F:\PortableRoboForm.exe] -> File not found \{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\RoboForm2Go\command \{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\RoboForm2Go\command\\"" -> F:\PortableRoboForm.exe [F:\PortableRoboForm.exe] -> File not found \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\AutoRun\command \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\AutoRun\command\\"" -> J:\Autorun.exe [J:\Autorun.exe /run] -> File not found \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell00\Command \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell00\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /run] -> File not found \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell01\Command \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell01\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /action] -> File not found \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell02\Command \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell02\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /uninstall] -> File not found < Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command -> comfile [open] -> "%1" %* -> File not found exefile [open] -> "%1" %* -> File not found [Registry - Additional Scans - Safe List] < Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command -> batfile [open] -> "%1" %* -> File not found chm.file [open] -> "C:\WINDOWS\hh.exe" %1 -> [2008/04/13 14:12:21 | 00,010,752 | ---- | M] (Microsoft Corporation) cmdfile [open] -> "%1" %* -> File not found comfile [open] -> "%1" %* -> File not found exefile [open] -> "%1" %* -> File not found htmlfile [edit] -> "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde -> File not found htmlfile [open] -> "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome -> [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) htmlfile [opennew] -> "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 -> [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) htmlfile [print] -> Reg Error: Key error. http [open] -> "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" -> [2009/09/09 19:15:54 | 00,908,280 | ---- | M] (Mozilla Corporation) https [open] -> "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" -> [2009/09/09 19:15:54 | 00,908,280 | ---- | M] (Mozilla Corporation) piffile [open] -> "%1" %* -> File not found regfile [merge] -> Reg Error: Key error. scrfile [config] -> "%1" -> File not found scrfile [install] -> rundll32.exe desk.cpl,InstallScreenSaver %l -> [2008/04/13 14:12:41 | 00,135,168 | ---- | M] (Microsoft Corporation) scrfile [open] -> "%1" %* -> File not found txtfile [edit] -> Reg Error: Key error. Directory [AddToPlaylistVLC] -> C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" -> [2008/12/06 04:57:20 | 00,114,840 | ---- | M] () Directory [find] -> %SystemRoot%\Explorer.exe -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) Directory [PlayWithVLC] -> C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" -> [2008/12/06 04:57:20 | 00,114,840 | ---- | M] () Folder [open] -> %SystemRoot%\Explorer.exe /idlist,%I,%L -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) Folder [explore] -> %SystemRoot%\Explorer.exe /e,/idlist,%I,%L -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) Drive [find] -> %SystemRoot%\Explorer.exe -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) Applications\iexplore.exe [open] -> "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 -> [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -> "C:\Program Files\Internet Explorer\iexplore.exe" -> [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) < EventViewer Logs - Last 10 Errors > -> Event Information -> Description Application [ Error ] 10/3/2009 8:31:05 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description = Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied. Action Description: The file was left unchanged. Application [ Error ] 10/3/2009 10:01:18 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description = Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description: The file was left unchanged. Application [ Error ] 10/3/2009 10:01:18 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description = Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied. Action Description: The file was left unchanged. Application [ Error ] 10/3/2009 10:01:19 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description = Risk Found!Risk: Trojan.Vundo in File: c:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan. Action: Cleaned by Deletion. Action Description: Application [ Error ] 10/3/2009 10:01:26 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711731 -> Description = Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan. Action: Cleaned by Deletion. Action Description: Application [ Error ] 10/3/2009 10:01:57 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description = Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description: The file was left unchanged. Application [ Error ] 10/3/2009 10:02:38 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description = Risk Found!Risk: Trojan.Vundo in File: c:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan. Action: Cleaned by Deletion. Action Description: Application [ Error ] 10/3/2009 10:37:14 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description = Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description: The file was left unchanged. Application [ Error ] 10/3/2009 3:39:53 PM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description = Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\gatotafi.dll.tmp by: Auto-Protect scan. Action: Cleaned by Deletion. Action Description: Application [ Error ] 10/3/2009 3:39:53 PM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description = Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\gatotafi.dll.tmp by: Auto-Protect scan. Action: Cleaned by Deletion. Action Description: System [ Error ] 8/27/2009 1:27:18 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009 -> Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect. System [ Error ] 8/27/2009 1:27:18 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 -> Description = The TrueVector Internet Monitor service failed to start due to the following error: %%1053 System [ Error ] 8/30/2009 12:43:18 AM Computer Name = DESKTOP | Source = LDMS | ID = 16780230 -> Description = Unhandled exception, exception code=6B System [ Error ] 8/30/2009 1:19:10 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009 -> Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect. System [ Error ] 8/30/2009 1:19:10 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 -> Description = The TrueVector Internet Monitor service failed to start due to the following error: %%1053 System [ Error ] 8/30/2009 1:42:42 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009 -> Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect. System [ Error ] 8/30/2009 1:42:43 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 -> Description = The TrueVector Internet Monitor service failed to start due to the following error: %%1053 [Files/Folders - Created Within 30 Days] Application Data -> C:\Documents and Settings\All Users\Application Data -> [2009/10/03 10:17:48 | 00,000,000 | RH-D | M] {755AC846-7372-4AC8-8550-C52491DAA8BD} -> C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} -> [2009/09/09 19:25:47 | 00,000,000 | ---D | M] Microsoft Help -> C:\Documents and Settings\All Users\Application Data\Microsoft Help -> [2009/09/09 03:03:23 | 00,000,000 | ---D | M] Application Data -> C:\Documents and Settings\JD\Application Data -> [2009/10/03 10:17:48 | 00,000,000 | -H-D | M] Apple Computer -> C:\Documents and Settings\JD\Application Data\Apple Computer -> [2009/09/09 19:29:33 | 00,000,000 | ---D | M] DNA -> C:\Documents and Settings\JD\Application Data\DNA -> [2009/10/03 10:34:32 | 00,000,000 | ---D | M] U3 -> C:\Documents and Settings\JD\Application Data\U3 -> [2009/09/21 21:20:18 | 00,000,000 | ---D | M] Apple Computer -> C:\Documents and Settings\JD\Local Settings\Application Data\Apple Computer -> [2009/10/02 18:10:00 | 00,000,000 | ---D | M] ApplicationHistory -> C:\Documents and Settings\JD\Local Settings\Application Data\ApplicationHistory -> [2009/09/06 11:24:16 | 00,000,000 | ---D | M] Microsoft -> C:\Documents and Settings\JD\Local Settings\Application Data\Microsoft -> [2009/09/27 15:47:32 | 00,000,000 | ---D | M] Temp -> C:\Documents and Settings\JD\Local Settings\Application Data\Temp -> [2009/10/01 20:30:40 | 00,000,000 | ---D | M] Apple -> C:\Program Files\Common Files\Apple -> [2009/09/09 19:24:33 | 00,000,000 | ---D | M] Program Files -> C:\Program Files -> [2009/09/27 15:47:27 | 00,000,000 | ---D | M] CCleaner -> C:\Program Files\CCleaner -> [2009/09/27 13:02:28 | 00,000,000 | ---D | M] DNA -> C:\Program Files\DNA -> [2009/10/03 10:24:29 | 00,000,000 | ---D | M] ERUNT -> C:\Program Files\ERUNT -> [2009/09/27 14:19:37 | 00,000,000 | ---D | M] Google -> C:\Program Files\Google -> [2009/09/08 10:18:39 | 00,000,000 | ---D | M] iPhone Configuration Utility -> C:\Program Files\iPhone Configuration Utility -> [2009/09/10 18:05:18 | 00,000,000 | ---D | M] iPod -> C:\Program Files\iPod -> [2009/09/09 19:24:36 | 00,000,000 | ---D | M] iTunes -> C:\Program Files\iTunes -> [2009/09/09 19:25:47 | 00,000,000 | ---D | M] Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2009/09/18 18:37:54 | 00,000,000 | ---D | M] Microsoft Silverlight -> C:\Program Files\Microsoft Silverlight -> [2009/09/27 15:47:27 | 00,000,000 | ---D | M] Mozilla Firefox -> C:\Program Files\Mozilla Firefox -> [2009/10/03 10:29:08 | 00,000,000 | ---D | M] QuickTime -> C:\Program Files\QuickTime -> [2009/09/09 19:02:21 | 00,000,000 | ---D | M] Spybot - Search & Destroy -> C:\Program Files\Spybot - Search & Destroy -> [2009/09/19 14:33:40 | 00,000,000 | ---D | M] Symantec AntiVirus -> C:\Program Files\Symantec AntiVirus -> [2009/10/03 10:26:07 | 00,000,000 | ---D | M] OTS.exe -> C:\Documents and Settings\JD\Desktop\OTS.exe -> [2009/10/03 10:30:52 | 00,519,680 | ---- | C] (OldTimer Tools) ERDNT -> C:\WINDOWS\ERDNT -> [2009/09/27 14:20:19 | 00,000,000 | ---D | C] VundoFix Backups -> C:\VundoFix Backups -> [2009/09/27 13:10:24 | 00,000,000 | ---D | C] iexplore.exe -> C:\Documents and Settings\JD\Desktop\iexplore.exe -> [2009/09/27 11:24:43 | 03,550,592 | ---- | C] (Sysinternals - www.sysinternals.com) triedit.dll -> C:\WINDOWS\System32\dllcache\triedit.dll -> [2009/09/08 17:39:37 | 00,153,088 | ---- | C] (Microsoft Corporation) ATIDEMGR.dll -> C:\WINDOWS\System32\ATIDEMGR.dll -> [2006/02/21 19:21:36 | 00,192,512 | ---- | C] ( ) [Files/Folders - Modified Within 30 Days] 6 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> mehudebe -> C:\WINDOWS\System32\mehudebe -> [2009/10/03 10:42:56 | 00,011,168 | -H-- | M] () OTS.exe -> C:\Documents and Settings\JD\Desktop\OTS.exe -> [2009/10/03 10:31:02 | 00,519,680 | ---- | M] (OldTimer Tools) GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job -> [2009/10/03 10:30:05 | 00,000,966 | ---- | M] () vsconfig.xml -> C:\WINDOWS\System32\vsconfig.xml -> [2009/10/03 10:28:19 | 00,350,197 | -H-- | M] () wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2009/10/03 10:25:21 | 00,001,158 | ---- | M] () GoogleUpdateTaskMachineCore.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job -> [2009/10/03 10:22:16 | 00,000,882 | ---- | M] () SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2009/10/03 10:22:13 | 00,000,006 | -H-- | M] () bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2009/10/03 10:21:47 | 00,002,048 | --S- | M] () hiberfil.sys -> C:\hiberfil.sys -> [2009/10/03 10:21:41 | 16,099,45088 | -HS- | M] () ntuser.dat -> C:\Documents and Settings\JD\ntuser.dat -> [2009/10/03 10:20:18 | 12,582,912 | ---- | M] () ntuser.ini -> C:\Documents and Settings\JD\ntuser.ini -> [2009/10/03 10:20:13 | 00,000,278 | -HS- | M] () IconCache.db -> C:\Documents and Settings\JD\Local Settings\Application Data\IconCache.db -> [2009/10/03 10:19:42 | 09,206,992 | -H-- | M] () GoogleUpdateTaskMachineUA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job -> [2009/10/03 10:17:00 | 00,000,886 | ---- | M] () GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job -> [2009/10/03 09:30:01 | 00,000,914 | ---- | M] () wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll -> [2009/10/03 05:21:32 | 00,091,136 | ---- | M] () Incremental Backup.job -> C:\WINDOWS\tasks\Incremental Backup.job -> [2009/10/03 04:00:16 | 00,000,804 | ---- | M] () iTunes.lnk -> C:\Documents and Settings\All Users\Desktop\iTunes.lnk -> [2009/10/02 18:00:55 | 00,002,137 | ---- | M] () vokafifu.dll -> C:\WINDOWS\System32\vokafifu.dll -> [2009/10/02 17:22:21 | 00,037,888 | -HS- | M] () famatoge.dll -> C:\WINDOWS\System32\famatoge.dll -> [2009/10/02 17:22:20 | 00,027,136 | -HS- | M] () Google Chrome.lnk -> C:\Documents and Settings\JD\Desktop\Google Chrome.lnk -> [2009/10/01 20:30:52 | 00,002,272 | ---- | M] () wayolelu.dll -> C:\WINDOWS\System32\wayolelu.dll -> [2009/10/01 04:27:44 | 00,026,624 | -HS- | M] () QUICKEN.INI -> C:\WINDOWS\QUICKEN.INI -> [2009/09/28 19:27:22 | 00,000,221 | ---- | M] () Ad-Aware Update (Weekly).job -> C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job -> [2009/09/28 10:42:33 | 00,000,472 | ---- | M] () Full Backups.job -> C:\WINDOWS\tasks\Full Backups.job -> [2009/09/28 08:00:11 | 00,000,832 | ---- | M] () NTREGOPT.lnk -> C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk -> [2009/09/27 14:19:31 | 00,000,622 | ---- | M] () ERUNT.lnk -> C:\Documents and Settings\JD\Desktop\ERUNT.lnk -> [2009/09/27 14:19:31 | 00,000,603 | ---- | M] () CCleaner.lnk -> C:\Documents and Settings\JD\Desktop\CCleaner.lnk -> [2009/09/27 13:02:28 | 00,001,559 | ---- | M] () iexplore.exe -> C:\Documents and Settings\JD\Desktop\iexplore.exe -> [2009/09/27 11:24:48 | 03,550,592 | ---- | M] (Sysinternals - www.sysinternals.com) wininit.ini -> C:\WINDOWS\wininit.ini -> [2009/09/25 05:56:21 | 00,000,095 | ---- | M] () Media Backup Schedule.job -> C:\WINDOWS\tasks\Media Backup Schedule.job -> [2009/09/22 09:15:28 | 00,000,768 | ---- | M] () AppleSoftwareUpdate.job -> C:\WINDOWS\tasks\AppleSoftwareUpdate.job -> [2009/09/10 18:03:04 | 00,000,284 | ---- | M] () mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation) imsins.BAK -> C:\WINDOWS\imsins.BAK -> [2009/09/09 03:03:40 | 00,001,355 | ---- | M] () [Files - No Company Name] hiberfil.sys -> C:\hiberfil.sys -> [2009/09/27 17:57:55 | 16,099,45088 | -HS- | C] () NTREGOPT.lnk -> C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk -> [2009/09/27 14:19:31 | 00,000,622 | ---- | C] () ERUNT.lnk -> C:\Documents and Settings\JD\Desktop\ERUNT.lnk -> [2009/09/27 14:19:31 | 00,000,603 | ---- | C] () CCleaner.lnk -> C:\Documents and Settings\JD\Desktop\CCleaner.lnk -> [2009/09/27 13:02:28 | 00,001,559 | ---- | C] () wininit.ini -> C:\WINDOWS\wininit.ini -> [2009/09/25 05:56:21 | 00,000,095 | ---- | C] () iTunes.lnk -> C:\Documents and Settings\All Users\Desktop\iTunes.lnk -> [2009/09/09 19:26:13 | 00,002,137 | ---- | C] () Media Backup Schedule.job -> C:\WINDOWS\tasks\Media Backup Schedule.job -> [2009/09/06 11:18:13 | 00,000,768 | ---- | C] () wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll -> [2009/07/03 05:21:30 | 00,091,136 | ---- | C] () tehunevo.dll -> C:\WINDOWS\System32\tehunevo.dll -> [2009/07/02 17:22:59 | 00,052,224 | ---- | C] () fedoniko.dll -> C:\WINDOWS\System32\fedoniko.dll -> [2009/07/02 17:22:59 | 00,052,224 | ---- | C] () vokafifu.dll -> C:\WINDOWS\System32\vokafifu.dll -> [2009/07/02 17:22:20 | 00,037,888 | -HS- | C] () famatoge.dll -> C:\WINDOWS\System32\famatoge.dll -> [2009/07/02 17:22:19 | 00,027,136 | -HS- | C] () wayolelu.dll -> C:\WINDOWS\System32\wayolelu.dll -> [2009/07/01 04:27:43 | 00,026,624 | -HS- | C] () AviSplitter.INI -> C:\WINDOWS\AviSplitter.INI -> [2009/02/15 20:03:04 | 00,000,038 | ---- | C] () prgiso.dll -> C:\WINDOWS\System32\prgiso.dll -> [2008/07/02 02:43:02 | 00,247,560 | ---- | C] () lgfwup.ini -> C:\WINDOWS\lgfwup.ini -> [2008/04/20 14:10:51 | 00,000,359 | ---- | C] () ppsio2.sys -> C:\WINDOWS\System32\drivers\ppsio2.sys -> [2008/04/17 20:22:20 | 00,022,272 | ---- | C] () xfcodec.dll -> C:\WINDOWS\System32\xfcodec.dll -> [2008/01/30 16:03:26 | 00,054,608 | ---- | C] () hpqEmlSz.INI -> C:\WINDOWS\hpqEmlSz.INI -> [2007/12/01 16:12:22 | 00,000,000 | ---- | C] () idxcntrs.ini -> C:\WINDOWS\System32\idxcntrs.ini -> [2007/09/27 10:51:02 | 00,020,698 | ---- | C] () gsrvctr.ini -> C:\WINDOWS\System32\gsrvctr.ini -> [2007/09/27 10:48:48 | 00,030,628 | ---- | C] () gthrctr.ini -> C:\WINDOWS\System32\gthrctr.ini -> [2007/09/27 10:48:28 | 00,031,698 | ---- | C] () HP_48BitScanUpdatePatch.ini -> C:\WINDOWS\HP_48BitScanUpdatePatch.ini -> [2007/06/12 18:01:48 | 00,000,214 | ---- | C] () DragToDiscUserNameE.txt -> C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameE.txt -> [2006/11/12 15:58:20 | 00,000,002 | ---- | C] () patchw32.dll -> C:\WINDOWS\patchw32.dll -> [2006/10/30 20:41:08 | 00,205,312 | R--- | C] () pw32a.dll -> C:\WINDOWS\pw32a.dll -> [2006/10/30 20:39:51 | 00,205,312 | R--- | C] () libeay32.dll -> C:\WINDOWS\System32\libeay32.dll -> [2006/10/30 06:48:44 | 00,684,032 | ---- | C] () libeay32_0.9.6l.dll -> C:\WINDOWS\System32\libeay32_0.9.6l.dll -> [2006/07/15 09:18:29 | 00,796,584 | ---- | C] () vpc32.INI -> C:\WINDOWS\vpc32.INI -> [2006/04/04 21:27:39 | 00,000,000 | ---- | C] () PureEdgeAPI.ini -> C:\WINDOWS\PureEdgeAPI.ini -> [2006/01/05 10:18:52 | 00,000,061 | ---- | C] () MSQOLE.DLL -> C:\WINDOWS\System32\MSQOLE.DLL -> [2006/01/05 10:18:48 | 00,167,936 | ---- | C] () QTSBandwidthCache -> C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache -> [2005/12/25 13:25:16 | 00,001,778 | ---- | C] () maxlink.ini -> C:\WINDOWS\maxlink.ini -> [2005/12/18 15:51:14 | 00,001,018 | ---- | C] () calera.ini -> C:\WINDOWS\calera.ini -> [2005/12/18 15:51:14 | 00,000,091 | ---- | C] () FPXIG.DLL -> C:\WINDOWS\System32\FPXIG.DLL -> [2005/12/18 15:51:08 | 00,269,312 | ---- | C] () IGFPX32P.DLL -> C:\WINDOWS\System32\IGFPX32P.DLL -> [2005/12/18 15:51:08 | 00,068,096 | ---- | C] () JPEGACC.DLL -> C:\WINDOWS\System32\JPEGACC.DLL -> [2005/12/18 15:51:08 | 00,065,024 | ---- | C] () WELSOF32.DLL -> C:\WINDOWS\System32\WELSOF32.DLL -> [2005/12/18 15:51:00 | 00,101,376 | ---- | C] () TTSServer.dll -> C:\WINDOWS\System32\TTSServer.dll -> [2005/11/28 21:11:16 | 00,172,032 | ---- | C] () Setup32.INI -> C:\WINDOWS\Setup32.INI -> [2005/11/28 21:10:17 | 00,000,000 | ---- | C] () libeay32.dll -> C:\WINDOWS\libeay32.dll -> [2005/11/25 11:37:36 | 00,684,032 | ---- | C] () ssleay32.dll -> C:\WINDOWS\ssleay32.dll -> [2005/11/25 11:37:36 | 00,155,648 | ---- | C] () iPlayer.INI -> C:\WINDOWS\iPlayer.INI -> [2005/09/24 09:31:20 | 00,000,000 | ---- | C] () lvcoinst.ini -> C:\WINDOWS\System32\lvcoinst.ini -> [2005/08/21 11:52:08 | 00,009,255 | R--- | C] () IVIresizeW7.dll -> C:\WINDOWS\System32\IVIresizeW7.dll -> [2005/04/01 14:23:31 | 00,204,800 | ---- | C] () IVIresizePX.dll -> C:\WINDOWS\System32\IVIresizePX.dll -> [2005/04/01 14:23:31 | 00,188,416 | ---- | C] () IVIresizeA6.dll -> C:\WINDOWS\System32\IVIresizeA6.dll -> [2005/04/01 14:23:30 | 00,200,704 | ---- | C] () IVIresizeP6.dll -> C:\WINDOWS\System32\IVIresizeP6.dll -> [2005/04/01 14:23:30 | 00,192,512 | ---- | C] () IVIresizeM6.dll -> C:\WINDOWS\System32\IVIresizeM6.dll -> [2005/04/01 14:23:30 | 00,192,512 | ---- | C] () IVIresize.dll -> C:\WINDOWS\System32\IVIresize.dll -> [2005/04/01 14:23:30 | 00,020,480 | ---- | C] () PhotoSnapViewer.INI -> C:\WINDOWS\PhotoSnapViewer.INI -> [2005/03/10 17:05:17 | 00,000,151 | ---- | C] () PerWin.ini -> C:\WINDOWS\PerWin.ini -> [2005/01/15 08:19:22 | 00,000,048 | ---- | C] () NeroDigital.ini -> C:\WINDOWS\NeroDigital.ini -> [2004/12/30 12:32:25 | 00,000,116 | ---- | C] () WNASPI32.DLL -> C:\WINDOWS\System32\WNASPI32.DLL -> [2004/12/26 12:32:37 | 00,030,208 | ---- | C] () msfsetup.ini -> C:\WINDOWS\msfsetup.ini -> [2004/12/26 12:32:37 | 00,000,291 | ---- | C] () GDIPFONTCACHEV1.DAT -> C:\Documents and Settings\JD\Application Data\GDIPFONTCACHEV1.DAT -> [2004/12/05 17:02:20 | 00,087,720 | ---- | C] () cdPlayer.ini -> C:\WINDOWS\cdPlayer.ini -> [2004/10/02 03:10:23 | 00,001,844 | ---- | C] () tx11.dll -> C:\WINDOWS\System32\tx11.dll -> [2004/09/29 11:02:00 | 00,569,344 | ---- | C] () G-Force Prefs (WindowsMediaPlayer).txt -> C:\Documents and Settings\JD\Application Data\G-Force Prefs (WindowsMediaPlayer).txt -> [2004/09/05 02:24:00 | 00,000,187 | ---- | C] () DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\JD\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2004/09/04 14:13:24 | 00,053,248 | ---- | C] () encore_launcher.ini -> C:\WINDOWS\encore_launcher.ini -> [2004/09/04 10:34:39 | 00,000,080 | ---- | C] () Wh2Robo.dll -> C:\WINDOWS\System32\Wh2Robo.dll -> [2004/09/03 05:34:28 | 00,047,104 | ---- | C] () IMPLODE.DLL -> C:\WINDOWS\System32\IMPLODE.DLL -> [2004/08/31 12:40:46 | 00,017,920 | ---- | C] () GDIPFONTCACHEV1.DAT -> C:\Documents and Settings\JD\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2004/08/26 13:09:28 | 00,127,096 | ---- | C] () desktop.ini -> C:\Documents and Settings\JD\Application Data\desktop.ini -> [2004/08/23 17:35:17 | 00,000,062 | -HS- | C] () IconCache.db -> C:\Documents and Settings\JD\Local Settings\Application Data\IconCache.db -> [2004/08/23 17:35:13 | 09,206,992 | -H-- | C] () fusioncache.dat -> C:\Documents and Settings\JD\Local Settings\Application Data\fusioncache.dat -> [2004/08/23 17:35:13 | 00,000,125 | ---- | C] () imbrmute.ini -> C:\WINDOWS\System32\imbrmute.ini -> [2004/07/11 12:46:42 | 00,001,193 | ---- | C] () QHI.INI -> C:\WINDOWS\QHI.INI -> [2004/06/30 16:17:51 | 00,000,086 | ---- | C] () intuprof.ini -> C:\WINDOWS\intuprof.ini -> [2004/06/30 16:06:13 | 00,001,280 | ---- | C] () qwimp.ini -> C:\WINDOWS\qwimp.ini -> [2004/06/30 16:06:11 | 00,000,078 | ---- | C] () Acroread.ini -> C:\WINDOWS\Acroread.ini -> [2004/06/28 18:46:13 | 00,000,037 | ---- | C] () smscfg.ini -> C:\WINDOWS\smscfg.ini -> [2003/12/17 04:08:40 | 00,000,061 | ---- | C] () mshrml.ini -> C:\WINDOWS\System32\mshrml.ini -> [2003/12/17 03:29:26 | 00,000,051 | ---- | C] () JAWTAccessBridge.dll -> C:\WINDOWS\System32\JAWTAccessBridge.dll -> [2003/12/16 23:09:37 | 00,028,672 | ---- | C] () PcdrKernelModeServices.dll -> C:\WINDOWS\System32\PcdrKernelModeServices.dll -> [2003/12/16 23:09:02 | 00,094,208 | ---- | C] () ProgressTrace.dll -> C:\WINDOWS\System32\ProgressTrace.dll -> [2003/12/16 23:09:02 | 00,077,824 | ---- | C] () PCDrJNI_1_1.dll -> C:\WINDOWS\System32\PCDrJNI_1_1.dll -> [2003/12/16 23:04:11 | 00,167,936 | ---- | C] () CHODDI.SYS -> C:\WINDOWS\System32\CHODDI.SYS -> [2003/12/16 22:45:51 | 00,029,259 | ---- | C] () syscontr.dll -> C:\WINDOWS\System32\syscontr.dll -> [2003/12/16 22:45:28 | 00,024,576 | ---- | C] () hpreg.dll -> C:\WINDOWS\System32\hpreg.dll -> [2003/12/16 22:44:51 | 00,045,056 | ---- | C] () ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2003/12/16 22:39:03 | 00,000,376 | ---- | C] () QUICKEN.INI -> C:\WINDOWS\QUICKEN.INI -> [2003/12/16 22:24:09 | 00,000,221 | ---- | C] () hpzinstall.log -> C:\Documents and Settings\All Users\Application Data\hpzinstall.log -> [2003/12/16 21:10:11 | 00,012,254 | ---- | C] () fxsperf.ini -> C:\WINDOWS\System32\fxsperf.ini -> [2003/12/16 20:59:03 | 00,001,793 | ---- | C] () PythonCOM22.dll -> C:\WINDOWS\System32\PythonCOM22.dll -> [2003/12/16 20:09:08 | 00,299,073 | ---- | C] () PyWinTypes22.dll -> C:\WINDOWS\System32\PyWinTypes22.dll -> [2003/12/16 20:09:08 | 00,065,536 | ---- | C] () bcbmm.dll -> C:\WINDOWS\System32\bcbmm.dll -> [2003/12/16 20:08:44 | 00,016,896 | ---- | C] () orun32.ini -> C:\WINDOWS\orun32.ini -> [2003/12/16 19:50:41 | 00,000,813 | ---- | C] () oeminfo.ini -> C:\WINDOWS\System32\oeminfo.ini -> [2003/12/16 18:30:15 | 00,000,667 | ---- | C] () win.ini -> C:\WINDOWS\win.ini -> [2003/12/16 18:29:27 | 00,000,930 | ---- | C] () System.ini -> C:\WINDOWS\System.ini -> [2003/12/16 18:29:22 | 00,000,264 | ---- | C] () desktop.ini -> C:\Documents and Settings\All Users\Application Data\desktop.ini -> [2003/12/16 11:34:43 | 00,000,062 | -HS- | C] () ati2evxx(2).dll -> C:\WINDOWS\System32\ati2evxx(2).dll -> [2003/12/12 03:42:14 | 00,086,016 | ---- | C] () psisdecd.dll -> C:\WINDOWS\System32\psisdecd.dll -> [2003/11/12 08:54:00 | 00,363,520 | ---- | C] () px.ini -> C:\WINDOWS\System32\px.ini -> [2003/09/22 22:19:42 | 00,000,000 | ---- | C] () indounin.dll -> C:\WINDOWS\System32\indounin.dll -> [1999/01/27 13:39:06 | 00,065,024 | ---- | C] () Iyvu9_32.dll -> C:\WINDOWS\System32\Iyvu9_32.dll -> [1997/06/13 15:56:08 | 00,056,832 | ---- | C] () [File - Lop Check] [File - Purity Scan] [Alternate Data Streams] @Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:825D5945 < End of report > --------------------------------------------------------------------------------- Malwarebytes' Anti-Malware 1.41 Database version: 2902 Windows 5.1.2600 Service Pack 3 10/3/2009 9:33:18 PM mbam-log-2009-10-03 (21-33-18).txt Scan type: Full Scan (C:\|) Objects scanned: 404512 Time elapsed: 2 hour(s), 37 minute(s), 15 second(s) Memory Processes Infected: 1 Memory Modules Infected: 1 Registry Keys Infected: 1 Registry Values Infected: 5 Registry Data Items Infected: 3 Folders Infected: 2 Files Infected: 58 Memory Processes Infected: C:\Documents and Settings\JD\Application Data\5811403403\5811403403.exe (Rogue.SecurityTool) -> Unloaded process successfully. Memory Modules Infected: c:\WINDOWS\system32\yirumuno.dll (Trojan.Vundo.H) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{e2d0c46a-a1fb-4932-9e54-26d606df3b4d} (Trojan.Vundo.H) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wefowuwus (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{e2d0c46a-a1fb-4932-9e54-26d606df3b4d} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\kuninoref (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\5811403403 (Rogue.SecurityTool) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\8899869141 (Rogue.SecurityTool) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\yirumuno.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\yirumuno.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Documents and Settings\JD\Application Data\5811403403 (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Documents and Settings\JD\Application Data\8899869141 (Rogue.SecurityTool) -> Quarantined and deleted successfully. Files Infected: c:\WINDOWS\system32\yirumuno.dll (Trojan.Vundo.H) -> Delete on reboot. C:\Documents and Settings\JD\Application Data\5811403403\5811403403.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Documents and Settings\JD\Application Data\8899869141\8899869141.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP696\A0353559.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP696\A0353593.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP696\A0353594.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP696\A0353595.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0353658.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0353664.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0353706.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0355712.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0355713.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0355715.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP699\A0358807.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359804.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359805.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359806.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359807.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359808.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359813.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359814.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359815.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359816.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0360870.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0361966.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0361967.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0362003.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0362004.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP702\A0362050.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP702\A0362051.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP703\A0362178.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP703\A0362179.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP703\A0362180.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP703\A0362208.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362329.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362330.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362331.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362332.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362333.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362334.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362335.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362336.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362337.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362338.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362339.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362340.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362343.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\WINDOWS\system32\nunoloje.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\WINDOWS\system32\zibuyiri.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\_OTS\MovedFiles\10032009_172248\C_WINDOWS\System32\fedoniko.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\_OTS\MovedFiles\10032009_172248\C_WINDOWS\System32\tehunevo.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\_OTS\MovedFiles\10032009_172248\C_WINDOWS\System32\wobihasa.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\JD\Application Data\5811403403\5811403403.bat (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Documents and Settings\JD\Application Data\5811403403\5811403403.cfg (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Documents and Settings\JD\Application Data\8899869141\8899869141.bat (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Documents and Settings\JD\Application Data\8899869141\8899869141.cfg (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\WINDOWS\system32\biwifasi.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\gamuduhe.dll (Trojan.Vundo) -> Quarantined and deleted successfully. ------------------------------------------------------------------------------------ OTL logfile created on: 10/3/2009 9:51:04 PM - Run 2 OTL by OldTimer - Version 3.0.16.0 Folder = C:\Documents and Settings\JD\My Documents\JD's Downloads Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.50 Gb Total Physical Memory | 0.67 Gb Available Physical Memory | 44.39% Memory free 2.11 Gb Paging File | 1.47 Gb Available in Paging File | 69.87% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 180.00 Gb Total Space | 33.48 Gb Free Space | 18.60% Space Free | Partition Type: NTFS Drive D: | 6.29 Gb Total Space | 1.12 Gb Free Space | 17.85% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: DESKTOP Current User Name: JD Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Minimal Quick Scan ========== Processes (SafeList) ========== PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.) PRC - C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG) PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation) PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.) PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation) PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation) PRC - C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe (Google Inc.) PRC - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated) PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) PRC - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation) PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation) PRC - C:\WINDOWS\ehome\ehSched.exe (Microsoft Corporation) PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC) PRC - C:\WINDOWS\System32\GEARSec.exe (GEAR Software) PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.) PRC - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) PRC - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation) PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe () PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation) PRC - C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation) PRC - C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation) PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation) PRC - C:\HP\KBD\KBD.EXE (Hewlett-Packard Company) PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.) PRC - C:\Program Files\Multimedia Card Reader\shwicon2k.exe (Alcor Micro, Corp.) PRC - C:\WINDOWS\System32\hphmon05.exe (Hewlett-Packard) PRC - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company) PRC - C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe () PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation) PRC - C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe (Symantec Corporation) PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) PRC - C:\Program Files\Visioneer\PaperPort\FBDirect.exe (Visioneer Inc.) PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation) PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation) PRC - C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC) PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.) PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD) PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) PRC - C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) PRC - C:\WINDOWS\System32\LVComsX.exe (Logitech Inc.) PRC - C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD) PRC - C:\Documents and Settings\JD\My Documents\JD's Downloads\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (AdobeActiveFileMonitor7.0 [Auto | Running]) -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated) SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation) SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.) SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\System32\ati2sgag.exe () SRV - (Automatic LiveUpdate Scheduler [Auto | Running]) -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation) SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) SRV - (ccEvtMgr [Auto | Running]) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation) SRV - (ccSetMgr [Auto | Running]) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation) SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (DefWatch [Auto | Running]) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation) SRV - (ehSched [Auto | Running]) -- C:\WINDOWS\ehome\ehSched.exe (Microsoft Corporation) SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.) SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (FreeAgentGoNext Service [Auto | Running]) -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC) SRV - (GEARSecurity [Auto | Running]) -- C:\WINDOWS\System32\GEARSec.exe (GEAR Software) SRV - (getPlusHelper [On_Demand | Stopped]) -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.) SRV - (gupdate1c9827bbeb07656 [Auto | Stopped]) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.) SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google) SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (hpqcxs08 [On_Demand | Running]) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.) SRV - (hpqddsvc [Auto | Running]) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.) SRV - (HPSLPSVC [Auto | Running]) -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.) SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation) SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (InCDsrv [Auto | Running]) -- C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG) SRV - (IntuitUpdateService [Auto | Running]) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.) SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) SRV - (Lavasoft Ad-Aware Service [On_Demand | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft) SRV - (LiveUpdate [On_Demand | Stopped]) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation) SRV - (MSSQL$SQLEXPRESS [Auto | Running]) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) SRV - (MSSQLServerADHelper [Disabled | Stopped]) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation) SRV - (Net Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\System32\HPZinw12.dll (Hewlett-Packard) SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (Norton Ghost [Auto | Running]) -- C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation) SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation) SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\System32\HPZipm12.dll (Hewlett-Packard) SRV - (RichVideo [Auto | Running]) -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe () SRV - (SavRoam [On_Demand | Stopped]) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec) SRV - (SNDSrvc [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation) SRV - (SPBBCSvc [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation) SRV - (SQLBrowser [Auto | Running]) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) SRV - (SQLWriter [Auto | Running]) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) SRV - (Symantec AntiVirus [Auto | Running]) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation) SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation) SRV - (vsmon [Auto | Running]) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD) SRV - (WMDM PMSP Service [Auto | Running]) -- C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.google.com/" FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1 FF - prefs.js..extensions.enabledItems: 6 FF - prefs.js..extensions.enabledItems: 2 FF - prefs.js..extensions.enabledItems: 41 FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.96 FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5 FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.32.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1 FF - prefs.js..extensions.enabledItems: statusbar@toodledo.com:1.60 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3 FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/24 03:04:09 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2009/09/08 10:18:41 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/09 19:16:03 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/09/09 19:16:03 | 00,000,000 | ---D | M] [2008/06/18 18:29:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Extensions [2008/06/18 18:29:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/10/03 09:28:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions [2008/04/20 09:59:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{1AF3FC34-0725-4485-A939-6B40EB7CA96A} [2009/06/26 19:17:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009/05/02 11:19:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} [2009/08/16 20:53:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2009/03/20 17:12:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\statusbar@toodledo.com [2008/10/12 18:10:36 | 00,000,276 | ---- | M] () -- C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\searchplugins\search.xml [2009/10/03 09:28:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/09/09 19:16:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2007/12/11 19:32:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2009/09/09 19:15:53 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/09/09 19:15:53 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2008/03/19 19:23:20 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll [2008/09/03 14:11:24 | 00,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\mozilla firefox\plugins\npbittorrent.dll [2008/06/17 20:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll [2007/10/11 14:17:50 | 01,435,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll [2009/09/09 19:15:56 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2007/05/10 22:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2006/09/07 10:08:58 | 00,618,496 | ---- | M] (Pixami) -- C:\Program Files\mozilla firefox\plugins\NPPxIm.dll [2006/09/07 10:08:58 | 00,819,200 | ---- | M] (Pixami) -- C:\Program Files\mozilla firefox\plugins\NPPxPrn.dll [2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2007/12/25 00:02:38 | 00,024,673 | ---- | M] (Check Point Software Technologies Ltd.) -- C:\Program Files\mozilla firefox\plugins\NPZoneSB.dll [2009/08/07 12:44:18 | 00,030,400 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\mozilla firefox\plugins\np_gp.dll [2009/08/15 07:48:37 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/08/15 07:48:37 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/08/15 07:48:37 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/08/15 07:48:37 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/08/15 07:48:37 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/08/15 07:48:37 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2009/08/15 07:48:37 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (319151 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 10945 more lines... O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.) O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (no name) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - No CLSID value found. O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (no name) - {bffe81e7-ca83-45d4-893f-519c62f1bcfe} - File not found O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll (Google Inc.) O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.) O3 - HKLM\..\Toolbar: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company) O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found. O3 - HKCU\..\Toolbar\ShellBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.) O3 - HKCU\..\Toolbar\ShellBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company) O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company) O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.) O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.) O4 - HKLM..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe () O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) O4 - HKLM..\Run: [HP Component Manager] C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company) O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe (Hewlett-Packard) O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard) O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation) O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation) O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation) O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation) O4 - HKLM..\Run: [KBD] C:\HP\KBD\KBD.EXE (Hewlett-Packard Company) O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC) O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe () O4 - HKLM..\Run: [Norton Ghost 9.0] C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe (Symantec Corporation) O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [PP7600usb] C:\Program Files\Visioneer\PaperPort\FBDirect.exe (Visioneer Inc.) O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE () O4 - HKLM..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe (Alcor Micro, Corp.) O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation) O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD) O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKCU..\Run: [Startup Cop Pro Startup Launcher] C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe (Ziff-Davis Media, Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Zone Labs Security.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD) O4 - Startup: C:\Documents and Settings\JD\Start Menu\Programs\Startup\TempClean.bat () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0 O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O8 - Extra context menu item: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html () O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html () O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html () O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.) O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.) O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll (Google Inc.) O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html () O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html () O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html () O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html () O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html () O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html () O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: PokerTime.net Poker - {E28AB5C9-B58F-4512-AF80-29001BC5A29D} - C:\Program Files\PokerTimeGuestMPP\MPPoker.exe (Microgaming) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites) O15 - HKCU\..Trusted Domains: 69 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://activation.rr.com/install/download/tgctlcm.cab (Support.com Configuration Class) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object) O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} https://quicken.ehosts.net/netagent/objects/custappx3.CAB (eAssist NetAgent Customer ActiveX Control version 3) O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab (LSSupCtl Class) O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} http://asp.mathxl.com/wizmodules/testgen/i...GenXInstall.cab (TTestGenXInstallObject) O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine) O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://spaces.msn.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1231725258781 (MUWebControl Class) O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll (InstallHelper Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll (There Voice Trainer) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab (Pearson Installation Assistant 2) O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} http://download.zonelabs.com/bin/promotion...ctor/WebSWK.cab (WebSpyWareKiller Class) O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab (Anonymizer Anti-Spyware Scanner) O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} file://c:\Program Files\There\ThereClient\ThereLauncher.dll (There Launcher) O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse...pDownloader.cab (MsnMessengerSetupDownloadControl Class) O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} https://www-secure.symantec.com/techsupp/asa/SymAData.cab (ActiveDataInfo Class) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object) O16 - DPF: {D44C75D8-C827-473E-8F68-A77E42500782} http://www.samsphotoclub.com/upload/WebUploadClient.cab (Uploader Class) O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} http://asp.mathxl.com/books/_Players/EconPlayer.cab (Pearson MyEconLab Player Control) O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} http://216.249.24.60/code/iPIX-ImageWell-ipix.cab (iPIX Media Send Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.25.227.55 209.18.47.61 24.25.227.53 O18 - Protocol\Handler\bw+0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw+0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw-0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw00 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw00s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw-0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw10 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw10s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw20 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw20s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw30 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw30s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw40 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw40s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw50 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw50s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw60 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw60s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw70 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw70s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw80 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw80s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw90 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bw90s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwa0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwa0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwb0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwb0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwc0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwc0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwd0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwd0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwe0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwe0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwf0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwf0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwg0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwg0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwh0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwh0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwi0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwi0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwj0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwj0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwk0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwk0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwl0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwl0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwm0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwm0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwn0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwn0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwo0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwo0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwp0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwp0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwq0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwq0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwr0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwr0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bws0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bws0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwt0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwt0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwu0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwu0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwv0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwv0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bww0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bww0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwx0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwx0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwy0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwy0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwz0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\bwz0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\offline-8876480 {9EB19210-0033-48C0-94F0-164D35CB93DB} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. ) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (c:\windows\system32\) - C:\WINDOWS\System32 [2009/10/03 21:37:11 | 00,000,000 | ---D | M] O20 - AppInit_DLLs: (tehunevo.dll) - File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.) O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation) O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\System32\NavLogon.dll (Symantec Corporation) O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2003/12/16 19:45:52 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2001/07/28 06:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ] O32 - AutoRun File - [2002/09/11 03:02:32 | 00,000,045 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ] O33 - MountPoints2\{391dd251-46bc-11dd-b7f4-000ea6c3bfc8}\Shell\AutoRun\command - "" = .\Encryption Tool\MaxtorEncryption.exe O33 - MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\AutoRun\command - "" = F:\PortableRoboForm.exe -- File not found O33 - MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\RoboForm2Go\command - "" = F:\PortableRoboForm.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe () ========== Files/Folders - Created Within 14 Days ========== [2009/10/03 17:22:48 | 00,000,000 | ---D | C] -- C:\_OTS [2009/10/03 10:52:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\JD\Desktop\SysProt [2009/10/03 10:49:54 | 00,355,033 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\SysProt.zip [2009/10/03 10:30:52 | 00,519,680 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\JD\Desktop\OTS.exe [2009/09/27 17:57:55 | 16,099,45088 | -HS- | C] () -- C:\hiberfil.sys [2009/09/27 15:47:27 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2009/09/27 14:20:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2009/09/27 14:19:31 | 00,000,622 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk [2009/09/27 14:19:31 | 00,000,603 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\ERUNT.lnk [2009/09/27 14:19:29 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT [2009/09/27 13:10:24 | 00,000,000 | ---D | C] -- C:\VundoFix Backups [2009/09/27 13:02:28 | 00,001,559 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\CCleaner.lnk [2009/09/27 13:02:26 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner [2009/09/27 11:24:43 | 03,550,592 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\JD\Desktop\iexplore.exe [2009/09/25 05:56:21 | 00,000,095 | ---- | C] () -- C:\WINDOWS\wininit.ini ========== Files - Modified Within 14 Days ========== [2009/10/03 21:45:49 | 00,350,197 | -H-- | M] () -- C:\WINDOWS\System32\vsconfig.xml [2009/10/03 21:39:53 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/10/03 21:38:08 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2009/10/03 21:38:04 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/10/03 21:37:20 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/10/03 21:37:15 | 16,099,45088 | -HS- | M] () -- C:\hiberfil.sys [2009/10/03 21:30:00 | 00,000,966 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job [2009/10/03 21:17:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2009/10/03 17:30:08 | 00,011,168 | -H-- | M] () -- C:\WINDOWS\System32\mehudebe [2009/10/03 17:25:58 | 00,038,912 | -HS- | M] () -- C:\WINDOWS\System32\benugame.dll [2009/10/03 17:00:51 | 09,736,692 | -H-- | M] () -- C:\Documents and Settings\JD\Local Settings\Application Data\IconCache.db [2009/10/03 16:21:24 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk [2009/10/03 10:50:31 | 00,355,033 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\SysProt.zip [2009/10/03 10:31:02 | 00,519,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JD\Desktop\OTS.exe [2009/10/03 09:30:01 | 00,000,914 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job [2009/10/03 04:00:16 | 00,000,804 | ---- | M] () -- C:\WINDOWS\tasks\Incremental Backup.job [2009/10/01 20:30:52 | 00,002,272 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\Google Chrome.lnk [2009/09/28 19:27:22 | 00,000,221 | ---- | M] () -- C:\WINDOWS\QUICKEN.INI [2009/09/28 10:42:33 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2009/09/28 08:00:11 | 00,000,832 | ---- | M] () -- C:\WINDOWS\tasks\Full Backups.job [2009/09/27 14:19:31 | 00,000,622 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk [2009/09/27 14:19:31 | 00,000,603 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\ERUNT.lnk [2009/09/27 13:02:28 | 00,001,559 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\CCleaner.lnk [2009/09/27 11:24:48 | 03,550,592 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\JD\Desktop\iexplore.exe [2009/09/25 05:56:21 | 00,000,095 | ---- | M] () -- C:\WINDOWS\wininit.ini [2009/09/22 09:15:28 | 00,000,768 | ---- | M] () -- C:\WINDOWS\tasks\Media Backup Schedule.job ========== LOP Check ========== [2009/10/03 10:17:48 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data [2009/03/27 19:12:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3} [2009/02/03 23:42:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} [2009/09/09 19:25:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} [2009/01/25 10:40:14 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800} [2009/04/09 19:04:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} [2005/04/10 06:27:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{A695AD8D-651B-4C8A-91DF-51F853449A57} [2004/12/29 19:20:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ahead [2008/04/20 14:23:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink [2007/12/31 14:24:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink [2008/10/17 18:50:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData [2008/10/17 17:36:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet [2009/01/24 17:26:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intuit [2007/10/01 16:43:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier [2003/12/16 23:06:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive [2006/01/05 10:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PureEdge [2005/03/10 15:28:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm [2003/12/16 19:51:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI [2009/09/01 22:35:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate [2005/09/19 20:49:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Support.com [2008/10/13 08:54:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2007/12/30 22:23:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tenebril [2005/11/26 13:07:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia [2004/12/30 14:55:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems [2008/11/14 22:02:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint [2009/10/03 21:33:18 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\JD\Application Data [2007/12/31 15:31:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\2K Games [2007/12/30 22:11:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\AccurateRip [2004/12/29 19:49:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Ahead [2007/12/01 14:33:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Amazon [2009/01/17 16:22:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Any Video Converter [2004/12/29 16:44:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\ArcSoft [2009/08/02 20:43:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\BitTorrent [2007/12/28 15:35:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\BookmarkBridge [2004/11/14 11:07:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Common Files [2008/04/20 14:23:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\CyberLink [2009/10/03 21:53:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\DNA [2009/08/03 05:11:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\DVD Flick [2009/06/11 19:56:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\dvdcss [2004/11/02 15:30:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\EuroTalk [2005/08/21 11:48:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\FotoWire [2008/06/29 19:22:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\gtk-2.0 [2007/11/25 15:09:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\interMute [2004/09/10 15:48:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\InterVideo [2008/07/22 18:02:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Intuit [2009/02/07 20:01:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\IObit [2008/01/05 15:59:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\iPhoneRingToneMaker [2004/11/02 12:45:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\IsolatedStorage [2006/10/14 20:15:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\LaCie [2007/01/26 17:21:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Leadertech [2008/12/16 20:26:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\LimeWire [2005/12/22 12:17:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Microgaming [2004/08/24 14:37:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Motive [2005/08/27 06:44:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Musicmatch [2007/07/27 22:45:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\NGC_IKTS [2005/12/24 11:01:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\OLYMPUS [2009/01/16 09:56:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PC Magazine Utilities [2008/10/17 18:52:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1 [2006/05/28 08:05:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Premiere [2006/01/05 10:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PureEdge [2007/12/13 22:26:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Roxio [2003/12/16 23:23:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\SampleView [2004/12/05 13:02:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\spweng [2007/12/30 22:23:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Tenebril [2009/09/21 21:20:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\U3 [2004/12/30 15:27:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Ulead Systems [2008/11/14 22:03:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Viewpoint [2009/05/13 06:36:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Windows Desktop Search [2009/06/08 17:58:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Windows Search [2009/09/28 10:42:33 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job [2009/09/10 18:03:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job [2003/07/30 09:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini [2009/09/28 08:00:11 | 00,000,832 | ---- | M] () -- C:\WINDOWS\Tasks\Full Backups.job [2009/10/03 21:38:08 | 00,000,882 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [2009/10/03 21:17:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [2009/10/03 09:30:01 | 00,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job [2009/10/03 21:30:00 | 00,000,966 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job [2009/10/03 04:00:16 | 00,000,804 | ---- | M] () -- C:\WINDOWS\Tasks\Incremental Backup.job [2009/09/22 09:15:28 | 00,000,768 | ---- | M] () -- C:\WINDOWS\Tasks\Media Backup Schedule.job [2009/10/03 21:38:04 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:825D5945 < End of report > ----------------------------------------------------------------------------------- GMER 1.0.15.15125 - http://www.gmer.net Rootkit scan 2009-10-04 04:06:31 Windows 5.1.2600 Service Pack 3 Running: gmer.exe; Driver: C:\DOCUME~1\JD\LOCALS~1\Temp\kxldapow.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwConnectPort [0xAE928FC0] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateFile [0xAE925C80] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateKey [0xAE940170] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreatePort [0xAE929580] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateProcess [0xAE93D900] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0xAE93DB10] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateSection [0xAE941B10] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xAE929670] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteFile [0xAE926210] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteKey [0xAE9409F0] SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAEDD1CB0] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0xAE93D280] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwLoadKey [0xAE940F10] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xAE940F90] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenFile [0xAE926070] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenProcess [0xAE93F180] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenThread [0xAE93EF40] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRenameKey [0xAE9416F0] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwReplaceKey [0xAE941150] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xAE928BE0] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRestoreKey [0xAE941540] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0xAE929190] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xAE926440] SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAEDD1F10] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0xAE93E200] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwTerminateProcess [0xAE93E080] ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!ZwYieldExecution + 12E 804E4968 12 Bytes [80, 95, 92, AE, 00, D9, 93, ...] {ADC BYTE [EBP-0x26ff516e], 0x93; SCASB ; ADC BL, BL; XCHG EBX, EAX; SCASB } ? srescan.sys The system cannot find the file specified. ! ? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS The system cannot find the file specified. ! ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\SearchIndexer.exe[3556] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateFile] [AE946B30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtSetInformationFile] [AE9268D0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateFile] [AE926A80] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtCreateFile] [AE9265E0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtOpenFile] [AE926980] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) AttachedDevice \FileSystem\Ntfs \Ntfs PQV2i.sys (StorageCraft Volume Snap-Shot/StorageCraft) Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) Device pci.sys (NT Plug and Play PCI Enumerator/Microsoft Corporation) Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 PQV2i.sys (StorageCraft Volume Snap-Shot/StorageCraft) AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 PQV2i.sys (StorageCraft Volume Snap-Shot/StorageCraft) AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) Device atapi.sys (IDE/ATAPI Port Driver/Microsoft Corporation) Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) AttachedDevice \FileSystem\Fastfat \Fat InCDrec.SYS (InCD File System Recognizer/Nero AG) ---- EOF - GMER 1.0.15 ---- |
|
|
Oct 4 2009, 09:57 AM
Post
#6
|
|
![]() Trusted Helper Posts: 1,499 From: UK OS: XP |
Hello,
Can you post the latest OTS log file which you will find in the folder C:\_OTS\MovedFiles Please follow these steps. -- Step 1 -- Run OTL
-- Step 2 -- Run Malwarebytes' Anti-Malware.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly. |
|
|
Oct 4 2009, 01:30 PM
Post
#7
|
|
|
New Member ![]() Posts: 9 OS: XP |
hammerman,
MBAM found no malicious items. Here are the logs: All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bffe81e7-ca83-45d4-893f-519c62f1bcfe}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bffe81e7-ca83-45d4-893f-519c62f1bcfe}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\ not found. File F:\PortableRoboForm.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\ not found. File F:\PortableRoboForm.exe not found. C:\WINDOWS\System32\mehudebe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\benugame.dll C:\WINDOWS\System32\benugame.dll NOT unregistered. C:\WINDOWS\System32\benugame.dll moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs deleted successfully. ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes User: Aimee ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: JD File delete failed. C:\Documents and Settings\JD\Local Settings\Temp\~DF745D.tmp scheduled to be deleted on reboot. ->Temp folder emptied: 322336 bytes File delete failed. C:\Documents and Settings\JD\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 198389 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 46344735 bytes ->Google Chrome cache emptied: 6299941 bytes ->Apple Safari cache emptied: 0 bytes User: Kids User: Laptop User: LocalService File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. ->Temp folder emptied: 65748 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_944.dat scheduled to be deleted on reboot. ->Temp folder emptied: 16384 bytes File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes File delete failed. C:\WINDOWS\temp\ZLT04d24.TMP scheduled to be deleted on reboot. Windows Temp folder emptied: 23200 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 50.87 mb OTL by OldTimer - Version 3.0.16.0 log created on 10042009_084725 Files\Folders moved on Reboot... C:\Documents and Settings\JD\Local Settings\Temp\~DF745D.tmp moved successfully. File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_944.dat not found! C:\WINDOWS\temp\ZLT04d24.TMP moved successfully. Registry entries deleted on Reboot... ------------------------------------------------------------------------------- Malwarebytes' Anti-Malware 1.41 Database version: 2905 Windows 5.1.2600 Service Pack 3 10/4/2009 9:24:10 AM mbam-log-2009-10-04 (09-24-10).txt Scan type: Quick Scan Objects scanned: 140394 Time elapsed: 24 minute(s), 25 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
Oct 4 2009, 02:19 PM
Post
#8
|
|
![]() Trusted Helper Posts: 1,499 From: UK OS: XP |
Hello,
Please follow these steps and then give me an update on how your computer's running now. -- Step 1 -- Please download JavaRa to your desktop and unzip it to its own folder
-- Step 2 -- This scan may take a few hours to run but it's very thorough. Please do an online scan with Kaspersky WebScanner Click on Accept You will be promted to install an ActiveX component from Kaspersky, Click Yes.
Scan Mail Bases
|
|
|
Oct 5 2009, 09:47 AM
Post
#9
|
|
|
New Member ![]() Posts: 9 OS: XP |
hammerman,
I ran JavaRa and reinstalled the latest JRE without a problem. So far when I have attempted to run Kapersky WebScanner, I haven't managed to get all the way through to the scan. The database download was only about 50% complete after 12 hours and then I started to get script errors. I was using Firefox, and I plan to attempt the scan again today with Explorer while I'm at work. Besides the failed Kapersky scan, the computer seems to be behaving and I have not received any virus alerts. Just wanted to give you an update. I'll post again after the second try at running Kapersky. Thanks for your help. BuzzBoy22 |
|
|
Oct 5 2009, 10:05 AM
Post
#10
|
|
![]() Trusted Helper Posts: 1,499 From: UK OS: XP |
Thanks for letting me know.
If you continue to have problems, use this scanner instead. Please bear in mind that these scans can take a few hours to complete. Please click here to download AVP Tool by Kaspersky.
After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok. Then choose OK again then you are back to the main screen.
This post has been edited by hammerman: Oct 5 2009, 10:06 AM |
|
|
Oct 6 2009, 09:23 AM
Post
#11
|
|
|
New Member ![]() Posts: 9 OS: XP |
hammerman,
I was able to complete the scan on the second try. -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0: scan report Tuesday, October 6, 2009 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, October 06, 2009 04:43:36 Records in database: 2920392 -------------------------------------------------------------------------------- Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ G:\ H:\ I:\ J:\ L:\ Scan statistics: Objects scanned: 254426 Threats found: 28 Infected objects found: 70 Suspicious objects found: 4 Scan duration: 07:28:22 File name / Threat / Threats count C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Email-Worm.Win32.Mydoom.a 1 C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst Infected: Email-Worm.Win32.Mydoom.a 1 C:\Documents and Settings\Administrator\My Documents\Email\Main\Deleted Items.dbx Infected: Email-Worm.Win32.Mydoom.a 1 C:\Documents and Settings\Aimee\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 2 C:\Documents and Settings\Aimee\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Exploit.HTML.ObjData 1 C:\Documents and Settings\Aimee\My Documents\Email\Main\Deleted Items.dbx Infected: Email-Worm.Win32.Mydoom.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80000\48FAC461.VBN Infected: Exploit.SWF.Downloader.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80001\48FACA64.VBN Infected: not-a-virus:AdWare.Win32.BHO.dht 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0000\4B6D6202.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0001\4B6D64F8.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0002\4B6D65AB.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0003\4B6D65D3.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0004\4B6D65FB.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0005\4B6D6623.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0006\4B6D664D.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0007\4B6D6675.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0008\4B6D669B.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0009\4B6D66C3.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C400000\4D5733D3.VBN Infected: Trojan.Win32.FraudPack.grt 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C400001\4D5733EE.VBN Infected: Trojan.Win32.FraudPack.grt 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C400002\4D574038.VBN Infected: Trojan.Win32.FraudPack.grt 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C400003\4D574054.VBN Infected: Trojan-Downloader.Win32.Agent.ames 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0000\4D9CFB79.VBN Infected: Trojan-Downloader.Win32.Zlob.aahv 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0001\4D9CFBB6.VBN Infected: Trojan.Win32.Agent.aiar 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0002\4D9D0508.VBN Infected: Trojan-Downloader.Win32.Small.afpi 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0003\4D9D0D32.VBN Infected: Trojan-Downloader.Win32.Zlob.aaij 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0004\4D9D1567.VBN Infected: Trojan-Downloader.Win32.Zlob.aasq 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0005\4D9D1D6B.VBN Infected: Trojan-Downloader.Win32.Zlob.aahr 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0006\4D9D2419.VBN Infected: Trojan.Win32.Agent.agyx 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0007\4D9D2A27.VBN Infected: Hoax.Win32.Agent.ge 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D140000\4DB7E4AC.VBN Infected: Trojan-Downloader.Win32.Small.abfp 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DC00000\4DF2BCD2.VBN Infected: Trojan-Dropper.Win32.KGen.gjp 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DD40001\4DDF68E7.VBN Infected: Trojan-Downloader.Win32.Injecter.ahh 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EB40000\4FF7DB72.VBN Infected: P2P-Worm.Win32.Nugg.w 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EB40001\4FF7DB8D.VBN Infected: P2P-Worm.Win32.Nugg.w 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EB40002\4FFC9E5D.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EB40003\4FFCA5F6.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EC00000\4FFB328A.VBN Infected: Trojan-Downloader.Win32.FraudLoad.vdck 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0ED80000\4EFCA90D.VBN Infected: Trojan-Downloader.Win32.Zlob.bxi 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080000.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080001.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080002.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080003.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080004.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080005.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080006.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080007.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080008.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080009.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000A.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000B.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000C.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000D.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000E.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000F.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080010.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080013.VBN Infected: Trojan-Downloader.Win32.Small.abax 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F180000.VBN Infected: Trojan-Downloader.Win32.FraudLoad.wbru 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F300002\4FF7A889.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.balk 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F300003\4FF7A8BD.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.balk 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F300005\4FF7A92E.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.balk 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F300006\4FF7A974.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.balk 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10900000\59FC5426.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10900001\59FC55AE.VBN Infected: Packed.Win32.Krap.p 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10E80000\58EA35DF.VBN Infected: Trojan-Downloader.Win32.Small.abfp 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13A00000\5BE835E9.VBN Infected: Trojan.Win32.Monder.bzea 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\1CB00000.VBN Infected: not-a-virus:PSWTool.Win32.Dialupass.dp 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\1CB00001.VBN Infected: not-a-virus:PSWTool.Win32.Dialupass.dp 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\1CB00002.VBN Infected: not-a-virus:PSWTool.Win32.Dialupass.dp 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\1CB00003.VBN Infected: not-a-virus:PSWTool.Win32.Dialupass.dp 1 C:\Documents and Settings\Laptop\Aimee\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 2 C:\Documents and Settings\Laptop\Aimee\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Exploit.HTML.ObjData 1 Selected area has been scanned. |
|
|
Oct 6 2009, 11:15 AM
Post
#12
|
|
![]() Trusted Helper Posts: 1,499 From: UK OS: XP |
Hello,
You have some infected e-mail messages in Outlook so you may want to remove any e-mails with suspicious attachments and empty your deleted items folder. Apart from that, your computer appears clean Let's remove the tools we've been using. Please follow these steps. -- Step 1 --
-- Step 2 -- Your backup files in the System Restore points may be infected and need to be cleared. The only way to do this is to turn off System Restore and then turn it back on again. This will delete all your backup files in the System Restore points, including any that are infected. You can then create a new restore point containing your clean files. Please follow these instructions.
Here are some measures you can take to ensure that your computer remains clean. 1. Updates Windows Updates It is essential that you regularly check and install the latest Windows Updates. Vulnerabilities within Windows can leave your computer open to infection. Regular updates are released to fix these security vulnerabilities. It is recommended that you set Windows to check, download and install your updates automatically.
As with Windows, Java also needs to be regularly updated to fix security vulnerabilites. You can download the latest version of the Java Runtime Environment (JRE) from here. Download, install and reboot your computer. You also need to uininstall older versions of Java.
Your Adobe reader needs updating. You should ensure you use the latest Adobe Acrobat Reader and install any security updates that are released. You can download the latest reader and updates from here. Other Updates Regularly check for updates for all your security programs including firewall, antivirus, antispyware etc 2. Security Programs Here is a list of security programs that I would recommend. Firewall A firewall is essential to stop hackers infiltrating your computer. The following firewalls are free for personal use. Do not install more than one firewall. Zone Alarm is an excellent free basic firewall which is very easy to use. Online-Armor Free is a more advanced firewall which includes a Host Intrusion Protection System (HIPS). This ensures that unrecognised programs will not run unless you give permission. Antivirus An antivirus program is essential. The following antivirus programs are free for personal use. Do not use more than one antivirus and always update virus definitions regularly. AVG Avira Free Avast Anti-Malware Malwarebytes Anti-Malware MBAM is an excellent anti-malware tool that should be updated and a Quick Scan performed regularly. A Full Scan does not have to be carried out on such a regular basis as the developers aim to detect the vast majority of malware with the Quick Scan. The scanner is free for on-demand scans only. Ad-Aware, Spybot, SuperAntispyware and A-Squared Free are also very good anti-malware programs that are free for on-demand scans. Spybot has a real-time protection feature called TeaTimer. Prevention SpywareBlaster is an excellent free tool for preventing the installation of spyware. SpywareGuard offers real-time protection so that spyware is detected and blocked before it can do any harm. Cleaner ATF Cleaner removes temporary Internet Explorer, Firefox and Windows files. Browser Firefox is an alternative browser to Internet Explorer and is more secure. NoScript is an add-on for Firefox and prevents execution of malicious scripts. MVPS is a HOSTS file to replace your existing file. This prevents you connecting to a list of well-known ad sites. |
|
|
Oct 6 2009, 03:16 PM
Post
#13
|
|
|
New Member ![]() Posts: 9 OS: XP |
hammerman,
Thanks a million for helping me out of this mess... you're my hero. Before we close this post, I have a couple of quick questions I hope you can help me with. Is there a way to determine which email messages are infected? As you know, I've been using Symantec AntiVirus. In your experience, is this a program you would stick with, or would you switch to AVG or one of the other programs in your post? Thanks again, BuzzBoy22 |
|
|
Oct 7 2009, 07:03 AM
Post
#14
|
|
![]() Trusted Helper Posts: 1,499 From: UK OS: XP |
Hello,
QUOTE Is there a way to determine which email messages are infected? I'm afraid not. The files contain all your emails. QUOTE As you know, I've been using Symantec AntiVirus. In your experience, is this a program you would stick with, or would you switch to AVG or one of the other programs in your post? I would recommend Avira antivirus. |
|
|
Oct 7 2009, 09:45 AM
Post
#15
|
|
|
New Member ![]() Posts: 9 OS: XP |
hammerman,
Thanks again for your help. My computer is running well with no sign of the virus. BuzzBoy22 |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
15 / 1,004 | 15th January 2008 - 12:49 PM OMGkorea started - last by Essexboy |
|||||
![]() |
19 / 1,330 | 17th December 2008 - 09:05 AM waiwai started - last by Gravity Gripp |
|||||
![]() |
11 / 341 | 2nd May 2009 - 01:52 AM Cougar1966 started - last by fenzodahl512 |
|||||
![]() |
14 / 613 | 26th September 2009 - 06:55 AM little_angel started - last by Essexboy |
|||||
|
Time is now: 20th November 2009 - 08:53 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising