Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
Suspected malware or spyware slowing computer down, HJT, Rooter and Malware Logs are pasted in body
Cowboylady
post Jun 24 2009, 12:38 AM
Post #1


New Member
*
Posts: 6
From: Byron, GA
OS: Windows XP SP3



I am appending to the bottom of this my two(2)OTL logs

I realize that I have alot of files that I do not know whether they should be running at most times or not. I am not able to tell which are valid files or add-ons and programs that I have picked up over the last few years. Please help me decipher some of these things. I have followed the instructions for malware removal per the instructions prior to posting...

Thanks so much for a reply when you can as my computer is freezing and takes a while to shut down and/or start up.

Logfile of Trend Micro HijackThis v2.0.2[/size]
Scan saved at 1:52:42 AM, on 6/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\program files\aol\aol toolbar 5.0\AolTbServer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\SYSTEM32\notepad.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn8\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn8\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: MySpace Toolbar - {28AED1AF-B164-44CD-B435-CF04AA955015} - C:\Program Files\MySpace\Toolbar\1.0.45.0\MySpaceToolbar.dll
O2 - BHO: AOL Radio Toolbar Loader - {2abdb2f7-4cbf-4939-ba12-fddc827b6a2d} - C:\Program Files\AOL Radio Toolbar\aolradiotb.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn8\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn8\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll
O3 - Toolbar: AOL Radio Toolbar - {9167da98-6f9b-46f1-991d-826cae46cab6} - C:\Program Files\AOL Radio Toolbar\aolradiotb.dll
O3 - Toolbar: MySpace Toolbar - {28AED1AF-B164-44CD-B435-CF04AA955015} - C:\Program Files\MySpace\Toolbar\1.0.45.0\MySpaceToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe" /hideme
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YahooWidgetEngine.exe] C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - HKUS\S-1-5-18\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0a\AOL.EXE" -b (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [VF0560Inst] RunDll32.exe C:\WINDOWS\system32\V0560Pin.dll,RunDLL32EP 515 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0a\AOL.EXE" -b (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [VF0560Inst] RunDll32.exe C:\WINDOWS\system32\V0560Pin.dll,RunDLL32EP 515 (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O8 - Extra context menu item: &AOL Radio Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL Radio Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200707...ex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1175811264578
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {885BB46A-3F1E-44C3-A01B-A7D9260CC98B} (InstallShield Update Service Setup Player) - http://updates.installshield.com/CAB/dwusplay.cab
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-tri...tg.1.0.0.33.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://rockyou.com/RockYouImageUploader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in...l/installer.exe
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes....cab?v=1,0,0,38
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2...15106/CTPID.cab
O16 - DPF: {FA945BB6-9D37-43FC-9B2A-AF09F56CBBF0} (moDiagCollectionActiveX Object) - http://yme.music.yahoo.com/qos/cabs/DiagCo...tionControl.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers...ivex-latest.cab
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate1c995062274baac) (gupdate1c995062274baac) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS360service - Unknown owner - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe

--
End of file - 16414 bytes

ph34r.gif
Rooter log
Rooter.exe (v1.0.1) by Eric_71
¨
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
32_bits - x86 Family 15 Model 2 Stepping 9, GenuineIntel
¨
C:\ [Fixed-NTFS] .. ( Total:74 Go - Free:39 Go )
D:\ [CD_Rom]
¨
Scan : 02:10.24
Path : C:\Documents and Settings\CHRISTINA\Local Settings\Temporary Internet Files\Content.IE5\1B3MVTWP\Rooter[1].exe
User : CHRISTINA ( Administrator -> YES )
¨
----------------------\\ Processes
¨
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (740)
______ \??\C:\WINDOWS\system32\csrss.exe (812)
______ \??\C:\WINDOWS\system32\winlogon.exe (836)
______ C:\WINDOWS\system32\services.exe (880)
______ C:\WINDOWS\system32\lsass.exe (892)
______ C:\WINDOWS\system32\svchost.exe (1052)
______ C:\WINDOWS\system32\svchost.exe (1132)
______ C:\Program Files\Windows Defender\MsMpEng.exe (1172)
______ C:\WINDOWS\System32\svchost.exe (1212)
______ C:\WINDOWS\system32\svchost.exe (1248)
______ C:\WINDOWS\System32\svchost.exe (1380)
______ C:\WINDOWS\system32\LEXBCES.EXE (1552)
______ C:\WINDOWS\system32\spoolsv.exe (1576)
______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (1632)
______ C:\WINDOWS\system32\LEXPPS.EXE (1644)
______ C:\Program Files\Bonjour\mDNSResponder.exe (1672)
______ C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (1796)
______ C:\Program Files\Java\jre6\bin\jqs.exe (1828)
______ C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (1860)
______ C:\Program Files\Common Files\Motive\McciCMService.exe (1884)
______ C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe (1936)
______ c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe (1988)
______ c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (2024)
______ C:\Program Files\Google\Update\GoogleUpdate.exe (2036)
______ C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (236)
______ C:\Program Files\McAfee\MPF\MPFSrv.exe (432)
______ C:\Program Files\McAfee\MSK\MskSrver.exe (536)
______ C:\WINDOWS\system32\PSIService.exe (592)
______ C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (640)
______ C:\WINDOWS\System32\tcpsvcs.exe (808)
______ C:\WINDOWS\System32\snmp.exe (816)
______ C:\WINDOWS\System32\svchost.exe (1068)
______ C:\WINDOWS\system32\SearchIndexer.exe (1452)
______ C:\WINDOWS\system32\fxssvc.exe (2152)
______ C:\WINDOWS\System32\svchost.exe (2708)
______ C:\WINDOWS\System32\alg.exe (2752)
______ C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (3264)
______ c:\PROGRA~1\mcafee.com\agent\mcagent.exe (3700)
______ C:\WINDOWS\Explorer.EXE (3920)
______ C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe (520)
______ C:\WINDOWS\system32\ctfmon.exe (600)
______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (2220)
______ C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (2804)
______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (412)
______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (204)
______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (1724)
______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (2924)
______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (2056)
______ C:\WINDOWS\System32\svchost.exe (3928)
______ C:\Program Files\Internet Explorer\IEXPLORE.EXE (3160)
______ C:\Program Files\Internet Explorer\IEXPLORE.EXE (3144)
______ c:\program files\aol\aol toolbar 5.0\AolTbServer.exe (3332)
______ C:\WINDOWS\system32\rundll32.exe (1156)
______ C:\Program Files\Windows Defender\MpCmdRun.exe (1948)
______ C:\Program Files\Internet Explorer\IEXPLORE.EXE (3608)
______ C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (3784)
______ C:\Documents and Settings\CHRISTINA\Local Settings\Temporary Internet Files\Content.IE5\1B3MVTWP\Rooter[1].exe (3896)
¨
----------------------\\ Device\Harddisk0\
¨
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
¨
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:32868864)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:32901120 | Length:79957946880)
¨
----------------------\\ Scheduled Tasks
¨
C:\WINDOWS\Tasks\DESKTOP.INI
C:\WINDOWS\Tasks\Google Software Updater.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
C:\WINDOWS\Tasks\McDefragTask.job
C:\WINDOWS\Tasks\McQcTask.job
C:\WINDOWS\Tasks\MP Scheduled Scan.job
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Tasks\User_Feed_Synchronization-{5DBDA0A7-2B36-4C06-A598-91EEF296D77A}.job
¨
----------------------\\ Registry
¨
¨
----------------------\\ Files & Folders
¨
----------------------\\ Scan completed at 02:13.40
¨
C:\Rooter$\Rooter_1.txt - (24/06/2009 | 02:13.40)
¨
C:\Rooter$\Rooter_2.txt - (24/06/2009 | 02:18.19)

Malwarebytes' Anti-Malware 1.38[size="2"]
Database version: 2327
Windows 5.1.2600 Service Pack 3

6/24/2009 2:28:35 AM
mbam-log-2009-06-24 (02-28-35).txt

Scan type: Quick Scan
Objects scanned: 108641
Time elapsed: 20 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security

Center\AntiVirusDisableNotify (Disabled.SecurityCenter) ->

Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security

Center\FirewallDisableNotify (Disabled.SecurityCenter) ->

Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security

Center\UpdatesDisableNotify (Disabled.SecurityCenter) ->

Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



OTL Extras.txt
OTL Extras logfile created on: 6/24/2009 2:46:12 AM - Run 1
OTL by OldTimer - Version 3.0.5.2 Folder = C:\Documents and Settings\CHRISTINA\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1021.98 Mb Total Physical Memory | 201.56 Mb Available Physical Memory | 19.72% Memory free
1.66 Gb Paging File | 0.99 Gb Available in Paging File | 59.56% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 39.90 Gb Free Space | 53.58% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STRAWBOSS
Current User Name: CHRISTINA
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 File not found
C:\Program Files\AOL 9.0a\waol.exe:*:Enabled:AOL 9.0a File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console (Microsoft Corporation)
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\SoundSpectrum\G-Force\G-Force V-Bar.exe:*:Enabled:G-Force V-Bar ()
C:\WINDOWS\SYSTEM32\ControlSuite.exe:*:Enabled:Broadcom Advanced Control Suite (Broadcom Corporation)
C:\Program Files\SoundSpectrum\G-Force\G-Force Standalone.exe:*:Enabled:G-Force Standalone ()
C:\Program Files\SoundSpectrum\G-Force\G-Force Toolbar.exe:*:Enabled:G-Force Toolbar ()
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe:*:Enabled:Yahoo! Widgets (Yahoo! Inc.)
C:\Program Files\Sonic\RecordNow!\RecordNow.exe:*:Enabled:RecordNow! ()
C:\Program Files\Intel\NCS\PROSet\PROSet.exe:*:Disabled:Intel® PROSet (Intel® Corporation)
C:\WINDOWS\SYSTEM32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE (Lexmark International, Inc.)
C:\Program Files\Intuit\QuickBooks 2007\QBDBMgrN.exe:*:Enabled:QuickBooks 2007 Data Manager (iAnywhere Solutions, Inc.)
C:\WINDOWS\SYSTEM32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test (Microsoft Corporation)
C:\Program Files\InterActual\InterActual Player\iPlayer.exe:*:Disabled:InterActual Player (Sonic Solutions)
C:\WINDOWS\network diagnostic\xpnetdiag.exe:*:Enabled:Network Diagnostic for Windows XP (Microsoft Corporation)
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)
C:\Program Files\Yahoo! Games\Bejeweled 2 Deluxe\WinBej2.exe:*:Enabled:Bejeweled2 (PopCap.com)
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook (Microsoft Corporation)
C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Intuit\QuickBooks 2009\QBDBMgrN.exe:*:Enabled:QuickBooks 2009 Data Manager (Intuit, Inc.)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax (Intuit, Inc.)
C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager (Intuit, Inc.)
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent (McAfee, Inc.)
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server (Intuit Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\Rhapsody\WiseUpd2.exe:*:Enabled:Check For Rhapsody Update ()
C:\Program Files\Flickr Uploadr\Flickr Uploadr.exe:*:Enabled:Flickr Uploadr (Yahoo! Inc.)
C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox (Mozilla Corporation)
C:\Program Files\Intuit\QuickBooks 2009\QBW32SimplestartLimited.exe:*:Enabled:QuickBooks Simple Start 2009 (Intuit Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{83FBD495-DDF6-4C8D-92D6-10261DD6F6A3}" = WordPerfect Office X3
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{43FCA273-9534-40DB-B7C5-D7758875616A}" = Dell Support
"{4468EF97-A253-4699-9E1C-88CAE2C6832D}" = ABBYY FineReader 5.0 Sprint
"{44A91B04-3D0C-47F9-B644-7F682869AFF3}" = MobileMe Control Panel
"{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = BACS
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{52C8FAA0-68CA-4AF9-8A7A-92CF3174CC77}" = Windows Media Player 9 Series Winter Fun Pack
"{52D56C42-8C69-4882-A661-39695537C9CF}" = DellConnect
"{548EEA8E-8299-497F-8057-811D2D7097DC}" = Dell Support 3.1
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5D50644B-310A-4C1B-B2DD-B8E781ADC430}" = WordPerfect MAIL
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6CF08AD2-00C5-4A63-B74B-2EFFFAFEBE1A}" = Microsoft Outlook Web Access S/MIME
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72B688ED-88AC-43D5-8A7A-A88D67CBA762}" = Catella4
"{737D7CA8-D05C-46C7-AFED-A76616E8CA3B}" = WordPerfect OfficeReady
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{7838752C-A838-4C73-849C-625C6114AF0C}" = SRS Audio Sandbox
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7E545666-F420-45FD-B3DF-C0B99A1A579F}" = QuickBooks Simple Start Edition
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{83FBD495-DDF6-4C8D-92D6-10261DD6F6A3}" = WordPerfect Office X3
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Client for Internet Explorer 1.03.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUSR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUSR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUSR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUSR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUSR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91208A47-5D08-4C79-986F-1931940F51BB}" = QuickBooks Product Listing Service
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{9A2F0810-3619-4E86-9072-973FBE1679C5}" = QuickBooks Simple Start 2009
"{9A2F0810-3622-4E86-9072-973FBE1679C5}" = QuickBooks Pro 2009
"{9A2F0810-369F-4E86-9072-973FBE1679C5}" = QuickBooks
"{9B79DCB0-AAD7-456B-8D07-433C936FA24B}" = DS21Patch
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6A13E30-656F-4876-9B03-FBD4D712BB40}" = Wal-Mart Music Downloads Store
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.5
"{AC76BA86-7AD7-1033-7B44-A81300000003}_814" = KB408682
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B535B621-5559-11DE-A7A1-005056806466}" = Google Earth Plugin
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CDEFD989-469E-421D-A8B1-EC7AB25C8CB2}" = TurboTax 2008 wgaiper
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D01653EF-9F9F-41D6-B879-654A6BF5892C}" = Digital Locker Assistant
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{D5F881C2-B134-474E-AA60-B25DD218AE0D}" = Crash Analysis Tool
"{D90AFDE3-3E67-407A-ACA8-F0BAAD012F08}" = Safari
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"3DGroove" = OTOY
"7-Zip" = 7-Zip 4.56 beta
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"ALLTEL.MCCInstall" = Windstream Broadband Check-up Center
"AOL Radio Toolbar" = AOL Radio Toolbar
"AOL Toolbar" = AOL Toolbar 5.0
"audcle" = Plus! MP3 Audio Converter LE
"AudioBurst" = AudioBurst FX Engine
"Audit Support Center" = Audit Support Center 1.0
"Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0
"Citrix ICA Web Client" = MetaFrame Presentation Server Web Client for Win32
"CNXT_MODEM_PCI_VEN_14F1&DEV_2702" = Conexant SmartHSFi V.9x 56K DF PCI Modem
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Creative VF0560" = Creative Live! Cam Optia AF (VF0560) Driver (1.00.06.00)
"Dell AIO Printer A940" = Dell AIO Printer A940
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Diner Dash" = Diner Dash
"ERUNT_is1" = ERUNT 1.1j
"Fair-Sound Audio DSP Plug-ins for Windows Media Player 9_is1" = Fair-Sound 2.0 for Windows Media Player 9
"Flickr Uploadr" = Flickr Uploadr 2.5.0.14
"GalleryPlayer Images" = GalleryPlayer Images
"G-Force" = G-Force
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Imikimi Plugin" = Imikimi Plugin
"InstallShield_{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = Broadcom Advanced Control Suite
"InterActual Player" = InterActual Player
"IObit Security 360_is1" = IObit Security 360 Beta 1.1
"LimeWire" = LimeWire 5.1.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"mmmusic" = Movie Maker Background Music Files
"mmsounds" = Movie Maker Sound Effects
"mmtitle" = Movie Maker Title Images
"Mozilla Firefox (3.0.5)" = Mozilla Firefox (3.0.5)
"mplibwiz.inf" = Media Library Management Wizard
"mpxlswiz.inf" = Windows Media Player Playlist Import to Excel Wizard
"mpxptray.inf" = Windows Media Player Tray Control
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MySpaceIM" = MySpaceIM
"MySpaceToolbar" = MySpace Toolbar
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROPLUSR" = Microsoft Office Professional Plus 2007
"PROSet" = Intel® PRO Network Connections Drivers
"R4" = R4
"Rhapsody" = Rhapsody
"Shockwave" = Shockwave
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SysInfo" = Creative System Information
"TBSB07183.TBSB07183Toolbar" = Fast Browser Search (My Web Tattoo)
"TurboTax 2008" = TurboTax 2008
"TurboTax Home & Business 2007" = TurboTax Home & Business 2007
"UnixUtils for Yahoo! Widgets" = Unix Utilities for Yahoo! Widgets
"Virtools3DLifePlayer" = Virtools 3D Life Player
"wa2wmp" = Windows Media Player Skin Importer
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Winamp Essentials Pack" = Winamp Essentials Pack v5.34
"Winamp Toolbar" = Winamp Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.6
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! IE Suggest" = Yahoo! IE Search Suggest
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Photos Drag-Drop Uploader 1v7" = Yahoo! Photos Easy Upload Tool 1v7
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Widget Engine" = Yahoo! Widgets
"YInstHelper" = Yahoo! Install Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/2/2009 12:09:04 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 4/2/2009 12:09:04 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 4/2/2009 12:09:04 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 4/2/2009 12:09:04 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 4/2/2009 12:33:59 PM | Computer Name = STRAWBOSS | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module urlmon.dll, version 8.0.6001.18702, fault address 0x0003e819.

Error - 4/2/2009 10:51:39 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 4/2/2009 10:51:39 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 4/2/2009 10:51:39 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 4/2/2009 10:51:39 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 4/2/2009 11:03:42 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks Pro 2009": tlg file
removal failed because the file was still ope

[ OSession Events ]
Error - 5/13/2009 3:12:27 PM | Computer Name = STRAWBOSS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 21
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/13/2009 3:13:21 PM | Computer Name = STRAWBOSS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 19
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/2/2009 8:17:13 PM | Computer Name = STRAWBOSS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/2/2009 8:17:30 PM | Computer Name = STRAWBOSS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 15
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 6/23/2009 3:28:21 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 6/23/2009 3:37:37 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 6/23/2009 3:40:54 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7034
Description = The QBCFMonitorService service terminated unexpectedly. It has done
this 1 time(s).

Error - 6/23/2009 3:41:10 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 2 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 6/23/2009 3:41:46 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7034
Description = The Intuit Update Service service terminated unexpectedly. It has
done this 1 time(s).

Error - 6/23/2009 3:42:18 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 3 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 6/23/2009 3:43:44 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 4 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 6/23/2009 10:24:23 PM | Computer Name = STRAWBOSS | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.254.1 for the Network Card with network
address 001018094F76 has been denied by the DHCP server 192.168.254.254 (The DHCP
Server sent a DHCPNACK message).

Error - 6/23/2009 10:34:12 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 6/23/2009 11:01:41 PM | Computer Name = STRAWBOSS | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.254.1 for the Network Card with network
address 001018094F76 has been denied by the DHCP server 192.168.254.254 (The DHCP
Server sent a DHCPNACK message).


< End of report >

OTL text log

OTL logfile created on: 6/24/2009 2:46:12 AM - Run 1
OTL by OldTimer - Version 3.0.5.2 Folder = C:\Documents and Settings\CHRISTINA\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1021.98 Mb Total Physical Memory | 201.56 Mb Available Physical Memory | 19.72% Memory free
1.66 Gb Paging File | 0.99 Gb Available in Paging File | 59.56% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 39.90 Gb Free Space | 53.58% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STRAWBOSS
Current User Name: CHRISTINA
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
PRC - C:\WINDOWS\System32\PSIService.exe ()
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\WINDOWS\System32\tcpsvcs.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\snmp.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.)
PRC - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - c:\program files\aol\aol toolbar 5.0\AolTbServer.exe (AOL LLC)
PRC - C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\CHRISTINA\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DSBrokerService [On_Demand | Stopped]) -- C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1c995062274baac [Auto | Stopped]) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [Auto | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [On_Demand | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IntuitUpdateService [Auto | Running]) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (IS360service [On_Demand | Stopped]) -- C:\Program Files\IObit\IObit Security 360\IS360srv.exe ()
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LexBceS [Auto | Running]) -- C:\WINDOWS\System32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (McAfee SiteAdvisor Service [Auto | Running]) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (McciCMService [Auto | Running]) -- C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (mcmscsvc [Auto | Running]) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService [Auto | Running]) -- C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (MSK80Service [Auto | Running]) -- C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (NetSvc [On_Demand | Stopped]) -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (ProtexisLicensing [Auto | Running]) -- C:\WINDOWS\System32\PSIService.exe ()
SRV - (QBCFMonitorService [Auto | Running]) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBFCService [On_Demand | Stopped]) -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (SimpTcp [Auto | Running]) -- C:\WINDOWS\System32\tcpsvcs.exe (Microsoft Corporation)
SRV - (SNMP [Auto | Running]) -- C:\WINDOWS\System32\snmp.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (b57w2k [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (bvrp_pci [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\bvrp_pci.sys ()
DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (drvmcdb [Boot | Running]) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) -- C:\WINDOWS\System32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (DSproct [On_Demand | Stopped]) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (ENETHUSB [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\enethusb.sys (Efficient Networks, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HSFHWBS2 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (i81x [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation)
DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mfeavfk [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) -- C:\WINDOWS\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (MODEMCSA [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (MPFP [System | Running]) -- C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (MREMP50 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MREMPR5 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (MRESP50 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) -- C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (PfModNT [Auto | Running]) -- C:\WINDOWS\System32\drivers\PfModNT.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RLDesignVirtualAudioCableWdm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\livecamv.sys ()
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (smwdm [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (SRS_SSCFilter [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\srs_sscfilter_i386.sys ()
DRV - (sscdbhk5 [System | Running]) -- C:\WINDOWS\System32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) -- C:\WINDOWS\System32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (tfsnboio [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (usbbus [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (V0560Afx [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\V0560Afx.sys (Creative Technology Ltd.)
DRV - (V0560Vid [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\V0560Vid.sys (Creative Technology Ltd.)
DRV - (wanatw [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe...-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc7&p="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.myspace.com/"
FF - prefs.js..extensions.enabledItems: anycolor.pavlos256@gmail.com:0.2.6
FF - prefs.js..extensions.enabledItems: {6ad56361-628f-471b-8f9d-4c338973a87d}:5.27.1.1
FF - prefs.js..extensions.enabledItems: facepad@lazyrussian.com:0.5.8
FF - prefs.js..extensions.enabledItems: {6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}:1.2.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.9
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: myspacefftb@myspace.com:1.0.45.0
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.0.3
FF - prefs.js..extensions.enabledItems: {1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}:2.1.2
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: plugin@yontoo.com:1.03.01
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11
FF - prefs.js..extensions.enabledItems: glowyblue-ff3-30@glowplug.bitasylum.net:3.1.3.1
FF - prefs.js..extensions.enabledItems: glowygreen-ff3-30@glowplug.bitasylum.net:3.1.3.1
FF - prefs.js..extensions.enabledItems: {a02c0c70-605c-11da-8cd6-0800200c9a66}:4.08
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr=chrff-brandt_off&type=000106X001US&p="


FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2009/06/06 17:52:47 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\myspacefftb@myspace.com: C:\Program Files\MySpace\Toolbar\1.0.45.0\ File not found
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/05/11 00:23:23 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/02/04 15:01:14 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/06/14 18:17:53 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/06/14 18:17:53 | 00,000,000 | ---D | M]

[2009/02/18 22:41:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Extensions
[2008/11/09 03:09:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/02/18 22:41:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Extensions\mozswing@mozswing.org
[2009/06/22 19:39:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions
[2009/04/14 20:18:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2009/04/16 14:18:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2009/04/13 14:12:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{469CEB59-8266-438b-91D9-82F56D595E15}
[2009/02/04 11:42:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/04/13 14:12:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2009/03/24 15:39:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{6ad56361-628f-471b-8f9d-4c338973a87d}
[2009/04/13 14:12:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}
[2008/11/09 03:09:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}
[2009/04/16 15:36:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\anycolor.pavlos256@gmail.com
[2009/05/09 13:05:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\facepad@lazyrussian.com
[2009/04/13 14:06:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\firefox@ghostery.com
[2009/03/07 15:04:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\glowyblue-ff3-30@glowplug.bitasylum.net
[2009/03/07 15:04:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\glowygreen-ff3-30@glowplug.bitasylum.net
[2009/04/13 21:31:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\plugin@yontoo.com
[2009/03/24 03:19:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\starpulsetoolbar@starpulse.com
[2009/01/17 22:01:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}\chrome\mozapps\extensions
[2009/03/24 15:39:52 | 00,001,741 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\aol-search.xml
[2008/11/09 04:39:31 | 00,002,273 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\ask.xml
[2009/03/19 18:12:34 | 00,002,158 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\MySpace.xml
[2007/05/06 21:10:43 | 00,002,386 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\siteadvisor.xml
[2009/04/14 20:18:59 | 00,001,196 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\winamp-search.xml
[2008/11/09 04:39:31 | 00,000,567 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\yahoo.xml
[2009/06/22 19:39:14 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2007/05/20 21:19:14 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{4be68a18-deba-49e0-9e09-ee7796f3b62a}(2)
[2009/06/14 18:17:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/05/23 19:31:43 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2009/02/04 15:02:31 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/05/12 11:20:21 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/14 18:17:45 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/14 18:17:45 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2007/12/17 13:16:14 | 00,065,536 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npkimi.dll
[2007/08/20 17:45:02 | 01,431,936 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/06/14 18:17:47 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2008/10/14 22:33:30 | 00,095,600 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/05/01 17:26:51 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/05/01 17:26:51 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/05/01 17:26:51 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/05/01 17:26:51 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/05/01 17:26:52 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/05/01 17:26:52 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/05/01 17:26:52 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2007/03/09 19:16:44 | 00,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
[2008/09/24 21:21:16 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/09/24 21:21:16 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/09/24 21:21:16 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/14 15:40:37 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/09/24 21:21:16 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/09/24 21:21:16 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/09/24 21:21:16 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (MySpace Toolbar) - {28AED1AF-B164-44CD-B435-CF04AA955015} - C:\Program Files\MySpace\Toolbar\1.0.45.0\MySpaceToolbar.dll ()
O2 - BHO: (AOL Radio Toolbar Loader) - {2abdb2f7-4cbf-4939-ba12-fddc827b6a2d} - C:\Program Files\AOL Radio Toolbar\aolradiotb.dll (AOL LLC.)
O2 - BHO: (Yahoo! IE Suggest) - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll (Yontoo Technology, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (MySpace Toolbar) - {28AED1AF-B164-44CD-B435-CF04AA955015} - C:\Program Files\MySpace\Toolbar\1.0.45.0\MySpaceToolbar.dll ()
O3 - HKLM\..\Toolbar: (AOL Radio Toolbar) - {9167da98-6f9b-46f1-991d-826cae46cab6} - C:\Program Files\AOL Radio Toolbar\aolradiotb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Fast Browser Search) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Radio Toolbar) - {9167DA98-6F9B-46F1-991D-826CAE46CAB6} - C:\Program Files\AOL Radio Toolbar\aolradiotb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKCU..\Run: [SRS Audio Sandbox] C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe (SRS Labs, Inc.)
O4 - HKCU..\Run: [YahooWidgetEngine.exe] C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] File not found
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Sony Corporation)
O4 - Startup: C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &AOL Radio Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL Radio Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html ()
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200707...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab (Reg Error: Value error.)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo...toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Value error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1175811264578 (MUWebControl Class)
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Value error.)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab (Groove Control)
O16 - DPF: {885BB46A-3F1E-44C3-A01B-A7D9260CC98B} http://updates.installshield.com/CAB/dwusplay.cab (InstallShield Update Service Setup Player)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} http://aolsvc.aol.com/onlinegames/free-tri...tg.1.0.0.33.cab (CPlayFirstddfotgControl Object)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} http://rockyou.com/RockYouImageUploader.cab (RockYou Image Uploader Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in...l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} http://imikimi.com/download/imikimi_plugin.cab (Imikimi_activex_plugin Control)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E...04/clearadj.cab (CTAdjust Class)
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} http://www.imagestation.com/common/classes....cab?v=1,0,0,38 (AxRUploadControl Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su2...15106/CTPID.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {FA945BB6-9D37-43FC-9B2A-AF09F56CBBF0} http://yme.music.yahoo.com/qos/cabs/DiagCo...tionControl.cab (moDiagCollectionActiveX Object)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers...ivex-latest.cab (DownloadManager Control)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254 192.168.254.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O18 - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\WINDOWS\Downloaded Program Files\mimectl.dll ()
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 10:59:58 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[4 C:\WINDOWS\*.tmp files]
[2009/06/24 02:43:40 | 00,512,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\CHRISTINA\Desktop\OTL.exe
[2009/06/24 02:13:40 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/06/24 02:04:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\CHRISTINA\Application Data\Malwarebytes
[2009/06/24 02:04:01 | 00,000,714 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/24 02:03:58 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/24 02:03:56 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/24 02:03:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/06/24 02:03:55 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/24 02:02:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/06/24 01:59:33 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/06/24 01:59:21 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\CHRISTINA\Desktop\NTREGOPT.lnk
[2009/06/24 01:59:21 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\CHRISTINA\Desktop\ERUNT.lnk
[2009/06/24 01:59:19 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/24 01:02:16 | 00,001,740 | ---- | C] () -- C:\Documents and Settings\CHRISTINA\Desktop\HijackThis.lnk
[2009/06/23 20:09:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\IObit
[2009/06/17 15:07:04 | 00,032,256 | ---- | C] () -- C:\Christina's Documents\Coverletter (Autosaved).doc
[2009/06/11 08:07:10 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll
[2009/06/11 08:07:10 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll
[2009/06/04 01:54:03 | 00,000,162 | -H-- | C] () -- C:\Christina's Documents\~$verletter.doc
[2009/06/01 15:56:47 | 00,027,648 | ---- | C] () -- C:\Christina's Documents\Bio on Greg Gatliff.doc
[2009/05/31 18:38:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\CHRISTINA\Application Data\gtk-2.0
[2009/05/31 18:33:19 | 00,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2009/05/27 00:50:00 | 00,270,336 | ---- | C] () -- C:\Christina's Documents\StateApp copy.doc
[2009/05/27 00:49:37 | 00,270,336 | ---- | C] () -- C:\Christina's Documents\StateApp (Autosaved).doc
[2009/05/25 20:37:53 | 00,000,000 | ---D | C] -- C:\Christina's Documents\MapView
[2009/01/17 13:47:27 | 00,031,616 | ---- | C] () -- C:\WINDOWS\System32\drivers\livecamv.sys
[2008/11/18 20:04:29 | 00,000,090 | ---- | C] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2007/09/27 11:51:02 | 00,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 00,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 00,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/05/30 11:02:15 | 00,458,752 | ---- | C] () -- C:\WINDOWS\System32\VagalumePluginWMP.dll
[2007/05/14 05:44:53 | 00,129,078 | ---- | C] () -- C:\WINDOWS\logow.sys
[2007/05/14 05:44:53 | 00,129,078 | ---- | C] () -- C:\WINDOWS\logos.sys
[2007/05/13 20:32:55 | 00,000,000 | ---- | C] () -- C:\WINDOWS\WB.ini
[2007/05/05 20:30:44 | 00,040,448 | ---- | C] () -- C:\WINDOWS\System32\regobj.dll
[2007/04/27 12:31:07 | 00,002,568 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2007/04/27 12:31:07 | 00,000,088 | RHS- | C] () -- C:\WINDOWS\System32\566C526187.sys
[2007/04/25 22:32:55 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\wbload.dll
[2007/04/20 22:01:55 | 00,006,048 | ---- | C] () -- C:\WINDOWS\System32\MCC16.dll
[2007/04/19 19:04:50 | 00,046,592 | R--- | C] () -- C:\WINDOWS\System32\drivers\tshd4_kern_i386.sys
[2007/04/19 19:04:50 | 00,044,416 | R--- | C] () -- C:\WINDOWS\System32\drivers\Surroundhp_kern_i386.sys
[2007/04/19 19:04:50 | 00,038,400 | R--- | C] () -- C:\WINDOWS\System32\drivers\SRS_SSCFilter_i386.sys
[2007/04/19 19:04:50 | 00,037,248 | R--- | C] () -- C:\WINDOWS\System32\drivers\csiidecoder_kern_i386.sys
[2007/02/18 18:39:06 | 00,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2005/09/13 17:27:08 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\dlbacnv4.dll
[2005/07/11 16:27:34 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/04/29 18:51:57 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Textart.INI
[2005/04/18 22:13:24 | 00,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2005/03/20 15:41:20 | 00,071,749 | ---- | C] () -- C:\WINDOWS\hcextoutput.dll
[2005/03/20 15:41:20 | 00,000,823 | ---- | C] () -- C:\WINDOWS\tsc.ini
[2005/03/20 15:08:02 | 00,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2004/11/18 19:16:45 | 00,000,026 | ---- | C] () -- C:\WINDOWS\UP9ASP.INI
[2004/10/06 18:17:11 | 00,000,035 | ---- | C] () -- C:\WINDOWS\A6W.INI
[2004/09/25 17:03:15 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2004/07/07 19:00:48 | 00,000,000 | ---- | C] () -- C:\WINDOWS\netscape.INI
[2004/06/12 17:39:51 | 00,000,021 | ---- | C] () -- C:\WINDOWS\DVDSentry.ini
[2004/05/29 16:01:40 | 00,004,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2004/05/21 20:08:10 | 00,000,930 | ---- | C] () -- C:\WINDOWS\System32\ncase.ini
[2004/02/18 20:49:35 | 00,002,743 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2004/01/29 19:07:39 | 00,000,106 | ---- | C] () -- C:\WINDOWS\AtxTCBizPref03.ini
[2004/01/26 23:33:03 | 00,000,174 | ---- | C] () -- C:\WINDOWS\System32\mcini.ini
[2004/01/26 19:02:37 | 00,000,973 | ---- | C] () -- C:\WINDOWS\DELLSTAT.INI
[2004/01/22 12:00:28 | 00,012,635 | ---- | C] () -- C:\WINDOWS\System32\DAntivirus.ini
[2004/01/21 17:55:52 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/01/21 17:44:47 | 00,000,513 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/01/21 17:41:15 | 00,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/01/21 17:24:58 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/01/21 17:24:44 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/01/21 17:10:52 | 00,000,550 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2003/08/14 00:54:00 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/02/17 19:00:42 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbavs.dll
[2003/02/17 19:00:36 | 00,000,177 | ---- | C] () -- C:\WINDOWS\System32\dlbacoin.ini
[2003/02/05 13:11:12 | 00,000,126 | ---- | C] () -- C:\WINDOWS\System32\DLBAPLC.INI
[2002/10/28 17:31:42 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\cursor.dll
[2002/09/03 10:59:58 | 00,000,650 | ---- | C] () -- C:\WINDOWS\WIN.INI
[2002/09/03 10:50:58 | 00,000,482 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI
[2001/05/07 15:57:20 | 00,137,728 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2001/05/07 15:56:30 | 00,660,480 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2000/01/06 20:00:00 | 00,024,448 | ---- | C] () -- C:\WINDOWS\System32\proclsvr.drv
[2000/01/06 20:00:00 | 00,024,448 | ---- | C] () -- C:\WINDOWS\sysgtime.dll
[1999/07/23 14:46:48 | 00,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 00,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\*.tmp files]
[2009/06/24 02:55:01 | 00,000,430 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5DBDA0A7-2B36-4C06-A598-91EEF296D77A}.job
[2009/06/24 02:43:50 | 00,512,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\CHRISTINA\Desktop\OTL.exe
[2009/06/24 02:04:01 | 00,000,714 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/24 01:59:33 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/06/24 01:59:21 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Desktop\NTREGOPT.lnk
[2009/06/24 01:59:21 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Desktop\ERUNT.lnk
[2009/06/24 01:42:29 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/06/24 01:05:41 | 00,000,973 | ---- | M] () -- C:\WINDOWS\DELLSTAT.INI
[2009/06/24 01:02:16 | 00,001,740 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Desktop\HijackThis.lnk
[2009/06/23 23:01:50 | 00,020,755 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF
[2009/06/23 22:51:00 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/06/23 22:41:01 | 00,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2009/06/23 22:34:08 | 00,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2009/06/23 22:33:57 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/06/23 22:33:53 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2009/06/23 22:33:52 | 10,716,97920 | -HS- | M] () -- C:\hiberfil.sys
[2009/06/23 22:31:57 | 11,647,862 | -H-- | M] () -- C:\Documents and Settings\CHRISTINA\Local Settings\Application Data\IconCache.db
[2009/06/23 10:39:14 | 00,002,568 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2009/06/22 01:00:47 | 00,000,340 | ---- | M] () -- C:\WINDOWS\tasks\McQcTask.job
[2009/06/21 15:32:36 | 00,021,504 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/20 08:35:34 | 00,870,128 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\mcs.rma
[2009/06/20 08:35:34 | 00,000,004 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\8FE0F8
[2009/06/17 15:07:05 | 00,032,256 | ---- | M] () -- C:\Christina's Documents\Coverletter (Autosaved).doc
[2009/06/17 11:27:56 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/15 00:44:49 | 00,000,348 | ---- | M] () -- C:\WINDOWS\tasks\McDefragTask.job
[2009/06/12 12:45:32 | 00,329,096 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/12 01:19:12 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/06/04 01:54:03 | 00,000,162 | -H-- | M] () -- C:\Christina's Documents\~$verletter.doc
[2009/06/01 15:56:47 | 00,027,648 | ---- | M] () -- C:\Christina's Documents\Bio on Greg Gatliff.doc
[2009/06/01 12:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/27 00:50:01 | 00,270,336 | ---- | M] () -- C:\Christina's Documents\StateApp copy.doc
[2009/05/27 00:49:38 | 00,270,336 | ---- | M] () -- C:\Christina's Documents\StateApp (Autosaved).doc

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\WINDOWS\explorer.scf:SummaryInformation
< End of report >


This post has been edited by Cowboylady: Jun 24 2009, 01:08 AM
Go to the top of the page
 
+Quote Post
 
Start new topic
Replies (1 - 9)
emeraldnzl
post Jun 28 2009, 05:49 PM
Post #2


Trusted Helper
Group Icon
Posts: 8,068
OS: XP Pro



Hello Cowboylady,

Welcome to Geekstogo.

QUOTE
Lastly, could you tell me why the email notifications I receive are in spanish? The translator widget on the forum website says spanish, but I do not need it translated to anything and not sure how to change the settings on this.


Don't know why that is happening. I will have to investigate. Looking at my own controls I see it says spanish too but I am still getting notifications in English.

Now

As we will likely be using Notepad please check that word wrap is turned off before you start. To do this, open Notepad, choose Format, then make sure Word Wrap is Un-checked. Word Wrap makes reading your log difficult and may prevent fixes using Notepad from working

Next

Please download ComboFix from one of these locations:

NOTE: If you are guest watching this topic. ComboFix is a very powerful tool. The disclaimer clearly states that you should not use it without supervision. There is good reason for this as ComboFix can, and sometimes does, run into conflict on a computer and render it unusable.

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Go to the top of the page
 
+Quote Post
Cowboylady
post Jun 29 2009, 12:42 AM
Post #3


New Member
*
Posts: 6
From: Byron, GA
OS: Windows XP SP3



Attached is combofix.txt. I tried DL the Windows Recovery module and each time it stated unable to download and began the scan anyway. If you know of a way to do differently, please advise.

BTW, thanks for the quick response. smile.gif

ComboFix 09-06-28.02 - CHRISTINA 06/29/2009 2:14:08.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.393 [GMT -4:00]
Running from: C:\Documents and Settings\CHRISTINA\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\patch.exe
C:\WINDOWS\system32\ncase.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_IPRIP


((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 )))))))))))))))))))))))))))))))
.

2009-06-26 17:55:04 . 2009-06-26 18:10:58 0 d-----w- C:\Documents and Settings\CHRISTINA\Local Settings\Application Data\Plaxo
2009-06-26 17:54:40 . 2009-06-29 06:25:51 0 d-----w- C:\Program Files\Plaxo
2009-06-24 06:13:40 . 2009-06-24 06:18:19 0 d-----w- C:\Rooter$
2009-06-24 06:04:14 . 2009-06-24 06:04:14 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\Malwarebytes
2009-06-24 06:03:58 . 2009-06-17 15:27:56 38160 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-06-24 06:03:56 . 2009-06-24 06:03:56 0 d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-06-24 06:03:56 . 2009-06-17 15:27:44 19096 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
2009-06-24 06:03:55 . 2009-06-24 06:04:07 0 d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-24 05:59:19 . 2009-06-24 05:59:34 0 d-----w- C:\Program Files\ERUNT
2009-06-24 00:09:16 . 2009-06-24 00:09:16 0 d-----w- C:\Documents and Settings\All Users\Application Data\IObit
2009-06-16 18:08:38 . 2009-06-16 18:09:28 0 d-----w- C:\Documents and Settings\CHRISTINA\My videos
2009-06-11 12:07:10 . 2009-04-30 21:22:34 12800 -c----w- C:\WINDOWS\system32\dllcache\xpshims.dll
2009-06-11 12:07:10 . 2009-04-30 21:22:31 246272 -c----w- C:\WINDOWS\system32\dllcache\ieproxy.dll
2009-06-11 02:27:05 . 2009-06-11 02:27:05 2173616 ----a-w- C:\Documents and Settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.45.0.exe
2009-05-31 22:38:25 . 2009-05-31 22:38:25 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\gtk-2.0
2009-05-31 22:34:53 . 2009-05-31 22:35:53 0 d-----w- C:\Documents and Settings\CHRISTINA\.gimp-2.6
2009-05-31 22:34:43 . 2009-05-31 22:34:51 0 d-----w- C:\Documents and Settings\CHRISTINA\.gegl-0.0
2009-05-31 22:33:19 . 2009-05-31 22:33:30 0 d-----w- C:\Program Files\GIMP-2.0

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-28 22:29:06 . 2008-11-19 01:55:17 3239 ----a-w- C:\Documents and Settings\All Users\Application Data\Intuit\QuickBooks 2009\qbbackup.sys
2009-06-28 22:21:54 . 2007-04-27 16:31:07 2568 --sha-w- C:\WINDOWS\system32\KGyGaAvL.sys
2009-06-28 21:05:32 . 2009-02-22 15:55:20 0 d-----w- C:\Documents and Settings\All Users\Application Data\Google Updater
2009-06-24 00:09:12 . 2007-05-17 14:35:06 0 d-----w- C:\Program Files\IObit
2009-06-23 21:24:44 . 2007-04-22 07:15:31 0 d-----w- C:\Program Files\Google
2009-06-15 05:02:50 . 2007-10-16 16:37:16 0 d-----w- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-06-12 16:45:27 . 2009-01-26 17:17:36 0 d-----w- C:\Program Files\Windows Desktop Search
2009-06-03 00:04:08 . 2007-03-23 16:51:35 0 d-----w- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2009-05-25 04:24:06 . 2008-05-27 03:18:26 350208 ------w- C:\WINDOWS\system32\mssph.dll
2009-05-19 21:25:44 . 2009-02-19 12:16:10 0 d-----w- C:\Documents and Settings\NetworkService\Application Data\SACore
2009-05-19 15:31:27 . 2009-05-19 14:41:14 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\Trondent Development Corp
2009-05-19 15:12:39 . 2008-11-26 18:38:45 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\IObit
2009-05-19 14:40:46 . 2004-01-21 21:42:40 0 d--h--w- C:\Program Files\InstallShield Installation Information
2009-05-13 05:15:55 . 2006-06-23 15:33:58 915456 ----a-w- C:\WINDOWS\system32\wininet.dll
2009-05-12 19:12:14 . 2005-05-15 23:53:54 26144 ----a-w- C:\WINDOWS\system32\spupdsvc.exe
2009-05-12 15:20:01 . 2004-01-21 21:34:30 0 d-----w- C:\Program Files\Java
2009-05-12 15:18:12 . 2009-05-11 15:30:02 152576 ----a-w- C:\Documents and Settings\CHRISTINA\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-11 16:19:29 . 2009-05-11 16:19:29 0 d-----w- C:\Documents and Settings\NetworkService\Application Data\MySpace
2009-05-11 16:19:13 . 2009-05-11 16:19:13 0 d-----w- C:\Documents and Settings\NetworkService\Application Data\Yahoo!
2009-05-11 11:13:07 . 2004-01-26 23:01:47 91544 ----a-w- C:\Documents and Settings\CHRISTINA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-11 04:47:57 . 2004-02-25 20:04:25 0 d-----w- C:\Program Files\Microsoft Works
2009-05-07 15:32:35 . 2003-07-16 20:32:09 345600 ----a-w- C:\WINDOWS\system32\localspl.dll
2009-05-07 01:23:19 . 2009-05-07 01:23:19 0 d-----w- C:\Program Files\Coupons
2009-05-06 01:53:49 . 2009-05-06 01:53:51 192512 ----a-w- C:\Documents and Settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\ICSharpCode.SharpZipLib.dll
2009-05-06 01:53:49 . 2008-11-19 16:34:43 861448 ----a-w- C:\Documents and Settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManager.exe
2009-05-06 01:53:49 . 2008-11-19 16:34:43 38664 ----a-w- C:\Documents and Settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManagerPatch.exe
2009-05-04 02:40:34 . 2007-08-06 22:34:58 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\Apple Computer
2009-05-04 01:08:02 . 2007-06-17 17:21:19 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\LimeWire
2009-05-01 23:34:40 . 2009-01-24 20:03:48 0 d-----w- C:\Program Files\LimeWire
2009-05-01 21:30:08 . 2009-05-01 21:29:30 0 d-----w- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-01 21:30:08 . 2008-12-29 21:35:41 0 d-----w- C:\Program Files\iTunes
2009-05-01 21:29:35 . 2009-05-01 21:29:35 0 d-----w- C:\Program Files\iPod
2009-05-01 21:29:34 . 2007-08-06 22:30:08 0 d-----w- C:\Program Files\Common Files\Apple
2009-05-01 21:26:50 . 2009-05-01 21:25:46 0 d-----w- C:\Program Files\QuickTime
2009-05-01 21:17:47 . 2009-05-01 21:17:47 75048 ----a-w- C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-05-01 21:15:06 . 2008-03-21 17:05:24 0 d-----w- C:\Program Files\Safari
2009-05-01 01:23:53 . 2009-05-01 01:23:54 1893936 ----a-w- C:\Documents and Settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.32.5.exe
2009-04-17 12:26:40 . 2003-07-16 20:51:25 1847168 ----a-w- C:\WINDOWS\system32\win32k.sys
2009-04-15 14:51:25 . 2004-03-06 02:16:11 585216 ----a-w- C:\WINDOWS\system32\rpcrt4.dll
2009-04-03 22:28:06 . 2009-04-03 22:28:10 1892856 ----a-w- C:\Documents and Settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.32.0.exe
2009-04-03 00:37:02 . 2009-04-14 16:06:47 36864 --s-a-r- C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
2007-04-26 23:41:30 . 2007-04-26 23:38:01 33032192 ----a-w- C:\Program Files\WP11SP1_EN.msp
2007-04-24 19:34:56 . 2007-04-24 19:30:11 353598016 ----a-w- C:\Program Files\SimpleStartFSEDirect.exe
2007-04-21 02:13:44 . 2007-04-21 02:13:51 774144 ----a-w- C:\Program Files\RngInterstitial.dll
2007-05-04 13:57:08 . 2007-04-27 16:31:07 88 --sh--r- C:\WINDOWS\SYSTEM32\566C526187.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2009-04-01 17:16:19 193472 ------w- C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SRS Audio Sandbox"="C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe" [2007-03-16 19:22:00 3153920]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 00:12:16 15360]
"YahooWidgetEngine.exe"="C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe" [2007-07-20 17:57:16 2913584]
"PlaxoUpdate"="C:\Program Files\Plaxo\3.20.0.13\PlaxoHelper_en.exe" [2009-05-01 15:30:36 379463]
"PlaxoSysTray"="C:\Program Files\Plaxo\3.20.0.13\PlaxoSysTray.exe" [2009-05-01 15:29:20 20480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2009-01-09 01:30:26 645328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2009-01-05 20:18:48 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 05:44:24 435096]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-14 00:04:18 5562368]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-27 15:24:23 68856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"VF0560Inst"="C:\WINDOWS\system32\V0560Pin.dll" [2008-06-02 01:00:00 40960]

C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-24 344064]
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-7-20 2913584]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 02:41:34 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\SoundSpectrum\\G-Force\\G-Force V-Bar.exe"=
"C:\\WINDOWS\\SYSTEM32\\ControlSuite.exe"=
"C:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Standalone.exe"=
"C:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Toolbar.exe"=
"C:\\Program Files\\Yahoo!\\Widgets\\YahooWidgetEngine.exe"=
"C:\\Program Files\\Sonic\\RecordNow!\\RecordNow.exe"=
"C:\\Program Files\\Intel\\NCS\\PROSet\\PROSet.exe"=
"C:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"C:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"C:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"C:\\Program Files\\InterActual\\InterActual Player\\iPlayer.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo! Games\\Bejeweled 2 Deluxe\\WinBej2.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Rhapsody\\WiseUpd2.exe"=
"C:\\Program Files\\Flickr Uploadr\\Flickr Uploadr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Intuit\\QuickBooks 2009\\QBW32SimplestartLimited.exe"=

R2 IntuitUpdateService;Intuit Update Service;C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [12/9/2008 1:37:02 PM 13088]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2/9/2009 2:48:11 PM 210216]
R2 WinDefend;Windows Defender;C:\Program Files\Windows Defender\MsMpEng.exe [11/3/2006 7:19:58 PM 13592]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;C:\WINDOWS\SYSTEM32\DRIVERS\livecamv.sys [1/17/2009 1:47:27 PM 31616]
R3 V0560Afx;Creative Camera VF0560 Audio Effects Driver;C:\WINDOWS\SYSTEM32\DRIVERS\V0560Afx.sys [1/17/2009 1:49:44 PM 160768]
R3 V0560Vid;Creative Live! Cam Optia AF Driver;C:\WINDOWS\SYSTEM32\DRIVERS\V0560Vid.sys [1/17/2009 1:49:26 PM 286592]
S2 gupdate1c995062274baac;Google Update Service (gupdate1c995062274baac);C:\Program Files\Google\Update\GoogleUpdate.exe [2/22/2009 11:56:31 AM 133104]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\WINDOWS\system32\DRIVERS\CtClsFlt.sys --> C:\WINDOWS\system32\DRIVERS\CtClsFlt.sys [?]
S3 IS360service;IS360service;C:\Program Files\IObit\IObit Security 360\IS360srv.exe [6/23/2009 8:09:14 PM 224528]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-29 C:\WINDOWS\Tasks\Google Software Updater.job
- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-22 07:15:37 . 2009-03-24 17:07:43]

2009-06-29 C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-22 15:56:31 . 2009-02-22 15:56:23]

2009-06-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2009-02-09 19:47:53 . 2009-01-09 15:53:12]

2009-06-29 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2009-02-09 19:47:53 . 2009-01-09 15:53:12]

2009-06-29 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20:06 . 2006-11-03 23:20:06]

2009-06-29 C:\WINDOWS\Tasks\User_Feed_Synchronization-{5DBDA0A7-2B36-4C06-A598-91EEF296D77A}.job
- C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 15:58:32 . 2009-03-08 08:31:54]
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-AOL Fast Start - C:\Program Files\AOL 9.0a\AOL.EXE


.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.aol.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AOL Radio Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL Radio Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
IE: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
DPF: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin.cab
FF - ProfilePath - C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\Firefox\Profiles\tcsd8sk1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc7&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=chrff-brandt_off&type=000106X001US&p=
FF - component: C:\Program Files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: C:\Program Files\MySpace\Toolbar\1.0.45.0\components\MySpaceFFoxTB.dll
FF - plugin: C:\Program Files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: C:\Program Files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npkimi.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
Go to the top of the page
 
+Quote Post
emeraldnzl
post Jun 29 2009, 01:17 AM
Post #4


Trusted Helper
Group Icon
Posts: 8,068
OS: XP Pro



Hello Cowboylady,

Looks like that Combofix txt go cut off. Please post the rest. smile.gif

Also do you know about this program?

IObit Security 360
Go to the top of the page
 
+Quote Post
Cowboylady
post Jun 29 2009, 08:41 AM
Post #5


New Member
*
Posts: 6
From: Byron, GA
OS: Windows XP SP3



QUOTE (emeraldnzl @ Jun 29 2009, 03:17 AM) *
Hello Cowboylady,

Looks like that Combofix txt go cut off. Please post the rest. smile.gif

Also do you know about this program?

IObit Security 360


Hi! Sorry about that. It was really late here last night when posted. I have Iobit Security 360. Just downloaded last week, but only have the free version (or beta.) I also have Advanced Windows Care Pro but do not keep it running all the time (as well as Windows Defender) due to conflicts with McAfee which I run at all times. I am not very impressed with WD and it can actually be uninstalled or inactivated to keep from conflict with McAfee but I do like some of the additional features AWS offers so I would like to keep.

The other concerns beside malware or other that might be slowing my computer down are processes that run that are not necessary and I do not know how to modify (or recognize them all) so that they do not restart. Here is a brief run down of processes I terminate manually when computer gets slow, but they are set up to restart immediately. I don't know how to determine if they are actually bogging things down or not also so if you can give me a little help with that too I would appreciate. headscratch.gif

  • Apple programs: such as Mobile Device helper, Bonjour, and related ( I only use rarely when using my daughter's IPOD to get songs off Itunes some)
  • Quickbooks File Monitoring and related
  • Google Updater: (rarely use Google other than checking an email or searching
  • Windows Defender
  • Desktop indexer and search programs: I do not search from my desktop
  • any other that you determine that can be manually started


Thanks,

Here is complete log file of Combofix:

ComboFix 09-06-28.02 - CHRISTINA 06/29/2009 2:14.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.393 [GMT -4:00]
Running from: c:\documents and settings\CHRISTINA\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\patch.exe
c:\windows\system32\ncase.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_IPRIP


((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 )))))))))))))))))))))))))))))))
.

2009-06-26 17:55 . 2009-06-26 18:10 -------- d-----w- c:\documents and settings\CHRISTINA\Local Settings\Application Data\Plaxo
2009-06-26 17:54 . 2009-06-29 06:25 -------- d-----w- c:\program files\Plaxo
2009-06-24 06:13 . 2009-06-24 06:18 -------- d-----w- C:\Rooter$
2009-06-24 06:04 . 2009-06-24 06:04 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Malwarebytes
2009-06-24 06:03 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-24 06:03 . 2009-06-24 06:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-24 06:03 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-24 06:03 . 2009-06-24 06:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-24 05:59 . 2009-06-24 05:59 -------- d-----w- c:\program files\ERUNT
2009-06-24 00:09 . 2009-06-24 00:09 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit
2009-06-16 18:08 . 2009-06-16 18:09 -------- d-----w- c:\documents and settings\CHRISTINA\My videos
2009-06-11 12:07 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-11 12:07 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-11 02:27 . 2009-06-11 02:27 2173616 ----a-w- c:\documents and settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.45.0.exe
2009-05-31 22:38 . 2009-05-31 22:38 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\gtk-2.0
2009-05-31 22:34 . 2009-05-31 22:35 -------- d-----w- c:\documents and settings\CHRISTINA\.gimp-2.6
2009-05-31 22:34 . 2009-05-31 22:34 -------- d-----w- c:\documents and settings\CHRISTINA\.gegl-0.0
2009-05-31 22:33 . 2009-05-31 22:33 -------- d-----w- c:\program files\GIMP-2.0

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-28 22:29 . 2008-11-19 01:55 3239 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\qbbackup.sys
2009-06-28 22:21 . 2007-04-27 16:31 2568 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-28 21:05 . 2009-02-22 15:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-24 00:09 . 2007-05-17 14:35 -------- d-----w- c:\program files\IObit
2009-06-23 21:24 . 2007-04-22 07:15 -------- d-----w- c:\program files\Google
2009-06-15 05:02 . 2007-10-16 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-12 16:45 . 2009-01-26 17:17 -------- d-----w- c:\program files\Windows Desktop Search
2009-06-03 00:04 . 2007-03-23 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-05-25 04:24 . 2008-05-27 03:18 350208 ------w- c:\windows\system32\mssph.dll
2009-05-19 21:25 . 2009-02-19 12:16 -------- d-----w- c:\documents and settings\NetworkService\Application Data\SACore
2009-05-19 15:31 . 2009-05-19 14:41 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Trondent Development Corp
2009-05-19 15:12 . 2008-11-26 18:38 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\IObit
2009-05-19 14:40 . 2004-01-21 21:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-13 05:15 . 2006-06-23 15:33 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-12 19:12 . 2005-05-15 23:53 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-05-12 15:20 . 2004-01-21 21:34 -------- d-----w- c:\program files\Java
2009-05-12 15:18 . 2009-05-11 15:30 152576 ----a-w- c:\documents and settings\CHRISTINA\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-11 16:19 . 2009-05-11 16:19 -------- d-----w- c:\documents and settings\NetworkService\Application Data\MySpace
2009-05-11 16:19 . 2009-05-11 16:19 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Yahoo!
2009-05-11 11:13 . 2004-01-26 23:01 91544 ----a-w- c:\documents and settings\CHRISTINA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-11 04:47 . 2004-02-25 20:04 -------- d-----w- c:\program files\Microsoft Works
2009-05-07 15:32 . 2003-07-16 20:32 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 01:23 . 2009-05-07 01:23 -------- d-----w- c:\program files\Coupons
2009-05-06 01:53 . 2009-05-06 01:53 192512 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\ICSharpCode.SharpZipLib.dll
2009-05-06 01:53 . 2008-11-19 16:34 861448 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManager.exe
2009-05-06 01:53 . 2008-11-19 16:34 38664 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManagerPatch.exe
2009-05-04 02:40 . 2007-08-06 22:34 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Apple Computer
2009-05-04 01:08 . 2007-06-17 17:21 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\LimeWire
2009-05-01 23:34 . 2009-01-24 20:03 -------- d-----w- c:\program files\LimeWire
2009-05-01 21:30 . 2009-05-01 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-01 21:30 . 2008-12-29 21:35 -------- d-----w- c:\program files\iTunes
2009-05-01 21:29 . 2009-05-01 21:29 -------- d-----w- c:\program files\iPod
2009-05-01 21:29 . 2007-08-06 22:30 -------- d-----w- c:\program files\Common Files\Apple
2009-05-01 21:26 . 2009-05-01 21:25 -------- d-----w- c:\program files\QuickTime
2009-05-01 21:17 . 2009-05-01 21:17 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-05-01 21:15 . 2008-03-21 17:05 -------- d-----w- c:\program files\Safari
2009-05-01 01:23 . 2009-05-01 01:23 1893936 ----a-w- c:\documents and settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.32.5.exe
2009-04-17 12:26 . 2003-07-16 20:51 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-03-06 02:16 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-03 22:28 . 2009-04-03 22:28 1892856 ----a-w- c:\documents and settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.32.0.exe
2009-04-03 00:37 . 2009-04-14 16:06 36864 --s-a-r- c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
2007-04-26 23:41 . 2007-04-26 23:38 33032192 ----a-w- c:\program files\WP11SP1_EN.msp
2007-04-24 19:34 . 2007-04-24 19:30 353598016 ----a-w- c:\program files\SimpleStartFSEDirect.exe
2007-04-21 02:13 . 2007-04-21 02:13 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-05-04 13:57 . 2007-04-27 16:31 88 --sh--r- c:\windows\SYSTEM32\566C526187.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2009-04-01 17:16 193472 ------w- c:\program files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SRS Audio Sandbox"="c:\program files\SRS Labs\Audio Sandbox2\SRSSSC.exe" [2007-03-16 3153920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"YahooWidgetEngine.exe"="c:\program files\Yahoo!\Widgets\YahooWidgetEngine.exe" [2007-07-20 2913584]
"PlaxoUpdate"="c:\program files\Plaxo\3.20.0.13\PlaxoHelper_en.exe" [2009-05-01 379463]
"PlaxoSysTray"="c:\program files\Plaxo\3.20.0.13\PlaxoSysTray.exe" [2009-05-01 20480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-08-14 5562368]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-27 68856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"VF0560Inst"="c:\windows\system32\V0560Pin.dll" [2008-06-02 40960]

c:\documents and settings\CHRISTINA\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-24 344064]
Yahoo! Widget Engine.lnk - c:\program files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-7-20 2913584]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force V-Bar.exe"=
"c:\\WINDOWS\\SYSTEM32\\ControlSuite.exe"=
"c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Standalone.exe"=
"c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Toolbar.exe"=
"c:\\Program Files\\Yahoo!\\Widgets\\YahooWidgetEngine.exe"=
"c:\\Program Files\\Sonic\\RecordNow!\\RecordNow.exe"=
"c:\\Program Files\\Intel\\NCS\\PROSet\\PROSet.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"c:\\Program Files\\InterActual\\InterActual Player\\iPlayer.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo! Games\\Bejeweled 2 Deluxe\\WinBej2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Rhapsody\\WiseUpd2.exe"=
"c:\\Program Files\\Flickr Uploadr\\Flickr Uploadr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBW32SimplestartLimited.exe"=

R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [12/9/2008 1:37 PM 13088]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2/9/2009 2:48 PM 210216]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;c:\windows\SYSTEM32\DRIVERS\livecamv.sys [1/17/2009 1:47 PM 31616]
R3 V0560Afx;Creative Camera VF0560 Audio Effects Driver;c:\windows\SYSTEM32\DRIVERS\V0560Afx.sys [1/17/2009 1:49 PM 160768]
R3 V0560Vid;Creative Live! Cam Optia AF Driver;c:\windows\SYSTEM32\DRIVERS\V0560Vid.sys [1/17/2009 1:49 PM 286592]
S2 gupdate1c995062274baac;Google Update Service (gupdate1c995062274baac);c:\program files\Google\Update\GoogleUpdate.exe [2/22/2009 11:56 AM 133104]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys --> c:\windows\system32\DRIVERS\CtClsFlt.sys [?]
S3 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [6/23/2009 8:09 PM 224528]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-22 17:07]

2009-06-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-22 15:56]

2009-06-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-09 15:53]

2009-06-29 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-09 15:53]

2009-06-29 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]

2009-06-29 c:\windows\Tasks\User_Feed_Synchronization-{5DBDA0A7-2B36-4C06-A598-91EEF296D77A}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-AOL Fast Start - c:\program files\AOL 9.0a\AOL.EXE


.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.aol.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AOL Radio Toolbar Search - c:\documents and settings\All Users\Application Data\AOL Radio Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin.cab
FF - ProfilePath - c:\documents and settings\CHRISTINA\Application Data\Mozilla\Firefox\Profiles\tcsd8sk1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc7&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=chrff-brandt_off&type=000106X001US&p=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: c:\program files\MySpace\Toolbar\1.0.45.0\components\MySpaceFFoxTB.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-29 02:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1788)
c:\windows\system32\WININET.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\program files\Plaxo\3.20.0.13\plx_hook.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\LEXBCES.EXE
c:\windows\SYSTEM32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\windows\SYSTEM32\PSIService.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\windows\SYSTEM32\tcpsvcs.exe
c:\windows\SYSTEM32\snmp.exe
c:\windows\SYSTEM32\fxssvc.exe
c:\windows\SYSTEM32\searchindexer.exe
c:\windows\SYSTEM32\wscntfy.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\windows\SYSTEM32\notepad.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\windows\SYSTEM32\searchprotocolhost.exe
.
**************************************************************************
.
Completion time: 2009-06-29 2:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-29 06:35

Pre-Run: 43,616,731,136 bytes free
Post-Run: 43,548,700,672 bytes free

298 --- E O F --- 2009-06-23 04:11
Go to the top of the page
 
+Quote Post
emeraldnzl
post Jun 29 2009, 05:37 PM
Post #6


Trusted Helper
Group Icon
Posts: 8,068
OS: XP Pro



Hi Cowboylady,

The reason I asked you about the IObit Security 360 was because it is a beta version and in testing mode. Often there can be problems with bugs or conflict with products in beta and I was thinking about the symptoms your machine was experiencing and wondering if there was a connection.

QUOTE
Advanced Windows Care Pro


Personally I am not a fan of any products that include registry cleaners. It is generally not necessary to clean your registry. Registry cleaners are notorious for causing problems on peoples computers. Often the problem doesn't appear until well down the track. A small change to the registry can go unnoticed until one day you call on that function and find it won't work anymore or alternatively an associated utility doesn't work properly.

QUOTE
Windows Defender


It is my understanding that usually your anti-virus will turn off Windows Defender when you first install it. This to ensure there is no conflict. You clearly turn it on and off as you want but just for the record here is how to do it:

To disable Windows Defender to prevent it from interfering with our fixes.

Go to this link for instructions on how to enable/disable Windows Defender

http://windowshelp.microsoft.com/Windows/e...1bf0dc1033.mspx

QUOTE
other that might be slowing my computer down are processes that run that are not necessary


You could try this one:

Download and install Startuplite. It is a tool to help you stop some programs not immediately needed from loading when you start your computer. They will begin automatically only when you click on them.

Might help a bit.

You could also download this:

Download and install Auslogics Disk Defrag

When it finishes it's defrag it might tell you there are junk files to remove. Take no notice of that...just trying to sell you another product. AFT-Cleaner mentioned next will attend to that for you.

Now

Please download ATF Cleaner by Atribune.
    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Next

You have used Malwarebytes before. If you still have it on your machine please update and run. Post the scan report back here.

If you no-longer have Malwarebytes please download from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Finally in this post

Kaspersky on line scanner is very thorough. It can take a long time and for periods may seem not to be working. Just be patient and let it do its job.

Kaspersky works with Internet Explorer and Firefox 3.

Go to Kaspersky website and perform an online antivirus scan.

Note: you will need to turn off your security programs to allow Kaspersky to do its job.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start dowanloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Copy and paste that information in your next post.

So when you return please post
  • MBAM log
  • Kaspersky scan results
  • and tell me how you machine is performing now

Go to the top of the page
 
+Quote Post
Cowboylady
post Jul 2 2009, 03:41 AM
Post #7


New Member
*
Posts: 6
From: Byron, GA
OS: Windows XP SP3



The logs requested are to follow, however, I have a question about the Kaspersky scan: Did it remove the file that it found from my computer?
ph34r.gif
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Thursday, July 2, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Thursday, July 02, 2009 03:25:15
Records in database: 2413044
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 124772
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 04:00:23


File name / Threat name / Threats count
C:\Documents and Settings\CHRISTINA\Shared\anywhere but here jason aldean.mp3 Infected: Trojan-Downloader.WMA.Wimad.r 1

The selected area was scanned.


MBAM log:

Malwarebytes' Anti-Malware 1.38
Database version: 2357
Windows 5.1.2600 Service Pack 3

7/1/2009 3:06:09 AM
mbam-log-2009-07-01 (03-06-09).txt

Scan type: Quick Scan
Objects scanned: 73922
Time elapsed: 7 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Go to the top of the page
 
+Quote Post
emeraldnzl
post Jul 2 2009, 04:59 AM
Post #8


Trusted Helper
Group Icon
Posts: 8,068
OS: XP Pro



QUOTE
Did it remove the file that it found from my computer?


Nope, we didn't want it to remove anything in case there was a false positive.

We will remove that one though. wink.gif

Now

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
KillAll::

File::
C:\Documents and Settings\CHRISTINA\Shared\anywhere but here jason aldean.mp3


Save this as CFScript.txt, in the same location as ComboFix.exe



Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it will produce a log for you at C:\ComboFix.txt. Please post that here for further review.

So when you come back please post
  • Combofix txt
  • and tell me how your machine is performing now

Go to the top of the page
 
+Quote Post
Cowboylady
post Jul 3 2009, 12:19 PM
Post #9


New Member
*
Posts: 6
From: Byron, GA
OS: Windows XP SP3



QUOTE (emeraldnzl @ Jul 2 2009, 06:59 AM) *
QUOTE
Did it remove the file that it found from my computer?


Nope, we didn't want it to remove anything in case there was a false positive.

We will remove that one though. wink.gif

Now

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
KillAll::

File::
C:\Documents and Settings\CHRISTINA\Shared\anywhere but here jason aldean.mp3


Save this as CFScript.txt, in the same location as ComboFix.exe



Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it will produce a log for you at C:\ComboFix.txt. Please post that here for further review.

So when you come back please post
  • Combofix txt
  • and tell me how your machine is performing now




ComboFix 09-07-02.02 - CHRISTINA 07/02/2009 23:27.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.565 [GMT -4:00]
Running from: c:\documents and settings\CHRISTINA\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\CHRISTINA\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
"c:\documents and settings\CHRISTINA\Shared\anywhere but here jason aldean.mp3"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\CHRISTINA\Shared\anywhere but here jason aldean.mp3
c:\windows\Installer\e047e9.msi

.
((((((((((((((((((((((((( Files Created from 2009-06-03 to 2009-07-03 )))))))))))))))))))))))))))))))
.

2009-07-01 16:51 . 2009-07-01 16:51 -------- d-----w- c:\documents and settings\CHRISTINA\Local Settings\Application Data\AOL Email Toolbar
2009-07-01 16:51 . 2009-07-01 16:51 -------- d-----w- c:\program files\Common Files\Software Update Utility
2009-07-01 16:51 . 2009-07-01 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Email Toolbar
2009-07-01 16:51 . 2009-07-01 16:51 -------- d-----w- c:\program files\AOL Email Toolbar
2009-06-30 16:57 . 2009-06-30 16:57 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Auslogics
2009-06-30 16:56 . 2009-06-30 16:56 -------- d-----w- c:\program files\Auslogics
2009-06-26 17:55 . 2009-06-26 18:10 -------- d-----w- c:\documents and settings\CHRISTINA\Local Settings\Application Data\Plaxo
2009-06-26 17:54 . 2009-07-02 10:59 -------- d-----w- c:\program files\Plaxo
2009-06-24 06:13 . 2009-06-24 06:18 -------- d-----w- C:\Rooter$
2009-06-24 06:04 . 2009-06-24 06:04 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Malwarebytes
2009-06-24 06:03 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-24 06:03 . 2009-06-24 06:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-24 06:03 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-24 06:03 . 2009-06-30 16:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-24 05:59 . 2009-06-24 05:59 -------- d-----w- c:\program files\ERUNT
2009-06-24 00:09 . 2009-06-24 00:09 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit
2009-06-16 18:08 . 2009-06-16 18:09 -------- d-----w- c:\documents and settings\CHRISTINA\My videos
2009-06-11 12:07 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-11 12:07 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-11 02:27 . 2009-06-11 02:27 2173616 ----a-w- c:\documents and settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.45.0.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-03 01:09 . 2009-02-22 15:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-01 19:54 . 2008-11-19 01:55 3239 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\qbbackup.sys
2009-06-28 22:21 . 2007-04-27 16:31 2568 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-24 00:09 . 2007-05-17 14:35 -------- d-----w- c:\program files\IObit
2009-06-23 21:24 . 2007-04-22 07:15 -------- d-----w- c:\program files\Google
2009-06-15 05:02 . 2007-10-16 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-12 16:45 . 2009-01-26 17:17 -------- d-----w- c:\program files\Windows Desktop Search
2009-06-03 00:04 . 2007-03-23 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-05-31 22:38 . 2009-05-31 22:38 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\gtk-2.0
2009-05-31 22:33 . 2009-05-31 22:33 -------- d-----w- c:\program files\GIMP-2.0
2009-05-25 04:24 . 2008-05-27 03:18 350208 ------w- c:\windows\system32\mssph.dll
2009-05-19 21:25 . 2009-02-19 12:16 -------- d-----w- c:\documents and settings\NetworkService\Application Data\SACore
2009-05-19 15:31 . 2009-05-19 14:41 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Trondent Development Corp
2009-05-19 15:12 . 2008-11-26 18:38 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\IObit
2009-05-19 14:40 . 2004-01-21 21:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-13 05:15 . 2006-06-23 15:33 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-12 19:12 . 2005-05-15 23:53 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-05-12 15:20 . 2004-01-21 21:34 -------- d-----w- c:\program files\Java
2009-05-12 15:18 . 2009-05-11 15:30 152576 ----a-w- c:\documents and settings\CHRISTINA\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-11 16:19 . 2009-05-11 16:19 -------- d-----w- c:\documents and settings\NetworkService\Application Data\MySpace
2009-05-11 16:19 . 2009-05-11 16:19 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Yahoo!
2009-05-11 11:13 . 2004-01-26 23:01 91544 ----a-w- c:\documents and settings\CHRISTINA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-11 04:47 . 2004-02-25 20:04 -------- d-----w- c:\program files\Microsoft Works
2009-05-07 15:32 . 2003-07-16 20:32 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 01:23 . 2009-05-07 01:23 -------- d-----w- c:\program files\Coupons
2009-05-06 01:53 . 2009-05-06 01:53 192512 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\ICSharpCode.SharpZipLib.dll
2009-05-06 01:53 . 2008-11-19 16:34 861448 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManager.exe
2009-05-06 01:53 . 2008-11-19 16:34 38664 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManagerPatch.exe
2009-05-05 18:16 . 2009-05-05 18:16 68608 ----a-w- c:\documents and settings\All Users\Application Data\AOL Email Toolbar\ieToolbar\resources\en-US\aolmailtbres.dll
2009-05-01 21:17 . 2009-05-01 21:17 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-05-01 01:23 . 2009-05-01 01:23 1893936 ----a-w- c:\documents and settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.32.5.exe
2009-04-17 12:26 . 2003-07-16 20:51 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-03-06 02:16 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2007-04-26 23:41 . 2007-04-26 23:38 33032192 ----a-w- c:\program files\WP11SP1_EN.msp
2007-04-24 19:34 . 2007-04-24 19:30 353598016 ----a-w- c:\program files\SimpleStartFSEDirect.exe
2007-04-21 02:13 . 2007-04-21 02:13 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-05-04 13:57 . 2007-04-27 16:31 88 --sh--r- c:\windows\SYSTEM32\566C526187.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-06-29_06.27.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-03 03:43 . 2009-07-03 03:43 16384 c:\windows\Temp\usgthrsvc\Perflib_Perfdata_8e0.dat
+ 2009-07-03 03:43 . 2009-07-03 03:43 16384 c:\windows\Temp\Perflib_Perfdata_794.dat
+ 2009-07-03 03:43 . 2009-07-03 03:43 16384 c:\windows\Temp\Perflib_Perfdata_718.dat
- 2002-09-03 08:08 . 2009-06-29 04:20 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
+ 2002-09-03 08:08 . 2009-07-03 05:44 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
- 2002-09-03 08:08 . 2009-06-29 04:20 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2002-09-03 08:08 . 2009-07-03 05:44 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2002-09-03 08:08 . 2009-06-29 04:20 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2002-09-03 08:08 . 2009-07-03 05:44 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2009-03-05 07:18 . 2009-03-05 07:18 78848 c:\windows\Installer\f6e0a63.msp
+ 2009-03-05 07:18 . 2009-03-05 07:18 18944 c:\windows\Installer\f6e0a58.msp
+ 2009-03-24 22:22 . 2009-03-24 22:22 19456 c:\windows\Installer\e1bf4.msp
+ 2009-03-20 02:35 . 2009-03-20 02:35 18944 c:\windows\Installer\e1bed.msp
+ 2009-03-20 02:35 . 2009-03-20 02:35 18944 c:\windows\Installer\e1be7.msp
+ 2008-07-30 01:07 . 2008-07-30 01:07 23040 c:\windows\Installer\d456647.msp
+ 2009-05-11 04:08 . 2009-05-11 04:08 88576 c:\windows\Installer\d3457fb.msi
+ 2009-05-11 19:10 . 2009-05-11 19:10 24064 c:\windows\Installer\bbb678.msi
+ 2009-07-01 02:33 . 2009-07-01 02:33 22528 c:\windows\Installer\979689e.msi
+ 2009-01-26 19:02 . 2009-01-26 19:02 20992 c:\windows\Installer\900c382.msi
+ 2009-01-26 19:02 . 2009-01-26 19:02 52736 c:\windows\Installer\900c37e.msi
+ 2009-01-26 19:02 . 2009-01-26 19:02 61440 c:\windows\Installer\900c37a.msi
+ 2009-01-26 19:01 . 2009-01-26 19:01 32256 c:\windows\Installer\900c376.msi
+ 2009-01-26 18:58 . 2009-01-26 18:58 22528 c:\windows\Installer\900c36b.msi
+ 2009-03-25 23:42 . 2009-03-25 23:42 25088 c:\windows\Installer\6b58f92.msi
+ 2009-03-14 01:14 . 2009-03-14 01:14 20992 c:\windows\Installer\53a1269.msp
+ 2009-03-14 01:17 . 2009-03-14 01:17 19456 c:\windows\Installer\53a11f2.msp
+ 2009-03-14 01:17 . 2009-03-14 01:17 18944 c:\windows\Installer\53a11eb.msp
+ 2009-02-27 05:08 . 2009-02-27 05:08 18944 c:\windows\Installer\1e282012.msp
+ 2009-02-13 03:09 . 2009-02-13 03:09 75776 c:\windows\Installer\1e28200c.msp
+ 2009-01-24 03:10 . 2009-01-24 03:10 18944 c:\windows\Installer\1a8fb75d.msp
+ 2007-10-01 00:37 . 2007-10-01 00:37 42496 c:\windows\Installer\198befe.msi
+ 2009-03-24 15:13 . 2009-03-24 15:13 51712 c:\windows\Installer\18d6858.msi
+ 2007-10-16 16:39 . 2007-10-16 16:39 48128 c:\windows\Installer\148b17a1.msi
+ 2008-09-17 21:00 . 2007-04-02 18:34 366080 c:\windows\ServicePackFiles\i386\digreqex.msi
+ 2008-09-17 21:00 . 2007-04-02 18:34 863232 c:\windows\ServicePackFiles\i386\digopt.msi
+ 2009-05-11 04:22 . 2009-05-11 04:22 652800 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.msi
+ 2009-02-08 04:30 . 2009-02-08 04:30 446464 c:\windows\Installer\fbe67e5.msi
+ 2009-03-05 07:16 . 2009-03-05 07:16 858112 c:\windows\Installer\f6e0b8a.msp
+ 2007-04-18 18:54 . 2007-04-18 18:54 270336 c:\windows\Installer\e22e91.msi
+ 2009-03-20 02:32 . 2009-03-20 02:32 170496 c:\windows\Installer\e1c73.msp
+ 2009-03-20 02:33 . 2009-03-20 02:33 428544 c:\windows\Installer\e1c5e.msp
+ 2008-12-13 13:58 . 2008-12-13 13:58 754688 c:\windows\Installer\d494908.msp
+ 2009-05-11 04:23 . 2009-05-11 04:23 648192 c:\windows\Installer\d4948e5.msi
+ 2008-07-30 01:23 . 2008-07-30 01:23 250880 c:\windows\Installer\d456650.msp
+ 2008-07-30 01:28 . 2008-07-30 01:28 278016 c:\windows\Installer\d45664e.msp
+ 2008-07-29 23:40 . 2008-07-29 23:40 291840 c:\windows\Installer\d45664c.msp
+ 2009-05-11 04:20 . 2009-05-11 04:20 137728 c:\windows\Installer\d456646.msi
+ 2008-07-29 21:35 . 2008-07-29 21:35 553472 c:\windows\Installer\d345800.msp
+ 2008-07-29 21:33 . 2008-07-29 21:33 506368 c:\windows\Installer\d3457fe.msp
+ 2008-07-29 21:37 . 2008-07-29 21:37 911360 c:\windows\Installer\d3457fd.msp
+ 2007-11-17 16:57 . 2007-11-17 16:57 331264 c:\windows\Installer\c95d9c7.msi
+ 2007-04-18 18:29 . 2007-04-18 18:29 275968 c:\windows\Installer\c8c310.msi
+ 2007-04-18 18:26 . 2007-04-18 18:26 660992 c:\windows\Installer\c8c30c.msi
+ 2004-01-21 21:54 . 2004-01-21 21:54 233472 c:\windows\Installer\b252.msi
+ 2004-01-21 21:54 . 2004-01-21 21:54 171008 c:\windows\Installer\b24c.msi
+ 2006-11-23 08:00 . 2006-11-23 08:00 428544 c:\windows\Installer\a4629ad.msi
+ 2007-04-20 00:40 . 2007-04-20 00:40 804864 c:\windows\Installer\9c470.msi
+ 2009-01-26 19:03 . 2009-01-26 19:03 201728 c:\windows\Installer\900c386.msi
+ 2007-04-24 19:52 . 2007-04-24 19:52 906240 c:\windows\Installer\8b4ba2.msi
+ 2007-04-24 19:38 . 2007-04-24 19:38 390656 c:\windows\Installer\8b4b8f.msi
+ 2009-06-23 21:25 . 2009-06-23 21:25 315392 c:\windows\Installer\6a4d62.msi
+ 2004-01-21 21:47 . 2004-01-21 21:47 558592 c:\windows\Installer\5a82b.msi
+ 2004-01-21 21:44 . 2004-01-21 21:44 456704 c:\windows\Installer\5a818.msi
+ 2004-01-21 21:44 . 2004-01-21 21:44 532992 c:\windows\Installer\5a80d.msi
+ 2004-01-21 21:42 . 2004-01-21 21:42 559616 c:\windows\Installer\5a7f4.msi
+ 2004-01-21 21:34 . 2004-01-21 21:34 616448 c:\windows\Installer\5a7d5.msi
+ 2009-02-04 17:14 . 2009-02-04 17:14 279040 c:\windows\Installer\4d5526.msi
+ 2008-09-14 14:11 . 2008-09-14 14:11 147968 c:\windows\Installer\4cb12.msi
+ 2009-04-01 21:48 . 2009-04-01 21:48 130560 c:\windows\Installer\46e131b.msp
+ 2007-05-11 20:02 . 2007-05-11 20:02 958976 c:\windows\Installer\3fdbb5f.msi
+ 2007-08-15 03:04 . 2007-08-15 03:04 871424 c:\windows\Installer\3cb964.msi
+ 2007-08-15 03:00 . 2007-08-15 03:00 431104 c:\windows\Installer\3cb95e.msi
+ 2007-04-01 21:58 . 2007-04-01 21:58 189952 c:\windows\Installer\36c7696.msi
+ 2008-11-12 06:03 . 2008-11-12 06:03 432640 c:\windows\Installer\311ab3e.msi
+ 2008-12-24 20:27 . 2008-12-24 20:27 164352 c:\windows\Installer\2883a8.msi
+ 2009-05-26 22:53 . 2009-05-26 22:53 579072 c:\windows\Installer\2079f4e4.msp
+ 2007-05-31 02:47 . 2007-05-31 02:47 571904 c:\windows\Installer\1fab4715.msi
+ 2009-02-27 05:08 . 2009-02-27 05:08 151552 c:\windows\Installer\1e28201d.msp
+ 2007-05-14 08:33 . 2007-05-14 08:33 174080 c:\windows\Installer\1d4419b.msi
+ 2007-04-19 19:03 . 2007-04-19 19:03 472576 c:\windows\Installer\1acd29.msi
+ 2009-01-24 03:09 . 2009-01-24 03:09 143360 c:\windows\Installer\1a8fb757.msp
+ 2009-01-24 03:08 . 2009-01-24 03:08 464896 c:\windows\Installer\1a8fb6be.msp
+ 2009-02-04 19:01 . 2009-02-04 19:01 562176 c:\windows\Installer\1a6981.msi
+ 2007-10-15 03:44 . 2007-10-15 03:44 324608 c:\windows\Installer\168c0fc.msp
+ 2007-10-15 03:46 . 2007-10-15 03:46 324608 c:\windows\Installer\168c0f6.msp
+ 2007-10-16 16:40 . 2007-10-16 16:40 501248 c:\windows\Installer\148b17b7.msi
+ 2007-10-16 16:40 . 2007-10-16 16:40 506880 c:\windows\Installer\148b17b2.msi
+ 2007-10-16 16:40 . 2007-10-16 16:40 516608 c:\windows\Installer\148b17ac.msi
+ 2007-10-16 16:40 . 2007-10-16 16:40 513024 c:\windows\Installer\148b17a6.msi
+ 2007-10-16 16:38 . 2007-10-16 16:38 501248 c:\windows\Installer\148b1789.msi
+ 2007-10-30 00:13 . 2007-10-30 00:13 501248 c:\windows\Installer\147af710.msi
+ 2008-11-19 01:29 . 2008-11-19 01:29 316928 c:\windows\Installer\132d6e18.msi
+ 2008-11-19 00:03 . 2008-11-19 00:03 889344 c:\windows\Installer\132d6de0.msi
+ 2008-11-19 00:03 . 2008-11-19 00:03 591872 c:\windows\Installer\132d6ddb.msi
+ 2002-09-03 08:06 . 2002-09-03 08:06 264704 c:\windows\Installer\1128E.MSI
+ 2009-07-02 10:59 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\7-2-2009\ERDNT.EXE
+ 2009-07-01 02:39 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\6-30-2009\ERDNT.EXE
+ 2003-07-16 20:51 . 2004-07-17 18:35 1326080 c:\windows\SYSTEM32\webfldrs.msi
+ 2004-01-26 23:00 . 2004-01-21 21:34 9121792 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}\Java 2 Runtime Environment, SE v1.4.2.msi
+ 2004-07-17 18:35 . 2004-07-17 18:35 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2008-09-17 21:02 . 2007-04-02 18:42 5080576 c:\windows\ServicePackFiles\i386\msnmsgs.msi
+ 2007-05-25 16:08 . 2007-05-25 16:08 9609728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp
+ 2007-01-18 22:14 . 2007-01-18 22:14 3463680 c:\windows\Microsoft.NET\Framework\v1.0.3705\Updates\M928367\M928367Uninstall.msp
+ 2009-03-05 07:15 . 2009-03-05 07:15 3058176 c:\windows\Installer\f6e0c82.msp
+ 2009-03-05 07:17 . 2009-03-05 07:17 1856512 c:\windows\Installer\f6e0bf5.msp
+ 2009-03-24 22:20 . 2009-03-24 22:20 2630656 c:\windows\Installer\e1ce8.msp
+ 2009-04-04 21:10 . 2009-04-04 21:10 1282560 c:\windows\Installer\d494ab1.msp
+ 2009-04-04 21:10 . 2009-04-04 21:10 7888384 c:\windows\Installer\d494aaa.msp
+ 2009-04-04 21:10 . 2009-04-04 21:10 9926144 c:\windows\Installer\d494aa1.msp
+ 2009-04-04 14:14 . 2009-04-04 14:14 1094656 c:\windows\Installer\d494913.msp
+ 2008-12-13 13:57 . 2008-12-13 13:57 8397824 c:\windows\Installer\d4948f3.msp
+ 2008-07-29 23:26 . 2008-07-29 23:26 1043456 c:\windows\Installer\d45664f.msp
+ 2008-07-30 00:37 . 2008-07-30 00:37 2679808 c:\windows\Installer\d45664d.msp
+ 2008-07-30 01:15 . 2008-07-30 01:15 3697664 c:\windows\Installer\d45664b.msp
+ 2008-07-29 23:34 . 2008-07-29 23:34 1448448 c:\windows\Installer\d45664a.msp
+ 2008-07-30 00:22 . 2008-07-30 00:22 4137984 c:\windows\Installer\d456649.msp
+ 2008-07-29 23:18 . 2008-07-29 23:18 3376640 c:\windows\Installer\d456648.msp
+ 2008-07-29 21:45 . 2008-07-29 21:45 2543616 c:\windows\Installer\d345804.msp
+ 2008-07-29 21:29 . 2008-07-29 21:29 2926080 c:\windows\Installer\d345803.msp
+ 2008-07-29 21:41 . 2008-07-29 21:41 6487040 c:\windows\Installer\d345802.msp
+ 2008-07-29 21:39 . 2008-07-29 21:39 3403264 c:\windows\Installer\d345801.msp
+ 2008-07-29 21:43 . 2008-07-29 21:43 1013248 c:\windows\Installer\d3457ff.msp
+ 2008-07-29 21:31 . 2008-07-29 21:31 6083072 c:\windows\Installer\d3457fc.msp
+ 2009-04-24 16:28 . 2009-04-24 16:28 4450816 c:\windows\Installer\d2b8620.msp
+ 2008-11-13 07:57 . 2008-11-13 07:57 5099520 c:\windows\Installer\cbd193.msp
+ 2008-10-20 15:18 . 2008-10-20 15:18 6474240 c:\windows\Installer\cbd17f.msp
+ 2009-05-22 02:39 . 2009-05-22 02:39 1711616 c:\windows\Installer\cae5814.msp
+ 2008-04-11 22:48 . 2008-04-11 22:48 6774272 c:\windows\Installer\c95e024.msp
+ 2008-07-16 23:01 . 2008-07-16 23:01 5110272 c:\windows\Installer\c95e00e.msp
+ 2007-04-18 18:31 . 2007-04-18 18:31 4410368 c:\windows\Installer\c8c319.msi
+ 2009-01-08 01:25 . 2009-01-08 01:25 5046784 c:\windows\Installer\c57752d.msp
+ 2008-01-28 23:09 . 2008-01-28 23:09 5055488 c:\windows\Installer\bf2de81.msp
+ 2007-10-28 15:53 . 2007-10-28 15:53 5047808 c:\windows\Installer\bae4e61.msp
+ 2009-05-21 21:44 . 2009-05-21 21:44 1401344 c:\windows\Installer\b9eb7fd.msi
+ 2009-01-27 06:23 . 2009-01-27 06:23 4192256 c:\windows\Installer\b6f9a9b.msi
+ 2004-01-21 21:54 . 2004-01-21 21:54 1989632 c:\windows\Installer\b248.msi
+ 2008-04-11 22:08 . 2008-04-11 22:08 6302720 c:\windows\Installer\a81730.msp
+ 2008-04-26 00:14 . 2008-04-26 00:14 5052928 c:\windows\Installer\a81718.msp
+ 2008-04-18 18:56 . 2008-04-18 18:56 6215680 c:\windows\Installer\a81704.msp
+ 2007-04-11 02:40 . 2007-04-11 02:40 1392128 c:\windows\Installer\984d85.msi
+ 2007-11-22 23:23 . 2007-11-22 23:23 5051904 c:\windows\Installer\90fb9c.msp
+ 2009-01-26 19:00 . 2009-01-26 19:00 2231296 c:\windows\Installer\900c372.msi
+ 2004-10-06 23:10 . 2004-10-06 23:10 2652672 c:\windows\Installer\8c13d6d9.msi
+ 2009-01-20 18:17 . 2009-01-20 18:17 1659392 c:\windows\Installer\860dc66.msi
+ 2007-04-18 16:57 . 2007-04-18 16:58 4065280 c:\windows\Installer\76629b.msi
+ 2008-06-05 17:56 . 2008-06-05 17:56 5111808 c:\windows\Installer\73cffde.msp
+ 2009-03-25 23:40 . 2009-03-25 23:40 4733440 c:\windows\Installer\679c96d.msp
+ 2004-01-21 21:45 . 2004-01-21 21:45 2778112 c:\windows\Installer\5a823.msi
+ 2004-01-21 21:44 . 2004-01-21 21:44 1264128 c:\windows\Installer\5a808.msi
+ 2004-01-21 21:43 . 2004-01-21 21:43 9017344 c:\windows\Installer\5a801.msi
+ 2004-01-21 21:43 . 2004-01-21 21:43 2303488 c:\windows\Installer\5a7f8.msi
+ 2004-01-21 21:42 . 2004-01-21 21:42 5564928 c:\windows\Installer\5a7e7.msi
+ 2004-01-21 21:40 . 2004-01-21 21:40 3443712 c:\windows\Installer\5a7df.msi
+ 2004-01-21 21:40 . 2004-01-21 21:40 2120192 c:\windows\Installer\5a7da.msi
+ 2009-05-01 21:31 . 2009-05-01 21:31 1674752 c:\windows\Installer\5867cfb.msi
+ 2009-05-01 21:30 . 2009-05-01 21:30 3966976 c:\windows\Installer\5867cc9.msi
+ 2009-05-01 21:26 . 2009-05-01 21:26 8992256 c:\windows\Installer\58679ab.msi
+ 2009-05-01 21:22 . 2009-05-01 21:22 3293696 c:\windows\Installer\5867708.msi
+ 2009-05-01 21:15 . 2009-05-01 21:15 2330624 c:\windows\Installer\58675fc.msi
+ 2007-04-05 22:31 . 2007-04-05 22:31 1142784 c:\windows\Installer\53c62d.msi
+ 2009-03-14 01:13 . 2009-03-14 01:13 1677312 c:\windows\Installer\53a12ca.msp
+ 2009-03-14 01:16 . 2009-03-14 01:16 1672192 c:\windows\Installer\53a125a.msp
+ 2008-11-20 19:48 . 2008-11-20 19:48 5097472 c:\windows\Installer\51a7021.msp
+ 2008-08-25 23:08 . 2008-08-25 23:08 1549312 c:\windows\Installer\4636035.msi
+ 2008-10-20 15:19 . 2008-10-20 15:19 5100032 c:\windows\Installer\311ab65.msp
+ 2008-02-15 12:54 . 2008-02-15 12:54 9736192 c:\windows\Installer\2c6db0b.msp
+ 2008-03-17 21:55 . 2008-03-17 21:55 5049344 c:\windows\Installer\2c6dae4.msp
+ 2007-03-31 02:20 . 2007-03-31 02:20 5800960 c:\windows\Installer\282b318.msp
+ 2007-03-31 02:21 . 2007-03-31 02:21 3886080 c:\windows\Installer\282b307.msp
+ 2007-06-01 19:54 . 2007-06-01 19:54 9626624 c:\windows\Installer\282b2d3.msp
+ 2007-07-21 17:26 . 2007-07-21 17:26 7574016 c:\windows\Installer\282b2c2.msp
+ 2007-07-30 18:44 . 2007-07-30 18:44 1155072 c:\windows\Installer\267915.msi
+ 2009-05-04 11:46 . 2009-05-04 11:46 8299008 c:\windows\Installer\2079f538.msp
+ 2009-05-04 11:47 . 2009-05-04 11:47 9124864 c:\windows\Installer\2079f523.msp
+ 2009-04-24 16:30 . 2009-04-24 16:30 2583552 c:\windows\Installer\2079f50e.msp
+ 2009-05-07 13:17 . 2009-05-07 13:17 5026816 c:\windows\Installer\2079f4f8.msp
+ 2009-04-24 16:29 . 2009-04-24 16:29 9013760 c:\windows\Installer\2079f4d1.msp
+ 2009-02-27 05:05 . 2009-02-27 05:05 3425792 c:\windows\Installer\1e28230c.msp
+ 2009-03-02 03:23 . 2009-03-02 03:23 1969152 c:\windows\Installer\1e282243.msp
+ 2009-02-28 09:55 . 2009-02-28 09:55 2728960 c:\windows\Installer\1e2820b4.msp
+ 2009-02-25 23:08 . 2009-02-25 23:08 8311808 c:\windows\Installer\1d1c445b.msp
+ 2009-03-28 13:50 . 2009-03-28 13:50 5025792 c:\windows\Installer\1d1c4448.msp
+ 2008-09-02 15:42 . 2008-09-02 15:42 5104640 c:\windows\Installer\1c96d6b0.msp
+ 2008-02-25 19:08 . 2008-02-25 19:08 5050368 c:\windows\Installer\1bcff8e6.msp
+ 2009-01-24 03:09 . 2009-01-24 03:09 2215424 c:\windows\Installer\1a8fb741.msp
+ 2009-01-24 03:07 . 2009-01-24 03:07 3441152 c:\windows\Installer\1a8fb667.msp
+ 2007-06-07 00:50 . 2007-06-07 00:50 4466176 c:\windows\Installer\1a57d93.msi
+ 2007-07-11 15:17 . 2007-07-11 15:17 6743040 c:\windows\Installer\19fefc94.msp
+ 2009-01-15 07:35 . 2009-01-15 07:35 4830720 c:\windows\Installer\18d685e.msp
+ 2007-10-15 03:43 . 2007-10-15 03:43 5749760 c:\windows\Installer\168c0d6.msp
+ 2007-03-27 20:14 . 2007-03-27 20:14 5566464 c:\windows\Installer\14afb01c.msp
+ 2007-10-01 01:12 . 2007-10-01 01:12 5052416 c:\windows\Installer\149c2847.msp
+ 2007-05-29 02:01 . 2007-05-29 02:01 4597760 c:\windows\Installer\149c27f7.msp
+ 2007-10-16 16:40 . 2007-10-16 16:40 1652736 c:\windows\Installer\148b17bc.msi
+ 2007-10-16 16:39 . 2007-10-16 16:39 1640960 c:\windows\Installer\148b1798.msi
+ 2007-10-16 16:39 . 2007-10-16 16:39 1713152 c:\windows\Installer\148b178e.msi
+ 2007-10-16 16:37 . 2007-10-16 16:37 2397184 c:\windows\Installer\148b1784.msi
+ 2007-10-30 00:13 . 2007-10-30 00:13 1652736 c:\windows\Installer\147af70b.msi
+ 2007-10-30 00:13 . 2007-10-30 00:13 1652736 c:\windows\Installer\147af703.msi
+ 2007-10-30 00:12 . 2007-10-30 00:12 2319872 c:\windows\Installer\147af6f2.msi
+ 2007-10-30 00:11 . 2007-10-30 00:11 2022912 c:\windows\Installer\147af6e7.msi
+ 2007-04-05 20:49 . 2007-04-05 20:49 5864960 c:\windows\Installer\117b026.msp
+ 2007-04-05 20:48 . 2007-04-05 20:48 1422848 c:\windows\Installer\117b01f.msp
+ 2009-02-07 03:31 . 2009-02-07 03:31 5047808 c:\windows\Installer\10c50a.msp
+ 2008-08-20 18:37 . 2008-08-20 18:37 5107712 c:\windows\Installer\103a3f78.msp
+ 2009-07-02 10:59 . 2009-07-02 10:59 1060864 c:\windows\ERDNT\AutoBackup\7-2-2009\Users\00000002\UsrClass.dat
+ 2009-07-02 10:59 . 2009-07-02 10:59 9928704 c:\windows\ERDNT\AutoBackup\7-2-2009\Users\00000001\ntuser.dat
+ 2009-07-01 02:39 . 2009-07-01 02:39 1060864 c:\windows\ERDNT\AutoBackup\6-30-2009\Users\00000002\UsrClass.dat
+ 2009-07-01 02:39 . 2009-07-01 02:39 9928704 c:\windows\ERDNT\AutoBackup\6-30-2009\Users\00000001\ntuser.dat
+ 2007-06-07 00:48 . 2007-06-07 00:48 9834496 c:\windows\Downloaded Installations\{FE6F1783-A2E5-4CFA-8255-BA2C5299B0BB}\URGE.msi
+ 2007-08-22 01:32 . 2007-08-22 01:32 5277696 c:\windows\Downloaded Installations\{98A091FD-535E-4DE9-A977-EC43764487FE}\MyFantasyMaker.msi
+ 2006-10-30 08:05 . 2006-10-30 08:05 11390464 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpf.msi
+ 2007-12-11 08:02 . 2007-12-11 08:02 24487424 c:\windows\Installer\f75cdab.msp
+ 2008-10-20 15:22 . 2008-10-20 15:22 11758592 c:\windows\Installer\e2c6c6.msp
+ 2008-10-20 15:21 . 2008-10-20 15:21 11937280 c:\windows\Installer\e2c6b2.msp
+ 2009-04-04 21:09 . 2009-04-04 21:09 15190016 c:\windows\Installer\d494933.msp
+ 2009-04-04 15:36 . 2009-04-04 15:36 21390848 c:\windows\Installer\d494914.msp
+ 2008-12-13 14:21 . 2008-12-13 14:21 10473472 c:\windows\Installer\d4948fd.msp
+ 2009-05-04 11:49 . 2009-05-04 11:49 10955776 c:\windows\Installer\ceeb52b.msp
+ 2008-10-20 15:16 . 2008-10-20 15:16 13211648 c:\windows\Installer\cbd1a8.msp
+ 2008-07-03 15:36 . 2008-07-03 15:36 11937792 c:\windows\Installer\c95e04c.msp
+ 2008-07-03 15:37 . 2008-07-03 15:37 11759104 c:\windows\Installer\c95e038.msp
+ 2004-01-21 21:53 . 2004-01-21 21:53 12298240 c:\windows\Installer\b244.msi
+ 2009-02-25 23:05 . 2009-02-25 23:05 11840000 c:\windows\Installer\af19922.msp
+ 2009-02-25 23:07 . 2009-02-25 23:07 11646464 c:\windows\Installer\af1990e.msp
+ 2008-04-11 22:07 . 2008-04-11 22:07 13257728 c:\windows\Installer\a81746.msp
+ 2007-04-24 19:47 . 2007-04-24 19:48 67772928 c:\windows\Installer\8b4b97.msi
+ 2007-04-05 14:45 . 2007-04-05 14:45 10723328 c:\windows\Installer\7f34a9b.msp
+ 2007-04-05 14:42 . 2007-04-05 14:42 19210240 c:\windows\Installer\7f34a47.msp
+ 2007-05-01 05:09 . 2007-05-01 05:09 12962816 c:\windows\Installer\6d89db.msp
+ 2008-11-19 16:34 . 2008-11-19 16:34 34966016 c:\windows\Installer\56eb0f3.msp
+ 2008-11-19 16:34 . 2008-11-19 16:34 17352192 c:\windows\Installer\56eb0f2.msp
+ 2008-05-21 05:30 . 2008-05-21 05:30 14308864 c:\windows\Installer\48c02.msp
+ 2009-02-11 20:47 . 2009-02-11 20:47 20803072 c:\windows\Installer\3a93ea9.msp
+ 2009-03-30 17:50 . 2009-03-30 17:50 25128448 c:\windows\Installer\3a93ea8.msp
+ 2008-09-24 17:05 . 2008-09-24 17:05 16381440 c:\windows\Installer\311ab51.msp
+ 2008-06-28 23:20 . 2008-06-28 23:20 10935296 c:\windows\Installer\2d19049e.msi
+ 2008-01-28 22:07 . 2008-01-28 22:07 19034624 c:\windows\Installer\2c6daf8.msp
+ 2007-08-06 16:47 . 2007-08-06 16:47 56805888 c:\windows\Installer\2aeb6b.msp
+ 2007-03-31 02:19 . 2007-03-31 02:19 10893312 c:\windows\Installer\282b2f5.msp
+ 2007-06-01 19:53 . 2007-06-01 19:53 10255360 c:\windows\Installer\282b2e4.msp
+ 2008-05-08 18:03 . 2008-05-08 18:03 22272512 c:\windows\Installer\1c92fc7e.msp
+ 2008-07-30 03:20 . 2008-07-30 03:20 11767296 c:\windows\Installer\1c86d376.msp
+ 2008-07-30 03:18 . 2008-07-30 03:18 11933184 c:\windows\Installer\1c86d362.msp
+ 2008-02-25 19:07 . 2008-02-25 19:07 11772416 c:\windows\Installer\1bcff933.msp
+ 2008-01-28 22:09 . 2008-01-28 22:09 11896320 c:\windows\Installer\1bcff91f.msp
+ 2008-01-28 22:10 . 2008-01-28 22:10 14201344 c:\windows\Installer\1bcff90a.msp
+ 2007-05-06 00:27 . 2007-05-06 00:27 13985280 c:\windows\Installer\1b1c892.msi
+ 2007-05-06 00:25 . 2007-05-06 00:25 22380032 c:\windows\Installer\1b1c88c.msi
+ 2007-07-11 15:26 . 2007-07-11 15:26 15256576 c:\windows\Installer\19fefcf2.msp
+ 2007-10-15 03:43 . 2007-10-15 03:43 12743168 c:\windows\Installer\168c0e7.msp
+ 2007-10-15 03:43 . 2007-10-15 03:43 21981184 c:\windows\Installer\168c0ad.msp
+ 2007-04-22 00:16 . 2007-04-22 00:16 12490752 c:\windows\Installer\14afb00a.msp
+ 2007-06-01 19:55 . 2007-06-01 19:55 10824704 c:\windows\Installer\149c2811.msp
+ 2007-10-30 00:22 . 2007-10-30 00:22 15830016 c:\windows\Installer\147af716.msi
+ 2009-01-09 21:37 . 2009-01-09 21:37 26120192 c:\windows\Installer\14079da5.msp
+ 2009-01-09 21:37 . 2009-01-09 21:37 19272704 c:\windows\Installer\14079da4.msp
+ 2008-11-19 01:22 . 2008-11-19 01:23 45664256 c:\windows\Installer\132d6e12.msi
+ 2008-08-11 15:51 . 2008-08-11 15:51 15916544 c:\windows\Installer\103a3f64.msp
+ 2008-08-11 15:49 . 2008-08-11 15:49 22457344 c:\windows\Installer\103a3f50.msp
+ 2007-04-18 00:30 . 2007-04-18 00:30 12682240 c:\windows\Downloaded Installations\Yahoo Jukebox\Yahoo! Music Jukebox.msi
+ 2007-08-25 21:32 . 2007-08-25 21:32 12560896 c:\windows\Downloaded Installations\{CA82323F-95EB-46BC-9FEF-C593133CC34F}\Yahoo! Music Jukebox.msi
+ 2007-11-27 01:37 . 2007-11-27 01:37 12568576 c:\windows\Downloaded Installations\{885582E4-09F5-4CE2-8234-187CEDE982B8}\Yahoo! Music Jukebox.msi
+ 2008-02-19 14:34 . 2008-02-19 14:34 12545536 c:\windows\Downloaded Installations\{6FB8D67A-9BAD-4361-9B96-E2970783552D}\Yahoo! Music Jukebox.msi
+ 2009-04-04 21:08 . 2009-04-04 21:08 343058432 c:\windows\Installer\d494a97.msp
+ 2007-10-15 03:43 . 2007-10-15 03:43 229852160 c:\windows\Installer\168c0a6.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2009-04-01 17:16 193472 ------w- c:\program files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SRS Audio Sandbox"="c:\program files\SRS Labs\Audio Sandbox2\SRSSSC.exe" [2007-03-16 3153920]
"YahooWidgetEngine.exe"="c:\program files\Yahoo!\Widgets\YahooWidgetEngine.exe" [2007-07-20 2913584]
"PlaxoUpdate"="c:\program files\Plaxo\3.20.0.13\PlaxoHelper_en.exe" [2009-05-01 379463]
"PlaxoSysTray"="c:\program files\Plaxo\3.20.0.13\PlaxoSysTray.exe" [2009-05-01 20480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-08-14 5562368]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-27 68856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"VF0560Inst"="c:\windows\system32\V0560Pin.dll" [2008-06-02 40960]

c:\documents and settings\CHRISTINA\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-24 344064]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force V-Bar.exe"=
"c:\\WINDOWS\\SYSTEM32\\ControlSuite.exe"=
"c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Standalone.exe"=
"c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Toolbar.exe"=
"c:\\Program Files\\Yahoo!\\Widgets\\YahooWidgetEngine.exe"=
"c:\\Program Files\\Sonic\\RecordNow!\\RecordNow.exe"=
"c:\\Program Files\\Intel\\NCS\\PROSet\\PROSet.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"c:\\Program Files\\InterActual\\InterActual Player\\iPlayer.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo! Games\\Bejeweled 2 Deluxe\\WinBej2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Rhapsody\\WiseUpd2.exe"=
"c:\\Program Files\\Flickr Uploadr\\Flickr Uploadr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBW32SimplestartLimited.exe"=

R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [12/9/2008 1:37 PM 13088]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2/9/2009 2:48 PM 210216]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;c:\windows\SYSTEM32\DRIVERS\livecamv.sys [1/17/2009 1:47 PM 31616]
R3 V0560Afx;Creative Camera VF0560 Audio Effects Driver;c:\windows\SYSTEM32\DRIVERS\V0560Afx.sys [1/17/2009 1:49 PM 160768]
R3 V0560Vid;Creative Live! Cam Optia AF Driver;c:\windows\SYSTEM32\DRIVERS\V0560Vid.sys [1/17/2009 1:49 PM 286592]
S2 gupdate1c995062274baac;Google Update Service (gupdate1c995062274baac);c:\program files\Google\Update\GoogleUpdate.exe [2/22/2009 11:56 AM 133104]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys --> c:\windows\system32\DRIVERS\CtClsFlt.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-03 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-22 17:07]

2009-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-22 15:56]

2009-06-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-09 15:53]

2009-06-29 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-09 15:53]

2009-07-03 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]

2009-07-03 c:\windows\Tasks\User_Feed_Synchronization-{5DBDA0A7-2B36-4C06-A598-91EEF296D77A}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.aol.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AOL Email Toolbar Search - c:\documents and settings\All Users\Application Data\AOL Email Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &AOL Radio Toolbar Search - c:\documents and settings\All Users\Application Data\AOL Radio Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin.cab
FF - ProfilePath - c:\documents and settings\CHRISTINA\Application Data\Mozilla\Firefox\Profiles\tcsd8sk1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50-ff-aolmailtb-chromesbox-en-us&query=
FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50-ff-aolmailtb-ab-en-us&query=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: c:\program files\MySpace\Toolbar\1.0.45.0\components\MySpaceFFoxTB.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-03 03:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\TEMP\mcafee_suO0bMjGZygouua 0 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3132)
c:\windows\system32\WININET.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\program files\Plaxo\3.20.0.13\plx_hook.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\LEXBCES.EXE
c:\windows\SYSTEM32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\windows\SYSTEM32\PSIService.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\windows\SYSTEM32\tcpsvcs.exe
c:\windows\SYSTEM32\snmp.exe
c:\windows\SYSTEM32\fxssvc.exe
c:\windows\SYSTEM32\searchindexer.exe
c:\progra~1\McAfee\VIRUSS~1\mcods.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
.
**************************************************************************
.
Completion time: 2009-07-03 3:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-03 07:48
ComboFix2.txt 2009-06-29 06:36

Pre-Run: 42,892,439,552 bytes free
Post-Run: 43,087,237,120 bytes free

560 --- E O F --- 2009-07-02 17:34


So far the computer is doing good with no freezeups. thumbsup.gif I am so thankful for your help and patience...mwahhh.
Go to the top of the page
 
+Quote Post
emeraldnzl
post Jul 3 2009, 03:27 PM
Post #10


Trusted Helper
Group Icon
Posts: 8,068
OS: XP Pro



Hello Cowboylady,

Almost there now. Just one that I think we should play on the safe with and remove and one scan to check for another possible infection.

Now

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
File::
c:\windows\system32\V0560Pin.dll

Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"VF0560Inst"=-


Save this as CFScript.txt, in the same location as ComboFix.exe



Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it will produce a log for you at C:\ComboFix.txt. Please post that here for further review.

Next

Please download GooredFix and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet.

So when you return please post
  • Combofix.txt
  • Goored.txt

Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies / Views Topic Information
No New Posts   5 / 953 3rd December 2007 - 05:04 AM
flash86 started - last by Kenny94
No New Posts   0 / 57 26th August 2009 - 04:44 PM
UMan01 started - last by UMan01
No New Posts   0 / 37 8th November 2009 - 04:48 PM
Vicadi started - last by Vicadi
No New Posts   4 / 59 12th November 2009 - 02:47 PM
woodworks started - last by rshaffer61

RSS Time is now: 21st November 2009 - 11:53 PM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising