Suspected malware or spyware slowing computer down, HJT, Rooter and Malware Logs are pasted in body |
Suspected malware or spyware slowing computer down, HJT, Rooter and Malware Logs are pasted in body |
Jun 24 2009, 12:38 AM
Post
#1
|
|
![]() New Member ![]() Posts: 6 From: Byron, GA OS: Windows XP SP3 |
I am appending to the bottom of this my two(2)OTL logs
I realize that I have alot of files that I do not know whether they should be running at most times or not. I am not able to tell which are valid files or add-ons and programs that I have picked up over the last few years. Please help me decipher some of these things. I have followed the instructions for malware removal per the instructions prior to posting... Thanks so much for a reply when you can as my computer is freezing and takes a while to shut down and/or start up. Logfile of Trend Micro HijackThis v2.0.2[/size] Scan saved at 1:52:42 AM, on 6/24/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\WINDOWS\system32\PSIService.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\system32\fxssvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\Explorer.EXE C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE c:\program files\aol\aol toolbar 5.0\AolTbServer.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\SYSTEM32\notepad.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def.../search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn8\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn8\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll O2 - BHO: MySpace Toolbar - {28AED1AF-B164-44CD-B435-CF04AA955015} - C:\Program Files\MySpace\Toolbar\1.0.45.0\MySpaceToolbar.dll O2 - BHO: AOL Radio Toolbar Loader - {2abdb2f7-4cbf-4939-ba12-fddc827b6a2d} - C:\Program Files\AOL Radio Toolbar\aolradiotb.dll O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn8\YTSingleInstance.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn8\yt.dll O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll O3 - Toolbar: AOL Radio Toolbar - {9167da98-6f9b-46f1-991d-826cae46cab6} - C:\Program Files\AOL Radio Toolbar\aolradiotb.dll O3 - Toolbar: MySpace Toolbar - {28AED1AF-B164-44CD-B435-CF04AA955015} - C:\Program Files\MySpace\Toolbar\1.0.45.0\MySpaceToolbar.dll O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe" /hideme O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [YahooWidgetEngine.exe] C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe O4 - HKUS\S-1-5-18\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0a\AOL.EXE" -b (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [VF0560Inst] RunDll32.exe C:\WINDOWS\system32\V0560Pin.dll,RunDLL32EP 515 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0a\AOL.EXE" -b (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [VF0560Inst] RunDll32.exe C:\WINDOWS\system32\V0560Pin.dll,RunDLL32EP 515 (User 'Default user') O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe O8 - Extra context menu item: &AOL Radio Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL Radio Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200707...ex/qtplugin.cab O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1175811264578 O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab O16 - DPF: {885BB46A-3F1E-44C3-A01B-A7D9260CC98B} (InstallShield Update Service Setup Player) - http://updates.installshield.com/CAB/dwusplay.cab O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-tri...tg.1.0.0.33.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://rockyou.com/RockYouImageUploader.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in...l/installer.exe O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin.cab O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes....cab?v=1,0,0,38 O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2...15106/CTPID.cab O16 - DPF: {FA945BB6-9D37-43FC-9B2A-AF09F56CBBF0} (moDiagCollectionActiveX Object) - http://yme.music.yahoo.com/qos/cabs/DiagCo...tionControl.cab O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers...ivex-latest.cab O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing) O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: Google Update Service (gupdate1c995062274baac) (gupdate1c995062274baac) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: IS360service - Unknown owner - C:\Program Files\IObit\IObit Security 360\IS360srv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- End of file - 16414 bytes Rooter log Rooter.exe (v1.0.1) by Eric_71 ¨ Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3 32_bits - x86 Family 15 Model 2 Stepping 9, GenuineIntel ¨ C:\ [Fixed-NTFS] .. ( Total:74 Go - Free:39 Go ) D:\ [CD_Rom] ¨ Scan : 02:10.24 Path : C:\Documents and Settings\CHRISTINA\Local Settings\Temporary Internet Files\Content.IE5\1B3MVTWP\Rooter[1].exe User : CHRISTINA ( Administrator -> YES ) ¨ ----------------------\\ Processes ¨ Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (740) ______ \??\C:\WINDOWS\system32\csrss.exe (812) ______ \??\C:\WINDOWS\system32\winlogon.exe (836) ______ C:\WINDOWS\system32\services.exe (880) ______ C:\WINDOWS\system32\lsass.exe (892) ______ C:\WINDOWS\system32\svchost.exe (1052) ______ C:\WINDOWS\system32\svchost.exe (1132) ______ C:\Program Files\Windows Defender\MsMpEng.exe (1172) ______ C:\WINDOWS\System32\svchost.exe (1212) ______ C:\WINDOWS\system32\svchost.exe (1248) ______ C:\WINDOWS\System32\svchost.exe (1380) ______ C:\WINDOWS\system32\LEXBCES.EXE (1552) ______ C:\WINDOWS\system32\spoolsv.exe (1576) ______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (1632) ______ C:\WINDOWS\system32\LEXPPS.EXE (1644) ______ C:\Program Files\Bonjour\mDNSResponder.exe (1672) ______ C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (1796) ______ C:\Program Files\Java\jre6\bin\jqs.exe (1828) ______ C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (1860) ______ C:\Program Files\Common Files\Motive\McciCMService.exe (1884) ______ C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe (1936) ______ c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe (1988) ______ c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (2024) ______ C:\Program Files\Google\Update\GoogleUpdate.exe (2036) ______ C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (236) ______ C:\Program Files\McAfee\MPF\MPFSrv.exe (432) ______ C:\Program Files\McAfee\MSK\MskSrver.exe (536) ______ C:\WINDOWS\system32\PSIService.exe (592) ______ C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (640) ______ C:\WINDOWS\System32\tcpsvcs.exe (808) ______ C:\WINDOWS\System32\snmp.exe (816) ______ C:\WINDOWS\System32\svchost.exe (1068) ______ C:\WINDOWS\system32\SearchIndexer.exe (1452) ______ C:\WINDOWS\system32\fxssvc.exe (2152) ______ C:\WINDOWS\System32\svchost.exe (2708) ______ C:\WINDOWS\System32\alg.exe (2752) ______ C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (3264) ______ c:\PROGRA~1\mcafee.com\agent\mcagent.exe (3700) ______ C:\WINDOWS\Explorer.EXE (3920) ______ C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe (520) ______ C:\WINDOWS\system32\ctfmon.exe (600) ______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (2220) ______ C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (2804) ______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (412) ______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (204) ______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (1724) ______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (2924) ______ C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (2056) ______ C:\WINDOWS\System32\svchost.exe (3928) ______ C:\Program Files\Internet Explorer\IEXPLORE.EXE (3160) ______ C:\Program Files\Internet Explorer\IEXPLORE.EXE (3144) ______ c:\program files\aol\aol toolbar 5.0\AolTbServer.exe (3332) ______ C:\WINDOWS\system32\rundll32.exe (1156) ______ C:\Program Files\Windows Defender\MpCmdRun.exe (1948) ______ C:\Program Files\Internet Explorer\IEXPLORE.EXE (3608) ______ C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (3784) ______ C:\Documents and Settings\CHRISTINA\Local Settings\Temporary Internet Files\Content.IE5\1B3MVTWP\Rooter[1].exe (3896) ¨ ----------------------\\ Device\Harddisk0\ ¨ \Device\Harddisk0 [Sectors : 63 x 512 Bytes] ¨ \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:32868864) \Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:32901120 | Length:79957946880) ¨ ----------------------\\ Scheduled Tasks ¨ C:\WINDOWS\Tasks\DESKTOP.INI C:\WINDOWS\Tasks\Google Software Updater.job C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job C:\WINDOWS\Tasks\McDefragTask.job C:\WINDOWS\Tasks\McQcTask.job C:\WINDOWS\Tasks\MP Scheduled Scan.job C:\WINDOWS\Tasks\SA.DAT C:\WINDOWS\Tasks\User_Feed_Synchronization-{5DBDA0A7-2B36-4C06-A598-91EEF296D77A}.job ¨ ----------------------\\ Registry ¨ ¨ ----------------------\\ Files & Folders ¨ ----------------------\\ Scan completed at 02:13.40 ¨ C:\Rooter$\Rooter_1.txt - (24/06/2009 | 02:13.40) ¨ C:\Rooter$\Rooter_2.txt - (24/06/2009 | 02:18.19) Malwarebytes' Anti-Malware 1.38[size="2"]Database version: 2327 Windows 5.1.2600 Service Pack 3 6/24/2009 2:28:35 AM mbam-log-2009-06-24 (02-28-35).txt Scan type: Quick Scan Objects scanned: 108641 Time elapsed: 20 minute(s), 56 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) OTL Extras.txt OTL Extras logfile created on: 6/24/2009 2:46:12 AM - Run 1 OTL by OldTimer - Version 3.0.5.2 Folder = C:\Documents and Settings\CHRISTINA\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1021.98 Mb Total Physical Memory | 201.56 Mb Available Physical Memory | 19.72% Memory free 1.66 Gb Paging File | 0.99 Gb Available in Paging File | 59.56% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 74.47 Gb Total Space | 39.90 Gb Free Space | 53.58% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: STRAWBOSS Current User Name: CHRISTINA Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusOverride" = 0 "FirewallOverride" = 0 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 File not found C:\Program Files\AOL 9.0a\waol.exe:*:Enabled:AOL 9.0a File not found %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console (Microsoft Corporation) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.) C:\Program Files\SoundSpectrum\G-Force\G-Force V-Bar.exe:*:Enabled:G-Force V-Bar () C:\WINDOWS\SYSTEM32\ControlSuite.exe:*:Enabled:Broadcom Advanced Control Suite (Broadcom Corporation) C:\Program Files\SoundSpectrum\G-Force\G-Force Standalone.exe:*:Enabled:G-Force Standalone () C:\Program Files\SoundSpectrum\G-Force\G-Force Toolbar.exe:*:Enabled:G-Force Toolbar () C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe:*:Enabled:Yahoo! Widgets (Yahoo! Inc.) C:\Program Files\Sonic\RecordNow!\RecordNow.exe:*:Enabled:RecordNow! () C:\Program Files\Intel\NCS\PROSet\PROSet.exe:*:Disabled:Intel® PROSet (Intel® Corporation) C:\WINDOWS\SYSTEM32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE (Lexmark International, Inc.) C:\Program Files\Intuit\QuickBooks 2007\QBDBMgrN.exe:*:Enabled:QuickBooks 2007 Data Manager (iAnywhere Solutions, Inc.) C:\WINDOWS\SYSTEM32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test (Microsoft Corporation) C:\Program Files\InterActual\InterActual Player\iPlayer.exe:*:Disabled:InterActual Player (Sonic Solutions) C:\WINDOWS\network diagnostic\xpnetdiag.exe:*:Enabled:Network Diagnostic for Windows XP (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation) C:\Program Files\Yahoo! Games\Bejeweled 2 Deluxe\WinBej2.exe:*:Enabled:Bejeweled2 (PopCap.com) C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook (Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player (Microsoft Corporation) %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation) C:\Program Files\Intuit\QuickBooks 2009\QBDBMgrN.exe:*:Enabled:QuickBooks 2009 Data Manager (Intuit, Inc.) C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.) C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax (Intuit, Inc.) C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager (Intuit, Inc.) C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent (McAfee, Inc.) C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC) C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server (Intuit Inc.) C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.) C:\Program Files\Rhapsody\WiseUpd2.exe:*:Enabled:Check For Rhapsody Update () C:\Program Files\Flickr Uploadr\Flickr Uploadr.exe:*:Enabled:Flickr Uploadr (Yahoo! Inc.) C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox (Mozilla Corporation) C:\Program Files\Intuit\QuickBooks 2009\QBW32SimplestartLimited.exe:*:Enabled:QuickBooks Simple Start 2009 (Intuit Inc.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "_{83FBD495-DDF6-4C8D-92D6-10261DD6F6A3}" = WordPerfect Office X3 "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager "{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center "{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 13 "{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation "{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine "{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page "{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36 "{43FCA273-9534-40DB-B7C5-D7758875616A}" = Dell Support "{4468EF97-A253-4699-9E1C-88CAE2C6832D}" = ABBYY FineReader 5.0 Sprint "{44A91B04-3D0C-47F9-B644-7F682869AFF3}" = MobileMe Control Panel "{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = BACS "{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement "{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies "{52C8FAA0-68CA-4AF9-8A7A-92CF3174CC77}" = Windows Media Player 9 Series Winter Fun Pack "{52D56C42-8C69-4882-A661-39695537C9CF}" = DellConnect "{548EEA8E-8299-497F-8057-811D2D7097DC}" = Dell Support 3.1 "{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool "{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service "{5D50644B-310A-4C1B-B2DD-B8E781ADC430}" = WordPerfect MAIL "{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{6CF08AD2-00C5-4A63-B74B-2EFFFAFEBE1A}" = Microsoft Outlook Web Access S/MIME "{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2 "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{72B688ED-88AC-43D5-8A7A-A88D67CBA762}" = Catella4 "{737D7CA8-D05C-46C7-AFED-A76616E8CA3B}" = WordPerfect OfficeReady "{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset "{7838752C-A838-4C73-849C-625C6114AF0C}" = SRS Audio Sandbox "{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English "{7E545666-F420-45FD-B3DF-C0B99A1A579F}" = QuickBooks Simple Start Edition "{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport "{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper "{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition "{83FBD495-DDF6-4C8D-92D6-10261DD6F6A3}" = WordPerfect Office X3 "{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Client for Internet Explorer 1.03.02 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver "{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12 "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_PROPLUSR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_PROPLUSR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUSR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_PROPLUSR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_PROPLUSR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization "{91120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007 "{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91208A47-5D08-4C79-986F-1931940F51BB}" = QuickBooks Product Listing Service "{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow! "{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry "{9A2F0810-3619-4E86-9072-973FBE1679C5}" = QuickBooks Simple Start 2009 "{9A2F0810-3622-4E86-9072-973FBE1679C5}" = QuickBooks Pro 2009 "{9A2F0810-369F-4E86-9072-973FBE1679C5}" = QuickBooks "{9B79DCB0-AAD7-456B-8D07-433C936FA24B}" = DS21Patch "{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime "{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A6A13E30-656F-4876-9B03-FBD4D712BB40}" = Wal-Mart Music Downloads Store "{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.5 "{AC76BA86-7AD7-1033-7B44-A81300000003}_814" = KB408682 "{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support "{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper "{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport "{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English) "{B535B621-5559-11DE-A7A1-005056806466}" = Google Earth Plugin "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album "{CC016F21-3970-11DE-B878-005056806466}" = Google Earth "{CDEFD989-469E-421D-A8B1-EC7AB25C8CB2}" = TurboTax 2008 wgaiper "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D01653EF-9F9F-41D6-B879-654A6BF5892C}" = Digital Locker Assistant "{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe "{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility "{D5F881C2-B134-474E-AA60-B25DD218AE0D}" = Crash Analysis Tool "{D90AFDE3-3E67-407A-ACA8-F0BAAD012F08}" = Safari "{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect "{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp "{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools "{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement "3DGroove" = OTOY "7-Zip" = 7-Zip 4.56 beta "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "Advanced Audio FX Engine" = Advanced Audio FX Engine "Advanced SystemCare 3_is1" = Advanced SystemCare 3 "ALLTEL.MCCInstall" = Windstream Broadband Check-up Center "AOL Radio Toolbar" = AOL Radio Toolbar "AOL Toolbar" = AOL Toolbar 5.0 "audcle" = Plus! MP3 Audio Converter LE "AudioBurst" = AudioBurst FX Engine "Audit Support Center" = Audit Support Center 1.0 "Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0 "Citrix ICA Web Client" = MetaFrame Presentation Server Web Client for Win32 "CNXT_MODEM_PCI_VEN_14F1&DEV_2702" = Conexant SmartHSFi V.9x 56K DF PCI Modem "CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem "Creative VF0560" = Creative Live! Cam Optia AF (VF0560) Driver (1.00.06.00) "Dell AIO Printer A940" = Dell AIO Printer A940 "Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver "Diner Dash" = Diner Dash "ERUNT_is1" = ERUNT 1.1j "Fair-Sound Audio DSP Plug-ins for Windows Media Player 9_is1" = Fair-Sound 2.0 for Windows Media Player 9 "Flickr Uploadr" = Flickr Uploadr 2.5.0.14 "GalleryPlayer Images" = GalleryPlayer Images "G-Force" = G-Force "Google Updater" = Google Updater "HijackThis" = HijackThis 2.0.2 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "Imikimi Plugin" = Imikimi Plugin "InstallShield_{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = Broadcom Advanced Control Suite "InterActual Player" = InterActual Player "IObit Security 360_is1" = IObit Security 360 Beta 1.1 "LimeWire" = LimeWire 5.1.2 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705 "Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime "mmmusic" = Movie Maker Background Music Files "mmsounds" = Movie Maker Sound Effects "mmtitle" = Movie Maker Title Images "Mozilla Firefox (3.0.5)" = Mozilla Firefox (3.0.5) "mplibwiz.inf" = Media Library Management Wizard "mpxlswiz.inf" = Windows Media Player Playlist Import to Excel Wizard "mpxptray.inf" = Windows Media Player Tray Control "MSC" = McAfee SecurityCenter "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MySpaceIM" = MySpaceIM "MySpaceToolbar" = MySpace Toolbar "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "PROPLUSR" = Microsoft Office Professional Plus 2007 "PROSet" = Intel® PRO Network Connections Drivers "R4" = R4 "Rhapsody" = Rhapsody "Shockwave" = Shockwave "StreetPlugin" = Learn2 Player (Uninstall Only) "SysInfo" = Creative System Information "TBSB07183.TBSB07183Toolbar" = Fast Browser Search (My Web Tattoo) "TurboTax 2008" = TurboTax 2008 "TurboTax Home & Business 2007" = TurboTax Home & Business 2007 "UnixUtils for Yahoo! Widgets" = Unix Utilities for Yahoo! Widgets "Virtools3DLifePlayer" = Virtools 3D Life Player "wa2wmp" = Windows Media Player Skin Importer "WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell "WIC" = Windows Imaging Component "Winamp" = Winamp "Winamp Essentials Pack" = Winamp Essentials Pack v5.34 "Winamp Toolbar" = Winamp Toolbar "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinGimp-2.0_is1" = GIMP 2.6.6 "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Extras" = Yahoo! Browser Services "Yahoo! IE Suggest" = Yahoo! IE Search Suggest "Yahoo! Mail" = Yahoo! Internet Mail "Yahoo! Messenger" = Yahoo! Messenger "Yahoo! Photos Drag-Drop Uploader 1v7" = Yahoo! Photos Easy Upload Tool 1v7 "Yahoo! Search Defender" = Yahoo! Search Protection "Yahoo! Widget Engine" = Yahoo! Widgets "YInstHelper" = Yahoo! Install Manager ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 4/2/2009 12:09:04 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4 Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance Hand Error - 4/2/2009 12:09:04 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4 Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance Hand Error - 4/2/2009 12:09:04 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4 Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance Hand Error - 4/2/2009 12:09:04 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4 Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance Hand Error - 4/2/2009 12:33:59 PM | Computer Name = STRAWBOSS | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module urlmon.dll, version 8.0.6001.18702, fault address 0x0003e819. Error - 4/2/2009 10:51:39 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4 Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance Hand Error - 4/2/2009 10:51:39 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4 Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance Hand Error - 4/2/2009 10:51:39 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4 Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance Hand Error - 4/2/2009 10:51:39 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4 Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance Hand Error - 4/2/2009 11:03:42 PM | Computer Name = STRAWBOSS | Source = QuickBooks | ID = 4 Description = An unexpected error has occured in "QuickBooks Pro 2009": tlg file removal failed because the file was still ope [ OSession Events ] Error - 5/13/2009 3:12:27 PM | Computer Name = STRAWBOSS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 21 seconds with 0 seconds of active time. This session ended with a crash. Error - 5/13/2009 3:13:21 PM | Computer Name = STRAWBOSS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 19 seconds with 0 seconds of active time. This session ended with a crash. Error - 6/2/2009 8:17:13 PM | Computer Name = STRAWBOSS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12 seconds with 0 seconds of active time. This session ended with a crash. Error - 6/2/2009 8:17:30 PM | Computer Name = STRAWBOSS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 15 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 6/23/2009 3:28:21 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7000 Description = The MCSTRM service failed to start due to the following error: %%2 Error - 6/23/2009 3:37:37 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7031 Description = The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error - 6/23/2009 3:40:54 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7034 Description = The QBCFMonitorService service terminated unexpectedly. It has done this 1 time(s). Error - 6/23/2009 3:41:10 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7031 Description = The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error - 6/23/2009 3:41:46 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7034 Description = The Intuit Update Service service terminated unexpectedly. It has done this 1 time(s). Error - 6/23/2009 3:42:18 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7031 Description = The Apple Mobile Device service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error - 6/23/2009 3:43:44 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7031 Description = The Apple Mobile Device service terminated unexpectedly. It has done this 4 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error - 6/23/2009 10:24:23 PM | Computer Name = STRAWBOSS | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.254.1 for the Network Card with network address 001018094F76 has been denied by the DHCP server 192.168.254.254 (The DHCP Server sent a DHCPNACK message). Error - 6/23/2009 10:34:12 PM | Computer Name = STRAWBOSS | Source = Service Control Manager | ID = 7000 Description = The MCSTRM service failed to start due to the following error: %%2 Error - 6/23/2009 11:01:41 PM | Computer Name = STRAWBOSS | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.254.1 for the Network Card with network address 001018094F76 has been denied by the DHCP server 192.168.254.254 (The DHCP Server sent a DHCPNACK message). < End of report > OTL text log OTL logfile created on: 6/24/2009 2:46:12 AM - Run 1 OTL by OldTimer - Version 3.0.5.2 Folder = C:\Documents and Settings\CHRISTINA\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1021.98 Mb Total Physical Memory | 201.56 Mb Available Physical Memory | 19.72% Memory free 1.66 Gb Paging File | 0.99 Gb Available in Paging File | 59.56% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 74.47 Gb Total Space | 39.90 Gb Free Space | 53.58% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: STRAWBOSS Current User Name: CHRISTINA Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) PRC - C:\WINDOWS\System32\LEXBCES.EXE (Lexmark International, Inc.) PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) PRC - C:\WINDOWS\System32\LEXPPS.EXE (Lexmark International, Inc.) PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.) PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe () PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.) PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.) PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.) PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.) PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.) PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.) PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.) PRC - C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.) PRC - C:\WINDOWS\System32\PSIService.exe () PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit) PRC - C:\WINDOWS\System32\tcpsvcs.exe (Microsoft Corporation) PRC - C:\WINDOWS\System32\snmp.exe (Microsoft Corporation) PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.) PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation) PRC - C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe (SRS Labs, Inc.) PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.) PRC - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Sony Corporation) PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.) PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.) PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.) PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.) PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.) PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) PRC - c:\program files\aol\aol toolbar 5.0\AolTbServer.exe (AOL LLC) PRC - C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation) PRC - C:\Documents and Settings\CHRISTINA\Desktop\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation) SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (DSBrokerService [On_Demand | Stopped]) -- C:\Program Files\DellSupport\brkrsvc.exe () SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (gupdate1c995062274baac [Auto | Stopped]) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.) SRV - (gusvc [Auto | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google) SRV - (helpsvc [On_Demand | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (IntuitUpdateService [Auto | Running]) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.) SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) SRV - (IS360service [On_Demand | Stopped]) -- C:\Program Files\IObit\IObit Security 360\IS360srv.exe () SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) SRV - (LexBceS [Auto | Running]) -- C:\WINDOWS\System32\LEXBCES.EXE (Lexmark International, Inc.) SRV - (McAfee SiteAdvisor Service [Auto | Running]) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe () SRV - (McciCMService [Auto | Running]) -- C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.) SRV - (mcmscsvc [Auto | Running]) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.) SRV - (McNASvc [Auto | Running]) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.) SRV - (McODS [On_Demand | Stopped]) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.) SRV - (McProxy [Auto | Running]) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.) SRV - (McShield [Unknown | Running]) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.) SRV - (McSysmon [On_Demand | Running]) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.) SRV - (MpfService [Auto | Running]) -- C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.) SRV - (MSK80Service [Auto | Running]) -- C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.) SRV - (NetSvc [On_Demand | Stopped]) -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation) SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation) SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) SRV - (ProtexisLicensing [Auto | Running]) -- C:\WINDOWS\System32\PSIService.exe () SRV - (QBCFMonitorService [Auto | Running]) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit) SRV - (QBFCService [On_Demand | Stopped]) -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.) SRV - (SimpTcp [Auto | Running]) -- C:\WINDOWS\System32\tcpsvcs.exe (Microsoft Corporation) SRV - (SNMP [Auto | Running]) -- C:\WINDOWS\System32\snmp.exe (Microsoft Corporation) SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (aeaudio [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\aeaudio.sys (Andrea Electronics Corporation) DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.) DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.) DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.) DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.) DRV - (b57w2k [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\b57xp32.sys (Broadcom Corporation) DRV - (bvrp_pci [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\bvrp_pci.sys () DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.) DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation) DRV - (drvmcdb [Boot | Running]) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions) DRV - (drvnddm [Auto | Running]) -- C:\WINDOWS\System32\drivers\drvnddm.sys (Sonic Solutions) DRV - (DSproct [On_Demand | Stopped]) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.) DRV - (dsunidrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\dsunidrv.sys (Gteko Ltd.) DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation) DRV - (ENETHUSB [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\enethusb.sys (Efficient Networks, Inc.) DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (HSFHWBS2 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.) DRV - (HSF_DP [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.) DRV - (i81x [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation) DRV - (iAimFP0 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation) DRV - (iAimFP1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation) DRV - (iAimFP2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation) DRV - (iAimFP3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation) DRV - (iAimFP4 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation) DRV - (iAimTV0 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation) DRV - (iAimTV1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation) DRV - (iAimTV3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation) DRV - (iAimTV4 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation) DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation) DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant) DRV - (mfeavfk [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\mfeavfk.sys (McAfee, Inc.) DRV - (mfebopk [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\mfebopk.sys (McAfee, Inc.) DRV - (mfehidk [System | Running]) -- C:\WINDOWS\System32\drivers\mfehidk.sys (McAfee, Inc.) DRV - (mferkdk [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\mferkdk.sys (McAfee, Inc.) DRV - (mfesmfk [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\mfesmfk.sys (McAfee, Inc.) DRV - (MODEMCSA [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\MODEMCSA.sys (Microsoft Corporation) DRV - (MPFP [System | Running]) -- C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.) DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.) DRV - (MREMP50 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA)) DRV - (MREMPR5 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.) DRV - (MRENDIS5 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.) DRV - (MRESP50 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA)) DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation) DRV - (omci [System | Running]) -- C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation) DRV - (PfModNT [Auto | Running]) -- C:\WINDOWS\System32\drivers\PfModNT.sys (Creative Technology Ltd.) DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.) DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions) DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation) DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation) DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation) DRV - (RLDesignVirtualAudioCableWdm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\livecamv.sys () DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation) DRV - (smwdm [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\smwdm.sys (Analog Devices, Inc.) DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.) DRV - (SRS_SSCFilter [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\srs_sscfilter_i386.sys () DRV - (sscdbhk5 [System | Running]) -- C:\WINDOWS\System32\drivers\sscdbhk5.sys (Sonic Solutions) DRV - (ssrtln [System | Running]) -- C:\WINDOWS\System32\drivers\ssrtln.sys (Sonic Solutions) DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.) DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic) DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic) DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic) DRV - (tfsnboio [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnboio.sys (Sonic Solutions) DRV - (tfsncofs [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsncofs.sys (Sonic Solutions) DRV - (tfsndrct [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsndrct.sys (Sonic Solutions) DRV - (tfsndres [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsndres.sys (Sonic Solutions) DRV - (tfsnifs [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnifs.sys (Sonic Solutions) DRV - (tfsnopio [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnopio.sys (Sonic Solutions) DRV - (tfsnpool [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnpool.sys (Sonic Solutions) DRV - (tfsnudf [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnudf.sys (Sonic Solutions) DRV - (tfsnudfa [Auto | Running]) -- C:\WINDOWS\System32\dla\tfsnudfa.sys (Sonic Solutions) DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.) DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.) DRV - (usbaudio [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation) DRV - (usbbus [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\lgusbbus.sys (LG Electronics Inc.) DRV - (UsbDiag [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.) DRV - (V0560Afx [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\V0560Afx.sys (Creative Technology Ltd.) DRV - (V0560Vid [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\V0560Vid.sys (Creative Technology Ltd.) DRV - (wanatw [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.) DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.) DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation) DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe...-8&fr=b1ie7 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/ IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll (Yahoo! Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yahoo" FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc7&p=" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.myspace.com/" FF - prefs.js..extensions.enabledItems: anycolor.pavlos256@gmail.com:0.2.6 FF - prefs.js..extensions.enabledItems: {6ad56361-628f-471b-8f9d-4c338973a87d}:5.27.1.1 FF - prefs.js..extensions.enabledItems: facepad@lazyrussian.com:0.5.8 FF - prefs.js..extensions.enabledItems: {6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}:1.2.3 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.9 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0 FF - prefs.js..extensions.enabledItems: myspacefftb@myspace.com:1.0.45.0 FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.0.3 FF - prefs.js..extensions.enabledItems: {1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}:2.1.2 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546 FF - prefs.js..extensions.enabledItems: plugin@yontoo.com:1.03.01 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11 FF - prefs.js..extensions.enabledItems: glowyblue-ff3-30@glowplug.bitasylum.net:3.1.3.1 FF - prefs.js..extensions.enabledItems: glowygreen-ff3-30@glowplug.bitasylum.net:3.1.3.1 FF - prefs.js..extensions.enabledItems: {a02c0c70-605c-11da-8cd6-0800200c9a66}:4.08 FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr=chrff-brandt_off&type=000106X001US&p=" FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2009/06/06 17:52:47 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\myspacefftb@myspace.com: C:\Program Files\MySpace\Toolbar\1.0.45.0\ File not found FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/05/11 00:23:23 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/02/04 15:01:14 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/06/14 18:17:53 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/06/14 18:17:53 | 00,000,000 | ---D | M] [2009/02/18 22:41:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Extensions [2008/11/09 03:09:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/02/18 22:41:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Extensions\mozswing@mozswing.org [2009/06/22 19:39:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions [2009/04/14 20:18:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2009/04/16 14:18:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37} [2009/04/13 14:12:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{469CEB59-8266-438b-91D9-82F56D595E15} [2009/02/04 11:42:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2009/04/13 14:12:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{64161300-e22b-11db-8314-0800200c9a66} [2009/03/24 15:39:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{6ad56361-628f-471b-8f9d-4c338973a87d} [2009/04/13 14:12:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3} [2008/11/09 03:09:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66} [2009/04/16 15:36:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\anycolor.pavlos256@gmail.com [2009/05/09 13:05:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\facepad@lazyrussian.com [2009/04/13 14:06:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\firefox@ghostery.com [2009/03/07 15:04:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\glowyblue-ff3-30@glowplug.bitasylum.net [2009/03/07 15:04:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\glowygreen-ff3-30@glowplug.bitasylum.net [2009/04/13 21:31:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\plugin@yontoo.com [2009/03/24 03:19:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\starpulsetoolbar@starpulse.com [2009/01/17 22:01:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\CHRISTINA\Application Data\mozilla\Firefox\Profiles\tcsd8sk1.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}\chrome\mozapps\extensions [2009/03/24 15:39:52 | 00,001,741 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\aol-search.xml [2008/11/09 04:39:31 | 00,002,273 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\ask.xml [2009/03/19 18:12:34 | 00,002,158 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\MySpace.xml [2007/05/06 21:10:43 | 00,002,386 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\siteadvisor.xml [2009/04/14 20:18:59 | 00,001,196 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\winamp-search.xml [2008/11/09 04:39:31 | 00,000,567 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\FireFox\Profiles\tcsd8sk1.default\searchplugins\yahoo.xml [2009/06/22 19:39:14 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2007/05/20 21:19:14 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{4be68a18-deba-49e0-9e09-ee7796f3b62a}(2) [2009/06/14 18:17:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2007/05/23 19:31:43 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [2009/02/04 15:02:31 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2009/05/12 11:20:21 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [2009/06/14 18:17:45 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/06/14 18:17:45 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009/03/09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll [2007/12/17 13:16:14 | 00,065,536 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npkimi.dll [2007/08/20 17:45:02 | 01,431,936 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll [2009/06/14 18:17:47 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2008/10/14 22:33:30 | 00,095,600 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2009/05/01 17:26:51 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2009/05/01 17:26:51 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2009/05/01 17:26:51 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2009/05/01 17:26:51 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2009/05/01 17:26:52 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2009/05/01 17:26:52 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2009/05/01 17:26:52 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2007/03/09 19:16:44 | 00,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll [2008/09/24 21:21:16 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2008/09/24 21:21:16 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2008/09/24 21:21:16 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2008/11/14 15:40:37 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2008/09/24 21:21:16 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2008/09/24 21:21:16 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2008/09/24 21:21:16 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll (Yahoo! Inc.) O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll () O2 - BHO: (MySpace Toolbar) - {28AED1AF-B164-44CD-B435-CF04AA955015} - C:\Program Files\MySpace\Toolbar\1.0.45.0\MySpaceToolbar.dll () O2 - BHO: (AOL Radio Toolbar Loader) - {2abdb2f7-4cbf-4939-ba12-fddc827b6a2d} - C:\Program Files\AOL Radio Toolbar\aolradiotb.dll (AOL LLC.) O2 - BHO: (Yahoo! IE Suggest) - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll (Yahoo! Inc.) O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\dla\tfswshx.dll (Sonic Solutions) O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC) O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.) O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll () O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll (Yontoo Technology, Inc.) O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\YTSingleInstance.dll (Yahoo! Inc) O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll () O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKLM\..\Toolbar: (MySpace Toolbar) - {28AED1AF-B164-44CD-B435-CF04AA955015} - C:\Program Files\MySpace\Toolbar\1.0.45.0\MySpaceToolbar.dll () O3 - HKLM\..\Toolbar: (AOL Radio Toolbar) - {9167da98-6f9b-46f1-991d-826cae46cab6} - C:\Program Files\AOL Radio Toolbar\aolradiotb.dll (AOL LLC.) O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC) O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Fast Browser Search) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - Reg Error: Value error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (AOL Radio Toolbar) - {9167DA98-6F9B-46F1-991D-826CAE46CAB6} - C:\Program Files\AOL Radio Toolbar\aolradiotb.dll (AOL LLC.) O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC) O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll (Yahoo! Inc.) O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) O4 - HKCU..\Run: [SRS Audio Sandbox] C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe (SRS Labs, Inc.) O4 - HKCU..\Run: [YahooWidgetEngine.exe] C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] File not found O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - Startup: C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE () O4 - Startup: C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Sony Corporation) O4 - Startup: C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (Yahoo! Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O8 - Extra context menu item: &AOL Radio Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL Radio Toolbar\ieToolbar\resources\en-US\local\search.html () O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html () O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html () O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta () O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200707...ex/qtplugin.cab (QuickTime Object) O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b...heckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock...director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support) O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control) O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab (Reg Error: Value error.) O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo...toUploader3.cab (Facebook Photo Uploader 4 Control) O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Value error.) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1175811264578 (MUWebControl Class) O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Value error.) O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab (Groove Control) O16 - DPF: {885BB46A-3F1E-44C3-A01B-A7D9260CC98B} http://updates.installshield.com/CAB/dwusplay.cab (InstallShield Update Service Setup Player) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Value error.) O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control) O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} http://aolsvc.aol.com/onlinegames/free-tri...tg.1.0.0.33.cab (CPlayFirstddfotgControl Object) O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} http://rockyou.com/RockYouImageUploader.cab (RockYou Image Uploader Control) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab (Shockwave Flash Object) O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in...l/installer.exe (Virtools WebPlayer Class) O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} http://imikimi.com/download/imikimi_plugin.cab (Imikimi_activex_plugin Control) O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E...04/clearadj.cab (CTAdjust Class) O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} http://www.imagestation.com/common/classes....cab?v=1,0,0,38 (AxRUploadControl Object) O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su2...15106/CTPID.cab (Creative Software AutoUpdate Support Package) O16 - DPF: {FA945BB6-9D37-43FC-9B2A-AF09F56CBBF0} http://yme.music.yahoo.com/qos/cabs/DiagCo...tionControl.cab (moDiagCollectionActiveX Object) O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers...ivex-latest.cab (DownloadManager Control) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254 192.168.254.254 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll () O18 - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\WINDOWS\Downloaded Program Files\mimectl.dll () O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation) O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2002/09/03 10:59:58 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found ========== Files/Folders - Created Within 30 Days ========== [4 C:\WINDOWS\*.tmp files] [2009/06/24 02:43:40 | 00,512,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\CHRISTINA\Desktop\OTL.exe [2009/06/24 02:13:40 | 00,000,000 | ---D | C] -- C:\Rooter$ [2009/06/24 02:04:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\CHRISTINA\Application Data\Malwarebytes [2009/06/24 02:04:01 | 00,000,714 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2009/06/24 02:03:58 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/06/24 02:03:56 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009/06/24 02:03:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2009/06/24 02:03:55 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009/06/24 02:02:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2009/06/24 01:59:33 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2009/06/24 01:59:21 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\CHRISTINA\Desktop\NTREGOPT.lnk [2009/06/24 01:59:21 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\CHRISTINA\Desktop\ERUNT.lnk [2009/06/24 01:59:19 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT [2009/06/24 01:02:16 | 00,001,740 | ---- | C] () -- C:\Documents and Settings\CHRISTINA\Desktop\HijackThis.lnk [2009/06/23 20:09:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\IObit [2009/06/17 15:07:04 | 00,032,256 | ---- | C] () -- C:\Christina's Documents\Coverletter (Autosaved).doc [2009/06/11 08:07:10 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll [2009/06/11 08:07:10 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll [2009/06/04 01:54:03 | 00,000,162 | -H-- | C] () -- C:\Christina's Documents\~$verletter.doc [2009/06/01 15:56:47 | 00,027,648 | ---- | C] () -- C:\Christina's Documents\Bio on Greg Gatliff.doc [2009/05/31 18:38:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\CHRISTINA\Application Data\gtk-2.0 [2009/05/31 18:33:19 | 00,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0 [2009/05/27 00:50:00 | 00,270,336 | ---- | C] () -- C:\Christina's Documents\StateApp copy.doc [2009/05/27 00:49:37 | 00,270,336 | ---- | C] () -- C:\Christina's Documents\StateApp (Autosaved).doc [2009/05/25 20:37:53 | 00,000,000 | ---D | C] -- C:\Christina's Documents\MapView [2009/01/17 13:47:27 | 00,031,616 | ---- | C] () -- C:\WINDOWS\System32\drivers\livecamv.sys [2008/11/18 20:04:29 | 00,000,090 | ---- | C] () -- C:\WINDOWS\QBChanUtil_Trigger.ini [2007/09/27 11:51:02 | 00,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini [2007/09/27 11:48:48 | 00,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini [2007/09/27 11:48:28 | 00,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini [2007/05/30 11:02:15 | 00,458,752 | ---- | C] () -- C:\WINDOWS\System32\VagalumePluginWMP.dll [2007/05/14 05:44:53 | 00,129,078 | ---- | C] () -- C:\WINDOWS\logow.sys [2007/05/14 05:44:53 | 00,129,078 | ---- | C] () -- C:\WINDOWS\logos.sys [2007/05/13 20:32:55 | 00,000,000 | ---- | C] () -- C:\WINDOWS\WB.ini [2007/05/05 20:30:44 | 00,040,448 | ---- | C] () -- C:\WINDOWS\System32\regobj.dll [2007/04/27 12:31:07 | 00,002,568 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys [2007/04/27 12:31:07 | 00,000,088 | RHS- | C] () -- C:\WINDOWS\System32\566C526187.sys [2007/04/25 22:32:55 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\wbload.dll [2007/04/20 22:01:55 | 00,006,048 | ---- | C] () -- C:\WINDOWS\System32\MCC16.dll [2007/04/19 19:04:50 | 00,046,592 | R--- | C] () -- C:\WINDOWS\System32\drivers\tshd4_kern_i386.sys [2007/04/19 19:04:50 | 00,044,416 | R--- | C] () -- C:\WINDOWS\System32\drivers\Surroundhp_kern_i386.sys [2007/04/19 19:04:50 | 00,038,400 | R--- | C] () -- C:\WINDOWS\System32\drivers\SRS_SSCFilter_i386.sys [2007/04/19 19:04:50 | 00,037,248 | R--- | C] () -- C:\WINDOWS\System32\drivers\csiidecoder_kern_i386.sys [2007/02/18 18:39:06 | 00,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini [2005/09/13 17:27:08 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\dlbacnv4.dll [2005/07/11 16:27:34 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2005/04/29 18:51:57 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Textart.INI [2005/04/18 22:13:24 | 00,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll [2005/03/20 15:41:20 | 00,071,749 | ---- | C] () -- C:\WINDOWS\hcextoutput.dll [2005/03/20 15:41:20 | 00,000,823 | ---- | C] () -- C:\WINDOWS\tsc.ini [2005/03/20 15:08:02 | 00,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini [2004/11/18 19:16:45 | 00,000,026 | ---- | C] () -- C:\WINDOWS\UP9ASP.INI [2004/10/06 18:17:11 | 00,000,035 | ---- | C] () -- C:\WINDOWS\A6W.INI [2004/09/25 17:03:15 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI [2004/07/07 19:00:48 | 00,000,000 | ---- | C] () -- C:\WINDOWS\netscape.INI [2004/06/12 17:39:51 | 00,000,021 | ---- | C] () -- C:\WINDOWS\DVDSentry.ini [2004/05/29 16:01:40 | 00,004,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys [2004/05/21 20:08:10 | 00,000,930 | ---- | C] () -- C:\WINDOWS\System32\ncase.ini [2004/02/18 20:49:35 | 00,002,743 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini [2004/01/29 19:07:39 | 00,000,106 | ---- | C] () -- C:\WINDOWS\AtxTCBizPref03.ini [2004/01/26 23:33:03 | 00,000,174 | ---- | C] () -- C:\WINDOWS\System32\mcini.ini [2004/01/26 19:02:37 | 00,000,973 | ---- | C] () -- C:\WINDOWS\DELLSTAT.INI [2004/01/22 12:00:28 | 00,012,635 | ---- | C] () -- C:\WINDOWS\System32\DAntivirus.ini [2004/01/21 17:55:52 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2004/01/21 17:44:47 | 00,000,513 | ---- | C] () -- C:\WINDOWS\wininit.ini [2004/01/21 17:41:15 | 00,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini [2004/01/21 17:24:58 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2004/01/21 17:24:44 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini [2004/01/21 17:10:52 | 00,000,550 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI [2003/08/14 00:54:00 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini [2003/02/17 19:00:42 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbavs.dll [2003/02/17 19:00:36 | 00,000,177 | ---- | C] () -- C:\WINDOWS\System32\dlbacoin.ini [2003/02/05 13:11:12 | 00,000,126 | ---- | C] () -- C:\WINDOWS\System32\DLBAPLC.INI [2002/10/28 17:31:42 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\cursor.dll [2002/09/03 10:59:58 | 00,000,650 | ---- | C] () -- C:\WINDOWS\WIN.INI [2002/09/03 10:50:58 | 00,000,482 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI [2001/05/07 15:57:20 | 00,137,728 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll [2001/05/07 15:56:30 | 00,660,480 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll [2000/01/06 20:00:00 | 00,024,448 | ---- | C] () -- C:\WINDOWS\System32\proclsvr.drv [2000/01/06 20:00:00 | 00,024,448 | ---- | C] () -- C:\WINDOWS\sysgtime.dll [1999/07/23 14:46:48 | 00,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini [1999/07/23 11:53:20 | 00,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll ========== Files - Modified Within 30 Days ========== [4 C:\WINDOWS\*.tmp files] [2009/06/24 02:55:01 | 00,000,430 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5DBDA0A7-2B36-4C06-A598-91EEF296D77A}.job [2009/06/24 02:43:50 | 00,512,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\CHRISTINA\Desktop\OTL.exe [2009/06/24 02:04:01 | 00,000,714 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2009/06/24 01:59:33 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2009/06/24 01:59:21 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Desktop\NTREGOPT.lnk [2009/06/24 01:59:21 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Desktop\ERUNT.lnk [2009/06/24 01:42:29 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job [2009/06/24 01:05:41 | 00,000,973 | ---- | M] () -- C:\WINDOWS\DELLSTAT.INI [2009/06/24 01:02:16 | 00,001,740 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Desktop\HijackThis.lnk [2009/06/23 23:01:50 | 00,020,755 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF [2009/06/23 22:51:00 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job [2009/06/23 22:41:01 | 00,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL [2009/06/23 22:34:08 | 00,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job [2009/06/23 22:33:57 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/06/23 22:33:53 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT [2009/06/23 22:33:52 | 10,716,97920 | -HS- | M] () -- C:\hiberfil.sys [2009/06/23 22:31:57 | 11,647,862 | -H-- | M] () -- C:\Documents and Settings\CHRISTINA\Local Settings\Application Data\IconCache.db [2009/06/23 10:39:14 | 00,002,568 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys [2009/06/22 01:00:47 | 00,000,340 | ---- | M] () -- C:\WINDOWS\tasks\McQcTask.job [2009/06/21 15:32:36 | 00,021,504 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/06/20 08:35:34 | 00,870,128 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\mcs.rma [2009/06/20 08:35:34 | 00,000,004 | ---- | M] () -- C:\Documents and Settings\CHRISTINA\Application Data\8FE0F8 [2009/06/17 15:07:05 | 00,032,256 | ---- | M] () -- C:\Christina's Documents\Coverletter (Autosaved).doc [2009/06/17 11:27:56 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/06/17 11:27:44 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009/06/15 00:44:49 | 00,000,348 | ---- | M] () -- C:\WINDOWS\tasks\McDefragTask.job [2009/06/12 12:45:32 | 00,329,096 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009/06/12 01:19:12 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2009/06/04 01:54:03 | 00,000,162 | -H-- | M] () -- C:\Christina's Documents\~$verletter.doc [2009/06/01 15:56:47 | 00,027,648 | ---- | M] () -- C:\Christina's Documents\Bio on Greg Gatliff.doc [2009/06/01 12:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe [2009/05/27 00:50:01 | 00,270,336 | ---- | M] () -- C:\Christina's Documents\StateApp copy.doc [2009/05/27 00:49:38 | 00,270,336 | ---- | M] () -- C:\Christina's Documents\StateApp (Autosaved).doc ========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\WINDOWS\explorer.scf:SummaryInformation < End of report > This post has been edited by Cowboylady: Jun 24 2009, 01:08 AM |
|
|
![]() |
Jun 28 2009, 05:49 PM
Post
#2
|
|
![]() Trusted Helper Posts: 8,068 OS: XP Pro |
Hello Cowboylady,
Welcome to Geekstogo. QUOTE Lastly, could you tell me why the email notifications I receive are in spanish? The translator widget on the forum website says spanish, but I do not need it translated to anything and not sure how to change the settings on this. Don't know why that is happening. I will have to investigate. Looking at my own controls I see it says spanish too but I am still getting notifications in English. Now As we will likely be using Notepad please check that word wrap is turned off before you start. To do this, open Notepad, choose Format, then make sure Word Wrap is Un-checked. Word Wrap makes reading your log difficult and may prevent fixes using Notepad from working Next Please download ComboFix from one of these locations: NOTE: If you are guest watching this topic. ComboFix is a very powerful tool. The disclaimer clearly states that you should not use it without supervision. There is good reason for this as ComboFix can, and sometimes does, run into conflict on a computer and render it unusable. Link 1 Link 2 Link 3 * IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply. |
|
|
Jun 29 2009, 12:42 AM
Post
#3
|
|
![]() New Member ![]() Posts: 6 From: Byron, GA OS: Windows XP SP3 |
Attached is combofix.txt. I tried DL the Windows Recovery module and each time it stated unable to download and began the scan anyway. If you know of a way to do differently, please advise.
BTW, thanks for the quick response. ComboFix 09-06-28.02 - CHRISTINA 06/29/2009 2:14:08.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.393 [GMT -4:00] Running from: C:\Documents and Settings\CHRISTINA\Desktop\ComboFix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\patch.exe C:\WINDOWS\system32\ncase.ini . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_IPRIP ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 ))))))))))))))))))))))))))))))) . 2009-06-26 17:55:04 . 2009-06-26 18:10:58 0 d-----w- C:\Documents and Settings\CHRISTINA\Local Settings\Application Data\Plaxo 2009-06-26 17:54:40 . 2009-06-29 06:25:51 0 d-----w- C:\Program Files\Plaxo 2009-06-24 06:13:40 . 2009-06-24 06:18:19 0 d-----w- C:\Rooter$ 2009-06-24 06:04:14 . 2009-06-24 06:04:14 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\Malwarebytes 2009-06-24 06:03:58 . 2009-06-17 15:27:56 38160 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2009-06-24 06:03:56 . 2009-06-24 06:03:56 0 d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2009-06-24 06:03:56 . 2009-06-17 15:27:44 19096 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys 2009-06-24 06:03:55 . 2009-06-24 06:04:07 0 d-----w- C:\Program Files\Malwarebytes' Anti-Malware 2009-06-24 05:59:19 . 2009-06-24 05:59:34 0 d-----w- C:\Program Files\ERUNT 2009-06-24 00:09:16 . 2009-06-24 00:09:16 0 d-----w- C:\Documents and Settings\All Users\Application Data\IObit 2009-06-16 18:08:38 . 2009-06-16 18:09:28 0 d-----w- C:\Documents and Settings\CHRISTINA\My videos 2009-06-11 12:07:10 . 2009-04-30 21:22:34 12800 -c----w- C:\WINDOWS\system32\dllcache\xpshims.dll 2009-06-11 12:07:10 . 2009-04-30 21:22:31 246272 -c----w- C:\WINDOWS\system32\dllcache\ieproxy.dll 2009-06-11 02:27:05 . 2009-06-11 02:27:05 2173616 ----a-w- C:\Documents and Settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.45.0.exe 2009-05-31 22:38:25 . 2009-05-31 22:38:25 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\gtk-2.0 2009-05-31 22:34:53 . 2009-05-31 22:35:53 0 d-----w- C:\Documents and Settings\CHRISTINA\.gimp-2.6 2009-05-31 22:34:43 . 2009-05-31 22:34:51 0 d-----w- C:\Documents and Settings\CHRISTINA\.gegl-0.0 2009-05-31 22:33:19 . 2009-05-31 22:33:30 0 d-----w- C:\Program Files\GIMP-2.0 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-28 22:29:06 . 2008-11-19 01:55:17 3239 ----a-w- C:\Documents and Settings\All Users\Application Data\Intuit\QuickBooks 2009\qbbackup.sys 2009-06-28 22:21:54 . 2007-04-27 16:31:07 2568 --sha-w- C:\WINDOWS\system32\KGyGaAvL.sys 2009-06-28 21:05:32 . 2009-02-22 15:55:20 0 d-----w- C:\Documents and Settings\All Users\Application Data\Google Updater 2009-06-24 00:09:12 . 2007-05-17 14:35:06 0 d-----w- C:\Program Files\IObit 2009-06-23 21:24:44 . 2007-04-22 07:15:31 0 d-----w- C:\Program Files\Google 2009-06-15 05:02:50 . 2007-10-16 16:37:16 0 d-----w- C:\Documents and Settings\All Users\Application Data\Microsoft Help 2009-06-12 16:45:27 . 2009-01-26 17:17:36 0 d-----w- C:\Program Files\Windows Desktop Search 2009-06-03 00:04:08 . 2007-03-23 16:51:35 0 d-----w- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion 2009-05-25 04:24:06 . 2008-05-27 03:18:26 350208 ------w- C:\WINDOWS\system32\mssph.dll 2009-05-19 21:25:44 . 2009-02-19 12:16:10 0 d-----w- C:\Documents and Settings\NetworkService\Application Data\SACore 2009-05-19 15:31:27 . 2009-05-19 14:41:14 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\Trondent Development Corp 2009-05-19 15:12:39 . 2008-11-26 18:38:45 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\IObit 2009-05-19 14:40:46 . 2004-01-21 21:42:40 0 d--h--w- C:\Program Files\InstallShield Installation Information 2009-05-13 05:15:55 . 2006-06-23 15:33:58 915456 ----a-w- C:\WINDOWS\system32\wininet.dll 2009-05-12 19:12:14 . 2005-05-15 23:53:54 26144 ----a-w- C:\WINDOWS\system32\spupdsvc.exe 2009-05-12 15:20:01 . 2004-01-21 21:34:30 0 d-----w- C:\Program Files\Java 2009-05-12 15:18:12 . 2009-05-11 15:30:02 152576 ----a-w- C:\Documents and Settings\CHRISTINA\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-05-11 16:19:29 . 2009-05-11 16:19:29 0 d-----w- C:\Documents and Settings\NetworkService\Application Data\MySpace 2009-05-11 16:19:13 . 2009-05-11 16:19:13 0 d-----w- C:\Documents and Settings\NetworkService\Application Data\Yahoo! 2009-05-11 11:13:07 . 2004-01-26 23:01:47 91544 ----a-w- C:\Documents and Settings\CHRISTINA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-11 04:47:57 . 2004-02-25 20:04:25 0 d-----w- C:\Program Files\Microsoft Works 2009-05-07 15:32:35 . 2003-07-16 20:32:09 345600 ----a-w- C:\WINDOWS\system32\localspl.dll 2009-05-07 01:23:19 . 2009-05-07 01:23:19 0 d-----w- C:\Program Files\Coupons 2009-05-06 01:53:49 . 2009-05-06 01:53:51 192512 ----a-w- C:\Documents and Settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\ICSharpCode.SharpZipLib.dll 2009-05-06 01:53:49 . 2008-11-19 16:34:43 861448 ----a-w- C:\Documents and Settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManager.exe 2009-05-06 01:53:49 . 2008-11-19 16:34:43 38664 ----a-w- C:\Documents and Settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManagerPatch.exe 2009-05-04 02:40:34 . 2007-08-06 22:34:58 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\Apple Computer 2009-05-04 01:08:02 . 2007-06-17 17:21:19 0 d-----w- C:\Documents and Settings\CHRISTINA\Application Data\LimeWire 2009-05-01 23:34:40 . 2009-01-24 20:03:48 0 d-----w- C:\Program Files\LimeWire 2009-05-01 21:30:08 . 2009-05-01 21:29:30 0 d-----w- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-05-01 21:30:08 . 2008-12-29 21:35:41 0 d-----w- C:\Program Files\iTunes 2009-05-01 21:29:35 . 2009-05-01 21:29:35 0 d-----w- C:\Program Files\iPod 2009-05-01 21:29:34 . 2007-08-06 22:30:08 0 d-----w- C:\Program Files\Common Files\Apple 2009-05-01 21:26:50 . 2009-05-01 21:25:46 0 d-----w- C:\Program Files\QuickTime 2009-05-01 21:17:47 . 2009-05-01 21:17:47 75048 ----a-w- C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe 2009-05-01 21:15:06 . 2008-03-21 17:05:24 0 d-----w- C:\Program Files\Safari 2009-05-01 01:23:53 . 2009-05-01 01:23:54 1893936 ----a-w- C:\Documents and Settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.32.5.exe 2009-04-17 12:26:40 . 2003-07-16 20:51:25 1847168 ----a-w- C:\WINDOWS\system32\win32k.sys 2009-04-15 14:51:25 . 2004-03-06 02:16:11 585216 ----a-w- C:\WINDOWS\system32\rpcrt4.dll 2009-04-03 22:28:06 . 2009-04-03 22:28:10 1892856 ----a-w- C:\Documents and Settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.32.0.exe 2009-04-03 00:37:02 . 2009-04-14 16:06:47 36864 --s-a-r- C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll 2007-04-26 23:41:30 . 2007-04-26 23:38:01 33032192 ----a-w- C:\Program Files\WP11SP1_EN.msp 2007-04-24 19:34:56 . 2007-04-24 19:30:11 353598016 ----a-w- C:\Program Files\SimpleStartFSEDirect.exe 2007-04-21 02:13:44 . 2007-04-21 02:13:51 774144 ----a-w- C:\Program Files\RngInterstitial.dll 2007-05-04 13:57:08 . 2007-04-27 16:31:07 88 --sh--r- C:\WINDOWS\SYSTEM32\566C526187.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] 2009-04-01 17:16:19 193472 ------w- C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SRS Audio Sandbox"="C:\Program Files\SRS Labs\Audio Sandbox2\SRSSSC.exe" [2007-03-16 19:22:00 3153920] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 00:12:16 15360] "YahooWidgetEngine.exe"="C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe" [2007-07-20 17:57:16 2913584] "PlaxoUpdate"="C:\Program Files\Plaxo\3.20.0.13\PlaxoHelper_en.exe" [2009-05-01 15:30:36 379463] "PlaxoSysTray"="C:\Program Files\Plaxo\3.20.0.13\PlaxoSysTray.exe" [2009-05-01 15:29:20 20480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2009-01-09 01:30:26 645328] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2009-01-05 20:18:48 413696] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 05:44:24 435096] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-14 00:04:18 5562368] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-27 15:24:23 68856] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "VF0560Inst"="C:\WINDOWS\system32\V0560Pin.dll" [2008-06-02 01:00:00 40960] C:\Documents and Settings\CHRISTINA\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-24 344064] Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-7-20 2913584] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 02:41:34 304128] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\SoundSpectrum\\G-Force\\G-Force V-Bar.exe"= "C:\\WINDOWS\\SYSTEM32\\ControlSuite.exe"= "C:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Standalone.exe"= "C:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Toolbar.exe"= "C:\\Program Files\\Yahoo!\\Widgets\\YahooWidgetEngine.exe"= "C:\\Program Files\\Sonic\\RecordNow!\\RecordNow.exe"= "C:\\Program Files\\Intel\\NCS\\PROSet\\PROSet.exe"= "C:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"= "C:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"= "C:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"= "C:\\Program Files\\InterActual\\InterActual Player\\iPlayer.exe"= "C:\\WINDOWS\\system32\\sessmgr.exe"= "C:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Yahoo! Games\\Bejeweled 2 Deluxe\\WinBej2.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Program Files\\Windows Media Player\\wmplayer.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Rhapsody\\WiseUpd2.exe"= "C:\\Program Files\\Flickr Uploadr\\Flickr Uploadr.exe"= "C:\\Program Files\\Mozilla Firefox\\firefox.exe"= "C:\\Program Files\\Intuit\\QuickBooks 2009\\QBW32SimplestartLimited.exe"= R2 IntuitUpdateService;Intuit Update Service;C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [12/9/2008 1:37:02 PM 13088] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2/9/2009 2:48:11 PM 210216] R2 WinDefend;Windows Defender;C:\Program Files\Windows Defender\MsMpEng.exe [11/3/2006 7:19:58 PM 13592] R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;C:\WINDOWS\SYSTEM32\DRIVERS\livecamv.sys [1/17/2009 1:47:27 PM 31616] R3 V0560Afx;Creative Camera VF0560 Audio Effects Driver;C:\WINDOWS\SYSTEM32\DRIVERS\V0560Afx.sys [1/17/2009 1:49:44 PM 160768] R3 V0560Vid;Creative Live! Cam Optia AF Driver;C:\WINDOWS\SYSTEM32\DRIVERS\V0560Vid.sys [1/17/2009 1:49:26 PM 286592] S2 gupdate1c995062274baac;Google Update Service (gupdate1c995062274baac);C:\Program Files\Google\Update\GoogleUpdate.exe [2/22/2009 11:56:31 AM 133104] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\WINDOWS\system32\DRIVERS\CtClsFlt.sys --> C:\WINDOWS\system32\DRIVERS\CtClsFlt.sys [?] S3 IS360service;IS360service;C:\Program Files\IObit\IObit Security 360\IS360srv.exe [6/23/2009 8:09:14 PM 224528] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-06-29 C:\WINDOWS\Tasks\Google Software Updater.job - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-22 07:15:37 . 2009-03-24 17:07:43] 2009-06-29 C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job - C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-22 15:56:31 . 2009-02-22 15:56:23] 2009-06-15 C:\WINDOWS\Tasks\McDefragTask.job - c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2009-02-09 19:47:53 . 2009-01-09 15:53:12] 2009-06-29 C:\WINDOWS\Tasks\McQcTask.job - c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2009-02-09 19:47:53 . 2009-01-09 15:53:12] 2009-06-29 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20:06 . 2006-11-03 23:20:06] 2009-06-29 C:\WINDOWS\Tasks\User_Feed_Synchronization-{5DBDA0A7-2B36-4C06-A598-91EEF296D77A}.job - C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 15:58:32 . 2009-03-08 08:31:54] . - - - - ORPHANS REMOVED - - - - HKU-Default-Run-AOL Fast Start - C:\Program Files\AOL 9.0a\AOL.EXE . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uStart Page = hxxp://www.aol.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com IE: &AOL Radio Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL Radio Toolbar\ieToolbar\resources\en-US\local\search.html IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html IE: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll DPF: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin.cab FF - ProfilePath - C:\Documents and Settings\CHRISTINA\Application Data\Mozilla\Firefox\Profiles\tcsd8sk1.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc7&p= FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=chrff-brandt_off&type=000106X001US&p= FF - component: C:\Program Files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - component: C:\Program Files\MySpace\Toolbar\1.0.45.0\components\MySpaceFFoxTB.dll FF - plugin: C:\Program Files\Google\Google Earth Plugin\npgeplugin.dll FF - plugin: C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: C:\Program Files\Google\Update\1.2.145.5\npGoogleOneClick8.dll FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npkimi.dll FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll FF - plugin: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- FF - user.js: browser.cache.memory.capacity - 16000 FF - user.js: browser.chrome.favicons - fales FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 4095 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 1000000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 1000000 FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service FF - user.js: dom.disable_window_status_change - true FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 1000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . |
|
|
Jun 29 2009, 01:17 AM
Post
#4
|
|
![]() Trusted Helper Posts: 8,068 OS: XP Pro |
Hello Cowboylady,
Looks like that Combofix txt go cut off. Please post the rest. Also do you know about this program? IObit Security 360 |
|
|
Jun 29 2009, 08:41 AM
Post
#5
|
|
![]() New Member ![]() Posts: 6 From: Byron, GA OS: Windows XP SP3 |
Hello Cowboylady, Looks like that Combofix txt go cut off. Please post the rest. Also do you know about this program? IObit Security 360 Hi! Sorry about that. It was really late here last night when posted. I have Iobit Security 360. Just downloaded last week, but only have the free version (or beta.) I also have Advanced Windows Care Pro but do not keep it running all the time (as well as Windows Defender) due to conflicts with McAfee which I run at all times. I am not very impressed with WD and it can actually be uninstalled or inactivated to keep from conflict with McAfee but I do like some of the additional features AWS offers so I would like to keep. The other concerns beside malware or other that might be slowing my computer down are processes that run that are not necessary and I do not know how to modify (or recognize them all) so that they do not restart. Here is a brief run down of processes I terminate manually when computer gets slow, but they are set up to restart immediately. I don't know how to determine if they are actually bogging things down or not also so if you can give me a little help with that too I would appreciate.
Thanks, Here is complete log file of Combofix: ComboFix 09-06-28.02 - CHRISTINA 06/29/2009 2:14.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.393 [GMT -4:00] Running from: c:\documents and settings\CHRISTINA\Desktop\ComboFix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\patch.exe c:\windows\system32\ncase.ini . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_IPRIP ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 ))))))))))))))))))))))))))))))) . 2009-06-26 17:55 . 2009-06-26 18:10 -------- d-----w- c:\documents and settings\CHRISTINA\Local Settings\Application Data\Plaxo 2009-06-26 17:54 . 2009-06-29 06:25 -------- d-----w- c:\program files\Plaxo 2009-06-24 06:13 . 2009-06-24 06:18 -------- d-----w- C:\Rooter$ 2009-06-24 06:04 . 2009-06-24 06:04 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Malwarebytes 2009-06-24 06:03 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-24 06:03 . 2009-06-24 06:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-24 06:03 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-24 06:03 . 2009-06-24 06:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-24 05:59 . 2009-06-24 05:59 -------- d-----w- c:\program files\ERUNT 2009-06-24 00:09 . 2009-06-24 00:09 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit 2009-06-16 18:08 . 2009-06-16 18:09 -------- d-----w- c:\documents and settings\CHRISTINA\My videos 2009-06-11 12:07 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-06-11 12:07 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-11 02:27 . 2009-06-11 02:27 2173616 ----a-w- c:\documents and settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.45.0.exe 2009-05-31 22:38 . 2009-05-31 22:38 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\gtk-2.0 2009-05-31 22:34 . 2009-05-31 22:35 -------- d-----w- c:\documents and settings\CHRISTINA\.gimp-2.6 2009-05-31 22:34 . 2009-05-31 22:34 -------- d-----w- c:\documents and settings\CHRISTINA\.gegl-0.0 2009-05-31 22:33 . 2009-05-31 22:33 -------- d-----w- c:\program files\GIMP-2.0 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-28 22:29 . 2008-11-19 01:55 3239 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\qbbackup.sys 2009-06-28 22:21 . 2007-04-27 16:31 2568 --sha-w- c:\windows\system32\KGyGaAvL.sys 2009-06-28 21:05 . 2009-02-22 15:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2009-06-24 00:09 . 2007-05-17 14:35 -------- d-----w- c:\program files\IObit 2009-06-23 21:24 . 2007-04-22 07:15 -------- d-----w- c:\program files\Google 2009-06-15 05:02 . 2007-10-16 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-06-12 16:45 . 2009-01-26 17:17 -------- d-----w- c:\program files\Windows Desktop Search 2009-06-03 00:04 . 2007-03-23 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion 2009-05-25 04:24 . 2008-05-27 03:18 350208 ------w- c:\windows\system32\mssph.dll 2009-05-19 21:25 . 2009-02-19 12:16 -------- d-----w- c:\documents and settings\NetworkService\Application Data\SACore 2009-05-19 15:31 . 2009-05-19 14:41 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Trondent Development Corp 2009-05-19 15:12 . 2008-11-26 18:38 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\IObit 2009-05-19 14:40 . 2004-01-21 21:42 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-05-13 05:15 . 2006-06-23 15:33 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-12 19:12 . 2005-05-15 23:53 26144 ----a-w- c:\windows\system32\spupdsvc.exe 2009-05-12 15:20 . 2004-01-21 21:34 -------- d-----w- c:\program files\Java 2009-05-12 15:18 . 2009-05-11 15:30 152576 ----a-w- c:\documents and settings\CHRISTINA\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-05-11 16:19 . 2009-05-11 16:19 -------- d-----w- c:\documents and settings\NetworkService\Application Data\MySpace 2009-05-11 16:19 . 2009-05-11 16:19 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Yahoo! 2009-05-11 11:13 . 2004-01-26 23:01 91544 ----a-w- c:\documents and settings\CHRISTINA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-11 04:47 . 2004-02-25 20:04 -------- d-----w- c:\program files\Microsoft Works 2009-05-07 15:32 . 2003-07-16 20:32 345600 ----a-w- c:\windows\system32\localspl.dll 2009-05-07 01:23 . 2009-05-07 01:23 -------- d-----w- c:\program files\Coupons 2009-05-06 01:53 . 2009-05-06 01:53 192512 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\ICSharpCode.SharpZipLib.dll 2009-05-06 01:53 . 2008-11-19 16:34 861448 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManager.exe 2009-05-06 01:53 . 2008-11-19 16:34 38664 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManagerPatch.exe 2009-05-04 02:40 . 2007-08-06 22:34 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Apple Computer 2009-05-04 01:08 . 2007-06-17 17:21 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\LimeWire 2009-05-01 23:34 . 2009-01-24 20:03 -------- d-----w- c:\program files\LimeWire 2009-05-01 21:30 . 2009-05-01 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-05-01 21:30 . 2008-12-29 21:35 -------- d-----w- c:\program files\iTunes 2009-05-01 21:29 . 2009-05-01 21:29 -------- d-----w- c:\program files\iPod 2009-05-01 21:29 . 2007-08-06 22:30 -------- d-----w- c:\program files\Common Files\Apple 2009-05-01 21:26 . 2009-05-01 21:25 -------- d-----w- c:\program files\QuickTime 2009-05-01 21:17 . 2009-05-01 21:17 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe 2009-05-01 21:15 . 2008-03-21 17:05 -------- d-----w- c:\program files\Safari 2009-05-01 01:23 . 2009-05-01 01:23 1893936 ----a-w- c:\documents and settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.32.5.exe 2009-04-17 12:26 . 2003-07-16 20:51 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2004-03-06 02:16 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-03 22:28 . 2009-04-03 22:28 1892856 ----a-w- c:\documents and settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.32.0.exe 2009-04-03 00:37 . 2009-04-14 16:06 36864 --s-a-r- c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll 2007-04-26 23:41 . 2007-04-26 23:38 33032192 ----a-w- c:\program files\WP11SP1_EN.msp 2007-04-24 19:34 . 2007-04-24 19:30 353598016 ----a-w- c:\program files\SimpleStartFSEDirect.exe 2007-04-21 02:13 . 2007-04-21 02:13 774144 ----a-w- c:\program files\RngInterstitial.dll 2007-05-04 13:57 . 2007-04-27 16:31 88 --sh--r- c:\windows\SYSTEM32\566C526187.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] 2009-04-01 17:16 193472 ------w- c:\program files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SRS Audio Sandbox"="c:\program files\SRS Labs\Audio Sandbox2\SRSSSC.exe" [2007-03-16 3153920] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "YahooWidgetEngine.exe"="c:\program files\Yahoo!\Widgets\YahooWidgetEngine.exe" [2007-07-20 2913584] "PlaxoUpdate"="c:\program files\Plaxo\3.20.0.13\PlaxoHelper_en.exe" [2009-05-01 379463] "PlaxoSysTray"="c:\program files\Plaxo\3.20.0.13\PlaxoSysTray.exe" [2009-05-01 20480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096] "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-08-14 5562368] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-27 68856] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "VF0560Inst"="c:\windows\system32\V0560Pin.dll" [2008-06-02 40960] c:\documents and settings\CHRISTINA\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-24 344064] Yahoo! Widget Engine.lnk - c:\program files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-7-20 2913584] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force V-Bar.exe"= "c:\\WINDOWS\\SYSTEM32\\ControlSuite.exe"= "c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Standalone.exe"= "c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Toolbar.exe"= "c:\\Program Files\\Yahoo!\\Widgets\\YahooWidgetEngine.exe"= "c:\\Program Files\\Sonic\\RecordNow!\\RecordNow.exe"= "c:\\Program Files\\Intel\\NCS\\PROSet\\PROSet.exe"= "c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"= "c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"= "c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"= "c:\\Program Files\\InterActual\\InterActual Player\\iPlayer.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Yahoo! Games\\Bejeweled 2 Deluxe\\WinBej2.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Windows Media Player\\wmplayer.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Rhapsody\\WiseUpd2.exe"= "c:\\Program Files\\Flickr Uploadr\\Flickr Uploadr.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Intuit\\QuickBooks 2009\\QBW32SimplestartLimited.exe"= R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [12/9/2008 1:37 PM 13088] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2/9/2009 2:48 PM 210216] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592] R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;c:\windows\SYSTEM32\DRIVERS\livecamv.sys [1/17/2009 1:47 PM 31616] R3 V0560Afx;Creative Camera VF0560 Audio Effects Driver;c:\windows\SYSTEM32\DRIVERS\V0560Afx.sys [1/17/2009 1:49 PM 160768] R3 V0560Vid;Creative Live! Cam Optia AF Driver;c:\windows\SYSTEM32\DRIVERS\V0560Vid.sys [1/17/2009 1:49 PM 286592] S2 gupdate1c995062274baac;Google Update Service (gupdate1c995062274baac);c:\program files\Google\Update\GoogleUpdate.exe [2/22/2009 11:56 AM 133104] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys --> c:\windows\system32\DRIVERS\CtClsFlt.sys [?] S3 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [6/23/2009 8:09 PM 224528] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-06-29 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-22 17:07] 2009-06-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-22 15:56] 2009-06-15 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-09 15:53] 2009-06-29 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-09 15:53] 2009-06-29 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20] 2009-06-29 c:\windows\Tasks\User_Feed_Synchronization-{5DBDA0A7-2B36-4C06-A598-91EEF296D77A}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 08:31] . - - - - ORPHANS REMOVED - - - - HKU-Default-Run-AOL Fast Start - c:\program files\AOL 9.0a\AOL.EXE . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uStart Page = hxxp://www.aol.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com IE: &AOL Radio Toolbar Search - c:\documents and settings\All Users\Application Data\AOL Radio Toolbar\ieToolbar\resources\en-US\local\search.html IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin.cab FF - ProfilePath - c:\documents and settings\CHRISTINA\Application Data\Mozilla\Firefox\Profiles\tcsd8sk1.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc7&p= FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=chrff-brandt_off&type=000106X001US&p= FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - component: c:\program files\MySpace\Toolbar\1.0.45.0\components\MySpaceFFoxTB.dll FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- FF - user.js: browser.cache.memory.capacity - 16000 FF - user.js: browser.chrome.favicons - fales FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 4095 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 1000000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 1000000 FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service FF - user.js: dom.disable_window_status_change - true FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 1000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-29 02:25 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(1788) c:\windows\system32\WININET.dll c:\program files\McAfee\SiteAdvisor\saHook.dll c:\program files\Plaxo\3.20.0.13\plx_hook.dll c:\program files\Windows Desktop Search\deskbar.dll c:\program files\Windows Desktop Search\en-us\dbres.dll.mui c:\program files\Windows Desktop Search\dbres.dll c:\program files\Windows Desktop Search\wordwheel.dll c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui c:\program files\Windows Desktop Search\msnlExtRes.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\SYSTEM32\LEXBCES.EXE c:\windows\SYSTEM32\LEXPPS.EXE c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Motive\McciCMService.exe c:\windows\SYSTEM32\PSIService.exe c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe c:\windows\SYSTEM32\tcpsvcs.exe c:\windows\SYSTEM32\snmp.exe c:\windows\SYSTEM32\fxssvc.exe c:\windows\SYSTEM32\searchindexer.exe c:\windows\SYSTEM32\wscntfy.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\program files\Common Files\McAfee\MNA\McNASvc.exe c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe c:\progra~1\McAfee.com\Agent\mcagent.exe c:\windows\SYSTEM32\notepad.exe c:\program files\McAfee\MPF\MpfSrv.exe c:\windows\SYSTEM32\searchprotocolhost.exe . ************************************************************************** . Completion time: 2009-06-29 2:36 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-29 06:35 Pre-Run: 43,616,731,136 bytes free Post-Run: 43,548,700,672 bytes free 298 --- E O F --- 2009-06-23 04:11 |
|
|
Jun 29 2009, 05:37 PM
Post
#6
|
|
![]() Trusted Helper Posts: 8,068 OS: XP Pro |
Hi Cowboylady,
The reason I asked you about the IObit Security 360 was because it is a beta version and in testing mode. Often there can be problems with bugs or conflict with products in beta and I was thinking about the symptoms your machine was experiencing and wondering if there was a connection. QUOTE Advanced Windows Care Pro Personally I am not a fan of any products that include registry cleaners. It is generally not necessary to clean your registry. Registry cleaners are notorious for causing problems on peoples computers. Often the problem doesn't appear until well down the track. A small change to the registry can go unnoticed until one day you call on that function and find it won't work anymore or alternatively an associated utility doesn't work properly. QUOTE Windows Defender It is my understanding that usually your anti-virus will turn off Windows Defender when you first install it. This to ensure there is no conflict. You clearly turn it on and off as you want but just for the record here is how to do it: To disable Windows Defender to prevent it from interfering with our fixes. Go to this link for instructions on how to enable/disable Windows Defender http://windowshelp.microsoft.com/Windows/e...1bf0dc1033.mspx QUOTE other that might be slowing my computer down are processes that run that are not necessary You could try this one: Download and install Startuplite. It is a tool to help you stop some programs not immediately needed from loading when you start your computer. They will begin automatically only when you click on them. Might help a bit. You could also download this: Download and install Auslogics Disk Defrag When it finishes it's defrag it might tell you there are junk files to remove. Take no notice of that...just trying to sell you another product. AFT-Cleaner mentioned next will attend to that for you. Now Please download ATF Cleaner by Atribune.
Under Main choose: Select All Click the Empty Selected button.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. For Technical Support, double-click the e-mail address located at the bottom of each menu. Next You have used Malwarebytes before. If you still have it on your machine please update and run. Post the scan report back here. If you no-longer have Malwarebytes please download from Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Finally in this post Kaspersky on line scanner is very thorough. It can take a long time and for periods may seem not to be working. Just be patient and let it do its job. Kaspersky works with Internet Explorer and Firefox 3. Go to Kaspersky website and perform an online antivirus scan. Note: you will need to turn off your security programs to allow Kaspersky to do its job.
So when you return please post
|
|
|
Jul 2 2009, 03:41 AM
Post
#7
|
|
![]() New Member ![]() Posts: 6 From: Byron, GA OS: Windows XP SP3 |
The logs requested are to follow, however, I have a question about the Kaspersky scan: Did it remove the file that it found from my computer?
-------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Thursday, July 2, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Thursday, July 02, 2009 03:25:15 Records in database: 2413044 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 124772 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 04:00:23 File name / Threat name / Threats count C:\Documents and Settings\CHRISTINA\Shared\anywhere but here jason aldean.mp3 Infected: Trojan-Downloader.WMA.Wimad.r 1 The selected area was scanned. MBAM log: Malwarebytes' Anti-Malware 1.38 Database version: 2357 Windows 5.1.2600 Service Pack 3 7/1/2009 3:06:09 AM mbam-log-2009-07-01 (03-06-09).txt Scan type: Quick Scan Objects scanned: 73922 Time elapsed: 7 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
Jul 2 2009, 04:59 AM
Post
#8
|
|
![]() Trusted Helper Posts: 8,068 OS: XP Pro |
QUOTE Did it remove the file that it found from my computer? Nope, we didn't want it to remove anything in case there was a false positive. We will remove that one though. Now 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: QUOTE KillAll:: File:: C:\Documents and Settings\CHRISTINA\Shared\anywhere but here jason aldean.mp3 Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it will produce a log for you at C:\ComboFix.txt. Please post that here for further review. So when you come back please post
|
|
|
Jul 3 2009, 12:19 PM
Post
#9
|
|
![]() New Member ![]() Posts: 6 From: Byron, GA OS: Windows XP SP3 |
QUOTE Did it remove the file that it found from my computer? Nope, we didn't want it to remove anything in case there was a false positive. We will remove that one though. Now 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: QUOTE KillAll:: File:: C:\Documents and Settings\CHRISTINA\Shared\anywhere but here jason aldean.mp3 Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it will produce a log for you at C:\ComboFix.txt. Please post that here for further review. So when you come back please post
ComboFix 09-07-02.02 - CHRISTINA 07/02/2009 23:27.4 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.565 [GMT -4:00] Running from: c:\documents and settings\CHRISTINA\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\CHRISTINA\Desktop\CFScript.txt AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE :: "c:\documents and settings\CHRISTINA\Shared\anywhere but here jason aldean.mp3" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\CHRISTINA\Shared\anywhere but here jason aldean.mp3 c:\windows\Installer\e047e9.msi . ((((((((((((((((((((((((( Files Created from 2009-06-03 to 2009-07-03 ))))))))))))))))))))))))))))))) . 2009-07-01 16:51 . 2009-07-01 16:51 -------- d-----w- c:\documents and settings\CHRISTINA\Local Settings\Application Data\AOL Email Toolbar 2009-07-01 16:51 . 2009-07-01 16:51 -------- d-----w- c:\program files\Common Files\Software Update Utility 2009-07-01 16:51 . 2009-07-01 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Email Toolbar 2009-07-01 16:51 . 2009-07-01 16:51 -------- d-----w- c:\program files\AOL Email Toolbar 2009-06-30 16:57 . 2009-06-30 16:57 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Auslogics 2009-06-30 16:56 . 2009-06-30 16:56 -------- d-----w- c:\program files\Auslogics 2009-06-26 17:55 . 2009-06-26 18:10 -------- d-----w- c:\documents and settings\CHRISTINA\Local Settings\Application Data\Plaxo 2009-06-26 17:54 . 2009-07-02 10:59 -------- d-----w- c:\program files\Plaxo 2009-06-24 06:13 . 2009-06-24 06:18 -------- d-----w- C:\Rooter$ 2009-06-24 06:04 . 2009-06-24 06:04 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Malwarebytes 2009-06-24 06:03 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-24 06:03 . 2009-06-24 06:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-24 06:03 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-24 06:03 . 2009-06-30 16:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-24 05:59 . 2009-06-24 05:59 -------- d-----w- c:\program files\ERUNT 2009-06-24 00:09 . 2009-06-24 00:09 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit 2009-06-16 18:08 . 2009-06-16 18:09 -------- d-----w- c:\documents and settings\CHRISTINA\My videos 2009-06-11 12:07 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-06-11 12:07 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-11 02:27 . 2009-06-11 02:27 2173616 ----a-w- c:\documents and settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.45.0.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-03 01:09 . 2009-02-22 15:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2009-07-01 19:54 . 2008-11-19 01:55 3239 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\qbbackup.sys 2009-06-28 22:21 . 2007-04-27 16:31 2568 --sha-w- c:\windows\system32\KGyGaAvL.sys 2009-06-24 00:09 . 2007-05-17 14:35 -------- d-----w- c:\program files\IObit 2009-06-23 21:24 . 2007-04-22 07:15 -------- d-----w- c:\program files\Google 2009-06-15 05:02 . 2007-10-16 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-06-12 16:45 . 2009-01-26 17:17 -------- d-----w- c:\program files\Windows Desktop Search 2009-06-03 00:04 . 2007-03-23 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion 2009-05-31 22:38 . 2009-05-31 22:38 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\gtk-2.0 2009-05-31 22:33 . 2009-05-31 22:33 -------- d-----w- c:\program files\GIMP-2.0 2009-05-25 04:24 . 2008-05-27 03:18 350208 ------w- c:\windows\system32\mssph.dll 2009-05-19 21:25 . 2009-02-19 12:16 -------- d-----w- c:\documents and settings\NetworkService\Application Data\SACore 2009-05-19 15:31 . 2009-05-19 14:41 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\Trondent Development Corp 2009-05-19 15:12 . 2008-11-26 18:38 -------- d-----w- c:\documents and settings\CHRISTINA\Application Data\IObit 2009-05-19 14:40 . 2004-01-21 21:42 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-05-13 05:15 . 2006-06-23 15:33 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-12 19:12 . 2005-05-15 23:53 26144 ----a-w- c:\windows\system32\spupdsvc.exe 2009-05-12 15:20 . 2004-01-21 21:34 -------- d-----w- c:\program files\Java 2009-05-12 15:18 . 2009-05-11 15:30 152576 ----a-w- c:\documents and settings\CHRISTINA\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-05-11 16:19 . 2009-05-11 16:19 -------- d-----w- c:\documents and settings\NetworkService\Application Data\MySpace 2009-05-11 16:19 . 2009-05-11 16:19 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Yahoo! 2009-05-11 11:13 . 2004-01-26 23:01 91544 ----a-w- c:\documents and settings\CHRISTINA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-11 04:47 . 2004-02-25 20:04 -------- d-----w- c:\program files\Microsoft Works 2009-05-07 15:32 . 2003-07-16 20:32 345600 ----a-w- c:\windows\system32\localspl.dll 2009-05-07 01:23 . 2009-05-07 01:23 -------- d-----w- c:\program files\Coupons 2009-05-06 01:53 . 2009-05-06 01:53 192512 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\ICSharpCode.SharpZipLib.dll 2009-05-06 01:53 . 2008-11-19 16:34 861448 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManager.exe 2009-05-06 01:53 . 2008-11-19 16:34 38664 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManagerPatch.exe 2009-05-05 18:16 . 2009-05-05 18:16 68608 ----a-w- c:\documents and settings\All Users\Application Data\AOL Email Toolbar\ieToolbar\resources\en-US\aolmailtbres.dll 2009-05-01 21:17 . 2009-05-01 21:17 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe 2009-05-01 01:23 . 2009-05-01 01:23 1893936 ----a-w- c:\documents and settings\CHRISTINA\Application Data\MySpace\Toolbar\Installers\MySpaceToolbar_Setup_1.0.32.5.exe 2009-04-17 12:26 . 2003-07-16 20:51 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2004-03-06 02:16 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2007-04-26 23:41 . 2007-04-26 23:38 33032192 ----a-w- c:\program files\WP11SP1_EN.msp 2007-04-24 19:34 . 2007-04-24 19:30 353598016 ----a-w- c:\program files\SimpleStartFSEDirect.exe 2007-04-21 02:13 . 2007-04-21 02:13 774144 ----a-w- c:\program files\RngInterstitial.dll 2007-05-04 13:57 . 2007-04-27 16:31 88 --sh--r- c:\windows\SYSTEM32\566C526187.sys . ((((((((((((((((((((((((((((( SnapShot@2009-06-29_06.27.15 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-03 03:43 . 2009-07-03 03:43 16384 c:\windows\Temp\usgthrsvc\Perflib_Perfdata_8e0.dat + 2009-07-03 03:43 . 2009-07-03 03:43 16384 c:\windows\Temp\Perflib_Perfdata_794.dat + 2009-07-03 03:43 . 2009-07-03 03:43 16384 c:\windows\Temp\Perflib_Perfdata_718.dat - 2002-09-03 08:08 . 2009-06-29 04:20 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT + 2002-09-03 08:08 . 2009-07-03 05:44 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT - 2002-09-03 08:08 . 2009-06-29 04:20 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT + 2002-09-03 08:08 . 2009-07-03 05:44 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT - 2002-09-03 08:08 . 2009-06-29 04:20 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT + 2002-09-03 08:08 . 2009-07-03 05:44 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT + 2009-03-05 07:18 . 2009-03-05 07:18 78848 c:\windows\Installer\f6e0a63.msp + 2009-03-05 07:18 . 2009-03-05 07:18 18944 c:\windows\Installer\f6e0a58.msp + 2009-03-24 22:22 . 2009-03-24 22:22 19456 c:\windows\Installer\e1bf4.msp + 2009-03-20 02:35 . 2009-03-20 02:35 18944 c:\windows\Installer\e1bed.msp + 2009-03-20 02:35 . 2009-03-20 02:35 18944 c:\windows\Installer\e1be7.msp + 2008-07-30 01:07 . 2008-07-30 01:07 23040 c:\windows\Installer\d456647.msp + 2009-05-11 04:08 . 2009-05-11 04:08 88576 c:\windows\Installer\d3457fb.msi + 2009-05-11 19:10 . 2009-05-11 19:10 24064 c:\windows\Installer\bbb678.msi + 2009-07-01 02:33 . 2009-07-01 02:33 22528 c:\windows\Installer\979689e.msi + 2009-01-26 19:02 . 2009-01-26 19:02 20992 c:\windows\Installer\900c382.msi + 2009-01-26 19:02 . 2009-01-26 19:02 52736 c:\windows\Installer\900c37e.msi + 2009-01-26 19:02 . 2009-01-26 19:02 61440 c:\windows\Installer\900c37a.msi + 2009-01-26 19:01 . 2009-01-26 19:01 32256 c:\windows\Installer\900c376.msi + 2009-01-26 18:58 . 2009-01-26 18:58 22528 c:\windows\Installer\900c36b.msi + 2009-03-25 23:42 . 2009-03-25 23:42 25088 c:\windows\Installer\6b58f92.msi + 2009-03-14 01:14 . 2009-03-14 01:14 20992 c:\windows\Installer\53a1269.msp + 2009-03-14 01:17 . 2009-03-14 01:17 19456 c:\windows\Installer\53a11f2.msp + 2009-03-14 01:17 . 2009-03-14 01:17 18944 c:\windows\Installer\53a11eb.msp + 2009-02-27 05:08 . 2009-02-27 05:08 18944 c:\windows\Installer\1e282012.msp + 2009-02-13 03:09 . 2009-02-13 03:09 75776 c:\windows\Installer\1e28200c.msp + 2009-01-24 03:10 . 2009-01-24 03:10 18944 c:\windows\Installer\1a8fb75d.msp + 2007-10-01 00:37 . 2007-10-01 00:37 42496 c:\windows\Installer\198befe.msi + 2009-03-24 15:13 . 2009-03-24 15:13 51712 c:\windows\Installer\18d6858.msi + 2007-10-16 16:39 . 2007-10-16 16:39 48128 c:\windows\Installer\148b17a1.msi + 2008-09-17 21:00 . 2007-04-02 18:34 366080 c:\windows\ServicePackFiles\i386\digreqex.msi + 2008-09-17 21:00 . 2007-04-02 18:34 863232 c:\windows\ServicePackFiles\i386\digopt.msi + 2009-05-11 04:22 . 2009-05-11 04:22 652800 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.msi + 2009-02-08 04:30 . 2009-02-08 04:30 446464 c:\windows\Installer\fbe67e5.msi + 2009-03-05 07:16 . 2009-03-05 07:16 858112 c:\windows\Installer\f6e0b8a.msp + 2007-04-18 18:54 . 2007-04-18 18:54 270336 c:\windows\Installer\e22e91.msi + 2009-03-20 02:32 . 2009-03-20 02:32 170496 c:\windows\Installer\e1c73.msp + 2009-03-20 02:33 . 2009-03-20 02:33 428544 c:\windows\Installer\e1c5e.msp + 2008-12-13 13:58 . 2008-12-13 13:58 754688 c:\windows\Installer\d494908.msp + 2009-05-11 04:23 . 2009-05-11 04:23 648192 c:\windows\Installer\d4948e5.msi + 2008-07-30 01:23 . 2008-07-30 01:23 250880 c:\windows\Installer\d456650.msp + 2008-07-30 01:28 . 2008-07-30 01:28 278016 c:\windows\Installer\d45664e.msp + 2008-07-29 23:40 . 2008-07-29 23:40 291840 c:\windows\Installer\d45664c.msp + 2009-05-11 04:20 . 2009-05-11 04:20 137728 c:\windows\Installer\d456646.msi + 2008-07-29 21:35 . 2008-07-29 21:35 553472 c:\windows\Installer\d345800.msp + 2008-07-29 21:33 . 2008-07-29 21:33 506368 c:\windows\Installer\d3457fe.msp + 2008-07-29 21:37 . 2008-07-29 21:37 911360 c:\windows\Installer\d3457fd.msp + 2007-11-17 16:57 . 2007-11-17 16:57 331264 c:\windows\Installer\c95d9c7.msi + 2007-04-18 18:29 . 2007-04-18 18:29 275968 c:\windows\Installer\c8c310.msi + 2007-04-18 18:26 . 2007-04-18 18:26 660992 c:\windows\Installer\c8c30c.msi + 2004-01-21 21:54 . 2004-01-21 21:54 233472 c:\windows\Installer\b252.msi + 2004-01-21 21:54 . 2004-01-21 21:54 171008 c:\windows\Installer\b24c.msi + 2006-11-23 08:00 . 2006-11-23 08:00 428544 c:\windows\Installer\a4629ad.msi + 2007-04-20 00:40 . 2007-04-20 00:40 804864 c:\windows\Installer\9c470.msi + 2009-01-26 19:03 . 2009-01-26 19:03 201728 c:\windows\Installer\900c386.msi + 2007-04-24 19:52 . 2007-04-24 19:52 906240 c:\windows\Installer\8b4ba2.msi + 2007-04-24 19:38 . 2007-04-24 19:38 390656 c:\windows\Installer\8b4b8f.msi + 2009-06-23 21:25 . 2009-06-23 21:25 315392 c:\windows\Installer\6a4d62.msi + 2004-01-21 21:47 . 2004-01-21 21:47 558592 c:\windows\Installer\5a82b.msi + 2004-01-21 21:44 . 2004-01-21 21:44 456704 c:\windows\Installer\5a818.msi + 2004-01-21 21:44 . 2004-01-21 21:44 532992 c:\windows\Installer\5a80d.msi + 2004-01-21 21:42 . 2004-01-21 21:42 559616 c:\windows\Installer\5a7f4.msi + 2004-01-21 21:34 . 2004-01-21 21:34 616448 c:\windows\Installer\5a7d5.msi + 2009-02-04 17:14 . 2009-02-04 17:14 279040 c:\windows\Installer\4d5526.msi + 2008-09-14 14:11 . 2008-09-14 14:11 147968 c:\windows\Installer\4cb12.msi + 2009-04-01 21:48 . 2009-04-01 21:48 130560 c:\windows\Installer\46e131b.msp + 2007-05-11 20:02 . 2007-05-11 20:02 958976 c:\windows\Installer\3fdbb5f.msi + 2007-08-15 03:04 . 2007-08-15 03:04 871424 c:\windows\Installer\3cb964.msi + 2007-08-15 03:00 . 2007-08-15 03:00 431104 c:\windows\Installer\3cb95e.msi + 2007-04-01 21:58 . 2007-04-01 21:58 189952 c:\windows\Installer\36c7696.msi + 2008-11-12 06:03 . 2008-11-12 06:03 432640 c:\windows\Installer\311ab3e.msi + 2008-12-24 20:27 . 2008-12-24 20:27 164352 c:\windows\Installer\2883a8.msi + 2009-05-26 22:53 . 2009-05-26 22:53 579072 c:\windows\Installer\2079f4e4.msp + 2007-05-31 02:47 . 2007-05-31 02:47 571904 c:\windows\Installer\1fab4715.msi + 2009-02-27 05:08 . 2009-02-27 05:08 151552 c:\windows\Installer\1e28201d.msp + 2007-05-14 08:33 . 2007-05-14 08:33 174080 c:\windows\Installer\1d4419b.msi + 2007-04-19 19:03 . 2007-04-19 19:03 472576 c:\windows\Installer\1acd29.msi + 2009-01-24 03:09 . 2009-01-24 03:09 143360 c:\windows\Installer\1a8fb757.msp + 2009-01-24 03:08 . 2009-01-24 03:08 464896 c:\windows\Installer\1a8fb6be.msp + 2009-02-04 19:01 . 2009-02-04 19:01 562176 c:\windows\Installer\1a6981.msi + 2007-10-15 03:44 . 2007-10-15 03:44 324608 c:\windows\Installer\168c0fc.msp + 2007-10-15 03:46 . 2007-10-15 03:46 324608 c:\windows\Installer\168c0f6.msp + 2007-10-16 16:40 . 2007-10-16 16:40 501248 c:\windows\Installer\148b17b7.msi + 2007-10-16 16:40 . 2007-10-16 16:40 506880 c:\windows\Installer\148b17b2.msi + 2007-10-16 16:40 . 2007-10-16 16:40 516608 c:\windows\Installer\148b17ac.msi + 2007-10-16 16:40 . 2007-10-16 16:40 513024 c:\windows\Installer\148b17a6.msi + 2007-10-16 16:38 . 2007-10-16 16:38 501248 c:\windows\Installer\148b1789.msi + 2007-10-30 00:13 . 2007-10-30 00:13 501248 c:\windows\Installer\147af710.msi + 2008-11-19 01:29 . 2008-11-19 01:29 316928 c:\windows\Installer\132d6e18.msi + 2008-11-19 00:03 . 2008-11-19 00:03 889344 c:\windows\Installer\132d6de0.msi + 2008-11-19 00:03 . 2008-11-19 00:03 591872 c:\windows\Installer\132d6ddb.msi + 2002-09-03 08:06 . 2002-09-03 08:06 264704 c:\windows\Installer\1128E.MSI + 2009-07-02 10:59 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\7-2-2009\ERDNT.EXE + 2009-07-01 02:39 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\6-30-2009\ERDNT.EXE + 2003-07-16 20:51 . 2004-07-17 18:35 1326080 c:\windows\SYSTEM32\webfldrs.msi + 2004-01-26 23:00 . 2004-01-21 21:34 9121792 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}\Java 2 Runtime Environment, SE v1.4.2.msi + 2004-07-17 18:35 . 2004-07-17 18:35 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi + 2008-09-17 21:02 . 2007-04-02 18:42 5080576 c:\windows\ServicePackFiles\i386\msnmsgs.msi + 2007-05-25 16:08 . 2007-05-25 16:08 9609728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp + 2007-01-18 22:14 . 2007-01-18 22:14 3463680 c:\windows\Microsoft.NET\Framework\v1.0.3705\Updates\M928367\M928367Uninstall.msp + 2009-03-05 07:15 . 2009-03-05 07:15 3058176 c:\windows\Installer\f6e0c82.msp + 2009-03-05 07:17 . 2009-03-05 07:17 1856512 c:\windows\Installer\f6e0bf5.msp + 2009-03-24 22:20 . 2009-03-24 22:20 2630656 c:\windows\Installer\e1ce8.msp + 2009-04-04 21:10 . 2009-04-04 21:10 1282560 c:\windows\Installer\d494ab1.msp + 2009-04-04 21:10 . 2009-04-04 21:10 7888384 c:\windows\Installer\d494aaa.msp + 2009-04-04 21:10 . 2009-04-04 21:10 9926144 c:\windows\Installer\d494aa1.msp + 2009-04-04 14:14 . 2009-04-04 14:14 1094656 c:\windows\Installer\d494913.msp + 2008-12-13 13:57 . 2008-12-13 13:57 8397824 c:\windows\Installer\d4948f3.msp + 2008-07-29 23:26 . 2008-07-29 23:26 1043456 c:\windows\Installer\d45664f.msp + 2008-07-30 00:37 . 2008-07-30 00:37 2679808 c:\windows\Installer\d45664d.msp + 2008-07-30 01:15 . 2008-07-30 01:15 3697664 c:\windows\Installer\d45664b.msp + 2008-07-29 23:34 . 2008-07-29 23:34 1448448 c:\windows\Installer\d45664a.msp + 2008-07-30 00:22 . 2008-07-30 00:22 4137984 c:\windows\Installer\d456649.msp + 2008-07-29 23:18 . 2008-07-29 23:18 3376640 c:\windows\Installer\d456648.msp + 2008-07-29 21:45 . 2008-07-29 21:45 2543616 c:\windows\Installer\d345804.msp + 2008-07-29 21:29 . 2008-07-29 21:29 2926080 c:\windows\Installer\d345803.msp + 2008-07-29 21:41 . 2008-07-29 21:41 6487040 c:\windows\Installer\d345802.msp + 2008-07-29 21:39 . 2008-07-29 21:39 3403264 c:\windows\Installer\d345801.msp + 2008-07-29 21:43 . 2008-07-29 21:43 1013248 c:\windows\Installer\d3457ff.msp + 2008-07-29 21:31 . 2008-07-29 21:31 6083072 c:\windows\Installer\d3457fc.msp + 2009-04-24 16:28 . 2009-04-24 16:28 4450816 c:\windows\Installer\d2b8620.msp + 2008-11-13 07:57 . 2008-11-13 07:57 5099520 c:\windows\Installer\cbd193.msp + 2008-10-20 15:18 . 2008-10-20 15:18 6474240 c:\windows\Installer\cbd17f.msp + 2009-05-22 02:39 . 2009-05-22 02:39 1711616 c:\windows\Installer\cae5814.msp + 2008-04-11 22:48 . 2008-04-11 22:48 6774272 c:\windows\Installer\c95e024.msp + 2008-07-16 23:01 . 2008-07-16 23:01 5110272 c:\windows\Installer\c95e00e.msp + 2007-04-18 18:31 . 2007-04-18 18:31 4410368 c:\windows\Installer\c8c319.msi + 2009-01-08 01:25 . 2009-01-08 01:25 5046784 c:\windows\Installer\c57752d.msp + 2008-01-28 23:09 . 2008-01-28 23:09 5055488 c:\windows\Installer\bf2de81.msp + 2007-10-28 15:53 . 2007-10-28 15:53 5047808 c:\windows\Installer\bae4e61.msp + 2009-05-21 21:44 . 2009-05-21 21:44 1401344 c:\windows\Installer\b9eb7fd.msi + 2009-01-27 06:23 . 2009-01-27 06:23 4192256 c:\windows\Installer\b6f9a9b.msi + 2004-01-21 21:54 . 2004-01-21 21:54 1989632 c:\windows\Installer\b248.msi + 2008-04-11 22:08 . 2008-04-11 22:08 6302720 c:\windows\Installer\a81730.msp + 2008-04-26 00:14 . 2008-04-26 00:14 5052928 c:\windows\Installer\a81718.msp + 2008-04-18 18:56 . 2008-04-18 18:56 6215680 c:\windows\Installer\a81704.msp + 2007-04-11 02:40 . 2007-04-11 02:40 1392128 c:\windows\Installer\984d85.msi + 2007-11-22 23:23 . 2007-11-22 23:23 5051904 c:\windows\Installer\90fb9c.msp + 2009-01-26 19:00 . 2009-01-26 19:00 2231296 c:\windows\Installer\900c372.msi + 2004-10-06 23:10 . 2004-10-06 23:10 2652672 c:\windows\Installer\8c13d6d9.msi + 2009-01-20 18:17 . 2009-01-20 18:17 1659392 c:\windows\Installer\860dc66.msi + 2007-04-18 16:57 . 2007-04-18 16:58 4065280 c:\windows\Installer\76629b.msi + 2008-06-05 17:56 . 2008-06-05 17:56 5111808 c:\windows\Installer\73cffde.msp + 2009-03-25 23:40 . 2009-03-25 23:40 4733440 c:\windows\Installer\679c96d.msp + 2004-01-21 21:45 . 2004-01-21 21:45 2778112 c:\windows\Installer\5a823.msi + 2004-01-21 21:44 . 2004-01-21 21:44 1264128 c:\windows\Installer\5a808.msi + 2004-01-21 21:43 . 2004-01-21 21:43 9017344 c:\windows\Installer\5a801.msi + 2004-01-21 21:43 . 2004-01-21 21:43 2303488 c:\windows\Installer\5a7f8.msi + 2004-01-21 21:42 . 2004-01-21 21:42 5564928 c:\windows\Installer\5a7e7.msi + 2004-01-21 21:40 . 2004-01-21 21:40 3443712 c:\windows\Installer\5a7df.msi + 2004-01-21 21:40 . 2004-01-21 21:40 2120192 c:\windows\Installer\5a7da.msi + 2009-05-01 21:31 . 2009-05-01 21:31 1674752 c:\windows\Installer\5867cfb.msi + 2009-05-01 21:30 . 2009-05-01 21:30 3966976 c:\windows\Installer\5867cc9.msi + 2009-05-01 21:26 . 2009-05-01 21:26 8992256 c:\windows\Installer\58679ab.msi + 2009-05-01 21:22 . 2009-05-01 21:22 3293696 c:\windows\Installer\5867708.msi + 2009-05-01 21:15 . 2009-05-01 21:15 2330624 c:\windows\Installer\58675fc.msi + 2007-04-05 22:31 . 2007-04-05 22:31 1142784 c:\windows\Installer\53c62d.msi + 2009-03-14 01:13 . 2009-03-14 01:13 1677312 c:\windows\Installer\53a12ca.msp + 2009-03-14 01:16 . 2009-03-14 01:16 1672192 c:\windows\Installer\53a125a.msp + 2008-11-20 19:48 . 2008-11-20 19:48 5097472 c:\windows\Installer\51a7021.msp + 2008-08-25 23:08 . 2008-08-25 23:08 1549312 c:\windows\Installer\4636035.msi + 2008-10-20 15:19 . 2008-10-20 15:19 5100032 c:\windows\Installer\311ab65.msp + 2008-02-15 12:54 . 2008-02-15 12:54 9736192 c:\windows\Installer\2c6db0b.msp + 2008-03-17 21:55 . 2008-03-17 21:55 5049344 c:\windows\Installer\2c6dae4.msp + 2007-03-31 02:20 . 2007-03-31 02:20 5800960 c:\windows\Installer\282b318.msp + 2007-03-31 02:21 . 2007-03-31 02:21 3886080 c:\windows\Installer\282b307.msp + 2007-06-01 19:54 . 2007-06-01 19:54 9626624 c:\windows\Installer\282b2d3.msp + 2007-07-21 17:26 . 2007-07-21 17:26 7574016 c:\windows\Installer\282b2c2.msp + 2007-07-30 18:44 . 2007-07-30 18:44 1155072 c:\windows\Installer\267915.msi + 2009-05-04 11:46 . 2009-05-04 11:46 8299008 c:\windows\Installer\2079f538.msp + 2009-05-04 11:47 . 2009-05-04 11:47 9124864 c:\windows\Installer\2079f523.msp + 2009-04-24 16:30 . 2009-04-24 16:30 2583552 c:\windows\Installer\2079f50e.msp + 2009-05-07 13:17 . 2009-05-07 13:17 5026816 c:\windows\Installer\2079f4f8.msp + 2009-04-24 16:29 . 2009-04-24 16:29 9013760 c:\windows\Installer\2079f4d1.msp + 2009-02-27 05:05 . 2009-02-27 05:05 3425792 c:\windows\Installer\1e28230c.msp + 2009-03-02 03:23 . 2009-03-02 03:23 1969152 c:\windows\Installer\1e282243.msp + 2009-02-28 09:55 . 2009-02-28 09:55 2728960 c:\windows\Installer\1e2820b4.msp + 2009-02-25 23:08 . 2009-02-25 23:08 8311808 c:\windows\Installer\1d1c445b.msp + 2009-03-28 13:50 . 2009-03-28 13:50 5025792 c:\windows\Installer\1d1c4448.msp + 2008-09-02 15:42 . 2008-09-02 15:42 5104640 c:\windows\Installer\1c96d6b0.msp + 2008-02-25 19:08 . 2008-02-25 19:08 5050368 c:\windows\Installer\1bcff8e6.msp + 2009-01-24 03:09 . 2009-01-24 03:09 2215424 c:\windows\Installer\1a8fb741.msp + 2009-01-24 03:07 . 2009-01-24 03:07 3441152 c:\windows\Installer\1a8fb667.msp + 2007-06-07 00:50 . 2007-06-07 00:50 4466176 c:\windows\Installer\1a57d93.msi + 2007-07-11 15:17 . 2007-07-11 15:17 6743040 c:\windows\Installer\19fefc94.msp + 2009-01-15 07:35 . 2009-01-15 07:35 4830720 c:\windows\Installer\18d685e.msp + 2007-10-15 03:43 . 2007-10-15 03:43 5749760 c:\windows\Installer\168c0d6.msp + 2007-03-27 20:14 . 2007-03-27 20:14 5566464 c:\windows\Installer\14afb01c.msp + 2007-10-01 01:12 . 2007-10-01 01:12 5052416 c:\windows\Installer\149c2847.msp + 2007-05-29 02:01 . 2007-05-29 02:01 4597760 c:\windows\Installer\149c27f7.msp + 2007-10-16 16:40 . 2007-10-16 16:40 1652736 c:\windows\Installer\148b17bc.msi + 2007-10-16 16:39 . 2007-10-16 16:39 1640960 c:\windows\Installer\148b1798.msi + 2007-10-16 16:39 . 2007-10-16 16:39 1713152 c:\windows\Installer\148b178e.msi + 2007-10-16 16:37 . 2007-10-16 16:37 2397184 c:\windows\Installer\148b1784.msi + 2007-10-30 00:13 . 2007-10-30 00:13 1652736 c:\windows\Installer\147af70b.msi + 2007-10-30 00:13 . 2007-10-30 00:13 1652736 c:\windows\Installer\147af703.msi + 2007-10-30 00:12 . 2007-10-30 00:12 2319872 c:\windows\Installer\147af6f2.msi + 2007-10-30 00:11 . 2007-10-30 00:11 2022912 c:\windows\Installer\147af6e7.msi + 2007-04-05 20:49 . 2007-04-05 20:49 5864960 c:\windows\Installer\117b026.msp + 2007-04-05 20:48 . 2007-04-05 20:48 1422848 c:\windows\Installer\117b01f.msp + 2009-02-07 03:31 . 2009-02-07 03:31 5047808 c:\windows\Installer\10c50a.msp + 2008-08-20 18:37 . 2008-08-20 18:37 5107712 c:\windows\Installer\103a3f78.msp + 2009-07-02 10:59 . 2009-07-02 10:59 1060864 c:\windows\ERDNT\AutoBackup\7-2-2009\Users\00000002\UsrClass.dat + 2009-07-02 10:59 . 2009-07-02 10:59 9928704 c:\windows\ERDNT\AutoBackup\7-2-2009\Users\00000001\ntuser.dat + 2009-07-01 02:39 . 2009-07-01 02:39 1060864 c:\windows\ERDNT\AutoBackup\6-30-2009\Users\00000002\UsrClass.dat + 2009-07-01 02:39 . 2009-07-01 02:39 9928704 c:\windows\ERDNT\AutoBackup\6-30-2009\Users\00000001\ntuser.dat + 2007-06-07 00:48 . 2007-06-07 00:48 9834496 c:\windows\Downloaded Installations\{FE6F1783-A2E5-4CFA-8255-BA2C5299B0BB}\URGE.msi + 2007-08-22 01:32 . 2007-08-22 01:32 5277696 c:\windows\Downloaded Installations\{98A091FD-535E-4DE9-A977-EC43764487FE}\MyFantasyMaker.msi + 2006-10-30 08:05 . 2006-10-30 08:05 11390464 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpf.msi + 2007-12-11 08:02 . 2007-12-11 08:02 24487424 c:\windows\Installer\f75cdab.msp + 2008-10-20 15:22 . 2008-10-20 15:22 11758592 c:\windows\Installer\e2c6c6.msp + 2008-10-20 15:21 . 2008-10-20 15:21 11937280 c:\windows\Installer\e2c6b2.msp + 2009-04-04 21:09 . 2009-04-04 21:09 15190016 c:\windows\Installer\d494933.msp + 2009-04-04 15:36 . 2009-04-04 15:36 21390848 c:\windows\Installer\d494914.msp + 2008-12-13 14:21 . 2008-12-13 14:21 10473472 c:\windows\Installer\d4948fd.msp + 2009-05-04 11:49 . 2009-05-04 11:49 10955776 c:\windows\Installer\ceeb52b.msp + 2008-10-20 15:16 . 2008-10-20 15:16 13211648 c:\windows\Installer\cbd1a8.msp + 2008-07-03 15:36 . 2008-07-03 15:36 11937792 c:\windows\Installer\c95e04c.msp + 2008-07-03 15:37 . 2008-07-03 15:37 11759104 c:\windows\Installer\c95e038.msp + 2004-01-21 21:53 . 2004-01-21 21:53 12298240 c:\windows\Installer\b244.msi + 2009-02-25 23:05 . 2009-02-25 23:05 11840000 c:\windows\Installer\af19922.msp + 2009-02-25 23:07 . 2009-02-25 23:07 11646464 c:\windows\Installer\af1990e.msp + 2008-04-11 22:07 . 2008-04-11 22:07 13257728 c:\windows\Installer\a81746.msp + 2007-04-24 19:47 . 2007-04-24 19:48 67772928 c:\windows\Installer\8b4b97.msi + 2007-04-05 14:45 . 2007-04-05 14:45 10723328 c:\windows\Installer\7f34a9b.msp + 2007-04-05 14:42 . 2007-04-05 14:42 19210240 c:\windows\Installer\7f34a47.msp + 2007-05-01 05:09 . 2007-05-01 05:09 12962816 c:\windows\Installer\6d89db.msp + 2008-11-19 16:34 . 2008-11-19 16:34 34966016 c:\windows\Installer\56eb0f3.msp + 2008-11-19 16:34 . 2008-11-19 16:34 17352192 c:\windows\Installer\56eb0f2.msp + 2008-05-21 05:30 . 2008-05-21 05:30 14308864 c:\windows\Installer\48c02.msp + 2009-02-11 20:47 . 2009-02-11 20:47 20803072 c:\windows\Installer\3a93ea9.msp + 2009-03-30 17:50 . 2009-03-30 17:50 25128448 c:\windows\Installer\3a93ea8.msp + 2008-09-24 17:05 . 2008-09-24 17:05 16381440 c:\windows\Installer\311ab51.msp + 2008-06-28 23:20 . 2008-06-28 23:20 10935296 c:\windows\Installer\2d19049e.msi + 2008-01-28 22:07 . 2008-01-28 22:07 19034624 c:\windows\Installer\2c6daf8.msp + 2007-08-06 16:47 . 2007-08-06 16:47 56805888 c:\windows\Installer\2aeb6b.msp + 2007-03-31 02:19 . 2007-03-31 02:19 10893312 c:\windows\Installer\282b2f5.msp + 2007-06-01 19:53 . 2007-06-01 19:53 10255360 c:\windows\Installer\282b2e4.msp + 2008-05-08 18:03 . 2008-05-08 18:03 22272512 c:\windows\Installer\1c92fc7e.msp + 2008-07-30 03:20 . 2008-07-30 03:20 11767296 c:\windows\Installer\1c86d376.msp + 2008-07-30 03:18 . 2008-07-30 03:18 11933184 c:\windows\Installer\1c86d362.msp + 2008-02-25 19:07 . 2008-02-25 19:07 11772416 c:\windows\Installer\1bcff933.msp + 2008-01-28 22:09 . 2008-01-28 22:09 11896320 c:\windows\Installer\1bcff91f.msp + 2008-01-28 22:10 . 2008-01-28 22:10 14201344 c:\windows\Installer\1bcff90a.msp + 2007-05-06 00:27 . 2007-05-06 00:27 13985280 c:\windows\Installer\1b1c892.msi + 2007-05-06 00:25 . 2007-05-06 00:25 22380032 c:\windows\Installer\1b1c88c.msi + 2007-07-11 15:26 . 2007-07-11 15:26 15256576 c:\windows\Installer\19fefcf2.msp + 2007-10-15 03:43 . 2007-10-15 03:43 12743168 c:\windows\Installer\168c0e7.msp + 2007-10-15 03:43 . 2007-10-15 03:43 21981184 c:\windows\Installer\168c0ad.msp + 2007-04-22 00:16 . 2007-04-22 00:16 12490752 c:\windows\Installer\14afb00a.msp + 2007-06-01 19:55 . 2007-06-01 19:55 10824704 c:\windows\Installer\149c2811.msp + 2007-10-30 00:22 . 2007-10-30 00:22 15830016 c:\windows\Installer\147af716.msi + 2009-01-09 21:37 . 2009-01-09 21:37 26120192 c:\windows\Installer\14079da5.msp + 2009-01-09 21:37 . 2009-01-09 21:37 19272704 c:\windows\Installer\14079da4.msp + 2008-11-19 01:22 . 2008-11-19 01:23 45664256 c:\windows\Installer\132d6e12.msi + 2008-08-11 15:51 . 2008-08-11 15:51 15916544 c:\windows\Installer\103a3f64.msp + 2008-08-11 15:49 . 2008-08-11 15:49 22457344 c:\windows\Installer\103a3f50.msp + 2007-04-18 00:30 . 2007-04-18 00:30 12682240 c:\windows\Downloaded Installations\Yahoo Jukebox\Yahoo! Music Jukebox.msi + 2007-08-25 21:32 . 2007-08-25 21:32 12560896 c:\windows\Downloaded Installations\{CA82323F-95EB-46BC-9FEF-C593133CC34F}\Yahoo! Music Jukebox.msi + 2007-11-27 01:37 . 2007-11-27 01:37 12568576 c:\windows\Downloaded Installations\{885582E4-09F5-4CE2-8234-187CEDE982B8}\Yahoo! Music Jukebox.msi + 2008-02-19 14:34 . 2008-02-19 14:34 12545536 c:\windows\Downloaded Installations\{6FB8D67A-9BAD-4361-9B96-E2970783552D}\Yahoo! Music Jukebox.msi + 2009-04-04 21:08 . 2009-04-04 21:08 343058432 c:\windows\Installer\d494a97.msp + 2007-10-15 03:43 . 2007-10-15 03:43 229852160 c:\windows\Installer\168c0a6.msp . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] 2009-04-01 17:16 193472 ------w- c:\program files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SRS Audio Sandbox"="c:\program files\SRS Labs\Audio Sandbox2\SRSSSC.exe" [2007-03-16 3153920] "YahooWidgetEngine.exe"="c:\program files\Yahoo!\Widgets\YahooWidgetEngine.exe" [2007-07-20 2913584] "PlaxoUpdate"="c:\program files\Plaxo\3.20.0.13\PlaxoHelper_en.exe" [2009-05-01 379463] "PlaxoSysTray"="c:\program files\Plaxo\3.20.0.13\PlaxoSysTray.exe" [2009-05-01 20480] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096] "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-08-14 5562368] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-27 68856] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "VF0560Inst"="c:\windows\system32\V0560Pin.dll" [2008-06-02 40960] c:\documents and settings\CHRISTINA\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-24 344064] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force V-Bar.exe"= "c:\\WINDOWS\\SYSTEM32\\ControlSuite.exe"= "c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Standalone.exe"= "c:\\Program Files\\SoundSpectrum\\G-Force\\G-Force Toolbar.exe"= "c:\\Program Files\\Yahoo!\\Widgets\\YahooWidgetEngine.exe"= "c:\\Program Files\\Sonic\\RecordNow!\\RecordNow.exe"= "c:\\Program Files\\Intel\\NCS\\PROSet\\PROSet.exe"= "c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"= "c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"= "c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"= "c:\\Program Files\\InterActual\\InterActual Player\\iPlayer.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Yahoo! Games\\Bejeweled 2 Deluxe\\WinBej2.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Windows Media Player\\wmplayer.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Rhapsody\\WiseUpd2.exe"= "c:\\Program Files\\Flickr Uploadr\\Flickr Uploadr.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Intuit\\QuickBooks 2009\\QBW32SimplestartLimited.exe"= R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [12/9/2008 1:37 PM 13088] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2/9/2009 2:48 PM 210216] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592] R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;c:\windows\SYSTEM32\DRIVERS\livecamv.sys [1/17/2009 1:47 PM 31616] R3 V0560Afx;Creative Camera VF0560 Audio Effects Driver;c:\windows\SYSTEM32\DRIVERS\V0560Afx.sys [1/17/2009 1:49 PM 160768] R3 V0560Vid;Creative Live! Cam Optia AF Driver;c:\windows\SYSTEM32\DRIVERS\V0560Vid.sys [1/17/2009 1:49 PM 286592] S2 gupdate1c995062274baac;Google Update Service (gupdate1c995062274baac);c:\program files\Google\Update\GoogleUpdate.exe [2/22/2009 11:56 AM 133104] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys --> c:\windows\system32\DRIVERS\CtClsFlt.sys [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-07-03 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-22 17:07] 2009-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-22 15:56] 2009-06-15 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-09 15:53] 2009-06-29 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-09 15:53] 2009-07-03 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20] 2009-07-03 c:\windows\Tasks\User_Feed_Synchronization-{5DBDA0A7-2B36-4C06-A598-91EEF296D77A}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 08:31] . . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uStart Page = hxxp://www.aol.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com IE: &AOL Email Toolbar Search - c:\documents and settings\All Users\Application Data\AOL Email Toolbar\ieToolbar\resources\en-US\local\search.html IE: &AOL Radio Toolbar Search - c:\documents and settings\All Users\Application Data\AOL Radio Toolbar\ieToolbar\resources\en-US\local\search.html IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin.cab FF - ProfilePath - c:\documents and settings\CHRISTINA\Application Data\Mozilla\Firefox\Profiles\tcsd8sk1.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50-ff-aolmailtb-chromesbox-en-us&query= FF - prefs.js: browser.search.selectedEngine - AOL Search FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/ FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50-ff-aolmailtb-ab-en-us&query= FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - component: c:\program files\MySpace\Toolbar\1.0.45.0\components\MySpaceFFoxTB.dll FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- FF - user.js: browser.cache.memory.capacity - 16000 FF - user.js: browser.chrome.favicons - fales FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 4095 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 1000000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 1000000 FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service FF - user.js: dom.disable_window_status_change - true FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 1000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-03 03:34 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\windows\TEMP\mcafee_suO0bMjGZygouua 0 bytes scan completed successfully hidden files: 1 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(3132) c:\windows\system32\WININET.dll c:\program files\McAfee\SiteAdvisor\saHook.dll c:\program files\Plaxo\3.20.0.13\plx_hook.dll c:\program files\Windows Desktop Search\deskbar.dll c:\program files\Windows Desktop Search\en-us\dbres.dll.mui c:\program files\Windows Desktop Search\dbres.dll c:\program files\Windows Desktop Search\wordwheel.dll c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui c:\program files\Windows Desktop Search\msnlExtRes.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\SYSTEM32\LEXBCES.EXE c:\windows\SYSTEM32\LEXPPS.EXE c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Motive\McciCMService.exe c:\windows\SYSTEM32\PSIService.exe c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe c:\windows\SYSTEM32\tcpsvcs.exe c:\windows\SYSTEM32\snmp.exe c:\windows\SYSTEM32\fxssvc.exe c:\windows\SYSTEM32\searchindexer.exe c:\progra~1\McAfee\VIRUSS~1\mcods.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe c:\progra~1\McAfee.com\Agent\mcagent.exe c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe c:\program files\McAfee\MPF\MpfSrv.exe . ************************************************************************** . Completion time: 2009-07-03 3:49 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-03 07:48 ComboFix2.txt 2009-06-29 06:36 Pre-Run: 42,892,439,552 bytes free Post-Run: 43,087,237,120 bytes free 560 --- E O F --- 2009-07-02 17:34 So far the computer is doing good with no freezeups. |
|
|
Jul 3 2009, 03:27 PM
Post
#10
|
|
![]() Trusted Helper Posts: 8,068 OS: XP Pro |
Hello Cowboylady,
Almost there now. Just one that I think we should play on the safe with and remove and one scan to check for another possible infection. Now 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: QUOTE File:: c:\windows\system32\V0560Pin.dll Registry:: [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "VF0560Inst"=- Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it will produce a log for you at C:\ComboFix.txt. Please post that here for further review. Next Please download GooredFix and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet. So when you return please post
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
5 / 953 | 3rd December 2007 - 05:04 AM flash86 started - last by Kenny94 |
|||||
![]() |
0 / 57 | 26th August 2009 - 04:44 PM UMan01 started - last by UMan01 |
|||||
![]() |
0 / 37 | 8th November 2009 - 04:48 PM Vicadi started - last by Vicadi |
|||||
![]() |
4 / 59 | 12th November 2009 - 02:47 PM woodworks started - last by rshaffer61 |
|||||
|
Time is now: 21st November 2009 - 11:53 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising