Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: Intel(R) Pentium(R) 4 CPU 1.60GHz Percentage of Memory in Use: 69% Physical Memory (total/avail): 511.01 MiB / 153.52 MiB Pagefile Memory (total/avail): 1249.75 MiB / 950.39 MiB Virtual Memory (total/avail): 2047.88 MiB / 1935.27 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 111.78 GiB total, 102.55 GiB free. D: is Fixed (FAT32) - 37.26 GiB total, 31.21 GiB free. E: is CDROM (No Media) F: is CDROM (No Media) \\.\PHYSICALDRIVE0 - ST3120814A - 111.79 GiB - 1 partition \PARTITION0 (bootable) - Installable File System - 111.78 GiB - C: \\.\PHYSICALDRIVE1 - ST340016A - 37.27 GiB - 1 partition \PARTITION0 (bootable) - Unknown - 37.27 GiB - D: -- Security Center ------------------------------------------------------------- AUOptions is disabled. Windows Internal Firewall is enabled. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" "C:\\Program Files\\Sawtooth Software\\SSI Web\\LocalWeb\\Apache.exe"="C:\\Program Files\\Sawtooth Software\\SSI Web\\LocalWeb\\Apache.exe:*:Enabled:Apache" "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader" "C:\\Program Files\\Intuit\\QuickBooks Pro\\QBDBMgrN.exe"="C:\\Program Files\\Intuit\\QuickBooks Pro\\QBDBMgrN.exe:*:Enabled:QuickBooks 2007 Data Manager" "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Disabled:Internet Explorer" "C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\martha\Application Data CLASSPATH=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=DELL1600 ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\martha LOGONSERVER=\\HOMESERVER NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\ PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 1 Stepping 2, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0102 ProgramFiles=C:\Program Files PROMPT=$P$G QTJAVA=C:\Program Files\QuickTime\QTSystem\QTJava.zip SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\martha\LOCALS~1\Temp TMP=C:\DOCUME~1\martha\LOCALS~1\Temp USERDNSDOMAIN=DRCHOME.LOCAL USERDOMAIN=drchome USERNAME=martha USERPROFILE=C:\Documents and Settings\martha windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- doug [I](new local, admin, net ready)[/I] martha [I](admin)[/I] -- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Installshield Installation Information\{08082022-2a50-4196-8196-a6f86d6e8f12}\QBReplace.exe {08082022-2a50-4196-8196-a6f86d6e8f12}#{01288593-26bb-4b3a-a04e-0a4ed28cc937} --> MsiExec.exe /I{71EEA108-09C9-4D81-8FA2-D48C70681242} --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete Adobe Reader 7.0.5 Language Support --> MsiExec.exe /I{AC76BA86-7AD7-5464-3428-7050000000A7} Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002} Adobe® Photoshop® Album Starter Edition 3.0 --> MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B} Apple Software Update --> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D} DING! --> MsiExec.exe /X{84031A18-BA9A-4156-A74F-E05B52DDFCE2} Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72} Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe" iTunes --> MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4} Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030} Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050} Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010} LiveUpdate 1.7 (Symantec Corporation) --> C:\Program Files\\Symantec\LiveUpdate\LSETUP.EXE /U Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe" Microsoft Office XP Professional --> MsiExec.exe /I{91110409-6000-11D3-8CFE-0050048383C9} Microsoft Publisher 2002 --> MsiExec.exe /I{91190409-6000-11D3-8CFE-0050048383C9} Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe" Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7} NVIDIA Drivers --> C:\WINDOWS\system32\nvudisp.exe UninstallGUI QuickBooks Pro 2007 --> msiexec.exe /I {71EEA108-09C9-4D81-8FA2-D48C70681242} UNIQUE_NAME="pro" QBFULLNAME="QuickBooks Pro 2007" ADDREMOVE=1 QuickBooks Product Listing Service --> MsiExec.exe /I{55584E16-4D70-44EE-93DD-F144E8B7D4B7} Quicken 2005 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{2DBE41DD-2129-4C65-A3D3-5647236A60F3} anything QuickTime --> MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A} Sawtooth Software SSI Web --> MsiExec.exe /I{8D9C3B54-60E7-44D5-87D5-F24CDAD14047} SlingPlayer --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1150\INTEL3~1\IDriver.exe /M{004B0DCB-4C60-465B-8F01-44B0A4111187} /l1033 Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe" Symantec AntiVirus Client --> MsiExec.exe /X{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E} TreeSize Personal 5.0 --> "C:\Program Files\JAM Software\TreeSize Personal\unins000.exe" TroopMaster 2005 --> C:\PROGRA~1\TROOPM~1\UNWISE.EXE C:\PROGRA~1\TROOPM~1\INSTALL.LOG Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe" -- Application Event Log ------------------------------------------------------- Event Record #/Type330 / Error Event Submitted/Written: 05/21/2008 11:58:32 AM Event ID/Source: 1054 / Userenv Event Description: Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Event Record #/Type329 / Error Event Submitted/Written: 05/21/2008 11:55:48 AM Event ID/Source: 5 / Norton AntiVirus Event Description: Virus Found!Virus name: Trojan.Adclicker in File: C:\WINDOWS\system32\clbdll.dll by: Realtime Protection scan. Action: Clean failed : Quarantine failed : Access denied Event Record #/Type328 / Error Event Submitted/Written: 05/21/2008 11:55:46 AM Event ID/Source: 5 / Norton AntiVirus Event Description: Virus Found!Virus name: Trojan.Adclicker in File: C:\WINDOWS\SYSTEM32\CLBDLL.DLL by: Realtime Protection scan. Action: Clean failed : Quarantine failed : Access denied Event Record #/Type327 / Error Event Submitted/Written: 05/21/2008 11:46:48 AM Event ID/Source: 5 / Norton AntiVirus Event Description: Virus Found!Virus name: Trojan.Adclicker in File: C:\WINDOWS\system32\clbdll.dll by: Realtime Protection scan. Action: Clean failed : Quarantine failed : Access denied Event Record #/Type326 / Error Event Submitted/Written: 05/21/2008 11:43:56 AM Event ID/Source: 5 / Norton AntiVirus Event Description: Virus Found!Virus name: Trojan.Adclicker in File: C:\WINDOWS\SYSTEM32\CLBDLL.DLL by: Realtime Protection scan. Action: Clean failed : Quarantine failed : Access denied -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type26585 / Warning Event Submitted/Written: 05/21/2008 11:59:35 AM Event ID/Source: 8193 / LSASRV Event Description: The Security System could not establish a secured connection with the server DNS/prisoner.iana.org. No authentication protocol was available. Event Record #/Type26573 / Error Event Submitted/Written: 05/21/2008 11:58:50 AM Event ID/Source: 29 / W32Time Event Description: The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Event Record #/Type26572 / Warning Event Submitted/Written: 05/21/2008 11:58:50 AM Event ID/Source: 14 / W32Time Event Description: The time provider NtpClient was unable to find a domain controller to use as a time source. NtpClient will try again in 15 minutes. Event Record #/Type26557 / Error Event Submitted/Written: 05/21/2008 11:58:33 AM Event ID/Source: 29 / W32Time Event Description: The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time. Event Record #/Type26556 / Warning Event Submitted/Written: 05/21/2008 11:58:33 AM Event ID/Source: 14 / W32Time Event Description: The time provider NtpClient was unable to find a domain controller to use as a time source. NtpClient will try again in 15 minutes. -- End of Deckard's System Scanner: finished at 2008-05-21 12:13:46 ------------