Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Definite Win32.TDSS infection - Expert Help Required [Solved]


  • This topic is locked This topic is locked

#1
WarGawd

WarGawd

    Member

  • Member
  • PipPip
  • 13 posts
I'll do my best to re-create the chronolgy and all known facts.

I run an Acer Aspire E700 quad core w/ 4Gb ram, Vista Home Premium SP1, with Northon 360 v2 as my primary (only?) protector. I religiously kept up to date with all Windows and Norton updates

On/about May 25/09 I experienced an issue that, after some research, led me to do a System Restore to the previous checkpoint. For the life of me I can't recall that exact issue, but the Restore seemed to work, after which I immediately downloaded and installed all Windows and Norton updates and did a COMPLETE system scan.

System seemed to function fine for several days aftwerward, and being a very heavy user, I believed prob was solved as I was sure I would have encountered problems if not.

Then very late May/Early June a couple days after upgrading to IE8, I had shut down the machine overnight, with a planned reboot in the morning. Ordinarily I'd just put it in sleep mode, but I run a very memory intensive database application which seems to cause issues after a week or so of system uptime. When I rebooted the system and attempted to run IE8, IE8 crashed on startup.

After multiple reboots and re-attempts, I tried a System restore to the point just after all the aforementioned Windows and Norton Updates. System Restore failed with a reported "disk issue" and I immediately began to get suspicious. Upon reboot, I was offered the option to Undo that Restore, which I attempted, and the Undo failed for the same reason.

Tried an earlier Restore Point, same results.

I then elected to uninstall IE8 from the Installed Updates area. Upon reboot, expecting to have reverted to a functioning IE7, I discovered IE7 crashed on Startup in identical fashion. This was puzzling. All other internet connected apps email, poker, games MSN messenger etc still ran ok, as did Norton Live Update.

Decided to enlist some help, got a Firefox browser install file emailed to me. Ran it, Firefox appeared to install successfully, but crashed on first run like IE8.

At that point I had my brother, a network admin get involved (by phone). No amount of disabling/modifying/re-configuring startup files, services etc etc seemed to get us anywhere. Eventually he recommended trying MalwareBytes. He sent via email, application installed ok, crashed on 1st run. Uninstalled, tried in safe mode...no run. Retried in normal mode, could never successfuly get it to update or run.

During this time, began to notice Application Errors piling up in the Event logs, related to very oddly named DLL: "gxvxcgicjxepmahuswxoibwqpioriktsftlvb.dll, version 0.0.0.0" and got more suspicious. REALLY got suspicious when I could NOT find that dll anywhere on the system, nor referenced in the registry despite exhaustive searching.

Next angle....I got him to send me another browser - Opera. Imstalled ok, and actually ran when started, so great now I had net access again and could do some of my own research. 1st tried MS to see if there were known IE8 issues-attempted some of the reccomendations for uninstalling it which seemed to do nothing (as expected given prev uninstall).

Tried googling for the wierd dll - no results.

Reinstalled IE8 - still crashed on start. Followed all recommendations for resetting IE settings, running w/o addons etc, no luck.

Using Opera, went to Norton site to look for info. Discovered some possible issues of conflicts IE8/Norton360 v2, and possible upgrade path. Downloaded N360v3 setup file, but when executed, setup could not connect to complete the installation.

Began to notice that Scans of any type (full, quick, custom) with N360v2 would run for hours with ZERO progress (files scanned always remained at 0)

^%*&^%*&^%!!!

Got Norton tech support involved...they tried a million angles, passed me back and forth for hours. During their attempt to assist, even they failed to get their tools to connect to Symantec sites for updates. 1st tech uninstalled N360v2, could never get it installed again. Supervisor coould not assist, concluded viral cause, but could not pinpoint. then I had to set it aside for a while to feed kids. When I called back they directed me to a paid service, and self help options. Tried self help path to see where I could get to.

Discovered that one of their tools had seemingly had a small impact, as IE8 suddenly started working again. Started googling for online virus scans.

Trend Micro (Housecall??) failed. Couldnt update
Kaspersky failed
PcTools virus scanner installed, updated ok, didnt detect anything
Finally Panda active scan picked something up: w32.tdss.bf.worm in two locations:

globalroot\systemroot\system32\gxvxcgicjxepmahuswxoibwqpioriktsftlvb.dll and
globalroot\systemroot\system32\gxvxcrqietvcnithnyenfftqnantrgqvtsfxu.dll

which led me to this info:
http://www.pandasecu...?idvirus=210378

Googled for info on that, which eventually led me here. Also noticed that point that some webpage links from Google didn't seem to land me where I expected...was puzzled at first but when I looked a little deeper I could tell that they were being "redirected" for lack of better term. Using back button, I could often get to the correct/intended page.

Following info and posts here I began trying to follow the steps in Malware & Spyware Cleaning Guide.
Deleted all temporary files with TFC.

D/L SysRestorePoint.exe, but info on that page suggests tool was dysfuntional, so after reboot following TFC, I manually created a restore point with System Restore. Then I attempted to run SysRestorePoint.exe, which failed with some issue related to Microsoft .Net Framework, error code 0x800423F4. Chose to cancel rather than continue.

Backed up registry with ERUNT, then I exported the ENTIRE registry to another location on my D: drive for good measure {well I suppose that's debateable :-) }

Tried again to run MBAM, 3 or 4 times including the tricks recommended - no luck it still refuses. Here, http://www.bleepingc...opic213273.html there was a reference to unlocking MBAM: http://www.malwareby...showtopic=12709 but following that link gets me a page that IE tells me it can't open, and offers to diagnose connection problem. So I cant get MBAM running.

From info read at various sites (including here) I suspected the nature of the issue was such that a virus may prevent MBAM from running, decided to go to Step 2. Following reccommendations I downloaded and installed Avast. At first opportunity to restart, I elected boot time scan of entire system. Avast picked up 3 instances of BV:Autorun-T in the autorun.inf files on each of C:, D: and K: (my USB key). I had those put in the Chest at that time. Avast did NOT pick up anything else, somewhat disappointingly as I really expecetd to detect someting in System32 folder based on the Panda Scan.

When the Avast boot scan finally finished, WIndows started and after few config steps,the heuristic scanner detected the following:
http://www.pocketfiv...4349293/640x480
Note names similar but not identical to the aforemnentioned weird dll.

Attempts to remove or repair these were thwarted due to file being in use.

Decided to make this post before I reran boot scan with Avast.

Here are the resulting Rooter and OTL logs:

ROOTER:
Microsoft Windows Vista Home Edition (6.0.6001) Service Pack 1

C:\ [Fixed] - NTFS - (Total:233609 Mo/Free:3060 Mo)
D:\ [Fixed] - NTFS - (Total:233334 Mo/Free:2367 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [Removable] (Total:0 Mo/Free:0 Mo)
G:\ [Removable] (Total:0 Mo/Free:0 Mo)
H:\ [Removable] (Total:0 Mo/Free:0 Mo)
I:\ [Removable] (Total:0 Mo/Free:0 Mo)
J:\ [Removable] (Total:0 Mo/Free:0 Mo)
K:\ [Removable] (Total:1927 Mo/Free:620 Mo)

Sun 06/07/2009| 5:05

----------------------\\ Processes..

--Locked-- [System Process]
--Locked-- System
---------- \SystemRoot\System32\smss.exe
---------- C:\Windows\system32\csrss.exe
---------- C:\Windows\system32\wininit.exe
---------- C:\Windows\system32\csrss.exe
---------- C:\Windows\system32\services.exe
---------- C:\Windows\system32\lsass.exe
---------- C:\Windows\system32\lsm.exe
---------- C:\Windows\system32\winlogon.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\system32\Ati2evxx.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\system32\svchost.exe
--Locked-- audiodg.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\SLsvc.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\Ati2evxx.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
---------- C:\Program Files\Alwil Software\Avast4\ashServ.exe
---------- C:\Windows\System32\spoolsv.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\Dwm.exe
---------- C:\Windows\system32\taskeng.exe
---------- C:\Windows\Explorer.EXE
---------- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
---------- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
---------- C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
---------- C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
---------- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
---------- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
---------- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
---------- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
---------- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
---------- C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\system32\SearchIndexer.exe
---------- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
---------- C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
---------- C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
---------- C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
---------- C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
---------- C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
---------- C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
---------- C:\Windows\system32\wbem\wmiprvse.exe
---------- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
---------- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
---------- C:\Program Files\Windows Media Player\wmpnscfg.exe
---------- C:\Program Files\Windows Media Player\wmpnetwk.exe
---------- C:\Windows\system32\wbem\unsecapp.exe
---------- C:\Windows\system32\wbem\wmiprvse.exe
---------- C:\Windows\system32\taskeng.exe
---------- C:\Windows\system32\SearchProtocolHost.exe
---------- C:\Windows\system32\SearchFilterHost.exe
---------- C:\Windows\system32\SearchProtocolHost.exe
---------- C:\Windows\system32\cmd.exe
---------- C:\Rooter$\RK.exe
--Locked-- LVPrcSrv.exe

----------------------\\ Search..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.108,85.255.112.211
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.108,85.255.112.211
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.108,85.255.112.211
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{1D0D20EF-F343-4599-90AE-C33E1ABA64E9}]
NameServer REG_SZ 85.255.112.108,192.168.1.211
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\..\{1D0D20EF-F343-4599-90AE-C33E1ABA64E9}]
NameServer REG_SZ 85.255.112.108,192.168.1.211
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{1D0D20EF-F343-4599-90AE-C33E1ABA64E9}]
NameServer REG_SZ 85.255.112.108,192.168.1.211
==> WAREOUT <==

----------------------\\ ROOTKIT !!



1 - "C:\Rooter$\Rooter_1.txt" - Sun 06/07/2009| 5:06

----------------------\\ Scan completed at 5:06




OTL:

OTL logfile created on: 6/7/2009 5:24:46 AM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\Randy\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 228.13 Gb Total Space | 74.99 Gb Free Space | 32.87% Space Free | Partition Type: NTFS
Drive D: | 227.87 Gb Total Space | 182.31 Gb Free Space | 80.01% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 1.88 Gb Total Space | 0.61 Gb Free Space | 32.18% Space Free | Partition Type: FAT

Computer Name: TAZMANIAC
Current User Name: Randy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe ()
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Users\Randy\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AcerMemUsageCheckService [Auto | Running]) -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe ()
SRV - (AlertService [Auto | Running]) -- C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
SRV - (aswUpdSv [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati External Event Utility [Auto | Running]) -- C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DQLWinService [Auto | Running]) -- C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
SRV - (ehRecvr [On_Demand | Stopped]) -- C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) -- C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) -- C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (eRecoveryService [Auto | Running]) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager [Disabled | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [Disabled | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (IAANTMON [Auto | Running]) -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IntelDHSvcConf [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe (Intel® Corporation)
SRV - (ISSM [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe (Intel® Corporation)
SRV - (LBTServ [On_Demand | Stopped]) -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (LightScribeService [Auto | Running]) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (LVCOMSer [Auto | Running]) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (M1 Server [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe ()
SRV - (MCLServiceATL [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (Intel® Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (pgsql-8.3 [Auto | Running]) -- C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (Steam Client Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Running]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (adp94xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (aic78xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (aswFsBlk [Auto | Running]) -- C:\Windows\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMonFlt [Auto | Running]) -- C:\Windows\system32\DRIVERS\aswMonFlt.sys (ALWIL Software)
DRV - (aswRdr [System | Running]) -- C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) -- C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) -- C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (atikmdag [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (BrFiltLo [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (e1express [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\e1e6032.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (elxstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HECI [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HECI.sys (Intel Corporation)
DRV - (HpCISSs [Disabled | Stopped]) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (iaStor [Boot | Running]) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (iaStorV [Disabled | Stopped]) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (int15 [Auto | Running]) -- C:\Acer\Empowering Technology\eRecovery\int15.sys ()
DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\Windows\system32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (IntelDH [On_Demand | Running]) -- C:\Windows\System32\Drivers\IntelDH.sys (Intel Corporation)
DRV - (iteatapi [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (L8042mou [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\L8042mou.Sys (Logitech Inc.)
DRV - (LHidFilt [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (LMouFilt [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\LMouKE.Sys (Logitech Inc.)
DRV - (LSI_FC [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (lvpopflt [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVRS [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (lvselsus [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvselsus.sys (Logitech Inc.)
DRV - (LVUSBSta [On_Demand | Running]) -- C:\Windows\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVUVC [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (megasas [Disabled | Stopped]) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (nfrd960 [Disabled | Stopped]) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (nmsgopro [Auto | Running]) -- C:\Windows\system32\DRIVERS\nmsgopro.sys (Gteko Ltd.)
DRV - (nmsunidr [Auto | Running]) -- C:\Windows\system32\DRIVERS\nmsunidr.sys (Gteko Ltd.)
DRV - (NTIDrvr [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (ntrigdigi [Disabled | Stopped]) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (pavboot [Boot | Running]) -- C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (ql2300 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (R300 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (RT73 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\Dr71WU.sys (Ralink Technology Inc.)
DRV - (secdrv [Auto | Running]) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (SQTECH905C [On_Demand | Stopped]) -- C:\Windows\System32\Drivers\Capt905c.sys (Service & Quality Technology.)
DRV - (sscdbus [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdbus.sys (MCCI)
DRV - (sscdmdfl [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdmdfl.sys (MCCI)
DRV - (sscdmdm [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdmdm.sys (MCCI)
DRV - (sscdserd [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdserd.sys (MCCI)
DRV - (StillCam [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (Symc8xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (SymVerifyTrust [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\SymVerifyTrust.sys (Symantec Corporation)
DRV - (Sym_hi [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (TSHWMDTCP [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys ()
DRV - (uliahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Running]) -- C:\Windows\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (WmBEnum [On_Demand | Running]) -- C:\Windows\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmFilter [On_Demand | Running]) -- C:\Windows\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmVirHid [On_Demand | Stopped]) -- C:\Windows\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore [On_Demand | Running]) -- C:\Windows\system32\drivers\WmXlCore.sys (Logitech Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://go.microsoft....k/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo....e...-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/05/26 18:17:04 | 00,000,000 | ---D | M]

[2009/05/31 15:17:48 | 00,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\mozilla\Extensions
[2009/05/31 15:17:48 | 00,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/31 15:17:48 | 00,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\mozilla\Firefox\Profiles\qkdepqo8.default\extensions

O1 HOSTS File: (19 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (jZip Webmail plugin) - {647FD14A-C4F1-46F4-8FC3-0B40F54226F7} - C:\Program Files\jZip\WebmailPlugin.dll (Discordia Limited)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨ă¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll (NetZero, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Acer Tour] File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKCU..\Run: [Acer Tour Reminder] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O9 - Extra Button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Poker Rewards Poker - {6DAF93EB-C7E3-41ab-83D9-CAE1785F41BC} - C:\Microgaming\Poker\pokerrewardsMPP\MPPoker.exe (Microgaming)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe ()
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfar...etup1.0.1.0.cab (Reg Error: Key error.)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} http://acs.pandasoft...s/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/...erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplane...C_2.3.7.109.cab (CDownloadCtrl Object)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} https://signin3.valu...018/flashax.cab (FlashXControl Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative....15035/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.108,85.255.112.211
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{1D0D20EF-F343-4599-90AE-C33E1ABA64E9}\\NameServer = 85.255.112.108,192.168.1.211
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\intu-qt2007 {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/07 05:04:06 | 00,000,000 | R--D | M]

========== Files/Folders - Created Within 30 Days ==========

[2009/06/07 05:05:33 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/06/07 05:03:27 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Users\Randy\Desktop\OTL.exe
[2009/06/07 05:02:48 | 00,267,612 | ---- | C] () -- C:\Users\Randy\Desktop\Rooter.exe
[2009/06/07 03:00:13 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2009/06/07 03:00:13 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\Windows\System32\AvastSS.scr
[2009/06/07 03:00:13 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2009/06/07 03:00:13 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2009/06/07 03:00:13 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2009/06/07 03:00:13 | 00,001,853 | ---- | C] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/06/07 03:00:02 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2009/06/07 03:00:02 | 00,380,928 | ---- | C] () -- C:\Windows\System32\actskin4.ocx
[2009/06/07 03:00:02 | 00,051,792 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2009/06/07 03:00:01 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/06/07 02:50:02 | 00,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/07 02:50:00 | 00,040,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/06/07 02:49:59 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/06/07 02:49:58 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/06/07 02:49:58 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/07 02:24:30 | 00,000,000 | ---D | C] -- C:\Windows\ERDNT
[2009/06/07 02:22:34 | 00,000,737 | ---- | C] () -- C:\Users\Randy\Desktop\NTREGOPT.lnk
[2009/06/07 02:22:34 | 00,000,718 | ---- | C] () -- C:\Users\Randy\Desktop\ERUNT.lnk
[2009/06/07 02:22:34 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/07 01:58:57 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\Randy\Desktop\erunt_setup.exe
[2009/06/07 01:58:06 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Users\Randy\Desktop\SysRestorePoint.exe
[2009/06/07 01:54:29 | 00,264,704 | ---- | C] (OldTimer Tools) -- C:\Users\Randy\Desktop\TFC.exe
[2009/06/06 23:19:05 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\Windows\System32\drivers\pavboot.sys
[2009/06/06 23:19:04 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2009/06/06 23:13:18 | 00,000,000 | ---D | C] -- C:\Windows\BDOSCAN8
[2009/06/06 23:12:58 | 00,000,000 | ---D | C] -- C:\Windows\Downloaded Program Files
[2009/06/06 22:08:08 | 44,571,776 | ---- | C] () -- C:\Users\Randy\Desktop\20090606-003-v5i32.exe
[2009/06/06 15:57:42 | 00,000,000 | ---D | C] -- C:\Users\Randy\Documents\Norton Premium Services
[2009/06/06 15:57:01 | 00,002,081 | ---- | C] () -- C:\Users\Public\Desktop\VRQTool.lnk
[2009/06/06 15:57:01 | 00,000,000 | ---D | C] -- C:\def
[2009/06/06 15:49:49 | 34,859,58144 | -HS- | C] () -- C:\hiberfil.sys
[2009/06/06 15:23:03 | 00,000,740 | ---- | C] () -- C:\Users\Randy\Desktop\Download Norton 360 Version 3.lnk
[2009/06/06 15:23:03 | 00,000,000 | ---D | C] -- C:\ProgramData\Symantec Temporary Files
[2009/06/06 14:02:06 | 00,000,000 | ---D | C] -- C:\Users\Randy\Desktop\NortonSecurityScan
[2009/06/06 14:00:35 | 01,881,911 | ---- | C] () -- C:\Users\Randy\Desktop\NortonSecurityScan.exe
[2009/06/06 13:14:06 | 00,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2009/06/06 13:14:06 | 00,000,000 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009/06/06 13:14:05 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2009/06/03 21:57:48 | 00,000,026 | ---- | C] () -- C:\Windows\Zone.Identifier
[2009/06/02 14:29:37 | 00,006,704 | ---- | C] () -- C:\Users\Randy\Documents\WSOP SEAT EBAY LISTING.html
[2009/06/02 14:29:02 | 00,024,970 | ---- | C] () -- C:\Users\Randy\Documents\WSOP SEAT.odt
[2009/06/01 07:19:05 | 00,003,706 | ---- | C] () -- C:\Users\Randy\Documents\test post.html
[2009/06/01 01:40:34 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2009/06/01 01:40:33 | 00,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2009/06/01 01:40:33 | 00,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2009/06/01 01:40:33 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2009/06/01 01:40:33 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2009/06/01 01:40:33 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
[2009/06/01 01:40:33 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
[2009/06/01 01:40:33 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2009/06/01 01:40:33 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2009/06/01 01:40:33 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2009/06/01 01:40:33 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\corpol.dll
[2009/06/01 01:40:32 | 01,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2009/06/01 01:40:32 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2009/06/01 01:40:32 | 00,236,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webcheck.dll
[2009/06/01 01:40:32 | 00,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2009/06/01 01:40:32 | 00,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2009/06/01 01:40:32 | 00,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2009/06/01 01:40:32 | 00,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2009/06/01 01:40:32 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2009/06/01 01:40:32 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2009/06/01 01:40:32 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2009/06/01 01:40:32 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2009/06/01 01:40:32 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2009/06/01 01:40:31 | 00,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2009/06/01 01:40:31 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2009/06/01 01:40:31 | 00,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2009/06/01 01:40:31 | 00,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe
[2009/06/01 01:40:31 | 00,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2009/06/01 01:40:31 | 00,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
[2009/06/01 01:40:31 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2009/06/01 01:40:31 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2009/06/01 01:40:31 | 00,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2009/06/01 01:40:31 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2009/06/01 01:40:31 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2009/06/01 01:40:30 | 00,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2009/06/01 01:40:30 | 00,420,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2009/06/01 01:40:30 | 00,391,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2009/06/01 01:40:30 | 00,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2009/06/01 01:40:30 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2009/06/01 01:40:29 | 03,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2009/06/01 01:40:29 | 01,985,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2009/06/01 01:40:29 | 00,914,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2009/06/01 01:40:29 | 00,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2009/06/01 01:40:29 | 00,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2009/06/01 01:40:29 | 00,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2009/06/01 01:40:29 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PDMSetup.exe
[2009/06/01 01:40:29 | 00,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2009/06/01 01:40:29 | 00,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2009/06/01 01:40:29 | 00,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2009/06/01 01:40:29 | 00,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetDepNx.exe
[2009/06/01 01:40:29 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
[2009/06/01 01:40:28 | 01,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2009/06/01 01:40:28 | 01,206,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2009/06/01 01:40:27 | 11,063,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2009/06/01 01:40:27 | 05,937,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009/06/01 00:30:54 | 00,000,000 | ---D | C] -- C:\Users\Randy\AppData\Roaming\Opera
[2009/06/01 00:30:27 | 00,000,718 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2009/06/01 00:30:26 | 00,000,000 | ---D | C] -- C:\Program Files\Opera
[2009/05/31 20:58:03 | 00,000,846 | ---- | C] () -- C:\Users\Randy\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/31 20:55:33 | 03,371,384 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Randy\Desktop\randombam.exe
[2009/05/31 19:38:01 | 00,000,000 | ---D | C] -- C:\Windows\pss
[2009/05/31 15:17:49 | 00,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/05/31 15:17:47 | 00,000,000 | ---D | C] -- C:\Users\Randy\AppData\Roaming\Mozilla
[2009/05/31 11:05:13 | 00,000,007 | ---- | C] () -- C:\ISACER.id
[2009/05/31 06:24:57 | 00,049,541 | ---- | C] () -- C:\Users\Randy\Documents\WSOP ME Structure.pdf
[2009/05/30 22:49:59 | 00,000,000 | ---D | C] -- C:\RECYCLER
[2009/05/28 23:23:28 | 00,023,966 | ---- | C] () -- C:\Users\Randy\Documents\WSOP ME Structure.ods
[2009/05/27 08:05:43 | 00,280,622 | ---- | C] () -- C:\Users\Randy\Documents\KIDS MP3 Player Manual SYL_SMPK2072_ENFR.pdf
[2009/05/26 18:31:42 | 00,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/05/26 18:31:42 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscb.dll
[2009/05/26 18:31:42 | 00,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/05/26 18:31:42 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshooks.dll
[2009/05/26 18:31:41 | 00,754,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\propsys.dll
[2009/05/26 18:31:41 | 00,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\thawbrkr.dll
[2009/05/26 18:31:41 | 00,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srchadmin.dll
[2009/05/26 18:31:41 | 00,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll
[2009/05/26 18:31:41 | 00,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\korwbrkr.dll
[2009/05/26 18:31:41 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchFilterHost.exe
[2009/05/26 18:31:41 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssitlb.dll
[2009/05/26 18:31:41 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\propdefs.dll
[2009/05/26 18:31:41 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msstrc.dll
[2009/05/26 18:31:41 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssprxy.dll
[2009/05/26 18:31:40 | 11,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex
[2009/05/26 18:31:40 | 06,103,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chtbrkr.dll
[2009/05/26 18:31:40 | 01,671,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chsbrkr.dll
[2009/05/26 18:31:40 | 01,582,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2009/05/26 18:31:40 | 01,418,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2009/05/26 18:31:40 | 00,670,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2009/05/26 18:31:40 | 00,439,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe
[2009/05/26 18:31:40 | 00,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2009/05/26 18:31:40 | 00,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2009/05/26 18:31:40 | 00,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\offfilt.dll
[2009/05/26 18:31:40 | 00,184,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchProtocolHost.exe
[2009/05/26 18:31:40 | 00,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlhtml.dll
[2009/05/26 18:31:40 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2009/05/26 18:31:40 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xmlfilter.dll
[2009/05/26 18:31:40 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mimefilt.dll
[2009/05/26 18:31:40 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtffilt.dll
[2009/05/26 18:31:40 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsepno.dll
[2009/05/26 18:14:13 | 00,105,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/05/26 18:14:13 | 00,097,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardapi.dll
[2009/05/26 18:14:13 | 00,037,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardcpl.cpl
[2009/05/26 18:14:12 | 00,622,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardagt.exe
[2009/05/26 18:14:12 | 00,043,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2009/05/26 18:14:12 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardres.dll
[2009/05/26 18:14:11 | 00,781,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationNative_v0300.dll
[2009/05/26 18:14:10 | 00,326,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2009/05/26 18:09:18 | 00,096,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dfshim.dll
[2009/05/26 18:09:15 | 00,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscoree.dll
[2009/05/26 18:09:14 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2009/05/26 18:08:54 | 00,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscorier.dll
[2009/05/26 18:08:49 | 00,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscories.dll
[2009/05/26 18:06:37 | 00,241,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
[2009/05/26 18:06:33 | 00,712,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecs.dll
[2009/05/26 18:06:33 | 00,425,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
[2009/05/26 18:06:33 | 00,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2009/05/26 18:05:59 | 00,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2009/05/26 18:05:58 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2009/05/26 18:05:58 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2009/05/26 18:05:57 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2009/05/26 18:05:57 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2009/05/26 18:05:57 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2009/05/26 18:05:51 | 01,645,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\connect.dll
[2009/05/26 18:05:49 | 00,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Faultrep.dll
[2009/05/26 18:05:49 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wersvc.dll
[2009/05/22 00:42:53 | 00,373,981 | ---- | C] () -- C:\Users\Randy\Documents\travel insurance policy- WSOP.pdf
[2009/05/12 22:33:31 | 00,071,680 | ---- | C] () -- C:\Users\Randy\Documents\Day Camp Letter.doc
[2009/01/05 15:44:10 | 00,000,453 | ---- | C] () -- C:\Windows\bdoscandellang.ini
[2008/09/09 14:14:43 | 00,011,776 | ---- | C] () -- C:\Windows\System32\pmsbfn32.dll
[2008/09/09 14:08:38 | 00,000,412 | ---- | C] () -- C:\Windows\MAXLINK.INI
[2008/09/09 13:28:24 | 00,003,584 | ---- | C] () -- C:\Windows\System32\CNCFLeNL.DLL
[2008/08/31 00:27:21 | 00,066,482 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2008/07/26 08:25:02 | 00,025,624 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2008/06/03 01:08:58 | 00,023,553 | ---- | C] () -- C:\Windows\System32\ofbdin_.dll
[2008/06/02 23:35:17 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008/04/30 01:50:31 | 00,045,056 | ---- | C] () -- C:\Windows\System32\pagesync.dll
[2007/11/19 23:00:50 | 00,000,392 | ---- | C] () -- C:\Windows\ODBC.INI
[2007/11/16 21:39:23 | 00,000,063 | ---- | C] () -- C:\Windows\wininit.ini
[2007/10/19 20:24:10 | 00,000,467 | ---- | C] () -- C:\Windows\SIERRA.INI
[2007/10/04 23:52:25 | 00,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini
[2007/10/04 23:52:25 | 00,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini
[2007/03/29 21:02:21 | 00,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
[2007/03/29 20:34:37 | 00,331,776 | ---- | C] () -- C:\Windows\System32\ScrollBarLib.dll
[2007/03/29 20:34:37 | 00,053,248 | ---- | C] ( ) -- C:\Windows\System32\Interop.Shell32.dll
[2007/03/29 18:49:30 | 00,000,685 | ---- | C] () -- C:\Windows\generic.ini
[2007/03/29 18:49:30 | 00,000,107 | ---- | C] () -- C:\Windows\Alaunch.ini
[2007/03/29 18:49:28 | 00,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1147.dll
[2006/11/02 08:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 06:23:31 | 00,000,144 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 04:30:49 | 00,024,578 | ---- | C] () -- C:\Windows\System32\wunkged.dll
[2006/11/02 03:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/06/23 12:09:34 | 00,019,968 | R--- | C] () -- C:\Windows\System32\cpuinf32.dll
[2001/12/26 18:12:30 | 00,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 01:46:38 | 00,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001/07/30 18:33:56 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001/07/24 00:04:36 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll

========== Files - Modified Within 30 Days ==========

[2009/06/07 05:03:32 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Users\Randy\Desktop\OTL.exe
[2009/06/07 05:02:50 | 00,267,612 | ---- | M] () -- C:\Users\Randy\Desktop\Rooter.exe
[2009/06/07 04:14:15 | 00,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/06/07 04:14:15 | 00,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/06/07 04:13:56 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/06/07 04:13:44 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/06/07 03:01:18 | 00,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2009/06/07 03:01:12 | 34,859,58144 | -HS- | M] () -- C:\hiberfil.sys
[2009/06/07 03:00:13 | 00,001,853 | ---- | M] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/06/07 03:00:12 | 00,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2009/06/07 02:50:02 | 00,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/07 02:22:34 | 00,000,737 | ---- | M] () -- C:\Users\Randy\Desktop\NTREGOPT.lnk
[2009/06/07 02:22:34 | 00,000,718 | ---- | M] () -- C:\Users\Randy\Desktop\ERUNT.lnk
[2009/06/07 01:59:00 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\Randy\Desktop\erunt_setup.exe
[2009/06/07 01:58:06 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Users\Randy\Desktop\SysRestorePoint.exe
[2009/06/07 01:54:31 | 00,264,704 | ---- | M] (OldTimer Tools) -- C:\Users\Randy\Desktop\TFC.exe
[2009/06/06 22:08:08 | 44,571,776 | ---- | M] () -- C:\Users\Randy\Desktop\20090606-003-v5i32.exe
[2009/06/06 21:46:39 | 00,000,740 | ---- | M] () -- C:\Users\Randy\Desktop\Download Norton 360 Version 3.lnk
[2009/06/06 15:58:21 | 00,000,019 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2009/06/06 15:57:42 | 00,002,081 | ---- | M] () -- C:\Users\Public\Desktop\VRQTool.lnk
[2009/06/06 14:00:35 | 01,881,911 | ---- | M] () -- C:\Users\Randy\Desktop\NortonSecurityScan.exe
[2009/06/06 13:14:06 | 00,000,000 | ---- | M] () -- C:\ProgramData\N360BUOptions.ini
[2009/06/04 03:04:07 | 00,000,026 | ---- | M] () -- C:\Windows\Zone.Identifier
[2009/06/02 14:37:05 | 00,006,704 | ---- | M] () -- C:\Users\Randy\Documents\WSOP SEAT EBAY LISTING.html
[2009/06/02 14:29:02 | 00,024,970 | ---- | M] () -- C:\Users\Randy\Documents\WSOP SEAT.odt
[2009/06/01 07:44:12 | 00,003,706 | ---- | M] () -- C:\Users\Randy\Documents\test post.html
[2009/06/01 00:30:27 | 00,000,718 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2009/05/31 20:58:03 | 00,000,846 | ---- | M] () -- C:\Users\Randy\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/31 20:55:33 | 03,371,384 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Randy\Desktop\randombam.exe
[2009/05/31 15:17:49 | 00,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2009/05/31 11:05:13 | 00,000,007 | ---- | M] () -- C:\ISACER.id
[2009/05/31 06:35:14 | 00,049,541 | ---- | M] () -- C:\Users\Randy\Documents\WSOP ME Structure.pdf
[2009/05/31 06:33:46 | 00,023,966 | ---- | M] () -- C:\Users\Randy\Documents\WSOP ME Structure.ods
[2009/05/27 08:05:43 | 00,280,622 | ---- | M] () -- C:\Users\Randy\Documents\KIDS MP3 Player Manual SYL_SMPK2072_ENFR.pdf
[2009/05/27 05:30:44 | 00,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/05/27 05:30:44 | 00,599,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/05/27 05:30:44 | 00,105,448 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/05/22 00:43:09 | 00,373,981 | ---- | M] () -- C:\Users\Randy\Documents\travel insurance policy- WSOP.pdf
[2009/05/13 12:46:06 | 00,001,891 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/05/12 22:33:34 | 00,071,680 | ---- | M] () -- C:\Users\Randy\Documents\Day Camp Letter.doc

========== Alternate Data Streams ==========

@Alternate Data Stream - 318 bytes -> C:\ProgramData\TEMP:8CEFE51A
@Alternate Data Stream - 24 bytes -> C:\Windows:80196BD8DBB98E4B
@Alternate Data Stream - 211 bytes -> C:\ProgramData\TEMP:B0A96209
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:089A7B08
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:1CFFB598
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:C05A8628
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:8E3D07DE
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:7E95B6FD
< End of report >



OTL EXTRAS:

OTL Extras logfile created on: 6/7/2009 5:24:46 AM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\Randy\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 228.13 Gb Total Space | 74.99 Gb Free Space | 32.87% Space Free | Partition Type: NTFS
Drive D: | 227.87 Gb Total Space | 182.31 Gb Free Space | 80.01% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 1.88 Gb Total Space | 0.61 Gb Free Space | 32.18% Space Free | Partition Type: FAT

Computer Name: TAZMANIAC
Current User Name: Randy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files\Opera\opera.exe (Opera Software)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
Reg Error: Unknown registry data type File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
"DisableNotifications" = 0
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile
"DisableNotifications" = 0
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu File not found
C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption File not found
C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications\List]

========== Vista Active Open Ports Exception List ==========

{10786088-0558-4576-B44F-6BF3AB451A1E} = LPORT=9442 | PROTOCOL=17 | DIR=IN | NAME=INTEL® VIIV™ MEDIA SERVER DISCOVERY |
{3698112C-362F-4AEE-BA59-E96E4BF12736} = LPORT=1900 | PROTOCOL=17 | DIR=IN | APP=SVCHOST.EXE | SVC=SSDPSRV |
{8E7F2898-E0A5-4BDC-A4C6-F4AE1BF0B1F3} = LPORT=2869 | PROTOCOL=6 | DIR=IN | APP=SYSTEM |
{A27A04BD-2071-4226-8531-0D2295C93119} = LPORT=1900 | PROTOCOL=17 | DIR=IN | NAME=INTEL® VIIV™ MEDIA SERVER UPNP DISCOVERY |

========== Vista Active Application Exception List ==========

{04FD94B2-B337-49FF-B025-40C22E3850B4} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\INTEL\INTELDH\INTEL MEDIA SERVER\MEDIA SERVER\BIN\MEDIASERVER.EXE |
{11499062-6BB3-4FA4-921A-F695AC201294} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\INTEL\INTELDH\INTEL MEDIA SERVER\MEDIA SERVER\BIN\MEDIASERVER.EXE |
{2AA03DFD-7528-4567-AD83-79EC8D352513} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\STEAM\STEAMAPPS\COMMON\PEGGLE DELUXE\PEGGLE.EXE |
{341655EE-C8E9-46A4-A79C-4669FBD662ED} = DIR=IN | APP=C:\PROGRAM FILES\ACER ZONE\ACER ZONE MAIN PAGE\MCE DELUXE SUITE.EXE |
{39BE3E02-BE53-42C5-B282-5C5D1CBA271D} = DIR=IN | APP=C:\PROGRAM FILES\ACER ZONE\ACER PLUG AND RECORD\COMPONENT\DVAX2PROCESS.EXE |
{3ADB8AB5-5E7A-4D5B-992E-4DA60454296B} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\INTEL\INTELDH\INTEL MEDIA SERVER\SHELLS\REMOTE UI SERVICE.EXE |
{3C85C8AD-A1B1-46D7-A26C-8F29282EEA4C} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\STEAM\STEAMAPPS\COMMON\PEGGLE NIGHTS\PEGGLENIGHTS.EXE |
{4E591012-80DC-4D96-AA6D-70BC9CAF0A45} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\INTEL\INTELDH\INTEL MEDIA SERVER\SHELLS\REMOTE UI SERVICE.EXE |
{4F15B457-622B-46CE-8BF8-BA8C7589A775} = DIR=IN | APP=C:\PROGRAM FILES\ACER ZONE\ACER PICTURE SLIDE DVD\COMPONENT\CLSLDVD.EXE |
{56029A8B-186F-4ADB-95DB-E7402DEE1F70} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\STEAM\STEAMAPPS\COMMON\PEGGLE DELUXE\PEGGLE.EXE |
{5E9A6AF0-930D-4B39-B828-C7F6FE629A7E} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\LOGITECH\DESKTOP MESSENGER\8876480\PROGRAM\LOGITECHDESKTOPMESSENGER.EXE |
{613CC9A0-5D66-449B-B002-D1F2BBD86002} = DIR=IN | APP=C:\PROGRAM FILES\WINDOWS LIVE\MESSENGER\MSNMSGR.EXE |
{77495009-D0E7-4C71-844C-35BAA92510CA} = DIR=IN | APP=C:\PROGRAM FILES\WINDOWS LIVE\MESSENGER\WLCSDK.EXE |
{786179FC-FC28-424E-B80C-DA61C97E6FA2} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\INTEL\INTELDH\INTEL MEDIA SERVER\MEDIA SERVER\BIN\TSHWMDTCP.EXE |
{7D3AD342-C782-416E-9ECA-2BD66F7D22CA} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\LOGITECH\DESKTOP MESSENGER\8876480\PROGRAM\LOGITECHDESKTOPMESSENGER.EXE |
{922AC9B6-AF2A-4736-A76E-7C73E3BB4427} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE |
{93494BBF-268D-4B14-8985-D1DAE0AE2C44} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\LOGITECH\DESKTOP MESSENGER\8876480\PROGRAM\LOGITECHDESKTOPMESSENGER.EXE |
{CEB38BD8-E0E8-4A89-BC32-952EB865B045} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YSERVER.EXE |
{CFA47F35-9319-4B1D-993D-8FF736F69089} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE |
{D4C3EC93-8880-4581-86D7-2BBA66354979} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\STEAM\STEAMAPPS\COMMON\PEGGLE NIGHTS\PEGGLENIGHTS.EXE |
{D91E3A20-3C08-4D63-BFDE-BE763B8BD70A} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\LOGITECH\DESKTOP MESSENGER\8876480\PROGRAM\LOGITECHDESKTOPMESSENGER.EXE |
{DF45376F-AE9E-41CF-9A52-C96460841211} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YSERVER.EXE |
{E2493805-D524-444E-9086-8F42EE88402C} = DIR=IN | APP=C:\PROGRAM FILES\ACER ZONE\ACER PLUG AND RECORD\COMPONENT\ARAWP.EXE |
{E84884A8-6247-49B4-8DE2-6416180298F9} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\SMARTFTP CLIENT\SMARTFTP.EXE |
{F59C5990-1FB8-4967-86D3-332374A7195D} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\INTEL\INTELDH\INTEL MEDIA SERVER\MEDIA SERVER\BIN\TSHWMDTCP.EXE |
{FADFA5ED-F6FB-4CE0-BC02-D9550B537882} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\SMARTFTP CLIENT\SMARTFTP.EXE |
TCP Query User{427E537B-E42E-4BD3-9C7C-AC4B1B909E35}C:\program files\internet explorer\iexplore.exe = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE |
TCP Query User{AA64F96C-AE81-4F26-B71D-49C2614E4E92}C:\sierra\half-life\hl.exe = PROTOCOL=6 | DIR=IN | APP=C:\SIERRA\HALF-LIFE\HL.EXE |
TCP Query User{E504B1E7-F12B-4882-91F9-B54A044D1FCF}C:\program files\common files\newtech infosystems\liveupdate\liveupdate.exe = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\COMMON FILES\NEWTECH INFOSYSTEMS\LIVEUPDATE\LIVEUPDATE.EXE |
UDP Query User{359599AE-63C3-408B-A5CE-1D0A22851437}C:\program files\common files\newtech infosystems\liveupdate\liveupdate.exe = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\COMMON FILES\NEWTECH INFOSYSTEMS\LIVEUPDATE\LIVEUPDATE.EXE |
UDP Query User{4FE92686-505F-4604-A18A-1EA0F6901072}C:\sierra\half-life\hl.exe = PROTOCOL=17 | DIR=IN | APP=C:\SIERRA\HALF-LIFE\HL.EXE |
UDP Query User{CF17F5E3-4AFE-402C-A61A-289A017B7A03}C:\program files\internet explorer\iexplore.exe = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX700_series" = Canon MX700 series
"{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{20C53FA2-4307-4671-A93F-9463B29DFCF1}" = Symantec Technical Support Web Controls
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22EC35BD-F8F2-45EB-8DCB-1C7FB65D0A71}" = QuickTax 2007
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{26C610BF-761B-4209-BD6A-A0F1B73D6DDE}" = Intel® Viiv™ Software
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3AF8FCCD-F51A-4014-9002-F195E1CBC876}" = Logitech QuickCam
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{41581EF5-45A7-11DA-9D78-000129760D75}" = Acer Picture Slide DVD
"{5C1DA723-24FC-48AD-93BA-925695C3EF26}" = Logitech Gaming Software
"{5C9DDCE0-66CF-11D4-9100-0090274FBE9A}" = Intel® System Information Viewer
"{68D5CEF9-0DA8-47FE-B0EB-4CBFB5AAF662}" = ArcSoft PhotoImpression 4
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6c651250-2eb2-11d5-8e33-0050dad72ac2}" = NetZero Internet
"{6D0C6BE4-F674-43D2-96BC-3509345108C9}_is1" = PokerStove version 1.23
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{83d96ed0-98aa-4515-8ddc-816f3efdd104}" = MyDSC2
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{92BF5DF3-ED6A-4C16-AE2C-97FB0B02A4BB}" = Mini-golf
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{94389919-B0AA-4882-9BE8-9F0B004ECA35}" = Acer Tour
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A14C40E7-F7E5-498D-B8BD-A3EAE942EED0}" = LEGO® Indiana Jones™
"{A2A60894-E3ED-46FE-9A6A-7CF7A87572A0}" = Opera 9.64
"{A46AA50A-5A57-3A6B-B09E-628C09CB7679}" = ATI Catalyst Install Manager
"{AA0D2D5F-612B-45D3-8759-DA87206E5CC9}" = QuickTax 2008
"{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.5
"{AC76BA86-7AD7-1033-7B44-A81300000003}_814" = KB408682
"{B823632F-3B72-4514-8861-B961CE263224}" = PostgreSQL 8.3
"{C169D3BB-9A27-43F5-9979-09A0D65FE95C}" = SmartFTP Client
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}" = Presto! PageManager 7.15.16
"{D462BF9E-0C35-4705-BF9B-3DF9F3816643}" = Acer ePerformance Management
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{DC415D0C-CF77-436A-B27B-CE8A049C1F9D}" = VRQTool
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Zone Main Page
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F6EFFB76-4A07-11DA-9D78-000129760D75}" = Acer Plug and Record
"{F9745BC1-93BD-49B9-A6C8-C005E7E92F3C}" = NTI CD & DVD-Maker
"Acer Assist" = Acer Assist
"Acer Registration" = Acer Registration
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast!" = avast! Antivirus
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"City 14" = City 14
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Download Manager" = Download Manager 2.3.7
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"ERUNT_is1" = ERUNT 1.1j
"FloorPlan v5 LT" = FloorPlan v5 LT
"Google Desktop" = Google Desktop
"Green Eggs and Ham" = Green Eggs and Ham
"Half-Life 2 Awakening 1.1" = Half-Life 2 Awakening 1.1
"HECI" = Intel® Management Engine Interface
"InstallShield_{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{A14C40E7-F7E5-498D-B8BD-A3EAE942EED0}" = LEGO® Indiana Jones™
"InstallShield_{F9745BC1-93BD-49B9-A6C8-C005E7E92F3C}" = NTI CD & DVD-Maker
"Intel® Configuration Center" = Intel® Viiv™ Software
"jZip" = jZip
"Ladbrokes Poker" = Ladbrokes Poker
"legacyqcam_11.10" = Logitech Legacy USB Camera Driver Package
"lvdrivers_11.80" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mansion Poker" = MansionPoker
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Million Dollar Poker Club" = Million Dollar Poker Club
"mIRC" = mIRC
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"Pacific Poker" = Pacific Poker
"PartyPoker" = PartyPoker
"Password Agent 2" = Password Agent 2.5.1
"PayNoRake" = PayNoRake
"Poker Rewards" = Poker Rewards
"Poker Rewards Calculator_is1" = Poker Rewards Calculator 1.0
"PokerRoom.com" = PokerRoom.com (remove only)
"PokerStars" = PokerStars
"PokerTracker3" = PokerTracker 3 (remove only)
"Reiner Knizia's Samurai_is1" = Reiner Knizia's Samurai 1.5.1
"SereneScreen Marine Aquarium 2.6_is1" = SereneScreen Marine Aquarium 2.6
"SmartFTP Client 2.5 Setup Files" = SmartFTP Client 2.5 Setup Files (remove only)
"SQLite ODBC Driver" = SQLite ODBC Driver (remove only)
"Steam App 215" = Source SDK Base
"Steam App 220" = Half-Life 2
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 3480" = Peggle Deluxe
"Steam App 3540" = Peggle Nights
"Steam App 380" = Half-Life 2: Episode One
"Steam App 400" = Portal
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 440" = Team Fortress 2
"SymSetupTemp.{2D617065-1C52-4240-B5BC-C0AE12157777}" = Norton 360
"TowerGaming" = Tower Gaming Poker Room (remove only)
"UltimateBet" = UltimateBet
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! ¤u¨ă¦C
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.0.0.320
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Smilebox" = Hallmark Smilebox
"Universal Replayer" = Universal Replayer

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 6/7/2009 4:27:29 AM | Computer Name = Tazmaniac | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 00000021.

Error - 6/7/2009 4:27:29 AM | Computer Name = Tazmaniac | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 00000021.

[ Application Events ]
Error - 6/7/2009 2:19:46 AM | Computer Name = Tazmaniac | Source = System Restore | ID = 8193
Description =

Error - 6/7/2009 2:39:09 AM | Computer Name = Tazmaniac | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007,
faulting module mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007, exception code
0x80000003, fault offset 0x00002dc0, process id 0x1070, application start time 0x01c9e73aa92d3d5d.

Error - 6/7/2009 2:43:06 AM | Computer Name = Tazmaniac | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007,
faulting module mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007, exception code
0x80000003, fault offset 0x00002dc0, process id 0xc4c, application start time 0x01c9e73b36f1a0ed.

Error - 6/7/2009 2:43:14 AM | Computer Name = Tazmaniac | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007,
faulting module mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007, exception code
0x80000003, fault offset 0x00002dc0, process id 0x1378, application start time 0x01c9e73b3bbb850d.

Error - 6/7/2009 2:44:31 AM | Computer Name = Tazmaniac | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 6/7/2009 2:50:03 AM | Computer Name = Tazmaniac | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007,
faulting module mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007, exception code
0x80000003, fault offset 0x00002dc0, process id 0x104, application start time 0x01c9e73c2f1231f5.

Error - 6/7/2009 2:50:49 AM | Computer Name = Tazmaniac | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007,
faulting module mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007, exception code
0x80000003, fault offset 0x00002dc0, process id 0x300, application start time 0x01c9e73c4adf8135.

Error - 6/7/2009 2:50:58 AM | Computer Name = Tazmaniac | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007,
faulting module mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007, exception code
0x80000003, fault offset 0x00002dc0, process id 0xc68, application start time 0x01c9e73c504e57e5.

Error - 6/7/2009 2:51:14 AM | Computer Name = Tazmaniac | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007,
faulting module mbam.exe, version 1.37.0.0, time stamp 0x4a1c3007, exception code
0x80000003, fault offset 0x00002dc0, process id 0x9f0, application start time 0x01c9e73c59ab6085.

Error - 6/7/2009 4:14:41 AM | Computer Name = Tazmaniac | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

[ Media Center Events ]
Error - 1/20/2008 5:44:39 AM | Computer Name = Tazmaniac | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 4/16/2008 11:28:27 PM | Computer Name = Tazmaniac | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 10/28/2008 3:54:55 AM | Computer Name = Tazmaniac | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 6/7/2009 2:44:12 AM | Computer Name = Tazmaniac | Source = HTTP | ID = 15016
Description =

Error - 6/7/2009 2:44:31 AM | Computer Name = Tazmaniac | Source = Service Control Manager | ID = 7023
Description =

Error - 6/7/2009 2:44:31 AM | Computer Name = Tazmaniac | Source = Service Control Manager | ID = 7001
Description =

Error - 6/7/2009 2:44:31 AM | Computer Name = Tazmaniac | Source = Service Control Manager | ID = 7026
Description =

Error - 6/7/2009 3:00:13 AM | Computer Name = Tazmaniac | Source = Service Control Manager | ID = 7030
Description =

Error - 6/7/2009 3:00:13 AM | Computer Name = Tazmaniac | Source = Service Control Manager | ID = 7030
Description =

Error - 6/7/2009 3:00:13 AM | Computer Name = Tazmaniac | Source = Service Control Manager | ID = 7030
Description =

Error - 6/7/2009 3:00:13 AM | Computer Name = Tazmaniac | Source = Service Control Manager | ID = 7030
Description =

Error - 6/7/2009 4:13:56 AM | Computer Name = Tazmaniac | Source = HTTP | ID = 15016
Description =

Error - 6/7/2009 4:14:34 AM | Computer Name = Tazmaniac | Source = Service Control Manager | ID = 7026
Description =


< End of report >



Ok thats all for now - hope there enough info to help. What's next experts?
Thx
WarGawd
  • 0

Advertisements


#2
WarGawd

WarGawd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Second Bootscan with Avast revealed several more culprits, while the Autorun-T issues appear to have been eliminated for the moment:

07/06/2009 4:33:28 AM Randy 4492 Sign of "Win32:Trojan-gen {Other}" has been found in "c:\windows\system32\gxvxcgicjxepmahuswxoibwqpioriktsftlvb.dll" file.
07/06/2009 7:30:51 AM Randy 7004 Sign of "Win32:Alureon-BH [Rtk]" has been found in "C:\Windows\System32\drivers\gxvxcfpnxvqmpsdojjjhvewsxiosebucgsren.sys" file.
07/06/2009 7:30:51 AM Randy 7004 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Windows\System32\gxvxcgicjxepmahuswxoibwqpioriktsftlvb.dll" file.
07/06/2009 7:30:52 AM Randy 7004 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Windows\System32\gxvxcrqietvcnithnyenfftqnantrgqvtsfxu.dll" file.
07/06/2009 7:30:53 AM Randy 7004 Sign of "Win32:Alureon-BH [Rtk]" has been found in "C:\Windows\system32\drivers\gxvxcfpnxvqmpsdojjjhvewsxiosebucgsren.sys" file.
07/06/2009 7:31:16 AM Randy 7004 Sign of "˜N“@₫" has been found in "C:\Windows\System32\drivers\gxvxcfpnxvqmpsdojjjhvewsxiosebucgsren.sys||AntiRootkit [FILE]||Wi?????????????????????g????Wi|10|0|2|COO1||COO2||C:\Windows\System32\gxvxcgicjxepmahuswxoibwqpioriktsftlvb.dll||AntiRootkit [FILE]||Wi |10|0|2|COO1||COO2||C:\Windows\System32\gxvxcrqietvcnithnyenfftqnantrgqvtsfxu.dll||AntiRootkit [FILE]||Wi????????m?|10|0|2|COO1||COO2||C:\Windows\system32\drivers\gxvxcfpnxvqmpsdojjjhvewsxiosebucgsren.sys||AntiRootkit [SVC]||Wi|40|0|2|COO1||COO2||" file.


All these were removed to the Chest during the boot scan, and I'll continue to scan with various tools and see what I find.

Is it necessary at this stage to upload new Rooter and OTL logs?

Thx
WarGawd
  • 0

#3
WarGawd

WarGawd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
After another full scan by Avast in the Windows environment, several mor items were picked up and put in the Chest:

07/06/2009 10:35:28 AM Randy 5652 Sign of "HTML:Malware-gen" has been found in "C:\Users\Randy\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\63322AF2-00000916.eml\PartNo_0#1339048570" file.
07/06/2009 11:07:40 AM Randy 5652 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Users\Randy\Downloads\PAHud-Install-v1.19.4.exe\$INSTDIR\PAHud.exe" file.
07/06/2009 12:22:37 PM Randy 5652 Sign of "HTML:Malware-gen" has been found in "D:\N360_BACKUP\Drive_C\Users\Randy\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\63322AF2-00000916.eml\PartNo_0#1339048570" file.
07/06/2009 12:44:28 PM Randy 5652 Sign of "HTML:Malware-gen" has been found in "D:\N360_BACKUP\{C16D677B-E25E-457F-812B-935CADFC51ED}\{2\831B638-8A19-4FC0-8F52-67A0193FDB6F}\PartNo_0#1339048570" file.
07/06/2009 12:50:30 PM Randy 5652 Sign of "HTML:Malware-gen" has been found in "D:\N360_BACKUP\{C16D677B-E25E-457F-812B-935CADFC51ED}\{C\222B4B3-E758-4918-BA75-B1F4E1597E01}\PartNo_0#1339048570" file.
07/06/2009 12:52:12 PM Randy 5652 Sign of "Win32:Klez-H [Wrm]" has been found in "D:\OLD PC FILES\D DRIVE\NT Email Storage\Kelly\Inbox.dbx\Mackenzie.eml#102356\millbroo[1].bat#755158202" file.


On a whim I tried MBAM after that last Avast scan completed, and not surprisingly it now runs without crashing. To busy to move ahead at the moment, but looks promising...will update with any results/info.

***EDIT was premature....can run, update capability still not functioning right


Thx
WarGawd

Edited by WarGawd, 07 June 2009 - 11:39 AM.

  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Lets clear your internet connection problem first and then see if Avast has left any of the rootkit behind - Yes I am vain I just love seeing my name in print :)

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.108,85.255.112.211
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{1D0D20EF-F343-4599-90AE-C33E1ABA64E9}\\NameServer = 85.255.112.108,192.168.1.211
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

THEN

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • 0

#5
WarGawd

WarGawd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Thx much Essex - you posted before I had a chance to put up the MBAM log - which clearly shows why I had the internet connection/redirection issue: the DNSchanger trojan. Upon removal of all MBAM detected threats, I temporarily lost internet connectivity, but quickly realized it was only due to the loss of correct DNS IP info:

Malwarebytes' Anti-Malware 1.37
Database version: 2182
Windows 6.0.6001 Service Pack 1

6/7/2009 3:08:27 PM
mbam-log-2009-06-07 (15-08-27).txt

Scan type: Full Scan (C:\|D:\|K:\|)
Objects scanned: 287980
Time elapsed: 1 hour(s), 16 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 23
Registry Values Infected: 0
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.108,85.255.112.211 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1d0d20ef-f343-4599-90ae-c33e1aba64e9}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.108,192.168.1.211 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.108,85.255.112.211 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{1d0d20ef-f343-4599-90ae-c33e1aba64e9}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.108,192.168.1.211 -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

I'll assume for the moment that even though the issue appears corrected, I should just proceed as directed. Wil post again with those results shortly.

Thx
WarGawd
  • 0

#6
WarGawd

WarGawd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Ok after running OTL fix supplied, a reboot, (and reset of DNS server addresses), I also had to login to Geeks again for first time.

Rand OTL scan again with these results (No Extras this time?):

OTL logfile created on: 6/7/2009 8:50:19 PM - Run 2
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\Randy\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 228.13 Gb Total Space | 75.57 Gb Free Space | 33.13% Space Free | Partition Type: NTFS
Drive D: | 227.87 Gb Total Space | 182.31 Gb Free Space | 80.01% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 1.88 Gb Total Space | 0.61 Gb Free Space | 32.18% Space Free | Partition Type: FAT

Computer Name: TAZMANIAC
Current User Name: Randy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe ()
PRC - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Users\Randy\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AcerMemUsageCheckService [Auto | Running]) -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe ()
SRV - (AlertService [Auto | Running]) -- C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
SRV - (aswUpdSv [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati External Event Utility [Auto | Running]) -- C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DQLWinService [Auto | Running]) -- C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
SRV - (ehRecvr [On_Demand | Stopped]) -- C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) -- C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) -- C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (eRecoveryService [Auto | Running]) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager [Disabled | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [Disabled | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (IAANTMON [Auto | Running]) -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IntelDHSvcConf [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe (Intel® Corporation)
SRV - (ISSM [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe (Intel® Corporation)
SRV - (LBTServ [On_Demand | Stopped]) -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (LightScribeService [Auto | Running]) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (LVCOMSer [Auto | Running]) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (M1 Server [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe ()
SRV - (MCLServiceATL [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (Intel® Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (pgsql-8.3 [Auto | Running]) -- C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (Steam Client Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Running]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (adp94xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (aic78xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (aswFsBlk [Auto | Running]) -- C:\Windows\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMonFlt [Auto | Running]) -- C:\Windows\system32\DRIVERS\aswMonFlt.sys (ALWIL Software)
DRV - (aswRdr [System | Running]) -- C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) -- C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) -- C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (atikmdag [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (BrFiltLo [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (e1express [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\e1e6032.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (elxstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HECI [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HECI.sys (Intel Corporation)
DRV - (HpCISSs [Disabled | Stopped]) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (iaStor [Boot | Running]) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (iaStorV [Disabled | Stopped]) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (int15 [Auto | Running]) -- C:\Acer\Empowering Technology\eRecovery\int15.sys ()
DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\Windows\system32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (IntelDH [On_Demand | Running]) -- C:\Windows\System32\Drivers\IntelDH.sys (Intel Corporation)
DRV - (iteatapi [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (L8042mou [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\L8042mou.Sys (Logitech Inc.)
DRV - (LHidFilt [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (LMouFilt [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\LMouKE.Sys (Logitech Inc.)
DRV - (LSI_FC [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (lvpopflt [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVRS [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (lvselsus [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvselsus.sys (Logitech Inc.)
DRV - (LVUSBSta [On_Demand | Running]) -- C:\Windows\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVUVC [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (megasas [Disabled | Stopped]) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (nfrd960 [Disabled | Stopped]) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (nmsgopro [Auto | Running]) -- C:\Windows\system32\DRIVERS\nmsgopro.sys (Gteko Ltd.)
DRV - (nmsunidr [Auto | Running]) -- C:\Windows\system32\DRIVERS\nmsunidr.sys (Gteko Ltd.)
DRV - (NTIDrvr [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (ntrigdigi [Disabled | Stopped]) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (pavboot [Boot | Running]) -- C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (ql2300 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (R300 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (RT73 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\Dr71WU.sys (Ralink Technology Inc.)
DRV - (secdrv [Auto | Running]) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (SQTECH905C [On_Demand | Stopped]) -- C:\Windows\System32\Drivers\Capt905c.sys (Service & Quality Technology.)
DRV - (sscdbus [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdbus.sys (MCCI)
DRV - (sscdmdfl [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdmdfl.sys (MCCI)
DRV - (sscdmdm [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdmdm.sys (MCCI)
DRV - (sscdserd [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdserd.sys (MCCI)
DRV - (StillCam [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (Symc8xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (SymVerifyTrust [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\SymVerifyTrust.sys (Symantec Corporation)
DRV - (Sym_hi [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (TSHWMDTCP [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys ()
DRV - (uliahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Running]) -- C:\Windows\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (WmBEnum [On_Demand | Running]) -- C:\Windows\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmFilter [On_Demand | Running]) -- C:\Windows\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmVirHid [On_Demand | Stopped]) -- C:\Windows\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore [On_Demand | Running]) -- C:\Windows\system32\drivers\WmXlCore.sys (Logitech Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://go.microsoft....k/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo....e...-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/05/26 18:17:04 | 00,000,000 | ---D | M]

[2009/05/31 15:17:48 | 00,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\mozilla\Extensions
[2009/05/31 15:17:48 | 00,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/31 15:17:48 | 00,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\mozilla\Firefox\Profiles\qkdepqo8.default\extensions

O1 HOSTS File: (19 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (jZip Webmail plugin) - {647FD14A-C4F1-46F4-8FC3-0B40F54226F7} - C:\Program Files\jZip\WebmailPlugin.dll (Discordia Limited)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨ă¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll (NetZero, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Acer Tour] File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKCU..\Run: [Acer Tour Reminder] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O9 - Extra Button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Poker Rewards Poker - {6DAF93EB-C7E3-41ab-83D9-CAE1785F41BC} - C:\Microgaming\Poker\pokerrewardsMPP\MPPoker.exe (Microgaming)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe ()
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} http://acs.pandasoft...s/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/...erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplane...C_2.3.7.109.cab (CDownloadCtrl Object)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} https://signin3.valu...018/flashax.cab (FlashXControl Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative....15035/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{1D0D20EF-F343-4599-90AE-C33E1ABA64E9}\\NameServer = 67.55.0.11,66.49.220.95
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\intu-qt2007 {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/07 15:06:53 | 00,000,000 | R--D | M]

========== Files/Folders - Created Within 30 Days ==========

[2009/06/07 20:31:31 | 00,000,000 | ---D | C] -- C:\_OTL
[2009/06/07 13:22:33 | 00,000,000 | ---D | C] -- C:\Users\Randy\AppData\Roaming\Malwarebytes
[2009/06/07 05:05:33 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/06/07 05:03:27 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Users\Randy\Desktop\OTL.exe
[2009/06/07 05:02:48 | 00,267,612 | ---- | C] () -- C:\Users\Randy\Desktop\Rooter.exe
[2009/06/07 03:00:13 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2009/06/07 03:00:13 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\Windows\System32\AvastSS.scr
[2009/06/07 03:00:13 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2009/06/07 03:00:13 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2009/06/07 03:00:13 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2009/06/07 03:00:13 | 00,001,853 | ---- | C] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/06/07 03:00:02 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2009/06/07 03:00:02 | 00,380,928 | ---- | C] () -- C:\Windows\System32\actskin4.ocx
[2009/06/07 03:00:02 | 00,051,792 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2009/06/07 03:00:01 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/06/07 02:50:02 | 00,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/07 02:50:00 | 00,040,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/06/07 02:49:59 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/06/07 02:49:58 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/06/07 02:49:58 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/07 02:24:30 | 00,000,000 | ---D | C] -- C:\Windows\ERDNT
[2009/06/07 02:22:34 | 00,000,737 | ---- | C] () -- C:\Users\Randy\Desktop\NTREGOPT.lnk
[2009/06/07 02:22:34 | 00,000,718 | ---- | C] () -- C:\Users\Randy\Desktop\ERUNT.lnk
[2009/06/07 02:22:34 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/07 01:58:57 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\Randy\Desktop\erunt_setup.exe
[2009/06/07 01:58:06 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Users\Randy\Desktop\SysRestorePoint.exe
[2009/06/07 01:54:29 | 00,264,704 | ---- | C] (OldTimer Tools) -- C:\Users\Randy\Desktop\TFC.exe
[2009/06/06 23:19:05 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\Windows\System32\drivers\pavboot.sys
[2009/06/06 23:19:04 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2009/06/06 23:13:18 | 00,000,000 | ---D | C] -- C:\Windows\BDOSCAN8
[2009/06/06 23:12:58 | 00,000,000 | ---D | C] -- C:\Windows\Downloaded Program Files
[2009/06/06 22:08:08 | 44,571,776 | ---- | C] () -- C:\Users\Randy\Desktop\20090606-003-v5i32.exe
[2009/06/06 15:57:42 | 00,000,000 | ---D | C] -- C:\Users\Randy\Documents\Norton Premium Services
[2009/06/06 15:57:01 | 00,002,081 | ---- | C] () -- C:\Users\Public\Desktop\VRQTool.lnk
[2009/06/06 15:57:01 | 00,000,000 | ---D | C] -- C:\def
[2009/06/06 15:49:49 | 34,880,43008 | -HS- | C] () -- C:\hiberfil.sys
[2009/06/06 15:23:03 | 00,000,740 | ---- | C] () -- C:\Users\Randy\Desktop\Download Norton 360 Version 3.lnk
[2009/06/06 15:23:03 | 00,000,000 | ---D | C] -- C:\ProgramData\Symantec Temporary Files
[2009/06/06 14:02:06 | 00,000,000 | ---D | C] -- C:\Users\Randy\Desktop\NortonSecurityScan
[2009/06/06 14:00:35 | 01,881,911 | ---- | C] () -- C:\Users\Randy\Desktop\NortonSecurityScan.exe
[2009/06/06 13:14:06 | 00,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2009/06/06 13:14:06 | 00,000,000 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009/06/06 13:14:05 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2009/06/03 21:57:48 | 00,000,026 | ---- | C] () -- C:\Windows\Zone.Identifier
[2009/06/02 14:29:37 | 00,006,704 | ---- | C] () -- C:\Users\Randy\Documents\WSOP SEAT EBAY LISTING.html
[2009/06/02 14:29:02 | 00,024,970 | ---- | C] () -- C:\Users\Randy\Documents\WSOP SEAT.odt
[2009/06/01 07:19:05 | 00,003,706 | ---- | C] () -- C:\Users\Randy\Documents\test post.html
[2009/06/01 01:40:34 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2009/06/01 01:40:33 | 00,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2009/06/01 01:40:33 | 00,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2009/06/01 01:40:33 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2009/06/01 01:40:33 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2009/06/01 01:40:33 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
[2009/06/01 01:40:33 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
[2009/06/01 01:40:33 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2009/06/01 01:40:33 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2009/06/01 01:40:33 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2009/06/01 01:40:33 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\corpol.dll
[2009/06/01 01:40:32 | 01,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2009/06/01 01:40:32 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2009/06/01 01:40:32 | 00,236,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webcheck.dll
[2009/06/01 01:40:32 | 00,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2009/06/01 01:40:32 | 00,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2009/06/01 01:40:32 | 00,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2009/06/01 01:40:32 | 00,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2009/06/01 01:40:32 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2009/06/01 01:40:32 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2009/06/01 01:40:32 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2009/06/01 01:40:32 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2009/06/01 01:40:32 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2009/06/01 01:40:31 | 00,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2009/06/01 01:40:31 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2009/06/01 01:40:31 | 00,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2009/06/01 01:40:31 | 00,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe
[2009/06/01 01:40:31 | 00,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2009/06/01 01:40:31 | 00,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
[2009/06/01 01:40:31 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2009/06/01 01:40:31 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2009/06/01 01:40:31 | 00,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2009/06/01 01:40:31 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2009/06/01 01:40:31 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2009/06/01 01:40:30 | 00,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2009/06/01 01:40:30 | 00,420,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2009/06/01 01:40:30 | 00,391,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2009/06/01 01:40:30 | 00,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2009/06/01 01:40:30 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2009/06/01 01:40:29 | 03,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2009/06/01 01:40:29 | 01,985,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2009/06/01 01:40:29 | 00,914,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2009/06/01 01:40:29 | 00,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2009/06/01 01:40:29 | 00,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2009/06/01 01:40:29 | 00,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2009/06/01 01:40:29 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PDMSetup.exe
[2009/06/01 01:40:29 | 00,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2009/06/01 01:40:29 | 00,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2009/06/01 01:40:29 | 00,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2009/06/01 01:40:29 | 00,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetDepNx.exe
[2009/06/01 01:40:29 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
[2009/06/01 01:40:28 | 01,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2009/06/01 01:40:28 | 01,206,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2009/06/01 01:40:27 | 11,063,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2009/06/01 01:40:27 | 05,937,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009/06/01 00:30:54 | 00,000,000 | ---D | C] -- C:\Users\Randy\AppData\Roaming\Opera
[2009/06/01 00:30:27 | 00,000,718 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2009/06/01 00:30:26 | 00,000,000 | ---D | C] -- C:\Program Files\Opera
[2009/05/31 20:58:03 | 00,000,846 | ---- | C] () -- C:\Users\Randy\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/31 20:55:33 | 03,371,384 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Randy\Desktop\randombam.exe
[2009/05/31 19:38:01 | 00,000,000 | ---D | C] -- C:\Windows\pss
[2009/05/31 15:17:49 | 00,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/05/31 15:17:47 | 00,000,000 | ---D | C] -- C:\Users\Randy\AppData\Roaming\Mozilla
[2009/05/31 11:05:13 | 00,000,007 | ---- | C] () -- C:\ISACER.id
[2009/05/31 06:24:57 | 00,049,541 | ---- | C] () -- C:\Users\Randy\Documents\WSOP ME Structure.pdf
[2009/05/30 22:50:03 | 00,000,004 | ---- | C] () -- C:\Windows\System32\gxvxccount
[2009/05/30 22:49:59 | 00,000,000 | ---D | C] -- C:\RECYCLER
[2009/05/28 23:23:28 | 00,023,966 | ---- | C] () -- C:\Users\Randy\Documents\WSOP ME Structure.ods
[2009/05/27 08:05:43 | 00,280,622 | ---- | C] () -- C:\Users\Randy\Documents\KIDS MP3 Player Manual SYL_SMPK2072_ENFR.pdf
[2009/05/26 18:31:42 | 00,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/05/26 18:31:42 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscb.dll
[2009/05/26 18:31:42 | 00,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/05/26 18:31:42 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshooks.dll
[2009/05/26 18:31:41 | 00,754,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\propsys.dll
[2009/05/26 18:31:41 | 00,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\thawbrkr.dll
[2009/05/26 18:31:41 | 00,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srchadmin.dll
[2009/05/26 18:31:41 | 00,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll
[2009/05/26 18:31:41 | 00,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\korwbrkr.dll
[2009/05/26 18:31:41 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchFilterHost.exe
[2009/05/26 18:31:41 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssitlb.dll
[2009/05/26 18:31:41 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\propdefs.dll
[2009/05/26 18:31:41 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msstrc.dll
[2009/05/26 18:31:41 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssprxy.dll
[2009/05/26 18:31:40 | 11,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex
[2009/05/26 18:31:40 | 06,103,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chtbrkr.dll
[2009/05/26 18:31:40 | 01,671,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chsbrkr.dll
[2009/05/26 18:31:40 | 01,582,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2009/05/26 18:31:40 | 01,418,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2009/05/26 18:31:40 | 00,670,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2009/05/26 18:31:40 | 00,439,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe
[2009/05/26 18:31:40 | 00,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2009/05/26 18:31:40 | 00,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2009/05/26 18:31:40 | 00,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\offfilt.dll
[2009/05/26 18:31:40 | 00,184,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchProtocolHost.exe
[2009/05/26 18:31:40 | 00,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlhtml.dll
[2009/05/26 18:31:40 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2009/05/26 18:31:40 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xmlfilter.dll
[2009/05/26 18:31:40 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mimefilt.dll
[2009/05/26 18:31:40 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtffilt.dll
[2009/05/26 18:31:40 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsepno.dll
[2009/05/26 18:14:13 | 00,105,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/05/26 18:14:13 | 00,097,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardapi.dll
[2009/05/26 18:14:13 | 00,037,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardcpl.cpl
[2009/05/26 18:14:12 | 00,622,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardagt.exe
[2009/05/26 18:14:12 | 00,043,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2009/05/26 18:14:12 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardres.dll
[2009/05/26 18:14:11 | 00,781,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationNative_v0300.dll
[2009/05/26 18:14:10 | 00,326,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2009/05/26 18:09:18 | 00,096,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dfshim.dll
[2009/05/26 18:09:15 | 00,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscoree.dll
[2009/05/26 18:09:14 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2009/05/26 18:08:54 | 00,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscorier.dll
[2009/05/26 18:08:49 | 00,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscories.dll
[2009/05/26 18:06:37 | 00,241,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
[2009/05/26 18:06:33 | 00,712,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecs.dll
[2009/05/26 18:06:33 | 00,425,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
[2009/05/26 18:06:33 | 00,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2009/05/26 18:05:59 | 00,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2009/05/26 18:05:58 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2009/05/26 18:05:58 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2009/05/26 18:05:57 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2009/05/26 18:05:57 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2009/05/26 18:05:57 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2009/05/26 18:05:51 | 01,645,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\connect.dll
[2009/05/26 18:05:49 | 00,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Faultrep.dll
[2009/05/26 18:05:49 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wersvc.dll
[2009/05/22 00:42:53 | 00,373,981 | ---- | C] () -- C:\Users\Randy\Documents\travel insurance policy- WSOP.pdf
[2009/05/12 22:33:31 | 00,071,680 | ---- | C] () -- C:\Users\Randy\Documents\Day Camp Letter.doc
[2009/01/05 15:44:10 | 00,000,453 | ---- | C] () -- C:\Windows\bdoscandellang.ini
[2008/09/09 14:14:43 | 00,011,776 | ---- | C] () -- C:\Windows\System32\pmsbfn32.dll
[2008/09/09 14:08:38 | 00,000,412 | ---- | C] () -- C:\Windows\MAXLINK.INI
[2008/09/09 13:28:24 | 00,003,584 | ---- | C] () -- C:\Windows\System32\CNCFLeNL.DLL
[2008/08/31 00:27:21 | 00,066,482 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2008/07/26 08:25:02 | 00,025,624 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2008/06/03 01:08:58 | 00,023,553 | ---- | C] () -- C:\Windows\System32\ofbdin_.dll
[2008/06/02 23:35:17 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008/04/30 01:50:31 | 00,045,056 | ---- | C] () -- C:\Windows\System32\pagesync.dll
[2007/11/19 23:00:50 | 00,000,392 | ---- | C] () -- C:\Windows\ODBC.INI
[2007/11/16 21:39:23 | 00,000,063 | ---- | C] () -- C:\Windows\wininit.ini
[2007/10/19 20:24:10 | 00,000,467 | ---- | C] () -- C:\Windows\SIERRA.INI
[2007/10/04 23:52:25 | 00,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini
[2007/10/04 23:52:25 | 00,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini
[2007/03/29 21:02:21 | 00,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
[2007/03/29 20:34:37 | 00,331,776 | ---- | C] () -- C:\Windows\System32\ScrollBarLib.dll
[2007/03/29 20:34:37 | 00,053,248 | ---- | C] ( ) -- C:\Windows\System32\Interop.Shell32.dll
[2007/03/29 18:49:30 | 00,000,685 | ---- | C] () -- C:\Windows\generic.ini
[2007/03/29 18:49:30 | 00,000,107 | ---- | C] () -- C:\Windows\Alaunch.ini
[2007/03/29 18:49:28 | 00,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1147.dll
[2006/11/02 08:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 06:23:31 | 00,000,144 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 04:30:49 | 00,024,578 | ---- | C] () -- C:\Windows\System32\wunkged.dll
[2006/11/02 03:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/06/23 12:09:34 | 00,019,968 | R--- | C] () -- C:\Windows\System32\cpuinf32.dll
[2001/12/26 18:12:30 | 00,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 01:46:38 | 00,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001/07/30 18:33:56 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001/07/24 00:04:36 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll

========== Files - Modified Within 30 Days ==========

[2009/06/07 20:35:45 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/06/07 20:35:44 | 00,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/06/07 20:35:44 | 00,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/06/07 20:35:41 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/06/07 20:34:59 | 00,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2009/06/07 20:34:56 | 34,880,43008 | -HS- | M] () -- C:\hiberfil.sys
[2009/06/07 05:03:32 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Users\Randy\Desktop\OTL.exe
[2009/06/07 05:02:50 | 00,267,612 | ---- | M] () -- C:\Users\Randy\Desktop\Rooter.exe
[2009/06/07 03:01:07 | 00,000,004 | ---- | M] () -- C:\Windows\System32\gxvxccount
[2009/06/07 03:00:13 | 00,001,853 | ---- | M] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/06/07 03:00:12 | 00,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2009/06/07 02:50:02 | 00,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/07 02:22:34 | 00,000,737 | ---- | M] () -- C:\Users\Randy\Desktop\NTREGOPT.lnk
[2009/06/07 02:22:34 | 00,000,718 | ---- | M] () -- C:\Users\Randy\Desktop\ERUNT.lnk
[2009/06/07 01:59:00 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\Randy\Desktop\erunt_setup.exe
[2009/06/07 01:58:06 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Users\Randy\Desktop\SysRestorePoint.exe
[2009/06/07 01:54:31 | 00,264,704 | ---- | M] (OldTimer Tools) -- C:\Users\Randy\Desktop\TFC.exe
[2009/06/06 22:08:08 | 44,571,776 | ---- | M] () -- C:\Users\Randy\Desktop\20090606-003-v5i32.exe
[2009/06/06 21:46:39 | 00,000,740 | ---- | M] () -- C:\Users\Randy\Desktop\Download Norton 360 Version 3.lnk
[2009/06/06 15:58:21 | 00,000,019 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2009/06/06 15:57:42 | 00,002,081 | ---- | M] () -- C:\Users\Public\Desktop\VRQTool.lnk
[2009/06/06 14:00:35 | 01,881,911 | ---- | M] () -- C:\Users\Randy\Desktop\NortonSecurityScan.exe
[2009/06/06 13:14:06 | 00,000,000 | ---- | M] () -- C:\ProgramData\N360BUOptions.ini
[2009/06/04 03:04:07 | 00,000,026 | ---- | M] () -- C:\Windows\Zone.Identifier
[2009/06/02 14:37:05 | 00,006,704 | ---- | M] () -- C:\Users\Randy\Documents\WSOP SEAT EBAY LISTING.html
[2009/06/02 14:29:02 | 00,024,970 | ---- | M] () -- C:\Users\Randy\Documents\WSOP SEAT.odt
[2009/06/01 07:44:12 | 00,003,706 | ---- | M] () -- C:\Users\Randy\Documents\test post.html
[2009/06/01 00:30:27 | 00,000,718 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2009/05/31 20:58:03 | 00,000,846 | ---- | M] () -- C:\Users\Randy\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/31 20:55:33 | 03,371,384 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Randy\Desktop\randombam.exe
[2009/05/31 15:17:49 | 00,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2009/05/31 11:05:13 | 00,000,007 | ---- | M] () -- C:\ISACER.id
[2009/05/31 06:35:14 | 00,049,541 | ---- | M] () -- C:\Users\Randy\Documents\WSOP ME Structure.pdf
[2009/05/31 06:33:46 | 00,023,966 | ---- | M] () -- C:\Users\Randy\Documents\WSOP ME Structure.ods
[2009/05/27 08:05:43 | 00,280,622 | ---- | M] () -- C:\Users\Randy\Documents\KIDS MP3 Player Manual SYL_SMPK2072_ENFR.pdf
[2009/05/27 05:30:44 | 00,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/05/27 05:30:44 | 00,599,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/05/27 05:30:44 | 00,105,448 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/05/22 00:43:09 | 00,373,981 | ---- | M] () -- C:\Users\Randy\Documents\travel insurance policy- WSOP.pdf
[2009/05/13 12:46:06 | 00,001,891 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/05/12 22:33:34 | 00,071,680 | ---- | M] () -- C:\Users\Randy\Documents\Day Camp Letter.doc

========== Alternate Data Streams ==========

@Alternate Data Stream - 318 bytes -> C:\ProgramData\TEMP:8CEFE51A
@Alternate Data Stream - 24 bytes -> C:\Windows:80196BD8DBB98E4B
@Alternate Data Stream - 211 bytes -> C:\ProgramData\TEMP:B0A96209
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:089A7B08
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:1CFFB598
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:C05A8628
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:8E3D07DE
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:7E95B6FD
< End of report >


On to combofix.....

WarGawd
  • 0

#7
WarGawd

WarGawd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Hmmmm

Combofix ran to a point where it indicated that the log file would be in C:\ComboFix.txt (last stage # I recall seeing was ~41 or 42???) and shortly after, appeared to crash the system. Had the vague impression that it was just about to close the Command prompt window, but can't be sure. At no point did it give any indications regarding Windows Recovery Console.

Rebooted after crash, looked for log file in stated location, was not there but one was located in sub-folder ComboFix (ie C:\ComboFix\Combofix.txt) which is posted below.

When I went to post it as a reply here, I discovered network config changes prevented internet access, and I had to "play" a good deal to get a collective group of settings that functioned. (As literate as I consider myself to be, my biggest weakness is in the area of network setup/config. Anyway, I'm here now, will post the ComboFix log I did find, but I have a sneaky suspicion it's incomplete. Will re-run ComboFix after posting this log, in hopes no crash occurs near end of process, and hopefully find my way back here ;-)

ComboFix 09-06-07.03 - Randy 06/07/2009 21:11:44.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.3326.2368 [GMT -4:00]
Running from: C:\Users\Randy\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\system32\drivers\lvuvc.hs
C:\Windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
C:\Windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
C:\Windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
C:\Windows\system32\x64
C:\Windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_GXVXCSERV.SYS
-------\Service_gxvxcserv.sys


((((((((((((((((((((((((( Files Created from 2009-05-08 to 2009-06-08 )))))))))))))))))))))))))))))))
.

2009-06-08 01:10:09 . 2009-06-08 01:10:12 0 d-----w- \Qoobox
2009-06-08 00:31:31 . 2009-06-08 00:31:31 0 d-----w- C:\_OTL
2009-06-08 00:31:31 . 2009-06-08 00:31:31 0 d-----w- \_OTL
2009-06-07 17:22:33 . 2009-06-07 17:22:33 0 d-----w- C:\Users\Randy\AppData\Roaming\Malwarebytes
2009-06-07 09:05:33 . 2009-06-07 09:06:28 0 d-----w- C:\Rooter$
2009-06-07 09:05:33 . 2009-06-07 09:06:28 0 d-----w- \Rooter$
2009-06-07 07:00:13 . 2009-02-05 20:07:23 114768 ----a-w- C:\Windows\system32\drivers\aswSP.sys
2009-06-07 07:00:13 . 2009-02-05 20:07:12 20560 ----a-w- C:\Windows\system32\drivers\aswFsBlk.sys
2009-06-07 07:00:13 . 2009-02-05 20:06:20 51376 ----a-w- C:\Windows\system32\drivers\aswTdi.sys
2009-06-07 07:00:13 . 2009-02-05 20:06:10 23152 ----a-w- C:\Windows\system32\drivers\aswRdr.sys
2009-06-07 07:00:13 . 2009-02-05 20:04:45 97480 ----a-w- C:\Windows\system32\AvastSS.scr
2009-06-07 07:00:02 . 2009-02-05 20:11:35 1256296 ----a-w- C:\Windows\system32\aswBoot.exe
2009-06-07 07:00:02 . 2009-02-05 20:06:59 51792 ----a-w- C:\Windows\system32\drivers\aswMonFlt.sys
2009-06-07 07:00:01 . 2009-06-07 07:00:01 0 d-----w- C:\Program Files\Alwil Software
2009-06-07 06:50:00 . 2009-05-26 17:20:08 40160 ----a-w- C:\Windows\system32\drivers\mbamswissarmy.sys
2009-06-07 06:49:59 . 2009-06-07 06:49:59 0 d-----w- C:\ProgramData\Malwarebytes
2009-06-07 06:49:58 . 2009-06-07 06:50:03 0 d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-07 06:49:58 . 2009-05-26 17:19:56 19096 ----a-w- C:\Windows\system32\drivers\mbam.sys
2009-06-07 06:29:59 . 2009-06-07 06:30:03 0 d-----w- C:\Users\Randy\AppData\Local\MigWiz
2009-06-07 06:22:34 . 2009-06-07 06:22:49 0 d-----w- C:\Program Files\ERUNT
2009-06-07 03:19:05 . 2008-06-19 21:24:30 28544 ----a-w- C:\Windows\system32\drivers\pavboot.sys
2009-06-07 03:19:04 . 2009-06-07 03:19:04 0 d-----w- C:\Program Files\Panda Security
2009-06-07 03:13:18 . 2009-06-07 03:14:57 0 d-----w- C:\Windows\BDOSCAN8
2009-06-07 03:12:58 . 2009-06-07 03:18:51 0 d-----w- C:\Windows\Downloaded Program Files
2009-06-07 02:32:07 . 2009-06-07 03:00:23 0 d-----w- C:\Users\Randy\.housecall6.6
2009-06-06 19:57:01 . 2009-06-06 19:57:01 0 d-----w- C:\def
2009-06-06 19:57:01 . 2009-06-06 19:57:01 0 d-----w- \def
2009-06-06 19:49:49 . 2009-06-08 01:16:25 3485974528 --sha-w- \hiberfil.sys
2009-06-06 19:23:03 . 2009-06-06 19:23:03 0 d-----w- C:\ProgramData\Symantec Temporary Files
2009-06-06 19:23:03 . 2009-06-06 19:23:03 0 ----a-w- C:\ProgramData\Symantec Temporary Files\N360S300EN.exe
2009-06-01 04:30:54 . 2009-06-01 04:30:54 0 d-----w- C:\Users\Randy\AppData\Local\Opera
2009-06-01 04:30:26 . 2009-06-01 04:30:27 0 d-----w- C:\Program Files\Opera
2009-05-31 19:17:49 . 2009-05-31 19:17:49 0 ----a-w- C:\Windows\nsreg.dat
2009-05-31 19:17:47 . 2009-05-31 19:17:47 0 d-----w- C:\Users\Randy\AppData\Local\Mozilla
2009-05-26 22:14:13 . 2008-06-20 01:14:45 105016 ----a-w- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-05-26 22:14:13 . 2008-06-20 01:14:34 97800 ----a-w- C:\Windows\system32\infocardapi.dll
2009-05-26 22:14:12 . 2008-06-20 01:14:45 43544 ----a-w- C:\Windows\system32\PresentationHostProxy.dll
2009-05-26 22:14:12 . 2008-06-20 01:14:34 11264 ----a-w- C:\Windows\system32\icardres.dll
2009-05-26 22:14:12 . 2008-06-20 01:14:33 622080 ----a-w- C:\Windows\system32\icardagt.exe
2009-05-26 22:14:11 . 2008-06-20 01:14:45 781344 ----a-w- C:\Windows\system32\PresentationNative_v0300.dll
2009-05-26 22:14:10 . 2008-06-20 01:14:45 326160 ----a-w- C:\Windows\system32\PresentationHost.exe
2009-05-26 22:09:18 . 2008-07-27 18:03:16 96760 ----a-w- C:\Windows\system32\dfshim.dll
2009-05-26 22:09:15 . 2008-07-27 18:03:17 282112 ----a-w- C:\Windows\system32\mscoree.dll
2009-05-26 22:09:14 . 2008-07-27 18:03:17 41984 ----a-w- C:\Windows\system32\netfxperf.dll
2009-05-26 22:08:54 . 2008-07-27 18:03:17 158720 ----a-w- C:\Windows\system32\mscorier.dll
2009-05-26 22:08:49 . 2008-07-27 18:03:17 83968 ----a-w- C:\Windows\system32\mscories.dll
2009-05-26 22:06:37 . 2008-10-22 03:57:30 241152 ----a-w- C:\Windows\system32\PortableDeviceApi.dll
2009-05-26 22:06:33 . 2008-08-28 03:40:11 712704 ----a-w- C:\Windows\system32\WindowsCodecs.dll
2009-05-26 22:06:33 . 2008-08-28 03:40:11 347136 ----a-w- C:\Windows\system32\WindowsCodecsExt.dll
2009-05-26 22:06:33 . 2008-08-28 03:40:09 425472 ----a-w- C:\Windows\system32\PhotoMetadataHandler.dll
2009-05-26 22:05:59 . 2008-12-05 04:32:35 428544 ----a-w- C:\Windows\system32\EncDec.dll
2009-05-26 22:05:58 . 2008-12-05 04:32:36 293376 ----a-w- C:\Windows\system32\psisdecd.dll
2009-05-26 22:05:51 . 2008-10-21 05:25:17 1645568 ----a-w- C:\Windows\system32\connect.dll
2009-05-26 22:05:49 . 2008-09-18 04:56:07 125952 ----a-w- C:\Windows\system32\wersvc.dll
2009-05-26 22:05:49 . 2008-09-18 04:56:02 147456 ----a-w- C:\Windows\system32\Faultrep.dll
2009-05-26 20:11:14 . 2009-05-26 20:11:14 0 d-----w- C:\Users\Randy\AppData\Local\Symantec

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-08 01:16:25 . 2009-06-06 19:49:49 3485974528 --sha-w- \hiberfil.sys
2009-06-08 01:16:23 . 2007-10-05 04:28:37 3801694208 --sha-w- \pagefile.sys
2009-06-07 02:41:48 . 2008-07-24 14:49:47 0 d-----w- C:\Users\Randy\AppData\Roaming\OpenOffice.org2
2009-06-06 20:38:58 . 2008-07-24 14:50:46 1 ----a-w- C:\Users\Randy\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-06-06 18:51:37 . 2008-07-21 16:36:39 680 ----a-w- C:\Users\Randy\AppData\Local\d3d9caps.dat
2009-06-06 17:14:13 . 2009-06-06 17:14:05 0 d-----w- C:\Program Files\Common Files\Symantec Shared
2009-06-06 17:14:06 . 2009-06-06 17:14:06 0 d-----w- C:\ProgramData\Symantec
2009-06-06 16:32:44 . 2009-02-21 10:23:33 0 d-----w- C:\ProgramData\old
2009-06-06 16:30:30 . 2008-02-23 20:01:58 0 d-----w- C:\Users\Randy\AppData\Roaming\Symantec
2009-06-03 17:18:47 . 2008-06-03 04:43:25 0 d-----w- C:\Program Files\PokerTracker 3
2009-06-01 11:00:58 . 2009-01-23 07:41:00 0 d-----w- C:\Program Files\Full Tilt Poker
2009-05-26 22:08:05 . 2006-11-02 11:18:33 0 d-----w- C:\Program Files\Windows Mail
2009-05-22 15:20:24 . 2007-11-24 16:24:48 0 d-----w- C:\Program Files\Steam
2009-04-25 15:42:55 . 2007-11-24 16:24:52 0 d-----w- C:\Program Files\Common Files\Steam
2009-04-25 05:52:01 . 2009-04-25 05:52:00 17 ----a-w- C:\Windows\popcinfo.dat
2009-04-24 02:05:33 . 2008-01-19 04:13:09 0 d-----w- C:\Program Files\Java
2009-04-22 05:27:11 . 2009-04-22 05:27:06 0 d-----w- C:\Program Files\NetZero
2009-04-22 05:27:05 . 2009-04-22 05:27:05 0 d-----w- C:\ProgramData\NetZero
2009-04-21 06:12:41 . 2007-10-20 06:48:05 0 d-----w- C:\Program Files\TowerGaming
2009-04-21 06:04:52 . 2008-09-04 16:57:28 0 d-----w- C:\Program Files\Million Dollar Poker Club
2009-04-17 16:49:49 . 2007-10-14 18:18:10 0 d-----w- C:\Users\Randy\AppData\Roaming\Microgaming
2009-04-15 00:56:03 . 2009-02-27 02:19:51 0 d-----w- C:\Program Files\QuickTax 2008
2009-04-12 20:37:30 . 2008-12-13 16:52:34 0 d-----w- C:\ProgramData\Steam
2009-04-12 20:37:27 . 2008-12-13 16:52:18 0 d-----w- C:\ProgramData\PopCap Games
2009-04-10 01:11:16 . 2009-04-10 01:11:16 0 d-----w- C:\Program Files\Citrix
2009-04-10 01:10:55 . 2009-04-10 01:10:54 60744 ----a-w- C:\Users\Randy\g2mdlhlpx.exe
2009-03-17 03:38:46 . 2009-04-16 00:38:55 13824 ----a-w- C:\Windows\system32\apilogen.dll
2009-03-17 03:38:44 . 2009-04-16 00:38:55 24064 ----a-w- C:\Windows\system32\amxread.dll
2009-03-15 16:45:57 . 2009-03-15 16:45:57 10344 ----a-w- C:\Windows\system32\drivers\symlcbrd.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 20:08:45 81000]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-16 01:39:08 151552]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=C:\Windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\Windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\Windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{341655EE-C8E9-46A4-A79C-4669FBD662ED}"= C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{4F15B457-622B-46CE-8BF8-BA8C7589A775}"= C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{E2493805-D524-444E-9086-8F42EE88402C}"= C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{39BE3E02-BE53-42C5-B282-5C5D1CBA271D}"= C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{786179FC-FC28-424E-B80C-DA61C97E6FA2}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{F59C5990-1FB8-4967-86D3-332374A7195D}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{3ADB8AB5-5E7A-4D5B-992E-4DA60454296B}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{4E591012-80DC-4D96-AA6D-70BC9CAF0A45}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{11499062-6BB3-4FA4-921A-F695AC201294}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv™ Media Server
"{04FD94B2-B337-49FF-B025-40C22E3850B4}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv™ Media Server
"{10786088-0558-4576-B44F-6BF3AB451A1E}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1:Intel® Viiv™ Media Server Discovery
"{A27A04BD-2071-4226-8531-0D2295C93119}"= TCP:Profile=Private|Profile=Public|1900:LocalSubnet:LocalSubnet:Intel® Viiv™ Media Server UPnP Discovery
"{FADFA5ED-F6FB-4CE0-BC02-D9550B537882}"= UDP:C:\Program Files\SmartFTP Client\SmartFTP.exe:SmartFTP Client
"{E84884A8-6247-49B4-8DE2-6416180298F9}"= TCP:C:\Program Files\SmartFTP Client\SmartFTP.exe:SmartFTP Client
"TCP Query User{E504B1E7-F12B-4882-91F9-B54A044D1FCF}C:\\program files\\common files\\newtech infosystems\\liveupdate\\liveupdate.exe"= UDP:C:\program files\common files\newtech infosystems\liveupdate\liveupdate.exe:LiveUpdate
"UDP Query User{359599AE-63C3-408B-A5CE-1D0A22851437}C:\\program files\\common files\\newtech infosystems\\liveupdate\\liveupdate.exe"= TCP:C:\program files\common files\newtech infosystems\liveupdate\liveupdate.exe:LiveUpdate
"{922AC9B6-AF2A-4736-A76E-7C73E3BB4427}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{CFA47F35-9319-4B1D-993D-8FF736F69089}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{DF45376F-AE9E-41CF-9A52-C96460841211}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{CEB38BD8-E0E8-4A89-BC32-952EB865B045}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{7D3AD342-C782-416E-9ECA-2BD66F7D22CA}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{93494BBF-268D-4B14-8985-D1DAE0AE2C44}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{D91E3A20-3C08-4D63-BFDE-BE763B8BD70A}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{5E9A6AF0-930D-4B39-B828-C7F6FE629A7E}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{56029A8B-186F-4ADB-95DB-E7402DEE1F70}"= UDP:C:\Program Files\Steam\SteamApps\common\peggle deluxe\Peggle.exe:Peggle Deluxe
"{2AA03DFD-7528-4567-AD83-79EC8D352513}"= TCP:C:\Program Files\Steam\SteamApps\common\peggle deluxe\Peggle.exe:Peggle Deluxe
"{D4C3EC93-8880-4581-86D7-2BBA66354979}"= UDP:C:\Program Files\Steam\SteamApps\common\peggle nights\PeggleNights.exe:Peggle Nights
"{3C85C8AD-A1B1-46D7-A26C-8F29282EEA4C}"= TCP:C:\Program Files\Steam\SteamApps\common\peggle nights\PeggleNights.exe:Peggle Nights

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"C:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"C:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption

R0 pavboot;pavboot;C:\Windows\System32\drivers\pavboot.sys [6/6/2009 11:19:05 PM 28544]
R1 aswSP;avast! Self Protection;C:\Windows\System32\drivers\aswSP.sys [6/7/2009 3:00:13 AM 114768]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [6/7/2009 3:00:13 AM 20560]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [6/7/2009 3:00:02 AM 51792]
R2 DQLWinService;DQLWinService;C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [10/29/2006 12:03:30 PM 208896]
R2 nmsgopro;GoProto Protocol Driver for NMS;C:\Windows\System32\drivers\nmsgopro.sys [9/27/2006 7:37:24 PM 28672]
R2 nmsunidr;UniDriver for NMS;C:\Windows\System32\drivers\nmsunidr.sys [10/19/2006 6:49:48 PM 7424]
R2 pgsql-8.3;PostgreSQL Database Server 8.3;C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe [2/1/2008 4:02:26 AM 65536]
R3 IntelDH;IntelDH Driver;C:\Windows\System32\drivers\IntelDH.sys [10/5/2007 12:33:37 AM 5504]
R3 SymVerifyTrust;SymVerifyTrust;C:\Program Files\Common Files\Symantec Shared\EENGINE\SymVerifyTrust.sys [10/13/2008 8:16:16 PM 280112]
S3 IntelDHSvcConf;IntelDHSvcConf;C:\Program Files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [11/18/2006 9:59:50 AM 36312]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Acer Tour Reminder - (no file)
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.ca/
IE: {{10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltimateBet\UltimateBet.lnk
IE: {{6DAF93EB-C7E3-41ab-83D9-CAE1785F41BC} - C:\Microgaming\Poker\pokerrewardsMPP\MPPoker.exe
TCP: {1D0D20EF-F343-4599-90AE-C33E1ABA64E9} = 67.55.0.11,66.49.220.95
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
.
(yes, that's how the file ends...)

Thx
WarGawd

***EDIT - I now see at beginning of log that Defender was enabled and prob shouldn't have been, thought Avast was the only thing running, and I HAD disabled that - will turn off Defender before this attempt.

Edited by WarGawd, 07 June 2009 - 08:26 PM.

  • 0

#8
WarGawd

WarGawd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Well my intuiton was correct, last ComboFix log was incomplete due to crash.

I had disabled Defender's realtime protection prior to this run. However with Avast running at startup, when ComboFix initiates a reboot, Avast starts with On-Access protection enabled - I also managed to quickly turn that off to avoid possible intereference with ComboFix. May have been either of these that resulted in last crash, but this time CF ran to completion and put the log in C:\ as stated. Here it is: (BTW still no reference to Recovery Console, so I assume it's already installed) (Network config fix this time amounted to a simple entry of the default gateway for the network connection)

ComboFix 09-06-07.03 - Randy 06/07/2009 22:38.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.3326.2405 [GMT -4:00]
Running from: c:\users\Randy\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\lvuvc.hs
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
---- Previous Run -------
.
c:\windows\system32\drivers\lvuvc.hs
c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
c:\windows\system32\x64
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_GXVXCSERV.SYS
-------\Service_gxvxcserv.sys


((((((((((((((((((((((((( Files Created from 2009-05-08 to 2009-06-08 )))))))))))))))))))))))))))))))
.

2009-06-08 02:43 . 2009-06-08 02:43 -------- d-sh--w- \$RECYCLE.BIN
2009-06-08 02:42 . 2009-06-08 02:43 -------- d-----w- c:\users\Randy\AppData\Local\temp
2009-06-08 02:42 . 2009-06-08 02:42 -------- d-----w- c:\users\postgres\AppData\Local\temp
2009-06-08 02:38 . 2009-06-08 02:43 -------- d-s---w- \ComboFix
2009-06-08 01:10 . 2009-06-08 01:22 -------- d-----w- \Qoobox
2009-06-08 00:31 . 2009-06-08 00:31 -------- d-----w- C:\_OTL
2009-06-08 00:31 . 2009-06-08 00:31 -------- d-----w- \_OTL
2009-06-07 17:22 . 2009-06-07 17:22 -------- d-----w- c:\users\Randy\AppData\Roaming\Malwarebytes
2009-06-07 09:05 . 2009-06-07 09:06 -------- d-----w- C:\Rooter$
2009-06-07 09:05 . 2009-06-07 09:06 -------- d-----w- \Rooter$
2009-06-07 07:00 . 2009-02-05 20:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-06-07 07:00 . 2009-02-05 20:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-06-07 07:00 . 2009-02-05 20:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-06-07 07:00 . 2009-02-05 20:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-06-07 07:00 . 2009-02-05 20:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-06-07 07:00 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-06-07 07:00 . 2009-02-05 20:06 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-06-07 07:00 . 2009-06-07 07:00 -------- d-----w- c:\program files\Alwil Software
2009-06-07 06:50 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-07 06:49 . 2009-06-07 06:49 -------- d-----w- c:\programdata\Malwarebytes
2009-06-07 06:49 . 2009-06-07 06:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-07 06:49 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-07 06:29 . 2009-06-07 06:30 -------- d-----w- c:\users\Randy\AppData\Local\MigWiz
2009-06-07 06:22 . 2009-06-07 06:22 -------- d-----w- c:\program files\ERUNT
2009-06-07 03:19 . 2008-06-19 21:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-06-07 03:19 . 2009-06-07 03:19 -------- d-----w- c:\program files\Panda Security
2009-06-07 03:13 . 2009-06-07 03:14 -------- d-----w- c:\windows\BDOSCAN8
2009-06-07 03:12 . 2009-06-07 03:18 -------- d-----w- c:\windows\Downloaded Program Files
2009-06-07 02:32 . 2009-06-07 03:00 -------- d-----w- c:\users\Randy\.housecall6.6
2009-06-06 19:57 . 2009-06-06 19:57 -------- d-----w- C:\def
2009-06-06 19:57 . 2009-06-06 19:57 -------- d-----w- \def
2009-06-06 19:49 . 2009-06-08 02:42 3488043008 --sha-w- \hiberfil.sys
2009-06-06 19:23 . 2009-06-06 19:23 -------- d-----w- c:\programdata\Symantec Temporary Files
2009-06-06 19:23 . 2009-06-06 19:23 0 ----a-w- c:\programdata\Symantec Temporary Files\N360S300EN.exe
2009-06-01 04:30 . 2009-06-01 04:30 -------- d-----w- c:\users\Randy\AppData\Local\Opera
2009-06-01 04:30 . 2009-06-01 04:30 -------- d-----w- c:\program files\Opera
2009-05-31 19:17 . 2009-05-31 19:17 0 ----a-w- c:\windows\nsreg.dat
2009-05-31 19:17 . 2009-05-31 19:17 -------- d-----w- c:\users\Randy\AppData\Local\Mozilla
2009-05-26 22:14 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-05-26 22:14 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-05-26 22:14 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-05-26 22:14 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2009-05-26 22:14 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-05-26 22:14 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-05-26 22:14 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-05-26 22:09 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-05-26 22:09 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-05-26 22:09 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-05-26 22:08 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2009-05-26 22:08 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
2009-05-26 22:06 . 2008-10-22 03:57 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-05-26 22:06 . 2008-08-28 03:40 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-05-26 22:06 . 2008-08-28 03:40 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-05-26 22:06 . 2008-08-28 03:40 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-05-26 22:05 . 2008-12-05 04:32 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-05-26 22:05 . 2008-12-05 04:32 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-05-26 22:05 . 2008-10-21 05:25 1645568 ----a-w- c:\windows\system32\connect.dll
2009-05-26 22:05 . 2008-09-18 04:56 125952 ----a-w- c:\windows\system32\wersvc.dll
2009-05-26 22:05 . 2008-09-18 04:56 147456 ----a-w- c:\windows\system32\Faultrep.dll
2009-05-26 20:11 . 2009-05-26 20:11 -------- d-----w- c:\users\Randy\AppData\Local\Symantec

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-08 02:42 . 2009-06-06 19:49 3488043008 --sha-w- \hiberfil.sys
2009-06-08 02:42 . 2007-10-05 04:28 3801694208 --sha-w- \pagefile.sys
2009-06-07 02:41 . 2008-07-24 14:49 -------- d-----w- c:\users\Randy\AppData\Roaming\OpenOffice.org2
2009-06-06 20:38 . 2008-07-24 14:50 1 ----a-w- c:\users\Randy\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-06-06 18:51 . 2008-07-21 16:36 680 ----a-w- c:\users\Randy\AppData\Local\d3d9caps.dat
2009-06-06 17:14 . 2009-06-06 17:14 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-06 17:14 . 2009-06-06 17:14 -------- d-----w- c:\programdata\Symantec
2009-06-06 16:32 . 2009-02-21 10:23 -------- d-----w- c:\programdata\old
2009-06-06 16:30 . 2008-02-23 20:01 -------- d-----w- c:\users\Randy\AppData\Roaming\Symantec
2009-06-03 17:18 . 2008-06-03 04:43 -------- d-----w- c:\program files\PokerTracker 3
2009-06-01 11:00 . 2009-01-23 07:41 -------- d-----w- c:\program files\Full Tilt Poker
2009-05-26 22:08 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-22 15:20 . 2007-11-24 16:24 -------- d-----w- c:\program files\Steam
2009-04-25 15:42 . 2007-11-24 16:24 -------- d-----w- c:\program files\Common Files\Steam
2009-04-25 05:52 . 2009-04-25 05:52 17 ----a-w- c:\windows\popcinfo.dat
2009-04-24 02:05 . 2008-01-19 04:13 -------- d-----w- c:\program files\Java
2009-04-22 05:27 . 2009-04-22 05:27 -------- d-----w- c:\program files\NetZero
2009-04-22 05:27 . 2009-04-22 05:27 -------- d-----w- c:\programdata\NetZero
2009-04-21 06:12 . 2007-10-20 06:48 -------- d-----w- c:\program files\TowerGaming
2009-04-21 06:04 . 2008-09-04 16:57 -------- d-----w- c:\program files\Million Dollar Poker Club
2009-04-17 16:49 . 2007-10-14 18:18 -------- d-----w- c:\users\Randy\AppData\Roaming\Microgaming
2009-04-15 00:56 . 2009-02-27 02:19 -------- d-----w- c:\program files\QuickTax 2008
2009-04-12 20:37 . 2008-12-13 16:52 -------- d-----w- c:\programdata\Steam
2009-04-12 20:37 . 2008-12-13 16:52 -------- d-----w- c:\programdata\PopCap Games
2009-04-10 01:11 . 2009-04-10 01:11 -------- d-----w- c:\program files\Citrix
2009-04-10 01:10 . 2009-04-10 01:10 60744 ----a-w- c:\users\Randy\g2mdlhlpx.exe
2009-03-17 03:38 . 2009-04-16 00:38 13824 ----a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 00:38 24064 ----a-w- c:\windows\system32\amxread.dll
2009-03-15 16:45 . 2009-03-15 16:45 10344 ----a-w- c:\windows\system32\drivers\symlcbrd.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-06-08_01.17.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-30 00:13 . 2009-06-08 01:48 63580 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-06-08 01:48 78110 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-10-05 03:50 . 2009-06-08 01:48 14950 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2909560603-757134358-2736131246-1001_UserData.bin
- 2007-10-05 03:44 . 2009-06-08 00:48 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-10-05 03:44 . 2009-06-08 02:06 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-10-05 03:44 . 2009-06-08 02:06 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-05 03:44 . 2009-06-08 00:48 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-10-05 03:44 . 2009-06-08 02:06 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-10-05 03:44 . 2009-06-08 00:48 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Acer Tour"="" [BU]
"eRecoveryService"="" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-16 151552]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{341655EE-C8E9-46A4-A79C-4669FBD662ED}"= c:\program files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{4F15B457-622B-46CE-8BF8-BA8C7589A775}"= c:\program files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{E2493805-D524-444E-9086-8F42EE88402C}"= c:\program files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{39BE3E02-BE53-42C5-B282-5C5D1CBA271D}"= c:\program files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{786179FC-FC28-424E-B80C-DA61C97E6FA2}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{F59C5990-1FB8-4967-86D3-332374A7195D}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{3ADB8AB5-5E7A-4D5B-992E-4DA60454296B}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{4E591012-80DC-4D96-AA6D-70BC9CAF0A45}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{11499062-6BB3-4FA4-921A-F695AC201294}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv™ Media Server
"{04FD94B2-B337-49FF-B025-40C22E3850B4}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv™ Media Server
"{10786088-0558-4576-B44F-6BF3AB451A1E}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1:Intel® Viiv™ Media Server Discovery
"{A27A04BD-2071-4226-8531-0D2295C93119}"= TCP:Profile=Private|Profile=Public|1900:LocalSubnet:LocalSubnet:Intel® Viiv™ Media Server UPnP Discovery
"{FADFA5ED-F6FB-4CE0-BC02-D9550B537882}"= UDP:c:\program files\SmartFTP Client\SmartFTP.exe:SmartFTP Client
"{E84884A8-6247-49B4-8DE2-6416180298F9}"= TCP:c:\program files\SmartFTP Client\SmartFTP.exe:SmartFTP Client
"TCP Query User{E504B1E7-F12B-4882-91F9-B54A044D1FCF}c:\\program files\\common files\\newtech infosystems\\liveupdate\\liveupdate.exe"= UDP:c:\program files\common files\newtech infosystems\liveupdate\liveupdate.exe:LiveUpdate
"UDP Query User{359599AE-63C3-408B-A5CE-1D0A22851437}c:\\program files\\common files\\newtech infosystems\\liveupdate\\liveupdate.exe"= TCP:c:\program files\common files\newtech infosystems\liveupdate\liveupdate.exe:LiveUpdate
"{922AC9B6-AF2A-4736-A76E-7C73E3BB4427}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{CFA47F35-9319-4B1D-993D-8FF736F69089}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{DF45376F-AE9E-41CF-9A52-C96460841211}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{CEB38BD8-E0E8-4A89-BC32-952EB865B045}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{7D3AD342-C782-416E-9ECA-2BD66F7D22CA}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{93494BBF-268D-4B14-8985-D1DAE0AE2C44}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{D91E3A20-3C08-4D63-BFDE-BE763B8BD70A}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{5E9A6AF0-930D-4B39-B828-C7F6FE629A7E}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{56029A8B-186F-4ADB-95DB-E7402DEE1F70}"= UDP:c:\program files\Steam\SteamApps\common\peggle deluxe\Peggle.exe:Peggle Deluxe
"{2AA03DFD-7528-4567-AD83-79EC8D352513}"= TCP:c:\program files\Steam\SteamApps\common\peggle deluxe\Peggle.exe:Peggle Deluxe
"{D4C3EC93-8880-4581-86D7-2BBA66354979}"= UDP:c:\program files\Steam\SteamApps\common\peggle nights\PeggleNights.exe:Peggle Nights
"{3C85C8AD-A1B1-46D7-A26C-8F29282EEA4C}"= TCP:c:\program files\Steam\SteamApps\common\peggle nights\PeggleNights.exe:Peggle Nights

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= c:\acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"c:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= c:\acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"c:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= c:\acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption

R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [6/6/2009 11:19 PM 28544]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [6/7/2009 3:00 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [6/7/2009 3:00 AM 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [6/7/2009 3:00 AM 51792]
R2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [10/29/2006 12:03 PM 208896]
R2 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\System32\drivers\nmsgopro.sys [9/27/2006 7:37 PM 28672]
R2 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [10/19/2006 6:49 PM 7424]
R2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [2/1/2008 4:02 AM 65536]
R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [10/5/2007 12:33 AM 5504]
R3 SymVerifyTrust;SymVerifyTrust;c:\program files\Common Files\Symantec Shared\EENGINE\SymVerifyTrust.sys [10/13/2008 8:16 PM 280112]
S3 IntelDHSvcConf;IntelDHSvcConf;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [11/18/2006 9:59 AM 36312]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.ca/
IE: {{10F055B8-F443-4adf-948A-EC551E9DBCE4} - c:\programdata\Microsoft\Windows\Start Menu\Programs\UltimateBet\UltimateBet.lnk
IE: {{6DAF93EB-C7E3-41ab-83D9-CAE1785F41BC} - c:\microgaming\Poker\pokerrewardsMPP\MPPoker.exe
TCP: {1D0D20EF-F343-4599-90AE-C33E1ABA64E9} = 67.55.0.11,66.49.220.95
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\QuickTax 2007\ic2007pp.dll
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-07 22:43
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

LVPrcSrv.exe [9652]

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(9620)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\SmartFTP Client\sfShellTools.dll
c:\program files\SmartFTP Client\SmartHook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\System32\Ati2evxx.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\program files\Intel\IntelDH\CCU\AlertService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\System32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-06-08 22:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-08 02:48

Pre-Run: 80,672,948,224 bytes free
Post-Run: 80,571,326,464 bytes free

299 --- E O F --- 2009-06-01 05:41

Finally feel like some good progress has been made. Very reluctant to proceed to do anything else without guidance. What's next?

Thx
WarGawd
  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Just a few elements to remove now and then I would like a blow by blow account of the elements in your system that are not working or are a bit hickey. As you have Vista the recovery console is not required, it's built in :)

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    O3 - HKLM\..\Toolbar: (no name) - Locked - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - Reg Error: Key error. File not found
    [2009/06/06 15:57:01 | 00,000,000 | ---D | C] -- C:\def
    [2009/05/30 22:50:03 | 00,000,004 | ---- | C] () -- C:\Windows\System32\gxvxccount
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

  • 0

#10
WarGawd

WarGawd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
LOL I'm dense today....watched this page all day, never saw any changes...took a while to realize i never refreshed it!!!

OK, followed instructions - OTL log posted below. With respect to the question regarding things not working/wonky, The only thing I'm aware of is that the Sleep mode no longer seems to function. It appears as though the process starts, but very shortly after, the system comes back to life, screen comes back on and it just continues on as If i never made the request. I normally initiate Sleep mode from a button on the keyboard, but the behavior is identical if I initiate it dfrom the Start menu.

Also I do prob need to do some Java and Flash upgrades, and I havent done a Windows Update (as it was not working earlier due to the DNSChanger trojan) so thats on the list to be done.

For now, the OTL log:

OTL logfile created on: 6/9/2009 2:58:14 AM - Run 3
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\Randy\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 228.13 Gb Total Space | 74.11 Gb Free Space | 32.49% Space Free | Partition Type: NTFS
Drive D: | 227.87 Gb Total Space | 182.31 Gb Free Space | 80.01% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 1.88 Gb Total Space | 0.60 Gb Free Space | 32.05% Space Free | Partition Type: FAT

Computer Name: TAZMANIAC
Current User Name: Randy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe ()
PRC - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Users\Randy\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AcerMemUsageCheckService [Auto | Running]) -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe ()
SRV - (AlertService [Auto | Running]) -- C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
SRV - (aswUpdSv [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati External Event Utility [Auto | Running]) -- C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Stopped]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Stopped]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DQLWinService [Auto | Running]) -- C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
SRV - (ehRecvr [On_Demand | Stopped]) -- C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) -- C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) -- C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (eRecoveryService [Auto | Running]) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager [Disabled | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [Disabled | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (IAANTMON [Auto | Running]) -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IntelDHSvcConf [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe (Intel® Corporation)
SRV - (ISSM [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe (Intel® Corporation)
SRV - (LBTServ [On_Demand | Stopped]) -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (LightScribeService [Auto | Running]) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (LVCOMSer [Auto | Running]) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (M1 Server [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe ()
SRV - (MCLServiceATL [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (Intel® Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (pgsql-8.3 [Auto | Running]) -- C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (Steam Client Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Running]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (adp94xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (aic78xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (aswFsBlk [Auto | Running]) -- C:\Windows\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMonFlt [Auto | Running]) -- C:\Windows\system32\DRIVERS\aswMonFlt.sys (ALWIL Software)
DRV - (aswRdr [System | Running]) -- C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) -- C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) -- C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (atikmdag [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (BrFiltLo [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (e1express [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\e1e6032.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (eeCtrl [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (elxstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HECI [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HECI.sys (Intel Corporation)
DRV - (HpCISSs [Disabled | Stopped]) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (iaStor [Boot | Running]) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (iaStorV [Disabled | Stopped]) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (int15 [Auto | Running]) -- C:\Acer\Empowering Technology\eRecovery\int15.sys ()
DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\Windows\system32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (IntelDH [On_Demand | Running]) -- C:\Windows\System32\Drivers\IntelDH.sys (Intel Corporation)
DRV - (iteatapi [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (L8042mou [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\L8042mou.Sys (Logitech Inc.)
DRV - (LHidFilt [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (LMouFilt [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\LMouKE.Sys (Logitech Inc.)
DRV - (LSI_FC [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (lvpopflt [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVRS [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (lvselsus [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvselsus.sys (Logitech Inc.)
DRV - (LVUSBSta [On_Demand | Running]) -- C:\Windows\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVUVC [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (megasas [Disabled | Stopped]) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (nfrd960 [Disabled | Stopped]) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (nmsgopro [Auto | Running]) -- C:\Windows\system32\DRIVERS\nmsgopro.sys (Gteko Ltd.)
DRV - (nmsunidr [Auto | Running]) -- C:\Windows\system32\DRIVERS\nmsunidr.sys (Gteko Ltd.)
DRV - (NTIDrvr [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (ntrigdigi [Disabled | Stopped]) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (pavboot [Boot | Running]) -- C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (ql2300 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (R300 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (RT73 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\Dr71WU.sys (Ralink Technology Inc.)
DRV - (secdrv [Auto | Running]) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (SQTECH905C [On_Demand | Stopped]) -- C:\Windows\System32\Drivers\Capt905c.sys (Service & Quality Technology.)
DRV - (sscdbus [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdbus.sys (MCCI)
DRV - (sscdmdfl [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdmdfl.sys (MCCI)
DRV - (sscdmdm [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdmdm.sys (MCCI)
DRV - (sscdserd [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\sscdserd.sys (MCCI)
DRV - (StillCam [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (Symc8xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (TSHWMDTCP [On_Demand | Stopped]) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys ()
DRV - (uliahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Running]) -- C:\Windows\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (WmBEnum [On_Demand | Running]) -- C:\Windows\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmFilter [On_Demand | Running]) -- C:\Windows\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmVirHid [On_Demand | Stopped]) -- C:\Windows\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore [On_Demand | Running]) -- C:\Windows\system32\drivers\WmXlCore.sys (Logitech Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo....e...-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/05/26 18:17:04 | 00,000,000 | ---D | M]

[2009/05/31 15:17:48 | 00,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\mozilla\Extensions
[2009/05/31 15:17:48 | 00,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/31 15:17:48 | 00,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\mozilla\Firefox\Profiles\qkdepqo8.default\extensions

O1 HOSTS File: (27 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (jZip Webmail plugin) - {647FD14A-C4F1-46F4-8FC3-0B40F54226F7} - C:\Program Files\jZip\WebmailPlugin.dll (Discordia Limited)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨ă¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll (NetZero, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Acer Tour] File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKCU..\Run: [Acer Tour Reminder] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Poker Rewards Poker - {6DAF93EB-C7E3-41ab-83D9-CAE1785F41BC} - C:\Microgaming\Poker\pokerrewardsMPP\MPPoker.exe (Microgaming)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe ()
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} http://acs.pandasoft...s/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/...erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplane...C_2.3.7.109.cab (CDownloadCtrl Object)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} https://signin3.valu...018/flashax.cab (FlashXControl Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative....15035/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{1D0D20EF-F343-4599-90AE-C33E1ABA64E9}\\NameServer = 67.55.0.11,66.49.220.95
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\intu-qt2007 {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\Explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/07 21:09:48 | 00,000,000 | R--D | M]

========== Files/Folders - Created Within 30 Days ==========

[2009/06/08 07:20:58 | 00,000,000 | ---- | C] () -- C:\Windows\System32\drivers\lvuvc.hs
[2009/06/07 22:48:23 | 00,000,000 | ---D | C] -- C:\temp
[2009/06/07 22:43:22 | 00,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2009/06/07 21:10:26 | 00,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2009/06/07 21:10:26 | 00,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2009/06/07 21:10:26 | 00,154,624 | ---- | C] () -- C:\Windows\PEV.exe
[2009/06/07 21:10:26 | 00,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2009/06/07 21:10:26 | 00,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2009/06/07 21:10:26 | 00,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2009/06/07 21:10:26 | 00,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2009/06/07 21:10:26 | 00,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2009/06/07 21:10:09 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/06/07 21:09:34 | 03,019,410 | R--- | C] () -- C:\Users\Randy\Desktop\ComboFix.exe
[2009/06/07 20:31:31 | 00,000,000 | ---D | C] -- C:\_OTL
[2009/06/07 13:22:33 | 00,000,000 | ---D | C] -- C:\Users\Randy\AppData\Roaming\Malwarebytes
[2009/06/07 05:05:33 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/06/07 05:03:27 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Users\Randy\Desktop\OTL.exe
[2009/06/07 05:02:48 | 00,267,612 | ---- | C] () -- C:\Users\Randy\Desktop\Rooter.exe
[2009/06/07 03:00:13 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2009/06/07 03:00:13 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\Windows\System32\AvastSS.scr
[2009/06/07 03:00:13 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2009/06/07 03:00:13 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2009/06/07 03:00:13 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2009/06/07 03:00:13 | 00,001,853 | ---- | C] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/06/07 03:00:02 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2009/06/07 03:00:02 | 00,380,928 | ---- | C] () -- C:\Windows\System32\actskin4.ocx
[2009/06/07 03:00:02 | 00,051,792 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2009/06/07 03:00:01 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/06/07 02:50:02 | 00,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/07 02:50:00 | 00,040,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/06/07 02:49:59 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/06/07 02:49:58 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/06/07 02:49:58 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/07 02:24:30 | 00,000,000 | ---D | C] -- C:\Windows\ERDNT
[2009/06/07 02:22:34 | 00,000,737 | ---- | C] () -- C:\Users\Randy\Desktop\NTREGOPT.lnk
[2009/06/07 02:22:34 | 00,000,718 | ---- | C] () -- C:\Users\Randy\Desktop\ERUNT.lnk
[2009/06/07 02:22:34 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/07 01:58:57 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\Randy\Desktop\erunt_setup.exe
[2009/06/07 01:58:06 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Users\Randy\Desktop\SysRestorePoint.exe
[2009/06/07 01:54:29 | 00,264,704 | ---- | C] (OldTimer Tools) -- C:\Users\Randy\Desktop\TFC.exe
[2009/06/06 23:19:05 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\Windows\System32\drivers\pavboot.sys
[2009/06/06 23:19:04 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2009/06/06 23:13:18 | 00,000,000 | ---D | C] -- C:\Windows\BDOSCAN8
[2009/06/06 23:12:58 | 00,000,000 | ---D | C] -- C:\Windows\Downloaded Program Files
[2009/06/06 22:08:08 | 44,571,776 | ---- | C] () -- C:\Users\Randy\Desktop\20090606-003-v5i32.exe
[2009/06/06 15:57:42 | 00,000,000 | ---D | C] -- C:\Users\Randy\Documents\Norton Premium Services
[2009/06/06 15:57:01 | 00,002,081 | ---- | C] () -- C:\Users\Public\Desktop\VRQTool.lnk
[2009/06/06 15:49:49 | 34,880,43008 | -HS- | C] () -- C:\hiberfil.sys
[2009/06/06 15:23:03 | 00,000,740 | ---- | C] () -- C:\Users\Randy\Desktop\Download Norton 360 Version 3.lnk
[2009/06/06 15:23:03 | 00,000,000 | ---D | C] -- C:\ProgramData\Symantec Temporary Files
[2009/06/06 14:02:06 | 00,000,000 | ---D | C] -- C:\Users\Randy\Desktop\NortonSecurityScan
[2009/06/06 14:00:35 | 01,881,911 | ---- | C] () -- C:\Users\Randy\Desktop\NortonSecurityScan.exe
[2009/06/06 13:14:06 | 00,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2009/06/06 13:14:06 | 00,000,000 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009/06/06 13:14:05 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2009/06/03 21:57:48 | 00,000,026 | ---- | C] () -- C:\Windows\Zone.Identifier
[2009/06/02 14:29:37 | 00,006,704 | ---- | C] () -- C:\Users\Randy\Documents\WSOP SEAT EBAY LISTING.html
[2009/06/02 14:29:02 | 00,024,970 | ---- | C] () -- C:\Users\Randy\Documents\WSOP SEAT.odt
[2009/06/01 07:19:05 | 00,003,706 | ---- | C] () -- C:\Users\Randy\Documents\test post.html
[2009/06/01 01:40:34 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2009/06/01 01:40:33 | 00,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2009/06/01 01:40:33 | 00,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2009/06/01 01:40:33 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2009/06/01 01:40:33 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2009/06/01 01:40:33 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
[2009/06/01 01:40:33 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
[2009/06/01 01:40:33 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2009/06/01 01:40:33 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2009/06/01 01:40:33 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2009/06/01 01:40:33 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\corpol.dll
[2009/06/01 01:40:32 | 01,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2009/06/01 01:40:32 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2009/06/01 01:40:32 | 00,236,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webcheck.dll
[2009/06/01 01:40:32 | 00,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2009/06/01 01:40:32 | 00,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2009/06/01 01:40:32 | 00,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2009/06/01 01:40:32 | 00,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2009/06/01 01:40:32 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2009/06/01 01:40:32 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2009/06/01 01:40:32 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2009/06/01 01:40:32 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2009/06/01 01:40:32 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2009/06/01 01:40:31 | 00,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2009/06/01 01:40:31 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2009/06/01 01:40:31 | 00,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2009/06/01 01:40:31 | 00,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe
[2009/06/01 01:40:31 | 00,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2009/06/01 01:40:31 | 00,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
[2009/06/01 01:40:31 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2009/06/01 01:40:31 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2009/06/01 01:40:31 | 00,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2009/06/01 01:40:31 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2009/06/01 01:40:31 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2009/06/01 01:40:30 | 00,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2009/06/01 01:40:30 | 00,420,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2009/06/01 01:40:30 | 00,391,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2009/06/01 01:40:30 | 00,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2009/06/01 01:40:30 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2009/06/01 01:40:29 | 03,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2009/06/01 01:40:29 | 01,985,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2009/06/01 01:40:29 | 00,914,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2009/06/01 01:40:29 | 00,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2009/06/01 01:40:29 | 00,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2009/06/01 01:40:29 | 00,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2009/06/01 01:40:29 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PDMSetup.exe
[2009/06/01 01:40:29 | 00,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2009/06/01 01:40:29 | 00,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2009/06/01 01:40:29 | 00,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2009/06/01 01:40:29 | 00,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetDepNx.exe
[2009/06/01 01:40:29 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
[2009/06/01 01:40:28 | 01,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2009/06/01 01:40:28 | 01,206,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2009/06/01 01:40:27 | 11,063,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2009/06/01 01:40:27 | 05,937,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009/06/01 00:30:54 | 00,000,000 | ---D | C] -- C:\Users\Randy\AppData\Roaming\Opera
[2009/06/01 00:30:27 | 00,000,718 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2009/06/01 00:30:26 | 00,000,000 | ---D | C] -- C:\Program Files\Opera
[2009/05/31 20:58:03 | 00,000,846 | ---- | C] () -- C:\Users\Randy\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/31 20:55:33 | 03,371,384 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Randy\Desktop\randombam.exe
[2009/05/31 19:38:01 | 00,000,000 | ---D | C] -- C:\Windows\pss
[2009/05/31 15:17:49 | 00,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/05/31 15:17:47 | 00,000,000 | ---D | C] -- C:\Users\Randy\AppData\Roaming\Mozilla
[2009/05/31 11:05:13 | 00,000,007 | ---- | C] () -- C:\ISACER.id
[2009/05/31 06:24:57 | 00,049,541 | ---- | C] () -- C:\Users\Randy\Documents\WSOP ME Structure.pdf
[2009/05/28 23:23:28 | 00,023,966 | ---- | C] () -- C:\Users\Randy\Documents\WSOP ME Structure.ods
[2009/05/27 08:05:43 | 00,280,622 | ---- | C] () -- C:\Users\Randy\Documents\KIDS MP3 Player Manual SYL_SMPK2072_ENFR.pdf
[2009/05/26 18:31:42 | 00,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/05/26 18:31:42 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscb.dll
[2009/05/26 18:31:42 | 00,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/05/26 18:31:42 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshooks.dll
[2009/05/26 18:31:41 | 00,754,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\propsys.dll
[2009/05/26 18:31:41 | 00,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\thawbrkr.dll
[2009/05/26 18:31:41 | 00,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srchadmin.dll
[2009/05/26 18:31:41 | 00,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll
[2009/05/26 18:31:41 | 00,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\korwbrkr.dll
[2009/05/26 18:31:41 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchFilterHost.exe
[2009/05/26 18:31:41 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssitlb.dll
[2009/05/26 18:31:41 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\propdefs.dll
[2009/05/26 18:31:41 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msstrc.dll
[2009/05/26 18:31:41 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssprxy.dll
[2009/05/26 18:31:40 | 11,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex
[2009/05/26 18:31:40 | 06,103,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chtbrkr.dll
[2009/05/26 18:31:40 | 01,671,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chsbrkr.dll
[2009/05/26 18:31:40 | 01,582,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2009/05/26 18:31:40 | 01,418,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2009/05/26 18:31:40 | 00,670,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2009/05/26 18:31:40 | 00,439,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe
[2009/05/26 18:31:40 | 00,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2009/05/26 18:31:40 | 00,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2009/05/26 18:31:40 | 00,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\offfilt.dll
[2009/05/26 18:31:40 | 00,184,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchProtocolHost.exe
[2009/05/26 18:31:40 | 00,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlhtml.dll
[2009/05/26 18:31:40 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2009/05/26 18:31:40 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xmlfilter.dll
[2009/05/26 18:31:40 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mimefilt.dll
[2009/05/26 18:31:40 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtffilt.dll
[2009/05/26 18:31:40 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsepno.dll
[2009/05/26 18:14:13 | 00,105,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/05/26 18:14:13 | 00,097,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardapi.dll
[2009/05/26 18:14:13 | 00,037,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardcpl.cpl
[2009/05/26 18:14:12 | 00,622,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardagt.exe
[2009/05/26 18:14:12 | 00,043,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2009/05/26 18:14:12 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardres.dll
[2009/05/26 18:14:11 | 00,781,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationNative_v0300.dll
[2009/05/26 18:14:10 | 00,326,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2009/05/26 18:09:18 | 00,096,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dfshim.dll
[2009/05/26 18:09:15 | 00,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscoree.dll
[2009/05/26 18:09:14 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2009/05/26 18:08:54 | 00,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscorier.dll
[2009/05/26 18:08:49 | 00,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscories.dll
[2009/05/26 18:06:37 | 00,241,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
[2009/05/26 18:06:33 | 00,712,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecs.dll
[2009/05/26 18:06:33 | 00,425,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
[2009/05/26 18:06:33 | 00,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2009/05/26 18:05:59 | 00,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2009/05/26 18:05:58 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2009/05/26 18:05:58 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2009/05/26 18:05:57 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2009/05/26 18:05:57 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2009/05/26 18:05:57 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2009/05/26 18:05:51 | 01,645,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\connect.dll
[2009/05/26 18:05:49 | 00,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Faultrep.dll
[2009/05/26 18:05:49 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wersvc.dll
[2009/05/22 00:42:53 | 00,373,981 | ---- | C] () -- C:\Users\Randy\Documents\travel insurance policy- WSOP.pdf
[2009/05/12 22:33:31 | 00,071,680 | ---- | C] () -- C:\Users\Randy\Documents\Day Camp Letter.doc
[2009/01/05 15:44:10 | 00,000,453 | ---- | C] () -- C:\Windows\bdoscandellang.ini
[2008/09/09 14:14:43 | 00,011,776 | ---- | C] () -- C:\Windows\System32\pmsbfn32.dll
[2008/09/09 14:08:38 | 00,000,412 | ---- | C] () -- C:\Windows\MAXLINK.INI
[2008/09/09 13:28:24 | 00,003,584 | ---- | C] () -- C:\Windows\System32\CNCFLeNL.DLL
[2008/08/31 00:27:21 | 00,066,482 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2008/07/26 08:25:02 | 00,025,624 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2008/06/03 01:08:58 | 00,023,553 | ---- | C] () -- C:\Windows\System32\ofbdin_.dll
[2008/06/02 23:35:17 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008/04/30 01:50:31 | 00,045,056 | ---- | C] () -- C:\Windows\System32\pagesync.dll
[2007/11/19 23:00:50 | 00,000,392 | ---- | C] () -- C:\Windows\ODBC.INI
[2007/11/16 21:39:23 | 00,000,063 | ---- | C] () -- C:\Windows\wininit.ini
[2007/10/19 20:24:10 | 00,000,467 | ---- | C] () -- C:\Windows\SIERRA.INI
[2007/10/04 23:52:25 | 00,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini
[2007/10/04 23:52:25 | 00,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini
[2007/03/29 21:02:21 | 00,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
[2007/03/29 20:34:37 | 00,331,776 | ---- | C] () -- C:\Windows\System32\ScrollBarLib.dll
[2007/03/29 20:34:37 | 00,053,248 | ---- | C] ( ) -- C:\Windows\System32\Interop.Shell32.dll
[2007/03/29 18:49:30 | 00,000,685 | ---- | C] () -- C:\Windows\generic.ini
[2007/03/29 18:49:30 | 00,000,107 | ---- | C] () -- C:\Windows\Alaunch.ini
[2007/03/29 18:49:28 | 00,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1147.dll
[2006/11/02 08:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:23:31 | 00,000,215 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 06:23:31 | 00,000,144 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 04:30:49 | 00,024,578 | ---- | C] () -- C:\Windows\System32\wunkged.dll
[2006/11/02 03:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/06/23 12:09:34 | 00,019,968 | R--- | C] () -- C:\Windows\System32\cpuinf32.dll
[2001/12/26 18:12:30 | 00,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 01:46:38 | 00,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001/07/30 18:33:56 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001/07/24 00:04:36 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll

========== Files - Modified Within 30 Days ==========

[2009/06/09 02:56:34 | 00,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/06/09 02:56:34 | 00,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/06/09 02:56:34 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/06/09 02:56:31 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/06/09 02:55:55 | 00,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2009/06/09 02:55:50 | 34,880,43008 | -HS- | M] () -- C:\hiberfil.sys
[2009/06/07 22:43:25 | 00,000,215 | ---- | M] () -- C:\Windows\system.ini
[2009/06/07 22:43:20 | 00,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2009/06/07 21:09:48 | 03,019,410 | R--- | M] () -- C:\Users\Randy\Desktop\ComboFix.exe
[2009/06/07 05:03:32 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Users\Randy\Desktop\OTL.exe
[2009/06/07 05:02:50 | 00,267,612 | ---- | M] () -- C:\Users\Randy\Desktop\Rooter.exe
[2009/06/07 03:00:13 | 00,001,853 | ---- | M] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/06/07 03:00:12 | 00,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2009/06/07 02:50:02 | 00,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/07 02:22:34 | 00,000,737 | ---- | M] () -- C:\Users\Randy\Desktop\NTREGOPT.lnk
[2009/06/07 02:22:34 | 00,000,718 | ---- | M] () -- C:\Users\Randy\Desktop\ERUNT.lnk
[2009/06/07 01:59:00 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\Randy\Desktop\erunt_setup.exe
[2009/06/07 01:58:06 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Users\Randy\Desktop\SysRestorePoint.exe
[2009/06/07 01:54:31 | 00,264,704 | ---- | M] (OldTimer Tools) -- C:\Users\Randy\Desktop\TFC.exe
[2009/06/06 22:08:08 | 44,571,776 | ---- | M] () -- C:\Users\Randy\Desktop\20090606-003-v5i32.exe
[2009/06/06 21:46:39 | 00,000,740 | ---- | M] () -- C:\Users\Randy\Desktop\Download Norton 360 Version 3.lnk
[2009/06/06 15:57:42 | 00,002,081 | ---- | M] () -- C:\Users\Public\Desktop\VRQTool.lnk
[2009/06/06 14:00:35 | 01,881,911 | ---- | M] () -- C:\Users\Randy\Desktop\NortonSecurityScan.exe
[2009/06/06 13:14:06 | 00,000,000 | ---- | M] () -- C:\ProgramData\N360BUOptions.ini
[2009/06/04 03:04:07 | 00,000,026 | ---- | M] () -- C:\Windows\Zone.Identifier
[2009/06/02 14:37:05 | 00,006,704 | ---- | M] () -- C:\Users\Randy\Documents\WSOP SEAT EBAY LISTING.html
[2009/06/02 14:29:02 | 00,024,970 | ---- | M] () -- C:\Users\Randy\Documents\WSOP SEAT.odt
[2009/06/01 07:44:12 | 00,003,706 | ---- | M] () -- C:\Users\Randy\Documents\test post.html
[2009/06/01 00:30:27 | 00,000,718 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2009/05/31 20:58:03 | 00,000,846 | ---- | M] () -- C:\Users\Randy\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/31 20:55:33 | 03,371,384 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Randy\Desktop\randombam.exe
[2009/05/31 15:17:49 | 00,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2009/05/31 11:08:41 | 00,154,624 | ---- | M] () -- C:\Windows\PEV.exe
[2009/05/31 11:05:13 | 00,000,007 | ---- | M] () -- C:\ISACER.id
[2009/05/31 06:35:14 | 00,049,541 | ---- | M] () -- C:\Users\Randy\Documents\WSOP ME Structure.pdf
[2009/05/31 06:33:46 | 00,023,966 | ---- | M] () -- C:\Users\Randy\Documents\WSOP ME Structure.ods
[2009/05/27 08:05:43 | 00,280,622 | ---- | M] () -- C:\Users\Randy\Documents\KIDS MP3 Player Manual SYL_SMPK2072_ENFR.pdf
[2009/05/27 05:30:44 | 00,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/05/27 05:30:44 | 00,599,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/05/27 05:30:44 | 00,105,448 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/05/22 00:43:09 | 00,373,981 | ---- | M] () -- C:\Users\Randy\Documents\travel insurance policy- WSOP.pdf
[2009/05/13 12:46:06 | 00,001,891 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/05/12 22:33:34 | 00,071,680 | ---- | M] () -- C:\Users\Randy\Documents\Day Camp Letter.doc

========== Alternate Data Streams ==========

@Alternate Data Stream - 318 bytes -> C:\ProgramData\TEMP:8CEFE51A
@Alternate Data Stream - 211 bytes -> C:\ProgramData\TEMP:B0A96209
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:089A7B08
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:1CFFB598
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:C05A8628
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:8E3D07DE
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:7E95B6FD
< End of report >


Thx again for the help
WarGawd

Edited by WarGawd, 09 June 2009 - 01:15 AM.

  • 0

Advertisements


#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets clear a security loophole and then I would like you to try windows update to ensure that, that works and does not need repairing

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.

  • 0

#12
WarGawd

WarGawd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Hmmmm turns out I was wrong about the sleep function....worked fine last night.

So that leaves me with no known issues at the moment. I see Essex you are reading this froum right now, hope u get this before u spend time constructing a plan to deal with the "issue"


Thx
Wargawd

*** edit nope missed you by 1 minute - I had thought I'd seen too many past installs of java updates, was gonna get rid of them all and start from scratch, so I'll follow direction above

**** Edit 2 - I did however just notice that the Run.. link on the startup menu has disappeared for whatever reason, will have to put that back

Edited by WarGawd, 09 June 2009 - 11:51 AM.

  • 0

#13
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
I cross post all the time :)
  • 0

#14
WarGawd

WarGawd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Okey all the Java remnants are gone -next on to the Windows Update and then Ill be back.

JavaRa 1.14 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Tue Jun 09 13:55:05 2009

Found and removed: C:\Program Files\Java\jre1.6.0_03

Found and removed: C:\Program Files\Java\jre1.6.0_04

Found and removed: C:\Program Files\Java\jre1.6.0_05

Found and removed: C:\Program Files\Java\jre1.6.0_07

Found and removed: C:\Users\Randy\AppData\LocalLow\Sun\Java\jre1.6.0_04

Found and removed: C:\Users\Randy\AppData\LocalLow\Sun\Java\jre1.6.0_11

Found and removed: C:\Users\Randy\AppData\LocalLow\Sun\Java\jre1.6.0_12

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610004

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610004

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610004

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\JavaPlugin.160_03

Found and removed: SOFTWARE\Classes\JavaPlugin.160_04

Found and removed: SOFTWARE\Classes\JavaPlugin.160_05

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_04

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_04

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610004

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610004

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610004

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160030}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160040}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\JavaPlugin.160_03

Found and removed: Software\Classes\JavaPlugin.160_04

Found and removed: Software\Classes\JavaPlugin.160_05

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05

Found and removed: Software\JavaSoft\Java2D\1.6.0_03

Found and removed: Software\JavaSoft\Java2D\1.6.0_04

Found and removed: Software\JavaSoft\Java2D\1.6.0_05

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07

Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610007

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_04\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_04\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_03.b05\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_04.b12\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_05.b13\

WarGawd

Edited by WarGawd, 09 June 2009 - 11:59 AM.

  • 0

#15
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
If you could now check that all is working as it should and try windows updates - if that turns out well I will remove my tools
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP