Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Black Desktop after Win Defragmenter Malware removal.


  • Please log in to reply

#1
mtovar76

mtovar76

    Member

  • Member
  • PipPip
  • 27 posts
I am using Windows XP 2002 Service Pack 3... I had some malware, apparently "Win Defragmenter"- this malware caused fake Windows warnings and said I had low RAM memory. It began scanning my computer and would suggest I buy WIN DEFRAGMENTER.
I used Stinger, Malwarebytes' Anti- Malware, and my McAfee Virus removal. The program is no longer on my desktop, or my launch bar and start menu. I no longer get any "ffake windows warnings" BUT now my desktop is totally black. Here is my OTL log:



OTL logfile created on: 12/7/2010 6:03:01 PM - Run 2
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Miguel\Desktop\Virus remove stuff
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 58.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 10.67 Gb Free Space | 9.55% Space Free | Partition Type: NTFS
Drive D: | 37.24 Gb Total Space | 19.17 Gb Free Space | 51.46% Space Free | Partition Type: NTFS
Drive E: | 698.46 Gb Total Space | 576.87 Gb Free Space | 82.59% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LYCAEUM
Current User Name: Miguel
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Miguel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Documents and Settings\Miguel\Desktop\Virus remove stuff\OTL-2.exe (OldTimer Tools)
PRC - C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe (WIDCOMM, Inc.)


========== Modules (SafeList) ==========

MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Documents and Settings\Miguel\Desktop\Virus remove stuff\OTL-2.exe (OldTimer Tools)
MOD - C:\Program Files\McAfee\SiteAdvisor\sahook.dll ()
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) -- C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (mfevtp) -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (LBTServ) -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (McProxy) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (CCALib8) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (btwdins) -- C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe (WIDCOMM, Inc.)


========== Driver Services (SafeList) ==========

DRV - (Pcouffin) -- C:\WINDOWS\System32\Drivers\Pcouffin.sys File not found
DRV - (PalmUSBD) -- C:\WINDOWS\System32\drivers\PalmUSBD.sys File not found
DRV - (IFP800) -- C:\WINDOWS\System32\drivers\ifp800.sys File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (BTWUSB) -- C:\WINDOWS\System32\Drivers\btwusb.sys File not found
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) -- C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) -- C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) -- C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) -- C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) -- C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) -- C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (klmd23) -- C:\WINDOWS\system32\drivers\klmd.sys (Kaspersky Lab, SLA)
DRV - (LMouFilt) -- C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LHidEqd) -- C:\WINDOWS\system32\drivers\LHidEqd.sys (Logitech, Inc.)
DRV - (LEqdUsb) -- C:\WINDOWS\system32\drivers\LEqdUsb.sys (Logitech, Inc.)
DRV - (LBeepKE) -- C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (RT25USBAP) -- C:\WINDOWS\system32\drivers\RT25USBAP.SYS (Ralink Technology Inc.)
DRV - (samhid) -- C:\WINDOWS\system32\drivers\Samhid.sys ()
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (BCMModem) -- C:\WINDOWS\system32\drivers\BCMSM.sys (Broadcom Corporation)
DRV - (BTSERIAL) -- C:\WINDOWS\system32\drivers\btserial.sys ()
DRV - (BTSLBCSP) -- C:\WINDOWS\system32\drivers\btslbcsp.sys (WIDCOMM, Inc.)
DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (WIDCOMM, Inc.)
DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (WIDCOMM, Inc.)
DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (WIDCOMM, Inc.)
DRV - (BtAudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (WIDCOMM, Inc.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (OMCI) -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (MODEMCSA) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http:/www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/09/08 05:44:22 | 000,000,000 | ---D | M]

[2010/07/18 19:20:16 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/07/24 21:14:06 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20101103070614.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKCU..\Run: [37184203] C:\DOCUME~1\Miguel\LOCALS~1\Temp\37184203.exe File not found
O4 - HKCU..\Run: [CobInVfBVF.exe] C:\DOCUME~1\Miguel\LOCALS~1\Temp\CobInVfBVF.exe File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Miguel\Start Menu\Programs\Startup\Logitech . Product Registration.lnk = C:\Program Files\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (Bodog)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...tes/ieawsdc.cab (Reg Error: Key error.)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/...UI.cab55579.cab (StagingUI Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} http://us.dl1.yimg.c...nst20040510.cab (YInstStarter Class)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.micr...922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.micr...D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/...dy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www1.snapfish...fishActivia.cab (Snapfish Activia)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} http://a1540.g.akama...meInstaller.exe (Reg Error: Key error.)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace....ploader1005.cab (MySpace Uploader Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.mail.liv...es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/...at.cab55579.cab (ZonePAChat Object)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebo...toUploader2.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebo...otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1138339832250 (WUWebControl Class)
O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} http://software.news...k1/isetupml.cab (InstallShield International Setup Player)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} http://zone.msn.com/...he.cab55579.cab (ZPA_TexasHoldem Object)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1....loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn...ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/...xy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://216.128.199.1...activex/AMC.cab (AxisMediaControlEmb Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.shockwave...aploader_v6.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Miguel\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Miguel\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/26 19:37:34 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008/11/10 09:57:38 | 000,000,000 | ---D | M] - E:\autorun -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/12/01 20:11:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Miguel\Application Data\onOne Software
[2010/12/01 18:37:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\onOne Software
[2010/12/01 18:37:34 | 000,000,000 | ---D | C] -- C:\Program Files\onOne Software
[2010/11/22 21:59:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/11/17 08:46:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Logitech
[2010/11/17 08:44:42 | 000,016,400 | ---- | C] (Logitech, Inc.) -- C:\WINDOWS\System32\drivers\LNonPnP.sys
[2010/11/17 08:43:44 | 000,010,448 | ---- | C] (Logitech, Inc.) -- C:\WINDOWS\System32\drivers\LBeepKE.sys
[2010/11/17 08:43:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\LogiShrd
[2010/11/17 08:42:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Logishrd
[2010/11/17 08:42:47 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2010/11/17 08:37:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LogiShrd
[2010/11/17 08:36:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Miguel\Application Data\Logitech
[2010/11/17 08:36:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Miguel\Application Data\Logishrd
[2010/10/19 17:52:38 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour

========== Files - Modified Within 90 Days ==========

[2010/12/07 17:53:12 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/12/07 17:51:29 | 000,001,595 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2010/12/06 07:16:52 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/03 19:26:13 | 009,961,472 | ---- | M] () -- C:\Documents and Settings\Miguel\ntuser.dat
[2010/12/03 07:59:17 | 000,001,836 | ---- | M] () -- C:\Documents and Settings\Miguel\Desktop\Google Earth.lnk
[2010/12/02 18:59:14 | 000,002,293 | ---- | M] () -- C:\Documents and Settings\Miguel\Desktop\Google Chrome.lnk
[2010/12/02 18:59:14 | 000,002,271 | ---- | M] () -- C:\Documents and Settings\Miguel\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/12/02 07:45:22 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Miguel\ntuser.ini
[2010/12/01 23:41:24 | 000,002,187 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/12/01 20:30:24 | 000,000,108 | ---- | M] () -- C:\WINDOWS\WFT-E3Utility.INI
[2010/12/01 10:29:12 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Miguel\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2010/12/01 09:16:47 | 000,111,104 | ---- | M] () -- C:\Documents and Settings\Miguel\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/01 09:11:06 | 000,000,777 | ---- | M] () -- C:\Documents and Settings\Miguel\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2010/12/01 09:11:06 | 000,000,759 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2010/11/28 14:50:49 | 000,000,653 | ---- | M] () -- C:\WINDOWS\DELLSTAT.INI
[2010/11/28 14:44:42 | 000,000,256 | ---- | M] () -- C:\WINDOWS\System32\pool.bin
[2010/11/28 13:41:02 | 000,000,256 | ---- | M] () -- C:\Documents and Settings\Miguel\pool.bin
[2010/11/28 13:37:55 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1592454029-2147250837-1004Core.job
[2010/11/23 07:16:35 | 000,119,430 | ---- | M] () -- C:\Documents and Settings\Miguel\My Documents\Driv lic.jpg
[2010/11/19 15:24:04 | 000,073,845 | ---- | M] () -- C:\Documents and Settings\Miguel\My Documents\photo.JPG
[2010/11/17 08:44:42 | 000,016,400 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\System32\drivers\LNonPnP.sys
[2010/11/17 08:44:42 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010/11/17 08:44:40 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/11/15 22:52:36 | 000,470,434 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/15 22:52:35 | 000,084,422 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/11/15 22:52:34 | 000,565,534 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/10/27 18:27:22 | 293,969,928 | ---- | M] () -- C:\Documents and Settings\Miguel\My Documents\sci2010-07-24.vm44.zip
[2010/10/27 18:20:17 | 081,695,854 | ---- | M] () -- C:\Documents and Settings\Miguel\My Documents\sci2001-03-08.matrix.shnf_64kb_mp3.zip
[2010/10/23 09:24:36 | 000,000,040 | ---- | M] () -- C:\WINDOWS\nero.INI
[2010/10/21 22:27:00 | 000,035,180 | ---- | M] () -- C:\Documents and Settings\Miguel\My Documents\C.docx
[2010/10/21 22:25:21 | 000,043,008 | ---- | M] () -- C:\Documents and Settings\Miguel\My Documents\C.doc
[2010/10/19 17:56:58 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\Miguel\Desktop\QuickTime Player.lnk
[2010/10/19 17:56:58 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/10/18 14:37:43 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cb6efbeeb84df6.job
[2010/10/17 18:22:37 | 000,329,096 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/13 21:28:54 | 000,386,840 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys
[2010/10/13 21:28:54 | 000,313,288 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfefirek.sys
[2010/10/13 21:28:54 | 000,152,960 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys
[2010/10/13 21:28:54 | 000,095,600 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeapfk.sys
[2010/10/13 21:28:54 | 000,088,544 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfendisk.sys
[2010/10/13 21:28:54 | 000,084,264 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdet.sys
[2010/10/13 21:28:54 | 000,084,072 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfetdi2k.sys
[2010/10/13 21:28:54 | 000,055,840 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\cfwids.sys
[2010/10/13 21:28:54 | 000,052,104 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfebopk.sys
[2010/10/13 21:28:54 | 000,009,344 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeclnk.sys
[2010/09/23 22:25:59 | 000,291,043 | ---- | M] () -- C:\Documents and Settings\Miguel\My Documents\4981887502_076c572966_b.jpg
[2010/09/19 19:04:18 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\Miguel\Desktop\babyshower.doc
[2010/09/15 06:30:16 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\Miguel\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk

========== Files Created - No Company Name ==========

[2010/12/07 17:51:27 | 000,001,595 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2010/12/03 07:59:17 | 000,001,836 | ---- | C] () -- C:\Documents and Settings\Miguel\Desktop\Google Earth.lnk
[2010/12/01 20:30:24 | 000,000,108 | ---- | C] () -- C:\WINDOWS\WFT-E3Utility.INI
[2010/12/01 10:29:12 | 000,000,951 | ---- | C] () -- C:\Documents and Settings\Miguel\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2010/12/01 09:11:06 | 000,000,777 | ---- | C] () -- C:\Documents and Settings\Miguel\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2010/12/01 09:11:06 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2010/11/30 07:25:08 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\Miguel\Desktop\QuickTime Player.lnk
[2010/11/28 13:39:42 | 000,002,293 | ---- | C] () -- C:\Documents and Settings\Miguel\Desktop\Google Chrome.lnk
[2010/11/28 13:39:42 | 000,002,271 | ---- | C] () -- C:\Documents and Settings\Miguel\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/11/28 13:37:55 | 000,000,930 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1592454029-2147250837-1004Core.job
[2010/11/23 07:16:35 | 000,119,430 | ---- | C] () -- C:\Documents and Settings\Miguel\My Documents\Driv lic.jpg
[2010/11/19 15:24:02 | 000,073,845 | ---- | C] () -- C:\Documents and Settings\Miguel\My Documents\photo.JPG
[2010/11/17 08:44:42 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010/10/27 18:17:48 | 293,969,928 | ---- | C] () -- C:\Documents and Settings\Miguel\My Documents\sci2010-07-24.vm44.zip
[2010/10/27 18:17:12 | 081,695,854 | ---- | C] () -- C:\Documents and Settings\Miguel\My Documents\sci2001-03-08.matrix.shnf_64kb_mp3.zip
[2010/10/21 22:26:53 | 000,035,180 | ---- | C] () -- C:\Documents and Settings\Miguel\My Documents\C.docx
[2010/10/21 22:22:04 | 000,043,008 | ---- | C] () -- C:\Documents and Settings\Miguel\My Documents\C.doc
[2010/10/19 18:04:09 | 000,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/10/19 17:56:58 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/10/18 14:37:43 | 000,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cb6efbeeb84df6.job
[2010/09/23 22:25:59 | 000,291,043 | ---- | C] () -- C:\Documents and Settings\Miguel\My Documents\4981887502_076c572966_b.jpg
[2010/09/17 16:41:11 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\Miguel\Desktop\babyshower.doc
[2010/07/17 02:04:20 | 000,000,186 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/08/04 14:48:40 | 000,002,528 | ---- | C] () -- C:\WINDOWS\FCIC.INI
[2007/05/28 16:05:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\sam.ini
[2007/05/28 16:04:33 | 000,007,548 | ---- | C] () -- C:\WINDOWS\System32\drivers\Samhid.sys
[2007/05/28 16:04:32 | 000,487,424 | ---- | C] () -- C:\WINDOWS\System32\FDRpage.dll
[2007/03/26 20:09:36 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2007/03/26 20:09:34 | 000,471,552 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2007/01/19 23:38:34 | 000,000,149 | ---- | C] () -- C:\WINDOWS\DVDFabGold.INI
[2007/01/07 20:25:57 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006/06/17 18:38:28 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006/06/15 17:37:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2006/04/30 22:42:36 | 000,000,156 | ---- | C] () -- C:\WINDOWS\KPCMS.INI
[2006/04/30 22:41:49 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2006/02/15 16:02:55 | 000,000,026 | ---- | C] () -- C:\WINDOWS\dvdSanta.INI
[2006/02/09 19:57:14 | 000,000,040 | ---- | C] () -- C:\WINDOWS\nero.INI
[2006/01/26 23:52:03 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2006/01/26 21:36:21 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/01/26 21:21:01 | 001,962,496 | ---- | C] () -- C:\WINDOWS\System32\quartz(2).dll
[2006/01/26 20:05:08 | 000,000,653 | ---- | C] () -- C:\WINDOWS\DELLSTAT.INI
[2006/01/26 20:04:45 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbavs.dll
[2006/01/26 20:04:08 | 000,000,177 | ---- | C] () -- C:\WINDOWS\System32\dlbacoin.ini
[2003/08/14 12:17:28 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\btsendto_ie.dll
[2003/08/14 12:16:30 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\btsendto_wab.dll
[2003/08/14 11:50:32 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2003/08/14 11:37:14 | 000,022,183 | ---- | C] () -- C:\WINDOWS\System32\drivers\btserial.sys
[2002/05/15 22:29:04 | 000,000,607 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2001/11/23 17:18:00 | 000,000,597 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2001/11/14 12:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2008/08/04 14:48:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FirstClass
[2006/06/14 23:01:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HotSync
[2008/03/28 08:31:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2010/04/23 19:32:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PhotoStitch
[2006/01/29 13:30:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2010/12/02 08:02:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/03/14 13:09:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2010/05/05 20:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2010/04/12 23:06:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/13 09:05:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/18 07:07:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/11/14 17:15:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2008/06/30 14:25:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\Any Video Converter
[2010/09/04 10:57:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\BitTorrent
[2009/10/12 13:29:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\Canon
[2009/11/14 17:28:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\DNA
[2010/03/17 20:34:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\Facebook
[2007/05/29 14:51:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\Gearbox Software
[2006/06/14 22:59:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\HotSync
[2006/05/21 17:44:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\Leadertech
[2010/12/01 20:11:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\onOne Software
[2008/07/16 11:56:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\RapidTyping
[2010/01/06 21:07:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\Research In Motion
[2008/07/16 11:56:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\SecondLife
[2007/03/16 13:51:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\Snapfish
[2008/03/14 13:08:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miguel\Application Data\TomTom
[2010/01/25 22:38:02 | 000,000,458 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2010/01/25 22:38:02 | 000,000,458 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2010/01/25 22:38:02 | 000,000,458 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2010/01/25 22:38:02 | 000,000,458 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2010/01/25 22:38:02 | 000,000,458 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E965A533
< End of report >


*** please note! I work in Florida and drive to Georgia every Friday afternoon. I have had my topics closed because I can go 4 days or so without replying to instructions, please know I am not ignoring your efforts!!! I will get everything finished, and I really do appreciate all any efforts at helping me out.

thanks!
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP