Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

trojan.alemod


  • This topic is locked This topic is locked

#1
bilzer

bilzer

    Member

  • Member
  • PipPip
  • 15 posts
Dear Group,

I recently updated my virus protection to Norton 360 and it detected the trojan.alemod on the computer and Norton will NOT automatically remove it. Can anyone suggest a somewhat easy method to remove this beast> My computer is running is running slowly as well and I am running Microsoft XP with service pack 3 installed. I also downloaded OTL and can post the results if needed as I see that is what is used alot on this forum to determine what is causing the issue.
Thanks very much for any help rendered.

Here is the OTL log:

OTL logfile created on: 4/20/2011 11:25:56 AM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\FABY
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 214.00 Mb Available Physical Memory | 22.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 34.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 158.79 Gb Free Space | 68.19% Space Free | Partition Type: NTFS
Drive G: | 55.76 Gb Total Space | 31.38 Gb Free Space | 56.29% Space Free | Partition Type: FAT32

Computer Name: HOME-FD4A3FFDBC | User Name: OWNER | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/19 21:32:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\FABY\OTL.exe
PRC - [2011/02/23 10:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/12/20 18:08:56 | 000,443,728 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2010/12/20 18:08:46 | 000,963,976 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2010/02/25 20:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe
PRC - [2009/12/03 01:59:34 | 004,362,096 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\hsplayer.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2003/04/09 18:11:12 | 000,028,672 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
PRC - [2003/04/09 17:59:24 | 000,311,296 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
PRC - [2003/04/09 17:49:36 | 000,286,720 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
PRC - [2003/04/09 17:41:38 | 000,323,646 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
PRC - [2000/06/29 04:45:10 | 000,052,224 | ---- | M] (Kenonic Controls Ltd.) -- C:\WINDOWS\system32\Crypserv.exe


========== Modules (SafeList) ==========

MOD - [2011/04/19 21:32:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\FABY\OTL.exe
MOD - [2011/02/23 10:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2010/09/20 15:26:01 | 000,415,088 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/07/12 00:02:02 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
MOD - [2009/07/12 00:02:00 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (SessionLauncher)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/02/23 10:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/02/25 20:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe -- (N360)
SRV - [2008/01/29 16:09:02 | 000,394,704 | ---- | M] (Symantec, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe -- (Symantec RemoteAssist)
SRV - [2007/11/06 16:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/08/24 18:53:16 | 000,362,992 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe -- (Roxio Upnp Server 10)
SRV - [2007/08/24 18:53:14 | 000,072,176 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe -- (Roxio UPnP Renderer 10)
SRV - [2007/08/24 18:52:48 | 000,309,744 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe -- (RoxLiveShare10)
SRV - [2007/08/24 18:52:46 | 000,166,384 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe -- (RoxWatch10)
SRV - [2007/08/24 18:52:38 | 001,083,888 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)
SRV - [2000/06/29 04:45:10 | 000,052,224 | ---- | M] (Kenonic Controls Ltd.) [Auto | Running] -- C:\WINDOWS\System32\Crypserv.exe -- (Crypkey License)


========== Driver Services (SafeList) ==========

DRV - [2011/04/15 16:29:05 | 000,802,936 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110419.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2011/03/31 11:26:12 | 001,393,144 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110419.034\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/03/31 11:26:12 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110419.034\NAVENG.SYS -- (NAVENG)
DRV - [2011/03/15 15:52:18 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/03/15 01:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/03/15 01:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/03/14 14:58:34 | 000,341,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110419.002\IDSXpx86.sys -- (IDSxpx86)
DRV - [2011/02/23 09:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 09:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 09:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 09:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/02/23 09:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 09:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/02/23 09:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/05/10 14:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Documents and Settings\OWNER\Local Settings\Temp\SAS_SelfExtract\saskutil.sys -- (SASKUTIL)
DRV - [2010/05/06 00:01:59 | 000,361,904 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS -- (SYMTDI)
DRV - [2010/04/29 01:03:51 | 000,116,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS -- (SymIRON)
DRV - [2010/04/21 23:02:20 | 000,173,104 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS -- (SymEFA)
DRV - [2010/04/21 22:29:50 | 000,325,680 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS -- (SRTSP)
DRV - [2010/04/21 22:29:50 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 20:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys -- (ccHP)
DRV - [2010/02/17 14:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Documents and Settings\OWNER\Local Settings\Temp\SAS_SelfExtract\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/10/14 23:50:05 | 000,328,752 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS -- (SymDS)
DRV - [2009/08/05 20:38:22 | 005,874,176 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/02/24 19:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2008/08/05 23:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/04/13 14:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2007/11/06 16:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2007/08/18 06:09:04 | 000,057,328 | ---- | M] (Sonic Solutions) [File_System | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\RxFilter.sys -- (RxFilter)
DRV - [2006/11/29 01:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\APLMp50.sys -- (APLMp50)
DRV - [2006/09/24 09:28:46 | 000,005,248 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2006/06/17 01:09:48 | 001,611,776 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/01/04 18:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2004/08/03 18:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2002/07/17 09:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [2000/02/03 15:53:12 | 000,024,608 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\ckldrv.sys -- (NetworkX)
DRV - [1996/04/03 15:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startingpage.com/
IE - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2011/03/16 17:44:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2011/03/15 15:53:43 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2011/03/22 19:14:58 | 000,421,897 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14550 more lines...
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O8 - Extra context menu item: SurfSaver 6 QuickSave - C:\Program Files\askSam\SurfSaver 6\QuickSave.htm ()
O8 - Extra context menu item: SurfSaver 6 Save... - C:\Program Files\askSam\SurfSaver 6\add.htm ()
O9 - Extra Button: SurfSaver 6 - {91D4580B-DB35-416E-BA9E-994BBADC7177} - C:\Program Files\askSam\SurfSaver 6\SurfSaverBar.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsu...oad/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1256869687453 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2....re/HPDEXAXO.cab (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.h...tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.71.230 68.87.73.246
O18 - Protocol\Handler\asksam6 {72A9B8AD-6895-422C-A3F7-F2A7A88B88DA} - C:\Program Files\askSam\SurfSaver 6\AS6_AIPP.dll (askSam Systems)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\OWNER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\OWNER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/28 17:57:55 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\...exe [@ = exefile] -- Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/04/19 23:24:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\DriverCure
[2011/04/19 23:23:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\ParetoLogic
[2011/04/19 23:22:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Start Menu\Programs\ParetoLogic
[2011/04/19 23:22:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ParetoLogic
[2011/04/19 23:22:11 | 000,000,000 | ---D | C] -- C:\Program Files\ParetoLogic
[2011/04/19 23:22:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/04/19 22:44:14 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/04/19 22:44:14 | 000,027,984 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\sbbd.exe
[2011/04/19 22:40:33 | 000,000,000 | ---D | C] -- C:\VIPRERESCUE
[2011/04/19 22:39:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/04/19 22:39:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\SUPERAntiSpyware.com
[2011/04/19 21:51:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2011/04/19 19:04:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 8
[2011/04/19 19:04:03 | 000,000,000 | ---D | C] -- C:\Program Files\DVDFab 8
[2011/03/27 18:22:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\Tific
[2011/03/22 20:53:47 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2011/03/22 19:38:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\Malwarebytes
[2011/03/22 19:37:45 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/22 19:37:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/22 19:37:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/03/22 19:37:33 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/22 19:37:32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/22 19:10:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/08/07 13:50:21 | 013,833,720 | ---- | C] (Fengtao Software Inc. ) -- C:\Program Files\DVDFab7070.exe
[2009/10/25 11:02:59 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\OWNER\Application Data\pcouffin.sys
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/20 11:01:03 | 000,000,234 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/04/20 02:38:24 | 000,000,418 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2011/04/19 23:24:57 | 000,000,444 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2011/04/19 23:22:45 | 000,000,838 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\ParetoLogic PC Health Advisor.lnk
[2011/04/19 23:22:42 | 000,000,376 | ---- | M] () -- C:\WINDOWS\tasks\PC Health Advisor Defrag.job
[2011/04/19 23:22:41 | 000,000,358 | ---- | M] () -- C:\WINDOWS\tasks\PC Health Advisor.job
[2011/04/19 20:53:00 | 000,002,948 | ---- | M] () -- C:\WINDOWS\citation.ini
[2011/04/19 19:28:04 | 000,000,312 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2011/04/19 19:26:51 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/19 19:26:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/19 19:04:16 | 000,000,688 | ---- | M] () -- C:\Documents and Settings\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2011/04/19 19:04:16 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\DVDFab 8.lnk
[2011/04/19 16:53:36 | 000,048,128 | ---- | M] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/18 16:15:54 | 000,000,488 | ---- | M] () -- C:\hpfr5550.xml
[2011/03/28 20:46:41 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/03/28 19:39:30 | 000,000,744 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/03/27 19:01:19 | 101,679,216 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\20110327-001-v5i32.exe
[2011/03/22 20:52:10 | 004,288,155 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\ComboFix.exe
[2011/03/22 18:44:59 | 000,000,610 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\UnHookExec.inf
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/19 23:24:52 | 000,000,444 | ---- | C] () -- C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2011/04/19 23:22:45 | 000,000,838 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\ParetoLogic PC Health Advisor.lnk
[2011/04/19 23:22:43 | 000,000,418 | ---- | C] () -- C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2011/04/19 23:22:40 | 000,000,376 | ---- | C] () -- C:\WINDOWS\tasks\PC Health Advisor Defrag.job
[2011/04/19 23:22:36 | 000,000,358 | ---- | C] () -- C:\WINDOWS\tasks\PC Health Advisor.job
[2011/04/19 19:04:16 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2011/04/19 19:04:15 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\DVDFab 8.lnk
[2011/03/28 19:39:17 | 000,000,744 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/03/27 18:49:27 | 101,679,216 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\20110327-001-v5i32.exe
[2011/03/22 20:51:40 | 004,288,155 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\ComboFix.exe
[2011/03/22 18:44:57 | 000,000,610 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\UnHookExec.inf
[2011/02/22 15:43:51 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Usbr38.DLL
[2011/02/20 22:31:18 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/01/15 17:42:08 | 000,026,337 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2010/09/07 11:44:18 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ExtRes.dll
[2010/09/06 12:39:35 | 000,036,653 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\Comma Separated Values (Windows).ADR
[2010/08/13 19:22:47 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2010/08/13 19:01:57 | 000,019,558 | ---- | C] () -- C:\WINDOWS\hpoins01.dat.temp
[2010/08/13 19:01:57 | 000,016,606 | ---- | C] () -- C:\WINDOWS\hpomdl01.dat.temp
[2010/08/13 18:52:07 | 000,019,558 | ---- | C] () -- C:\WINDOWS\hpoins01.dat
[2010/08/13 18:52:07 | 000,016,606 | ---- | C] () -- C:\WINDOWS\hpomdl01.dat
[2010/08/07 13:50:23 | 000,273,288 | ---- | C] () -- C:\Program Files\Install.pdf
[2010/03/19 11:19:05 | 000,025,864 | ---- | C] () -- C:\WINDOWS\System32\EEInstMngr.exe
[2010/02/06 20:40:07 | 000,000,422 | ---- | C] () -- C:\WINDOWS\System32\MSST42.DLL
[2010/02/06 13:02:07 | 000,000,422 | ---- | C] () -- C:\WINDOWS\System32\MSST45.DLL
[2010/01/30 14:15:51 | 000,002,948 | ---- | C] () -- C:\WINDOWS\citation.ini
[2009/10/29 22:36:23 | 000,111,724 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\rx_audio.Cache
[2009/10/25 11:02:59 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\inst.exe
[2009/10/25 11:02:59 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\pcouffin.cat
[2009/10/25 11:02:59 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\pcouffin.inf
[2009/10/18 22:26:06 | 000,000,088 | ---- | C] () -- C:\WINDOWS\Crypkey.ini
[2009/10/18 22:26:02 | 000,027,648 | R--- | C] () -- C:\WINDOWS\Setup_ck.exe
[2009/10/18 22:26:02 | 000,024,608 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2009/10/18 22:26:02 | 000,018,432 | ---- | C] () -- C:\WINDOWS\Setup_ck.dll
[2009/10/18 22:26:02 | 000,011,776 | ---- | C] () -- C:\WINDOWS\Ckrfresh.exe
[2009/10/18 21:51:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Dvm.INI
[2009/10/09 00:59:57 | 000,032,192 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\Schedule8.dat
[2009/10/04 15:52:04 | 000,000,363 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2009/10/03 16:07:21 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\getpntid.exe
[2009/10/03 15:00:23 | 000,945,776 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\rx_image.Cache
[2009/09/28 23:23:01 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\qrz32.dll
[2009/09/28 23:23:01 | 000,062,464 | ---- | C] () -- C:\WINDOWS\System32\agwdll32.dll
[2009/09/28 23:23:01 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\RACCD32a.dll
[2009/09/28 23:23:01 | 000,030,208 | ---- | C] () -- C:\WINDOWS\System32\GoWin32.dll
[2009/09/28 23:23:01 | 000,026,112 | ---- | C] () -- C:\WINDOWS\System32\Hamcal32.dll
[2009/09/28 01:00:10 | 000,048,128 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/27 22:53:07 | 000,000,636 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/08/28 18:40:18 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2009/08/28 18:00:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/08/28 17:54:34 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/08/28 10:43:36 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/08/28 10:42:28 | 000,187,408 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/11/06 16:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007/08/21 15:22:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/06/02 17:15:44 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\LDecVorbis.dll
[2006/05/24 12:37:27 | 000,045,568 | RHS- | C] () -- C:\WINDOWS\System32\cygz.dll
[2006/05/24 12:37:27 | 000,027,648 | -HS- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2006/04/28 19:05:14 | 000,127,614 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/02/24 03:41:59 | 000,438,272 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2006/02/24 03:41:59 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\libfaac.dll
[2006/02/23 11:36:20 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\LMOggSpl.dll
[2006/02/23 11:36:20 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\LMOggMux.dll
[2005/09/23 15:15:04 | 001,798,144 | ---- | C] () -- C:\WINDOWS\System32\ltmm_n.dll
[2004/08/04 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,441,124 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,071,060 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/01/30 18:07:46 | 000,245,408 | ---- | C] () -- C:\WINDOWS\System32\unicows.dll
[2003/03/09 21:31:04 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2002/03/04 11:16:34 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\Jpeg32.dll
[2000/01/05 13:51:22 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\Welsof32.dll
[1996/04/03 15:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2010/06/20 17:38:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/03/15 14:28:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2011/03/14 18:11:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/07/03 08:27:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2011/03/15 14:28:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/19 23:22:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/10/04 00:46:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/02/22 15:50:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ResMed
[2011/01/15 17:41:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/10/03 13:55:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2011/03/28 20:01:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/12/11 18:26:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/04/19 19:38:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2010/03/27 15:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2010/07/04 22:30:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/30 00:46:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/10/09 23:56:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\DeepBurner
[2011/04/19 23:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\DriverCure
[2011/03/24 17:07:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\DVDFab
[2009/10/06 22:47:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\GlarySoft
[2010/07/03 08:30:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ICQ
[2010/08/08 10:28:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ImgBurn
[2009/09/30 00:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\iPod Copy Expert
[2011/04/19 23:23:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ParetoLogic
[2010/09/07 08:01:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\PresPro
[2011/03/15 19:51:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\RegistryKeys
[2011/01/15 17:45:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ScanSoft
[2011/03/27 18:22:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\Tific
[2010/08/07 14:01:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\Vso
[2010/01/17 18:20:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\WeatherBug
[2009/10/04 19:22:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\YouSendIt
[2010/11/30 20:16:07 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1281741011.job
[2011/04/19 19:28:04 | 000,000,312 | ---- | M] () -- C:\WINDOWS\Tasks\GlaryInitialize.job
[2011/04/19 23:24:57 | 000,000,444 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Registration3.job
[2011/04/20 02:38:24 | 000,000,418 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Update Version3.job
[2011/04/19 23:22:42 | 000,000,376 | ---- | M] () -- C:\WINDOWS\Tasks\PC Health Advisor Defrag.job
[2011/04/19 23:22:41 | 000,000,358 | ---- | M] () -- C:\WINDOWS\Tasks\PC Health Advisor.job
[2011/04/20 11:01:03 | 000,000,234 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A2947BEA

< End of report >

Edited by bilzer, 20 April 2011 - 09:56 AM.

  • 0

Advertisements


#2
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi bilzer,

Welcome to Geeks to Go! My name is SpySentinel and I will be helping you fix your malware problem.

If for any reason you do not understand any of the instructions, or are just unsure then please post back with your question, and we will go through it :D



Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
    IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
    O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O7 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
    O7 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
    O7 - HKU\S-1-5-21-1123561945-1844237615-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
    [2011/04/19 19:28:04 | 000,000,312 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
    @Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A2947BEA
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done

  • 0

#3
bilzer

bilzer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Hi Spy Sentinal,

Thanks for helping me here. I folowed your directions and I will post the OTL report that I ran AFTER running the OTL scan and adding the additional informatin you sent. The computer re-booted up.

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
C:\Program Files\Ask.com\GenericAskToolbar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_USERS\S-1-5-21-1123561945-1844237615-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files\Ask.com\GenericAskToolbar.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\control panel\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\restrictions\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HonorAutoRunSetting deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoCDBurning deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\RestrictRun deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel\ not found.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions\ not found.
Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions\ not found.
Registry value HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions\ not found.
Registry value HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions\ not found.
Registry value HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry key HKEY_USERS\S-1-5-21-1123561945-1844237615-725345543-1003\Software\Policies\Microsoft\Internet Explorer\control panel\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-1123561945-1844237615-725345543-1003\Software\Policies\Microsoft\Internet Explorer\restrictions\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1123561945-1844237615-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1123561945-1844237615-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoLowDiskSpaceChecks deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1123561945-1844237615-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\RestrictRun deleted successfully.
C:\WINDOWS\tasks\GlaryInitialize.job moved successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:A2947BEA deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 67986 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: OWNER
->Temp folder emptied: 139616596 bytes
->Temporary Internet Files folder emptied: 131995173 bytes
->Java cache emptied: 396916 bytes
->Flash cache emptied: 24460 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 18424 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 12795206 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 1876962 bytes

Total Files Cleaned = 274.00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: OWNER
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb

Unable to start service SrService!

OTL by OldTimer - Version 3.2.22.3 log created on 04202011_202052

Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DF4BE7.tmp not found!
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DF4DF1.tmp not found!
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DF51E9.tmp not found!
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DF530D.tmp not found!
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DF5718.tmp not found!
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DF58AD.tmp not found!
C:\Documents and Settings\OWNER\Local Settings\Temp\~DF67ED.tmp moved successfully.
C:\Documents and Settings\OWNER\Local Settings\Temp\~DFBAE2.tmp moved successfully.
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DFE1B8.tmp not found!
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DFE1ED.tmp not found!
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DFE67B.tmp not found!
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DFE6A6.tmp not found!
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DFE7C1.tmp not found!
File\Folder C:\Documents and Settings\OWNER\Local Settings\Temp\~DFE967.tmp not found!
C:\Documents and Settings\OWNER\Local Settings\Temporary Internet Files\Content.IE5\WD0BRWMG\page__pid__1998662[1].txt moved successfully.
C:\Documents and Settings\OWNER\Local Settings\Temporary Internet Files\Content.IE5\WD0BRWMG\software_updates[1].html moved successfully.
C:\Documents and Settings\OWNER\Local Settings\Temporary Internet Files\Content.IE5\NSQUXC41\like[1].php moved successfully.
C:\Documents and Settings\OWNER\Local Settings\Temporary Internet Files\Content.IE5\NSQUXC41\page__pid__1998662[1].txt moved successfully.
C:\Documents and Settings\OWNER\Local Settings\Temporary Internet Files\Content.IE5\H5NXVEJ1\search[2].aspx moved successfully.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_4b4.dat not found!

Registry entries deleted on Reboot...
  • 0

#4
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi Bill,

You're welcome :D


Launch Malwarebytes' Anti-Malware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.





Run ESET Online Scan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image
You can refer to this animation by neomage if needed.
  • 0

#5
bilzer

bilzer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Dear Spy,

I ran Malwarebytes and will include the log. It looks like the only thing it picked up was a program I use called evidence eliminator. I didn't see anything other than that so I did not select Remove selected.

I will wait to hear from you before move onto the next step

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6415

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

4/21/2011 3:18:15 PM
mbam-log-2011-04-21 (15-16-34).txt

Scan type: Quick scan
Objects scanned: 155841
Time elapsed: 8 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 145

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Evidence Eliminator Quick Mode (Rogue.EvidenceEliminator) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Evidence Eliminator Safe Restart (Rogue.EvidenceEliminator) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Evidence Eliminator Safe Shutdown (Rogue.EvidenceEliminator) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Evidence Eliminator Safe Recycle (Rogue.EvidenceEliminator) -> No action taken.
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\Evidence Eliminator (Rogue.EvidenceEliminator) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Evidence Eliminator (Rogue.EvidenceEliminator) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Evidence Eliminator (Rogue.EvidenceEliminator) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\program files\evidence eliminator (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Help (Rogue.EvidenceEliminator) -> No action taken.
c:\documents and settings\OWNER\start menu\Programs\evidence eliminator (Rogue.EvidenceEliminator) -> No action taken.

Files Infected:
c:\program files\evidence eliminator\Ee.exe (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\eeshellext.dll (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\ReadMe.txt (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\UNWISE.EXE (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\UNWISE.INI (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Config.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Drives.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Files.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\filescontents.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Folders.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\folderscans.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\iecookieskeep.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\iedownloadedkeep.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\mozillacookieskeep.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\oe5choicelist.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\pluginselections.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\scanmasks.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\tbchoicelist.dat (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\absoluteftp.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\acdsee photo viewer v3.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adaptec easy cd creator v4.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe acrobat reader v3.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe acrobat reader v4.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe acrobat reader v5.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe acrobat reader v5.1.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe acrobat reader v6.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe acrobat reader v7.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe acrobat reader v8.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe acrobat reader v9.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe acrobat v6.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe photoshop v10.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe photoshop v11.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe photoshop v12.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe photoshop v5.0 le.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe photoshop v5.5.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe photoshop v5.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe photoshop v6.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe photoshop v7.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe photoshop v8.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe photoshop v9.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\ASPack.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\avant browser.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\cabinet manager.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\copernic 2000 pro.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\copernic 2000.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\copernic agent.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\corel paintshop pro v10.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\cute ftp v4.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\cute ftp v7.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\delphi v3.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\delphi v4.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\delphi v5.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\diskkeeper v5.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\divxplayer.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\download accelerator.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\eudora mail.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\EventLog.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\ftp explorer.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\getright explorerbar.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\getright v4.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\google chrome.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\googlebar.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\googlenavigation.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\GoZilla.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\helios textpad v3.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\helios textpad v4.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\helpwriter.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\icon extractor.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\icq 2000a.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\installshield express.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\j2 messenger.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\jasc paintshop pro v5.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\jasc paintshop pro v6.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\jasc paintshop pro v7.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\jasc paintshop pro v8.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\adobe acrobat reader v3.1.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\cute ftp v3.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\norton internet security 2004.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\real audio player v6 v7 v8.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\ulead photo explorer v4.2.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\WinOnCD.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\jet photoshell v1.2.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\Kazaa.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\limewire v4.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\macromedia flash v4.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\mastersplitter v2.1.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\mcafee virus scan v4.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\microangelo 98.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\micrografx picture publisher v7.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\micrografx picture publisher v8.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\microsoft frontpage express.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\microsoft frontpage.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\microsoft help workshop.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\microsoft html help.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\microsoft office.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\microsoft publisher 2000.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\microsoft send-to extensions.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\microsoft windows paint.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\microsoft windows wordpad.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\my network places.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\napster music community.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\neato labels.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\neoplanet v5.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\norton antivirus 2000 (v6).eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\norton antivirus 2003.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\norton file manager.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\norton personal firewall.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\norton utilities 2000.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\notetab pro.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\opera browser v4.02 final.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\opera browser.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\packagefortheweb.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\personal ancestral file.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\quicktime.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\real download v4.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\real player v10.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\realone player.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\remotedesktop.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\roxio easy cd creator v6.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\safari browser.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\surething cd labeler.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\Telnet.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\ulead gif animator v4.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\ulead photo viewer v4.0.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\ulead photoimpact v10.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\ulead photoimpact v5.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\ulead photoimpact viewer v4.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\ultraedit v4.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\ultraedit v7.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\web ferret v3.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\winrar v2.6.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\winrar v2.70.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\winrar v3.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\winzip v7.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\winzip v8.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\wise installer.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\yahoo player.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\yahoomessenger.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\zipmagic 2000.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Data\Plug-Ins\zone alarm.eep (Rogue.EvidenceEliminator) -> No action taken.
c:\program files\evidence eliminator\Help\ee.chm (Rogue.EvidenceEliminator) -> No action taken.
c:\documents and settings\OWNER\start menu\Programs\evidence eliminator\evidence eliminator help.lnk (Rogue.EvidenceEliminator) -> No action taken.
c:\documents and settings\OWNER\start menu\Programs\evidence eliminator\evidence eliminator license agreement.lnk (Rogue.EvidenceEliminator) -> No action taken.
c:\documents and settings\OWNER\start menu\Programs\evidence eliminator\evidence eliminator read me.lnk (Rogue.EvidenceEliminator) -> No action taken.
c:\documents and settings\OWNER\start menu\Programs\evidence eliminator\evidence eliminator.lnk (Rogue.EvidenceEliminator) -> No action taken.
  • 0

#6
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi Bill,

It is up to you if you want to remove Evidence Eliminator, however, they have bee linked to some interesting activity lately that I think you should be aware of:
http://forums.malwar...?showtopic=5476
  • 0

#7
bilzer

bilzer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Spy,

Norton 360 did a scan on the computer an found some trojans still that it can't remove. They are located in:
C:\Documents and Settings\OWNER\Local Settings\Temp This appears to be temporary files. Should I delete them?
I am also including a recent OTL scan for your review and suggestions. I was hoping that all was well with the computer but it appears it still has some issues. I certainly appreciate your help and your expertise.

OTL logfile created on: 4/22/2011 11:35:45 AM - Run 5
OTL by OldTimer - Version 3.2.22.3 Folder = C:\FABY
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 213.00 Mb Available Physical Memory | 22.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 158.21 Gb Free Space | 67.94% Space Free | Partition Type: NTFS

Computer Name: HOME-FD4A3FFDBC | User Name: OWNER | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/19 21:32:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\FABY\OTL.exe
PRC - [2011/02/23 10:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/09/20 15:24:40 | 000,377,200 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\mcui32.exe
PRC - [2010/02/25 20:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/08/24 15:52:46 | 000,166,384 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
PRC - [2000/06/29 04:45:10 | 000,052,224 | ---- | M] (Kenonic Controls Ltd.) -- C:\WINDOWS\system32\Crypserv.exe


========== Modules (SafeList) ==========

MOD - [2011/04/19 21:32:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\FABY\OTL.exe
MOD - [2011/02/23 10:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2010/09/20 15:26:01 | 000,415,088 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/07/12 00:02:02 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
MOD - [2009/07/12 00:02:00 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (SessionLauncher)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/02/23 10:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/02/25 20:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe -- (N360)
SRV - [2008/01/29 16:09:02 | 000,394,704 | ---- | M] (Symantec, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe -- (Symantec RemoteAssist)
SRV - [2007/11/06 16:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/08/24 15:53:16 | 000,362,992 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe -- (Roxio Upnp Server 10)
SRV - [2007/08/24 15:53:14 | 000,072,176 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe -- (Roxio UPnP Renderer 10)
SRV - [2007/08/24 15:52:48 | 000,309,744 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe -- (RoxLiveShare10)
SRV - [2007/08/24 15:52:46 | 000,166,384 | ---- | M] (Sonic Solutions) [Auto | Running] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe -- (RoxWatch10)
SRV - [2007/08/24 15:52:38 | 001,083,888 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)
SRV - [2000/06/29 04:45:10 | 000,052,224 | ---- | M] (Kenonic Controls Ltd.) [Auto | Running] -- C:\WINDOWS\System32\Crypserv.exe -- (Crypkey License)


========== Driver Services (SafeList) ==========

DRV - [2011/04/15 16:29:05 | 000,802,936 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110419.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2011/03/31 11:26:12 | 001,393,144 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110421.036\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/03/31 11:26:12 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110421.036\NAVENG.SYS -- (NAVENG)
DRV - [2011/03/15 15:52:18 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/03/15 01:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/03/15 01:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/03/14 14:58:34 | 000,341,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110421.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2011/02/23 09:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 09:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 09:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 09:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/02/23 09:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 09:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/02/23 09:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/11/09 14:56:12 | 000,098,392 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SBREDrv.sys -- (SBRE)
DRV - [2010/05/06 00:01:59 | 000,361,904 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS -- (SYMTDI)
DRV - [2010/04/29 01:03:51 | 000,116,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS -- (SymIRON)
DRV - [2010/04/21 23:02:20 | 000,173,104 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS -- (SymEFA)
DRV - [2010/04/21 22:29:50 | 000,325,680 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS -- (SRTSP)
DRV - [2010/04/21 22:29:50 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 20:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys -- (ccHP)
DRV - [2009/10/14 23:50:05 | 000,328,752 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS -- (SymDS)
DRV - [2009/08/05 20:38:22 | 005,874,176 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/02/24 19:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2008/08/05 23:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/04/13 14:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2007/11/06 16:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2007/08/18 03:09:04 | 000,057,328 | ---- | M] (Sonic Solutions) [File_System | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\RxFilter.sys -- (RxFilter)
DRV - [2006/11/29 01:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\APLMp50.sys -- (APLMp50)
DRV - [2006/09/24 09:28:46 | 000,005,248 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2006/06/17 01:09:48 | 001,611,776 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/01/04 18:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2004/08/03 18:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2002/07/17 09:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [2000/02/03 15:53:12 | 000,024,608 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\ckldrv.sys -- (NetworkX)
DRV - [1996/04/03 15:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startingpage.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2011/03/16 17:44:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2011/03/15 15:53:43 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2011/04/20 20:21:06 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O8 - Extra context menu item: SurfSaver 6 QuickSave - C:\Program Files\askSam\SurfSaver 6\QuickSave.htm ()
O8 - Extra context menu item: SurfSaver 6 Save... - C:\Program Files\askSam\SurfSaver 6\add.htm ()
O9 - Extra Button: SurfSaver 6 - {91D4580B-DB35-416E-BA9E-994BBADC7177} - C:\Program Files\askSam\SurfSaver 6\SurfSaverBar.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsu...oad/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1256869687453 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2....re/HPDEXAXO.cab (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.h...tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.71.230 68.87.73.246
O18 - Protocol\Handler\asksam6 {72A9B8AD-6895-422C-A3F7-F2A7A88B88DA} - C:\Program Files\askSam\SurfSaver 6\AS6_AIPP.dll (askSam Systems)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\OWNER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\OWNER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/28 17:57:55 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/04/21 21:44:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011/04/21 15:56:26 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/04/20 22:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\InterActual
[2011/04/20 21:32:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Roxio Easy Media Creator 10
[2011/04/20 21:32:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sonic Shared
[2011/04/20 21:31:09 | 000,000,000 | ---D | C] -- C:\Program Files\Roxio
[2011/04/20 20:20:52 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/04/19 23:24:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\DriverCure
[2011/04/19 23:23:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\ParetoLogic
[2011/04/19 23:22:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Start Menu\Programs\ParetoLogic
[2011/04/19 23:22:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ParetoLogic
[2011/04/19 23:22:11 | 000,000,000 | ---D | C] -- C:\Program Files\ParetoLogic
[2011/04/19 23:22:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/04/19 22:44:14 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/04/19 22:44:14 | 000,027,984 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\sbbd.exe
[2011/04/19 22:40:33 | 000,000,000 | ---D | C] -- C:\VIPRERESCUE
[2011/04/19 22:39:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/04/19 22:39:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\SUPERAntiSpyware.com
[2011/04/19 21:51:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2011/04/19 19:04:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 8
[2011/04/19 19:04:03 | 000,000,000 | ---D | C] -- C:\Program Files\DVDFab 8
[2011/03/27 18:22:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\Tific
[2010/08/07 13:50:21 | 013,833,720 | ---- | C] (Fengtao Software Inc. ) -- C:\Program Files\DVDFab7070.exe
[2009/10/25 11:02:59 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\OWNER\Application Data\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2011/04/22 11:30:50 | 000,002,948 | ---- | M] () -- C:\WINDOWS\citation.ini
[2011/04/22 11:26:48 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011/04/22 11:01:00 | 000,000,234 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/04/22 10:51:49 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/21 18:00:01 | 000,000,444 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2011/04/21 14:33:18 | 000,000,488 | ---- | M] () -- C:\hpfr5550.xml
[2011/04/20 22:18:15 | 000,187,408 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/20 21:32:22 | 000,001,931 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Easy Media Creator 10 Suite.lnk
[2011/04/20 20:21:06 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/04/20 18:36:58 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/04/20 18:33:11 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/04/20 18:33:11 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/04/20 02:38:24 | 000,000,418 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2011/04/19 23:22:45 | 000,000,838 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\ParetoLogic PC Health Advisor.lnk
[2011/04/19 23:22:42 | 000,000,376 | ---- | M] () -- C:\WINDOWS\tasks\PC Health Advisor Defrag.job
[2011/04/19 23:22:41 | 000,000,358 | ---- | M] () -- C:\WINDOWS\tasks\PC Health Advisor.job
[2011/04/19 19:26:51 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/19 19:04:16 | 000,000,688 | ---- | M] () -- C:\Documents and Settings\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2011/04/19 19:04:16 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\DVDFab 8.lnk
[2011/04/19 16:53:36 | 000,048,128 | ---- | M] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/28 20:46:41 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/03/28 19:39:30 | 000,000,744 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/03/27 19:01:19 | 101,679,216 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\20110327-001-v5i32.exe

========== Files Created - No Company Name ==========

[2011/04/20 21:32:22 | 000,001,931 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Easy Media Creator 10 Suite.lnk
[2011/04/19 23:24:52 | 000,000,444 | ---- | C] () -- C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2011/04/19 23:22:45 | 000,000,838 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\ParetoLogic PC Health Advisor.lnk
[2011/04/19 23:22:43 | 000,000,418 | ---- | C] () -- C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2011/04/19 23:22:40 | 000,000,376 | ---- | C] () -- C:\WINDOWS\tasks\PC Health Advisor Defrag.job
[2011/04/19 23:22:36 | 000,000,358 | ---- | C] () -- C:\WINDOWS\tasks\PC Health Advisor.job
[2011/04/19 19:04:16 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2011/04/19 19:04:15 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\DVDFab 8.lnk
[2011/03/28 19:39:17 | 000,000,744 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/03/27 18:49:27 | 101,679,216 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\20110327-001-v5i32.exe
[2011/02/22 15:43:51 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Usbr38.DLL
[2011/02/20 22:31:18 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/01/15 17:42:08 | 000,026,337 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2010/09/07 11:44:18 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ExtRes.dll
[2010/09/06 12:39:35 | 000,036,653 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\Comma Separated Values (Windows).ADR
[2010/08/13 19:22:47 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2010/08/13 19:01:57 | 000,019,558 | ---- | C] () -- C:\WINDOWS\hpoins01.dat.temp
[2010/08/13 19:01:57 | 000,016,606 | ---- | C] () -- C:\WINDOWS\hpomdl01.dat.temp
[2010/08/13 18:52:07 | 000,019,558 | ---- | C] () -- C:\WINDOWS\hpoins01.dat
[2010/08/13 18:52:07 | 000,016,606 | ---- | C] () -- C:\WINDOWS\hpomdl01.dat
[2010/08/07 13:50:23 | 000,273,288 | ---- | C] () -- C:\Program Files\Install.pdf
[2010/03/19 11:19:05 | 000,025,864 | ---- | C] () -- C:\WINDOWS\System32\EEInstMngr.exe
[2010/02/06 20:40:07 | 000,000,422 | ---- | C] () -- C:\WINDOWS\System32\MSST42.DLL
[2010/02/06 13:02:07 | 000,000,422 | ---- | C] () -- C:\WINDOWS\System32\MSST45.DLL
[2010/01/30 14:15:51 | 000,002,948 | ---- | C] () -- C:\WINDOWS\citation.ini
[2009/10/29 22:36:23 | 000,111,724 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\rx_audio.Cache
[2009/10/25 11:02:59 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\inst.exe
[2009/10/25 11:02:59 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\pcouffin.cat
[2009/10/25 11:02:59 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\pcouffin.inf
[2009/10/18 22:26:06 | 000,000,088 | ---- | C] () -- C:\WINDOWS\Crypkey.ini
[2009/10/18 22:26:02 | 000,027,648 | R--- | C] () -- C:\WINDOWS\Setup_ck.exe
[2009/10/18 22:26:02 | 000,024,608 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2009/10/18 22:26:02 | 000,018,432 | ---- | C] () -- C:\WINDOWS\Setup_ck.dll
[2009/10/18 22:26:02 | 000,011,776 | ---- | C] () -- C:\WINDOWS\Ckrfresh.exe
[2009/10/18 21:51:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Dvm.INI
[2009/10/09 00:59:57 | 000,032,192 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\Schedule8.dat
[2009/10/04 15:52:04 | 000,000,363 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2009/10/03 16:07:21 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\getpntid.exe
[2009/10/03 15:00:23 | 000,945,776 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\rx_image.Cache
[2009/09/28 23:23:01 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\qrz32.dll
[2009/09/28 23:23:01 | 000,062,464 | ---- | C] () -- C:\WINDOWS\System32\agwdll32.dll
[2009/09/28 23:23:01 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\RACCD32a.dll
[2009/09/28 23:23:01 | 000,030,208 | ---- | C] () -- C:\WINDOWS\System32\GoWin32.dll
[2009/09/28 23:23:01 | 000,026,112 | ---- | C] () -- C:\WINDOWS\System32\Hamcal32.dll
[2009/09/28 01:00:10 | 000,048,128 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/27 22:53:07 | 000,000,636 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/08/28 18:40:18 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2009/08/28 18:00:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/08/28 17:54:34 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/08/28 10:43:36 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/08/28 10:42:28 | 000,187,408 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/11/06 16:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007/08/21 15:22:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/06/02 17:15:44 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\LDecVorbis.dll
[2006/05/24 12:37:27 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\cygz.dll
[2006/05/24 12:37:27 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2006/04/28 19:05:14 | 000,127,614 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/02/24 03:41:59 | 000,438,272 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2006/02/24 03:41:59 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\libfaac.dll
[2006/02/23 11:36:20 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\LMOggSpl.dll
[2006/02/23 11:36:20 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\LMOggMux.dll
[2005/09/23 15:15:04 | 001,798,144 | ---- | C] () -- C:\WINDOWS\System32\ltmm_n.dll
[2004/08/04 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,441,124 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,071,060 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/01/30 18:07:46 | 000,245,408 | ---- | C] () -- C:\WINDOWS\System32\unicows.dll
[2003/03/09 21:31:04 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2002/03/04 11:16:34 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Jpeg32.dll
[2000/01/05 13:51:22 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\Welsof32.dll
[1996/04/03 15:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2010/06/20 17:38:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/03/15 14:28:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2011/03/14 18:11:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/07/03 08:27:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2011/03/15 14:28:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/19 23:22:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/10/04 00:46:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/02/22 15:50:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ResMed
[2011/01/15 17:41:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/10/03 13:55:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2011/03/28 20:01:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/12/11 18:26:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/04/19 19:38:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2010/03/27 15:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2010/07/04 22:30:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/30 00:46:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/10/09 23:56:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\DeepBurner
[2011/04/19 23:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\DriverCure
[2011/03/24 17:07:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\DVDFab
[2009/10/06 22:47:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\GlarySoft
[2010/07/03 08:30:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ICQ
[2010/08/08 10:28:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ImgBurn
[2009/09/30 00:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\iPod Copy Expert
[2011/04/19 23:23:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ParetoLogic
[2010/09/07 08:01:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\PresPro
[2011/03/15 19:51:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\RegistryKeys
[2011/01/15 17:45:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ScanSoft
[2011/03/27 18:22:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\Tific
[2010/08/07 14:01:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\Vso
[2010/01/17 18:20:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\WeatherBug
[2009/10/04 19:22:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\YouSendIt
[2010/11/30 20:16:07 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1281741011.job
[2011/04/21 18:00:01 | 000,000,444 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Registration3.job
[2011/04/20 02:38:24 | 000,000,418 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Update Version3.job
[2011/04/19 23:22:42 | 000,000,376 | ---- | M] () -- C:\WINDOWS\Tasks\PC Health Advisor Defrag.job
[2011/04/19 23:22:41 | 000,000,358 | ---- | M] () -- C:\WINDOWS\Tasks\PC Health Advisor.job
[2011/04/22 11:01:00 | 000,000,234 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



< End of report >
  • 0

#8
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi Bill,

Yes you can have Norton remove those files.


I do not recommend that you have more than one anti virus product installed and running on your computer at a time. The reason for this is that if both products have their automatic (Real-Time) protection switched on, then those products which do not encrypt the virus strings within them can cause other anti virus products to cause "false alarms". It can also lead to a clash as both products fight for access to files which are opened again this is the resident/automatic protection. In general terms, the two programs may conflict and cause:
1) False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
2) System Performance Problems: Your system may lock up due to both products attempting to access the same file at the same time.
Therefore please go to add/remove in the control panel and remove either avast! or Norton 360.




Download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.



Let me know how your computer is running afterwards.
  • 0

#9
bilzer

bilzer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Spy,

I completed the TFC.exe program and I removed avast anti-virus as I have Norton as well and you suggested keeping just one anti-virus program. I ran Mcafee STINGER and it picked up some more maleware / viruses. Some that is says came from some programs I downloaded that were suggested by this site. Any suggestions on how to proceed?

Here is the stinger log file:

McAfee® Labs Stinger™ Version 10.1.0.1535 built on Apr 21 2011
Copyright © 2011 McAfee, Inc. All Rights Reserved.
Virus data file v1000.0000 created on Apr 21 2011.
Ready to scan for 2358 viruses, trojans and variants.

Scan initiated on Fri Apr 22 20:54:33 2011
Number of clean files: 7

Scan initiated on Fri Apr 22 20:56:22 2011
C:\Documents and Settings\OWNER\desktop\ComboFix.exe\PAUSEP.CFXXE
Found the Artemis!C8ED6BEC6378 trojan !!!
C:\Documents and Settings\OWNER\desktop\ComboFix.exe\PAUSEP.CFXXE is infected with the Artemis!C8ED6BEC6378 virus !!!
C:\Documents and Settings\OWNER\desktop\ComboFix.exe\PEVB.CFXXE
Found the Artemis!44318FE27B32 trojan !!!
C:\Documents and Settings\OWNER\desktop\ComboFix.exe\PEVB.CFXXE is infected with the Artemis!44318FE27B32 virus !!!
C:\Documents and Settings\OWNER\desktop\ComboFix.exe\SETPATH.CFXXE
Found the Artemis!6C0ABDDD67C0 trojan !!!
C:\Documents and Settings\OWNER\desktop\ComboFix.exe\SETPATH.CFXXE is infected with the Artemis!6C0ABDDD67C0 virus !!!
C:\FABY\ComboFix.exe\PAUSEP.CFXXE
Found the Artemis!C8ED6BEC6378 trojan !!!
C:\FABY\ComboFix.exe\PAUSEP.CFXXE is infected with the Artemis!C8ED6BEC6378 virus !!!
C:\FABY\ComboFix.exe\PEVB.CFXXE
Found the Artemis!44318FE27B32 trojan !!!
C:\FABY\ComboFix.exe\PEVB.CFXXE is infected with the Artemis!44318FE27B32 virus !!!
C:\FABY\ComboFix.exe\SETPATH.CFXXE
Found the Artemis!6C0ABDDD67C0 trojan !!!
C:\FABY\ComboFix.exe\SETPATH.CFXXE is infected with the Artemis!6C0ABDDD67C0 virus !!!
C:\FABY\OTL.exe
Found the Artemis!D1CFB2FA6A16 trojan !!!
C:\FABY\OTL.exe is infected with the Artemis!D1CFB2FA6A16 virus !!!
C:\Program Files\PresentationPro\PPTool.ocx
Found the Artemis!C94CF1F4F775 trojan !!!
C:\Program Files\PresentationPro\PPTool.ocx is infected with the Artemis!C94CF1F4F775 virus !!!
C:\System Volume Information\_restore{43F2A6A5-B13A-4932-9845-F94F254CBD8E}\RP2\A0000132.exe\PAUSEP.CFXXE
Found the Artemis!C8ED6BEC6378 trojan !!!
C:\System Volume Information\_restore{43F2A6A5-B13A-4932-9845-F94F254CBD8E}\RP2\A0000132.exe\PAUSEP.CFXXE is infected with the Artemis!C8ED6BEC6378 virus !!!
C:\System Volume Information\_restore{43F2A6A5-B13A-4932-9845-F94F254CBD8E}\RP2\A0000132.exe\PEVB.CFXXE
Found the Artemis!44318FE27B32 trojan !!!
C:\System Volume Information\_restore{43F2A6A5-B13A-4932-9845-F94F254CBD8E}\RP2\A0000132.exe\PEVB.CFXXE is infected with the Artemis!44318FE27B32 virus !!!
C:\System Volume Information\_restore{43F2A6A5-B13A-4932-9845-F94F254CBD8E}\RP2\A0000132.exe\SETPATH.CFXXE
Found the Artemis!6C0ABDDD67C0 trojan !!!
C:\System Volume Information\_restore{43F2A6A5-B13A-4932-9845-F94F254CBD8E}\RP2\A0000132.exe\SETPATH.CFXXE is infected with the Artemis!6C0ABDDD67C0 virus !!!
C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
Found the FakeAlert!fakealert-REP trojan !!!
C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe is infected with the FakeAlert!fakealert-REP virus !!!
C:\WINDOWS\iun6002.exe
Found the FakeAlert!fakealert-REP trojan !!!
C:\WINDOWS\iun6002.exe is infected with the FakeAlert!fakealert-REP virus !!!
C:\WINDOWS\system32\Macromed\Flash\FlashUtil10m_ActiveX.exe
Found the FakeAlert!fakealert-REP trojan !!!
C:\WINDOWS\system32\Macromed\Flash\FlashUtil10m_ActiveX.exe is infected with the FakeAlert!fakealert-REP virus !!!
Number of clean files: 213390
Number of infected files: 14
  • 0

#10
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi Bill,

Please do not run tools unless instructed to. McAfee Stinger is picking up legitimate tools that we are using to clean your computer, so these are considered False Positives by McAfee.

Other than what McAfee detected, how is your computer running?
  • 0

Advertisements


#11
bilzer

bilzer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Spy,

I will NOT run anything unless you suggest. I can see that I can easily get into more trouble that what I was dealing with. Should I run another OTL for you? The computer seems to be opening and closing program ok. I just want to make sure I have gottten rid of any nasties.
  • 0

#12
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi Bill,

Yes, please post a fresh OTL log so I can make sure your system is clean.
  • 0

#13
bilzer

bilzer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Spy,

Here is the OTL log that I just ran:

OTL logfile created on: 4/23/2011 10:17:15 PM - Run 6
OTL by OldTimer - Version 3.2.22.3 Folder = C:\FABY
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 140.00 Mb Available Physical Memory | 15.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 54.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 157.99 Gb Free Space | 67.84% Space Free | Partition Type: NTFS
Drive L: | 931.51 Gb Total Space | 925.59 Gb Free Space | 99.36% Space Free | Partition Type: NTFS

Computer Name: HOME-FD4A3FFDBC | User Name: OWNER | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/23 17:18:56 | 000,122,880 | ---- | M] (MSCom India) -- C:\Documents and Settings\OWNER\Local Settings\Temporary Internet Files\Content.IE5\6SNMKJLR\SysScanner[1].exe
PRC - [2011/04/19 21:32:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\FABY\OTL.exe
PRC - [2011/01/30 19:00:37 | 000,016,824 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
PRC - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/02/25 20:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/08/24 15:52:46 | 000,166,384 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
PRC - [2000/06/29 04:45:10 | 000,052,224 | ---- | M] (Kenonic Controls Ltd.) -- C:\WINDOWS\system32\Crypserv.exe


========== Modules (SafeList) ==========

MOD - [2011/04/19 21:32:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\FABY\OTL.exe
MOD - [2010/09/20 15:26:01 | 000,415,088 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/07/12 00:02:02 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
MOD - [2009/07/12 00:02:00 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (SessionLauncher)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/02/25 20:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe -- (N360)
SRV - [2008/01/29 16:09:02 | 000,394,704 | ---- | M] (Symantec, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe -- (Symantec RemoteAssist)
SRV - [2007/11/06 16:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/08/24 15:53:16 | 000,362,992 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe -- (Roxio Upnp Server 10)
SRV - [2007/08/24 15:53:14 | 000,072,176 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe -- (Roxio UPnP Renderer 10)
SRV - [2007/08/24 15:52:48 | 000,309,744 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe -- (RoxLiveShare10)
SRV - [2007/08/24 15:52:46 | 000,166,384 | ---- | M] (Sonic Solutions) [Auto | Running] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe -- (RoxWatch10)
SRV - [2007/08/24 15:52:38 | 001,083,888 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)
SRV - [2000/06/29 04:45:10 | 000,052,224 | ---- | M] (Kenonic Controls Ltd.) [Auto | Running] -- C:\WINDOWS\System32\Crypserv.exe -- (Crypkey License)


========== Driver Services (SafeList) ==========

DRV - [2011/04/15 16:29:05 | 000,802,936 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110419.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2011/03/31 11:26:12 | 001,393,144 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110423.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/03/31 11:26:12 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110423.002\NAVENG.SYS -- (NAVENG)
DRV - [2011/03/15 15:52:18 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/03/15 01:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/03/15 01:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/03/14 14:58:34 | 000,341,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110421.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/11/09 14:56:12 | 000,098,392 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SBREDrv.sys -- (SBRE)
DRV - [2010/05/06 00:01:59 | 000,361,904 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS -- (SYMTDI)
DRV - [2010/04/29 01:03:51 | 000,116,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS -- (SymIRON)
DRV - [2010/04/21 23:02:20 | 000,173,104 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS -- (SymEFA)
DRV - [2010/04/21 22:29:50 | 000,325,680 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS -- (SRTSP)
DRV - [2010/04/21 22:29:50 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 20:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys -- (ccHP)
DRV - [2009/10/22 13:54:18 | 000,037,392 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\21974102.sys -- (21974102)
DRV - [2009/10/14 23:50:05 | 000,328,752 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS -- (SymDS)
DRV - [2009/10/09 23:31:10 | 000,315,408 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\2197410.sys -- (setup_9.0.0.722_20.04.2011_18-56drv)
DRV - [2009/09/25 17:59:42 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\21974101.sys -- (21974101)
DRV - [2009/08/05 20:38:22 | 005,874,176 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/02/24 19:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2008/08/05 23:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/04/13 14:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2007/11/06 16:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2007/08/18 03:09:04 | 000,057,328 | ---- | M] (Sonic Solutions) [File_System | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\RxFilter.sys -- (RxFilter)
DRV - [2006/11/29 01:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\APLMp50.sys -- (APLMp50)
DRV - [2006/09/24 09:28:46 | 000,005,248 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2006/06/17 01:09:48 | 001,611,776 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/01/04 18:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2004/08/03 18:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2002/07/17 09:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [2000/02/03 15:53:12 | 000,024,608 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\ckldrv.sys -- (NetworkX)
DRV - [1996/04/03 15:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startingpage.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2011/03/16 17:44:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2011/03/15 15:53:43 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2011/04/22 15:25:12 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: SurfSaver 6 QuickSave - C:\Program Files\askSam\SurfSaver 6\QuickSave.htm ()
O8 - Extra context menu item: SurfSaver 6 Save... - C:\Program Files\askSam\SurfSaver 6\add.htm ()
O9 - Extra Button: SurfSaver 6 - {91D4580B-DB35-416E-BA9E-994BBADC7177} - C:\Program Files\askSam\SurfSaver 6\SurfSaverBar.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsu...oad/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1256869687453 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2....re/HPDEXAXO.cab (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.h...tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.71.230 68.87.73.246
O18 - Protocol\Handler\asksam6 {72A9B8AD-6895-422C-A3F7-F2A7A88B88DA} - C:\Program Files\askSam\SurfSaver 6\AS6_AIPP.dll (askSam Systems)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe ()
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\OWNER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\OWNER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/28 17:57:55 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/04/23 14:32:10 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\2197410.sys
[2011/04/23 14:32:10 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\21974101.sys
[2011/04/23 14:32:10 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\21974102.sys
[2011/04/23 14:32:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Desktop\Virus Removal Tool
[2011/04/23 11:17:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/04/23 11:16:10 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/04/23 11:16:10 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/04/23 11:16:10 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/04/22 17:42:13 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/04/22 17:41:00 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\OWNER\Desktop\TFC.exe
[2011/04/22 12:47:49 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/04/22 12:39:22 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/04/22 12:39:22 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/04/22 12:39:22 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/04/22 12:39:22 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/04/22 12:37:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/04/22 12:37:00 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/22 12:35:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Desktop\RK_Quarantine
[2011/04/21 21:44:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011/04/21 15:56:26 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/04/20 22:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\InterActual
[2011/04/20 21:32:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Roxio Easy Media Creator 10
[2011/04/20 21:32:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sonic Shared
[2011/04/20 21:31:09 | 000,000,000 | ---D | C] -- C:\Program Files\Roxio
[2011/04/20 20:20:52 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/04/19 23:24:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\DriverCure
[2011/04/19 23:23:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\ParetoLogic
[2011/04/19 23:22:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Start Menu\Programs\ParetoLogic
[2011/04/19 23:22:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ParetoLogic
[2011/04/19 23:22:11 | 000,000,000 | ---D | C] -- C:\Program Files\ParetoLogic
[2011/04/19 23:22:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/04/19 22:44:14 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/04/19 22:44:14 | 000,027,984 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\sbbd.exe
[2011/04/19 22:40:33 | 000,000,000 | ---D | C] -- C:\VIPRERESCUE
[2011/04/19 22:39:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/04/19 22:39:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\SUPERAntiSpyware.com
[2011/04/19 21:51:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2011/04/19 19:04:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 8
[2011/04/19 19:04:03 | 000,000,000 | ---D | C] -- C:\Program Files\DVDFab 8
[2011/03/27 18:22:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OWNER\Application Data\Tific
[2010/08/07 13:50:21 | 013,833,720 | ---- | C] (Fengtao Software Inc. ) -- C:\Program Files\DVDFab7070.exe
[2009/10/25 11:02:59 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\OWNER\Application Data\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2011/04/23 18:00:00 | 000,000,444 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2011/04/23 17:00:06 | 000,002,948 | ---- | M] () -- C:\WINDOWS\citation.ini
[2011/04/23 16:53:50 | 000,000,327 | -HS- | M] () -- C:\boot.ini
[2011/04/23 16:50:57 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/23 16:09:06 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/23 13:36:41 | 000,000,488 | ---- | M] () -- C:\hpfr5550.xml
[2011/04/23 04:54:51 | 000,000,358 | ---- | M] () -- C:\WINDOWS\tasks\PC Health Advisor.job
[2011/04/22 18:28:10 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/04/22 17:48:46 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/22 17:41:11 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\OWNER\Desktop\TFC.exe
[2011/04/22 15:25:12 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/22 12:33:34 | 001,098,752 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\RogueKiller.exe
[2011/04/22 11:26:48 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/04/20 22:18:15 | 000,187,408 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/20 21:32:22 | 000,001,931 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Easy Media Creator 10 Suite.lnk
[2011/04/20 18:36:58 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/04/20 18:33:11 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/04/20 18:33:11 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/04/20 02:38:24 | 000,000,418 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2011/04/19 23:22:45 | 000,000,838 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\ParetoLogic PC Health Advisor.lnk
[2011/04/19 23:22:42 | 000,000,376 | ---- | M] () -- C:\WINDOWS\tasks\PC Health Advisor Defrag.job
[2011/04/19 19:04:16 | 000,000,688 | ---- | M] () -- C:\Documents and Settings\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2011/04/19 19:04:16 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\DVDFab 8.lnk
[2011/04/19 16:53:36 | 000,048,128 | ---- | M] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/28 19:39:30 | 000,000,744 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/03/27 19:01:19 | 101,679,216 | ---- | M] () -- C:\Documents and Settings\OWNER\Desktop\20110327-001-v5i32.exe

========== Files Created - No Company Name ==========

[2011/04/22 12:47:56 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/04/22 12:47:53 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/04/22 12:39:22 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/04/22 12:39:22 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/04/22 12:39:22 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/04/22 12:39:22 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/04/22 12:39:22 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/04/22 12:33:32 | 001,098,752 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\RogueKiller.exe
[2011/04/20 21:32:22 | 000,001,931 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Easy Media Creator 10 Suite.lnk
[2011/04/19 23:24:52 | 000,000,444 | ---- | C] () -- C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2011/04/19 23:22:45 | 000,000,838 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\ParetoLogic PC Health Advisor.lnk
[2011/04/19 23:22:43 | 000,000,418 | ---- | C] () -- C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2011/04/19 23:22:40 | 000,000,376 | ---- | C] () -- C:\WINDOWS\tasks\PC Health Advisor Defrag.job
[2011/04/19 23:22:36 | 000,000,358 | ---- | C] () -- C:\WINDOWS\tasks\PC Health Advisor.job
[2011/04/19 19:04:16 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2011/04/19 19:04:15 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\DVDFab 8.lnk
[2011/03/28 19:39:17 | 000,000,744 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/03/27 18:49:27 | 101,679,216 | ---- | C] () -- C:\Documents and Settings\OWNER\Desktop\20110327-001-v5i32.exe
[2011/02/22 15:43:51 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Usbr38.DLL
[2011/02/20 22:31:18 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/01/15 17:42:08 | 000,026,337 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2010/09/07 11:44:18 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ExtRes.dll
[2010/09/06 12:39:35 | 000,036,653 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\Comma Separated Values (Windows).ADR
[2010/08/13 19:22:47 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2010/08/13 19:01:57 | 000,019,558 | ---- | C] () -- C:\WINDOWS\hpoins01.dat.temp
[2010/08/13 19:01:57 | 000,016,606 | ---- | C] () -- C:\WINDOWS\hpomdl01.dat.temp
[2010/08/13 18:52:07 | 000,019,558 | ---- | C] () -- C:\WINDOWS\hpoins01.dat
[2010/08/13 18:52:07 | 000,016,606 | ---- | C] () -- C:\WINDOWS\hpomdl01.dat
[2010/08/07 13:50:23 | 000,273,288 | ---- | C] () -- C:\Program Files\Install.pdf
[2010/03/19 11:19:05 | 000,025,864 | ---- | C] () -- C:\WINDOWS\System32\EEInstMngr.exe
[2010/02/06 20:40:07 | 000,000,422 | ---- | C] () -- C:\WINDOWS\System32\MSST42.DLL
[2010/02/06 13:02:07 | 000,000,422 | ---- | C] () -- C:\WINDOWS\System32\MSST45.DLL
[2010/01/30 14:15:51 | 000,002,948 | ---- | C] () -- C:\WINDOWS\citation.ini
[2009/10/29 22:36:23 | 000,111,724 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\rx_audio.Cache
[2009/10/25 11:02:59 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\pcouffin.cat
[2009/10/25 11:02:59 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\OWNER\Application Data\pcouffin.inf
[2009/10/18 22:26:06 | 000,000,088 | ---- | C] () -- C:\WINDOWS\Crypkey.ini
[2009/10/18 22:26:02 | 000,027,648 | R--- | C] () -- C:\WINDOWS\Setup_ck.exe
[2009/10/18 22:26:02 | 000,024,608 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2009/10/18 22:26:02 | 000,018,432 | ---- | C] () -- C:\WINDOWS\Setup_ck.dll
[2009/10/18 22:26:02 | 000,011,776 | ---- | C] () -- C:\WINDOWS\Ckrfresh.exe
[2009/10/18 21:51:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Dvm.INI
[2009/10/09 00:59:57 | 000,032,192 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\Schedule8.dat
[2009/10/04 15:52:04 | 000,000,363 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2009/10/03 16:07:21 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\getpntid.exe
[2009/10/03 15:00:23 | 000,945,776 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\rx_image.Cache
[2009/09/28 23:23:01 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\qrz32.dll
[2009/09/28 23:23:01 | 000,062,464 | ---- | C] () -- C:\WINDOWS\System32\agwdll32.dll
[2009/09/28 23:23:01 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\RACCD32a.dll
[2009/09/28 23:23:01 | 000,030,208 | ---- | C] () -- C:\WINDOWS\System32\GoWin32.dll
[2009/09/28 23:23:01 | 000,026,112 | ---- | C] () -- C:\WINDOWS\System32\Hamcal32.dll
[2009/09/28 01:00:10 | 000,048,128 | ---- | C] () -- C:\Documents and Settings\OWNER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/27 22:53:07 | 000,000,636 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/08/28 18:40:18 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2009/08/28 18:00:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/08/28 17:54:34 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/08/28 10:43:36 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/08/28 10:42:28 | 000,187,408 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/11/06 16:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007/08/21 15:22:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/06/02 17:15:44 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\LDecVorbis.dll
[2006/05/24 12:37:27 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\cygz.dll
[2006/05/24 12:37:27 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2006/04/28 19:05:14 | 000,127,614 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/02/24 03:41:59 | 000,438,272 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2006/02/24 03:41:59 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\libfaac.dll
[2006/02/23 11:36:20 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\LMOggSpl.dll
[2006/02/23 11:36:20 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\LMOggMux.dll
[2005/09/23 15:15:04 | 001,798,144 | ---- | C] () -- C:\WINDOWS\System32\ltmm_n.dll
[2004/08/04 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,441,124 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,071,060 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/01/30 18:07:46 | 000,245,408 | ---- | C] () -- C:\WINDOWS\System32\unicows.dll
[2003/03/09 21:31:04 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2002/03/04 11:16:34 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Jpeg32.dll
[2000/01/05 13:51:22 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\Welsof32.dll
[1996/04/03 15:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2010/06/20 17:38:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/03/15 14:28:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2011/03/14 18:11:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/07/03 08:27:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2011/03/15 14:28:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/19 23:22:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/10/04 00:46:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/02/22 15:50:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ResMed
[2011/01/15 17:41:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/10/03 13:55:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2011/03/28 20:01:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/12/11 18:26:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/04/19 19:38:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2010/03/27 15:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2010/07/04 22:30:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/30 00:46:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/10/09 23:56:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\DeepBurner
[2011/04/19 23:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\DriverCure
[2011/03/24 17:07:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\DVDFab
[2009/10/06 22:47:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\GlarySoft
[2010/07/03 08:30:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ICQ
[2010/08/08 10:28:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ImgBurn
[2009/09/30 00:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\iPod Copy Expert
[2011/04/19 23:23:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ParetoLogic
[2010/09/07 08:01:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\PresPro
[2011/03/15 19:51:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\RegistryKeys
[2011/01/15 17:45:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\ScanSoft
[2011/03/27 18:22:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\Tific
[2010/08/07 14:01:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\Vso
[2010/01/17 18:20:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\WeatherBug
[2009/10/04 19:22:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\OWNER\Application Data\YouSendIt
[2010/11/30 20:16:07 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1281741011.job
[2011/04/23 18:00:00 | 000,000,444 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Registration3.job
[2011/04/20 02:38:24 | 000,000,418 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Update Version3.job
[2011/04/19 23:22:42 | 000,000,376 | ---- | M] () -- C:\WINDOWS\Tasks\PC Health Advisor Defrag.job
[2011/04/23 04:54:51 | 000,000,358 | ---- | M] () -- C:\WINDOWS\Tasks\PC Health Advisor.job

========== Purity Check ==========



< End of report >
  • 0

#14
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi Bill,

I would like to see one more deep scan:


  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

  • 0

#15
bilzer

bilzer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Spy,

Here are the two logs:

Logfile of random's system information tool 1.08 (written by random/random)
Run by OWNER at 2011-04-24 00:35:02
Microsoft Windows XP Professional Service Pack 3
System drive C: has 162 GB (68%) free of 238 GB
Total RAM: 958 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:35:32 AM, on 4/24/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\OWNER\Local Settings\Temporary Internet Files\Content.IE5\6SNMKJLR\SysScanner[1].exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\OWNER\Desktop\RSIT.exe
C:\Program Files\trend micro\OWNER.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://startingpage.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\IPSBHO.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEPlg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O8 - Extra context menu item: SurfSaver 6 QuickSave - C:\Program Files\askSam\SurfSaver 6\QuickSave.htm
O8 - Extra context menu item: SurfSaver 6 Save... - C:\Program Files\askSam\SurfSaver 6\add.htm
O9 - Extra button: SurfSaver 6 - {91D4580B-DB35-416E-BA9E-994BBADC7177} - C:\Program Files\askSam\SurfSaver 6\SurfSaverBar.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} - http://www.comcastsu...oad/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1256869687453
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - https://h20436.www2....re/HPDEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.h...tDetection2.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset...lineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.ad...Plus/1.6/gp.cab
O18 - Protocol: asksam6 - {72A9B8AD-6895-422C-A3F7-F2A7A88B88DA} - C:\Program Files\askSam\SurfSaver 6\AS6_AIPP.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SessionLauncher - Unknown owner - C:\DOCUME~1\OWNER\LOCALS~1\Temp\DX9\SessionLauncher.exe (file missing)
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

--
End of file - 9104 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1281741011.job
C:\WINDOWS\tasks\ParetoLogic Registration3.job
C:\WINDOWS\tasks\ParetoLogic Update Version3.job
C:\WINDOWS\tasks\PC Health Advisor Defrag.job
C:\WINDOWS\tasks\PC Health Advisor.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEPlg.dll [2010-09-03 396144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\IPSBHO.DLL [2009-11-16 79224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-09 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEPlg.dll [2010-09-03 396144]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-08-04 18702336]
"MSConfig"=C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE [2008-04-13 169984]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-08-10 421888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe [2007-08-14 113136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [2003-02-27 40960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-12-20 443728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe [2007-08-24 240112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp psc 2000 Series.lnk]
C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpobnz08.exe [2003-04-09 323646]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe [2003-04-09 28672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-06-17 86016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe"="C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe:*:Enabled:RoxioUPnPRenderer10"
"C:\Program Files\Roxio\Creator Classic 10\Creator10.exe"="C:\Program Files\Roxio\Creator Classic 10\Creator10.exe:*:Enabled:Creator10"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe"="C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe:*:Enabled:RoxioUPnPRenderer10"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2011-04-24 00:35:06 ----D---- C:\Program Files\trend micro
2011-04-24 00:35:02 ----D---- C:\rsit
2011-04-23 14:32:10 ----A---- C:\WINDOWS\system32\drivers\21974102.sys
2011-04-23 14:32:10 ----A---- C:\WINDOWS\system32\drivers\21974101.sys
2011-04-23 14:32:10 ----A---- C:\WINDOWS\system32\drivers\2197410.sys
2011-04-23 11:17:03 ----D---- C:\Program Files\Common Files\Java
2011-04-23 11:16:10 ----A---- C:\WINDOWS\system32\javaws.exe
2011-04-23 11:16:10 ----A---- C:\WINDOWS\system32\javaw.exe
2011-04-23 11:16:10 ----A---- C:\WINDOWS\system32\java.exe
2011-04-22 17:42:13 ----SHD---- C:\RECYCLER
2011-04-22 17:36:49 ----A---- C:\ComboFix.txt
2011-04-22 12:47:56 ----A---- C:\Boot.bak
2011-04-22 12:47:49 ----RASHD---- C:\cmdcons
2011-04-22 12:39:22 ----A---- C:\WINDOWS\zip.exe
2011-04-22 12:39:22 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-04-22 12:39:22 ----A---- C:\WINDOWS\SWSC.exe
2011-04-22 12:39:22 ----A---- C:\WINDOWS\SWREG.exe
2011-04-22 12:39:22 ----A---- C:\WINDOWS\sed.exe
2011-04-22 12:39:22 ----A---- C:\WINDOWS\PEV.exe
2011-04-22 12:39:22 ----A---- C:\WINDOWS\NIRCMD.exe
2011-04-22 12:39:22 ----A---- C:\WINDOWS\MBR.exe
2011-04-22 12:39:22 ----A---- C:\WINDOWS\grep.exe
2011-04-22 12:37:31 ----D---- C:\WINDOWS\ERDNT
2011-04-22 12:37:00 ----D---- C:\Qoobox
2011-04-21 21:44:27 ----D---- C:\WINDOWS\pss
2011-04-21 15:56:26 ----D---- C:\Program Files\ESET
2011-04-20 22:19:20 ----D---- C:\Program Files\InterActual
2011-04-20 21:32:18 ----D---- C:\Program Files\Common Files\Sonic Shared
2011-04-20 21:31:09 ----D---- C:\Program Files\Roxio
2011-04-20 20:20:52 ----D---- C:\_OTL
2011-04-20 18:41:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-04-20 18:36:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2011-04-20 18:36:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2011-04-20 18:36:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2506223$
2011-04-20 18:36:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2524375$
2011-04-20 18:34:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2011-04-20 18:29:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2011-04-20 18:28:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2503658$
2011-04-20 18:28:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2011-04-20 18:28:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2011-04-20 18:28:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2511455$
2011-04-20 18:28:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2011-04-20 18:27:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-04-19 23:24:02 ----D---- C:\Documents and Settings\OWNER\Application Data\DriverCure
2011-04-19 23:23:58 ----D---- C:\Documents and Settings\OWNER\Application Data\ParetoLogic
2011-04-19 23:22:15 ----D---- C:\Program Files\Common Files\ParetoLogic
2011-04-19 23:22:11 ----D---- C:\Program Files\ParetoLogic
2011-04-19 23:22:11 ----D---- C:\Documents and Settings\All Users\Application Data\ParetoLogic
2011-04-19 22:44:14 ----N---- C:\WINDOWS\system32\sbbd.exe
2011-04-19 22:44:14 ----N---- C:\WINDOWS\system32\drivers\SBREDrv.sys
2011-04-19 22:40:33 ----D---- C:\VIPRERESCUE
2011-04-19 22:39:18 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2011-04-19 22:39:17 ----D---- C:\Documents and Settings\OWNER\Application Data\SUPERAntiSpyware.com
2011-04-19 21:51:24 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2011-04-19 19:04:03 ----D---- C:\Program Files\DVDFab 8
2011-03-27 18:22:04 ----D---- C:\Documents and Settings\OWNER\Application Data\Tific

======List of files/folders modified in the last 1 months======

2011-04-24 00:35:09 ----D---- C:\WINDOWS\Temp
2011-04-24 00:35:06 ----RD---- C:\Program Files
2011-04-24 00:34:56 ----A---- C:\WINDOWS\citation.ini
2011-04-24 00:34:37 ----D---- C:\WINDOWS\Prefetch
2011-04-24 00:33:35 ----D---- C:\FABY
2011-04-23 16:53:50 ----ASH---- C:\boot.ini
2011-04-23 16:53:50 ----A---- C:\WINDOWS\win.ini
2011-04-23 16:53:50 ----A---- C:\WINDOWS\system.ini
2011-04-23 16:51:43 ----SHD---- C:\System Volume Information
2011-04-23 16:36:46 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-04-23 16:34:55 ----D---- C:\WINDOWS\system32\drivers
2011-04-23 16:05:01 ----D---- C:\WINDOWS
2011-04-23 16:04:50 ----HD---- C:\WINDOWS\inf
2011-04-23 12:40:48 ----D---- C:\WINDOWS\system32\CatRoot2
2011-04-23 11:17:05 ----SHD---- C:\WINDOWS\Installer
2011-04-23 11:17:05 ----D---- C:\Config.Msi
2011-04-23 11:17:03 ----D---- C:\Program Files\Common Files
2011-04-23 11:16:12 ----D---- C:\WINDOWS\system32
2011-04-23 11:16:02 ----D---- C:\Program Files\Java
2011-04-22 18:27:23 ----SD---- C:\WINDOWS\Tasks
2011-04-22 15:25:12 ----D---- C:\WINDOWS\system32\drivers\etc
2011-04-22 13:01:04 ----RSD---- C:\WINDOWS\Fonts
2011-04-22 13:01:04 ----RSD---- C:\WINDOWS\assembly
2011-04-22 13:01:04 ----RD---- C:\WINDOWS\Offline Web Pages
2011-04-22 12:56:50 ----D---- C:\WINDOWS\AppPatch
2011-04-21 23:05:01 ----A---- C:\WINDOWS\system32\MRT.exe
2011-04-21 21:55:18 ----D---- C:\WINDOWS\system32\Restore
2011-04-21 17:42:36 ----D---- C:\Winlog32
2011-04-21 15:56:34 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-04-21 13:21:04 ----D---- C:\WINDOWS\Minidump
2011-04-20 22:22:52 ----D---- C:\Documents and Settings\OWNER\Application Data\Roxio
2011-04-20 21:37:36 ----D---- C:\Program Files\Common Files\Roxio Shared
2011-04-20 21:34:56 ----D---- C:\Documents and Settings\All Users\Application Data\Roxio
2011-04-20 21:34:01 ----D---- C:\temp
2011-04-20 19:53:20 ----D---- C:\WINDOWS\Microsoft.NET
2011-04-20 18:44:26 ----D---- C:\Program Files\Internet Explorer
2011-04-20 18:41:24 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-04-20 18:37:08 ----D---- C:\WINDOWS\Debug
2011-04-20 18:36:58 ----A---- C:\WINDOWS\imsins.BAK
2011-04-20 18:36:29 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-20 18:35:26 ----D---- C:\WINDOWS\ie8updates
2011-04-20 18:34:45 ----D---- C:\WINDOWS\WinSxS
2011-04-20 18:33:11 ----N---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-20 01:32:47 ----D---- C:\Program Files\DVDFab 7
2011-04-19 21:51:28 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-04-19 19:38:15 ----D---- C:\Documents and Settings\All Users\Application Data\vsosdk
2011-04-19 17:41:50 ----D---- C:\Program Files\Replay AV 8
2011-04-12 20:49:59 ----D---- C:\Program Files\SpeedFan
2011-03-28 20:01:53 ----D---- C:\Documents and Settings\All Users\Application Data\STOPzilla!

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 21974102;21974102 Boot Guard Driver; C:\WINDOWS\system32\DRIVERS\21974102.sys [2009-10-22 37392]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-07-26 43872]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 SymDS;Symantec Data Store; C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS [2009-10-14 328752]
R0 SymEFA;Symantec Extended File Attributes; C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS [2010-04-21 173104]
R1 21974101;21974101; C:\WINDOWS\system32\DRIVERS\21974101.sys [2009-09-25 128016]
R1 BHDrvx86;BHDrvx86; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110419.001\BHDrvx86.sys []
R1 ccHP;Symantec Hash Provider; C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys [2010-02-25 501888]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 NetworkX;NetworkX; C:\WINDOWS\system32\ckldrv.sys [2000-02-03 24608]
R1 SBRE;SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys []
R1 setup_9.0.0.722_20.04.2011_18-56drv;setup_9.0.0.722_20.04.2011_18-56drv; C:\WINDOWS\system32\DRIVERS\2197410.sys [2009-10-09 315408]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS [2010-04-21 43696]
R1 SymIRON;Symantec Iron Driver; C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS [2010-04-29 116784]
R1 SYMTDI;Symantec Network Dispatch Driver; C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS [2010-05-06 361904]
R2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys [2002-07-17 16877]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-06-17 1611776]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-03-09 51024]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-03-09 16080]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2009-08-26 21568]
R3 IDSxpx86;IDSxpx86; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110421.001\IDSxpx86.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-08-05 5874176]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys [2009-02-24 116736]
R3 NAVENG;NAVENG; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110423.002\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110423.002\NAVEX15.SYS []
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-08-07 47360]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 SRTSP;Symantec Real Time Storage Protection; C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS [2010-04-21 325680]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2009-05-22 29696]
S0 is3srv;is3srv; C:\WINDOWS\system32\drivers\is3srv.sys []
S0 szkg5;szkg5; C:\WINDOWS\system32\DRIVERS\szkg.sys []
S0 szkgfs;szkgfs; C:\WINDOWS\system32\drivers\szkgfs.sys []
S1 SASDIFSV;SASDIFSV; \??\C:\DOCUME~1\OWNER\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\DOCUME~1\OWNER\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 APLMp50;APLMp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\APLMp50.sys [2006-11-29 28224]
S3 catchme;catchme; \??\C:\DOCUME~1\OWNER\LOCALS~1\Temp\catchme.sys []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 nm;Network Monitor Driver; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 RxFilter;RxFilter; C:\WINDOWS\system32\DRIVERS\RxFilter.sys [2007-08-18 57328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-08-13 144672]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-06-17 389120]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-07-27 345376]
R2 Crypkey License;Crypkey License; C:\WINDOWS\system32\crypserv.exe [2000-06-29 52224]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-02 153376]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-12-20 363344]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 N360;Norton Security Suite; C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe [2010-02-25 126392]
R2 RoxWatch10;Roxio Hard Drive Watcher 10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2007-08-24 166384]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10; C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe [2007-08-24 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2007-08-24 309744]
S2 SessionLauncher;SessionLauncher; C:\DOCUME~1\OWNER\LOCALS~1\Temp\DX9\SessionLauncher.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-09-01 820008]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10; C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2007-08-24 72176]
S3 RoxMediaDB10;RoxMediaDB10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2007-08-24 1083888]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S3 Symantec RemoteAssist;Symantec RemoteAssist; C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe [2008-01-29 394704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------



info.txt logfile of random's system information tool 1.08 2011-04-24 00:35:39

======Uninstall list======

-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {4F3FCD41-AD1C-4EE8-9D5C-35DBA58BA060}
-->MsiExec.exe /I{8A42F680-2DD6-11D4-9A8C-0040F6982C20}
-->MsiExec.exe /I{A2529672-574A-4A99-86A5-C1770A0E31FE}
-->MsiExec.exe /X{1AFDB2AB-DF91-47B8-8A9C-A6E4BBAD562B}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com-->MsiExec.exe /X{6D8D64BE-F500-55B6-705D-DFD08AFE0624}
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10m_ActiveX.exe -maintain activex
Adobe Reader 9.4.4-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A94000000001}
Apple Application Support-->MsiExec.exe /I{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}
Apple Mobile Device Support-->MsiExec.exe /I{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}
Apple Software Update-->MsiExec.exe /I{C41300B9-185D-475E-BFEC-39EF732F19B1}
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Audible Download Manager-->C:\Program Files\Audible\Bin\AudibleDM_WMPSetup[1].exe /Uninstall
AudibleManager-->C:\Program Files\Audible\Bin\Upgrade.exe /Uninstall
Bonjour-->MsiExec.exe /X{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
DeepBurner v1.8.0.224-->"C:\Program Files\Astonsoft\DeepBurner\Uninstall.exe" "C:\Program Files\Astonsoft\DeepBurner\install.log"
Digital Voice Recorder-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B478ACE-8512-4A46-ACB2-69D83DF2F6C7}\setup.exe" -l0x9 -remove
DirectXInstallService-->MsiExec.exe /X{098122AB-C605-4853-B441-C0A4EB359B75}
Dr Paper 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1EC161CA-7A70-48A9-BB6C-250394C37F4F}\setup.exe" -uninst
Driver Detective-->MsiExec.exe /X{5721A8EA-A30F-4F66-9046-3F40C43AE1DC}
DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.2.2.2-->"C:\Program Files\DVDFab 5\unins000.exe"
DVDFab 7.0.9.2 (05/08/2010)-->"C:\Program Files\DVDFab 7\unins000.exe"
DVDFab 8.0.8.5 (19/03/2011)-->"C:\Program Files\DVDFab 8\unins000.exe"
E.M. PowerPoint Video Converter 2.90-->"C:\Program Files\E.M. PowerPoint Video Converter\unins000.exe"
Easy Backup Wizard-->MsiExec.exe /I{EFAF2228-4FC8-4D74-A78F-F73E9C16531B}
EMC 10 Content-->MsiExec.exe /X{FDB46DE7-9045-47BB-970A-3E4ED5369E03}
Enhanced Sound Card Driver 8.0-->C:\WINDOWS\iun6002.exe "C:\Program Files\Replay AV 8\irunin.ini"
ESET Online Scanner v3-->C:\Program Files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
FaceDetect-->MsiExec.exe /I{0A93CC85-79D6-4F78-8163-2BF6A81C6FAF}
Glary Utilities 2.32.0.1126-->"C:\Program Files\Glary Utilities\unins000.exe"
Handwriting Analyst-->C:\WINDOWS\ST5UNST.EXE -n "C:\Program Files\Handwriting Analyst\ST5UNST.LOG"
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
High Quality Photo Resizer 5.02-->"C:\Program Files\High Quality Photo Resizer\unins000.exe"
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB2158563)-->"C:\WINDOWS\$NtUninstallKB2158563$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB2443685)-->"C:\WINDOWS\$NtUninstallKB2443685$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB981793)-->"C:\WINDOWS\$NtUninstallKB981793$\spuninst\spuninst.exe"
HP Photo and Imaging 2.0 - All-in-One Drivers-->MsiExec.exe /X{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}
HP Photo and Imaging 2.0 - All-in-One-->MsiExec.exe /X{9867A917-5D17-40DE-83BA-BEA5293194B1}
HP Photo and Imaging 2.0 - hp psc 2170 series-->C:\Program Files\Hewlett-Packard\Digital Imaging\{7C8BB31C-E09E-4c7d-BBF1-45E33B467FE1}\Setup\hpzscr01.exe -datfile hposcr02.dat -forcereboot
HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
hp psc 2170 series-->MsiExec.exe /X{93FB47FB-4FDF-4131-B5FD-7A37883868E7}
ImgBurn-->"C:\Program Files\ImgBurn\uninstall.exe"
iPod Copy Expert 3.1.2-->"C:\Program Files\iPod Copy Expert\unins000.exe"
IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
iTunes-->MsiExec.exe /I{350FB27C-CF62-4EF3-AF9D-70FF313FE221}
Java™ 6 Update 24-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216023FF}
jZip-->C:\PROGRA~1\jZip\UNWISE.EXE /U C:\PROGRA~1\jZip\INSTALL.LOG
Magic ISO Maker v5.5 (build 0276)-->C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
MagicDisc 2.7.106-->C:\PROGRA~1\MAGICD~1\UNWISE.EXE C:\PROGRA~1\MAGICD~1\INSTALL.LOG
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Medieval CUE Splitter-->MsiExec.exe /I{B96D2269-568B-4CBF-9332-12FAE8B158F7}
Microsoft .NET Framework 1.1 Security Update (KB2416447)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M2416447\M2416447Uninstall.msp"
Microsoft .NET Framework 1.1 Security Update (KB979906)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office XP Professional with FrontPage-->MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
ML-1710 Series-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{18499419-2B80-4C3F-86D3-C6C45CD2062E}\setup.exe"
MobileMe Control Panel-->MsiExec.exe /I{3AC54383-31D1-4907-961B-B12CBB1D0AE8}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 6 Service Pack 2 (KB973686)-->MsiExec.exe /I{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
Norton Security Suite-->C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360\7190B588\4.3.0.5\InstStub.exe /X
PaperPort 9.0-->MsiExec.exe /I{FDCE9C15-EB45-11D5-89C7-0050DA162A25}
PaperPort DesktopDelivery-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ScanSoft\PaperPort DesktopDelivery\PPDD.isu"
ParetoLogic PC Health Advisor-->C:\Program Files\ParetoLogic\PCHA\uninstall.exe
PowerDesigns Express Tool 2.7.0-->MsiExec.exe /I{55647445-D0D5-40CD-BCD3-B663348BA196}
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
QuickTime-->MsiExec.exe /I{EB900AF8-CC61-4E15-871B-98D1EA3E8025}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Replay 7.0-->C:\WINDOWS\iun6002.exe "C:\Program Files\Replay7\irunin.ini"
Replay AV 8-->C:\WINDOWS\iun6002.exe "C:\Program Files\Replay AV 8\uninstall8.ini"
Replay Converter 3-->"C:\WINDOWS\Replay Converter 3\uninstall.exe" "/U:C:\Program Files\Replay Converter 3\Uninstall\ReplayConverrter3Uninstall.xml"
ResMed Ventilator Installer v1.72.0-->"C:\Program Files\ResMed\Ventilator\Drivers\uninstall.exe"
ResScan-->MsiExec.exe /I{71800408-16A0-4360-B3F0-76F6C35CB32C}
Roxio Activation Module-->MsiExec.exe /I{EC877639-07AB-495C-BFD1-D63AF9140810}
Roxio BackOnTrack-->MsiExec.exe /I{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}
Roxio Central Audio-->MsiExec.exe /I{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}
Roxio Central Copy-->MsiExec.exe /I{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}
Roxio Central Core-->MsiExec.exe /I{ED439A64-F018-4DD4-8BA5-328D85AB09AB}
Roxio Central Data-->MsiExec.exe /I{08E81ABD-79F7-49C2-881F-FD6CB0975693}
Roxio Central Tools-->MsiExec.exe /I{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}
Roxio CinePlayer Decoder Pack-->MsiExec.exe /I{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}
Roxio CinePlayer-->MsiExec.exe /I{1B683082-8791-4D00-8ADE-6C8986FCCC68}
Roxio Disc Gallery-->MsiExec.exe /I{3E67A8DA-FE7B-4160-8465-F5571EA18753}
Roxio Easy Media Creator 10 Suite-->MsiExec.exe /I{BF83EFE2-C9F0-40D4-841C-2066668C1D7A}
Roxio File Backup-->MsiExec.exe /I{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}
Roxio MediaShare-->MsiExec.exe /I{9A9A1828-31D1-4590-A99F-022B7237AFAE}
Roxio Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A8894F19-59C8-38D2-8A75-36C0CCE56A5B} /qb+ REBOOTPROMPT=""
Security Update for Windows Internet Explorer 8 (KB2183461)-->"C:\WINDOWS\ie8updates\KB2183461-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB2360131)-->"C:\WINDOWS\ie8updates\KB2360131-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB2416400)-->"C:\WINDOWS\ie8updates\KB2416400-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB2482017)-->"C:\WINDOWS\ie8updates\KB2482017-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB2497640)-->"C:\WINDOWS\ie8updates\KB2497640-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB2510531)-->"C:\WINDOWS\ie8updates\KB2510531-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB981332)-->"C:\WINDOWS\ie8updates\KB981332-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB982381)-->"C:\WINDOWS\ie8updates\KB982381-IE8\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB2378111)-->"C:\WINDOWS\$NtUninstallKB2378111_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB975558)-->"C:\WINDOWS\$NtUninstallKB975558_WM8$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB978695)-->"C:\WINDOWS\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2079403)-->"C:\WINDOWS\$NtUninstallKB2079403$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2115168)-->"C:\WINDOWS\$NtUninstallKB2115168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2121546)-->"C:\WINDOWS\$NtUninstallKB2121546$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2160329)-->"C:\WINDOWS\$NtUninstallKB2160329$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2229593)-->"C:\WINDOWS\$NtUninstallKB2229593$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2259922)-->"C:\WINDOWS\$NtUninstallKB2259922$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2279986)-->"C:\WINDOWS\$NtUninstallKB2279986$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2286198)-->"C:\WINDOWS\$NtUninstallKB2286198$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2296011)-->"C:\WINDOWS\$NtUninstallKB2296011$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2296199)-->"C:\WINDOWS\$NtUninstallKB2296199$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2347290)-->"C:\WINDOWS\$NtUninstallKB2347290$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2360937)-->"C:\WINDOWS\$NtUninstallKB2360937$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2387149)-->"C:\WINDOWS\$NtUninstallKB2387149$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2393802)-->"C:\WINDOWS\$NtUninstallKB2393802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2412687)-->"C:\WINDOWS\$NtUninstallKB2412687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2419632)-->"C:\WINDOWS\$NtUninstallKB2419632$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2423089)-->"C:\WINDOWS\$NtUninstallKB2423089$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2436673)-->"C:\WINDOWS\$NtUninstallKB2436673$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2440591)-->"C:\WINDOWS\$NtUninstallKB2440591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2443105)-->"C:\WINDOWS\$NtUninstallKB2443105$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2476687)-->"C:\WINDOWS\$NtUninstallKB2476687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2478960)-->"C:\WINDOWS\$NtUninstallKB2478960$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2478971)-->"C:\WINDOWS\$NtUninstallKB2478971$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2479628)-->"C:\WINDOWS\$NtUninstallKB2479628$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2479943)-->"C:\WINDOWS\$NtUninstallKB2479943$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2481109)-->"C:\WINDOWS\$NtUninstallKB2481109$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2483185)-->"C:\WINDOWS\$NtUninstallKB2483185$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2485376)-->"C:\WINDOWS\$NtUninstallKB2485376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2485663)-->"C:\WINDOWS\$NtUninstallKB2485663$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2503658)-->"C:\WINDOWS\$NtUninstallKB2503658$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2506212)-->"C:\WINDOWS\$NtUninstallKB2506212$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2506223)-->"C:\WINDOWS\$NtUninstallKB2506223$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2507618)-->"C:\WINDOWS\$NtUninstallKB2507618$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2508272)-->"C:\WINDOWS\$NtUninstallKB2508272$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2508429)-->"C:\WINDOWS\$NtUninstallKB2508429$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2509553)-->"C:\WINDOWS\$NtUninstallKB2509553$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2511455)-->"C:\WINDOWS\$NtUninstallKB2511455$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2524375)-->"C:\WINDOWS\$NtUninstallKB2524375$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961371-v2)-->"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974455)-->"C:\WINDOWS\$NtUninstallKB974455$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975561)-->"C:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975562)-->"C:\WINDOWS\$NtUninstallKB975562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977816)-->"C:\WINDOWS\$NtUninstallKB977816$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978338)-->"C:\WINDOWS\$NtUninstallKB978338$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978542)-->"C:\WINDOWS\$NtUninstallKB978542$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978601)-->"C:\WINDOWS\$NtUninstallKB978601$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979309)-->"C:\WINDOWS\$NtUninstallKB979309$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979482)-->"C:\WINDOWS\$NtUninstallKB979482$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979559)-->"C:\WINDOWS\$NtUninstallKB979559$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979683)-->"C:\WINDOWS\$NtUninstallKB979683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979687)-->"C:\WINDOWS\$NtUninstallKB979687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980195)-->"C:\WINDOWS\$NtUninstallKB980195$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980218)-->"C:\WINDOWS\$NtUninstallKB980218$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980232)-->"C:\WINDOWS\$NtUninstallKB980232$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980436)-->"C:\WINDOWS\$NtUninstallKB980436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB981322)-->"C:\WINDOWS\$NtUninstallKB981322$\spuninst\spuninst.exe"
Security Update for Windows XP (KB981852)-->"C:\WINDOWS\$NtUninstallKB981852$\spuninst\spuninst.exe"
Security Update for Windows XP (KB981957)-->"C:\WINDOWS\$NtUninstallKB981957$\spuninst\spuninst.exe"
Security Update for Windows XP (KB981997)-->"C:\WINDOWS\$NtUninstallKB981997$\spuninst\spuninst.exe"
Security Update for Windows XP (KB982132)-->"C:\WINDOWS\$NtUninstallKB982132$\spuninst\spuninst.exe"
Security Update for Windows XP (KB982214)-->"C:\WINDOWS\$NtUninstallKB982214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB982665)-->"C:\WINDOWS\$NtUninstallKB982665$\spuninst\spuninst.exe"
Security Update for Windows XP (KB982802)-->"C:\WINDOWS\$NtUninstallKB982802$\spuninst\spuninst.exe"
SmartSound Quicktracks Plugin-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
SpeedFan (remove only)-->"C:\Program Files\SpeedFan\uninstall.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
StyleWriter-->C:\WINDOWS\IsUninst.exe -fC:\SWWIN\Uninst.isu
SurfSaver 6-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{CD7C7505-89AC-414D-A025-E8626F386454}
Symantec Technical Support Web Controls-->MsiExec.exe /X{20C53FA2-4307-4671-A93F-9463B29DFCF1}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Windows Internet Explorer 8 (KB975364)-->"C:\WINDOWS\ie8updates\KB975364-IE8\spuninst\spuninst.exe"
Update for Windows Internet Explorer 8 (KB976662)-->"C:\WINDOWS\ie8updates\KB976662-IE8\spuninst\spuninst.exe"
Update for Windows XP (KB2141007)-->"C:\WINDOWS\$NtUninstallKB2141007$\spuninst\spuninst.exe"
Update for Windows XP (KB2345886)-->"C:\WINDOWS\$NtUninstallKB2345886$\spuninst\spuninst.exe"
Update for Windows XP (KB2467659)-->"C:\WINDOWS\$NtUninstallKB2467659$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Update for Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Update for Windows XP (KB971029)-->"C:\WINDOWS\$NtUninstallKB971029$\spuninst\spuninst.exe"
Update for Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
Update for Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Update for Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Video Edit Magic 4.14-->"C:\Program Files\Deskshare\Video Edit Magic 4.1\unins000.exe"
VirtualCloneDrive-->"C:\Program Files\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe" /D="C:\Program Files\Elaborate Bytes\VirtualCloneDrive"
WeatherBug-->MsiExec.exe /X{8F931595-5561-4E26-AC78-7E9B1E3E9C98}
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Winlog32 v5.5.5-->"C:\Winlog32\unins000.exe"
WinPcap 4.0.2-->C:\Program Files\WinPcap\uninstall.exe
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WinZip 14.0-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240BC}
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
YouSendIt Express-->C:\Program Files\InstallShield Installation Information\{1193600A-134F-40F9-9F71-FEF54C93C629}\setup.exe -runfromtemp -l0x0409

======Security center information======

AV: Norton Security Suite
FW: Norton Security Suite

======System event log======

Computer Name: HOME-FD4A3FFDBC
Event Code: 7001
Message: The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:
A device attached to the system is not functioning.


Record Number: 59
Source Name: Service Control Manager
Time Written: 20110315142241.000000-240
Event Type: error
User:

Computer Name: HOME-FD4A3FFDBC
Event Code: 10005
Message: DCOM got error "%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Record Number: 58
Source Name: DCOM
Time Written: 20110315142229.000000-240
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: HOME-FD4A3FFDBC
Event Code: 8007
Message: The browser was unable to update the service status bits. The data is the error.

Record Number: 31
Source Name: BROWSER
Time Written: 20110315123227.000000-240
Event Type: error
User:

Computer Name: HOME-FD4A3FFDBC
Event Code: 8007
Message: The browser was unable to update the service status bits. The data is the error.

Record Number: 30
Source Name: BROWSER
Time Written: 20110315102707.000000-240
Event Type: error
User:

Computer Name: HOME-FD4A3FFDBC
Event Code: 8007
Message: The browser was unable to update the service status bits. The data is the error.

Record Number: 29
Source Name: BROWSER
Time Written: 20110315082527.000000-240
Event Type: error
User:

=====Application event log=====

Computer Name: HOME-FD4A3FFDBC
Event Code: 100
Message: Client application registered 2 identical instances of service Bill’s\032Library._daap._tcp.local. port 3689.

Record Number: 668
Source Name: Bonjour Service
Time Written: 20110412010251.000000-240
Event Type: error
User:

Computer Name: HOME-FD4A3FFDBC
Event Code: 100
Message: 248: ERROR: read_msg errno 10054 (An existing connection was forcibly closed by the remote host.)

Record Number: 667
Source Name: Bonjour Service
Time Written: 20110412010223.000000-240
Event Type: error
User:

Computer Name: HOME-FD4A3FFDBC
Event Code: 1000
Message: Faulting application itunes.exe, version 10.0.0.68, faulting module quicktime.qts, version 7.67.75.0, fault address 0x00104124.

Record Number: 666
Source Name: Application Error
Time Written: 20110412010202.000000-240
Event Type: error
User:

Computer Name: HOME-FD4A3FFDBC
Event Code: 1000
Message: Faulting application outlook.exe, version 10.0.2616.0, faulting module outlcm.dll, version 10.0.2623.0, fault address 0x00014afb.

Record Number: 460
Source Name: Microsoft Office 10
Time Written: 20110324131956.000000-240
Event Type: error
User:

Computer Name: HOME-FD4A3FFDBC
Event Code: 1015
Message: Failed to connect to server. Error: 0x800401F0

Record Number: 175
Source Name: MsiInstaller
Time Written: 20110314180449.000000-240
Event Type: warning
User: HOME-FD4A3FFDBC\OWNER

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\Common Files\Roxio Shared\10.0\DLLShared;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\QuickTime\QTSystem;C:\Program Files\jZip
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=0407
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"asl.log"=Destination=file;OnFirstLog=command,environment,parent
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\10.0\Roxio Central36\

-----------------EOF-----------------
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP