ok here is what you asked for:
MBR.zip 613bytes
315 downloadsComboFix 11-09-26.02 - Art 09/26/2011 20:16:54.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1534.1196 [GMT -5:00]
Running from: c:\documents and settings\Art\Desktop\ComboFix.exe
Command switches used :: /killall
AV: Norton AntiVirus *Disabled/Outdated* {B5510F6F-87E1-47F7-A411-360BC453007C}
FW: Norton Internet Security *Enabled* {825036E0-9F94-4752-8789-8B92454AF49B}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini.inuse
c:\documents and settings\All Users\Application Data\mC06511DpHpB06511
c:\documents and settings\All Users\Application Data\mC06511DpHpB06511\mC06511DpHpB06511
c:\documents and settings\All Users\Application Data\mC06511DpHpB06511\mC06511DpHpB06511.exe
c:\documents and settings\All Users\Application Data\microsoft\media index\wmplibrary_v_0_12.lrd
c:\documents and settings\Art\Application Data\.#
c:\documents and settings\Art\Application Data\.#\MBX@58C@383FC0.###
c:\documents and settings\Art\Application Data\.#\MBX@BC0@383FC0.###
c:\documents and settings\Art\Application Data\.#\MBX@BDC@383FC0.###
c:\documents and settings\Art\Application Data\.#\MBX@E2C@383FC0.###
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\AlertView.exe.8de2ebce.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\AllertEula.exe.561b80e6.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\ClientApplicationFrameWork.exe.3ead1c54.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\DNGen.exe.8bb9a8a9.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\e-Speaking.exe.eb991bba.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\MSID8.tmp.f19ddaae.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\MSIE2.tmp.704001e7.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\rng.exe.ac4aa698.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\SL150.tmp.e4d71ed.ini
c:\documents and settings\Art\Local Settings\Application Data\ApplicationHistory\tps.exe.8b23323f.ini
c:\documents and settings\Art\Local Settings\Application Data\Microsoft\nvvsvc.exe
c:\documents and settings\Art\WINDOWS
C:\install.exe
c:\program files\messenger\msmsgsin.exe
c:\program files\Search Toolbar
c:\program files\Search Toolbar\SearchToolbar.dll
c:\windows\$NtUninstallKB27593$\2458191539\@
c:\windows\$NtUninstallKB27593$\2458191539\click.tlb
c:\windows\$NtUninstallKB27593$\2458191539\L\fbnzapxf
c:\windows\$NtUninstallKB27593$\2458191539\loader.tlb
c:\windows\$NtUninstallKB27593$\2458191539\U\@00000001
c:\windows\$NtUninstallKB27593$\2458191539\U\@000000c0
c:\windows\$NtUninstallKB27593$\2458191539\U\@000000cb
c:\windows\$NtUninstallKB27593$\2458191539\U\@000000cf
c:\windows\$NtUninstallKB27593$\2458191539\U\@80000000
c:\windows\$NtUninstallKB27593$\2458191539\U\@800000c0
c:\windows\$NtUninstallKB27593$\2458191539\U\@800000cb
c:\windows\$NtUninstallKB27593$\2458191539\U\@800000cf
c:\windows\$NtUninstallKB27593$\3406984657
c:\windows\{2521BB91-29B1-4d7e-9137-AC9875D77735}
c:\windows\assembly\GAC_MSIL\desktop.ini
c:\windows\system32\
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\_000011_.tmp.dll
c:\windows\system32\_000012_.tmp.dll
c:\windows\system32\d3d9caps.dat
c:\windows\system32\encapi32.dll
c:\windows\system32\SysInfo.dll
c:\windows\TSOC.LOG
c:\windows\$NtUninstallKB27593$ . . . . Failed to delete
.
Infected copy of c:\windows\SYSTEM32\wuauclt.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\wuauclt.exe
.
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe . . . is infected!!
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Common Files\Symantec Shared\ccProxy.exe . . . is infected!!
c:\program files\Common Files\Symantec Shared\ccProxy.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe . . . is infected!!
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\EaseUS\Todo Backup\bin\Agent.exe . . . is infected!!
c:\program files\EaseUS\Todo Backup\bin\Agent.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Java\jre6\bin\jqs.exe . . . is infected!!
c:\program files\Java\jre6\bin\jqs.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Norton Internet Security\Norton AntiVirus\navapsvc.exe . . . is infected!!
c:\program files\Norton Internet Security\Norton AntiVirus\navapsvc.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Norton Internet Security\Norton AntiVirus\SAVScan.exe . . . is infected!!
c:\program files\Norton Internet Security\Norton AntiVirus\SAVScan.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\progra~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe . . . is infected!!
c:\progra~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe . . . is infected!!
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe . . . is infected!!
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe . . . is infected!!
c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe . . . was deleted!! You should re-install the program it pertains to
.
c:\windows\system32\SearchIndexer.exe . . . is infected!!
c:\windows\system32\SearchIndexer.exe . . . was deleted!! You should re-install the program it pertains to
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_928506b3
.
.
((((((((((((((((((((((((( Files Created from 2011-08-27 to 2011-09-27 )))))))))))))))))))))))))))))))
.
.
2011-09-24 21:44 . 2011-09-24 21:44 -------- d-----w- c:\documents and settings\Administrator\Application Data\Webshots
2011-09-24 21:12 . 2011-09-24 21:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\OpenOffice.org
2011-09-24 01:19 . 2011-09-24 01:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2011-09-22 04:29 . 2011-09-22 04:31 -------- d-----w- c:\program files\Jasc Software Inc
2011-09-22 03:06 . 2011-09-22 03:06 -------- d-----w- c:\documents and settings\Art\Application Data\SUPERAntiSpyware.com
2011-09-22 03:06 . 2011-09-22 03:06 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-09-22 02:03 . 2010-11-09 19:56 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-09-22 02:03 . 2010-11-09 19:56 27984 ----a-w- c:\windows\system32\sbbd.exe
2011-09-22 01:42 . 2004-02-10 16:50 155648 ----a-w- c:\windows\system32\igfxres.dll
2011-09-21 12:42 . 2011-09-21 12:42 -------- d-----w- C:\Malwarebytes' Anti-Malware
2011-09-19 12:14 . 2011-09-19 12:14 -------- d--h--w- c:\windows\PIF
2011-09-19 11:03 . 2011-09-19 11:03 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\VS Revo Group
2011-09-19 10:47 . 2011-09-19 10:47 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Identities
2011-09-19 10:46 . 2011-09-19 10:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\Windows Desktop Search
2011-09-19 10:46 . 2011-09-19 10:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\Windows Search
2011-09-18 06:26 . 2011-09-18 06:26 -------- d-----w- c:\program files\BitPim
2011-09-16 09:31 . 2011-09-16 09:31 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-16 09:08 . 2011-09-16 09:08 -------- d-----w- C:\295b6f360e3123054473
2011-09-11 16:22 . 2011-09-11 16:22 -------- d-----w- c:\documents and settings\Art\Application Data\gtk-2.0
2011-09-11 16:22 . 2011-09-11 16:22 -------- d-----w- c:\documents and settings\Art\.thumbnails
2011-09-11 16:21 . 2011-09-22 02:06 -------- d-----w- c:\documents and settings\Art\.gimp-2.6
2011-09-11 16:20 . 2011-09-11 16:20 -------- d-----w- c:\program files\GIMP-2.0
2011-09-11 16:03 . 2011-09-11 16:03 -------- d-----w- c:\documents and settings\Art\Application Data\Preclick
2011-09-09 11:05 . 2011-09-09 11:05 -------- d-----w- c:\documents and settings\NetworkService\Application Data\iolo
2011-09-05 15:29 . 2011-09-05 15:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrium
2011-09-05 15:28 . 2011-09-05 15:28 -------- d-----w- c:\program files\Macrium
2011-09-05 15:12 . 2011-09-05 15:12 -------- d-----w- C:\temp_hkeo1mr3dck
2011-09-05 15:12 . 2011-09-05 15:12 -------- d-----w- C:\temp_Backupper
2011-09-05 14:57 . 2011-09-05 14:57 160704 ----a-w- c:\windows\Open Source Backup Uninstaller.exe
2011-09-05 14:57 . 2011-09-05 14:57 -------- d-----w- c:\program files\Open Source Backup
2011-09-05 03:00 . 2011-09-05 03:00 276992 --sha-w- C:\EUMONBMP.SYS
2011-09-05 02:53 . 2011-08-06 05:52 184072 ----a-w- c:\windows\system32\drivers\EuFdDisk.sys
2011-09-05 02:53 . 2011-08-06 05:52 16008 ----a-w- c:\windows\system32\drivers\eudskacs.sys
2011-09-05 02:53 . 2011-08-06 05:52 38920 ----a-w- c:\windows\system32\drivers\eubakup.sys
2011-09-05 02:53 . 2011-08-06 05:52 42376 ----a-w- c:\windows\system32\drivers\EUBKMON.sys
2011-09-05 02:50 . 2011-08-06 05:52 20616 ----a-w- c:\windows\system32\fbnative.exe
2011-09-05 02:50 . 2011-09-05 02:50 -------- d-----w- c:\program files\EaseUS
2011-09-04 09:13 . 2011-09-04 09:13 -------- d-----w- c:\program files\Combat Engineer
2011-09-04 09:07 . 2011-09-04 09:07 -------- d-----w- c:\program files\SilverCreekCommonFiles
2011-09-04 09:07 . 2011-09-04 09:08 -------- d-----w- c:\program files\#1 Free Minesweeper
2011-09-03 10:17 . 2011-09-09 09:12 599040 ------w- c:\windows\system32\dllcache\crypt32.dll
2011-08-28 22:33 . 2011-09-15 12:55 -------- d-----w- c:\documents and settings\Art\Application Data\dvdcss
2011-08-28 21:53 . 2011-08-28 21:53 -------- d-----w- c:\program files\VideoLAN
2011-08-28 21:53 . 2011-08-28 21:53 -------- d-----w- c:\program files\Shop to Win 9
2011-08-28 21:39 . 2011-08-28 21:39 -------- d-----w- c:\program files\DVD Codecs
2011-08-28 17:11 . 2011-08-28 17:12 -------- d-----w- c:\documents and settings\Art\Local Settings\Application Data\Tific
2011-08-28 17:11 . 2011-08-28 17:11 -------- d-----w- c:\documents and settings\Art\Application Data\Tific
2011-08-28 17:10 . 2011-09-18 13:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2011-08-28 16:34 . 2011-08-28 16:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Driver Boost
2011-08-28 04:45 . 2000-03-15 00:07 57344 ----a-w- c:\windows\system32\GkSui16.EXE
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:12 . 2002-09-23 15:10 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-07-15 13:29 . 2002-11-18 11:27 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2004-03-19 22:40 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-01 17:56 . 2011-07-01 17:56 12952 ----a-w- c:\windows\system32\drivers\PSVolAcc.sys
2011-07-01 17:55 . 2011-07-01 17:55 16024 ----a-w- c:\windows\system32\drivers\pssnap.sys
2011-07-01 17:55 . 2011-07-01 17:55 45208 ----a-w- c:\windows\system32\drivers\psmounter.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0BC6E3FA-78EF-4886-842C-5A1258C4455A}"= "mscoree.dll" [2009-11-07 297808]
.
[HKEY_CLASSES_ROOT\clsid\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
[HKEY_CLASSES_ROOT\agihelper.AGUtils]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
2009-11-07 06:07 297808 ----a-w- c:\windows\SYSTEM32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-29 04:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-29 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-29 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-02-10 118784]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-09 71328]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-06-26 421888]
"EaseUs Watch"="c:\program files\EaseUS\Todo Backup\bin\EuWatch.exe" [2011-08-06 70792]
"EaseUs Tray"="c:\program files\EaseUS\Todo Backup\bin\TrayNotify.exe" [2011-08-06 744072]
"TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\documents and settings\Art\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
Webshots.lnk - c:\program files\Webshots\3.1.5.7617\Launcher.exe [2010-4-7 157088]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HLBackupScheduler]
2010-12-08 09:24 5247624 ----a-w- c:\program files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
2004-03-23 20:48 70800 ----a-w- c:\program files\Norton Internet Security\UrlLstCk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"VSS"=3 (0x3)
"UPS"=3 (0x3)
"srservice"=2 (0x2)
"mnmsrvc"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
"ERSvc"=3 (0x3)
"Browser"=3 (0x3)
"WSearch"=2 (0x2)
"TrkWks"=2 (0x2)
"SwPrv"=3 (0x3)
"stisvc"=2 (0x2)
"seclogon"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"Dot3svc"=3 (0x3)
"CiSvc"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"c:\\Program Files\\microsoft frontpage\\bin\\fpexplor.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Documents and Settings\\Art\\Application Data\\mjusbsp\\magicJack.exe"=
"d:\\misc install\\PDFReader_Setup.exe"=
"c:\\WINDOWS\\SYSTEM32\\mmc.exe"=
"c:\\Program Files\\Webshots\\3.1.5.7617\\Webshots.scr"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 EUBAKUP;EUBAKUP;c:\windows\SYSTEM32\DRIVERS\eubakup.sys [9/4/2011 9:53 PM 38920]
R0 EUBKMON;EUBKMON;c:\windows\SYSTEM32\DRIVERS\EUBKMON.sys [9/4/2011 9:53 PM 42376]
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\SYSTEM32\DRIVERS\pssnap.sys [7/1/2011 12:55 PM 16024]
R1 EUDSKACS;EUDSKACS;c:\windows\SYSTEM32\DRIVERS\eudskacs.sys [9/4/2011 9:53 PM 16008]
R1 EUFDDISK;EUFDDISK;c:\windows\SYSTEM32\DRIVERS\EuFdDisk.sys [9/4/2011 9:53 PM 184072]
R1 SBRE;SBRE;c:\windows\SYSTEM32\DRIVERS\SBREDrv.sys [9/21/2011 9:03 PM 98392]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [4/6/2010 8:51 AM 711352]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [4/6/2010 8:51 AM 711352]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys --> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys --> c:\windows\system32\DRIVERS\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys --> c:\windows\system32\drivers\szkgfs.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\Art\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS --> c:\docume~1\Art\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\Art\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS --> c:\docume~1\Art\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 EaseUS Agent;EaseUS Agent;c:\program files\EaseUS\Todo Backup\bin\Agent.exe --> c:\program files\EaseUS\Todo Backup\bin\Agent.exe [?]
S2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe /s --> c:\program files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe [?]
S2 PCCUJobMgr;Common Client Job Manager Service;"c:\program files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe" /s "PCCUJobMgr" /m "c:\program files\Norton PC Checkup\Engine\2.0.12.27\diMaster.dll" /prefetch:1 --> c:\program files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\SYSTEM32\DRIVERS\motccgp.sys [8/21/2008 11:49 PM 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\SYSTEM32\DRIVERS\motccgpfl.sys [8/21/2008 11:49 PM 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\SYSTEM32\DRIVERS\motport.sys [6/18/2007 8:18 PM 23680]
S3 Revoflt;Revoflt;c:\windows\SYSTEM32\DRIVERS\revoflt.sys [8/8/2010 1:35 PM 27064]
S3 TrueSight;TrueSight;c:\documents and settings\Art\Desktop\TrueSight.sys [9/23/2011 7:50 PM 60800]
S3 WPFFontCache_v0400;Windows PreseaswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-09-26 21:20:57
-----------------------------
21:20:57.875 OS Version: Windows 5.1.2600 Service Pack 3
21:20:57.875 Number of processors: 1 586 0x209
21:20:57.875 ComputerName: ARTS UserName: Art
21:20:59.328 Initialize success
21:21:16.140 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
21:21:16.140 Disk 0 Vendor: ST340014A 8.16 Size: 38146MB BusType: 3
21:21:16.140 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c
21:21:16.140 Disk 1 Vendor: ST36423A 3.05 Size: 6149MB BusType: 3
21:21:18.171 Disk 0 MBR read successfully
21:21:18.171 Disk 0 MBR scan
21:21:18.171 Disk 0 unknown MBR code
21:21:18.171 Disk 0 scanning sectors +78108030
21:21:18.250 Disk 0 scanning C:\WINDOWS\system32\drivers
21:21:29.718 Service scanning
21:21:30.687 Modules scanning
21:21:38.765 Disk 0 trace - called modules:
21:21:38.796 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
21:21:38.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a25dab8]
21:21:39.328 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x8a275b00]
21:21:39.328 Scan finished successfully
21:21:52.421 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Art\Desktop\MBR.dat"
21:21:52.453 The log file has been saved successfully to "C:\Documents and Settings\Art\Desktop\aswMBR.txt"
ntation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [7/1/2011 12:55 PM 220824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-23 c:\windows\Tasks\Auslogics Boost Speed Disk Defrag Console Defragmentation.job
- c:\program files\Auslogics\Auslogics Disk Defrag\cdefrag.exe [2010-04-10 14:32]
.
2011-09-17 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Art.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2004-03-23 20:48]
.
2011-09-27 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-09-01 23:38]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.2.1 192.168.1.254
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Hoyle Classic Games - b:\sierra\HOYLECG\Uninst.isu
AddRemove-Malwarebytes' Anti-Malware_is1 - b:\malwarebytes' anti-malware\unins000.exe
AddRemove-NortonPCCheckup - c:\program files\NortonInstaller\{170fa89a-6886-4c9e-b17b-12bccdd80788}\NortonPCCheckup\LicenseType\2.0.12.27\InstStub.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-09-26 20:33
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCCUJobMgr]
"ImagePath"="\"c:\program files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files\Norton PC Checkup\Engine\2.0.12.27\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3836)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\IME\SPGRMR.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\tcpsvcs.exe
c:\progra~1\Webshots\315~1.761\Webshots.scr
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2011-09-26 20:40:12 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-27 01:40
.
Pre-Run: 5,089,968,128 bytes free
Post-Run: 5,368,127,488 bytes free
.
- - End Of File - - 01B99022895489CC75FFD77C7A34E1FC
___________________________________________________________________________________________________________________________________________________________________
OTL logfile created on: 9/26/2011 9:09:10 PM - Run 4
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Art\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 73.30% Memory free
3.60 Gb Paging File | 3.39 Gb Available in Paging File | 94.06% Paging File free
Paging file location(s): C:\pagefile.sys 2301 2301 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.71 Gb Total Space | 5.06 Gb Free Space | 15.00% Space Free | Partition Type: NTFS
Drive D: | 6.00 Gb Total Space | 1.88 Gb Free Space | 31.27% Space Free | Partition Type: NTFS
Computer Name: ARTS | User Name: Art | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/09/26 19:11:14 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Art\Desktop\OTL.exe
PRC - [2011/08/06 00:52:46 | 000,744,072 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) -- C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe
PRC - [2011/08/06 00:52:46 | 000,070,792 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) -- C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe
PRC - [2010/07/06 15:08:06 | 000,711,352 | ---- | M] () -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
PRC - [2010/05/21 00:28:00 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010/05/21 00:27:58 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009/12/08 13:38:16 | 003,474,848 | ---- | M] (Webshots.com) -- C:\Program Files\Webshots\3.1.5.7617\Webshots.scr
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/03/09 11:47:52 | 000,071,328 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
========== Modules (No Company Name) ========== MOD - [2011/08/06 00:51:50 | 000,051,848 | ---- | M] () -- C:\Program Files\EaseUS\Todo Backup\bin\CodeLog.dll
MOD - [2010/07/06 15:08:06 | 000,711,352 | ---- | M] () -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
MOD - [2010/05/04 15:36:28 | 000,970,752 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2006/12/10 22:51:08 | 000,077,824 | R--- | M] () -- C:\Program Files\HP\Digital Imaging\bin\crm\xmltok.dll
MOD - [2006/12/10 22:51:08 | 000,065,536 | R--- | M] () -- C:\Program Files\HP\Digital Imaging\bin\crm\xmlparse.dll
MOD - [2001/07/31 09:17:12 | 000,094,274 | ---- | M] () -- C:\WINDOWS\SYSTEM32\HPBHEALR.DLL
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (WSearch)
SRV - File not found [Auto | Stopped] -- -- (SymWSC)
SRV - File not found [Auto | Stopped] -- -- (Symantec Core LC)
SRV - File not found [Auto | Stopped] -- -- (SNDSrvc)
SRV - File not found [Auto | Stopped] -- -- (SBService)
SRV - File not found [On_Demand | Stopped] -- -- (SAVScan)
SRV - File not found [Unknown | Stopped] -- -- (PCCUJobMgr)
SRV - File not found [Auto | Stopped] -- -- (Norton PC Checkup Application Launcher)
SRV - File not found [On_Demand | Stopped] -- -- (navapsvc)
SRV - File not found [Auto | Stopped] -- -- (JavaQuickStarterService)
SRV - File not found [On_Demand | Stopped] -- -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (EaseUS Agent)
SRV - File not found [Auto | Stopped] -- -- (ccSetMgr)
SRV - File not found [Auto | Stopped] -- -- (ccProxy)
SRV - File not found [Auto | Stopped] -- -- (ccEvtMgr)
SRV - [2011/07/01 12:55:20 | 000,220,824 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\Macrium\Reflect\ReflectService.exe -- (ReflectService)
SRV - [2010/07/06 15:08:06 | 000,711,352 | ---- | M] () [Auto | Running] -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe -- (ioloSystemService)
SRV - [2010/07/06 15:08:06 | 000,711,352 | ---- | M] () [Auto | Running] -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe -- (ioloFileInfoList)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Disabled | Stopped] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2006/03/09 11:48:08 | 000,087,712 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc)
SRV - [2006/01/05 01:06:02 | 000,163,840 | ---- | M] (Alex Feinman) [On_Demand | Stopped] -- C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe -- (Imapi Helper)
SRV - [2005/07/25 15:25:18 | 000,491,520 | ---- | M] ( ) [On_Demand | Stopped] -- C:\WINDOWS\System32\lxcgcoms.exe -- (lxcg_device)
========== Driver Services (SafeList) ========== DRV - [2011/09/23 19:52:02 | 000,060,800 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\Art\Desktop\TrueSight.sys -- (TrueSight)
DRV - [2011/08/06 00:52:38 | 000,184,072 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\EuFdDisk.sys -- (EUFDDISK)
DRV - [2011/08/06 00:52:36 | 000,042,376 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\EUBKMON.sys -- (EUBKMON)
DRV - [2011/08/06 00:52:30 | 000,016,008 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\eudskacs.sys -- (EUDSKACS)
DRV - [2011/08/06 00:52:28 | 000,038,920 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\eubakup.sys -- (EUBAKUP)
DRV - [2011/07/01 12:55:38 | 000,016,024 | ---- | M] (Macrium Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\pssnap.sys -- (pssnap)
DRV - [2010/12/29 04:00:00 | 001,360,760 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110105.003\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/12/29 04:00:00 | 000,086,008 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110105.003\NAVENG.SYS -- (NAVENG)
DRV - [2010/11/09 14:56:12 | 000,098,392 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\SBREDrv.sys -- (SBRE)
DRV - [2009/12/30 11:20:56 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\revoflt.sys -- (Revoflt)
DRV - [2008/11/11 13:42:00 | 000,024,832 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\lgusbmodem.sys -- (USBModem)
DRV - [2008/11/11 13:41:00 | 000,019,968 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\lgusbdiag.sys -- (UsbDiag)
DRV - [2008/11/11 13:41:00 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\lgusbbus.sys -- (usbbus)
DRV - [2008/08/21 23:49:58 | 000,008,320 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\motccgpfl.sys -- (motccgpfl)
DRV - [2008/08/21 23:49:22 | 000,018,688 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\motccgp.sys -- (motccgp)
DRV - [2008/04/13 14:19:42 | 000,075,264 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys -- (IPSec)
DRV - [2008/04/13 13:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/04/13 13:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys -- (nm)
DRV - [2007/06/18 20:18:26 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\motport.sys -- (motport)
DRV - [2007/06/18 20:18:26 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\motmodem.sys -- (motmodem)
DRV - [2006/07/24 18:51:34 | 000,009,341 | ---- | M] (iolo technologies, LLC (based on original work by Bo Brantén)) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\filedisk.sys -- (FileDisk)
DRV - [2005/01/25 22:48:52 | 000,305,288 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Norton Internet Security\Norton AntiVirus\savrt.sys -- (SAVRT)
DRV - [2005/01/25 22:48:52 | 000,037,000 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Norton Internet Security\Norton AntiVirus\savrtpel.sys -- (SAVRTPEL)
DRV - [2004/08/31 19:23:01 | 000,004,096 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\symlcbrd.sys -- (symlcbrd)
DRV - [2004/03/23 15:48:02 | 000,263,296 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2004/03/23 15:48:02 | 000,164,512 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMFW.SYS -- (SYMFW)
DRV - [2004/03/23 15:48:02 | 000,136,704 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMIDSCO.SYS -- (SYMIDSCO)
DRV - [2004/03/23 15:48:02 | 000,082,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent)
DRV - [2004/03/23 15:48:02 | 000,051,520 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMNDIS.SYS -- (SYMNDIS)
DRV - [2004/03/23 15:48:02 | 000,046,336 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMIDS.SYS -- (SYMIDS)
DRV - [2004/03/23 15:48:02 | 000,016,288 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2004/03/23 15:48:02 | 000,010,688 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMDNS.SYS -- (SYMDNS)
DRV - [2004/03/19 17:41:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKNB.SYS -- (NwlnkNb)
DRV - [2004/03/19 17:41:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKSPX.SYS -- (NwlnkSpx)
DRV - [2004/03/05 22:15:34 | 000,647,929 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys -- (IntelC52)
DRV - [2004/03/05 22:14:42 | 001,233,525 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys -- (IntelC51)
DRV - [2004/03/05 22:13:52 | 000,060,949 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys -- (IntelC53)
DRV - [2004/03/05 22:13:38 | 000,037,048 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys -- (mohfilt)
DRV - [2003/05/23 12:58:30 | 000,043,136 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2002/11/08 13:45:06 | 000,017,217 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
DRV - [2001/07/24 21:21:10 | 000,334,248 | ---- | M] (Grandtech Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\GT891x1.sys -- (DCamUSBDXGTech) Fashion Cam 01 Dual-Mode DSC (Video Camera)
DRV - [2001/07/05 12:13:14 | 000,018,088 | ---- | M] (Grandtech Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\GT890X.SYS -- (GT890x)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\Art\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
[2011/08/28 16:52:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Art\Application Data\Mozilla\Extensions
========== Chrome ========== CHR - Extension: No name found = C:\Documents and Settings\Art\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bdfkbdkkfmmckaadapdipihjfaacnkgd\3_0\
O1 HOSTS File: ([2011/09/26 20:32:23 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahooo Search Protection) - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O2 - BHO: (CNisExtBho Class) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O2 - BHO: (CNavExtBho Class) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O2 - BHO: (Neopets) - {CD292324-974F-4224-D074-CACA427AA030} - C:\Program Files\Neopets\Toolbar\Toolbar.dll (Velocity Services, Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Web assistant) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Neopets) - {CD292324-974F-4224-D074-CACA427AA030} - C:\Program Files\Neopets\Toolbar\Toolbar.dll (Velocity Services, Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Web assistant) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Neopets) - {CD292324-974F-4224-D074-CACA427AA030} - C:\Program Files\Neopets\Toolbar\Toolbar.dll (Velocity Services, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [EaseUs Tray] C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [EaseUs Watch] C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\Art\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\Art\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\Art\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\3.1.5.7617\Launcher.exe (Webshots.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra 'Tools' menuitem : Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.appl...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1270494171107 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.h...tDetection2.cab (GMNRev Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BD92E848-ECFB-4F6D-BD2D-6D9DB5578BF2}: DhcpNameServer = 192.168.2.1 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Art\Application Data\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Art\Application Data\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/03/20 12:58:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/09/26 21:04:19 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/09/26 20:52:26 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/09/26 20:44:22 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Art\Desktop\OTL.exe
[2011/09/26 20:04:30 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/09/26 20:04:30 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/09/26 20:04:30 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/09/26 20:04:29 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/09/26 20:03:38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/09/26 19:16:47 | 004,228,780 | R--- | C] (Swearware) -- C:\Documents and Settings\Art\Desktop\ComboFix.exe
[2011/09/22 01:19:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Desktop\My Shared Folder
[2011/09/21 23:31:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Jasc Software
[2011/09/21 23:29:19 | 000,000,000 | ---D | C] -- C:\Program Files\Jasc Software Inc
[2011/09/21 22:06:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Application Data\SUPERAntiSpyware.com
[2011/09/21 22:06:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/09/21 21:03:34 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/09/21 21:03:34 | 000,027,984 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\sbbd.exe
[2011/09/21 20:42:38 | 000,155,648 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxres.dll
[2011/09/21 07:42:43 | 000,000,000 | ---D | C] -- C:\Malwarebytes' Anti-Malware
[2011/09/19 07:14:33 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2011/09/19 07:12:44 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2011/09/18 01:27:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\My Documents\bitpim
[2011/09/18 01:26:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\BitPim
[2011/09/18 01:26:44 | 000,000,000 | ---D | C] -- C:\Program Files\BitPim
[2011/09/16 04:31:48 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/09/16 04:08:02 | 000,000,000 | ---D | C] -- C:\295b6f360e3123054473
[2011/09/11 11:22:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Application Data\gtk-2.0
[2011/09/11 11:22:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\.thumbnails
[2011/09/11 11:21:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\My Documents\gegl-0.0
[2011/09/11 11:21:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\.gimp-2.6
[2011/09/11 11:20:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GIMP
[2011/09/11 11:20:04 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2011/09/11 11:03:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Application Data\Preclick
[2011/09/09 06:05:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\iolo
[2011/09/05 10:43:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\My Documents\Reflect
[2011/09/05 10:29:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Macrium
[2011/09/05 10:28:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Macrium
[2011/09/05 10:28:16 | 000,000,000 | ---D | C] -- C:\Program Files\Macrium
[2011/09/05 10:12:07 | 000,000,000 | ---D | C] -- C:\temp_hkeo1mr3dck
[2011/09/05 10:12:07 | 000,000,000 | ---D | C] -- C:\temp_Backupper
[2011/09/05 09:57:05 | 000,000,000 | ---D | C] -- C:\Program Files\Open Source Backup
[2011/09/05 09:57:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Start Menu\Programs\Open Source Backup
[2011/09/04 21:53:09 | 000,184,072 | ---- | C] (CHENGDU YIWO Tech Development Co., Ltd) -- C:\WINDOWS\System32\drivers\EuFdDisk.sys
[2011/09/04 21:53:08 | 000,038,920 | ---- | C] (CHENGDU YIWO Tech Development Co., Ltd) -- C:\WINDOWS\System32\drivers\eubakup.sys
[2011/09/04 21:53:08 | 000,016,008 | ---- | C] (CHENGDU YIWO Tech Development Co., Ltd) -- C:\WINDOWS\System32\drivers\eudskacs.sys
[2011/09/04 21:53:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\EaseUS Todo Backup 3.0
[2011/09/04 21:50:35 | 000,020,616 | ---- | C] (CHENGDU YIWO Tech Development Co., Ltd) -- C:\WINDOWS\System32\fbnative.exe
[2011/09/04 21:50:03 | 000,000,000 | ---D | C] -- C:\Program Files\EaseUS
[2011/09/04 04:13:16 | 000,000,000 | ---D | C] -- C:\Program Files\Combat Engineer
[2011/09/04 04:13:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Start Menu\Programs\Combat Engineer
[2011/09/04 04:08:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Start Menu\Programs\#1 Free Minesweeper
[2011/09/04 04:07:59 | 000,000,000 | ---D | C] -- C:\Program Files\SilverCreekCommonFiles
[2011/09/04 04:07:54 | 000,000,000 | ---D | C] -- C:\Program Files\#1 Free Minesweeper
[2011/09/03 05:17:37 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll
[2011/08/28 17:33:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Application Data\dvdcss
[2011/08/28 16:54:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2011/08/28 16:53:49 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2011/08/28 16:53:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\My Documents\DealRunner
[2011/08/28 16:53:08 | 000,000,000 | ---D | C] -- C:\Program Files\Shop to Win 9
[2011/08/28 16:51:29 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Art\Start Menu\Programs\Administrative Tools
[2011/08/28 16:48:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Start Menu\Programs\FoxTab FLV Player
[2011/08/28 16:39:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Start Menu\Programs\DVD Codecs
[2011/08/28 16:39:43 | 000,000,000 | ---D | C] -- C:\Program Files\DVD Codecs
[2011/08/28 16:21:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\My Documents\BlazeVideo
[2011/08/28 12:11:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Local Settings\Application Data\Tific
[2011/08/28 12:11:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Art\Application Data\Tific
[2011/08/28 12:10:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2011/08/28 12:08:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2011/08/28 11:34:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Driver Boost
[2005/07/25 15:31:30 | 001,183,744 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgserv.dll
[2005/07/25 15:27:22 | 000,483,328 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcglmpm.dll
[2005/07/25 15:26:58 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcomm.dll
[2005/07/25 15:25:40 | 000,372,736 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgih.exe
[2005/07/25 15:25:26 | 000,114,688 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgpplc.dll
[2005/07/25 15:25:18 | 000,491,520 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcoms.exe
[2005/07/25 15:24:46 | 000,704,512 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcomc.dll
[2005/07/25 15:24:14 | 000,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgprox.dll
[2005/07/25 15:19:36 | 001,134,592 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgusb1.dll
========== Files - Modified Within 30 Days ========== [2011/09/26 21:09:00 | 000,000,428 | ---- | M] () -- C:\WINDOWS\tasks\Symantec NetDetect.job
[2011/09/26 21:07:55 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2011/09/26 21:05:03 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2011/09/26 21:05:01 | 1608,585,216 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/26 20:32:23 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2011/09/26 19:11:14 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Art\Desktop\OTL.exe
[2011/09/26 19:07:44 | 004,228,780 | R--- | M] (Swearware) -- C:\Documents and Settings\Art\Desktop\ComboFix.exe
[2011/09/26 14:21:14 | 000,000,981 | ---- | M] () -- C:\WINDOWS\QUICKEN.INI
[2011/09/23 19:52:02 | 000,060,800 | ---- | M] () -- C:\Documents and Settings\Art\Desktop\TrueSight.sys
[2011/09/23 03:06:05 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\Auslogics Boost Speed Disk Defrag Console Defragmentation.job
[2011/09/21 23:48:48 | 000,011,407 | ---- | M] () -- C:\Documents and Settings\Art\My Documents\pspbrwse.jbf
[2011/09/21 23:47:47 | 000,001,399 | ---- | M] () -- C:\pspbrwse.jbf
[2011/09/21 23:46:55 | 000,002,523 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Jasc Paint Shop Pro 8.lnk
[2011/09/21 21:28:16 | 000,000,925 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Revo Uninstaller Pro.lnk
[2011/09/21 21:03:40 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\SBRC.dat
[2011/09/21 20:40:33 | 004,194,304 | ---- | M] () -- C:\Documents and Settings\Art\NTUSER.bak
[2011/09/21 19:38:52 | 000,000,992 | ---- | M] () -- C:\Documents and Settings\Art\Desktop\magicJack.lnk
[2011/09/19 18:26:59 | 000,000,777 | ---- | M] () -- C:\Documents and Settings\Art\Start Menu\Programs\Startup\Webshots.lnk
[2011/09/19 06:52:09 | 000,000,211 | RHS- | M] () -- C:\BOOT.INI
[2011/09/16 22:17:58 | 000,000,544 | ---- | M] () -- C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Art.job
[2011/09/16 04:31:48 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/09/11 12:32:55 | 000,001,569 | ---- | M] () -- C:\Documents and Settings\Art\.recently-used.xbel
[2011/09/11 11:20:38 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\GIMP 2.lnk
[2011/09/09 04:12:13 | 000,599,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll
[2011/09/05 10:51:33 | 000,002,375 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Macrium Reflect.lnk
[2011/09/05 09:57:05 | 000,160,704 | ---- | M] () -- C:\WINDOWS\Open Source Backup Uninstaller.exe
[2011/09/04 22:00:51 | 000,276,992 | -HS- | M] () -- C:\EUMONBMP.SYS
[2011/09/04 21:53:06 | 000,001,744 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\EaseUS Todo Backup Free 3.0.lnk
[2011/09/04 04:13:16 | 000,000,761 | ---- | M] () -- C:\Documents and Settings\Art\Desktop\Combat Engineer.lnk
[2011/09/04 04:08:04 | 000,000,808 | ---- | M] () -- C:\Documents and Settings\Art\Desktop\Play Minesweeper.lnk
[2011/09/02 12:46:17 | 000,000,712 | ---- | M] () -- C:\Documents and Settings\Art\Desktop\Outlook.lnk
[2011/08/28 16:54:04 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2011/08/28 16:32:29 | 000,000,398 | ---- | M] () -- C:\Documents and Settings\Art\Application Data\burnaware.ini
[2011/08/28 11:49:44 | 000,000,139 | ---- | M] () -- C:\WINDOWS\wininit.ini
========== Files Created - No Company Name ========== [2011/09/26 20:04:30 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/09/26 20:04:30 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/09/26 20:04:30 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/09/26 20:04:30 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/09/26 20:04:30 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/09/26 19:21:35 | 1608,585,216 | -HS- | C] () -- C:\hiberfil.sys
[2011/09/23 19:50:09 | 000,060,800 | ---- | C] () -- C:\Documents and Settings\Art\Desktop\TrueSight.sys
[2011/09/21 23:48:48 | 000,011,407 | ---- | C] () -- C:\Documents and Settings\Art\My Documents\pspbrwse.jbf
[2011/09/21 23:47:47 | 000,001,399 | ---- | C] () -- C:\pspbrwse.jbf
[2011/09/21 23:32:04 | 000,002,523 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Jasc Paint Shop Pro 8.lnk
[2011/09/21 21:03:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\SBRC.dat
[2011/09/11 12:32:55 | 000,001,569 | ---- | C] () -- C:\Documents and Settings\Art\.recently-used.xbel
[2011/09/11 11:20:38 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\GIMP 2.lnk
[2011/09/05 10:28:19 | 000,002,375 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Macrium Reflect.lnk
[2011/09/05 09:57:05 | 000,160,704 | ---- | C] () -- C:\WINDOWS\Open Source Backup Uninstaller.exe
[2011/09/04 22:00:51 | 000,276,992 | -HS- | C] () -- C:\EUMONBMP.SYS
[2011/09/04 21:53:07 | 000,042,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\EUBKMON.sys
[2011/09/04 21:53:06 | 000,001,744 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\EaseUS Todo Backup Free 3.0.lnk
[2011/09/04 04:13:16 | 000,000,761 | ---- | C] () -- C:\Documents and Settings\Art\Desktop\Combat Engineer.lnk
[2011/09/04 04:08:04 | 000,000,808 | ---- | C] () -- C:\Documents and Settings\Art\Desktop\Play Minesweeper.lnk
[2011/09/02 12:45:40 | 000,000,712 | ---- | C] () -- C:\Documents and Settings\Art\Desktop\Outlook.lnk
[2011/08/28 16:54:04 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2011/08/27 23:45:49 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\GkSui16.EXE
[2011/08/21 11:55:22 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2011/08/21 11:23:40 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\CommonDL.dll
[2011/08/21 11:23:40 | 000,002,413 | ---- | C] () -- C:\WINDOWS\System32\lgAxconfig.ini
[2011/03/06 17:47:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\netscape.INI
[2011/03/06 17:39:16 | 000,041,016 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/03/06 17:38:36 | 000,634,087 | ---- | C] () -- C:\WINDOWS\cd32.exe
[2011/02/26 23:49:17 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\GTCODEC.DLL
[2011/02/26 23:49:17 | 000,000,598 | ---- | C] () -- C:\WINDOWS\FashionCam01.ini
[2011/02/26 23:49:17 | 000,000,025 | ---- | C] () -- C:\WINDOWS\AVIMaker.INI
[2011/02/26 21:51:47 | 000,001,042 | ---- | C] () -- C:\WINDOWS\hpwmdl10.dat
[2011/01/23 14:40:32 | 000,000,271 | ---- | C] () -- C:\WINDOWS\SysMech.INI
[2011/01/18 22:50:21 | 000,000,398 | ---- | C] () -- C:\Documents and Settings\Art\Application Data\burnaware.ini
[2010/12/19 12:36:42 | 000,136,210 | ---- | C] () -- C:\WINDOWS\hpwins10.dat
[2010/12/19 12:36:08 | 000,010,376 | ---- | C] () -- C:\WINDOWS\hpwscr10.dat
[2010/11/16 18:23:54 | 000,000,613 | ---- | C] () -- C:\WINDOWS\wizards.ini
[2010/10/12 00:15:56 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2010/10/03 08:23:59 | 000,000,300 | ---- | C] () -- C:\WINDOWS\sporting.ini
[2010/09/26 11:08:43 | 000,000,535 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2010/09/23 20:43:19 | 000,001,243 | ---- | C] () -- C:\WINDOWS\fpexplor.INI
[2010/09/23 20:39:25 | 000,000,459 | ---- | C] () -- C:\WINDOWS\frontpg.ini
[2010/09/21 17:08:01 | 000,006,172 | ---- | C] () -- C:\WINDOWS\hplj1300.ini
[2010/08/29 06:24:52 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2010/08/08 12:20:53 | 002,304,558 | ---- | C] () -- C:\WINDOWS\BrunetteShow.dat
[2010/08/08 12:17:18 | 000,000,571 | ---- | C] () -- C:\WINDOWS\WSST_Screen_Saver.ini
[2010/08/08 12:17:16 | 003,719,606 | ---- | C] () -- C:\WINDOWS\STRIPSHOW.dat
[2010/08/08 12:17:16 | 000,180,224 | ---- | C] () -- C:\WINDOWS\UninstallWSST.exe
[2010/06/12 20:44:29 | 000,008,704 | ---- | C] () -- C:\Documents and Settings\Art\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/06 10:20:15 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\Art\Local Settings\Application Data\fusioncache.dat
[2010/04/06 08:51:38 | 002,319,536 | ---- | C] () -- C:\WINDOWS\System32\Incinerator.dll
[2010/04/06 08:51:17 | 000,030,208 | ---- | C] () -- C:\WINDOWS\System32\iolobtdfg.exe
[2010/04/06 08:51:17 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\smrgdf.exe
[2010/04/06 06:38:48 | 000,000,429 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2010/04/06 04:01:12 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[2010/04/05 21:58:55 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2010/04/05 14:25:48 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2010/04/05 07:23:39 | 000,000,052 | ---- | C] () -- C:\WINDOWS\intuprof.ini
[2010/04/05 07:23:37 | 000,000,981 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2010/04/05 07:23:36 | 000,007,406 | ---- | C] () -- C:\WINDOWS\ICOADB32.DAT
[2008/05/26 22:18:18 | 000,184,832 | ---- | C] () -- C:\WINDOWS\System32\searchprotocolhost.exe
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2005/07/07 05:12:28 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcgvs.dll
[2004/08/31 19:30:20 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/08/31 19:26:32 | 000,149,504 | ---- | C] () -- C:\WINDOWS\UNWISE.EXE
[2004/08/31 19:23:01 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\symlcbrd.sys
[2004/08/31 19:22:03 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/08/31 19:17:45 | 000,000,139 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/08/31 19:06:46 | 000,002,048 | --S- | C] () -- C:\WINDOWS\BOOTSTAT.DAT
[2004/08/31 19:04:42 | 000,491,520 | ---- | C] () -- C:\WINDOWS\System32\PERFH009.DAT
[2004/08/31 19:04:42 | 000,088,652 | ---- | C] () -- C:\WINDOWS\System32\PERFC009.DAT
[2004/08/31 19:04:31 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/08/31 18:52:26 | 000,000,550 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/05/26 15:09:26 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\DSRIRREM.EXE
[2004/03/20 13:22:58 | 000,611,672 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/03/20 13:21:34 | 000,000,791 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/03/20 12:58:20 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/03/20 12:55:54 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/03/19 17:41:30 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\PERFI009.DAT
[2004/03/19 17:41:30 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\PERFD009.DAT
[2004/03/19 17:40:40 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[2004/03/19 17:39:04 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\MLANG.DAT
[2004/03/19 17:39:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\MIB.BIN
[2004/03/19 17:38:18 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\drivers\ipsec.sys
[2004/03/19 17:36:56 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\DSSEC.DAT
[2004/03/19 17:35:06 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2002/09/03 08:31:46 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2002/09/03 08:31:44 | 000,004,594 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2001/07/31 09:17:12 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
========== Alternate Data Streams ========== @Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:307AA992
< End of report >
___________________________________________________________________________________________________________________________________________________________________
OTL Extras logfile created on: 9/26/2011 9:09:10 PM - Run 4
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Art\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 73.30% Memory free
3.60 Gb Paging File | 3.39 Gb Available in Paging File | 94.06% Paging File free
Paging file location(s): C:\pagefile.sys 2301 2301 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.71 Gb Total Space | 5.06 Gb Free Space | 15.00% Space Free | Partition Type: NTFS
Drive D: | 6.00 Gb Total Space | 1.88 Gb Free Space | 31.27% Space Free | Partition Type: NTFS
Computer Name: ARTS | User Name: Art | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe" = C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe:*:Disabled:javaw -- ()
"C:\Program Files\microsoft frontpage\bin\fpexplor.exe" = C:\Program Files\microsoft frontpage\bin\fpexplor.exe:*:Disabled:Microsoft FrontPage Explorer -- (Microsoft Corporation)
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Disabled:Microsoft Fax Console -- (Microsoft Corporation)
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows -- (Ares Development Group)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Documents and Settings\Art\Application Data\mjusbsp\magicJack.exe" = C:\Documents and Settings\Art\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack -- (magicJack L.P.)
"D:\misc install\PDFReader_Setup.exe" = D:\misc install\PDFReader_Setup.exe:*:Enabled:InstallCore™ -- (InstallCore© Technologies )
"C:\WINDOWS\SYSTEM32\mmc.exe" = C:\WINDOWS\SYSTEM32\mmc.exe:*:Disabled:Microsoft Management Console -- (Microsoft Corporation)
"C:\Program Files\Webshots\3.1.5.7617\Webshots.scr" = C:\Program Files\Webshots\3.1.5.7617\Webshots.scr:*:Enabled:Webshots Photo Manager -- (Webshots.com)
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"#1 Free Minesweeper" = #1 Free Minesweeper
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{12E2B9E9-05B1-407d-B0FD-B5F350535125}" = Norton Internet Security
"{1485B7CD-4CBD-4039-8EAE-5A22993D7F54}" = hp LaserJet 1150 / 1300
"{1526D87C-A955-4FAB-BF18-697BA457E352}" = Norton WMI Update
"{152BF35B-56D7-4652-B519-1661AAC270EE}" = The Print Shop 20
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{26A24AE4-039D-4CA4-87B4-2F83216020F0}" = Java 6 Update 20
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java 6 Update 21
"{2857dbef-0b50-361c-8690-7d505747009f}" = Webshots Desktop
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3B29A786-5803-4e9e-9B58-3014A5B4E519}" = Norton AntiSpam
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C43EAE7-22C0-4b33-ABFB-3757ECA5FD7B}" = HP Officejet All-In-One Series
"{40724630-C95F-449d-B71D-777CFDE9EA21}" = J5700
"{40BA976E-38B8-4C63-990C-50999C8C3521}" = BPD_Scan
"{41A96655-19FB-473c-AAB7-429E372527C8}" = ProductContext
"{43FCA273-9534-40DB-B7C5-D7758875616A}" = Dell Support
"{449F3A9E-9903-4a0d-A209-08030D45A935}" = Norton Internet Security
"{48185814-A224-447a-81DA-71BD20580E1B}" = Norton Internet Security
"{4945EDF1-CEA8-4FE2-BC48-82C69EBA9695}" = FashionCam 01
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}" = Norton Internet Security
"{5677563D-0CB1-485f-9E18-C5025306BB3F}" = Norton AntiSpam
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5D0F0C1F-46B0-4AA2-B8DC-02E5FE777C19}" = 5700_Help
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.3
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{901C0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Access 2003 Runtime
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91AA4B1F-B918-4e0b-A304-F8D4EC5D7726}" = Norton Internet Security
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A2CC286B-BFE9-4D1F-9EDA-AA3E8289CA12}" = BPDSoftware_Ini
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A398F2DC-D706-4bb2-AC38-5532CD229D08}" = CC_ccProxyMSI
"{A403D88E-ED7D-48E3-91FD-B8C8A720EDA1}" = Microsoft Speech SDK 5.1
"{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}" = SimCity 4 Deluxe
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A93C9E60-29B6-49da-BA21-F70AC6AADE20}" = Norton Internet Security
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{BB912177-24CC-4AEE-8329-97D7ACD125D4}" = Macrium Reflect - Free Edition
"{BBD3F66B-1180-4785-B679-3F91572CD3B4}_is1" = iolo technologies' System Mechanic Professional
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D327AFC9-7BAA-473A-8319-6EB7A0D40138}" = Symantec Script Blocking Installer
"{D6414CC7-F215-467F-88B1-546ED863F35B}" = CC_ccStart
"{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}" = ccCommon
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{DFC6573E-124D-4026-BFA4-B433C9D3FF21}" = ISO Recorder
"{E13A66A4-8A37-451E-B4C5-E60BA0A777E3}" = Preclick PhotoBack Plug-in for HP
"{E47EE8FB-ACC0-4608-859C-4E2851B18A6A}" = Norton Internet Security
"{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton Internet Security
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EBD89E93-9774-433A-A638-27E268519A12}" = Delta60
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{FC2C0536-583C-46c0-844A-62CECAE01F22}" = Norton Internet Security
"{FC37ABD0-2108-4beb-B010-1254E0662B5A}" = MSRedist
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Amazon Kindle" = Amazon Kindle
"Ares" = Ares 2.1.7
"AtomTime Pro_is1" = AtomTime Pro 3.1d
"BurnAware Free_is1" = BurnAware Free 3.1.1
"Combat Engineer" = Combat Engineer v.2.0
"EaseUS Todo Backup Free 3.0_is1" = EaseUS Todo Backup Free 3.0
"EKS Floyd's Bumpershoot" = EKS Floyd's Bumpershoot
"EKS Sherlock" = EKS Sherlock
"ERUNT_is1" = ERUNT 1.1j
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"FrontPage v2.0" = Microsoft FrontPage 97
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Image Composer" = Microsoft Image Composer 1.0
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"Lexmark 2300 Series" = Lexmark 2300 Series
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 1.90 (Symantec Corporation)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"mvl_spor" = mvl_spor
"Neopets" = Neopets
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Open Source Backup" = Open Source Backup
"Quicken 2002 New User Edition" = Quicken 2002 New User Edition
"Shockwave" = Shockwave
"Sierra Utilities" = Sierra Utilities
"STANDARDR" = Microsoft Office Standard 2007
"SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}" = Norton Internet Security (Symantec Corporation)
"Unlocker" = Unlocker 1.9.1
"Verizon V CAST Media Manager" = Verizon V CAST Media Manager
"VLC media player" = VideoLAN VLC media player 0.8.6f
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WebPost" = Microsoft Web Publishing Wizard 1.52
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works" = Microsoft Works 4.5
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.1.0.366
"magicJack" = magicJack
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 9/23/2011 5:01:19 AM | Computer Name = ARTS | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 1.1 - Update '{2F6EFCE6-10DF-49F9-9E64-9AE3775B2588}'
could not be installed. Error code 1603. Additional information is available in
the log file C:\WINDOWS\TEMP\NDP1.1sp1-KB2416447-X86\NDP1.1sp1-KB2416447-X86-msi.0.log.
Error - 9/23/2011 5:01:20 AM | Computer Name = ARTS | Source = NativeWrapper | ID = 5000
Description =
Error - 9/23/2011 8:17:50 PM | Computer Name = ARTS | Source = SNDSrvc | ID = 13
Description =
Error - 9/23/2011 11:26:46 PM | Computer Name = ARTS | Source = SNDSrvc | ID = 13
Description =
Error - 9/26/2011 8:21:57 PM | Computer Name = ARTS | Source = SNDSrvc | ID = 13
Description =
Error - 9/26/2011 8:27:38 PM | Computer Name = ARTS | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft .NET Framework 1.1 -- Error 1706.No valid source
could be found for product Microsoft .NET Framework 1.1. The Windows installer
cannot continue.
Error - 9/26/2011 8:27:42 PM | Computer Name = ARTS | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 1.1 - Update '{2F6EFCE6-10DF-49F9-9E64-9AE3775B2588}'
could not be installed. Error code 1603. Additional information is available in
the log file C:\WINDOWS\TEMP\NDP1.1sp1-KB2416447-X86\NDP1.1sp1-KB2416447-X86-msi.0.log.
Error - 9/26/2011 8:27:46 PM | Computer Name = ARTS | Source = NativeWrapper | ID = 5000
Description =
Error - 9/26/2011 9:15:48 PM | Computer Name = ARTS | Source = JavaQuickStarterService | ID = 1
Description =
Error - 9/26/2011 9:15:53 PM | Computer Name = ARTS | Source = SNDSrvc | ID = 13
Description =
[ System Events ]
Error - 9/2/2011 5:00:59 AM | Computer Name = ARTS | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 1.1 SP1 on
Windows XP, Windows Vista, and Windows Server 2008 x86 (KB2416447).
Error - 9/2/2011 8:47:44 AM | Computer Name = ARTS | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 9/2/2011 12:57:08 PM | Computer Name = ARTS | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 9/2/2011 1:04:34 PM | Computer Name = ARTS | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 9/2/2011 1:29:49 PM | Computer Name = ARTS | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 9/2/2011 1:37:12 PM | Computer Name = ARTS | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 9/2/2011 1:44:37 PM | Computer Name = ARTS | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 9/2/2011 1:45:48 PM | Computer Name = ARTS | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 9/2/2011 1:48:45 PM | Computer Name = ARTS | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 9/3/2011 5:00:59 AM | Computer Name = ARTS | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 1.1 SP1 on
Windows XP, Windows Vista, and Windows Server 2008 x86 (KB2416447).
< End of report >
____________________________________________________________________________________________________________________________________________________________
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-09-26 21:20:57
-----------------------------
21:20:57.875 OS Version: Windows 5.1.2600 Service Pack 3
21:20:57.875 Number of processors: 1 586 0x209
21:20:57.875 ComputerName: ARTS UserName: Art
21:20:59.328 Initialize success
21:21:16.140 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
21:21:16.140 Disk 0 Vendor: ST340014A 8.16 Size: 38146MB BusType: 3
21:21:16.140 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c
21:21:16.140 Disk 1 Vendor: ST36423A 3.05 Size: 6149MB BusType: 3
21:21:18.171 Disk 0 MBR read successfully
21:21:18.171 Disk 0 MBR scan
21:21:18.171 Disk 0 unknown MBR code
21:21:18.171 Disk 0 scanning sectors +78108030
21:21:18.250 Disk 0 scanning C:\WINDOWS\system32\drivers
21:21:29.718 Service scanning
21:21:30.687 Modules scanning
21:21:38.765 Disk 0 trace - called modules:
21:21:38.796 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
21:21:38.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a25dab8]
21:21:39.328 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x8a275b00]
21:21:39.328 Scan finished successfully
21:21:52.421 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Art\Desktop\MBR.dat"
21:21:52.453 The log file has been saved successfully to "C:\Documents and Settings\Art\Desktop\aswMBR.txt"