1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved ebay-c card and other re-directs, virus-root toolkits

Discussion in 'Malware and Virus Removal Archive' started by kkrich, 2011/03/17.

  1. 2011/03/17
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    [Resolved] ebay-c card and other re-directs, virus-root toolkits

    Running Windows XP Pro, all current updates except IE.

    Ok, board says I am 13971 characters to many so I will try to ad to this post in a little while.

    I have a problem with redirects that started with ebay and credit card sites. Log on pages looked ok but the next pages were way off so I stopped and used ZA Pro (paid) to stop Internet connection (later unplugged cat 5e). Both the next screens asked for way to much account information to be correct. Both passwords were changed from another computer. I ran the AVG AV scan but it didn't help. Download Avast, uninstalled AVG, installed Avast and ran complete scan, all drives. It found problems and removed them. Three days later the problem was back. Also tired system restore for a week back, but it would not take. I read this post and one other that was similar; http://www.windowsbbs.com/malware-virus-removal/announcements.html. There were also other redirects to weird sites when using google and bing and from typing into the address bar.

    After I had read above post followed the instructions but never could get GMER to complete before it froze the computer. I did run it before I read and followed the above post. I have that in a txt file for here. I am not sure it is complete though. I tried it 4 times today without success and then disabled "drives" and ran it again but it had a BSOD. Tried again and it froze again. Started in Safe mode and ran it but it froze again. Gave up on GMER. Went ahead and ran DDS. From the other post it recommend to run MBR also and I have included that. I have tried both browser, Firefox 3.6.2 and IE 7.0.5730.13 and both appear to working with out redirects at this time.

    Attach.txt
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_11-03-05.01)
    .
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 2/12/2010 10:39:04 AM
    System Uptime: 3/16/2011 11:26:38 PM (0 hours ago)
    .
    Motherboard: MICRO-STAR INTERNATIONAL CO., LTD | | MS-7125
    Processor: AMD Athlon(tm) 64 Processor 4000+ | Socket 939 | 2412/201mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 186 GiB total, 55.006 GiB free.
    D: is Removable
    E: is FIXED (NTFS) - 186 GiB total, 47.438 GiB free.
    F: is FIXED (FAT32) - 149 GiB total, 73.702 GiB free.
    G: is Removable
    M: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: NVIDIA nForce Networking Controller
    Device ID: {1A3E09BE-1E45-494B-9174-D7385B45BBF5}\NVNET_DEV0057\4&1434C427&0&00
    Manufacturer: NVIDIA
    Name: NVIDIA nForce 10/100/1000 Mbps Ethernet #2
    PNP Device ID: {1A3E09BE-1E45-494B-9174-D7385B45BBF5}\NVNET_DEV0057\4&1434C427&0&00
    Service: NVENETFD
    .
    Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
    Description: ATI T200 Unified AVStream Driver
    Device ID: DISPLAY\NTATIVRV01\5&377FC9D&1&80000008&05&00
    Manufacturer: ATI Technologies
    Name: ATI T200 Unified AVStream Driver
    PNP Device ID: DISPLAY\NTATIVRV01\5&377FC9D&1&80000008&05&00
    Service: ATIAVAIW
    .
    ==== System Restore Points ===================
    .
    RP417: 2/21/2011 7:53:38 PM - System Checkpoint
    RP418: 2/22/2011 8:04:01 PM - System Checkpoint
    RP419: 2/23/2011 8:13:03 PM - System Checkpoint
    RP420: 2/24/2011 8:21:56 PM - System Checkpoint
    RP421: 2/25/2011 8:26:23 PM - System Checkpoint
    RP422: 2/26/2011 8:31:56 PM - System Checkpoint
    RP423: 2/27/2011 9:30:46 PM - System Checkpoint
    RP424: 2/28/2011 10:30:44 PM - System Checkpoint
    RP425: 3/1/2011 11:30:40 PM - System Checkpoint
    RP426: 3/3/2011 12:30:36 AM - System Checkpoint
    RP427: 3/4/2011 1:16:54 AM - System Checkpoint
    RP428: 3/5/2011 2:05:05 AM - System Checkpoint
    RP429: 3/6/2011 2:32:32 AM - System Checkpoint
    RP430: 3/7/2011 2:41:26 AM - System Checkpoint
    RP431: 3/8/2011 2:46:08 AM - System Checkpoint
    RP432: 3/9/2011 2:49:14 AM - System Checkpoint
    RP433: 3/10/2011 3:19:11 AM - System Checkpoint
    RP434: 3/10/2011 8:47:08 PM - Restore Operation
    RP435: 3/10/2011 9:10:30 PM - Restore Operation
    RP436: 3/11/2011 9:53:41 PM - System Checkpoint
    RP437: 3/12/2011 11:29:42 PM - System Checkpoint
    RP438: 3/13/2011 11:34:10 PM - System Checkpoint
    RP439: 3/15/2011 12:08:13 AM - System Checkpoint
    RP440: 3/16/2011 5:41:20 AM - System Checkpoint
    .
    ==== Installed Programs ======================
    .
    1AVCapture
    7-Zip 4.57
    AceView
    Acrobat.com
    Active@ ISO Burner
    Adobe AIR
    Adobe Download Manager
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Media Player
    Adobe Reader 9
    Adobe SVG Viewer 3.0
    Advanced Port Scanner v1.3
    Airlink101 SkyIPCam Utility
    AnvSoft Flash to Video Converter Professional 1.2.3
    AOL Uninstaller (Choose which Products to Remove)
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft Print Creations
    ArcSoft Print Creations - Greeting Card
    ArcSoft Print Creations - Photo Book
    ArcSoft Print Creations - Photo Calendar
    ATI - Software Uninstall Utility
    ATI Catalyst Control Center
    ATI Decoder
    ATI Display Driver
    ATI Multimedia Center
    ATI Multimedia Center 9.16
    ATI Parental Control & Encoder
    Avant Browser (remove only)
    avast! Free Antivirus
    AVG Anti-Rootkit Free
    AVIVO Codecs
    AVS DVDMenu Editor 1.2.1.19
    AVS Video Converter 5.6
    AVS4YOU Software Navigator 1.2
    AXIS Media Control Embedded
    Belarc Advisor 7.2
    Bonjour
    Brother BRAdmin Professiona 2.64
    Brother HL-5250DN
    Brownie
    BUFFALO LinkStation(LS-CHL) Setup Guide
    BUFFALO NAS Navigator
    Camera Finder
    CamStudio
    Canon PIXMA iP5000
    CardScan 8.0.5
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    ccc-core-static
    ccc-utility
    CCC Help English
    CCleaner (remove only)
    Chinese Simplified Fonts Support For Adobe Reader 8
    Chinese Traditional Fonts Support For Adobe Reader 8
    CoffeeCup Direct FTP
    CoffeeCup Flash Blogger - Registered
    CoffeeCup Flash Firestarter
    CoffeeCup Flash Form Builder - Registered
    CoffeeCup Flash Menu Builder
    CoffeeCup Flash Photo Gallery - Registered
    CoffeeCup Flash Website Font
    CoffeeCup Flash Website Font Pack
    CoffeeCup Flash Website Search - Registered
    CoffeeCup Google SiteMapper
    CoffeeCup Image Mapper
    CoffeeCup Live Chat - Registered
    CoffeeCup PixConverter
    CoffeeCup StyleSheet Maker
    CoffeeCup Visual Site Designer
    CoffeeCup Web Calendar
    CoffeeCup Web JukeBox - Registered
    CoffeeCup Web Video Player - Registered
    CoffeeCup WebCam 3.5
    Compatibility Pack for the 2007 Office system
    ConvertHelper 2.1
    Core Center
    Craigs Search Agent Trial Version 2.2
    CraigsWatch
    CutePDF Printer Setup
    DAO
    Debugging Tools for Windows (x86)
    DesignCAD 3D Max 17.0
    DriverAgent by eSupport.com
    EasyWeather
    EPSON Artisan 810 Series Printer Uninstall
    Epson Event Manager
    Epson FAX Utility
    Epson PC-FAX Driver
    Epson Print CD
    EPSON Scan
    eSearch for eBay 2.0
    Everything 1.1.4.301
    Favorites Finder
    Fences
    Flash Movie Player 1.5
    FlashCatch
    FLV Player 2.0, build 23
    FLVideoConverter
    FormatFactory
    Free CraigsList Reader Pro from CraigsPal 4.5.1
    Front Panel Designer 3.50
    FW LiveUpdate
    Gadwin PrintScreen
    Gadwin PrintScreen Professional
    GDR 4053 for SQL Server Tools and Workstation Components 2005 ENU (KB970892)
    GeoVision ADPCM
    GeoVision H264
    GeoVision JPEG
    GeoVision MPEG2
    GeoVision MPEG4
    GeoVision MPEG4 ASP
    GeoVision MPEG4 AVC
    Google Toolbar for Internet Explorer
    GUIDE PLUS+(TM) for Windows® System - ATI
    HDD Health v3.3 Beta
    HDDlife
    HijackThis 2.0.0
    Hotfix for Microsoft .NET Framework 3.0 (KB932471)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB2443685)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    i-Pro Viewer 1.2.1
    i-Speeder
    IBM ViaVoice TTS Runtime v5.0 - US English
    Identity Finder
    IIS 6.0 Resource Kit Tools
    ImgBurn
    Index Dat Spy
    Intelligent IP Installer
    IP Camera
    IP Camera Calculator 3.0
    IP Setup
    IP Setup Program
    IPLocator v4.1 Application
    IPWizard
    IsoBuster 2.5
    IsoBuster Toolbar
    iTunes
    IVI-ViewCommander
    J2SE Runtime Environment 5.0 Update 11
    Japanese Fonts Support For Adobe Reader 8
    Java(TM) 6 Update 11
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    JDiskReport
    JimsList
    Jing
    KashBox 2.08
    Korean Fonts Support For Adobe Reader 8
    LANsurveyor Express
    LinksysOne Surveillance Utility
    LiveView Control
    LogMeIn
    magicJack
    magicJack Outlook Add-In 1.0.3.521
    Malwarebytes' Anti-Malware
    Management & Control Software
    Management & Control Software hawking
    MediaLife
    Memeo AutoBackup
    MFC42DLLVersionUpTool
    Microsoft .NET Compact Framework 2.0 SP2
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft .NET Framework 4 Extended
    Microsoft ActiveSync
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Easy Assist
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Professional Edition 2003
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Visio 2007 Service Pack 2 (SP2)
    Microsoft Office Visio MUI (English) 2007
    Microsoft Office Visio Professional 2007
    Microsoft Software Update for Web Folders (English) 12
    Microsoft SQL Server 2005
    Microsoft SQL Server 2005 Tools Express Edition
    Microsoft SQL Server Native Client
    Microsoft SQL Server Setup Support Files (English)
    Microsoft SQL Server VSS Writer
    Microsoft Text-to-Speech Engine 4.0 (English)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Windows Media Video 9 VCM
    Mozilla Firefox (3.6.2)
    Mozilla Thunderbird (1.5.0.13)
    MSI DigiCell
    MSI Live Update 3
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6.0 Parser (KB933579)
    Network Camera Recorder
    Network Camera View3
    Network Recording Player
    newbay_res_200906
    NVIDIA Drivers
    OGA Notifier 2.0.0048.0
    OneTouch Version 3.0
    OpenOffice.org 3.0
    P-touch Editor 3.2
    PaperPort 7.02
    PC BackUp
    PdaNet for Windows Mobile 1.12 (Beta)
    Ping Plotter Freeware
    PlainSight Desktop Calendar 2.4.4
    PokerStars
    Port Detective
    Presto! PageManager 8.15.01 SE
    Primo
    PrintFileListPro
    Process Lasso
    psqlODBC
    QuickTime
    QuickTime Alternative 1.78
    RealPlayer Basic
    Realtek AC'97 Audio
    reedexpo_iscwest_showdirectory09
    RegCure
    Remote Printer Console
    Revo Uninstaller Pro 2.2.0
    Rovio
    Roxio Easy Media Creator 7
    Runtime
    Seagate Manager Installer
    Security Task Manager 1.8c
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Windows Internet Explorer 7 (KB2183461)
    Security Update for Windows Internet Explorer 7 (KB2360131)
    Security Update for Windows Internet Explorer 7 (KB2416400)
    Security Update for Windows Internet Explorer 7 (KB2482017)
    Security Update for Windows Internet Explorer 7 (KB938127-v2)
    Security Update for Windows Internet Explorer 7 (KB976325)
    Security Update for Windows Internet Explorer 7 (KB978207)
    Security Update for Windows Media Encoder (KB2447961)
    Security Update for Windows Media Encoder (KB979332)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2124261)
    Security Update for Windows XP (KB2160329)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2290570)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2296199)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB2393802)
    Security Update for Windows XP (KB2419632)
    Security Update for Windows XP (KB2423089)
    Security Update for Windows XP (KB2436673)
    Security Update for Windows XP (KB2440591)
    Security Update for Windows XP (KB2443105)
    Security Update for Windows XP (KB2476687)
    Security Update for Windows XP (KB2478960)
    Security Update for Windows XP (KB2478971)
    Security Update for Windows XP (KB2479628)
    Security Update for Windows XP (KB2483185)
    Security Update for Windows XP (KB2485376)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953155)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB970483)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB976323)
    Security Update for Windows XP (KB977165-v2)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981349)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982665)
    Security Update for Windows XP (KB982802)
    Sierra Wireless Sprint Setup Wizard
    Sierra Wireless Verizon Setup Wizard
    Skins
    Snapshot Viewer 9.0
    SolarWinds IP Address Tracker
    Sony Picture Utility
    Sophos Anti-Rootkit 1.5.4
    Spiceworks
    Sprite Backup
    Startup Delayer v2.5 (build 138)
    Sun ODF Plugin for Microsoft Office 1.2
    SUPERAntiSpyware Professional
    SVG Factory 1.0
    TeamViewer 4
    TeamViewer 5
    The Dude
    Timex Data Link USB
    TitanTV Client components for ATI
    TomTom HOME 2.7.6.2056
    TomTom HOME Visual Studio Merge Modules
    Tweak UI
    TweakNow PowerPack 2009
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Visio 2007 Help (KB963666)
    Update for Microsoft Windows (KB971513)
    Update for Windows Internet Explorer 7 (KB980182)
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB2467659)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Update for Windows XP (KB978207)
    Utilities
    VC 9.0 Runtime
    Venta Fax & Voice 6.1 (Home version) (remove/restore)
    VersaCheck Smart Invoice and Estimates 8.0
    Viewpoint Media Player
    VisualTCPIPRouter 1.0
    WebEx
    WebFldrs XP
    WebVideo ActiveX
    WELS3
    WinAce Archiver
    Windows 7 Upgrade Advisor
    Windows Essentials Media Codec Pack 2.1
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Installer Clean Up
    Windows Internet Explorer 7
    Windows Management Framework Core
    Windows Media Encoder 9 Series
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Mobile Update (KB949168) - March 2008 DST Update
    Windows Presentation Foundation
    Windows Time Synchronizer
    Windows XP Service Pack 3
    Wireless Ace 3G
    XML Paper Specification Shared Components Pack 1.0
    Yahoo! Messenger
    Youtorial Player
    Zinio Reader
    ZoneAlarm Pro
    Zoom V.92 PCI Voice Faxmodem
    .
    ==== Event Viewer Messages From Past Week ========
    .
    3/9/2011 7:21:22 PM, error: Service Control Manager [7034] - The TomTomHOMEService service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:39:45 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: atapi PCIIde Si3114r5
    3/16/2011 6:07:31 PM, error: Service Control Manager [7034] - The Windows Time Synchronizer service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:31 PM, error: Service Control Manager [7034] - The NMSAccess service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:31 PM, error: Service Control Manager [7034] - The NAS PM Service service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:31 PM, error: Service Control Manager [7034] - The LogMeIn service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:30 PM, error: Service Control Manager [7034] - The World Wide Web Publishing service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:30 PM, error: Service Control Manager [7034] - The Simple Mail Transfer Protocol (SMTP) service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:30 PM, error: Service Control Manager [7034] - The Seagate Service service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:30 PM, error: Service Control Manager [7034] - The LogMeIn Maintenance Service service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:30 PM, error: Service Control Manager [7034] - The LMIGuardianSvc service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:30 PM, error: Service Control Manager [7034] - The EPSON V5 Service4(01) service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:30 PM, error: Service Control Manager [7034] - The EPSON V3 Service4(01) service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:30 PM, error: Service Control Manager [7034] - The ArcSoft Connect Daemon service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:30 PM, error: Service Control Manager [7034] - The AOL Connectivity Service service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 6:07:30 PM, error: Service Control Manager [7031] - The IIS Admin service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1 milliseconds: Run the configured recovery program.
    3/16/2011 5:42:55 PM, error: Service Control Manager [7034] - The InstallDriver Table Manager service terminated unexpectedly. It has done this 1 time(s).
    3/16/2011 5:12:02 AM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\D.
    3/16/2011 10:08:41 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD AmdPPM aswRdr aswSnx aswSP aswTdi BANTExt Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL sptd Tcpip vsdatant
    3/16/2011 10:08:41 PM, error: Service Control Manager [7001] - The TrueVector Internet Monitor service depends on the vsdatant service which failed to start because of the following error: A device attached to the system is not functioning.
    3/16/2011 10:08:41 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
    3/16/2011 10:08:41 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    3/16/2011 10:08:41 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    3/16/2011 10:08:41 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    3/11/2011 8:20:10 AM, error: Service Control Manager [7034] - The NsEngine service terminated unexpectedly. It has done this 1 time(s).
    3/11/2011 8:19:56 AM, error: Service Control Manager [7034] - The COM+ System Application service terminated unexpectedly. It has done this 3 time(s).
    3/11/2011 8:19:46 AM, error: Service Control Manager [7031] - The COM+ System Application service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
    3/11/2011 8:19:25 AM, error: Service Control Manager [7034] - The MS Software Shadow Copy Provider service terminated unexpectedly. It has done this 1 time(s).
    3/11/2011 8:19:25 AM, error: Service Control Manager [7031] - The COM+ System Application service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
    3/11/2011 8:05:26 AM, error: Removable Storage Service [111] - RSM could not load media in drive Drive 0 of library Generic STORAGE DEVICE USB Device.
    3/11/2011 7:56:16 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Net.Tcp Port Sharing Service service to connect.
    3/11/2011 7:56:16 AM, error: Service Control Manager [7000] - The TomTomHOMEService service failed to start due to the following error: The system cannot find the path specified.
    3/11/2011 7:56:16 AM, error: Service Control Manager [7000] - The Net.Tcp Port Sharing Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    3/11/2011 7:50:56 AM, error: ati2mtag [45062] - CRT invalid display type
    3/11/2011 7:48:07 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    3/10/2011 9:43:42 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments " " in order to run the server: {000C101C-0000-0000-C000-000000000046}
    3/10/2011 9:38:54 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdPPM BANTExt Fips SASDIFSV SASKUTIL sptd
    3/10/2011 9:38:54 PM, error: Service Control Manager [7001] - The World Wide Web Publishing service depends on the IIS Admin service which failed to start because of the following error: The dependency service or group failed to start.
    3/10/2011 9:38:54 PM, error: Service Control Manager [7001] - The Simple Mail Transfer Protocol (SMTP) service depends on the IIS Admin service which failed to start because of the following error: The dependency service or group failed to start.
    3/10/2011 9:37:56 PM, error: sptd [4] - Driver detected an internal error in its data structures for .
    3/10/2011 9:27:40 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdPPM AvgLdx86 AvgMfx86 BANTExt Fips SASDIFSV SASKUTIL sptd
    3/10/2011 9:10:12 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdPPM AvgLdx86 AvgMfx86 BANTExt Cdr4_xp Fips SASDIFSV SASKUTIL sptd
    3/10/2011 8:50:39 PM, error: DCOM [10005] - DCOM got error "%1068" attempting to start the service IISADMIN with arguments " " in order to run the server: {A9E69610-B80D-11D0-B9B9-00A0C922E750}
    3/10/2011 6:15:21 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Cdr4_xp
    3/10/2011 5:11:08 AM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    3/10/2011 10:53:50 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments " " in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    3/10/2011 10:22:14 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments " " in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
    .
    ==== End Of File ===========================
    DSS.txt
    .
    DDS (Ver_11-03-05.01) - NTFSx86
    Run by Kerry at 23:34:50.08 on Wed 03/16/2011
    Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1466 [GMT -6:00]
    .
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: ZoneAlarm Pro Firewall *Disabled*
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
    C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
    E:\Program Files\seagate\seagatemanager\Sync\FreeAgentService.exe
    C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\BUFFALO\NASNAVI\nassvc.exe
    C:\Program Files\StompSoft\PC BackUp\NbkCtrl.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
    C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
    C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
    C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    C:\Program Files\AVAST Software\Avast\avastUI.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    C:\Program Files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe
    C:\Program Files\NewSoft\Presto! PageManager 8 for EP\PMSpeed.EXE
    C:\Program Files\StompSoft\PC BackUp\NMSAccess.exe
    C:\Program Files\StompSoft\PC BackUp\NSENGINE.exe
    C:\PROGRA~1\MICROS~4\rapimgr.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Windows Time Synchronizer\WinTimeSync.Exe
    C:\Program Files\Brownie\brstswnd.exe
    C:\Program Files\Brownie\brpjp04a.exe
    E:\Program Files\Mozilla Firefox\firefox.exe
    E:\firefox downloads\dds.scr
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = about:blank
    uSearch Bar = hxxp://www.google.com/ie
    uSearch Page = hxxp://www.bing.com/?pc=AVBR
    uWindow Title = Windows Internet Explorer provided by Comcast
    mStart Page = hxxp://www.comcast.net/
    mSearch Bar = hxxp://www.google.com/ie
    mWindow Title = Windows Internet Explorer provided by Comcast
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: FlashCatchBHO Class: {88618a96-6d8a-42e7-b932-9073d5b2080f} - c:\program files\flashcatch\flashcatch.dll
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
    BHO: {aa58ed58-01dd-4d91-8333-cf10577473f7} - Google Toolbar Helper
    BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
    TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} -
    TB: FlashCatch: {10cecf4f-a96e-4803-8ac2-f565fb29ff47} - c:\program files\flashcatch\flashcatch.dll
    TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    EB: Favorites Finderâ„¢: {656726dd-0b46-461e-860d-56de91c7db90} - c:\program files\favorites finder\FavoritesFinderBar.dll
    uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe "
    uRun: [cdloader] "c:\documents and settings\kerry\application data\mjusbsp\cdloader2.exe" MAGICJACK
    uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win
    uRun: [Gadwin PrintScreen Pro] c:\program files\gadwin systems\printscreenpro\PrintScreenPro.exe /nosplash
    uRun: [PMSpeed] c:\program files\newsoft\presto! pagemanager 8 for ep\PMSpeed.EXE
    uRun: [EPSON Artisan 810 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatifra.exe /fu "c:\windows\temp\E_S1D7E.tmp" /EF "HKCU "
    mRun: [NovaBackup 7 Tray Control] "c:\program files\stompsoft\pc backup\NbkCtrl.exe "
    mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime alternative\qttask.exe" -atboottime
    mRun: [WrtMon.exe] c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe
    mRun: [OneTouch Monitor] c:\program files\visioneer onetouch\OneTouchMon.exe
    mRun: [FUFAXSTM] "c:\program files\epson software\fax utility\FUFAXSTM.exe "
    mRun: [EEventManager] c:\progra~1\epsons~1\eventm~1\EEventManager.exe
    mRun: [ZoneAlarm Client] "e:\program files\zonealarm\zlclient.exe "
    mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
    StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Screen lock.cmd
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\taskmg~1.lnk - c:\windows\system32\taskmgr.exe
    mPolicies-system: LogonType = 0 (0x0)
    IE: CallClerk Dial - file://c:\documents and settings\kerry\application data\callclerk\callclerk.htm
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll
    IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll
    IE: {44226DFF-747E-4edc-B30C-78752E50CD0C} - {44226DFF-747E-4edc-B30C-78752E50CD0C} - c:\program files\ati multimedia\dtv\EXPLBAR.DLL
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
    Trusted Zone: eairlink.com
    Trusted Zone: eairlink.com\bwssd
    Trusted Zone: eairlink.com\jn12ms41
    Trusted Zone: lunarpages.com\almach
    Trusted Zone: microsoft.com\*.update
    Trusted Zone: ups.com
    Trusted Zone: windowsupdate.com\download
    DPF: {00000055-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/fhg.CAB
    DPF: {021E4485-E1A2-4204-8F61-147AC25089D4} - hxxp://192.168.0.24/UltraCamX.cab
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
    DPF: {108D3206-846A-4A93-BACB-F0572D043ED7} - hxxp://192.168.0.190/dvrweb.cab
    DPF: {14E35D5F-DEBA-4DB3-B2ED-17542BA12D1F} - hxxp://74.7.157.178/AV718.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
    DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} - hxxp://74.7.157.172/VatDec.cab
    DPF: {32C11E38-E587-4BE9-9ABB-D69158C21CE5} - hxxp://tigercam.eairlink.com:12345/activex/decoder/mpeg4_dec.cab
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} - hxxp://74.7.157.171/RtspVaPgDec.cab
    DPF: {3E278D18-99A7-4885-9C9A-8D1219D474F8} - hxxp://192.168.0.10:8777/program/SNCIntelligence.cab
    DPF: {45830FF9-D9E6-4F41-86ED-B266933D8E90} - hxxp://67.90.229.242/RtspVaPgDec.cab
    DPF: {49CD73D5-CBE2-4FAA-B70F-0252C74809AB} - hxxp://192.168.0.9:7227/classes/PLANETCamV.cab
    DPF: {5CB430A9-CAAC-4C91-AF61-6D410EEE1221} - hxxp://168.103.190.141/program/SonySncP5View.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1266003140090
    DPF: {673204A0-F8B3-4090-8506-80658C5D02C6} - hxxp://68.25.146.122:7227/nwcv3setup.exe
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258768524832
    DPF: {6E49B4EF-9FE5-44DF-8D04-445AA94F83DB} - hxxp://192.168.0.100/program/SonyNetworkCameraViewer.cab
    DPF: {7340F0E4-AEDA-47C6-8971-9DB314030BD7} - hxxp://166.130.99.76:12345/activex/decoder/h264_dec.cab
    DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://nexushawk.on-the-web.tv:8080/activex/AMC.cab
    DPF: {7B133798-FAA8-4A7E-950D-BEB35D3363AF} - hxxp://192.168.0.13/LinksysViewer.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {8D7AFAB7-42D6-4671-A53E-CD355673F026} - hxxp://192.168.0.155/SonySncMView.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {9F1C0B35-8230-4176-8B99-5C2485121A4E} - hxxp://192.168.0.10/program/SNCActiveXViewer.cab
    DPF: {9FCBA748-B8E5-460D-8B5F-E536BDA58A70} - hxxp://204.187.62.147:1024/program/SonyNetworkCameraViewer2.cab
    DPF: {A3D93B25-4601-49D2-B3AF-F447C73D561F} - hxxp://streetlight.eairlink.com:7227/program/SonySncRz25View.cab
    DPF: {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} - hxxp://192.168.0.126/codebase/DVM_IPCam2.ocx
    DPF: {A7D87345-E8F9-4B6D-837A-50D468DEC8FE} - hxxp://68.193.3.154:5735/H264Inst.cab
    DPF: {AC3FC1E2-26B3-46E5-8EC2-B1D5E4C90331} - hxxp://www.microseven.com/hrctech/front/CameraOCX.cab
    DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} - hxxp://dvr12722.dipmap.com/cab/OCXChecker_8120.cab
    DPF: {B8E53531-F29E-4180-AE3E-DF485CC8BE32} - hxxp://68.193.3.154:5735/JpegInstV4.cab
    DPF: {B9940246-4344-4D1B-BD82-DBAF7E657FF9} - hxxp://192.168.0.199/SysCamInst.cab
    DPF: {BA7A56EB-D1B9-443B-96E9-086532A378F1} - hxxp://192.168.0.100/activex/decoder/aac_dec.cab
    DPF: {C20E8541-3280-40DC-BC3E-D988F63CD907} - hxxp://192.168.0.13/adm/LinksysAlertCfg.cab
    DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://166.130.99.76:12345/activex/AMC.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {E3CF5F1B-C29E-4D21-B695-E1B0E1CB6EC9} - hxxp://63.147.165.151:7000/codebase/NewHCNetActiveX.cab
    DPF: {EF991872-9158-4570-A7FF-E7DBB6A4B8E9} - hxxp://democam6.iqeye.com/iqweb.ocx
    DPF: {F47E687B-551F-4043-89B3-F6E3F5DAD01E} - hxxp://122.116.137.123:29077/VDControl.CAB
    DPF: {FA478DB9-803F-4154-9DDB-765EA9E35333} - hxxp://152.3.125.165/program/SonySncP1View.cab
    DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
    DPF: {FE92D9C3-4A69-4EC7-8651-1DC8531D0075} - hxxp://68.15.12.110:8012/user/TSBnwCam.CAB
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - c:\program files\common files\g7ps\shared files\g7psdll\G7PS.dll
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
    Notify: AtiExtEvent - Ati2evxx.dll
    Notify: LMIinit - LMIinit.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    STS: {1984DD45-52CF-49cd-AB77-18F378FEA264} - No File
    SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File
    LSA: Notification Packages = :\windows\system32\srrst
    mASetup: ccc-core-static - msiexec /fums {3CBBEE47-C8F4-316A-92FF-ED7E3DFAE41E} /qb
    Hosts: 192.168.0.158 sony camera
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-10 371544]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-3-10 301528]
    R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2009-2-21 3968]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-3-10 19544]
    S3 FLASHSYS;FLASHSYS;c:\windows\system32\drivers\FlashSys.sys [2007-5-8 6912]
    .
    =============== Created Last 30 ================
    .
    2011-03-17 00:22:29 -------- d-----w- c:\docume~1\kerry\applic~1\Malwarebytes
    2011-03-17 00:22:18 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-03-17 00:22:17 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2011-03-17 00:22:11 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-03-17 00:22:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-03-16 23:28:09 -------- d-----w- c:\docume~1\alluse~1\applic~1\SecTaskMan
    2011-03-16 23:27:47 -------- d-----w- c:\program files\Security Task Manager
    2011-03-16 14:44:04 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
    2011-03-11 04:43:45 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-03-11 04:43:37 40648 ----a-w- c:\windows\avastSS.scr
    2011-03-11 04:43:33 -------- d-----w- c:\program files\AVAST Software
    2011-03-11 04:43:33 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVAST Software
    2011-03-10 09:47:33 -------- d-----w- C:\spoolerlogs
    2011-02-22 15:58:57 -------- d-----w- c:\docume~1\kerry\applic~1\org.youtorial.YoutorialDesktopSuite.5CAFF6D48BBB3E2215B4D4EF06B9C780F44150C1.1
    2011-02-22 15:58:33 -------- d-----w- c:\program files\Youtorial
    .
    ==================== Find3M ====================
    .
    2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
    2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
    2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
    2010-12-22 12:34:28 301568 ----a-w- c:\windows\system32\kerberos.dll
    2010-12-21 00:15:24 21648 ----a-w- c:\windows\system\CTL3DV2.DLL
    2010-12-20 23:08:45 832512 ----a-w- c:\windows\system32\wininet.dll
    2010-12-20 23:08:45 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-12-20 23:08:45 1830912 ------w- c:\windows\system32\inetcpl.cpl
    2010-12-20 23:08:45 17408 ----a-w- c:\windows\system32\corpol.dll
    2010-12-20 17:26:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
    2010-12-20 12:55:25 389120 ----a-w- c:\windows\system32\html.iec
    .
    =================== ROOTKIT ====================
    .
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: WDC_WD2000JS-60NCB1 rev.10.02E02 -> Harddisk0\DR0 -> \Device\0000008c
    .
    device: opened successfully
    user: MBR read successfully
    .
    Disk trace:
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89B2EAED]<<
    _asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; LEA EAX, [EBP+0x8]; MOV [EBP-0x4], EAX; CMP ESP, 0x52; JNZ 0x10; INC ECX; MOV EAX, [0x89baa630]; MOV ECX, [EBP+0x10]; CMP ECX, [EAX]; JBE 0x56; MOV EAX, [EBP+0x10]; }
    1 ntkrnlpa!IofCallDriver[0x804EE130] -> \Device\Harddisk0\DR0[0x8A791AB8]
    3 CLASSPNP[0xBA118FD7] -> ntkrnlpa!IofCallDriver[0x804EE130] -> \Device\0000008d[0x8A73AA78]
    5 ACPI[0xB9E74620] -> ntkrnlpa!IofCallDriver[0x804EE130] -> \Device\0000008b[0x8A791030]
    \Driver\nvatabus[0x8A7DD3E0] -> IRP_MJ_CREATE -> 0x8A8261F8
    kernel: MBR read successfully
    _asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
    user != kernel MBR !!!
    sectors 390721966 (+1): user != kernel
    Warning: possible TDL4 rootkit infection !
    TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
    .
    ============= FINISH: 23:37:46.11 ===============
    mbam-log-2011-03-16 (18-33-24).txt
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 6080

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 7.0.5730.13

    3/16/2011 6:33:24 PM
    mbam-log-2011-03-16 (18-33-24).txt

    Scan type: Quick scan
    Objects scanned: 238234
    Time elapsed: 7 minute(s), 31 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 11
    Registry Values Infected: 0
    Registry Data Items Infected: 4
    Folders Infected: 8
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogoff (PUM.Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\microsoft common (Trojan.Agent) -> Quarantined and deleted successfully.
    c:\program files\mywebsearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Files Infected:
    c:\WINDOWS\system32\f3PSSavr.scr (PUP.FunWebProducts) -> Quarantined and deleted successfully.
    c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Any assistance would be greatly appreciated.
    Kerry
     
  2. 2011/03/17
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Your Java is seriously out of date. Uninstall ALL of these, then install the latest version.


    A Malware expert will have a look at your log in due course.
     
    Arie,
    #2

  3. to hide this advert.

  4. 2011/03/17
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    ebay-c card and other re-directs, virus-root toolkits Part 2

    Java update. Thanks
    Part 2 of reports

    MBRCheck_03.16.11_23.33.16.txt
    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000107d

    Kernel Drivers (total 171):
    0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
    0x806D1000 \WINDOWS\system32\hal.dll
    0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
    0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
    0xB9EB4000 spyu.sys
    0xBA5AA000 \WINDOWS\System32\Drivers\WMILIB.SYS
    0xB9E9C000 \WINDOWS\System32\Drivers\SCSIPORT.SYS
    0xB9E6E000 ACPI.sys
    0xB9E5D000 pci.sys
    0xBA0A8000 ohci1394.sys
    0xBA0B8000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
    0xBA0C8000 isapnp.sys
    0xBA5AC000 avgarkt.sys
    0xBA4BC000 compbatt.sys
    0xBA4C0000 \WINDOWS\system32\DRIVERS\BATTC.SYS
    0xBA670000 PCIIde.sys
    0xBA328000 \WINDOWS\System32\Drivers\PCIIDEX.SYS
    0xBA0D8000 MountMgr.sys
    0xB9E3E000 ftdisk.sys
    0xBA5AE000 dmload.sys
    0xB9E18000 dmio.sys
    0xBA0E8000 sbp2port.sys
    0xBA330000 PartMgr.sys
    0xBA0F8000 VolSnap.sys
    0xB9E00000 atapi.sys
    0xB9DEA000 nvatabus.sys
    0xB9DB4000 Si3114r5.sys
    0xBA108000 disk.sys
    0xBA118000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xB9D94000 fltmgr.sys
    0xB9D82000 sr.sys
    0xBA4C4000 SiWinAcc.sys
    0xBA128000 PxHelp20.sys
    0xB9D6B000 KSecDD.sys
    0xB9CDE000 Ntfs.sys
    0xB9CB1000 NDIS.sys
    0xBA5B0000 SiRemFil.sys
    0xB9C97000 Mup.sys
    0xBA158000 \SystemRoot\system32\DRIVERS\nic1394.sys
    0xBA178000 \SystemRoot\system32\DRIVERS\AmdPPM.sys
    0xBA3D0000 \SystemRoot\system32\DRIVERS\usbohci.sys
    0xB82A3000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xBA3D8000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xB8071000 \SystemRoot\system32\drivers\ALCXWDM.SYS
    0xB804D000 \SystemRoot\system32\drivers\portcls.sys
    0xBA188000 \SystemRoot\system32\drivers\drmk.sys
    0xB802A000 \SystemRoot\system32\drivers\ks.sys
    0xBA198000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xBA1A8000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xB907C000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xBA3E0000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    0xB7F5C000 \SystemRoot\system32\DRIVERS\winachcf.sys
    0xBA3E8000 \SystemRoot\System32\Drivers\Modem.SYS
    0xB906C000 \SystemRoot\system32\DRIVERS\nvnetbus.sys
    0xB7E72000 \SystemRoot\system32\DRIVERS\NVNRM.SYS
    0xB7E2C000 \SystemRoot\system32\DRIVERS\yk51x86.sys
    0xB7A06000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
    0xB79F2000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xBA3F0000 \SystemRoot\system32\DRIVERS\fdc.sys
    0xB905C000 \SystemRoot\system32\DRIVERS\serial.sys
    0xBA550000 \SystemRoot\system32\DRIVERS\serenum.sys
    0xB79DE000 \SystemRoot\system32\DRIVERS\parport.sys
    0xB904C000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0xBA3F8000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xBA774000 \SystemRoot\system32\DRIVERS\lmimirr.sys
    0xBA775000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xB903C000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xB8E32000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xB79C7000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xB8357000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xB8347000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xBA400000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xB79B6000 \SystemRoot\system32\DRIVERS\psched.sys
    0xB8337000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xBA408000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xBA410000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xBA418000 \SystemRoot\system32\DRIVERS\wanatw4.sys
    0xB7986000 \SystemRoot\system32\DRIVERS\rdpdr.sys
    0xB8327000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xBA420000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xBA5DA000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xB7928000 \SystemRoot\system32\DRIVERS\update.sys
    0xB8E12000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xB78FC000 \SystemRoot\system32\drivers\windrvr6.sys
    0xBA1C8000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xBA1D8000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xBA5E6000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xBA5A4000 \SystemRoot\system32\drivers\MODEMCSA.sys
    0xBA358000 \SystemRoot\system32\DRIVERS\flpydisk.sys
    0xBA753000 \SystemRoot\System32\Drivers\Cdr4_xp.SYS
    0xBA754000 \SystemRoot\System32\Drivers\Cdralw2k.SYS
    0xBA368000 \??\C:\WINDOWS\system32\SAVRKBootTasks.sys
    0xBA62A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xBA755000 \SystemRoot\System32\Drivers\Null.SYS
    0xBA62C000 \SystemRoot\System32\Drivers\Beep.SYS
    0xBA757000 \SystemRoot\System32\DRIVERS\AvgArCln.sys
    0xBA370000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xBA378000 \SystemRoot\System32\drivers\vga.sys
    0xBA62E000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xBA630000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xA767D000 \SystemRoot\System32\Drivers\DVDVRRdr_xp.SYS
    0xBA380000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xBA388000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xA75EA000 \SystemRoot\System32\Drivers\UDFReadr.SYS
    0xB7890000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xA759D000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xA7544000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xBA308000 \SystemRoot\System32\Drivers\aswTdi.SYS
    0xA751C000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xBA390000 \SystemRoot\System32\Drivers\aswRdr.SYS
    0xA749C000 \SystemRoot\System32\vsdatant.sys
    0xA7476000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xBA318000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xBA168000 \SystemRoot\system32\DRIVERS\arp1394.sys
    0xA7454000 \SystemRoot\System32\drivers\afd.sys
    0xB6EA0000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xA7393000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
    0xBA398000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
    0xA5B20000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xA5AB0000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xB41BB000 \SystemRoot\System32\Drivers\Fips.SYS
    0xB6EBC000 \SystemRoot\system32\DRIVERS\usbscan.sys
    0xB6C77000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0xBA74C000 \SystemRoot\System32\Drivers\BANTExt.sys
    0xA4271000 \SystemRoot\System32\Drivers\aswSP.SYS
    0xA4213000 \SystemRoot\System32\Drivers\aswSnx.SYS
    0xBA360000 \SystemRoot\System32\Drivers\Aavmker4.SYS
    0xA18DC000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0x9E53F000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    0x9E250000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0xA18CC000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0x9E537000 \SystemRoot\system32\DRIVERS\usbprint.sys
    0xA75B0000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0xB6ED4000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0x9E52F000 \SystemRoot\system32\DRIVERS\HidBatt.sys
    0x9E037000 \SystemRoot\System32\Drivers\dump_nvatabus.sys
    0x9E73E000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xA63BE000 \SystemRoot\System32\drivers\Dxapi.sys
    0x9E527000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xBA69F000 \SystemRoot\System32\drivers\dxgthk.sys
    0xA63BA000 \SystemRoot\system32\DRIVERS\BdaSup.SYS
    0xBF012000 \SystemRoot\System32\ati2dvag.dll
    0xBF05F000 \SystemRoot\System32\ati2cqag.dll
    0xBF0DE000 \SystemRoot\System32\atikvmag.dll
    0xBF14E000 \SystemRoot\System32\atiok3x2.dll
    0xBF17C000 \SystemRoot\System32\ati3duag.dll
    0xBF484000 \SystemRoot\System32\ativvaxx.dll
    0x9BE13000 \SystemRoot\System32\Drivers\Fastfat.SYS
    0xBF633000 \SystemRoot\System32\ATMFD.DLL
    0xB6EB0000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
    0x9BDFD000 \SystemRoot\system32\DRIVERS\nwlnkipx.sys
    0xB82F7000 \SystemRoot\system32\DRIVERS\nwlnknb.sys
    0xBA58C000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0x9BCA6000 \SystemRoot\System32\Drivers\aswMon2.SYS
    0x9BBC9000 \SystemRoot\system32\drivers\wdmaud.sys
    0x9E0DC000 \SystemRoot\system32\drivers\sysaudio.sys
    0x9EE9A000 \SystemRoot\system32\DRIVERS\nwlnkspx.sys
    0x9B96C000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0xA7623000 \SystemRoot\System32\drivers\BrPar.sys
    0xBA5D6000 \SystemRoot\System32\Drivers\ParVdm.SYS
    0xA65C1000 \SystemRoot\System32\Drivers\ASCTRM.SYS
    0x9B847000 \SystemRoot\System32\Drivers\HTTP.sys
    0x9B52E000 \SystemRoot\system32\DRIVERS\srv.sys
    0x9ECA5000 \??\C:\Program Files\LogMeIn\x86\rainfo.sys
    0x9B5F6000 \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
    0x9B72F000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
    0xA7653000 \SystemRoot\System32\Drivers\TDTCP.SYS
    0x9A7A2000 \SystemRoot\System32\Drivers\RDPWD.SYS
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 52):
    0 System Idle Process
    4 System
    704 C:\WINDOWS\system32\smss.exe
    788 csrss.exe
    828 C:\WINDOWS\system32\winlogon.exe
    872 C:\WINDOWS\system32\services.exe
    884 C:\WINDOWS\system32\lsass.exe
    1040 C:\WINDOWS\system32\svchost.exe
    1188 svchost.exe
    1236 C:\WINDOWS\system32\svchost.exe
    1380 svchost.exe
    1532 svchost.exe
    1640 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    176 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    476 C:\WINDOWS\system32\spoolsv.exe
    1752 svchost.exe
    1152 C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
    1952 C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
    1980 C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
    2092 E:\Program Files\seagate\seagatemanager\Sync\FreeAgentService.exe
    2264 C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    2364 C:\WINDOWS\explorer.exe
    2388 C:\WINDOWS\system32\inetsrv\inetinfo.exe
    2468 C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
    2548 C:\Program Files\LogMeIn\x86\ramaint.exe
    2596 C:\Program Files\LogMeIn\x86\LogMeIn.exe
    2900 C:\Program Files\BUFFALO\NASNAVI\nassvc.exe
    3068 C:\Program Files\StompSoft\PC BackUp\NBKCTRL.exe
    3100 C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    3184 C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
    3196 C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
    3244 C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
    3316 C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
    3328 C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    3364 E:\Program Files\ZoneAlarm\zlclient.exe
    3384 C:\Program Files\AVAST Software\Avast\AvastUI.exe
    3416 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    3492 C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    3512 C:\Program Files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe
    3524 C:\Program Files\NewSoft\Presto! PageManager 8 for EP\PMSpeed.exe
    3536 C:\Program Files\StompSoft\PC BackUp\NMSAccess.exe
    3608 C:\Program Files\StompSoft\PC BackUp\NSENGINE.exe
    3640 C:\PROGRA~1\MICROS~4\rapimgr.exe
    3680 C:\WINDOWS\system32\taskmgr.exe
    3784 C:\WINDOWS\system32\svchost.exe
    3988 C:\Program Files\Windows Time Synchronizer\WinTimeSync.exe
    508 C:\Program Files\Brownie\BrStsWnd.exe
    1724 C:\Program Files\Brownie\brpjp04a.exe
    2796 C:\WINDOWS\system32\wuauclt.exe
    3768 alg.exe
    4624 E:\Program Files\Mozilla Firefox\firefox.exe
    5652 E:\firefox downloads\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
    \\.\E: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
    \\.\F: --> \\.\PhysicalDrive4 at offset 0x00000000`007e0000 (FAT32)

    PhysicalDrive0 Model Number: WDCWD2000JS-60NCB1, Rev: 10.02E02
    PhysicalDrive1 Model Number: WDCWD2000JS-60NCB1, Rev: 10.02E02
    PhysicalDrive4 Model Number: USB-HSWDC WD1600BB-22G, Rev: 0.01

    Size Device Name MBR Status
    --------------------------------------------
    186 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
    186 GB \\.\PhysicalDrive1 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
    149 GB \\.\PhysicalDrive4 RE: Windows 98 MBR code detected
    SHA1: 48F01D7E76A0F3C038D08611E3FDC0EE4EF9FD3E


    Done!



    gmar c drive log to txt.txt

    GMER 1.0.15.15530 - http://www.gmer.net
    Rootkit quick scan 2011-03-16 00:29:36
    Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\00000089 WDC_WD2000JS-60NCB1 rev.10.02E02
    Running: 59jk23ct.exe; Driver: C:\DOCUME~1\Kerry\LOCALS~1\Temp\pxtdipow.sys


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0x9E130026]
    SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0x9E12FE91]

    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
    Device \FileSystem\Ntfs \Ntfs 8A8921F8

    AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

    Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/AVAST Software)
    Device \FileSystem\Fastfat \Fat 8A189500

    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
    AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

    Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

    AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

    Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

    AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

    Device \Driver\Tcpip \Device\Udp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

    AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

    Device \Driver\Tcpip \Device\RawIp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

    AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

    ---- EOF - GMER 1.0.15 ----

    mbr.log
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: WDC_WD2000JS-60NCB1 rev.10.02E02 -> Harddisk0\DR0 -> \Device\0000008c

    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user != kernel MBR !!!
    sectors 390721966 (+1): user != kernel

    Thank you, Kerry.
     
  5. 2011/03/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard :)

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ================================================================

    You're infected with a rootkit.

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  6. 2011/03/17
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    after tddsskiller

    Thanks Smart. Hopefully it is gone now.

    2011/03/17 18:29:24.0764 3788 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
    2011/03/17 18:29:26.0766 3788 ================================================================================
    2011/03/17 18:29:26.0766 3788 SystemInfo:
    2011/03/17 18:29:26.0766 3788
    2011/03/17 18:29:26.0766 3788 OS Version: 5.1.2600 ServicePack: 3.0
    2011/03/17 18:29:26.0766 3788 Product type: Workstation
    2011/03/17 18:29:26.0766 3788 ComputerName: HOME
    2011/03/17 18:29:26.0766 3788 UserName: Kerry
    2011/03/17 18:29:26.0766 3788 Windows directory: C:\WINDOWS
    2011/03/17 18:29:26.0766 3788 System windows directory: C:\WINDOWS
    2011/03/17 18:29:26.0766 3788 Processor architecture: Intel x86
    2011/03/17 18:29:26.0766 3788 Number of processors: 1
    2011/03/17 18:29:26.0766 3788 Page size: 0x1000
    2011/03/17 18:29:26.0766 3788 Boot type: Normal boot
    2011/03/17 18:29:26.0766 3788 ================================================================================
    2011/03/17 18:29:29.0941 3788 Initialize success
    2011/03/17 18:29:37.0622 3912 ================================================================================
    2011/03/17 18:29:37.0622 3912 Scan started
    2011/03/17 18:29:37.0622 3912 Mode: Manual;
    2011/03/17 18:29:37.0622 3912 ================================================================================
    2011/03/17 18:29:38.0373 3912 Aavmker4 (83631291adf2887cffc786d034d3fa15) C:\WINDOWS\system32\drivers\Aavmker4.sys
    2011/03/17 18:29:39.0024 3912 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    2011/03/17 18:29:39.0305 3912 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
    2011/03/17 18:29:39.0495 3912 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
    2011/03/17 18:29:39.0655 3912 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
    2011/03/17 18:29:40.0416 3912 ALCXWDM (4e0aca5290b2966f24c45250a56c2da1) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
    2011/03/17 18:29:40.0767 3912 AmdPPM (033448d435e65c4bd72e70521fd05c76) C:\WINDOWS\system32\DRIVERS\AmdPPM.sys
    2011/03/17 18:29:40.0877 3912 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
    2011/03/17 18:29:41.0047 3912 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys
    2011/03/17 18:29:41.0137 3912 aswFsBlk (1c2e6bb4fe8621b1b863855b02bc33eb) C:\WINDOWS\system32\drivers\aswFsBlk.sys
    2011/03/17 18:29:41.0337 3912 aswMon2 (452d0ecd14fa02f9b061f42c8a30dd49) C:\WINDOWS\system32\drivers\aswMon2.sys
    2011/03/17 18:29:41.0408 3912 aswRdr (b6a9373619d851be80fb5f1b5eed0d4e) C:\WINDOWS\system32\drivers\aswRdr.sys
    2011/03/17 18:29:41.0448 3912 aswSnx (9be41c1ae8bc481eb662d85c98d979c2) C:\WINDOWS\system32\drivers\aswSnx.sys
    2011/03/17 18:29:41.0528 3912 aswSP (4b1a54ba2bc5873a774df6b70ab8b0b3) C:\WINDOWS\system32\drivers\aswSP.sys
    2011/03/17 18:29:41.0588 3912 aswTdi (c7f1cea32766184911293f4e1ee653f5) C:\WINDOWS\system32\drivers\aswTdi.sys
    2011/03/17 18:29:41.0638 3912 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    2011/03/17 18:29:41.0758 3912 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
    2011/03/17 18:29:42.0028 3912 ati2mtag (ed24215d4223c60989f02e196a1fff73) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
    2011/03/17 18:29:42.0119 3912 ATIAVAIW (e5a0af0af6021edbb48835a0702eaa48) C:\WINDOWS\system32\DRIVERS\atinavt2.sys
    2011/03/17 18:29:42.0249 3912 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    2011/03/17 18:29:42.0499 3912 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    2011/03/17 18:29:42.0589 3912 AVG Anti-Rootkit (e8054a423e5d2bdae6062bab6da159c4) C:\WINDOWS\system32\DRIVERS\avgarkt.sys
    2011/03/17 18:29:42.0609 3912 AvgArCln (ec08d1625f5c6cf2a57b79eb35186f8c) C:\WINDOWS\system32\DRIVERS\AvgArCln.sys
    2011/03/17 18:29:42.0659 3912 BANTExt (5d7be7b19e827125e016325334e58ff1) C:\WINDOWS\System32\Drivers\BANTExt.sys
    2011/03/17 18:29:42.0719 3912 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    2011/03/17 18:29:42.0800 3912 BrPar (2fe6d5be0629f706197b30c0aa05de30) C:\WINDOWS\System32\drivers\BrPar.sys
    2011/03/17 18:29:42.0910 3912 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    2011/03/17 18:29:42.0990 3912 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
    2011/03/17 18:29:43.0110 3912 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    2011/03/17 18:29:43.0130 3912 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
    2011/03/17 18:29:43.0190 3912 Cdr4_xp (9714b7c918c6543d69074ec101f86ac4) C:\WINDOWS\system32\drivers\Cdr4_xp.sys
    2011/03/17 18:29:43.0240 3912 Cdralw2k (0d856d16c08440bfb566d6cdd9948d4e) C:\WINDOWS\system32\drivers\Cdralw2k.sys
    2011/03/17 18:29:43.0300 3912 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    2011/03/17 18:29:43.0450 3912 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
    2011/03/17 18:29:43.0581 3912 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
    2011/03/17 18:29:43.0681 3912 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
    2011/03/17 18:29:43.0751 3912 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys
    2011/03/17 18:29:43.0781 3912 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    2011/03/17 18:29:43.0831 3912 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
    2011/03/17 18:29:43.0891 3912 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
    2011/03/17 18:29:43.0991 3912 DSXUSB (abc654a2e8afcf06c299bd990afa13aa) C:\WINDOWS\system32\DRIVERS\DSXUSB.sys
    2011/03/17 18:29:44.0041 3912 DVDVRRdr_xp (47cbf30c2e818ce0fd799b10fc6a3265) C:\WINDOWS\system32\drivers\DVDVRRdr_xp.sys
    2011/03/17 18:29:44.0121 3912 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
    2011/03/17 18:29:44.0151 3912 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
    2011/03/17 18:29:44.0272 3912 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
    2011/03/17 18:29:44.0352 3912 FLASHSYS (504cdaee963160c2690cb72cd4dfe195) C:\WINDOWS\system32\DRIVERS\FLASHSYS.sys
    2011/03/17 18:29:44.0422 3912 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    2011/03/17 18:29:44.0482 3912 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
    2011/03/17 18:29:44.0542 3912 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    2011/03/17 18:29:44.0622 3912 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    2011/03/17 18:29:44.0702 3912 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
    2011/03/17 18:29:44.0772 3912 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    2011/03/17 18:29:44.0802 3912 HidBatt (748031ff4fe45ccc47546294905feab8) C:\WINDOWS\system32\DRIVERS\HidBatt.sys
    2011/03/17 18:29:44.0842 3912 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    2011/03/17 18:29:44.0933 3912 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
    2011/03/17 18:29:44.0993 3912 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    2011/03/17 18:29:45.0033 3912 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
    2011/03/17 18:29:45.0153 3912 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
    2011/03/17 18:29:45.0213 3912 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    2011/03/17 18:29:45.0293 3912 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    2011/03/17 18:29:45.0353 3912 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    2011/03/17 18:29:45.0403 3912 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    2011/03/17 18:29:45.0453 3912 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
    2011/03/17 18:29:45.0503 3912 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    2011/03/17 18:29:45.0554 3912 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    2011/03/17 18:29:45.0574 3912 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
    2011/03/17 18:29:45.0604 3912 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
    2011/03/17 18:29:45.0644 3912 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
    2011/03/17 18:29:45.0904 3912 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\rainfo.sys
    2011/03/17 18:29:45.0974 3912 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys
    2011/03/17 18:29:46.0024 3912 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
    2011/03/17 18:29:46.0184 3912 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
    2011/03/17 18:29:46.0305 3912 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    2011/03/17 18:29:46.0355 3912 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
    2011/03/17 18:29:46.0385 3912 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
    2011/03/17 18:29:46.0435 3912 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    2011/03/17 18:29:46.0475 3912 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    2011/03/17 18:29:46.0525 3912 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
    2011/03/17 18:29:46.0575 3912 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys
    2011/03/17 18:29:46.0655 3912 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    2011/03/17 18:29:46.0745 3912 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    2011/03/17 18:29:46.0775 3912 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
    2011/03/17 18:29:46.0845 3912 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    2011/03/17 18:29:46.0875 3912 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
    2011/03/17 18:29:46.0935 3912 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    2011/03/17 18:29:46.0976 3912 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
    2011/03/17 18:29:46.0996 3912 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
    2011/03/17 18:29:47.0036 3912 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
    2011/03/17 18:29:47.0066 3912 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
    2011/03/17 18:29:47.0106 3912 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
    2011/03/17 18:29:47.0176 3912 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    2011/03/17 18:29:47.0246 3912 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    2011/03/17 18:29:47.0276 3912 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    2011/03/17 18:29:47.0346 3912 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
    2011/03/17 18:29:47.0406 3912 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
    2011/03/17 18:29:47.0456 3912 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
    2011/03/17 18:29:47.0526 3912 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
    2011/03/17 18:29:47.0576 3912 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
    2011/03/17 18:29:47.0647 3912 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
    2011/03/17 18:29:47.0747 3912 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    2011/03/17 18:29:47.0807 3912 nvatabus (e4f1f95a6bbbfbbff9a713c6063aa2cb) C:\WINDOWS\system32\DRIVERS\nvatabus.sys
    2011/03/17 18:29:47.0887 3912 NVENETFD (7d275ecda4628318912f6c945d5cf963) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
    2011/03/17 18:29:47.0917 3912 nvnetbus (b64aacefad2be5bff5353fe681253c67) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
    2011/03/17 18:29:47.0977 3912 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    2011/03/17 18:29:48.0007 3912 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    2011/03/17 18:29:48.0077 3912 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
    2011/03/17 18:29:48.0107 3912 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
    2011/03/17 18:29:48.0137 3912 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
    2011/03/17 18:29:48.0177 3912 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
    2011/03/17 18:29:48.0237 3912 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
    2011/03/17 18:29:48.0257 3912 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
    2011/03/17 18:29:48.0287 3912 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
    2011/03/17 18:29:48.0368 3912 PCASp50 (00ae175b903d45ed4a62384d3315dc2a) C:\WINDOWS\system32\Drivers\PCASp50.sys
    2011/03/17 18:29:48.0408 3912 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
    2011/03/17 18:29:48.0498 3912 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\drivers\PCIIde.sys
    2011/03/17 18:29:48.0558 3912 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
    2011/03/17 18:29:48.0808 3912 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    2011/03/17 18:29:48.0828 3912 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
    2011/03/17 18:29:48.0858 3912 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
    2011/03/17 18:29:48.0898 3912 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    2011/03/17 18:29:48.0968 3912 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
    2011/03/17 18:29:49.0119 3912 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    2011/03/17 18:29:49.0199 3912 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    2011/03/17 18:29:49.0239 3912 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    2011/03/17 18:29:49.0279 3912 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    2011/03/17 18:29:49.0349 3912 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    2011/03/17 18:29:49.0379 3912 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    2011/03/17 18:29:49.0409 3912 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
    2011/03/17 18:29:49.0479 3912 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
    2011/03/17 18:29:49.0509 3912 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
    2011/03/17 18:29:49.0579 3912 Revoflt (8b5b8a11306190c6963d3473f052d3c8) C:\WINDOWS\system32\DRIVERS\revoflt.sys
    2011/03/17 18:29:49.0750 3912 SASDIFSV (c030c9a39e85b6f04a8dd25d1a50258a) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
    2011/03/17 18:29:49.0800 3912 SASENUM (e9c2d75c748c3f0a4c34d6cf2ae1d754) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
    2011/03/17 18:29:49.0830 3912 SASKUTIL (64c100dbf57c6cb6e7d5d24153f5e444) C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
    2011/03/17 18:29:49.0900 3912 SAVRKBootTasks (0aef47e0a6b0cba8c9833d55298b2791) C:\WINDOWS\system32\SAVRKBootTasks.sys
    2011/03/17 18:29:49.0950 3912 sbp2port (b244960e5a1db8e9d5d17086de37c1e4) C:\WINDOWS\system32\DRIVERS\sbp2port.sys
    2011/03/17 18:29:50.0020 3912 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    2011/03/17 18:29:50.0050 3912 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
    2011/03/17 18:29:50.0070 3912 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
    2011/03/17 18:29:50.0120 3912 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
    2011/03/17 18:29:50.0190 3912 Si3114r5 (09889d435edc82435b18c7c311fe5721) C:\WINDOWS\system32\DRIVERS\Si3114r5.sys
    2011/03/17 18:29:50.0240 3912 SiFilter (46b92189fe4db53a09e3a0099aa3084c) C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys
    2011/03/17 18:29:50.0300 3912 SiRemFil (b688378d258d1ecce4768cdb55d48d92) C:\WINDOWS\system32\DRIVERS\SiRemFil.sys
    2011/03/17 18:29:50.0350 3912 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
    2011/03/17 18:29:50.0421 3912 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
    2011/03/17 18:29:50.0501 3912 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
    2011/03/17 18:29:50.0511 3912 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
    2011/03/17 18:29:50.0521 3912 sptd - detected Locked file (1)
    2011/03/17 18:29:50.0541 3912 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
    2011/03/17 18:29:50.0671 3912 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
    2011/03/17 18:29:50.0721 3912 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
    2011/03/17 18:29:50.0741 3912 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
    2011/03/17 18:29:50.0781 3912 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
    2011/03/17 18:29:50.0901 3912 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
    2011/03/17 18:29:51.0031 3912 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    2011/03/17 18:29:51.0071 3912 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
    2011/03/17 18:29:51.0091 3912 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
    2011/03/17 18:29:51.0122 3912 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
    2011/03/17 18:29:51.0232 3912 tunmp (8f861eda21c05857eb8197300a92501c) C:\WINDOWS\system32\DRIVERS\tunmp.sys
    2011/03/17 18:29:51.0292 3912 TVICHW32 (e266683fc95abdec17cd378564e1b54b) C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS
    2011/03/17 18:29:51.0372 3912 UDFReadr (e6bc5b364df5696b7888545b54a56ab7) C:\WINDOWS\system32\drivers\UDFReadr.sys
    2011/03/17 18:29:51.0472 3912 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
    2011/03/17 18:29:51.0582 3912 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
    2011/03/17 18:29:51.0692 3912 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
    2011/03/17 18:29:51.0772 3912 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
    2011/03/17 18:29:51.0833 3912 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    2011/03/17 18:29:51.0863 3912 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    2011/03/17 18:29:51.0913 3912 usbkey (5c0720235cd5a6495346befb72377076) C:\WINDOWS\system32\DRIVERS\USBKey.sys
    2011/03/17 18:29:51.0973 3912 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
    2011/03/17 18:29:51.0993 3912 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
    2011/03/17 18:29:52.0023 3912 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
    2011/03/17 18:29:52.0053 3912 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    2011/03/17 18:29:52.0083 3912 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys
    2011/03/17 18:29:52.0113 3912 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
    2011/03/17 18:29:52.0203 3912 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
    2011/03/17 18:29:52.0283 3912 vsdatant (7f10c6c385a03f40b07d682bfaa07e2f) C:\WINDOWS\system32\vsdatant.sys
    2011/03/17 18:29:52.0413 3912 vusbser (198b1a2308eae17cfc0d0b5c77936d68) C:\WINDOWS\system32\DRIVERS\vusbser.sys
    2011/03/17 18:29:52.0443 3912 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    2011/03/17 18:29:52.0504 3912 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
    2011/03/17 18:29:52.0564 3912 wceusbsh (46a247f6617526afe38b6f12f5512120) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
    2011/03/17 18:29:52.0634 3912 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
    2011/03/17 18:29:52.0724 3912 Winachcf (ddb6b2d33bb299664f1470ed4e83c389) C:\WINDOWS\system32\DRIVERS\winachcf.sys
    2011/03/17 18:29:52.0794 3912 WinDriver6 (8741604ecc3c006b7d2f769bf55dea9a) C:\WINDOWS\system32\drivers\windrvr6.sys
    2011/03/17 18:29:52.0904 3912 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
    2011/03/17 18:29:52.0954 3912 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    2011/03/17 18:29:52.0984 3912 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
    2011/03/17 18:29:53.0074 3912 yukonwxp (4322c32ced8c4772e039616dcbf01d3f) C:\WINDOWS\system32\DRIVERS\yk51x86.sys
    2011/03/17 18:29:53.0154 3912 \HardDisk1 - detected Backdoor.Win32.Sinowal.knf (0)
    2011/03/17 18:29:53.0235 3912 ================================================================================
    2011/03/17 18:29:53.0235 3912 Scan finished
    2011/03/17 18:29:53.0235 3912 ================================================================================
    2011/03/17 18:29:53.0255 4396 Detected object count: 2
    2011/03/17 18:30:55.0294 4396 Locked file(sptd) - User select action: Skip
    2011/03/17 18:30:55.0334 4396 \HardDisk1 (Backdoor.Win32.Sinowal.knf) - will be cured after reboot
    2011/03/17 18:30:55.0334 4396 \HardDisk1 - ok
    2011/03/17 18:30:55.0334 4396 Backdoor.Win32.Sinowal.knf(\HardDisk1) - User select action: Cure
    2011/03/17 18:31:22.0673 6128 Deinitialize success
     
  7. 2011/03/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very well :)

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  8. 2011/03/18
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    Broni, thanks for you help. I had to run this twice as the first time it lockup after rebooting in the combo cmd box; let it run over night but nothing. Second time it seemed to work fine. It also produce a combo log file that was longer than combofix.txt
    Kerry

    ComboFix 11-03-17.02 - Kerry 03/18/2011 5:25.2.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1522 [GMT -6:00]
    Running from: c:\documents and settings\Kerry\Desktop\reports\kerryComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: ZoneAlarm Pro Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ---- Previous Run -------
    .
    c:\documents and settings\All Users\ntuser.pol
    c:\documents and settings\Kerry\g2mdlhlpx.exe
    c:\documents and settings\Kerry\Local Settings\Application Data\{21B8AB5F-8A45-4EFC-889A-6E6C2FEBFFD8}
    c:\documents and settings\Kerry\Local Settings\Application Data\{21B8AB5F-8A45-4EFC-889A-6E6C2FEBFFD8}\chrome.manifest
    c:\documents and settings\Kerry\Local Settings\Application Data\{21B8AB5F-8A45-4EFC-889A-6E6C2FEBFFD8}\chrome\content\_cfg.js
    c:\documents and settings\Kerry\Local Settings\Application Data\{21B8AB5F-8A45-4EFC-889A-6E6C2FEBFFD8}\chrome\content\c.js
    c:\documents and settings\Kerry\Local Settings\Application Data\{21B8AB5F-8A45-4EFC-889A-6E6C2FEBFFD8}\chrome\content\overlay.xul
    c:\documents and settings\Kerry\Local Settings\Application Data\{21B8AB5F-8A45-4EFC-889A-6E6C2FEBFFD8}\install.rdf
    c:\documents and settings\Kerry\ntuser.pol
    C:\ErrLog.txt
    c:\program files\Internet Explorer\SETFFA.tmp
    C:\readme.txt
    c:\windows\Downloaded Program Files\Install.inf
    c:\windows\Downloaded Program Files\LiveView
    c:\windows\Downloaded Program Files\LiveView\disable.jpg
    c:\windows\Downloaded Program Files\LiveView\down.jpg
    c:\windows\Downloaded Program Files\LiveView\Logo.tif
    c:\windows\Downloaded Program Files\LiveView\mask.jpg
    c:\windows\Downloaded Program Files\LiveView\normal.jpg
    c:\windows\Downloaded Program Files\LiveView\over.jpg
    c:\windows\Downloaded Program Files\LiveView\skin.ini
    c:\windows\Downloaded Program Files\LiveView\Thumbs.db
    c:\windows\Downloaded Program Files\ODCTOOLS
    c:\windows\Downloaded Program Files\ODCTOOLS\ef6b26db-344d-4ad3-ba24-aca0bdaa999a.cab
    c:\windows\Downloaded Program Files\ODCTOOLS\f04d289f-c60a-422b-8396-6c372047042e.cab
    c:\windows\system32\4004614100.dat
    c:\windows\system32\Cache
    c:\windows\system32\CONFIG.exe
    c:\windows\system32\Hook.dll
    c:\windows\system32\Ijl11.dll
    c:\windows\system32\Packet.dll
    c:\windows\system32\player.dll
    c:\windows\system32\shdoclc.dll.old2
    c:\windows\system32\spool\prtprocs\w32x86\Ppbiproc.dll
    c:\windows\system32\uniq.tll
    c:\windows\system32\Update.exe
    c:\windows\system32\WanPacket.dll
    c:\windows\system32\wl.exe
    c:\windows\system32\wpcap.dll
    c:\windows\winhelp.ini
    E:\autorun.inf
    L:\autorun.inf
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Legacy_SCARDSVRSHAREDACCESS
    -------\Service_SCardSvrSharedAccess
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-02-18 to 2011-03-18 )))))))))))))))))))))))))))))))
    .
    .
    2011-03-17 15:46 . 2011-03-17 15:46 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-03-17 15:45 . 2011-03-17 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2011-03-17 00:22 . 2011-03-17 00:22 -------- d-----w- c:\documents and settings\Kerry\Application Data\Malwarebytes
    2011-03-17 00:22 . 2010-12-21 00:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-03-17 00:22 . 2011-03-17 00:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2011-03-17 00:22 . 2011-03-17 00:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-03-17 00:22 . 2010-12-21 00:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-03-16 23:28 . 2011-03-17 00:19 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan
    2011-03-16 23:27 . 2011-03-16 23:27 -------- d-----w- c:\program files\Security Task Manager
    2011-03-16 14:44 . 2010-05-26 17:45 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
    2011-03-11 04:43 . 2011-02-23 14:56 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2011-03-11 04:43 . 2011-02-23 14:54 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2011-03-11 04:43 . 2011-02-23 14:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-03-11 04:43 . 2011-02-23 14:55 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2011-03-11 04:43 . 2011-02-23 14:55 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2011-03-11 04:43 . 2011-02-23 14:55 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2011-03-11 04:43 . 2011-02-23 14:55 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2011-03-11 04:43 . 2011-02-23 14:54 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2011-03-11 04:43 . 2011-02-23 15:04 40648 ----a-w- c:\windows\avastSS.scr
    2011-03-11 04:43 . 2011-02-23 15:04 190016 ----a-w- c:\windows\system32\aswBoot.exe
    2011-03-11 04:43 . 2011-03-11 04:43 -------- d-----w- c:\program files\AVAST Software
    2011-03-11 04:43 . 2011-03-11 04:43 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
    2011-03-10 09:47 . 2011-03-10 09:47 -------- d-----w- C:\spoolerlogs
    2011-02-22 15:58 . 2011-02-22 15:58 -------- d-----w- c:\documents and settings\Kerry\Application Data\org.youtorial.YoutorialDesktopSuite.5CAFF6D48BBB3E2215B4D4EF06B9C780F44150C1.1
    2011-02-22 15:58 . 2011-02-22 15:58 -------- d-----w- c:\program files\Youtorial
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-03-17 15:46 . 2007-06-09 04:37 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-01-21 14:44 . 2004-08-04 12:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
    2011-01-07 14:09 . 2004-08-04 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
    2010-12-31 13:10 . 2004-08-04 12:00 1854976 ----a-w- c:\windows\system32\win32k.sys
    2010-12-22 12:34 . 2004-08-04 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
    2010-12-21 00:15 . 2010-12-21 00:15 21648 ----a-w- c:\windows\system\CTL3DV2.DLL
    2010-12-20 23:08 . 2004-08-04 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
    2010-12-20 23:08 . 2004-08-04 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-12-20 23:08 . 2004-08-04 12:00 1830912 ------w- c:\windows\system32\inetcpl.cpl
    2010-12-20 23:08 . 2004-08-04 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
    2010-12-20 17:26 . 2004-08-04 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
    2010-12-20 12:55 . 2004-08-04 12:00 389120 ----a-w- c:\windows\system32\html.iec
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @= "{472083B0-C522-11CF-8763-00608CC02F24} "
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2011-02-23 15:04 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "cdloader "= "c:\documents and settings\Kerry\Application Data\mjusbsp\cdloader2.exe" [2010-12-03 50592]
    "FreeRAM XP "= "c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 1591808]
    "Gadwin PrintScreen Pro "= "c:\program files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe" [2009-02-28 516096]
    "PMSpeed "= "c:\program files\NewSoft\Presto! PageManager 8 for EP\PMSpeed.EXE" [2008-12-09 55120]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NovaBackup 7 Tray Control "= "c:\program files\StompSoft\PC BackUp\NbkCtrl.exe" [2006-02-21 1204224]
    "LogMeIn GUI "= "c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 63048]
    "QuickTime Task "= "c:\program files\QuickTime Alternative\QTTask.exe" [2009-09-05 417792]
    "WrtMon.exe "= "c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2008-05-24 26448]
    "OneTouch Monitor "= "c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2002-09-24 86016]
    "FUFAXSTM "= "c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-02-06 843776]
    "EEventManager "= "c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-01-12 669520]
    "ZoneAlarm Client "= "e:\program files\ZoneAlarm\zlclient.exe" [2010-07-21 1038848]
    "avast "= "c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Screen lock.cmd [2008-9-10 159]
    taskmgr.exe.lnk - c:\windows\system32\taskmgr.exe [2004-8-4 135680]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "LogonType "= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 18:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
    2010-12-08 20:11 87424 ----a-w- c:\windows\system32\LMIinit.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0sprestrt\0sprestrt
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Device Detector 2.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Device Detector 2.lnk
    backup=c:\windows\pss\Device Detector 2.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DigiCell.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DigiCell.lnk
    backup=c:\windows\pss\DigiCell.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Screen lock.cmd]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Screen lock.cmd
    backup=c:\windows\pss\Screen lock.cmdCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Timex Data Link USB Launcher.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Timex Data Link USB Launcher.lnk
    backup=c:\windows\pss\Timex Data Link USB Launcher.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^BUFFALO NAS Navigator.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\BUFFALO NAS Navigator.lnk
    backup=c:\windows\pss\BUFFALO NAS Navigator.lnkStartup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^CallClerk.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\CallClerk.lnk
    backup=c:\windows\pss\CallClerk.lnkStartup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^Memeo AutoBackup Launcher.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\Memeo AutoBackup Launcher.lnk
    backup=c:\windows\pss\Memeo AutoBackup Launcher.lnkStartup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^NAS Scheduler.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\NAS Scheduler.lnk
    backup=c:\windows\pss\NAS Scheduler.lnkStartup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^PMB Media Check Tool.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\PMB Media Check Tool.lnk
    backup=c:\windows\pss\PMB Media Check Tool.lnkStartup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^VentaDrv.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\VentaDrv.lnk
    backup=c:\windows\pss\VentaDrv.lnkStartup
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Remote Control
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
    2008-11-06 11:42 50472 ------w- e:\aol 9.1\aol.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
    2010-03-18 17:19 207360 ------w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI DeviceDetect]
    2006-11-01 04:24 57344 ----a-w- c:\program files\ATI Multimedia\main\atidtct.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
    2006-11-01 04:27 102400 ----a-w- c:\program files\ATI Multimedia\main\LaunchPd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CardScanAgent]
    2008-08-28 01:30 152824 ------w- e:\program files\cardscan\CardScanAgent.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLSA]
    2010-10-24 00:54 1895889 ----a-w- e:\program files\Good Deal Software\Craigs Search Agent\search_agent.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
    2007-05-25 17:16 42032 ------w- c:\program files\Common Files\AOL\1174865921\EE\aolsoftware.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxMenuMgr]
    2009-09-26 06:31 185640 ------w- e:\program files\seagate\seagatemanager\FreeAgent Status\stxmenumgr.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ncr]
    2004-12-01 07:54 77824 ----a-w- c:\windows\SOUNDMAN.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProcessGovernor]
    2010-07-28 05:49 232464 ----a-w- c:\program files\Process Lasso\ProcessGovernor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProcessLassoManagementConsole]
    2010-07-28 05:49 417296 ----a-w- c:\program files\Process Lasso\ProcessLasso.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    2004-12-01 07:54 77824 ----a-w- c:\windows\SOUNDMAN.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    2006-11-10 19:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartupDelayer]
    2009-03-08 12:47 147456 ----a-w- c:\program files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2008-11-10 12:43 136600 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "WMPNetworkSvc "=3 (0x3)
    "ose "=2 (0x2)
    "MDM "=2 (0x2)
    "atnthost "=2 (0x2)
    "ATI Smart "=2 (0x2)
    "Ati HotKey Poller "=2 (0x2)
    "AOL ACS "=2 (0x2)
    "mnmsrvc "=3 (0x3)
    "Hawking_ST3402 "=3 (0x3)
    "JavaQuickStarterService "=2 (0x2)
    "iPod Service "=3 (0x3)
    "x10nets "=3 (0x3)
    "WebUpdate4 "=3 (0x3)
    "SQLWriter "=2 (0x2)
    "SCardSvrSharedAccess "=2 (0x2)
    "odserv "=2 (0x2)
    "MSSQLServerADHelper "=3 (0x3)
    "MSSQL$MSSMLBIZ "=3 (0x3)
    "avg9emc "=2 (0x2)
    "Apple Mobile Device "=3 (0x3)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring "=dword:00000001
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe "=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe "=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe "=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe "=
    "c:\\Program Files\\Common Files\\AOL\\1174865921\\EE\\AOLServiceHost.exe "=
    "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "f:\\aol 9 backup\\America Online 9.0\\waol.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "c:\program files\Microsoft ActiveSync\rapimgr.exe "= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "c:\program files\Microsoft ActiveSync\wcescomm.exe "= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "c:\program files\Microsoft ActiveSync\WCESMgr.exe "= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "c:\\Program Files\\Common Files\\AOL\\1174865921\\EE\\aolsoftware.exe "=
    "e:\\AOL 9.1\\waol.exe "=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe "=
    "c:\\Program Files\\Intelligent IP Installer\\IPCamManager.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "e:\\itunes\\iTunes.exe "=
    "c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe "=
    "c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe "=
    "c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe "=
    "c:\\Documents and Settings\\Kerry\\Application Data\\mjusbsp\\magicJack.exe "=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "1723:TCP "= 1723:TCP:mad:xpsp2res.dll,-22015
    "1701:UDP "= 1701:UDP:mad:xpsp2res.dll,-22016
    "500:UDP "= 500:UDP:mad:xpsp2res.dll,-22017
    "26675:TCP "= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
    "3389:TCP "= 3389:TCP:Remote Desktop
    "5985:TCP "= 5985:TCP:*:Disabled:Windows Remote Management
    "65533:TCP "= 65533:TCP:Services
    "52344:TCP "= 52344:TCP:Services
    "4965:TCP "= 4965:TCP:Services
    "8430:TCP "= 8430:TCP:Services
    "6629:TCP "= 6629:TCP:Services
    "6630:TCP "= 6630:TCP:Services
    "8269:TCP "= 8269:TCP:Services
    "8270:TCP "= 8270:TCP:Services
    "8960:TCP "= 8960:TCP:Services
    "8883:TCP "= 8883:TCP:Services
    "9701:TCP "= 9701:TCP:Services
    "8659:TCP "= 8659:TCP:Services
    "5167:TCP "= 5167:TCP:Services
    "7117:TCP "= 7117:TCP:Services
    "1620:TCP "= 1620:TCP:Services
    "8148:TCP "= 8148:TCP:Services
    "8149:TCP "= 8149:TCP:Services
    "2173:TCP "= 2173:TCP:Services
    "2886:TCP "= 2886:TCP:Services
    "8619:TCP "= 8619:TCP:Services
    "4697:TCP "= 4697:TCP:Services
    "8158:TCP "= 8158:TCP:Services
    "8159:TCP "= 8159:TCP:Services
    "7958:TCP "= 7958:TCP:Services
    "7006:TCP "= 7006:TCP:Services
    "7287:TCP "= 7287:TCP:Services
    "7288:TCP "= 7288:TCP:Services
    "6666:TCP "= 6666:TCP:Services
    "6686:TCP "= 6686:TCP:Services
    "5494:TCP "= 5494:TCP:Services
    "7526:TCP "= 7526:TCP:Services
    "9754:TCP "= 9754:TCP:Services
    "9755:TCP "= 9755:TCP:Services
    .
    R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2/16/2010 3:13 PM 691696]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [3/10/2011 10:43 PM 371544]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/10/2011 10:43 PM 301528]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2009 12:43 PM 8944]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2009 12:43 PM 55024]
    R1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [3/16/2011 8:44 AM 18816]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/10/2011 10:43 PM 19544]
    R2 FreeAgentGoNext Service;Seagate Service;e:\program files\seagate\seagatemanager\Sync\FreeAgentService.exe [9/26/2009 12:32 AM 189736]
    R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [10/1/2010 11:11 AM 374152]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [8/3/2007 4:09 PM 12856]
    R2 NasPmService;NAS PM Service;c:\program files\BUFFALO\NASNAVI\nassvc.exe -Service_Execute -dcyc=60 -dto=3 -dluc=0 -dmin=1 -dmax=60 -dflc=0 -apc=0 -log=0 -pm=1 -pall=1 -phttp=0 -pbc=0 -ppro=0 -pcyc=0 -pmin=1 -pmax=60 -pflc=0 --> c:\program files\BUFFALO\NASNAVI\nassvc.exe -Service_Execute -dcyc=60 -dto=3 -dluc=0 -dmin=1 -dmax=60 -dflc=0 -apc=0 -log=0 -pm=1 -pall=1 -phttp=0 -pbc=0 -ppro=0 -pcyc=0 -pmin=1 -pmax=60 -pflc=0 [?]
    R2 WinTimeSync;Windows Time Synchronizer;c:\program files\Windows Time Synchronizer\WinTimeSync.exe [3/13/2004 1:36 PM 1032192]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
    S2 TomTomHOMEService;TomTomHOMEService;j:\program files\TomTom HOME 2\TomTomHOMEService.exe --> j:\program files\TomTom HOME 2\TomTomHOMEService.exe [?]
    S3 FLASHSYS;FLASHSYS;c:\windows\system32\drivers\FlashSys.sys [5/8/2007 1:08 PM 6912]
    S3 LELMZ;LELMZ;c:\docume~1\Kerry\LOCALS~1\Temp\LELMZ.exe --> c:\docume~1\Kerry\LOCALS~1\Temp\LELMZ.exe [?]
    S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\8.tmp --> c:\windows\system32\8.tmp [?]
    S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [4/29/2010 10:22 AM 27064]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2009 12:43 PM 7408]
    S3 usbkey;USB Dongle;c:\windows\system32\drivers\usbkey.sys [1/4/2008 11:28 AM 40352]
    S3 vusbser;Rovio ARM-Based MCU driver;c:\windows\system32\drivers\vusbser.sys [12/19/2008 6:42 PM 30720]
    S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/4/2004 6:00 AM 14336]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
    S4 Hawking_ST3402;Hawking Management & Control Software Launcher;c:\program files\Hawking\Management & Control Software\Launcher_HAWK.exe [5/11/2005 3:04 PM 360448]
    S4 IPVision3.DirectorService;IPVision3.DirectorService; "c:\program files\IPVision Software\IPVision Security Information Manager\IPVision3.DirectorService.exe" --> c:\program files\IPVision Software\IPVision Security Information Manager\IPVision3.DirectorService.exe [?]
    S4 IPVision3.ProviderService;IPVision3.ProviderService; "c:\program files\IPVision Software\IPVision Security Information Manager\IPVision3.ProviderService.exe" --> c:\program files\IPVision Software\IPVision Security Information Manager\IPVision3.ProviderService.exe [?]
    S4 ViewCommander-NVR;ViewCommander-NVR;c:\program files\IVI\ViewCommander\Utilities\VCService\VCService.exe [1/4/2008 10:27 AM 65536]
    S4 WebUpdate4;Web Update Wizard Service V4;c:\windows\system32\WebUpdateSvc4.exe [9/15/2008 3:57 AM 262360]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    getPlusHelper REG_MULTI_SZ getPlusHelper
    WINRM REG_MULTI_SZ WINRM
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-03-17 c:\windows\Tasks\RegCure Program Check.job
    - c:\program files\RegCure\RegCure.exe [2010-04-29 18:43]
    .
    2011-03-18 c:\windows\Tasks\RegCure Startup.job
    - c:\program files\RegCure\RegCure.exe [2010-04-29 18:43]
    .
    2011-03-17 c:\windows\Tasks\RegCure.job
    - c:\program files\RegCure\RegCure.exe [2010-04-29 18:43]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    mStart Page = hxxp://www.comcast.net/
    mSearch Bar = hxxp://www.google.com/ie
    mWindow Title = Windows Internet Explorer provided by Comcast
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: CallClerk Dial - file://c:\documents and settings\Kerry\Application Data\CallClerk\callclerk.htm
    Trusted Zone: eairlink.com
    Trusted Zone: eairlink.com\bwssd
    Trusted Zone: eairlink.com\jn12ms41
    Trusted Zone: lunarpages.com\almach
    Trusted Zone: microsoft.com\*.update
    Trusted Zone: ups.com
    Trusted Zone: windowsupdate.com\download
    DPF: {021E4485-E1A2-4204-8F61-147AC25089D4} - hxxp://192.168.0.24/UltraCamX.cab
    DPF: {108D3206-846A-4A93-BACB-F0572D043ED7} - hxxp://192.168.0.190/dvrweb.cab
    DPF: {14E35D5F-DEBA-4DB3-B2ED-17542BA12D1F} - hxxp://74.7.157.178/AV718.cab
    DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} - hxxp://74.7.157.172/VatDec.cab
    DPF: {32C11E38-E587-4BE9-9ABB-D69158C21CE5} - hxxp://tigercam.eairlink.com:12345/activex/decoder/mpeg4_dec.cab
    DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} - hxxp://74.7.157.171/RtspVaPgDec.cab
    DPF: {3E278D18-99A7-4885-9C9A-8D1219D474F8} - hxxp://192.168.0.10:8777/program/SNCIntelligence.cab
    DPF: {45830FF9-D9E6-4F41-86ED-B266933D8E90} - hxxp://67.90.229.242/RtspVaPgDec.cab
    DPF: {49CD73D5-CBE2-4FAA-B70F-0252C74809AB} - hxxp://192.168.0.9:7227/classes/PLANETCamV.cab
    DPF: {5CB430A9-CAAC-4C91-AF61-6D410EEE1221} - hxxp://168.103.190.141/program/SonySncP5View.cab
    DPF: {673204A0-F8B3-4090-8506-80658C5D02C6} - hxxp://68.25.146.122:7227/nwcv3setup.exe
    DPF: {7340F0E4-AEDA-47C6-8971-9DB314030BD7} - hxxp://166.130.99.76:12345/activex/decoder/h264_dec.cab
    DPF: {7B133798-FAA8-4A7E-950D-BEB35D3363AF} - hxxp://192.168.0.13/LinksysViewer.cab
    DPF: {8D7AFAB7-42D6-4671-A53E-CD355673F026} - hxxp://192.168.0.155/SonySncMView.cab
    DPF: {9F1C0B35-8230-4176-8B99-5C2485121A4E} - hxxp://192.168.0.10/program/SNCActiveXViewer.cab
    DPF: {9FCBA748-B8E5-460D-8B5F-E536BDA58A70} - hxxp://204.187.62.147:1024/program/SonyNetworkCameraViewer2.cab
    DPF: {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} - hxxp://192.168.0.126/codebase/DVM_IPCam2.ocx
    DPF: {A7D87345-E8F9-4B6D-837A-50D468DEC8FE} - hxxp://68.193.3.154:5735/H264Inst.cab
    DPF: {AC3FC1E2-26B3-46E5-8EC2-B1D5E4C90331} - hxxp://www.microseven.com/hrctech/front/CameraOCX.cab
    DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} - hxxp://dvr12722.dipmap.com/cab/OCXChecker_8120.cab
    DPF: {B8E53531-F29E-4180-AE3E-DF485CC8BE32} - hxxp://68.193.3.154:5735/JpegInstV4.cab
    DPF: {BA7A56EB-D1B9-443B-96E9-086532A378F1} - hxxp://192.168.0.100/activex/decoder/aac_dec.cab
    DPF: {C20E8541-3280-40DC-BC3E-D988F63CD907} - hxxp://192.168.0.13/adm/LinksysAlertCfg.cab
    DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://166.130.99.76:12345/activex/AMC.cab
    DPF: {E3CF5F1B-C29E-4D21-B695-E1B0E1CB6EC9} - hxxp://63.147.165.151:7000/codebase/NewHCNetActiveX.cab
    DPF: {EF991872-9158-4570-A7FF-E7DBB6A4B8E9} - hxxp://democam6.iqeye.com/iqweb.ocx
    DPF: {F47E687B-551F-4043-89B3-F6E3F5DAD01E} - hxxp://122.116.137.123:29077/VDControl.CAB
    DPF: {FA478DB9-803F-4154-9DDB-765EA9E35333} - hxxp://152.3.125.165/program/SonySncP1View.cab
    DPF: {FE92D9C3-4A69-4EC7-8651-1DC8531D0075} - hxxp://68.15.12.110:8012/user/TSBnwCam.CAB
    .
    - - - - ORPHANS REMOVED - - - -
    .
    SharedTaskScheduler-{1984DD45-52CF-49cd-AB77-18F378FEA264} - (no file)
    ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
    MSConfigStartUp-ddoctorv2 - c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe
    MSConfigStartUp-TomTomHOME - j:\program files\TomTom HOME 2\TomTomHOMERunner.exe
    HKLM_ActiveSetup-ccc-core-static - msiexec
    AddRemove-HijackThis - c:\documents and settings\Kerry\Desktop\Utilities\HijackThis.exe
    AddRemove-TomTom HOME - j:\program files\TomTom HOME 2\Uninstall TomTom HOME.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-03-18 05:37
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: WDC_WD2000JS-60NCB1 rev.10.02E02 -> Harddisk0\DR0 -> \Device\0000008e
    .
    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user != kernel MBR !!!
    sectors 390721966 (+1): user != kernel
    .
    **************************************************************************
    .
    [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\MEMSWEEP2]
    "ImagePath "= "\??\c:\windows\system32\8.tmp "
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    [HKEY_USERS\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Microsoft\Windows\CurrentVersion\UnreadMail]
    @Denied: (Full) (Administrators)
    @Denied: (Full) (S-1-5-21-1935655697-1957994488-839522115-1003)
    .
    [HKEY_USERS\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Microsoft\Windows\CurrentVersion\UnreadMail\America Online - kkrich@aol.com]
    "MessageCount "=dword:0000000f
    "TimeStamp "=hex:70,fd,6a,7f,37,6f,c7,01
    "Application "= "\ "e:\\Program Files\\America Online 9.0a\\waol.exe\" -nkkrich -u\ "aol://1722:mailbox\" "
    .
    [HKEY_USERS\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (S-1-5-21-1935655697-1957994488-839522115-1003)
    @Allowed: (Read) (S-1-5-21-1935655697-1957994488-839522115-1003)
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @= "FlashBroker "
    "LocalizedString "= "@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @= "c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @= "IFlashBroker4 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @= "{00020424-0000-0000-C000-000000000046} "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    "Version "= "1.0 "
    .
    [HKEY_LOCAL_MACHINE\software\Xanthic\{EAC0842F-9764-03DD-A0B6-5FFFB48AD6EB}*_]
    "fr "= "078E797A5F5144 "
    "lr "= "078E7E625A514E "
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(820)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    c:\windows\system32\WININET.dll
    c:\windows\system32\Ati2evxx.dll
    c:\windows\system32\LMIinit.dll
    c:\windows\system32\LMIRfsClientNP.dll
    .
    - - - - - - - > 'explorer.exe'(536)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\LMIRfsClientNP.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2011-03-18 05:41:50
    ComboFix-quarantined-files.txt 2011-03-18 11:41
    .
    Pre-Run: 56,934,072,320 bytes free
    Post-Run: 56,875,917,312 bytes free
    .
    Current=3 Default=3 Failed=0 LastKnownGood=5 Sets=2,3,4,5
    - - End Of File - - 99CFC3BE42097675B6485B8CB9CCB68A
     
  9. 2011/03/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Uninstall RegCure.
    Registry cleaners/optimizers are not recommended for several reasons:

    • Registry cleaners are extremely powerful applications that can damage the registry by using aggressive cleaning routines and cause your computer to become unbootable.

      The Windows registry is a central repository (database) for storing configuration data, user settings and machine-dependent settings, and options for the operating system. It contains information and settings for all hardware, software, users, and preferences. Whenever a user makes changes to settings, file associations, system policies, or installed software, the changes are reflected and stored in this repository. The registry is a crucial component because it is where Windows "remembers" all this information, how it works together, how Windows boots the system and what files it uses when it does. The registry is also a vulnerable subsystem, in that relatively small changes done incorrectly can render the system inoperable. For a more detailed explanation, read Understanding The Registry.
    • Not all registry cleaners are created equal. There are a number of them available but they do not all work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad entry ". One cleaner may find entries on your system that will not cause problems when removed, another may not find the same entries, and still another may want to remove entries required for a program to work.
    • Not all registry cleaners create a backup of the registry before making changes. If the changes prevent the system from booting up, then there is no backup available to restore it in order to regain functionality. A backup of the registry is essential BEFORE making any changes to the registry.
    • Improperly removing registry entries can hamper malware disinfection and make the removal process more difficult if your computer becomes infected. For example, removing malware related registry entries before the infection is properly identified can contribute to system instability and even make the malware undetectable to removal tools.
    • The usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid, and erroneous entries does not affect system performance but it can result in "unpredictable results ".
    Unless you have a particular problem that requires a registry edit to correct it, I would suggest you leave the registry alone. Using registry cleaning tools unnecessarily or incorrectly could lead to disastrous effects on your operating system such as preventing it from ever starting again. For routine use, the benefits to your computer are negligible while the potential risks are great.


    ================================================================

    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\docume~1\Kerry\LOCALS~1\Temp\LELMZ.exe
    c:\windows\system32\8.tmp
    
    
    DDS::
    Trusted Zone: eairlink.com
    Trusted Zone: eairlink.com\bwssd
    Trusted Zone: eairlink.com\jn12ms41
    Trusted Zone: lunarpages.com\almach
    Trusted Zone: microsoft.com\*.update
    Trusted Zone: ups.com
    Trusted Zone: windowsupdate.com\download
    
    Driver::
    LELMZ
    MEMSWEEP2
    
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
     "DisableMonitoring "=dword:00000000
    [-HKEY_LOCAL_MACHINE\System\ControlSet003\Services\MEMSWEEP2]
    
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
     
  10. 2011/03/18
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    Broni,

    I am out of town until Monday evening or Tuesday morning. As soon as I get back I will follow your instructions.

    Have a great weekend.
     
  11. 2011/03/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No problem.
    Thank you for letting me know :)
     
  12. 2011/03/22
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    CFScript.txt ran

    Broni, I removed regcure. I copied and pasted what you said to into a file name CFScript.txt with notebook and saved it to my desktop. Closed firewall and Avast. The dragged CFScript.txt to combox. It ask to update and I said yes. It ran and after a few minutes an error box popped up stating something to the effect it can't save an rtf file but only txt. I clicked ok on that box and it appeared to finish. I searched all drives for combofix.txt by date and could not find it. I did find a couple of txt files that I had not seen before or maybe missed, but they were dberr.txt (23kb) and fwdbglog.txt(1kb, ZA log???). I don't know why but I opened the CFScript.txt file on my desktop and the contents had changed. Inside the CFScript.txt instead of what I had copied and pasted was this:

    {\rtf1\ansi\ansicpg1252\deff0\deflang1033{\fonttbl{\f0\fswiss\fcharset0 Arial;}}
    {\*\generator Msftedit 5.41.15.1515;}\viewkind4\uc1\pard\f0\fs20 File::\par
    c:\\docume~1\\Kerry\\LOCALS~1\\Temp\\LELMZ.exe\par
    c:\\windows\\system32\\8.tmp\par
    \par
    \par
    DDS::\par
    Trusted Zone: eairlink.com\par
    Trusted Zone: eairlink.com\\bwssd\par
    Trusted Zone: eairlink.com\\jn12ms41\par
    Trusted Zone: lunarpages.com\\almach\par
    Trusted Zone: microsoft.com\\*.update\par
    Trusted Zone: ups.com\par
    Trusted Zone: windowsupdate.com\\download\par
    \par
    Driver::\par
    LELMZ\par
    MEMSWEEP2\par
    \par
    \par
    Registry::\par
    [HKEY_LOCAL_MACHINE\\software\\microsoft\\security center\\Monitoring\\ZoneLabsFirewall]\par
    "DisableMonitoring "=dword:00000000\par
    [-HKEY_LOCAL_MACHINE\\System\\ControlSet003\\Services\\MEMSWEEP2]\par
    }


    I will wait until I have heard from you before I try a making a new CFScript.txt in notepad and running it again.

    Thank you, Kerry
     
  13. 2011/03/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Make sure, you use Notepad to create CFScript.txt.
    Simply redo instructions from my reply #8.
     
  14. 2011/03/23
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    I copied and pasted it again in notepad. This time when I drug it over, combofix started and asked to update and I clicked ok. After it updated, it restarted and ran. At the end it said to let combo reboot and not do it manually. Combfix rebooted the computer and at the windows splash screen combofix started a cmd box for combofix and it said "please wait" with a blinking curser. I let it run for a couple of hours and when nothing happened, I went to bed. This morning the combofix was still running in the cmd box and still saying please wait. At this point it had been well over 8 hours so I rebooted the computer. When windows loaded the combofix cmd box was gone. I check for combofix.txt and there was new file for it dated 3-22-11, time at 7:51 pm (that would be about the time that combfix rebooted last night after the second time running it). Below is the text of that file:

    ComboFix 11-03-22.04 - Kerry 03/22/2011 19:39:52.3.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1413 [GMT -6:00]
    Running from: C:\Documents and Settings\Kerry\Desktop\kerryComboFix.exe
    Command switches used :: C:\Documents and Settings\Kerry\Desktop\CFScript.txt
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: ZoneAlarm Pro Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

    FILE ::
    "c:\docume~1\Kerry\LOCALS~1\Temp\LELMZ.exe "
    "c:\windows\system32\8.tmp "

    Thanks, Kerry
     
  15. 2011/03/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Try one more time, please.
     
  16. 2011/03/23
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    Ok, I will try it again.

    Kerry
     
  17. 2011/03/23
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    CFScript.txt ran again

    Broni, I ran it again and this time there was no rebooting. Did get a no disk box pop up and I have that written down if you need it. Below is the text from combofix.txt:

    ComboFix 11-03-22.09 - Kerry 03/23/2011 11:09:07.4.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1529 [GMT -6:00]
    Running from: c:\documents and settings\Kerry\Desktop\kerryComboFix.exe
    Command switches used :: c:\documents and settings\Kerry\Desktop\CFScript.txt
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: ZoneAlarm Pro Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    .
    FILE ::
    "c:\docume~1\Kerry\LOCALS~1\Temp\LELMZ.exe "
    "c:\windows\system32\8.tmp "
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Legacy_LELMZ
    -------\Legacy_MEMSWEEP2
    -------\Service_LELMZ
    -------\Service_MEMSWEEP2
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-02-23 to 2011-03-23 )))))))))))))))))))))))))))))))
    .
    .
    2011-03-17 15:46 . 2011-03-17 15:46 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-03-17 15:45 . 2011-03-17 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2011-03-17 00:22 . 2011-03-17 00:22 -------- d-----w- c:\documents and settings\Kerry\Application Data\Malwarebytes
    2011-03-17 00:22 . 2010-12-21 00:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-03-17 00:22 . 2011-03-17 00:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2011-03-17 00:22 . 2011-03-17 00:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-03-17 00:22 . 2010-12-21 00:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-03-16 23:28 . 2011-03-17 00:19 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan
    2011-03-16 23:27 . 2011-03-16 23:27 -------- d-----w- c:\program files\Security Task Manager
    2011-03-16 14:44 . 2010-05-26 17:45 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
    2011-03-11 04:43 . 2011-02-23 14:56 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2011-03-11 04:43 . 2011-02-23 14:54 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2011-03-11 04:43 . 2011-02-23 14:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-03-11 04:43 . 2011-02-23 14:55 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2011-03-11 04:43 . 2011-02-23 14:55 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2011-03-11 04:43 . 2011-02-23 14:55 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2011-03-11 04:43 . 2011-02-23 14:55 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2011-03-11 04:43 . 2011-02-23 14:54 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2011-03-11 04:43 . 2011-02-23 15:04 40648 ----a-w- c:\windows\avastSS.scr
    2011-03-11 04:43 . 2011-02-23 15:04 190016 ----a-w- c:\windows\system32\aswBoot.exe
    2011-03-11 04:43 . 2011-03-11 04:43 -------- d-----w- c:\program files\AVAST Software
    2011-03-11 04:43 . 2011-03-11 04:43 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
    2011-03-10 09:47 . 2011-03-10 09:47 -------- d-----w- C:\spoolerlogs
    2011-02-22 15:58 . 2011-02-22 15:58 -------- d-----w- c:\documents and settings\Kerry\Application Data\org.youtorial.YoutorialDesktopSuite.5CAFF6D48BBB3E2215B4D4EF06B9C780F44150C1.1
    2011-02-22 15:58 . 2011-02-22 15:58 -------- d-----w- c:\program files\Youtorial
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-03-17 15:46 . 2007-06-09 04:37 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-01-21 14:44 . 2004-08-04 12:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
    2011-01-07 14:09 . 2004-08-04 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
    2010-12-31 13:10 . 2004-08-04 12:00 1854976 ----a-w- c:\windows\system32\win32k.sys
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2011-03-18_11.38.08 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2011-03-23 14:23 . 2011-03-23 14:23 16384 c:\windows\Temp\Perflib_Perfdata_688.dat
    + 2007-03-25 04:05 . 2011-03-23 14:39 4212 c:\windows\system32\zllictbl.dat
    - 2007-03-25 04:05 . 2011-03-18 05:15 4212 c:\windows\system32\zllictbl.dat
    + 2010-03-30 09:39 . 2011-03-23 14:27 226034 c:\windows\system32\inetsrv\MetaBase.bin
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @= "{472083B0-C522-11CF-8763-00608CC02F24} "
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2011-02-23 15:04 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "cdloader "= "c:\documents and settings\Kerry\Application Data\mjusbsp\cdloader2.exe" [2010-12-03 50592]
    "FreeRAM XP "= "c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 1591808]
    "Gadwin PrintScreen Pro "= "c:\program files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe" [2009-02-28 516096]
    "PMSpeed "= "c:\program files\NewSoft\Presto! PageManager 8 for EP\PMSpeed.EXE" [2008-12-09 55120]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NovaBackup 7 Tray Control "= "c:\program files\StompSoft\PC BackUp\NbkCtrl.exe" [2006-02-21 1204224]
    "LogMeIn GUI "= "c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 63048]
    "QuickTime Task "= "c:\program files\QuickTime Alternative\QTTask.exe" [2009-09-05 417792]
    "WrtMon.exe "= "c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2008-05-24 26448]
    "OneTouch Monitor "= "c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2002-09-24 86016]
    "FUFAXSTM "= "c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-02-06 843776]
    "EEventManager "= "c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-01-12 669520]
    "ZoneAlarm Client "= "e:\program files\ZoneAlarm\zlclient.exe" [2010-07-21 1038848]
    "avast "= "c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Screen lock.cmd [2008-9-10 159]
    taskmgr.exe.lnk - c:\windows\system32\taskmgr.exe [2004-8-4 135680]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "LogonType "= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 18:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
    2010-12-08 20:11 87424 ----a-w- c:\windows\system32\LMIinit.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0sprestrt\0sprestrt
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Device Detector 2.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Device Detector 2.lnk
    backup=c:\windows\pss\Device Detector 2.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DigiCell.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DigiCell.lnk
    backup=c:\windows\pss\DigiCell.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Screen lock.cmd]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Screen lock.cmd
    backup=c:\windows\pss\Screen lock.cmdCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Timex Data Link USB Launcher.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Timex Data Link USB Launcher.lnk
    backup=c:\windows\pss\Timex Data Link USB Launcher.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^BUFFALO NAS Navigator.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\BUFFALO NAS Navigator.lnk
    backup=c:\windows\pss\BUFFALO NAS Navigator.lnkStartup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^CallClerk.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\CallClerk.lnk
    backup=c:\windows\pss\CallClerk.lnkStartup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^Memeo AutoBackup Launcher.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\Memeo AutoBackup Launcher.lnk
    backup=c:\windows\pss\Memeo AutoBackup Launcher.lnkStartup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^NAS Scheduler.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\NAS Scheduler.lnk
    backup=c:\windows\pss\NAS Scheduler.lnkStartup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^PMB Media Check Tool.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\PMB Media Check Tool.lnk
    backup=c:\windows\pss\PMB Media Check Tool.lnkStartup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Kerry^Start Menu^Programs^Startup^VentaDrv.lnk]
    path=c:\documents and settings\Kerry\Start Menu\Programs\Startup\VentaDrv.lnk
    backup=c:\windows\pss\VentaDrv.lnkStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
    2008-11-06 11:42 50472 ------w- e:\aol 9.1\aol.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
    2010-03-18 17:19 207360 ------w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI DeviceDetect]
    2006-11-01 04:24 57344 ----a-w- c:\program files\ATI Multimedia\main\atidtct.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
    2006-11-01 04:27 102400 ----a-w- c:\program files\ATI Multimedia\main\LaunchPd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CardScanAgent]
    2008-08-28 01:30 152824 ------w- e:\program files\cardscan\CardScanAgent.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLSA]
    2010-10-24 00:54 1895889 ----a-w- e:\program files\Good Deal Software\Craigs Search Agent\search_agent.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
    2007-05-25 17:16 42032 ------w- c:\program files\Common Files\AOL\1174865921\EE\aolsoftware.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxMenuMgr]
    2009-09-26 06:31 185640 ------w- e:\program files\seagate\seagatemanager\FreeAgent Status\stxmenumgr.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ncr]
    2004-12-01 07:54 77824 ----a-w- c:\windows\SOUNDMAN.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProcessGovernor]
    2010-07-28 05:49 232464 ----a-w- c:\program files\Process Lasso\ProcessGovernor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProcessLassoManagementConsole]
    2010-07-28 05:49 417296 ----a-w- c:\program files\Process Lasso\ProcessLasso.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    2004-12-01 07:54 77824 ----a-w- c:\windows\SOUNDMAN.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    2006-11-10 19:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartupDelayer]
    2009-03-08 12:47 147456 ----a-w- c:\program files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2008-11-10 12:43 136600 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "WMPNetworkSvc "=3 (0x3)
    "ose "=2 (0x2)
    "MDM "=2 (0x2)
    "atnthost "=2 (0x2)
    "ATI Smart "=2 (0x2)
    "Ati HotKey Poller "=2 (0x2)
    "AOL ACS "=2 (0x2)
    "mnmsrvc "=3 (0x3)
    "Hawking_ST3402 "=3 (0x3)
    "JavaQuickStarterService "=2 (0x2)
    "iPod Service "=3 (0x3)
    "x10nets "=3 (0x3)
    "WebUpdate4 "=3 (0x3)
    "SQLWriter "=2 (0x2)
    "SCardSvrSharedAccess "=2 (0x2)
    "odserv "=2 (0x2)
    "MSSQLServerADHelper "=3 (0x3)
    "MSSQL$MSSMLBIZ "=3 (0x3)
    "avg9emc "=2 (0x2)
    "Apple Mobile Device "=3 (0x3)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe "=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe "=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe "=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe "=
    "c:\\Program Files\\Common Files\\AOL\\1174865921\\EE\\AOLServiceHost.exe "=
    "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "f:\\aol 9 backup\\America Online 9.0\\waol.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "c:\program files\Microsoft ActiveSync\rapimgr.exe "= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "c:\program files\Microsoft ActiveSync\wcescomm.exe "= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "c:\program files\Microsoft ActiveSync\WCESMgr.exe "= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "c:\\Program Files\\Common Files\\AOL\\1174865921\\EE\\aolsoftware.exe "=
    "e:\\AOL 9.1\\waol.exe "=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe "=
    "c:\\Program Files\\Intelligent IP Installer\\IPCamManager.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "e:\\itunes\\iTunes.exe "=
    "c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe "=
    "c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe "=
    "c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe "=
    "c:\\Documents and Settings\\Kerry\\Application Data\\mjusbsp\\magicJack.exe "=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "1723:TCP "= 1723:TCP:mad:xpsp2res.dll,-22015
    "1701:UDP "= 1701:UDP:mad:xpsp2res.dll,-22016
    "500:UDP "= 500:UDP:mad:xpsp2res.dll,-22017
    "26675:TCP "= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
    "3389:TCP "= 3389:TCP:Remote Desktop
    "5985:TCP "= 5985:TCP:*:Disabled:Windows Remote Management
    "65533:TCP "= 65533:TCP:Services
    "52344:TCP "= 52344:TCP:Services
    "4965:TCP "= 4965:TCP:Services
    "8430:TCP "= 8430:TCP:Services
    "6629:TCP "= 6629:TCP:Services
    "6630:TCP "= 6630:TCP:Services
    "8269:TCP "= 8269:TCP:Services
    "8270:TCP "= 8270:TCP:Services
    "8960:TCP "= 8960:TCP:Services
    "8883:TCP "= 8883:TCP:Services
    "9701:TCP "= 9701:TCP:Services
    "8659:TCP "= 8659:TCP:Services
    "5167:TCP "= 5167:TCP:Services
    "7117:TCP "= 7117:TCP:Services
    "1620:TCP "= 1620:TCP:Services
    "8148:TCP "= 8148:TCP:Services
    "8149:TCP "= 8149:TCP:Services
    "2173:TCP "= 2173:TCP:Services
    "2886:TCP "= 2886:TCP:Services
    "8619:TCP "= 8619:TCP:Services
    "4697:TCP "= 4697:TCP:Services
    "8158:TCP "= 8158:TCP:Services
    "8159:TCP "= 8159:TCP:Services
    "7958:TCP "= 7958:TCP:Services
    "7006:TCP "= 7006:TCP:Services
    "7287:TCP "= 7287:TCP:Services
    "7288:TCP "= 7288:TCP:Services
    "6666:TCP "= 6666:TCP:Services
    "6686:TCP "= 6686:TCP:Services
    "5494:TCP "= 5494:TCP:Services
    "7526:TCP "= 7526:TCP:Services
    "9754:TCP "= 9754:TCP:Services
    "9755:TCP "= 9755:TCP:Services
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 TomTomHOMEService;TomTomHOMEService;j:\program files\TomTom HOME 2\TomTomHOMEService.exe [x]
    R3 FLASHSYS;FLASHSYS;c:\windows\system32\DRIVERS\FLASHSYS.sys [2006-11-02 6912]
    R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [2009-12-30 27064]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
    R3 usbkey;USB Dongle;c:\windows\system32\DRIVERS\USBKey.sys [2008-07-13 40352]
    R3 vusbser;Rovio ARM-Based MCU driver;c:\windows\system32\DRIVERS\vusbser.sys [2008-12-20 30720]
    R3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe [2008-04-14 14336]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    R4 Hawking_ST3402;Hawking Management & Control Software Launcher;c:\program files\Hawking\Management & Control Software\Launcher_HAWK.exe [2005-05-11 360448]
    R4 IPVision3.DirectorService;IPVision3.DirectorService;c:\program files\IPVision Software\IPVision Security Information Manager\IPVision3.DirectorService.exe [x]
    R4 IPVision3.ProviderService;IPVision3.ProviderService;c:\program files\IPVision Software\IPVision Security Information Manager\IPVision3.ProviderService.exe [x]
    R4 ViewCommander-NVR;ViewCommander-NVR;c:\program files\IVI\ViewCommander\Utilities\VCService\VCService.exe [2008-01-04 65536]
    R4 WebUpdate4;Web Update Wizard Service V4;c:\windows\system32\WebUpdateSvc4.exe [2008-09-15 262360]
    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-16 691696]
    S1 aswSnx;aswSnx; [x]
    S1 aswSP;aswSP; [x]
    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-02-17 8944]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-02-17 55024]
    S1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [2010-05-26 18816]
    S2 aswFsBlk;aswFsBlk; [x]
    S2 FreeAgentGoNext Service;Seagate Service;e:\program files\seagate\seagatemanager\Sync\FreeAgentService.exe [2009-09-26 189736]
    S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [2010-12-08 374152]
    S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [2008-02-28 12856]
    S2 NasPmService;NAS PM Service;c:\program files\BUFFALO\NASNAVI\nassvc.exe [2009-05-15 251184]
    S2 WinTimeSync;Windows Time Synchronizer;c:\program files\Windows Time Synchronizer\WinTimeSync.Exe [2004-03-13 1032192]
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    getPlusHelper REG_MULTI_SZ getPlusHelper
    WINRM REG_MULTI_SZ WINRM
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    mStart Page = hxxp://www.comcast.net/
    mSearch Bar = hxxp://www.google.com/ie
    mWindow Title = Windows Internet Explorer provided by Comcast
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: CallClerk Dial - file://c:\documents and settings\Kerry\Application Data\CallClerk\callclerk.htm
    DPF: {021E4485-E1A2-4204-8F61-147AC25089D4} - hxxp://192.168.0.24/UltraCamX.cab
    DPF: {108D3206-846A-4A93-BACB-F0572D043ED7} - hxxp://192.168.0.190/dvrweb.cab
    DPF: {14E35D5F-DEBA-4DB3-B2ED-17542BA12D1F} - hxxp://74.7.157.178/AV718.cab
    DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} - hxxp://74.7.157.172/VatDec.cab
    DPF: {32C11E38-E587-4BE9-9ABB-D69158C21CE5} - hxxp://tigercam.eairlink.com:12345/activex/decoder/mpeg4_dec.cab
    DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} - hxxp://74.7.157.171/RtspVaPgDec.cab
    DPF: {3E278D18-99A7-4885-9C9A-8D1219D474F8} - hxxp://192.168.0.10:8777/program/SNCIntelligence.cab
    DPF: {45830FF9-D9E6-4F41-86ED-B266933D8E90} - hxxp://67.90.229.242/RtspVaPgDec.cab
    DPF: {49CD73D5-CBE2-4FAA-B70F-0252C74809AB} - hxxp://192.168.0.9:7227/classes/PLANETCamV.cab
    DPF: {5CB430A9-CAAC-4C91-AF61-6D410EEE1221} - hxxp://168.103.190.141/program/SonySncP5View.cab
    DPF: {673204A0-F8B3-4090-8506-80658C5D02C6} - hxxp://68.25.146.122:7227/nwcv3setup.exe
    DPF: {7340F0E4-AEDA-47C6-8971-9DB314030BD7} - hxxp://166.130.99.76:12345/activex/decoder/h264_dec.cab
    DPF: {7B133798-FAA8-4A7E-950D-BEB35D3363AF} - hxxp://192.168.0.13/LinksysViewer.cab
    DPF: {8D7AFAB7-42D6-4671-A53E-CD355673F026} - hxxp://192.168.0.155/SonySncMView.cab
    DPF: {9F1C0B35-8230-4176-8B99-5C2485121A4E} - hxxp://192.168.0.10/program/SNCActiveXViewer.cab
    DPF: {9FCBA748-B8E5-460D-8B5F-E536BDA58A70} - hxxp://204.187.62.147:1024/program/SonyNetworkCameraViewer2.cab
    DPF: {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} - hxxp://192.168.0.126/codebase/DVM_IPCam2.ocx
    DPF: {A7D87345-E8F9-4B6D-837A-50D468DEC8FE} - hxxp://68.193.3.154:5735/H264Inst.cab
    DPF: {AC3FC1E2-26B3-46E5-8EC2-B1D5E4C90331} - hxxp://www.microseven.com/hrctech/front/CameraOCX.cab
    DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} - hxxp://dvr12722.dipmap.com/cab/OCXChecker_8120.cab
    DPF: {B8E53531-F29E-4180-AE3E-DF485CC8BE32} - hxxp://68.193.3.154:5735/JpegInstV4.cab
    DPF: {BA7A56EB-D1B9-443B-96E9-086532A378F1} - hxxp://192.168.0.100/activex/decoder/aac_dec.cab
    DPF: {C20E8541-3280-40DC-BC3E-D988F63CD907} - hxxp://192.168.0.13/adm/LinksysAlertCfg.cab
    DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://166.130.99.76:12345/activex/AMC.cab
    DPF: {E3CF5F1B-C29E-4D21-B695-E1B0E1CB6EC9} - hxxp://63.147.165.151:7000/codebase/NewHCNetActiveX.cab
    DPF: {EF991872-9158-4570-A7FF-E7DBB6A4B8E9} - hxxp://democam6.iqeye.com/iqweb.ocx
    DPF: {F47E687B-551F-4043-89B3-F6E3F5DAD01E} - hxxp://122.116.137.123:29077/VDControl.CAB
    DPF: {FA478DB9-803F-4154-9DDB-765EA9E35333} - hxxp://152.3.125.165/program/SonySncP1View.cab
    DPF: {FE92D9C3-4A69-4EC7-8651-1DC8531D0075} - hxxp://68.15.12.110:8012/user/TSBnwCam.CAB
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-03-23 11:19
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: WDC_WD2000JS-60NCB1 rev.10.02E02 -> Harddisk0\DR0 -> \Device\0000008e
    .
    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user != kernel MBR !!!
    sectors 390721966 (+1): user != kernel
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    [HKEY_USERS\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Microsoft\Windows\CurrentVersion\UnreadMail]
    @Denied: (Full) (Administrators)
    @Denied: (Full) (S-1-5-21-1935655697-1957994488-839522115-1003)
    .
    [HKEY_USERS\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Microsoft\Windows\CurrentVersion\UnreadMail\America Online - kkrich@aol.com]
    "MessageCount "=dword:0000000f
    "TimeStamp "=hex:70,fd,6a,7f,37,6f,c7,01
    "Application "= "\ "e:\\Program Files\\America Online 9.0a\\waol.exe\" -nkkrich -u\ "aol://1722:mailbox\" "
    .
    [HKEY_USERS\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (S-1-5-21-1935655697-1957994488-839522115-1003)
    @Allowed: (Read) (S-1-5-21-1935655697-1957994488-839522115-1003)
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @= "FlashBroker "
    "LocalizedString "= "@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @= "c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @= "IFlashBroker4 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @= "{00020424-0000-0000-C000-000000000046} "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    "Version "= "1.0 "
    .
    [HKEY_LOCAL_MACHINE\software\Xanthic\{EAC0842F-9764-03DD-A0B6-5FFFB48AD6EB}*_]
    "fr "= "078E797A5F5144 "
    "lr "= "078E7E625A514E "
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(820)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    c:\windows\system32\WININET.dll
    c:\windows\system32\Ati2evxx.dll
    c:\windows\system32\LMIinit.dll
    c:\windows\system32\LMIRfsClientNP.dll
    .
    - - - - - - - > 'explorer.exe'(1824)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\LMIRfsClientNP.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2011-03-23 11:24:31
    ComboFix-quarantined-files.txt 2011-03-23 17:24
    ComboFix2.txt 2011-03-18 11:41
    .
    Pre-Run: 54,369,001,472 bytes free
    Post-Run: 54,340,337,664 bytes free
    .
    Current=3 Default=3 Failed=0 LastKnownGood=5 Sets=2,3,4,5
    - - End Of File - - CE06AF0FB5B17A9713F825FD27E3867E

    Thank you, Kerry
     
  18. 2011/03/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good :)

    How are the issues?

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  19. 2011/03/23
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    otl ran, otl.txt info part one

    Broni, popup again for windows no disk box, 30 times, click try again once but had to click on "continue button" but seem to work. I hadn't noticed before but I have 2 SATA drives that are missing. Will check bios when this is all done. otl.txt. Posting to large, I have to do it in 2 posts.

    OTL logfile created on: 3/23/2011 12:19:10 PM - Run 1
    OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Kerry\Desktop
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 7.0.5730.13)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
    4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
    Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 186.30 Gb Total Space | 50.58 Gb Free Space | 27.15% Space Free | Partition Type: NTFS
    Drive E: | 186.31 Gb Total Space | 47.33 Gb Free Space | 25.40% Space Free | Partition Type: NTFS
    Drive F: | 149.00 Gb Total Space | 73.52 Gb Free Space | 49.34% Space Free | Partition Type: FAT32
    Drive G: | 249.72 Mb Total Space | 37.19 Mb Free Space | 14.89% Space Free | Partition Type: FAT
    Drive Z: | 917.07 Gb Total Space | 578.25 Gb Free Space | 63.05% Space Free | Partition Type: NTFS

    Computer Name: HOME | User Name: Kerry | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2011/03/23 12:05:04 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kerry\Desktop\OTL.exe
    PRC - [2011/02/23 09:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
    PRC - [2011/02/23 09:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    PRC - [2010/12/08 14:11:38 | 000,136,584 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe
    PRC - [2010/12/08 14:11:32 | 000,374,152 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
    PRC - [2010/11/08 13:04:18 | 000,390,528 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
    PRC - [2010/07/20 21:24:38 | 002,434,568 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    PRC - [2010/07/20 21:22:56 | 001,038,848 | ---- | M] (Check Point Software Technologies LTD) -- E:\Program Files\ZoneAlarm\zlclient.exe
    PRC - [2009/09/26 00:32:18 | 000,189,736 | ---- | M] (Seagate Technology LLC) -- E:\Program Files\seagate\seagatemanager\Sync\FreeAgentService.exe
    PRC - [2009/05/15 04:36:50 | 000,251,184 | R--- | M] (BUFFALO INC.) -- C:\Program Files\BUFFALO\NASNAVI\nassvc.exe
    PRC - [2009/02/28 11:39:04 | 000,516,096 | ---- | M] (Gadwin Systems, Inc) -- C:\Program Files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe
    PRC - [2009/02/06 01:00:00 | 000,843,776 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
    PRC - [2008/12/09 10:32:06 | 000,055,120 | ---- | M] (NewSoft Technology Corporation) -- C:\Program Files\NewSoft\Presto! PageManager 8 for EP\PMSpeed.exe
    PRC - [2008/11/03 16:21:18 | 000,030,544 | ---- | M] (NewSoft Technology Corporation) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
    PRC - [2008/05/24 15:34:28 | 000,026,448 | ---- | M] (NewSoft Technology Corporation) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
    PRC - [2008/04/13 18:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe
    PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2007/08/03 16:09:34 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    PRC - [2007/05/25 11:16:08 | 000,042,032 | ---- | M] (AOL LLC) -- C:\Program Files\Common Files\AOL\1174865921\EE\aolsoftware.exe
    PRC - [2006/10/23 06:50:35 | 000,046,640 | R--- | M] (AOL LLC) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
    PRC - [2006/02/21 13:37:08 | 001,204,224 | ---- | M] () -- C:\Program Files\StompSoft\PC BackUp\NBKCTRL.exe
    PRC - [2006/02/21 13:37:02 | 000,118,784 | ---- | M] () -- C:\Program Files\StompSoft\PC BackUp\NSENGINE.exe
    PRC - [2005/10/14 01:00:00 | 000,671,744 | ---- | M] (brother) -- C:\Program Files\Brownie\BrStsWnd.exe
    PRC - [2005/03/10 02:01:00 | 000,069,632 | ---- | M] (brother) -- C:\Program Files\Brownie\brpjp04a.exe
    PRC - [2004/03/13 13:36:09 | 001,032,192 | ---- | M] (Stefan Sigmund) -- C:\Program Files\Windows Time Synchronizer\WinTimeSync.exe


    ========== Modules (SafeList) ==========

    MOD - [2011/03/23 12:05:04 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kerry\Desktop\OTL.exe
    MOD - [2011/02/23 09:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
    MOD - [2010/08/23 10:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Disabled | Stopped] -- -- (x10nets)
    SRV - File not found [Auto | Stopped] -- -- (TomTomHOMEService)
    SRV - File not found [Disabled | Stopped] -- -- (IPVision3.ProviderService)
    SRV - File not found [Disabled | Stopped] -- -- (IPVision3.DirectorService)
    SRV - [2011/02/23 09:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
    SRV - [2010/12/08 14:11:38 | 000,136,584 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint)
    SRV - [2010/12/08 14:11:32 | 000,374,152 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe -- (LMIGuardianSvc)
    SRV - [2010/11/08 13:04:18 | 000,390,528 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
    SRV - [2010/07/20 21:24:38 | 002,434,568 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
    SRV - [2010/03/18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
    SRV - [2009/09/26 00:32:18 | 000,189,736 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- E:\Program Files\seagate\seagatemanager\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service)
    SRV - [2009/08/07 12:43:04 | 000,045,816 | ---- | M] (NOS Microsystems Ltd.) [Disabled | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
    SRV - [2009/05/15 04:36:50 | 000,251,184 | R--- | M] (BUFFALO INC.) [Auto | Running] -- C:\Program Files\BUFFALO\NASNAVI\nassvc.exe -- (NasPmService)
    SRV - [2008/09/15 03:57:04 | 000,262,360 | ---- | M] (Data Perceptions / PowerProgrammer) [Disabled | Stopped] -- C:\WINDOWS\system32\WebUpdateSvc4.exe -- (WebUpdate4)
    SRV - [2008/04/13 18:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (W3SVC)
    SRV - [2008/04/13 18:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (SMTPSVC) Simple Mail Transfer Protocol (SMTP)
    SRV - [2008/04/13 18:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (IISADMIN)
    SRV - [2008/01/04 10:27:22 | 000,065,536 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\IVI\ViewCommander\Utilities\VCService\VCService.exe -- (ViewCommander-NVR)
    SRV - [2007/12/16 21:00:00 | 000,143,872 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Stopped] -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE -- (EPSON_EB_RPCV4_01) EPSON V5 Service4(01)
    SRV - [2007/01/10 21:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Stopped] -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE -- (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)
    SRV - [2006/10/23 06:50:35 | 000,046,640 | R--- | M] (AOL LLC) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS)
    SRV - [2006/02/21 13:37:02 | 000,118,784 | ---- | M] () [Auto | Running] -- C:\Program Files\StompSoft\PC BackUp\NSENGINE.exe -- (NsEngine)
    SRV - [2006/02/21 13:24:50 | 000,045,056 | ---- | M] () [Auto | Stopped] -- C:\Program Files\StompSoft\PC BackUp\NMSAccess.exe -- (NMSAccess)
    SRV - [2005/05/11 15:04:34 | 000,360,448 | ---- | M] (Hawking Technology Inc.) [Disabled | Stopped] -- C:\Program Files\Hawking\Management & Control Software\Launcher_HAWK.exe -- (Hawking_ST3402)
    SRV - [2004/10/15 14:54:14 | 000,100,016 | ---- | M] (America Online, Inc) [On_Demand | Stopped] -- C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe -- (AOL TopSpeedMonitor)
    SRV - [2004/03/13 13:36:09 | 001,032,192 | ---- | M] (Stefan Sigmund) [Auto | Running] -- C:\Program Files\Windows Time Synchronizer\WinTimeSync.exe -- (WinTimeSync)
    SRV - [2002/04/19 10:58:38 | 000,065,536 | ---- | M] (America Online, Inc.) [Disabled | Stopped] -- C:\WINDOWS\wanmpsvc.exe -- (WANMiniportService) WAN Miniport (ATW)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
    DRV - [2011/02/23 08:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
    DRV - [2011/02/23 08:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
    DRV - [2011/02/23 08:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
    DRV - [2011/02/23 08:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
    DRV - [2011/02/23 08:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
    DRV - [2011/02/23 08:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
    DRV - [2011/02/23 08:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
    DRV - [2010/12/08 14:12:02 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
    DRV - [2010/06/09 19:16:12 | 000,528,128 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
    DRV - [2010/05/26 11:45:04 | 000,018,816 | ---- | M] (Sophos Plc) [Kernel | System | Running] -- C:\WINDOWS\system32\SAVRKBootTasks.sys -- (SAVRKBootTasks)
    DRV - [2010/02/16 15:13:21 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
    DRV - [2009/12/30 12:20:54 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\revoflt.sys -- (Revoflt)
    DRV - [2009/02/17 12:43:30 | 000,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
    DRV - [2009/02/17 12:43:28 | 000,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
    DRV - [2009/02/17 12:43:28 | 000,008,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
    DRV - [2008/12/19 18:42:18 | 000,030,720 | ---- | M] (Winbond Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vusbser.sys -- (vusbser)
    DRV - [2008/11/25 02:35:54 | 000,211,496 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Si3114r5.sys -- (Si3114r5)
    DRV - [2008/11/25 02:35:54 | 000,017,064 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys -- (SiFilter)
    DRV - [2008/11/25 02:35:54 | 000,012,200 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SiRemFil.sys -- (SiRemFil)
    DRV - [2008/10/17 14:06:58 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
    DRV - [2008/08/01 18:36:26 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
    DRV - [2008/08/01 18:36:20 | 000,054,784 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
    DRV - [2008/07/13 15:07:03 | 000,040,352 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbkey.sys -- (usbkey)
    DRV - [2008/07/04 12:22:36 | 000,009,200 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k)
    DRV - [2008/07/04 12:22:36 | 000,009,072 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp)
    DRV - [2008/04/13 12:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
    DRV - [2008/04/13 12:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
    DRV - [2008/03/29 07:21:54 | 002,873,856 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
    DRV - [2008/02/28 16:31:50 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
    DRV - [2008/02/27 14:49:00 | 000,003,840 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\BANTExt.sys -- (BANTExt)
    DRV - [2007/12/06 10:51:00 | 000,285,952 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
    DRV - [2007/04/16 22:46:00 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
    DRV - [2007/03/24 21:25:25 | 000,008,552 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
    DRV - [2007/01/31 07:33:46 | 000,005,632 | ---- | M] (GRISOFT, s.r.o.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\avgarkt.sys -- (AVG Anti-Rootkit)
    DRV - [2007/01/18 06:00:28 | 000,003,968 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AvgArCln.sys -- (AvgArCln)
    DRV - [2007/01/04 20:26:28 | 000,168,832 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atinavt2.sys -- (ATIAVAIW)
    DRV - [2006/11/01 18:03:00 | 000,006,912 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FlashSys.sys -- (FLASHSYS)
    DRV - [2004/12/07 02:15:54 | 000,087,936 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvatabus.sys -- (nvatabus)
    DRV - [2004/12/01 06:40:08 | 002,300,928 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
    DRV - [2004/10/25 15:40:58 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PCASp50.sys -- (PCASp50)
    DRV - [2004/09/07 19:57:00 | 000,316,152 | ---- | M] (Jungo) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\windrvr6.sys -- (WinDriver6)
    DRV - [2004/08/04 06:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
    DRV - [2004/08/04 06:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
    DRV - [2004/04/13 16:32:50 | 000,140,416 | ---- | M] (Windows (R) 2000 DDK provider) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys -- (DVDVRRdr_xp)
    DRV - [2004/04/13 16:29:44 | 000,198,528 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\Udfreadr.sys -- (UDFReadr)
    DRV - [2004/01/06 16:57:24 | 000,887,431 | ---- | M] (Conexant) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\winachcf.sys -- (Winachcf)
    DRV - [2003/01/10 15:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
    DRV - [2002/01/21 13:39:54 | 000,039,635 | ---- | M] (OLYMPUS OPTICAL CO.,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DSXUSB.sys -- (DSXUSB)
    DRV - [2000/07/24 02:01:00 | 000,019,537 | ---- | M] (Brother Industries Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\BrPar.sys -- (BrPar)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
    IE - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0

    ========== FireFox ==========

    FF - prefs.js..browser.search.update: false
    FF - prefs.js..browser.search.useDBForOrder: true
    FF - prefs.js..browser.startup.homepage: "bing.com "
    FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.9
    FF - prefs.js..extensions.enabledItems: {9BAE5926-8513-417d-8E47-774955A7C60D}:1.1.1d
    FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
    FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
    FF - prefs.js..extensions.enabledItems: {A5475360-A7EA-437b-9A79-29208F476940}:1.3.1
    FF - prefs.js..extensions.enabledItems: optout@dubfire.net:3.20
    FF - prefs.js..extensions.enabledItems: wrc@avast.com:20110101
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
    FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

    FF - HKLM\software\mozilla\Firefox\Extensions\\flashcatch@flashcatch.com: C:\Program Files\FlashCatch\firefox [2009/10/10 17:53:36 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/03/10 22:43:39 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2010/05/17 12:24:00 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2011/03/17 09:46:55 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Thunderbird 1.5.0.13\Extensions\\Components: E:\Program Files\components\ [2010/03/30 10:12:01 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Thunderbird 1.5.0.13\Extensions\\Plugins: E:\Program Files\plugins\ [2010/03/30 10:12:01 | 000,000,000 | ---D | M]

    [2010/06/02 11:37:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Extensions
    [2010/06/02 11:37:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Extensions\home2@tomtom.com
    [2011/03/17 10:41:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Firefox\Profiles\f2otyrlm.default\extensions
    [2010/10/01 17:29:33 | 000,000,000 | ---D | M] (Forecastfox Weather) -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Firefox\Profiles\f2otyrlm.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
    [2010/04/27 19:19:40 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Firefox\Profiles\f2otyrlm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2010/03/31 20:59:57 | 000,000,000 | ---D | M] (FireFTP button) -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Firefox\Profiles\f2otyrlm.default\extensions\{9BAE5926-8513-417d-8E47-774955A7C60D}
    [2010/04/06 18:46:14 | 000,000,000 | ---D | M] (Simple RSS Reader (SRR)) -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Firefox\Profiles\f2otyrlm.default\extensions\{A5475360-A7EA-437b-9A79-29208F476940}
    [2010/10/01 17:29:31 | 000,000,000 | ---D | M] (FireFTP) -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Firefox\Profiles\f2otyrlm.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
    [2010/10/01 17:29:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Firefox\Profiles\f2otyrlm.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2010/12/06 08:01:24 | 000,000,000 | ---D | M] (TACO 3.0 with Abine) -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Firefox\Profiles\f2otyrlm.default\extensions\optout@dubfire.net
    [2010/04/01 09:20:26 | 000,001,820 | ---- | M] () -- C:\Documents and Settings\Kerry\Application Data\Mozilla\Firefox\Profiles\f2otyrlm.default\searchplugins\bing.xml
    [2011/03/10 22:43:39 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
    [2011/03/17 09:46:43 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
    [2011/03/17 09:46:58 | 000,000,000 | ---D | M] (Java Console) -- E:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}

    O1 HOSTS File: ([2011/03/17 22:58:04 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
    O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (FlashCatchBHO Class) - {88618A96-6D8A-42E7-B932-9073D5B2080F} - C:\Program Files\FlashCatch\flashcatch.dll (Level 9 Technology, Inc.)
    O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - Reg Error: Value error. File not found
    O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (FlashCatch) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - C:\Program Files\FlashCatch\flashcatch.dll (Level 9 Technology, Inc.)
    O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Reg Error: Value error. File not found
    O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
    O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Value error. File not found
    O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Value error. File not found
    O3 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\..\Toolbar\ShellBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Value error. File not found
    O3 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\..\Toolbar\WebBrowser: (FlashCatch) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - C:\Program Files\FlashCatch\flashcatch.dll (Level 9 Technology, Inc.)
    O3 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\..\Toolbar\WebBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Value error. File not found
    O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
    O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
    O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
    O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
    O4 - HKLM..\Run: [NovaBackup 7 Tray Control] C:\Program Files\StompSoft\PC BackUp\NbkCtrl.exe ()
    O4 - HKLM..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe (Visioneer Inc)
    O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime Alternative\QTTask.exe (Apple Inc.)
    O4 - HKLM..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)
    O4 - HKLM..\Run: [ZoneAlarm Client] E:\Program Files\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
    O4 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003..\Run: [FreeRAM XP] C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions (TM))
    O4 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003..\Run: [Gadwin PrintScreen Pro] C:\Program Files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe (Gadwin Systems, Inc)
    O4 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003..\Run: [PMSpeed] C:\Program Files\NewSoft\Presto! PageManager 8 for EP\PMSpeed.exe (NewSoft Technology Corporation)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Screen lock.cmd ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Security present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonType = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: CallClerk Dial - C:\Documents and Settings\Kerry\Application Data\CallClerk\callclerk.htm ()
    O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_24.dll (Sun Microsystems, Inc.)
    O9 - Extra Button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL (ATI Technologies Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
    O15 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
    O15 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\..Trusted Ranges: Range1 ([*] in Trusted sites)
    O15 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\..Trusted Ranges: Range1 ([http] in Trusted sites)
    O15 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\..Trusted Ranges: Range2 ([http] in Trusted sites)
    O15 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\..Trusted Ranges: Range3 ([*] in Trusted sites)
    O15 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\..Trusted Ranges: Range3 ([http] in Local intranet)
    O15 - HKU\S-1-5-21-1935655697-1957994488-839522115-1003\..Trusted Ranges: Range4 ([http] in Trusted sites)
    O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
    O16 - DPF: {021E4485-E1A2-4204-8F61-147AC25089D4} http://192.168.0.24/UltraCamX.cab (UltraCamX Class)
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
    O16 - DPF: {108D3206-846A-4A93-BACB-F0572D043ED7} http://192.168.0.190/dvrweb.cab (DHSurveillanceCtrl Control)
    O16 - DPF: {14E35D5F-DEBA-4DB3-B2ED-17542BA12D1F} http://74.7.157.178/AV718.cab (CV781Object Object)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
    O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} http://74.7.157.172/VatDec.cab (VatCtrl Class)
    O16 - DPF: {32C11E38-E587-4BE9-9ABB-D69158C21CE5} http://tigercam.eairlink.com:12345/activex/decoder/mpeg4_dec.cab (Moonlight MPEG-4 Video Decoder)
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
    O16 - DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} http://74.7.157.171/RtspVaPgDec.cab (RtspVaPgCtrl Class)
    O16 - DPF: {3E278D18-99A7-4885-9C9A-8D1219D474F8} http://192.168.0.10:8777/program/SNCIntelligence.cab (SNCIntelligence Class)
    O16 - DPF: {45830FF9-D9E6-4F41-86ED-B266933D8E90} http://67.90.229.242/RtspVaPgDec.cab (RtspVaPgCtrlNew Class)
    O16 - DPF: {49CD73D5-CBE2-4FAA-B70F-0252C74809AB} http://192.168.0.9:7227/classes/PLANETCamV.cab (PLANET IPCamera Control)
    O16 - DPF: {5CB430A9-CAAC-4C91-AF61-6D410EEE1221} http://168.103.190.141/program/SonySncP5View.cab (Sony SNC-P5 Control)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1266003140090 (WUWebControl Class)
    O16 - DPF: {673204A0-F8B3-4090-8506-80658C5D02C6} http://68.25.146.122:7227/nwcv3setup.exe (WebVideoCtrl Class)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1258768524832 (MUWebControl Class)
    O16 - DPF: {6E49B4EF-9FE5-44DF-8D04-445AA94F83DB} http://192.168.0.100/program/SonyNetworkCameraViewer.cab (Sony Network Camera Viewer Control)
    O16 - DPF: {7340F0E4-AEDA-47C6-8971-9DB314030BD7} http://166.130.99.76:12345/activex/decoder/h264_dec.cab (CAxH264Dec Class)
    O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} http://nexushawk.on-the-web.tv:8080/activex/AMC.cab (Reg Error: Key error.)
    O16 - DPF: {7B133798-FAA8-4A7E-950D-BEB35D3363AF} http://192.168.0.13/LinksysViewer.cab (LinksysViewer Control)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
    O16 - DPF: {8D7AFAB7-42D6-4671-A53E-CD355673F026} http://192.168.0.155/SonySncMView.cab (SonySncMView Control)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {9F1C0B35-8230-4176-8B99-5C2485121A4E} http://192.168.0.10/program/SNCActiveXViewer.cab (SNCActiveXViewerControl Class)
    O16 - DPF: {9FCBA748-B8E5-460D-8B5F-E536BDA58A70} http://204.187.62.147:1024/program/SonyNetworkCameraViewer2.cab (SonyNetworkCameraViewer2Control Class)
    O16 - DPF: {A3D93B25-4601-49D2-B3AF-F447C73D561F} http://streetlight.eairlink.com:7227/program/SonySncRz25View.cab (Sony SNC-RZ25 Control)
    O16 - DPF: {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} http://192.168.0.126/codebase/DVM_IPCam2.ocx (DVM_IPCam2 Control)
    O16 - DPF: {A7D87345-E8F9-4B6D-837A-50D468DEC8FE} http://68.193.3.154:5735/H264Inst.cab (PccCamActXCtrl Control)
    O16 - DPF: {AC3FC1E2-26B3-46E5-8EC2-B1D5E4C90331} http://www.microseven.com/hrctech/front/CameraOCX.cab (Reg Error: Key error.)
    O16 - DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} http://dvr12722.dipmap.com/cab/OCXChecker_8120.cab (OCXDownloadChecker Control)
    O16 - DPF: {B8E53531-F29E-4180-AE3E-DF485CC8BE32} http://68.193.3.154:5735/JpegInstV4.cab (pmjpegaudioV4 Class)
    O16 - DPF: {B9940246-4344-4D1B-BD82-DBAF7E657FF9} http://192.168.0.199/SysCamInst.cab (AudioClient Control)
    O16 - DPF: {BA7A56EB-D1B9-443B-96E9-086532A378F1} http://192.168.0.100/activex/decoder/aac_dec.cab (CAxAacDecEmb Class)
    O16 - DPF: {C20E8541-3280-40DC-BC3E-D988F63CD907} http://192.168.0.13/adm/LinksysAlertCfg.cab (LinksysAlertCfg Control)
    O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://166.130.99.76:12345/activex/AMC.cab (AxisMediaControlEmb Class)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
    O16 - DPF: {E3CF5F1B-C29E-4D21-B695-E1B0E1CB6EC9} http://63.147.165.151:7000/codebase/NewHCNetActiveX.cab (Newocx Control)
    O16 - DPF: {EF991872-9158-4570-A7FF-E7DBB6A4B8E9} http://democam6.iqeye.com/iqweb.ocx (IQeye Control)
    O16 - DPF: {F47E687B-551F-4043-89B3-F6E3F5DAD01E} http://122.116.137.123:29077/VDControl.CAB (VideoDeviceControl Class)
    O16 - DPF: {FA478DB9-803F-4154-9DDB-765EA9E35333} http://152.3.125.165/program/SonySncP1View.cab (Sony SNC-P1 Control)
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
    O16 - DPF: {FE92D9C3-4A69-4EC7-8651-1DC8531D0075} http://68.15.12.110:8012/user/TSBnwCam.CAB (TSBnwCam Control)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.85.102 68.87.69.150
    O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    O18 - Protocol\Handler\g7ps {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll (G7 Productivity Systems, Inc.)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
    O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
    O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
    O24 - Desktop Components:1 (Double K Security) - http://www.doubleksecurity.com/
    O24 - Desktop WallPaper: C:\Documents and Settings\Kerry\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kerry\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2007/03/24 18:46:07 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
    O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2011/03/23 12:04:59 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kerry\Desktop\OTL.exe
    [2011/03/17 22:48:29 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2011/03/17 22:46:50 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2011/03/17 22:46:50 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2011/03/17 22:46:50 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2011/03/17 22:46:50 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2011/03/17 22:46:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2011/03/17 22:46:18 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2011/03/17 18:28:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerry\Desktop\tddss
    [2011/03/17 11:44:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
    [2011/03/17 09:47:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
    [2011/03/17 09:45:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
    [2011/03/16 23:30:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerry\Desktop\reports
    [2011/03/16 18:22:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerry\Application Data\Malwarebytes
    [2011/03/16 18:22:18 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2011/03/16 18:22:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2011/03/16 18:22:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2011/03/16 18:22:11 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2011/03/16 18:22:11 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2011/03/16 17:28:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
    [2011/03/16 17:27:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Security Task Manager
    [2011/03/16 17:27:47 | 000,000,000 | ---D | C] -- C:\Program Files\Security Task Manager
    [2011/03/16 08:44:04 | 000,018,816 | ---- | C] (Sophos Plc) -- C:\WINDOWS\System32\SAVRKBootTasks.sys
    [2011/03/16 00:26:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerry\Desktop\checks of rtk
    [2011/03/15 23:27:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerry\Desktop\mbr logs
    [2011/03/10 22:43:46 | 000,301,528 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
    [2011/03/10 22:43:46 | 000,019,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
    [2011/03/10 22:43:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
    [2011/03/10 22:43:45 | 000,371,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
    [2011/03/10 22:43:45 | 000,102,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
    [2011/03/10 22:43:45 | 000,096,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
    [2011/03/10 22:43:45 | 000,049,240 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
    [2011/03/10 22:43:45 | 000,030,680 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
    [2011/03/10 22:43:45 | 000,025,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
    [2011/03/10 22:43:37 | 000,190,016 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
    [2011/03/10 22:43:37 | 000,040,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
    [2011/03/10 22:43:33 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
    [2011/03/10 22:43:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
    [2011/03/10 03:47:33 | 000,000,000 | ---D | C] -- C:\spoolerlogs
    [2011/03/02 12:17:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerry\Desktop\mayrath
    [2011/02/22 09:58:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerry\Application Data\org.youtorial.YoutorialDesktopSuite.5CAFF6D48BBB3E2215B4D4EF06B9C780F44150C1.1
    [2011/02/22 09:58:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Youtorial
    [2011/02/22 09:58:33 | 000,000,000 | ---D | C] -- C:\Program Files\Youtorial
    [2009/06/06 18:55:21 | 000,024,576 | ---- | C] ( ) -- C:\WINDOWS\GV_AccessIni_Memory.dll
    [2008/01/25 11:47:00 | 000,217,088 | ---- | C] ( ) -- C:\Documents and Settings\Kerry\Local Settings\Application Data\Interop.Microsoft.Office.Core.dll
    [2007/08/09 15:50:38 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Kerry\Local Settings\Application Data\stdole.dll
    [2007/07/14 22:31:52 | 000,769,536 | ---- | C] (Toshiba Samsung Storage Technology Coporation) -- C:\Documents and Settings\Kerry\Application Data\sfdnwin.dll
    [2003/04/09 21:44:06 | 000,229,376 | ---- | C] ( ) -- C:\WINDOWS\System32\mpeg4xvid.dll

    ========== Files - Modified Within 30 Days ==========

    [2011/03/23 12:11:18 | 000,552,071 | ---- | M] () -- C:\trace.atf
    [2011/03/23 12:05:04 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kerry\Desktop\OTL.exe
    [2011/03/23 11:44:06 | 000,000,426 | ---- | M] () -- C:\WINDOWS\BRWMARK.INI
    [2011/03/23 11:41:43 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
    [2011/03/23 11:04:55 | 004,300,354 | R--- | M] () -- C:\Documents and Settings\Kerry\Desktop\kerryComboFix.exe
    [2011/03/23 09:35:51 | 000,052,430 | ---- | M] () -- E:\ColoradoHomesteadLaws[1].pdf
    [2011/03/23 09:26:19 | 001,875,769 | ---- | M] () -- E:\adl_10_win7_tips[1].pdf
    [2011/03/23 09:24:24 | 000,142,625 | ---- | M] () -- E:\adl_five_tips_faster_browsing[1].pdf
    [2011/03/23 08:25:22 | 000,013,726 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2011/03/23 08:25:16 | 000,000,312 | ---- | M] () -- C:\WINDOWS\Brownie.ini
    [2011/03/23 08:22:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2011/03/18 11:57:49 | 000,477,378 | ---- | M] () -- E:\sncdmds_product_brochure.pdf
    [2011/03/18 11:00:01 | 000,114,671 | ---- | M] () -- C:\Documents and Settings\Kerry\Desktop\Roping gray wolf wy 1887.jpeg
    [2011/03/17 22:58:04 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2011/03/17 22:48:34 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2011/03/17 18:11:10 | 000,000,820 | ---- | M] () -- C:\WINDOWS\PKZIPW.INI
    [2011/03/17 11:44:02 | 000,000,575 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    [2011/03/16 21:11:45 | 002,317,728 | ---- | M] () -- E:\gmer first screen.rtf
    [2011/03/15 23:12:27 | 000,000,369 | ---- | M] () -- C:\Documents and Settings\Kerry\Desktop\Ebay.url
    [2011/03/15 22:57:54 | 004,080,375 | ---- | M] () -- E:\ebay problems 3-15-11.rtf
    [2011/03/15 19:04:10 | 000,089,088 | ---- | M] () -- C:\Documents and Settings\Kerry\Desktop\mbr.exe
    [2011/03/15 18:46:57 | 004,212,621 | ---- | M] () -- E:\avast location of problem w ff and ebay.rtf
    [2011/03/15 17:51:04 | 000,572,768 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2011/03/15 17:51:04 | 000,113,856 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2011/03/15 08:15:16 | 000,007,168 | ---- | M] () -- C:\Documents and Settings\Kerry\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/03/14 15:49:08 | 002,253,511 | ---- | M] () -- E:\avast settings.rtf
    [2011/03/13 04:26:59 | 000,000,645 | ---- | M] () -- C:\Documents and Settings\Kerry\Desktop\alarm clock.lnk
    [2011/03/11 19:03:32 | 000,132,579 | ---- | M] () -- E:\IdentityFinder_error_report_110311-180331.zip
    [2011/03/11 19:02:09 | 000,133,240 | ---- | M] () -- E:\IdentityFinder_error_report_110311-180208.zip
    [2011/03/10 22:43:46 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
    [2011/03/10 22:43:45 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
    [2011/03/10 18:21:18 | 000,000,949 | ---- | M] () -- C:\Documents and Settings\Kerry\Desktop\sargui.exe.lnk
    [2011/03/10 07:17:10 | 000,001,004 | ---- | M] () -- C:\Documents and Settings\Kerry\Desktop\magicJack.lnk
    [2011/03/09 08:48:55 | 001,936,119 | ---- | M] () -- E:\PSIM+PPT+20101004.pdf
    [2011/03/09 08:48:34 | 000,193,499 | ---- | M] () -- E:\DynaView_PSIM_C3S_2010.pdf
    [2011/03/08 12:12:45 | 000,133,856 | ---- | M] () -- E:\mayrath Aug49_04_1000.jpg
    [2011/03/08 08:21:59 | 013,134,961 | ---- | M] () -- E:\A-Handbook-of-Health.pdf
    [2011/03/08 08:21:36 | 000,186,045 | ---- | M] () -- E:\43NutritionSecretsRevealed.pdf
    [2011/03/08 08:21:30 | 000,155,597 | ---- | M] () -- E:\TheSevenSecretOfAGoodDiet.pdf
    [2011/03/08 08:21:24 | 000,270,198 | ---- | M] () -- E:\SupplementingWithSuperfoods.pdf
    [2011/03/08 08:21:19 | 001,134,133 | ---- | M] () -- E:\SuperfoodsforOptimumHealthChlorellaandSpirulina.pdf
    [2011/03/08 08:20:17 | 000,753,968 | ---- | M] () -- E:\skin tag Removal.pdf
    [2011/03/07 10:16:52 | 010,908,492 | ---- | M] () -- E:\cat PECJ0003-03.pdf
    [2011/03/04 11:26:34 | 000,830,606 | ---- | M] () -- E:\WP_MS_WindowsXPMode within Windows 7.pdf
    [2011/03/02 12:31:11 | 000,307,270 | ---- | M] () -- E:\five_tips_rootkits[1].pdf
    [2011/03/02 11:02:12 | 000,184,664 | ---- | M] () -- E:\Researchers Say Nasal Spray May Prevent Alzheimer.pdf
    [2011/02/25 12:01:56 | 007,272,375 | ---- | M] () -- E:\davis 2-25-11 Weather_Catalog[1].pdf
    [2011/02/23 09:04:21 | 000,040,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
    [2011/02/23 09:04:17 | 000,190,016 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
    [2011/02/23 08:56:55 | 000,371,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
    [2011/02/23 08:56:45 | 000,301,528 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
    [2011/02/23 08:55:49 | 000,049,240 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
    [2011/02/23 08:55:47 | 000,102,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
    [2011/02/23 08:55:44 | 000,096,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
    [2011/02/23 08:55:10 | 000,025,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
    [2011/02/23 08:54:57 | 000,030,680 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
    [2011/02/23 08:54:55 | 000,019,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
    [2011/02/22 16:49:25 | 000,213,860 | ---- | M] () -- E:\wilson amplifier 801245(6).pdf
    [2011/02/22 10:19:00 | 000,062,929 | ---- | M] () -- E:\Synergy Troubleshooting.pdf
    [2011/02/22 10:18:17 | 000,172,854 | ---- | M] () -- E:\Starting synergy automatically.pdf
    [2011/02/22 10:17:18 | 000,094,061 | ---- | M] () -- E:\Synergy Configuration File Format.pdf


    Kerry
     
  20. 2011/03/23
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    otl ran, otl.txt info part two

    [2011/02/22 10:16:54 | 000,090,772 | ---- | M] () -- E:\Authentication and Encryption.pdf
    [2011/02/22 10:15:06 | 000,347,001 | ---- | M] () -- E:\Running Synergy.pdf
    [2011/02/22 10:14:28 | 000,113,665 | ---- | M] () -- E:\Synergy screen s.pdf
    [2011/02/21 15:56:54 | 000,979,685 | ---- | M] () -- E:\mercury payment systems 2-21-11.pdf
    [2011/02/21 15:55:34 | 004,575,814 | ---- | M] () -- E:\mercury payment systems.jpg
    [2011/02/21 13:03:20 | 008,066,405 | ---- | M] () -- E:\joel 22111.rtf

    ========== Files Created - No Company Name ==========

    [2011/03/23 09:35:51 | 000,052,430 | ---- | C] () -- E:\ColoradoHomesteadLaws[1].pdf
    [2011/03/23 09:26:19 | 001,875,769 | ---- | C] () -- E:\adl_10_win7_tips[1].pdf
    [2011/03/23 09:24:24 | 000,142,625 | ---- | C] () -- E:\adl_five_tips_faster_browsing[1].pdf
    [2011/03/22 15:16:53 | 004,300,354 | R--- | C] () -- C:\Documents and Settings\Kerry\Desktop\kerryComboFix.exe
    [2011/03/18 11:57:49 | 000,477,378 | ---- | C] () -- E:\sncdmds_product_brochure.pdf
    [2011/03/18 11:00:01 | 000,114,671 | ---- | C] () -- C:\Documents and Settings\Kerry\Desktop\Roping gray wolf wy 1887.jpeg
    [2011/03/17 22:48:33 | 000,000,211 | ---- | C] () -- C:\Boot.bak
    [2011/03/17 22:48:32 | 000,260,272 | RHS- | C] () -- C:\cmldr
    [2011/03/17 22:46:50 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2011/03/17 22:46:50 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2011/03/17 22:46:50 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2011/03/17 22:46:50 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2011/03/17 22:46:50 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2011/03/17 11:44:02 | 000,000,575 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    [2011/03/16 21:11:45 | 002,317,728 | ---- | C] () -- E:\gmer first screen.rtf
    [2011/03/15 19:04:10 | 000,089,088 | ---- | C] () -- C:\Documents and Settings\Kerry\Desktop\mbr.exe
    [2011/03/15 18:46:57 | 004,212,621 | ---- | C] () -- E:\avast location of problem w ff and ebay.rtf
    [2011/03/15 18:33:12 | 004,080,375 | ---- | C] () -- E:\ebay problems 3-15-11.rtf
    [2011/03/14 15:49:08 | 002,253,511 | ---- | C] () -- E:\avast settings.rtf
    [2011/03/13 04:26:38 | 000,000,645 | ---- | C] () -- C:\Documents and Settings\Kerry\Desktop\alarm clock.lnk
    [2011/03/11 19:03:37 | 000,132,579 | ---- | C] () -- E:\IdentityFinder_error_report_110311-180331.zip
    [2011/03/11 19:02:28 | 000,133,240 | ---- | C] () -- E:\IdentityFinder_error_report_110311-180208.zip
    [2011/03/10 22:43:46 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
    [2011/03/10 18:21:18 | 000,000,949 | ---- | C] () -- C:\Documents and Settings\Kerry\Desktop\sargui.exe.lnk
    [2011/03/09 08:48:41 | 001,936,119 | ---- | C] () -- E:\PSIM+PPT+20101004.pdf
    [2011/03/09 08:48:33 | 000,193,499 | ---- | C] () -- E:\DynaView_PSIM_C3S_2010.pdf
    [2011/03/08 12:12:45 | 000,133,856 | ---- | C] () -- E:\mayrath Aug49_04_1000.jpg
    [2011/03/08 08:21:42 | 013,134,961 | ---- | C] () -- E:\A-Handbook-of-Health.pdf
    [2011/03/08 08:21:36 | 000,186,045 | ---- | C] () -- E:\43NutritionSecretsRevealed.pdf
    [2011/03/08 08:21:30 | 000,155,597 | ---- | C] () -- E:\TheSevenSecretOfAGoodDiet.pdf
    [2011/03/08 08:21:24 | 000,270,198 | ---- | C] () -- E:\SupplementingWithSuperfoods.pdf
    [2011/03/08 08:21:17 | 001,134,133 | ---- | C] () -- E:\SuperfoodsforOptimumHealthChlorellaandSpirulina.pdf
    [2011/03/08 08:20:16 | 000,753,968 | ---- | C] () -- E:\skin tag Removal.pdf
    [2011/03/07 10:16:46 | 010,908,492 | ---- | C] () -- E:\cat PECJ0003-03.pdf
    [2011/03/04 11:26:34 | 000,830,606 | ---- | C] () -- E:\WP_MS_WindowsXPMode within Windows 7.pdf
    [2011/03/02 12:31:11 | 000,307,270 | ---- | C] () -- E:\five_tips_rootkits[1].pdf
    [2011/03/02 11:02:11 | 000,184,664 | ---- | C] () -- E:\Researchers Say Nasal Spray May Prevent Alzheimer.pdf
    [2011/02/25 12:01:56 | 007,272,375 | ---- | C] () -- E:\davis 2-25-11 Weather_Catalog[1].pdf
    [2011/02/22 16:49:25 | 000,213,860 | ---- | C] () -- E:\wilson amplifier 801245(6).pdf
    [2011/02/22 10:19:00 | 000,062,929 | ---- | C] () -- E:\Synergy Troubleshooting.pdf
    [2011/02/22 10:18:17 | 000,172,854 | ---- | C] () -- E:\Starting synergy automatically.pdf
    [2011/02/22 10:17:18 | 000,094,061 | ---- | C] () -- E:\Synergy Configuration File Format.pdf
    [2011/02/22 10:16:54 | 000,090,772 | ---- | C] () -- E:\Authentication and Encryption.pdf
    [2011/02/22 10:15:05 | 000,347,001 | ---- | C] () -- E:\Running Synergy.pdf
    [2011/02/22 10:14:27 | 000,113,665 | ---- | C] () -- E:\Synergy screen s.pdf
    [2011/02/21 15:56:50 | 000,979,685 | ---- | C] () -- E:\mercury payment systems 2-21-11.pdf
    [2011/02/21 15:55:30 | 004,575,814 | ---- | C] () -- E:\mercury payment systems.jpg
    [2011/02/21 13:07:19 | 008,066,405 | ---- | C] () -- E:\joel 22111.rtf
    [2010/07/20 13:12:12 | 000,000,215 | ---- | C] () -- C:\WINDOWS\PROPCALC.INI
    [2010/03/26 11:47:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI
    [2010/03/26 01:36:10 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\ustor.dll
    [2010/03/26 01:36:10 | 000,028,672 | R--- | C] () -- C:\WINDOWS\System32\DMAPI.dll
    [2010/03/03 18:37:54 | 000,073,220 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
    [2010/03/03 18:37:54 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
    [2010/03/03 18:37:54 | 000,029,114 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
    [2010/03/03 18:37:54 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
    [2010/03/03 18:37:54 | 000,021,021 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
    [2010/03/03 18:37:54 | 000,015,670 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
    [2010/03/03 18:37:54 | 000,013,280 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
    [2010/03/03 18:37:54 | 000,010,673 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
    [2010/03/03 18:37:54 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
    [2010/03/03 18:37:54 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
    [2010/03/03 18:37:54 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
    [2010/03/03 18:37:54 | 000,001,137 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
    [2010/03/03 18:37:54 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
    [2010/03/03 18:37:54 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
    [2010/03/03 18:37:54 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
    [2010/03/03 18:37:54 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
    [2010/03/03 18:33:16 | 000,000,090 | ---- | C] () -- C:\WINDOWS\EPART810.ini
    [2009/10/18 05:17:15 | 000,074,944 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
    [2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
    [2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
    [2009/07/01 12:52:33 | 000,004,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
    [2009/06/28 09:06:32 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
    [2009/06/06 18:55:21 | 000,200,704 | ---- | C] () -- C:\WINDOWS\JxIni.dll
    [2009/06/06 18:55:21 | 000,139,264 | ---- | C] () -- C:\WINDOWS\GV_GeoPTZini.dll
    [2009/06/06 18:55:21 | 000,139,264 | ---- | C] () -- C:\WINDOWS\GeoEditAVIDll.dll
    [2009/05/15 04:36:50 | 000,014,344 | ---- | C] () -- C:\WINDOWS\UN060501.INI
    [2009/05/15 04:36:50 | 000,004,398 | ---- | C] () -- C:\WINDOWS\UN090415.INI
    [2009/03/06 17:16:30 | 000,161,319 | ---- | C] () -- C:\WINDOWS\Intelligent IP Installer Uninstaller.exe
    [2009/03/06 16:44:12 | 000,278,528 | ---- | C] () -- C:\WINDOWS\System32\qsysd.dll
    [2009/03/05 09:19:08 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\RPVersion.ini
    [2009/03/02 19:52:35 | 000,000,335 | ---- | C] () -- C:\WINDOWS\mozregistry.dat
    [2009/02/28 13:07:41 | 000,000,494 | ---- | C] () -- C:\WINDOWS\ViewCommander-Player.INI
    [2009/02/23 12:56:04 | 000,000,023 | -HS- | C] () -- C:\WINDOWS\System32\fdcebf2_z.dll
    [2009/02/21 22:02:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\regtrace.INI
    [2009/02/11 16:32:25 | 000,000,185 | ---- | C] () -- C:\WINDOWS\System32\msblcd32.dll
    [2009/01/28 17:05:50 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
    [2009/01/13 16:30:45 | 000,001,362 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2009/01/07 17:54:39 | 000,000,036 | -H-- | C] () -- C:\WINDOWS\System32\swk.ini
    [2008/12/19 18:42:59 | 000,049,736 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\logo.bmp
    [2008/12/19 18:42:32 | 000,000,120 | ---- | C] () -- C:\WINDOWS\WebUpdateSvc4.INI
    [2008/12/19 18:42:22 | 000,291,792 | ---- | C] () -- C:\WINDOWS\System32\wuwinstaller.exe
    [2008/12/19 18:42:22 | 000,024,792 | ---- | C] () -- C:\WINDOWS\System32\wuwstub.exe
    [2008/12/19 18:42:18 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\vcomco.dll
    [2008/12/11 22:20:01 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\ventmon.dll
    [2008/11/20 02:52:44 | 001,806,410 | ---- | C] () -- C:\WINDOWS\System32\MP6Player.exe
    [2008/11/20 02:52:44 | 000,250,144 | ---- | C] () -- C:\WINDOWS\System32\BmpToJpg.dll
    [2008/11/20 02:52:44 | 000,139,325 | ---- | C] () -- C:\WINDOWS\System32\HH5PlayerSDK.dll
    [2008/11/20 02:52:44 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\HHNetClient.dll
    [2008/10/29 19:47:26 | 000,000,086 | ---- | C] () -- C:\WINDOWS\FILEDG32.ini
    [2008/09/15 03:57:06 | 000,418,008 | ---- | C] () -- C:\WINDOWS\System32\WuWUI.exe
    [2008/07/23 12:21:24 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\device_shr_web.dll
    [2008/07/23 12:21:24 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\MediaMan.dll
    [2008/07/23 12:21:24 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\XNS_web.dll
    [2008/07/23 12:10:22 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\device_dvr_web.dll
    [2008/07/13 15:07:03 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\NWKL2_32.DLL
    [2008/07/13 15:07:03 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\KL2DLL32.DLL
    [2008/07/13 15:07:03 | 000,024,136 | ---- | C] () -- C:\WINDOWS\System32\ppmon.exe
    [2008/07/13 15:07:03 | 000,012,480 | ---- | C] () -- C:\WINDOWS\System32\KL2N.DLL
    [2008/07/13 15:07:03 | 000,008,968 | ---- | C] () -- C:\WINDOWS\System32\KL2DLL.DLL
    [2008/07/13 15:07:03 | 000,007,440 | ---- | C] () -- C:\WINDOWS\System32\ppmon.dll
    [2008/05/02 20:06:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Dssole.INI
    [2008/04/28 01:31:48 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\DvrNet.dll
    [2008/04/28 01:31:40 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\NetChannel.dll
    [2008/04/17 09:59:05 | 000,000,512 | ---- | C] () -- C:\WINDOWS\DVRSystem.sys
    [2008/04/12 16:04:55 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
    [2008/03/21 10:17:10 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
    [2008/03/18 12:03:52 | 000,121,856 | ---- | C] () -- C:\WINDOWS\System32\dllmpeg4.dll
    [2008/03/13 19:11:59 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
    [2008/03/13 19:11:47 | 000,014,441 | ---- | C] () -- C:\WINDOWS\HL-5250DN.INI
    [2008/03/13 19:11:12 | 000,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
    [2008/03/13 19:11:12 | 000,000,034 | ---- | C] () -- C:\WINDOWS\System32\BD5250DN.DAT
    [2008/02/28 16:30:08 | 000,462,848 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
    [2008/02/08 14:53:46 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerLang.dll
    [2008/02/06 21:18:59 | 001,015,808 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
    [2008/02/06 21:18:59 | 000,220,160 | ---- | C] () -- C:\WINDOWS\System32\WnASPI32.dll
    [2008/02/06 21:18:59 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
    [2008/02/06 21:18:59 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\libfaac.dll
    [2008/02/06 21:18:59 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\DGRip.dll
    [2008/02/06 21:18:58 | 001,163,264 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
    [2008/02/06 21:18:58 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
    [2008/02/06 21:18:58 | 000,036,352 | ---- | C] () -- C:\WINDOWS\System32\MP2enc.dll
    [2008/02/06 21:04:24 | 000,000,108 | -HS- | C] () -- C:\WINDOWS\WSYS049.SYS
    [2008/02/06 21:04:19 | 000,247,376 | ---- | C] () -- C:\WINDOWS\CoffeeCup Visual Site Designer Uninstaller.exe
    [2008/02/05 09:48:04 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerUninstaller.exe
    [2008/01/31 13:10:56 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ImageProcess.dll
    [2008/01/28 02:15:38 | 000,229,480 | ---- | C] () -- C:\WINDOWS\System32\DecPlayer.dll
    [2008/01/24 12:30:40 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\AVC718Viewer.dll
    [2008/01/23 22:48:21 | 000,655,872 | ---- | C] () -- C:\WINDOWS\System32\xviddll.dll
    [2008/01/23 22:48:21 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2008/01/23 22:48:21 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2008/01/10 14:54:44 | 000,364,544 | ---- | C] () -- C:\WINDOWS\System32\hi_h264dec_w.dll
    [2008/01/04 18:31:41 | 000,000,024 | ---- | C] () -- C:\WINDOWS\hl1270.ini
    [2008/01/04 18:29:44 | 000,000,312 | ---- | C] () -- C:\WINDOWS\Brownie.ini
    [2008/01/04 18:29:44 | 000,000,265 | ---- | C] () -- C:\WINDOWS\brvideo.ini
    [2008/01/04 18:29:18 | 000,001,058 | ---- | C] () -- C:\WINDOWS\Hl-1240.ini
    [2008/01/04 11:28:04 | 000,040,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\usbkey.sys
    [2007/12/25 03:59:36 | 000,786,432 | ---- | C] () -- C:\WINDOWS\System32\DllMonitor.dll
    [2007/11/30 12:49:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
    [2007/10/17 16:23:36 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\rtsp.dll
    [2007/10/17 16:22:42 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\RecordSndDll.dll
    [2007/10/17 16:22:40 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\snd.dll
    [2007/10/17 16:22:34 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\QCodec.dll
    [2007/10/17 16:17:38 | 000,083,968 | ---- | C] () -- C:\WINDOWS\System32\qproc.dll
    [2007/10/09 17:15:00 | 000,401,408 | ---- | C] () -- C:\WINDOWS\System32\IPSDK.dll
    [2007/10/03 13:51:54 | 000,000,020 | ---- | C] () -- C:\WINDOWS\TaxFMRg.dat
    [2007/09/29 03:36:06 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
    [2007/09/29 03:36:06 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
    [2007/09/19 16:28:39 | 000,001,091 | ---- | C] () -- C:\WINDOWS\UnitConverter.INI
    [2007/09/13 15:24:09 | 000,000,788 | ---- | C] () -- C:\WINDOWS\Calendar.INI
    [2007/08/28 13:25:18 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\mp4spvd.dll
    [2007/08/24 06:39:10 | 000,434,270 | ---- | C] () -- C:\WINDOWS\System32\Mp4ADecoder.dll
    [2007/08/14 00:56:08 | 000,589,824 | ---- | C] () -- C:\WINDOWS\System32\playm4.dll
    [2007/08/10 16:20:52 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\langchg.dll
    [2007/08/02 12:55:11 | 000,000,027 | ---- | C] () -- C:\WINDOWS\SonySNCP1.ini
    [2007/07/27 15:49:02 | 000,225,355 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiW.dll
    [2007/07/27 15:49:02 | 000,196,683 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiA.dll
    [2007/07/25 10:55:18 | 000,290,816 | ---- | C] () -- C:\WINDOWS\System32\ShowHCRemCfgWnd.dll
    [2007/07/14 22:30:28 | 000,000,472 | ---- | C] () -- C:\Documents and Settings\Kerry\Application Data\SamsungLiveUpdateConfig.ini
    [2007/06/21 14:05:39 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\cutemon2k.dll
    [2007/06/21 14:05:39 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\UnCutePP.exe
    [2007/06/19 17:08:44 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\TrustZoneRegister.dll
    [2007/06/01 14:33:34 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\RemoteCfgRes_ENG.dll
    [2007/05/21 12:56:25 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\WMVCodec.dll
    [2007/05/21 12:56:01 | 000,000,730 | ---- | C] () -- C:\WINDOWS\m3jpeg.ini
    [2007/05/14 09:55:01 | 000,000,027 | ---- | C] () -- C:\WINDOWS\SonySNCCS1011.ini
    [2007/05/08 13:08:40 | 000,273,408 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
    [2007/05/08 13:08:01 | 000,006,912 | ---- | C] () -- C:\WINDOWS\System32\drivers\FlashSys.sys
    [2007/05/03 16:14:21 | 000,000,036 | ---- | C] () -- C:\WINDOWS\iltwain.ini
    [2007/05/03 10:12:57 | 000,038,419 | ---- | C] () -- C:\Documents and Settings\Kerry\Application Data\Microsoft Excel.ADR
    [2007/05/01 10:37:51 | 000,000,054 | ---- | C] () -- C:\WINDOWS\SonySNCRZ25.ini
    [2007/05/01 10:28:00 | 000,000,145 | ---- | C] () -- C:\WINDOWS\SonyNetworkCameraViewer.ini
    [2007/04/25 05:12:52 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\FilePlayer.dll
    [2007/04/22 07:39:00 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\RealPlay.dll
    [2007/04/22 07:38:14 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\SearchPlay.dll
    [2007/04/17 12:29:30 | 000,142,780 | ---- | C] () -- C:\Documents and Settings\Kerry\Local Settings\Application Data\imageCache7.db
    [2007/04/06 18:10:47 | 000,118,207 | ---- | C] () -- C:\WINDOWS\PrintFileListPro Uninstaller.exe
    [2007/04/03 20:40:51 | 000,021,791 | ---- | C] () -- C:\WINDOWS\System32\smtpctrs.ini
    [2007/04/03 20:40:51 | 000,001,037 | ---- | C] () -- C:\WINDOWS\System32\ntfsdrct.ini
    [2007/04/03 20:40:42 | 000,038,576 | ---- | C] () -- C:\WINDOWS\System32\w3ctrs.ini
    [2007/04/03 20:40:42 | 000,010,225 | ---- | C] () -- C:\WINDOWS\System32\axperf.ini
    [2007/04/03 20:40:39 | 000,011,435 | ---- | C] () -- C:\WINDOWS\System32\infoctrs.ini
    [2007/04/03 12:22:14 | 000,001,402 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
    [2007/04/03 12:22:14 | 000,000,080 | ---- | C] () -- C:\WINDOWS\calera.ini
    [2007/04/03 12:22:08 | 000,269,312 | ---- | C] () -- C:\WINDOWS\System32\FPXIG.DLL
    [2007/04/03 12:22:08 | 000,068,096 | ---- | C] () -- C:\WINDOWS\System32\IGFPX32P.DLL
    [2007/04/03 12:22:08 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\JPEGACC.DLL
    [2007/04/03 12:21:59 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\WELSOF32.DLL
    [2007/04/03 12:07:43 | 000,055,808 | ---- | C] () -- C:\WINDOWS\System32\pttzpcf.dll
    [2007/04/03 02:21:50 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\DvrSetup.dll
    [2007/04/02 20:18:36 | 000,040,308 | ---- | C] () -- C:\WINDOWS\System32\dhchs.ini
    [2007/03/27 00:30:26 | 000,023,507 | ---- | C] () -- C:\Documents and Settings\Kerry\Application Data\Comma Separated Values (DOS).ADR
    [2007/03/27 00:27:06 | 000,038,428 | ---- | C] () -- C:\Documents and Settings\Kerry\Application Data\Tab Separated Values (Windows).ADR
    [2007/03/26 22:46:33 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\Kerry\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/03/26 17:46:57 | 000,000,600 | ---- | C] () -- C:\WINDOWS\ViewCommander.INI
    [2007/03/26 17:27:13 | 000,050,784 | ---- | C] () -- C:\WINDOWS\System32\drivers\atntwink.sys
    [2007/03/26 11:12:06 | 000,000,546 | ---- | C] () -- C:\WINDOWS\MTU.INI
    [2007/03/26 09:17:16 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
    [2007/03/25 20:16:57 | 000,011,016 | ---- | C] () -- C:\WINDOWS\System32\NT5CDLMU.DLL
    [2007/03/25 20:16:30 | 000,405,504 | ---- | C] () -- C:\WINDOWS\deinscdl.exe
    [2007/03/25 19:52:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ATIMMC.INI
    [2007/03/25 18:58:36 | 000,033,789 | ---- | C] () -- C:\Documents and Settings\Kerry\Application Data\Comma Separated Values (Windows).ADR
    [2007/03/25 18:44:52 | 000,000,327 | ---- | C] () -- C:\WINDOWS\wininit.ini
    [2007/03/25 18:32:57 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Kerry\Application Data\$_hpcst$.hpc
    [2007/03/25 18:28:14 | 000,005,169 | ---- | C] () -- C:\WINDOWS\mozver.dat
    [2007/03/25 17:41:07 | 000,000,715 | ---- | C] () -- C:\WINDOWS\aolback.exe.lnk
    [2007/03/25 17:34:05 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
    [2007/03/25 09:29:34 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS6d.DLL
    [2007/03/25 08:37:01 | 000,000,820 | ---- | C] () -- C:\WINDOWS\PKZIPW.INI
    [2007/03/24 23:35:24 | 000,081,920 | R--- | C] () -- C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
    [2007/03/24 22:51:08 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2007/03/24 22:20:27 | 000,000,510 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2007/03/24 22:05:57 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
    [2007/03/24 22:05:55 | 000,796,312 | ---- | C] () -- C:\WINDOWS\System32\libeay32_0.9.6l.dll
    [2007/03/24 21:22:26 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
    [2007/03/24 19:20:00 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
    [2007/03/24 19:18:06 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
    [2007/03/24 18:59:50 | 000,000,258 | ---- | C] () -- C:\WINDOWS\System32\raidmgmt.ini
    [2007/03/24 18:47:54 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2007/03/24 18:43:36 | 000,026,248 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2007/03/24 11:36:46 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2007/03/24 11:34:05 | 000,348,992 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2007/03/20 20:00:42 | 000,050,578 | ---- | C] () -- C:\WINDOWS\System32\dheng.ini
    [2007/02/02 13:40:11 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
    [2007/02/01 15:22:56 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\RemoteCfgRes_TRAD.dll
    [2007/02/01 15:13:06 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\RemoteCfgRes_CHI.dll
    [2007/01/31 18:27:16 | 000,045,444 | ---- | C] () -- C:\WINDOWS\System32\dhtrk.ini
    [2007/01/30 10:21:34 | 000,168,883 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
    [2007/01/22 12:54:56 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\HCNetSDK.dll
    [2007/01/09 02:52:12 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\DvsNDKEx.dll
    [2006/11/29 10:04:42 | 000,038,853 | ---- | C] () -- C:\WINDOWS\System32\dhitalian.ini
    [2006/11/24 10:18:10 | 000,051,456 | ---- | C] () -- C:\WINDOWS\System32\dhjapanese.ini
    [2006/11/24 09:36:26 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\render.dll
    [2006/11/21 21:29:44 | 000,036,418 | ---- | C] () -- C:\WINDOWS\System32\dhcht.ini
    [2006/11/20 12:02:02 | 000,704,512 | ---- | C] () -- C:\WINDOWS\System32\NVSDK.DLL
    [2006/08/30 17:02:26 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\dllh264.dll
    [2006/08/10 18:58:08 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\WlanInstallDll.dll
    [2006/07/28 18:46:26 | 000,033,751 | ---- | C] () -- C:\WINDOWS\System32\dhrussian.ini
    [2006/04/05 14:52:56 | 000,067,072 | ---- | C] () -- C:\WINDOWS\System32\AudioRecord.dll
    [2006/04/05 14:52:54 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\ConfigManage.dll
    [2006/04/05 14:52:48 | 000,181,248 | ---- | C] () -- C:\WINDOWS\System32\avcodec.dll
    [2006/03/16 21:09:36 | 000,413,696 | ---- | C] () -- C:\WINDOWS\System32\RTClientSDK55.dll
    [2006/01/27 20:30:32 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\TextOverlayEx.dll
    [2006/01/06 12:02:54 | 000,000,988 | ---- | C] () -- C:\WINDOWS\System32\IPCamera.ini
    [2005/12/05 20:25:22 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\lnod32umc.dll
    [2005/12/05 13:37:10 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\lnod32upd.dll
    [2005/11/11 23:57:48 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\Audio.dll
    [2005/09/06 04:30:16 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\NetChannel1.dll
    [2005/09/06 03:09:46 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\DvrNet1.dll
    [2005/07/01 13:46:08 | 000,021,507 | ---- | C] () -- C:\WINDOWS\System32\dhgerman.ini
    [2005/06/21 11:29:20 | 000,047,830 | ---- | C] () -- C:\WINDOWS\System32\dhfrench.ini
    [2005/03/30 16:11:04 | 000,290,816 | ---- | C] () -- C:\WINDOWS\System32\Upgrade.dll
    [2005/02/15 10:40:30 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\decode.dll
    [2004/10/14 14:05:08 | 000,020,691 | ---- | C] () -- C:\WINDOWS\System32\dhspanish.ini
    [2004/08/04 06:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
    [2004/08/04 06:00:00 | 000,778,240 | ---- | C] () -- C:\WINDOWS\System32\CommCtl32.dll
    [2004/08/04 06:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
    [2004/08/04 06:00:00 | 000,572,768 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
    [2004/08/04 06:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
    [2004/08/04 06:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
    [2004/08/04 06:00:00 | 000,113,856 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
    [2004/08/04 06:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
    [2004/08/04 06:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
    [2004/08/04 06:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
    [2004/08/04 06:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
    [2004/08/04 06:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
    [2004/08/04 06:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
    [2004/08/03 18:56:46 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
    [2004/07/23 21:30:56 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\decompress.dll
    [2004/06/27 13:18:40 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\CreateAvi.dll
    [2004/04/25 11:22:40 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\AudioACM.dll
    [2004/04/14 13:56:36 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\EZXSCSHook.dll
    [2004/01/28 12:42:06 | 000,066,560 | ---- | C] () -- C:\WINDOWS\System32\atiyuv12.dll
    [2004/01/28 12:42:06 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
    [2004/01/28 12:42:06 | 000,013,601 | ---- | C] () -- C:\WINDOWS\System32\vctest.ini
    [2003/08/26 18:00:52 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\NaviDll.dll
    [2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
    [2002/09/02 22:14:16 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\netdecdll.dll
    [2000/04/25 14:58:08 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\Wrkgadm.exe
    [1998/09/16 23:25:24 | 000,004,096 | ---- | C] () -- C:\WINDOWS\delttsul.exe

    ========== LOP Check ==========

    [2010/03/31 18:10:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin2\Application Data\Stardock
    [2009/12/21 19:56:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Stardock
    [2008/07/17 16:06:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
    [2011/03/10 22:43:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
    [2010/11/22 20:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CallClerk
    [2007/04/07 18:39:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CardScan
    [2009/02/16 09:44:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverCure
    [2010/03/03 18:40:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
    [2007/05/03 16:16:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\G7PS
    [2009/02/22 13:56:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Geek Squad
    [2007/05/30 08:59:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
    [2008/05/20 13:37:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Logic Software
    [2011/03/23 04:02:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
    [2010/10/29 19:45:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\magicJack
    [2010/06/29 16:53:12 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Memeo
    [2010/12/28 05:22:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
    [2009/07/14 12:35:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\r2 Studios
    [2011/03/22 15:12:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegCure
    [2009/04/05 12:21:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
    [2010/02/12 20:12:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
    [2011/03/16 18:19:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
    [2010/01/22 13:52:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SolarWinds
    [2010/08/26 17:11:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
    [2011/02/14 10:09:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2007/10/03 13:49:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Thought Communications
    [2010/06/02 11:37:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
    [2010/09/23 11:37:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2009/10/07 10:13:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2009/12/21 18:38:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{A87EB928-0C6C-4071-AEF1-59E32BAEDF1B}
    [2011/03/23 08:25:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\.oit
    [2009/05/06 09:33:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\41a8e9572df1b3e866f9c54ee96f22f5.8A83BD0BE459142F50C111755484E359D8DBFFF2.1
    [2011/03/23 12:16:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Abine
    [2008/02/09 18:54:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\AirLink
    [2009/03/05 11:37:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\BinarySense
    [2010/11/22 21:11:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\CallClerk
    [2007/04/07 18:44:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\CardScan
    [2008/02/06 21:14:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\CoffeeCup Software
    [2008/11/17 12:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    [2009/12/29 16:21:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\ContentGuard
    [2007/04/07 19:49:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Corex
    [2009/01/28 16:35:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\DriverCure
    [2010/11/18 16:33:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Epson
    [2007/05/24 17:14:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\G7PS
    [2010/12/21 15:17:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Good Deal Software
    [2008/09/25 13:34:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\ICAClient
    [2009/11/09 13:55:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\ICT
    [2009/05/15 12:11:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\ImgBurn
    [2007/05/30 08:59:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\iolo
    [2010/12/21 15:31:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Jim's Cheap Software
    [2010/03/03 18:53:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Leadertech
    [2008/05/20 14:03:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Logic Software
    [2010/11/22 21:19:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\magicJackOutlookAddIn
    [2011/03/10 21:55:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\mjusbsp
    [2010/06/29 16:46:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\NASNaviator2
    [2008/07/18 20:03:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\OfficeUpdate12
    [2008/10/21 12:07:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\OpenOffice.org
    [2011/02/22 09:58:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\org.youtorial.YoutorialDesktopSuite.5CAFF6D48BBB3E2215B4D4EF06B9C780F44150C1.1
    [2010/12/26 11:09:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\ParetoLogic
    [2010/07/30 10:15:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\ProcessLasso
    [2009/07/14 12:35:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\r2 Studios
    [2008/11/17 17:33:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Sprite Software
    [2009/10/18 14:27:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Stardock
    [2009/12/11 14:37:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\TeamViewer
    [2007/12/23 23:08:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Thunderbird
    [2010/06/02 11:37:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\TomTom
    [2009/10/07 18:06:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\TweakNow PowerPack 2009
    [2008/07/02 14:39:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Uniblue
    [2007/05/23 11:16:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\Viewpoint
    [2008/10/23 12:26:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\WebEx
    [2008/11/09 17:35:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerry\Application Data\X-Chat 2
    [2010/06/03 20:40:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kids\Application Data\Epson
    [2009/11/27 18:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kids\Application Data\Stardock
    [2010/05/17 11:47:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kkr\Application Data\Epson

    ========== Purity Check ==========



    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Kerry\Desktop\Screen lock.cmd:SummaryInformation
    @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Screen lock.cmd:SummaryInformation
    @Alternate Data Stream - 330 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EFEEA74F
    @Alternate Data Stream - 231 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEDA5B17
    @Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2966AFCC
    @Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A9CA5BEF
    @Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

    < End of report >

    Kerry
     
  21. 2011/03/23
    kkrich

    kkrich Inactive Thread Starter

    Joined:
    2011/03/16
    Messages:
    25
    Likes Received:
    0
    otl extras.txt info

    OTL Extras logfile created on: 3/23/2011 12:19:10 PM - Run 1
    OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Kerry\Desktop
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 7.0.5730.13)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
    4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
    Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 186.30 Gb Total Space | 50.58 Gb Free Space | 27.15% Space Free | Partition Type: NTFS
    Drive E: | 186.31 Gb Total Space | 47.33 Gb Free Space | 25.40% Space Free | Partition Type: NTFS
    Drive F: | 149.00 Gb Total Space | 73.52 Gb Free Space | 49.34% Space Free | Partition Type: FAT32
    Drive G: | 249.72 Mb Total Space | 37.19 Mb Free Space | 14.89% Space Free | Partition Type: FAT
    Drive Z: | 917.07 Gb Total Space | 578.25 Gb Free Space | 63.05% Space Free | Partition Type: NTFS

    Computer Name: HOME | User Name: Kerry | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

    [HKEY_USERS\S-1-5-21-1935655697-1957994488-839522115-1003\SOFTWARE\Classes\<extension>]
    .html [@ = htmlfile] -- Reg Error: Key error. File not found

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    exefile [open] -- "%1" %*
    InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring" = 1

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "139:TCP" = 139:TCP:*:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:*:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:*:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:*:Enabled:mad:xpsp2res.dll,-22002
    "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22008
    "4434:TCP" = 4434:TCP:*:Enabled:nVision Agent Data Server
    "1723:TCP" = 1723:TCP:*:Enabled:mad:xpsp2res.dll,-22015
    "1701:UDP" = 1701:UDP:*:Enabled:mad:xpsp2res.dll,-22016
    "500:UDP" = 500:UDP:*:Enabled:mad:xpsp2res.dll,-22017
    "26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
    "3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
    "65533:TCP" = 65533:TCP:*:Enabled:Services
    "52344:TCP" = 52344:TCP:*:Enabled:Services
    "4965:TCP" = 4965:TCP:*:Enabled:Services
    "8430:TCP" = 8430:TCP:*:Enabled:Services
    "6629:TCP" = 6629:TCP:*:Enabled:Services
    "6630:TCP" = 6630:TCP:*:Enabled:Services
    "8269:TCP" = 8269:TCP:*:Enabled:Services
    "8270:TCP" = 8270:TCP:*:Enabled:Services
    "8960:TCP" = 8960:TCP:*:Enabled:Services
    "8883:TCP" = 8883:TCP:*:Enabled:Services
    "9701:TCP" = 9701:TCP:*:Enabled:Services
    "8659:TCP" = 8659:TCP:*:Enabled:Services
    "5167:TCP" = 5167:TCP:*:Enabled:Services
    "7117:TCP" = 7117:TCP:*:Enabled:Services
    "1620:TCP" = 1620:TCP:*:Enabled:Services
    "8148:TCP" = 8148:TCP:*:Enabled:Services
    "8149:TCP" = 8149:TCP:*:Enabled:Services
    "2173:TCP" = 2173:TCP:*:Enabled:Services
    "2886:TCP" = 2886:TCP:*:Enabled:Services
    "8619:TCP" = 8619:TCP:*:Enabled:Services
    "4697:TCP" = 4697:TCP:*:Enabled:Services
    "8158:TCP" = 8158:TCP:*:Enabled:Services
    "8159:TCP" = 8159:TCP:*:Enabled:Services
    "7958:TCP" = 7958:TCP:*:Enabled:Services
    "7006:TCP" = 7006:TCP:*:Enabled:Services
    "7287:TCP" = 7287:TCP:*:Enabled:Services
    "7288:TCP" = 7288:TCP:*:Enabled:Services
    "6666:TCP" = 6666:TCP:*:Enabled:Services
    "6686:TCP" = 6686:TCP:*:Enabled:Services
    "5494:TCP" = 5494:TCP:*:Enabled:Services
    "7526:TCP" = 7526:TCP:*:Enabled:Services
    "9754:TCP" = 9754:TCP:*:Enabled:Services
    "9755:TCP" = 9755:TCP:*:Enabled:Services

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 0
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "139:TCP" = 139:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22002
    "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22008
    "1723:TCP" = 1723:TCP:*:Enabled:mad:xpsp2res.dll,-22015
    "1701:UDP" = 1701:UDP:*:Enabled:mad:xpsp2res.dll,-22016
    "500:UDP" = 500:UDP:*:Enabled:mad:xpsp2res.dll,-22017
    "26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
    "3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
    "5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
    "65533:TCP" = 65533:TCP:*:Enabled:Services
    "52344:TCP" = 52344:TCP:*:Enabled:Services
    "4965:TCP" = 4965:TCP:*:Enabled:Services
    "8430:TCP" = 8430:TCP:*:Enabled:Services
    "6629:TCP" = 6629:TCP:*:Enabled:Services
    "6630:TCP" = 6630:TCP:*:Enabled:Services
    "8269:TCP" = 8269:TCP:*:Enabled:Services
    "8270:TCP" = 8270:TCP:*:Enabled:Services
    "8960:TCP" = 8960:TCP:*:Enabled:Services
    "8883:TCP" = 8883:TCP:*:Enabled:Services
    "9701:TCP" = 9701:TCP:*:Enabled:Services
    "8659:TCP" = 8659:TCP:*:Enabled:Services
    "5167:TCP" = 5167:TCP:*:Enabled:Services
    "7117:TCP" = 7117:TCP:*:Enabled:Services
    "1620:TCP" = 1620:TCP:*:Enabled:Services
    "8148:TCP" = 8148:TCP:*:Enabled:Services
    "8149:TCP" = 8149:TCP:*:Enabled:Services
    "2173:TCP" = 2173:TCP:*:Enabled:Services
    "2886:TCP" = 2886:TCP:*:Enabled:Services
    "8619:TCP" = 8619:TCP:*:Enabled:Services
    "4697:TCP" = 4697:TCP:*:Enabled:Services
    "8158:TCP" = 8158:TCP:*:Enabled:Services
    "8159:TCP" = 8159:TCP:*:Enabled:Services
    "7958:TCP" = 7958:TCP:*:Enabled:Services
    "7006:TCP" = 7006:TCP:*:Enabled:Services
    "7287:TCP" = 7287:TCP:*:Enabled:Services
    "7288:TCP" = 7288:TCP:*:Enabled:Services
    "6666:TCP" = 6666:TCP:*:Enabled:Services
    "6686:TCP" = 6686:TCP:*:Enabled:Services
    "5494:TCP" = 5494:TCP:*:Enabled:Services
    "7526:TCP" = 7526:TCP:*:Enabled:Services
    "9754:TCP" = 9754:TCP:*:Enabled:Services
    "9755:TCP" = 9755:TCP:*:Enabled:Services

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "C:\Program Files\Axence\NetTools\3.1\nVision.exe" = C:\Program Files\Axence\NetTools\3.1\nVision.exe:*:Enabled:nVision

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader -- (AOL LLC)
    "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- (AOL LLC)
    "C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon -- (America Online, Inc)
    "C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed -- (America Online Inc)
    "C:\Program Files\Common Files\AOL\1174865921\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1174865921\EE\AOLServiceHost.exe:*:Enabled:AOL -- (America Online, Inc.)
    "C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL -- (AOL LLC)
    "F:\aol 9 backup\America Online 9.0\waol.exe" = F:\aol 9 backup\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 -- (America Online, Inc.)
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
    "C:\Program Files\Common Files\AOL\1174865921\EE\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1174865921\EE\aolsoftware.exe:*:Enabled:AOL Shared Components -- (AOL LLC)
    "E:\AOL 9.1\waol.exe" = E:\AOL 9.1\waol.exe:*:Enabled:AOL -- (AOL, LLC.)
    "C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed -- (AOL LLC)
    "C:\Program Files\Intelligent IP Installer\IPCamManager.exe" = C:\Program Files\Intelligent IP Installer\IPCamManager.exe:*:Enabled:Intelligent IP Installer -- ()
    "C:\Program Files\TeamViewer\Version5\TeamViewer.exe" = C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH)
    "C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon -- (Check Point Software Technologies LTD)
    "C:\Program Files\Epson Software\Event Manager\EEventManager.exe" = C:\Program Files\Epson Software\Event Manager\EEventManager.exe:*:Enabled:EEventManager Application -- (SEIKO EPSON CORPORATION)
    "C:\Documents and Settings\Kerry\Application Data\mjusbsp\magicJack.exe" = C:\Documents and Settings\Kerry\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack -- (magicJack L.P.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
    "{03A26689-82BB-6FF9-1FDA-93B18547C8C8}" = Catalyst Control Center Graphics Full New
    "{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
    "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
    "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
    "{0A87BE08-63E5-43A8-8571-DB651B7FB564}" = i-Pro Viewer 1.2.1
    "{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
    "{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}" = Epson FAX Utility
    "{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences
    "{11F5D779-7BD9-465A-BBC4-10701386BCB9}" = FW LiveUpdate
    "{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
    "{13500404-66C6-BFFA-F108-7FD0837DB3A2}" = newbay_res_200906
    "{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{1EBB57D4-63FF-87CC-A0F0-D73982CF6008}" = Adobe Media Player
    "{21BC2871-0B96-9EC1-6CBF-A0B9BCBC0D89}" = Skins
    "{25331195-4E18-11D7-9D73-0008C7223F91}" = Zoom V.92 PCI Voice Faxmodem
    "{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24
    "{26BEEF24-B264-41E3-9D5E-0529D79FADB6}" = Free CraigsList Reader Pro from CraigsPal 4.5.1
    "{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
    "{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.1
    "{28A9CE0D-C3DE-451D-AC4D-46E1B7711D93}" = Sierra Wireless Sprint Setup Wizard
    "{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
    "{2EDC23E5-29FB-49D0-BF6D-F2D55EA25496}" = HDDlife
    "{3127EBAB-6A3B-4512-BC10-0D6C9EF09672}_is1" = FLVideoConverter
    "{32887C3D-A51F-4D42-9B3C-13FDA797092D}" = Management & Control Software
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{362BFFCD-8274-11D8-97C8-000129760CBE}" = MediaLife
    "{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
    "{3A56DC57-3B78-4347-A76E-BEF7E1E46FD9}" = LinksysOne Surveillance Utility
    "{3B079A8F-1D23-418D-9B6A-BE7DE0186320}" = CraigsWatch
    "{3B8F561D-6D57-40ED-9F9B-2CE6E1E577CE}" = LANsurveyor Express
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}" = ATI Multimedia Center
    "{3CBBEE47-C8F4-316A-92FF-ED7E3DFAE41E}" = ccc-core-static
    "{410DB4DE-354D-F472-F66D-FCFF345A8960}" = Catalyst Control Center Graphics Previews Common
    "{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
    "{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4FC19392-E4A5-4CCB-B45A-AB7E8126D3C9}" = Microsoft Easy Assist
    "{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
    "{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
    "{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
    "{5A29E75C-A8DE-49B4-9AF3-2266CE76C428}" = Sun ODF Plugin for Microsoft Office 1.2
    "{5C92F2C1-3DF9-4BC7-962E-1844326E1789}" = Network Recording Player
    "{5E7F7636-BCC9-4775-B66F-76ED856A0412}" = PC BackUp
    "{5F25FD22-238D-4880-A326-FDF4434C0304}" = Sierra Wireless Verizon Setup Wizard
    "{5F49D1B0-D558-F251-715E-A46CD0A30FED}" = ccc-utility
    "{61BA2A5B-881D-EEF7-F5D2-5EFAF7CCBDA9}" = Catalyst Control Center Graphics Light
    "{651E5E05-3416-E761-B919-37EF1F4272F9}" = Catalyst Control Center Core Implementation
    "{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.2.0
    "{67A5D171-4C74-4075-A492-0E480FA4B944}" = Brother BRAdmin Professiona 2.64
    "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
    "{6C71E42B-7D26-4638-8EC4-364E9E881747}" = IPWizard
    "{6CB0FBF8-E6FD-4DF7-8BBF-C9D23F229C55}" = AceView
    "{7191C910-3F72-B2CA-0FA5-F0E78F5F8FD2}" = CCC Help English
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{73CD9967-000C-49C6-A900-C87D5B2D253F}" = Presto! PageManager 8.15.01 SE
    "{757E0E87-8F54-46FD-BA00-54CCF341F4A9}" = ArcSoft Print Creations
    "{7694E0B1-2332-448B-9235-929F84B41E3F}" = Active@ ISO Burner
    "{76E6BBAA-25E6-4BFC-9613-75A5CACE2940}" = Utilities
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
    "{7E7658A2-CD3F-48A7-93EA-0882BCA4FD2A}" = LogMeIn
    "{7EC96FCD-0C12-46D3-988A-FB802F138BEB}" = Jing
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{838E187D-8B7A-473D-B93C-C8E970B15D2B}" = psqlODBC
    "{83DD27C9-CDC2-489A-87FA-8622C1F8F8EC}" = Debugging Tools for Windows (x86)
    "{8827923A-B5B5-44F9-8FAF-DFFDB23BBEB8}" = Sprite Backup
    "{8B0527BE-427B-459B-93B1-D30ED8CB4F93}" = Network Camera Recorder
    "{8EB278E8-7FDA-4ED9-A429-C87A76F95087}" = 1AVCapture
    "{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
    "{8FF6231F-D670-4AFD-9512-957515E2E1DF}" = Timex Data Link USB
    "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
    "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
    "{90120000-001F-0409-0000-0000000FF1CE}_VISPROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}_VISPROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}_VISPROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
    "{90120000-0054-0409-0000-0000000FF1CE}_VISPROR_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
    "{90120000-006E-0409-0000-0000000FF1CE}_VISPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0115-0409-0000-0000000FF1CE}_VISPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{91120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
    "{91120000-0051-0000-0000-0000000FF1CE}_VISPROR_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
    "{91120000-0051-0000-0000-0000000FF1CE}_VISPROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{936C8C76-1773-4382-A862-5C0E788D8A4D}" = Identity Finder
    "{940DCDA7-4629-C23B-695D-446E120183E0}" = reedexpo_iscwest_showdirectory09
    "{94703490-74B7-437D-9BFE-9DD5CD9E081D}" = IP Setup
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
    "{99D34763-7E45-4FE5-8424-28DBC3A5F0BF}" = GUIDE PLUS+(TM) for Windows® System - ATI
    "{9AD57F2B-DF54-4B87-959D-8CD3AA2B9905}" = VersaCheck Smart Invoice and Estimates 8.0
    "{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
    "{A0A51923-2B36-4850-8E68-7F360D0CCD47}" = FormatFactory
    "{A0AB2980-1FDD-4b6c-940C-FC87C84F05B7}_is1" = FlashCatch
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A3DD7BA6-37A6-4245-A167-B3AA137B2157}" = TitanTV Client components for ATI
    "{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
    "{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
    "{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
    "{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
    "{AC76BA86-7AD7-2447-0000-800000000003}" = Chinese Simplified Fonts Support For Adobe Reader 8
    "{AC76BA86-7AD7-2448-0000-800000000003}" = Chinese Traditional Fonts Support For Adobe Reader 8
    "{AC76BA86-7AD7-5670-0000-800000000003}" = Korean Fonts Support For Adobe Reader 8
    "{AC76BA86-7AD7-5760-0000-800000000003}" = Japanese Fonts Support For Adobe Reader 8
    "{B15F6758-D185-4377-9F3A-7B30B03E9A97}" = MSI DigiCell
    "{B16F9D61-248F-4429-8A3E-C0FA8128E60B}" = WebVideo ActiveX
    "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
    "{B7C82F0E-A726-4484-972B-F7988F1E63C5}" = DesignCAD 3D Max 17.0
    "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
    "{BD1F8143-C678-43CD-A296-A3A32A8C2976}" = Memeo AutoBackup
    "{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
    "{BE424768-FB04-4F36-8BE0-425B3477C8DD}" = Wireless Ace 3G
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C35A5AD9-1271-4A73-B886-6F81F9A67883}" = SolarWinds IP Address Tracker
    "{C46E44D8-208A-41CD-9D8B-5226B634A5E0}" = Airlink101 SkyIPCam Utility
    "{C5EA9A30-54CF-4166-A0D8-525E1F01455A}_is1" = Windows Time Synchronizer
    "{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
    "{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}" = AVIVO Codecs
    "{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CB4544EA-C189-41FE-9E3A-76591DDB852B}" = Roxio Easy Media Creator 7
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Professional
    "{CE1B03BC-3C99-4580-A2AC-A41DB9B83378}" = EasyWeather
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D16A31F9-276D-4968-A753-FFEAC56995D0}" = Epson Print CD
    "{D3816978-13B2-35A7-6280-B9CEF5E79D46}" = Youtorial Player
    "{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
    "{D57F6264-CCF3-49C6-B720-7E364F775BBA}" = Brother HL-5250DN
    "{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
    "{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
    "{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
    "{E303B395-E0C1-42E6-9EF9-F3BC23DEF2D7}" = Remote Printer Console
    "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
    "{E98F49CA-C6E4-4478-A283-AB94A4520DDB}" = LiveView Control
    "{EC33A4E0-A500-D4A2-C1F8-DCA04496B053}" = Catalyst Control Center Graphics Full Existing
    "{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2
    "{EF128055-9B10-4FF9-8500-5648CF8F899C}" = ATI Decoder
    "{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
    "{F1028A20-AE8B-44CE-BBAA-155F66952FE7}" = Network Camera View3
    "{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
    "{F843FCA5-5AF8-4080-88A8-652453FBC841}" = CardScan 8.0.5
    "{F8FBDC28-C265-4F0D-8B91-6E92913E19F6}" = IIS 6.0 Resource Kit Tools
    "{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
    "7-Zip" = 7-Zip 4.57
    "ActiveTouchMeetingClient" = WebEx
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Adobe SVG Viewer" = Adobe SVG Viewer 3.0
    "Advanced Port Scanner v1.3" = Advanced Port Scanner v1.3
    "All ATI Software" = ATI - Software Uninstall Utility
    "AnvSoft Flash to Video Converter Professional_is1" = AnvSoft Flash to Video Converter Professional 1.2.3
    "AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
    "ATI Display Driver" = ATI Display Driver
    "AvantBrowser" = Avant Browser (remove only)
    "avast" = avast! Free Antivirus
    "AVGantiRootkit" = AVG Anti-Rootkit Free
    "AVS DVDMenu Editor_is1" = AVS DVDMenu Editor 1.2.1.19
    "AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.2
    "AVS4YOU Video Converter_is1" = AVS Video Converter 5.6
    "AXIS Media Control Embedded" = AXIS Media Control Embedded
    "Belarc Advisor" = Belarc Advisor 7.2
    "BROWNIE" = Brownie
    "CamStudio" = CamStudio
    "CANONBJ_Deinstall_CNMCP6d.DLL" = Canon PIXMA iP5000
    "CCleaner" = CCleaner
    "Codec_264" = GeoVision H264
    "Codec_amp4" = GeoVision MPEG4 ASP
    "Codec_AVC" = GeoVision MPEG4 AVC
    "Codec_jpeg" = GeoVision JPEG
    "Codec_mp2" = GeoVision MPEG2
    "CoffeeCup Flash Blogger - Registered" = CoffeeCup Flash Blogger - Registered
    "CoffeeCup Flash Form Builder - Registered" = CoffeeCup Flash Form Builder - Registered
    "CoffeeCup Flash Menu Builder" = CoffeeCup Flash Menu Builder
    "CoffeeCup Flash Photo Gallery - Registered" = CoffeeCup Flash Photo Gallery - Registered
    "CoffeeCup Flash Website Font" = CoffeeCup Flash Website Font
    "CoffeeCup Flash Website Font Pack" = CoffeeCup Flash Website Font Pack
    "CoffeeCup Flash Website Search - Registered" = CoffeeCup Flash Website Search - Registered
    "CoffeeCup Google SiteMapper" = CoffeeCup Google SiteMapper
    "CoffeeCup Image Mapper" = CoffeeCup Image Mapper
    "CoffeeCup Live Chat - Registered" = CoffeeCup Live Chat - Registered
    "CoffeeCup PixConverter" = CoffeeCup PixConverter
    "CoffeeCup StyleSheet Maker" = CoffeeCup StyleSheet Maker
    "CoffeeCup Visual Site Designer" = CoffeeCup Visual Site Designer
    "CoffeeCup Web Calendar" = CoffeeCup Web Calendar
    "CoffeeCup Web JukeBox - Registered" = CoffeeCup Web JukeBox - Registered
    "CoffeeCup Web Video Player - Registered" = CoffeeCup Web Video Player - Registered
    "CoffeeCup WebCam 3.5" = CoffeeCup WebCam 3.5
    "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
    "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
    "Core Center" = Core Center
    "Craigs Search Agent" = Craigs Search Agent Trial Version 2.2
    "CutePDF Port Monitor" = CutePDF Printer Setup
    "DriverAgent.exe" = DriverAgent by eSupport.com
    "Dude" = The Dude
    "EPSON Artisan 810 Series" = EPSON Artisan 810 Series Printer Uninstall
    "EPSON PC-FAX Driver 2" = Epson PC-FAX Driver
    "EPSON Scanner" = EPSON Scan
    "eSearch_is1" = eSearch for eBay 2.0
    "Everything" = Everything 1.1.4.301
    "Fences" = Fences
    "Flash Movie Player" = Flash Movie Player 1.5
    "FLV Player" = FLV Player 2.0, build 23
    "Front Panel Designer 3.50" = Front Panel Designer 3.50
    "Gadwin PrintScreen" = Gadwin PrintScreen
    "Gadwin PrintScreen Professional" = Gadwin PrintScreen Professional
    "GeoADPCM" = GeoVision ADPCM
    "GEOXCodec" = GeoVision MPEG4
    "HDD Health_is1" = HDD Health v3.3 Beta
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie7" = Windows Internet Explorer 7
    "ImgBurn" = ImgBurn
    "Index Dat Spy" = Index Dat Spy
    "InstallShield_{28A9CE0D-C3DE-451D-AC4D-46E1B7711D93}" = Sierra Wireless Sprint Setup Wizard
    "InstallShield_{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
    "InstallShield_{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}" = ATI Multimedia Center 9.16
    "InstallShield_{5F25FD22-238D-4880-A326-FDF4434C0304}" = Sierra Wireless Verizon Setup Wizard
    "InstallShield_{94703490-74B7-437D-9BFE-9DD5CD9E081D}" = IP Setup
    "InstallShield_{C35A5AD9-1271-4A73-B886-6F81F9A67883}" = SolarWinds IP Address Tracker
    "InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
    "InstallShield_{EF128055-9B10-4FF9-8500-5648CF8F899C}" = ATI Decoder
    "InstallShield_{F8FBDC28-C265-4F0D-8B91-6E92913E19F6}" = IIS 6.0 Resource Kit Tools
    "Intelligent IP Installer" = Intelligent IP Installer
    "IP Camera" = IP Camera
    "IP Camera Bandwidth and Disk Space Calculator_is1" = IP Camera Calculator 3.0
    "IP Setup Program" = IP Setup Program
    "IsoBuster Toolbar" = IsoBuster Toolbar
    "IsoBuster_is1" = IsoBuster 2.5
    "i-Speeder" = i-Speeder
    "IVI-ViewCommander" = IVI-ViewCommander
    "JimsList" = JimsList
    "KashBox" = KashBox 2.08
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "MFC42DLLVersionUpTool" = MFC42DLLVersionUpTool
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "Microsoft SQL Server 2005" = Microsoft SQL Server 2005
    "Mozilla Firefox (3.6.2)" = Mozilla Firefox (3.6.2)
    "Mozilla Thunderbird (1.5.0.13)" = Mozilla Thunderbird (1.5.0.13)
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "MSI Live Update 3" = MSI Live Update 3
    "MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "NVIDIA Drivers" = NVIDIA Drivers
    "OneTouch Version 3.0" = OneTouch Version 3.0
    "org.youtorial.YoutorialDesktopSuite.5CAFF6D48BBB3E2215B4D4EF06B9C780F44150C1.1" = Youtorial Player
    "PaperPort 7.02" = PaperPort 7.02
    "PdaNet_is1" = PdaNet for Windows Mobile 1.12 (Beta)
    "Ping Plotter Freeware" = Ping Plotter Freeware
    "PlainSight Desktop Calendar_is1" = PlainSight Desktop Calendar 2.4.4
    "PokerStars" = PokerStars
    "Port_Detective_2.0" = Port Detective
    "PrintFileListPro" = PrintFileListPro
    "ProcessLasso" = Process Lasso
    "P-touch Editor ver 3.2" = P-touch Editor 3.2
    "QuicktimeAlt_is1" = QuickTime Alternative 1.78
    "RealPlayer 6.0" = RealPlayer Basic
    "Rovio_is1" = Rovio
    "Security Task Manager" = Security Task Manager 1.8c
    "Snapshot Viewer 9.0" = Snapshot Viewer 9.0
    "Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.4
    "Spiceworks" = Spiceworks
    "ST6UNST #1" = Camera Finder
    "ST6UNST #3" = IPLocator v4.1 Application
    "Startup Delayer" = Startup Delayer v2.5 (build 138)
    "SVG Factory" = SVG Factory 1.0
    "TeamViewer 4" = TeamViewer 4
    "TeamViewer 5" = TeamViewer 5
    "Tweak UI 2.10" = Tweak UI
    "TweakNow PowerPack 2009_is1" = TweakNow PowerPack 2009
    "UN060501" = BUFFALO NAS Navigator
    "UN090415" = BUFFALO LinkStation(LS-CHL) Setup Guide
    "Venta Fax & Voice 6.1 (Home version)" = Venta Fax & Voice 6.1 (Home version) (remove/restore)
    "ViewpointMediaPlayer" = Viewpoint Media Player
    "VISPROR" = Microsoft Office Visio Professional 2007
    "VisualTCPIPRouter_is1" = VisualTCPIPRouter 1.0
    "VV_Outloud_50_En_US" = IBM ViaVoice TTS Runtime v5.0 - US English
    "WELS_is1" = WELS3
    "WinAce Archiver" = WinAce Archiver
    "Windows Essentials Media Codec Pack" = Windows Essentials Media Codec Pack 2.1
    "Windows Media Encoder 9" = Windows Media Encoder 9 Series
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "WMV9_VCM" = Microsoft Windows Media Video 9 VCM
    "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
    "Yahoo! Messenger" = Yahoo! Messenger
    "Zinio Reader" = Zinio Reader
    "ZoneAlarm Pro" = ZoneAlarm Pro

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-1935655697-1957994488-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{CB4AF7DA-CE59-41A9-93A6-DA921F809361}" = CoffeeCup Flash Firestarter
    "{EC90EAE9-0E03-44A1-BF36-0B670B8B8E19}" = CoffeeCup Direct FTP
    "Favorites Finder" = Favorites Finder
    "InstallShield_{32887C3D-A51F-4D42-9B3C-13FDA797092D}" = Management & Control Software hawking
    "InstallShield_{BD1F8143-C678-43CD-A296-A3A32A8C2976}" = Memeo AutoBackup
    "JDiskReport" = JDiskReport
    "magicJack" = magicJack
    "magicJack Outlook Add-In" = magicJack Outlook Add-In 1.0.3.521

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 11/22/2010 10:54:18 PM | Computer Name = HOME | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: A connection with the server could not be established

    Error - 11/22/2010 10:54:18 PM | Computer Name = HOME | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: A connection with the server could not be established

    Error - 11/22/2010 10:54:18 PM | Computer Name = HOME | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: A connection with the server could not be established

    Error - 12/15/2010 7:48:00 PM | Computer Name = HOME | Source = TomTomHOMEService | ID = 10000
    Description =

    Error - 12/15/2010 7:49:38 PM | Computer Name = HOME | Source = TomTomHOMEService | ID = 10000
    Description =

    Error - 12/26/2010 12:41:31 PM | Computer Name = HOME | Source = Application Error | ID = 1000
    Description = Faulting application pplinks.exe, version 7.0.2.0, faulting module
    unknown, version 0.0.0.0, fault address 0x607a8ef0.

    Error - 12/26/2010 12:55:03 PM | Computer Name = HOME | Source = Application Error | ID = 1000
    Description = Faulting application pplinks.exe, version 7.0.2.0, faulting module
    unknown, version 0.0.0.0, fault address 0x607a8ef0.

    Error - 12/26/2010 1:06:33 PM | Computer Name = HOME | Source = Application Error | ID = 1000
    Description = Faulting application pplinks.exe, version 7.0.2.0, faulting module
    unknown, version 0.0.0.0, fault address 0x607a8ef0.

    Error - 12/26/2010 1:09:22 PM | Computer Name = HOME | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file.

    Error - 12/26/2010 1:09:22 PM | Computer Name = HOME | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file.

    [ System Events ]
    Error - 3/22/2011 9:57:17 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7000
    Description = The TomTomHOMEService service failed to start due to the following
    error: %%3

    Error - 3/23/2011 10:22:55 AM | Computer Name = HOME | Source = ati2mtag | ID = 45062
    Description = CRT invalid display type

    Error - 3/23/2011 10:22:55 AM | Computer Name = HOME | Source = ati2mtag | ID = 45062
    Description = CRT invalid display type

    Error - 3/23/2011 10:25:08 AM | Computer Name = HOME | Source = Service Control Manager | ID = 7009
    Description = Timeout (30000 milliseconds) waiting for the Net.Tcp Port Sharing
    Service service to connect.

    Error - 3/23/2011 10:25:09 AM | Computer Name = HOME | Source = Service Control Manager | ID = 7000
    Description = The Net.Tcp Port Sharing Service service failed to start due to the
    following error: %%1053

    Error - 3/23/2011 10:25:09 AM | Computer Name = HOME | Source = Service Control Manager | ID = 7000
    Description = The TomTomHOMEService service failed to start due to the following
    error: %%3

    Error - 3/23/2011 1:02:34 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7034
    Description = The AOL Connectivity Service service terminated unexpectedly. It
    has done this 1 time(s).

    Error - 3/23/2011 1:03:52 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7034
    Description = The EPSON V5 Service4(01) service terminated unexpectedly. It has
    done this 1 time(s).

    Error - 3/23/2011 1:03:52 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7034
    Description = The EPSON V3 Service4(01) service terminated unexpectedly. It has
    done this 1 time(s).

    Error - 3/23/2011 1:08:39 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7034
    Description = The NMSAccess service terminated unexpectedly. It has done this 1
    time(s).


    < End of report >


    Thanks, Kerry.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.