1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive IE 8 crashes, and will not allow Windows update to install

Discussion in 'Malware and Virus Removal Archive' started by Paulie634, 2012/12/18.

  1. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    [Inactive] IE 8 crashes, and will not allow Windows update to install

    I've been having numerous problems using IE8 (crashes, "done but with errors on page ", pages load very slowly (this also happens using Firefox), so I have humbly come to this forum to try to seek some assistance.

    I am also unable to run Windows Update: each time I try, the webpage tries install Windows Update but when I click the "install" button the webpage disappears, and I get an error message to the effect "This tab has been recovered. A problem with the webpage has caused Internet Explorer to close and reopen the tab." Usually after two attempts, I then get the message

    "Internet Explorer has closed this webpage to help protect your computer

    A malfunctioning or malicious add-on has caused Internet Explorer to close this webpage.

    What you can do:

    Go to your home page

    Try to return to microsoft.com

    More information


    I've done my best to follow the instructions posted, and to supply the requested logfiles.

    Please let me know what I may have missed or is otherwise needed.

    Thanks in advance - Paul


    Malwarebytes Anti-Malware 1.65.1.1000
    www.malwarebytes.org

    Database version: v2012.12.18.07

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 8.0.6001.18702
    Paul :: PCDS-BUSINESS [administrator]

    12/18/2012 6:14:45 PM
    mbam-log-2012-12-18 (18-14-45).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 288290
    Time elapsed: 7 minute(s), 59 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)


    aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
    Run date: 2012-12-18 18:30:09
    -----------------------------
    18:30:09.312 OS Version: Windows 5.1.2600 Service Pack 3
    18:30:09.312 Number of processors: 2 586 0x403
    18:30:09.312 ComputerName: PCDS-BUSINESS UserName: Paul
    18:30:10.718 Initialize success
    18:30:11.968 AVAST engine defs: 12121801
    18:31:03.734 The log file has been saved successfully to "C:\Documents and Settings\Paul\Desktop\aswMBR.txt "


    DDS (Ver_2012-11-20.01) - NTFS_x86
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.10.2
    Run by Paul at 18:38:21 on 2012-12-18
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1029 [GMT -5:00]
    .
    AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    ============== Running Processes ================
    .
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Java\jre7\bin\jqs.exe
    C:\Program Files\Memeo\AutoBackupPro\MemeoBackgroundService.exe
    C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    C:\Program Files\AVAST Software\Avast\avastUI.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
    C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k NetworkService
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.wral.com
    uProxyOverride = 127.0.0.1;*.local
    mSearchAssistant = hxxp://www.google.com/ie
    dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned>
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
    BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
    BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
    TB: &Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: &Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
    EB: Real.com: {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\shdocvw.dll
    uRun: [Google Update] "c:\documents and settings\paul\local settings\application data\google\update\GoogleUpdate.exe" /c
    uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10v_Plugin.exe -update plugin
    mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
    mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
    mRun: [Memeo AutoSync] c:\program files\memeo\autosync\MemeoLauncher2.exe --silent
    mRun: [Seagate Dashboard] c:\program files\seagate\seagate dashboard\MemeoLauncher.exe --silent --no_ui
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    dRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    StartupFolder: c:\docume~1\paul\startm~1\programs\startup\seagat~1.lnk - c:\documents and settings\paul\application data\leadertech\powerregister\Seagate NA0DYB3N Product Registration.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppsc2~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpobnz08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
    mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
    mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
    IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    .
    INFO: HKCU has more than 50 listed domains.
    If you wish to scan all of them, select the 'Force scan all domains' option.
    .
    DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
    DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
    DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1343150019000
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199920907406
    DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
    TCP: NameServer = 209.18.47.61 209.18.47.62
    TCP: Interfaces\{269D9EAF-165C-460C-8356-905B77320BD0} : DHCPNameServer = 209.18.47.61 209.18.47.62
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
    Notify: igfxcui - igfxsrvc.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe "
    Hosts: 127.0.0.1 www.spywareinfo.com
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\documents and settings\paul\application data\mozilla\firefox\profiles\0gasbm2g.default\
    FF - plugin: c:\documents and settings\paul\local settings\application data\google\update\1.3.21.123\npGoogleUpdate3.dll
    FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
    FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll
    FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
    FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
    FF - ExtSQL: 2012-11-09 10:07; wrc@avast.com; c:\program files\avast software\avast\webrep\FF
    FF - ExtSQL: !HIDDEN! 2010-04-21 17:12; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-20 738504]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-3-20 361032]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 299984]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-3-20 21256]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-3-20 44808]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\memeo\autobackuppro\MemeoBackgroundService.exe [2010-4-22 25824]
    R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\seagate\seagate dashboard\SeagateDashboardService.exe [2011-6-1 14088]
    R3 MOSUMAC;USB-Ethernet Driver;c:\windows\system32\drivers\MOSUMAC.SYS [2012-9-28 40960]
    S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2010-10-8 100560]
    S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\vboxnetflt.sys --> c:\windows\system32\drivers\VBoxNetFlt.sys [?]
    S4 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2010-2-12 30192]
    S4 ldb;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
    S4 LMIRfsClientNP;LMIRfsClientNP; [x]
    .
    =============== Created Last 30 ================
    .
    2012-12-17 17:20:15 93640 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2012-12-01 21:14:59 58848 ----a-w- c:\program files\mozilla firefox\libEGL.dll
    2012-11-29 23:51:41 -------- d-----w- c:\program files\iPod
    2012-11-29 23:51:37 -------- d-----w- c:\program files\iTunes
    2012-11-29 23:51:37 -------- d-----w- c:\documents and settings\all users\application data\188F1432-103A-4ffb-80F1-36B633C5C9E1
    2012-11-29 23:45:54 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
    2012-11-29 23:45:54 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
    2012-11-29 23:45:53 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
    2012-11-29 23:45:53 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
    2012-11-29 23:45:53 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
    2012-11-29 23:45:53 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
    2012-11-20 20:04:06 -------- d-----w- c:\program files\Mozilla Maintenance Service
    2012-11-20 17:52:35 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
    2012-11-20 17:49:11 -------- d-----w- c:\program files\Bonjour
    .
    ==================== Find3M ====================
    .
    2012-12-17 17:13:36 112784 ----a-w- c:\documents and settings\paul\g2ax_customer_downloadhelper_win32_x86.exe
    2012-12-17 16:47:40 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
    2012-12-17 16:47:40 746984 ----a-w- c:\windows\system32\deployJava1.dll
    2012-12-06 00:54:52 73656 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-12-06 00:54:52 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2012-11-13 01:25:12 1866368 ----a-w- c:\windows\system32\win32k.sys
    2012-11-06 00:41:17 290560 ----a-w- c:\windows\system32\atmfd.dll
    2012-11-02 02:02:42 375296 ----a-w- c:\windows\system32\dpnet.dll
    2012-11-01 12:17:54 916992 ----a-w- c:\windows\system32\wininet.dll
    2012-11-01 12:17:54 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2012-11-01 12:17:54 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2012-11-01 00:35:34 385024 ----a-w- c:\windows\system32\html.iec
    2012-10-30 22:51:58 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2012-10-30 22:51:07 41224 ----a-w- c:\windows\avastSS.scr
    2012-10-25 08:12:26 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2012-10-25 08:12:26 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2012-10-02 18:04:21 58368 ----a-w- c:\windows\system32\synceng.dll
    2012-09-29 23:54:26 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-09-28 15:32:56 5989776 ----a-w- c:\windows\system32\usbaaplrc.dll
    2012-09-28 15:32:56 44544 ----a-w- c:\windows\system32\drivers\usbaapl.sys
    .
    ============= FINISH: 18:39:01.60 ===============


    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 1/5/2008 9:02:54 PM
    System Uptime: 12/17/2012 12:44:16 PM (30 hours ago)
    .
    Motherboard: Intel Corporation | | D915GAG
    Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | | 3000/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 229 GiB total, 187.249 GiB free.
    D: is FIXED (NTFS) - 466 GiB total, 412.89 GiB free.
    E: is CDROM ()
    F: is CDROM ()
    G: is Removable
    H: is FIXED (FAT32) - 4 GiB total, 1.227 GiB free.
    I: is Removable
    J: is Removable
    K: is Removable
    L: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: 1394 Net Adapter
    Device ID: V1394\NIC1394\6A8901132000
    Manufacturer: Microsoft
    Name: 1394 Net Adapter
    PNP Device ID: V1394\NIC1394\6A8901132000
    Service: NIC1394
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Intel(R) PRO/100 VE Network Connection
    Device ID: PCI\VEN_8086&DEV_1064&SUBSYS_4037107B&REV_03\4&14E6004F&0&40F0
    Manufacturer: Intel
    Name: Intel(R) PRO/100 VE Network Connection
    PNP Device ID: PCI\VEN_8086&DEV_1064&SUBSYS_4037107B&REV_03\4&14E6004F&0&40F0
    Service: E100B
    .
    ==== System Restore Points ===================
    .
    RP1851: 9/20/2012 11:43:53 AM - System Checkpoint
    RP1852: 9/21/2012 12:19:09 PM - System Checkpoint
    RP1853: 9/22/2012 6:00:17 AM - Software Distribution Service 3.0
    RP1854: 9/23/2012 6:22:31 AM - System Checkpoint
    RP1855: 9/24/2012 7:34:35 AM - System Checkpoint
    RP1856: 9/25/2012 9:22:40 AM - System Checkpoint
    RP1857: 9/26/2012 10:15:25 AM - System Checkpoint
    RP1858: 9/27/2012 10:21:49 AM - System Checkpoint
    RP1859: 9/28/2012 12:39:06 PM - System Checkpoint
    RP1860: 9/29/2012 3:38:00 PM - System Checkpoint
    RP1861: 10/1/2012 3:33:21 PM - System Checkpoint
    RP1862: 10/2/2012 4:28:49 PM - System Checkpoint
    RP1863: 10/3/2012 4:33:31 PM - System Checkpoint
    RP1864: 10/4/2012 6:38:51 PM - System Checkpoint
    RP1865: 10/5/2012 6:48:38 PM - System Checkpoint
    RP1866: 10/6/2012 7:48:39 PM - System Checkpoint
    RP1867: 10/7/2012 8:48:43 PM - System Checkpoint
    RP1868: 10/8/2012 9:27:05 PM - System Checkpoint
    RP1869: 10/9/2012 10:27:07 PM - System Checkpoint
    RP1870: 10/10/2012 11:27:09 PM - System Checkpoint
    RP1871: 10/11/2012 6:00:23 AM - Software Distribution Service 3.0
    RP1872: 10/12/2012 6:25:52 AM - System Checkpoint
    RP1873: 10/13/2012 7:26:02 AM - System Checkpoint
    RP1874: 10/14/2012 8:25:56 AM - System Checkpoint
    RP1875: 10/15/2012 9:25:55 AM - System Checkpoint
    RP1876: 10/16/2012 10:25:56 AM - System Checkpoint
    RP1877: 10/17/2012 11:25:55 AM - System Checkpoint
    RP1878: 10/18/2012 12:34:46 PM - System Checkpoint
    RP1879: 10/19/2012 1:14:55 PM - System Checkpoint
    RP1880: 10/20/2012 2:14:58 PM - System Checkpoint
    RP1881: 10/21/2012 3:15:00 PM - System Checkpoint
    RP1882: 10/22/2012 12:57:29 PM - Installed Java 7 Update 9
    RP1883: 10/23/2012 1:48:01 PM - System Checkpoint
    RP1884: 10/24/2012 2:51:07 PM - System Checkpoint
    RP1885: 10/25/2012 3:48:00 PM - System Checkpoint
    RP1886: 10/26/2012 4:48:03 PM - System Checkpoint
    RP1887: 10/27/2012 5:55:03 PM - System Checkpoint
    RP1888: 10/28/2012 4:37:05 PM - Revo Uninstaller's restore point - HP Photo and Imaging 2.0 - hp psc 2200 series
    RP1889: 10/28/2012 4:38:34 PM - Removed HP Photo and Imaging 2.0 - All-in-One
    RP1890: 10/28/2012 4:39:44 PM - Removed HP Photo and Imaging 2.0 - All-in-One Drivers
    RP1891: 10/28/2012 4:40:27 PM - Removed hp psc 2200 series
    RP1892: 10/28/2012 4:52:44 PM - Revo Uninstaller's restore point - hp instant support
    RP1893: 10/28/2012 4:56:08 PM - Revo Uninstaller's restore point - hp instant support
    RP1894: 10/28/2012 5:08:11 PM - Installed Product Software
    RP1895: 10/28/2012 5:09:05 PM - Installed Product Drivers
    RP1896: 10/28/2012 5:11:43 PM - Installed hp psc 2200 series
    RP1897: 10/28/2012 5:55:06 PM - Revo Uninstaller's restore point - hp instant support
    RP1898: 10/28/2012 5:56:49 PM - Revo Uninstaller's restore point - HP OfficeJet/PSC Scrubber
    RP1899: 10/28/2012 5:58:15 PM - Revo Uninstaller's restore point - HP Photo and Imaging 2.0 - All-in-One Drivers
    RP1900: 10/28/2012 5:58:36 PM - Removed HP Photo and Imaging 2.0 - All-in-One Drivers
    RP1901: 10/28/2012 7:40:35 PM - Revo Uninstaller's restore point - HP Photo and Imaging 2.0 - All-in-One Drivers
    RP1902: 10/28/2012 7:42:30 PM - Revo Uninstaller's restore point - HP Photo and Imaging 2.0 - All-in-One
    RP1903: 10/28/2012 7:42:44 PM - Removed HP Photo and Imaging 2.0 - All-in-One
    RP1904: 10/28/2012 7:43:57 PM - Revo Uninstaller's restore point - HP Photo and Imaging 2.0 - hp psc 2200 series
    RP1905: 10/28/2012 8:48:49 PM - Removed hp psc 2200 series
    RP1906: 10/28/2012 8:53:36 PM - Installed Product Software
    RP1907: 10/28/2012 8:54:46 PM - Installed Product Drivers
    RP1908: 10/28/2012 8:57:24 PM - Installed hp psc 2200 series
    RP1909: 10/29/2012 2:36:12 PM - Removed HP Photo and Imaging 2.0 - All-in-One
    RP1910: 10/29/2012 2:37:20 PM - Removed HP Photo and Imaging 2.0 - All-in-One Drivers
    RP1911: 10/29/2012 2:38:03 PM - Removed hp psc 2200 series
    RP1912: 10/29/2012 5:12:32 PM - Installed Product Software
    RP1913: 10/29/2012 5:13:20 PM - Installed Product Drivers
    RP1914: 10/29/2012 5:18:06 PM - Installed hp psc 2200 series
    RP1915: 10/30/2012 6:32:35 PM - System Checkpoint
    RP1916: 10/31/2012 7:29:28 PM - System Checkpoint
    RP1917: 11/1/2012 8:12:12 PM - System Checkpoint
    RP1918: 11/2/2012 8:37:36 PM - System Checkpoint
    RP1919: 11/3/2012 9:37:36 PM - System Checkpoint
    RP1920: 11/4/2012 9:33:04 PM - System Checkpoint
    RP1921: 11/5/2012 9:37:36 PM - System Checkpoint
    RP1922: 11/6/2012 10:37:37 PM - System Checkpoint
    RP1923: 11/7/2012 11:37:40 PM - System Checkpoint
    RP1924: 11/9/2012 12:37:36 AM - System Checkpoint
    RP1925: 11/10/2012 1:08:56 AM - System Checkpoint
    RP1926: 11/11/2012 2:08:59 AM - System Checkpoint
    RP1927: 11/12/2012 3:09:02 AM - System Checkpoint
    RP1928: 11/13/2012 4:09:02 AM - System Checkpoint
    RP1929: 11/14/2012 5:09:05 AM - System Checkpoint
    RP1930: 11/14/2012 6:00:27 AM - Software Distribution Service 3.0
    RP1931: 11/15/2012 6:35:25 AM - System Checkpoint
    RP1932: 11/16/2012 6:48:55 AM - System Checkpoint
    RP1933: 11/17/2012 7:49:11 AM - System Checkpoint
    RP1934: 11/18/2012 8:49:02 AM - System Checkpoint
    RP1935: 11/19/2012 9:49:00 AM - System Checkpoint
    RP1936: 11/20/2012 10:49:03 AM - System Checkpoint
    RP1937: 11/20/2012 12:50:51 PM - Installed iTunes
    RP1938: 11/21/2012 12:54:07 PM - System Checkpoint
    RP1939: 11/22/2012 1:53:03 PM - System Checkpoint
    RP1940: 11/23/2012 2:02:13 PM - System Checkpoint
    RP1941: 11/24/2012 2:53:08 PM - System Checkpoint
    RP1942: 11/25/2012 4:28:57 PM - System Checkpoint
    RP1943: 11/26/2012 4:53:10 PM - System Checkpoint
    RP1944: 11/27/2012 5:10:57 PM - System Checkpoint
    RP1945: 11/28/2012 6:09:53 PM - System Checkpoint
    RP1946: 11/29/2012 7:04:30 PM - System Checkpoint
    RP1947: 11/30/2012 7:52:53 PM - System Checkpoint
    RP1948: 12/1/2012 8:41:52 PM - System Checkpoint
    RP1949: 12/2/2012 9:41:57 PM - System Checkpoint
    RP1950: 12/3/2012 10:15:27 PM - System Checkpoint
    RP1951: 12/4/2012 10:27:32 PM - System Checkpoint
    RP1952: 12/5/2012 11:21:28 PM - System Checkpoint
    RP1953: 12/6/2012 11:42:09 PM - System Checkpoint
    RP1954: 12/8/2012 12:42:13 AM - System Checkpoint
    RP1955: 12/9/2012 1:42:14 AM - System Checkpoint
    RP1956: 12/10/2012 2:42:16 AM - System Checkpoint
    RP1957: 12/11/2012 3:42:13 AM - System Checkpoint
    RP1958: 12/12/2012 3:46:40 AM - System Checkpoint
    RP1959: 12/12/2012 6:00:33 AM - Software Distribution Service 3.0
    RP1960: 12/12/2012 3:14:07 PM - Installed Windows XP KB2604042.
    RP1961: 12/13/2012 3:28:41 PM - System Checkpoint
    RP1962: 12/14/2012 5:03:12 PM - System Checkpoint
    RP1963: 12/15/2012 5:28:41 PM - System Checkpoint
    RP1964: 12/16/2012 6:32:27 PM - System Checkpoint
    RP1965: 12/17/2012 11:34:20 AM - Removed Java 7 Update 9
    RP1966: 12/17/2012 11:47:36 AM - Installed Java 7 Update 9
    RP1967: 12/17/2012 12:19:35 PM - Installed Java 7 Update 10
    RP1968: 12/17/2012 10:39:38 PM - Software Distribution Service 3.0
    .
    ==== Installed Programs ======================
    .
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 11 ActiveX
    Adobe Photoshop 7.0
    Adobe Reader X (10.1.4)
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    avast! Free Antivirus
    Belarc Advisor 8.1
    Bonjour
    CCleaner
    ClearType Tuning Control Panel Applet
    Compatibility Pack for the 2007 Office system
    Critical Update for Windows Media Player 11 (KB959772)
    DesignPro 5.4 Limited Edition
    Digital Media Reader
    DVD Shrink 3.2
    EasyGPS 2.9.6
    Garmin Communicator Plugin
    Garmin POI Loader
    Garmin USB Drivers
    Garmin WebUpdater
    Google Chrome
    Google Desktop
    Google Drive
    Google Toolbar for Internet Explorer
    Google Update Helper
    Google Updater
    High Definition Audio Driver Package - KB835221
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 10 (KB903157)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB2443685)
    Hotfix for Windows XP (KB2570791)
    Hotfix for Windows XP (KB2633952)
    Hotfix for Windows XP (KB2756822)
    Hotfix for Windows XP (KB2779562)
    Hotfix for Windows XP (KB942288-v3)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB971276-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    hp instant support
    HP OfficeJet/PSC Scrubber
    HP Photo and Imaging 2.0 - All-in-One
    HP Photo and Imaging 2.0 - All-in-One Drivers
    HP Photo and Imaging 2.0 - hp psc 2200 series
    hp psc 2200 series
    ieSpell
    InfraRecorder
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) PRO Network Adapters and Drivers
    iTunes
    Java 7 Update 10
    Java Auto Updater
    LG CyberLink LabelPrint
    LG CyberLink Power2Go
    LG CyberLink PowerBackup
    LG CyberLink PowerDVD
    LG CyberLink PowerProducer
    LG CyberLink YouCam
    LG ODD Auto Firmware Update
    LG Power Tools
    LightScribe System Software
    Logitech Desktop Messenger
    Logitech Harmony Remote Software 7
    Malwarebytes Anti-Malware version 1.65.1.1000
    Memeo AutoSync
    Memeo Backup Premium
    Memeo LifeAgent Explorer Extension
    Memeo Send
    Memeo Share
    Microsoft .NET Framework 1.0 Hotfix (KB2572066)
    Microsoft .NET Framework 1.0 Hotfix (KB2604042)
    Microsoft .NET Framework 1.0 Hotfix (KB2656378)
    Microsoft .NET Framework 1.0 Hotfix (KB953295)
    Microsoft .NET Framework 1.0 Hotfix (KB979904)
    Microsoft .NET Framework 1.0 Security Update (KB2698035)
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2656370)
    Microsoft .NET Framework 1.1 Security Update (KB2698023)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Digital Image Library 9 - Blocker
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Money 2005
    Microsoft National Language Support Downlevel APIs
    Microsoft Office File Validation Add-In
    Microsoft Office Professional Edition 2003
    Microsoft Picture It! Library 10
    Microsoft Picture It! Premium 10
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Works
    Mozilla Firefox 17.0.1 (x86 en-US)
    Mozilla Maintenance Service
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP2 Parser and SDK
    MSXML 6.0 Parser
    Multimedia Keyboard Driver
    Napster Burn Engine
    OpenOffice.org 3.2
    PowerDVD
    QuickTime
    RealPlayer Basic
    Realtek High Definition Audio Driver
    Recover My Files
    Recovery Software Suite Gateway
    Remote Control USB Driver
    Revo Uninstaller 1.94
    Seagate Dashboard
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
    Security Update for Microsoft Windows (KB2564958)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB2416400)
    Security Update for Windows Internet Explorer 8 (KB2482017)
    Security Update for Windows Internet Explorer 8 (KB2497640)
    Security Update for Windows Internet Explorer 8 (KB2510531)
    Security Update for Windows Internet Explorer 8 (KB2530548)
    Security Update for Windows Internet Explorer 8 (KB2544521)
    Security Update for Windows Internet Explorer 8 (KB2559049)
    Security Update for Windows Internet Explorer 8 (KB2586448)
    Security Update for Windows Internet Explorer 8 (KB2618444)
    Security Update for Windows Internet Explorer 8 (KB2699988)
    Security Update for Windows Internet Explorer 8 (KB2722913)
    Security Update for Windows Internet Explorer 8 (KB2744842)
    Security Update for Windows Internet Explorer 8 (KB2761465)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2160329)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2296199)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB2393802)
    Security Update for Windows XP (KB2412687)
    Security Update for Windows XP (KB2419632)
    Security Update for Windows XP (KB2423089)
    Security Update for Windows XP (KB2436673)
    Security Update for Windows XP (KB2440591)
    Security Update for Windows XP (KB2443105)
    Security Update for Windows XP (KB2476490)
    Security Update for Windows XP (KB2476687)
    Security Update for Windows XP (KB2478960)
    Security Update for Windows XP (KB2478971)
    Security Update for Windows XP (KB2479628)
    Security Update for Windows XP (KB2481109)
    Security Update for Windows XP (KB2483185)
    Security Update for Windows XP (KB2485376)
    Security Update for Windows XP (KB2485663)
    Security Update for Windows XP (KB2503658)
    Security Update for Windows XP (KB2503665)
    Security Update for Windows XP (KB2506212)
    Security Update for Windows XP (KB2506223)
    Security Update for Windows XP (KB2507618)
    Security Update for Windows XP (KB2507938)
    Security Update for Windows XP (KB2508272)
    Security Update for Windows XP (KB2508429)
    Security Update for Windows XP (KB2509553)
    Security Update for Windows XP (KB2511455)
    Security Update for Windows XP (KB2524375)
    Security Update for Windows XP (KB2535512)
    Security Update for Windows XP (KB2536276-v2)
    Security Update for Windows XP (KB2536276)
    Security Update for Windows XP (KB2544893-v2)
    Security Update for Windows XP (KB2544893)
    Security Update for Windows XP (KB2555917)
    Security Update for Windows XP (KB2562937)
    Security Update for Windows XP (KB2566454)
    Security Update for Windows XP (KB2567053)
    Security Update for Windows XP (KB2567680)
    Security Update for Windows XP (KB2570222)
    Security Update for Windows XP (KB2570947)
    Security Update for Windows XP (KB2584146)
    Security Update for Windows XP (KB2585542)
    Security Update for Windows XP (KB2592799)
    Security Update for Windows XP (KB2598479)
    Security Update for Windows XP (KB2603381)
    Security Update for Windows XP (KB2618451)
    Security Update for Windows XP (KB2620712)
    Security Update for Windows XP (KB2624667)
    Security Update for Windows XP (KB2631813)
    Security Update for Windows XP (KB2633171)
    Security Update for Windows XP (KB2639417)
    Security Update for Windows XP (KB2646524)
    Security Update for Windows XP (KB2653956)
    Security Update for Windows XP (KB2655992)
    Security Update for Windows XP (KB2659262)
    Security Update for Windows XP (KB2661637)
    Security Update for Windows XP (KB2676562)
    Security Update for Windows XP (KB2685939)
    Security Update for Windows XP (KB2686509)
    Security Update for Windows XP (KB2691442)
    Security Update for Windows XP (KB2695962)
    Security Update for Windows XP (KB2698365)
    Security Update for Windows XP (KB2705219)
    Security Update for Windows XP (KB2707511)
    Security Update for Windows XP (KB2712808)
    Security Update for Windows XP (KB2718523)
    Security Update for Windows XP (KB2719985)
    Security Update for Windows XP (KB2723135)
    Security Update for Windows XP (KB2724197)
    Security Update for Windows XP (KB2727528)
    Security Update for Windows XP (KB2731847)
    Security Update for Windows XP (KB2753842)
    Security Update for Windows XP (KB2758857)
    Security Update for Windows XP (KB2761226)
    Security Update for Windows XP (KB2770660)
    Security Update for Windows XP (KB2779030)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982665)
    Security Update for Windows XP (KB982802)
    SoftV92 Data Fax Modem with SmartCP
    Sonic Activation Module
    Spybot - Search & Destroy
    SupportSoft Assisted Service
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB971930)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB976749)
    Update for Windows Internet Explorer 8 (KB980182)
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB2467659)
    Update for Windows XP (KB2541763)
    Update for Windows XP (KB2607712)
    Update for Windows XP (KB2616676)
    Update for Windows XP (KB2641690)
    Update for Windows XP (KB2661254-v2)
    Update for Windows XP (KB2718704)
    Update for Windows XP (KB2736233)
    Update for Windows XP (KB2749655)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971029)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Update Rollup 2 for Windows XP Media Center Edition 2005
    USB-Ethernet Adapter Device
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    WebFldrs XP
    WIDCOMM Bluetooth Software
    Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows Live OneCare safety scanner
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player Firefox Plugin
    Windows PowerShell(TM) 1.0
    Windows XP Media Center Edition 2005 KB2502898
    Windows XP Media Center Edition 2005 KB2619340
    Windows XP Media Center Edition 2005 KB2628259
    Windows XP Media Center Edition 2005 KB890629
    Windows XP Media Center Edition 2005 KB890760
    Windows XP Media Center Edition 2005 KB895198
    Windows XP Media Center Edition 2005 KB895678
    Windows XP Media Center Edition 2005 KB925766
    Windows XP Media Center Edition 2005 KB973768
    Windows XP Service Pack 3
    WinPatrol
    XPS Essentials Pack
    XPS Essentials Pack 1.0
    Yahoo! Install Manager
    .
    ==== Event Viewer Messages From Past Week ========
    .
    12/17/2012 5:51:34 PM, error: NetBT [4319] - A duplicate name has been detected on the TCP network. The IP address of the machine that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state.
    12/17/2012 5:51:34 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer LAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{269D9EAF-165C-460C-83. The master browser is stopping or an election is being forced.
    .
    ==== End Of File ===========================
     
  2. 2012/12/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    =============================

    aswMBR log is incomplete.
    Redo. Be patient. Let it finish.
     

  3. to hide this advert.

  4. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    Will do. How will I know when it has completed the scan?
     
    Last edited: 2012/12/18
  5. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    Completed aswMBR.txt file as requested

    aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
    Run date: 2012-12-18 20:21:23
    -----------------------------
    20:21:23.906 OS Version: Windows 5.1.2600 Service Pack 3
    20:21:23.906 Number of processors: 2 586 0x403
    20:21:23.906 ComputerName: PCDS-BUSINESS UserName: Paul
    20:21:24.437 Initialize success
    20:21:24.562 AVAST engine defs: 12121801
    20:21:27.906 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
    20:21:27.906 Disk 0 Vendor: WDC_WD2500JS-08NCB1 10.02E01 Size: 238475MB BusType: 3
    20:21:27.921 Disk 0 MBR read successfully
    20:21:27.921 Disk 0 MBR scan
    20:21:27.984 Disk 0 unknown MBR code
    20:21:27.984 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 234174 MB offset 8803620
    20:21:27.984 Disk 0 Partition 2 00 0B FAT32 RECOVERY 4298 MB offset 63
    20:21:28.000 Disk 0 scanning sectors +488392065
    20:21:28.031 Disk 0 scanning C:\WINDOWS\system32\drivers
    20:21:42.234 Service scanning
    20:21:56.671 Modules scanning
    20:22:22.765 Disk 0 trace - called modules:
    20:22:22.796 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
    20:22:22.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a7b81f8]
    20:22:22.796 3 CLASSPNP.SYS[ba168fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x8a7abd98]
    20:22:23.281 AVAST engine scan C:\WINDOWS
    20:22:30.062 AVAST engine scan C:\WINDOWS\system32
    20:25:13.343 AVAST engine scan C:\WINDOWS\system32\drivers
    20:25:36.921 AVAST engine scan C:\Documents and Settings\Paul
    20:37:21.531 AVAST engine scan C:\Documents and Settings\All Users
    20:40:10.203 Scan finished successfully
    20:42:17.812 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Paul\Desktop\MBR.dat "
    20:42:17.828 The log file has been saved successfully to "C:\Documents and Settings\Paul\Desktop\aswMBR.txt "
     
  6. 2012/12/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    • Download RogueKiller on the desktop
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again
     
  7. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    MBR.dat file also produced by aswMBR scan

    The aswMBR scan also produced the file MBR.dat, seen below:


    3ÿ¾ Ž×¼ z» ‹ÎŽÛŽÃó¤Ãª_   z "¹Ãµ±8dt
    8DtĮâñéÆ » ÿ0ÿ1 ۑsóì
    Àtú´» Ãëò½¾¿Ãޏ è¿Ã¿Ã†ۮE ‹ý¸ è°Ã¿Ã† ÆEÆE ö\uSö\uX´Ãu3Å [
    Ã’tJ‹6cè©Ã¿±¸0 ÂÃþÊx06Å l€Ã´Ãu 6:luóëܾWèÿ´Ã<rt€ü…u ÆEۑ¾WèfÿÆ€ö\tÆE ö\@t¾ÃŽè:ÿ±‹ý€=€tĂâö‹6_è6ÿ´ ÃÀ&\ù¸ C²â‚Ãrâf‹]f‰" Æ |´BÃrÃŽ>þUªâ€¹6]uÆê |
    er~€Missing OS
    MBR Error

    Press F11 to start recovery [§Ãžâ€¡Ã € $þÿÿ$U† ]ð•  þ¿#? Ã¥T† Uª
     
  8. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    Will do as advised. Thank you!
     
  9. 2012/12/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Leave MBR.dat alone.
     
  10. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    OK - Thanks...
     
  11. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    RogueKiller report

    RogueKiller V8.4.0 [Dec 18 2012] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website : http://tigzy.geekstogo.com/roguekiller.php
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : Paul [Admin rights]
    Mode : Remove -- Date : 12/18/2012 20:59:25

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 4 ¤¤¤
    [STARTUP][SUSP PATH] Seagate NA0DYB3N Product Registration.lnk @Paul : C:\Documents and Settings\Paul\Application Data\Leadertech\PowerRegister\Seagate NA0DYB3N Product Registration.exe -> DELETED
    [HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
    [HJ DESK] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost
    127.0.0.1 007guard.com
    127.0.0.1 www.007guard.com
    127.0.0.1 008i.com
    127.0.0.1 008k.com
    127.0.0.1 www.008k.com
    127.0.0.1 00hq.com
    127.0.0.1 www.00hq.com
    127.0.0.1 010402.com
    127.0.0.1 032439.com
    127.0.0.1 www.032439.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100888290cs.com
    127.0.0.1 100sexlinks.com
    127.0.0.1 www.100sexlinks.com
    127.0.0.1 10sek.com
    127.0.0.1 www.10sek.com
    127.0.0.1 123topsearch.com
    127.0.0.1 www.123topsearch.com
    127.0.0.1 132.com
    [...]
     
  12. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    I found another RK report

    Apparently, RogueKiller produced two reports, and I only posted the second report. Here is the first report:

    RogueKiller V8.4.0 [Dec 18 2012] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website : http://tigzy.geekstogo.com/roguekiller.php
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : Paul [Admin rights]
    Mode : Scan -- Date : 12/18/2012 20:58:56

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 4 ¤¤¤
    [STARTUP][SUSP PATH] Seagate NA0DYB3N Product Registration.lnk @Paul : C:\Documents and Settings\Paul\Application Data\Leadertech\PowerRegister\Seagate NA0DYB3N Product Registration.exe -> FOUND
    [HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    [HJ DESK] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost
    127.0.0.1 007guard.com
    127.0.0.1 www.007guard.com
    127.0.0.1 008i.com
    127.0.0.1 008k.com
    127.0.0.1 www.008k.com
    127.0.0.1 00hq.com
    127.0.0.1 www.00hq.com
    127.0.0.1 010402.com
    127.0.0.1 032439.com
    127.0.0.1 www.032439.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100888290cs.com
    127.0.0.1 100sexlinks.com
    127.0.0.1 www.100sexlinks.com
    127.0.0.1 10sek.com
    127.0.0.1 www.10sek.com
    127.0.0.1 123topsearch.com
    127.0.0.1 www.123topsearch.com
    127.0.0.1 132.com
    [...]


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: WDC WD2500JS-08NCB1 +++++
    --- User ---
    [MBR] 4a4b0c0d0a40c88d99794bdf1e1b8178
    [BSP] fef6cb1f32f32479539922e4a2ad9397 : Legit2 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 8803620 | Size: 234174 Mo
    1 - [XXXXXX] FAT32 (0x0b) [VISIBLE] Offset (sectors): 63 | Size: 4298 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive1: Seagate USB 3.0 Cable USB Device +++++
    --- User ---
    [MBR] bcc7cb6373f66937b39bac4f7ffad1b8
    [BSP] 5cab7fac78b6fe5301595cea6da44b25 : MBR Code unknown
    Partition table:
    0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 Mo
    User = LL1 ... OK!
    Error reading LL2 MBR!

    Finished : << RKreport[1]_S_12182012_02d2058.txt >>
    RKreport[1]_S_12182012_02d2058.txt
     
  13. 2012/12/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Create new restore point before proceeding with the next step....
    How to:
    - Windows 8: http://www.vikitech.com/11302/system-restore-windows-8
    - Windows 7: http://www.howtogeek.com/howto/3195/create-a-system-restore-point-in-windows-7/
    - Vista: http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/
    - XP: http://support.microsoft.com/kb/948247

    =============================

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
      If the connection is not there use restore point you created prior to running Combofix.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
     
  14. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    Must go walk the dog. Will be back ASAP.
     
  15. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    Bsod

    Broni:

    I'm sending you this via a nearby laptop. The desktop has crashed...

    I started running ComboFix after creating a restore point and disabling the Avast firewall and all seemed to be running fine. When I left to walk the dog it had completed Stage 5, I believe. Just got back and I've got a blue screen which reads:

    A problem has been detected and Windows has been shut down to prevent damage to your computer.

    Plug and Play detected an error most likely caused by a faulty driver.

    If this is the first time you've seen this Stop error screen, restart your computer. If this screen appears again, follow these steps:

    Check to make sure any new hardware or software is properly installed. f this is a new installation, ask your hardware or software manufacturer for any windows updates you may need.

    If problems continue, disable or remove any newly installed hardware or software. Disable BIOS memory options such as caching or shadowing. If you need to use safe mode to remove or disable components, restart your computer, press F8 to select advanced startup options, and then select Safe Mode.

    Technical information:

    *** STOP: 0x000000CA (0x00000004, 0x87CA8F10, 0x00000000, 0x00000000)

    Beginning dump of physical memory
    Physical memory dump complete.
    Contact your system administrator or technical support group for further assistance.

    What to do? A hard boot?

    Thanks - Paul
     
  16. 2012/12/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Yes, reboot and try again.
     
  17. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    ComboFix log

    Broni:

    The file produced after CF Finished was named "log.txt" rather than ComboFix.txt, but here it is:



    ComboFix 12-12-17.02 - Paul 12/18/2012 23:10:48.2.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1341 [GMT -5:00]
    Running from: c:\documents and settings\Paul\Desktop\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\Administrator\WINDOWS
    c:\documents and settings\All Users\Application Data\TEMP
    c:\documents and settings\All Users\Application Data\TEMP\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\PostBuild.exe
    c:\documents and settings\All Users\Application Data\TEMP\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\PostBuild.exe
    c:\documents and settings\All Users\Application Data\TEMP\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
    c:\documents and settings\All Users\Application Data\TEMP\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
    c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
    c:\documents and settings\All Users\Application Data\TEMP\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\PostBuild.exe
    c:\documents and settings\All Users\Application Data\TEMP\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\PostBuild.exe
    c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
    c:\documents and settings\Default User\WINDOWS
    c:\documents and settings\Guest\WINDOWS
    c:\documents and settings\LogMeInRemoteUser\WINDOWS
    c:\documents and settings\Paul\g2ax_customer_downloadhelper_win32_x86.exe
    c:\documents and settings\Paul\GoToAssistDownloadHelper.exe
    c:\documents and settings\Paul\My Documents\DPE.DUS
    c:\documents and settings\Paul\WINDOWS
    c:\windows\system32\config\systemprofile\WINDOWS
    c:\windows\system32\SET131.tmp
    c:\windows\system32\SET136.tmp
    c:\windows\system32\SET13D.tmp
    c:\windows\system32\SET14A.tmp
    c:\windows\system32\SETE1.tmp
    c:\windows\system32\SETE2.tmp
    c:\windows\system32\URTTemp
    c:\windows\system32\URTTemp\fusion.dll
    c:\windows\system32\URTTemp\mscoree.dll
    c:\windows\system32\URTTemp\mscoree.dll.local
    c:\windows\system32\URTTemp\mscorsn.dll
    c:\windows\system32\URTTemp\mscorwks.dll
    c:\windows\system32\URTTemp\msvcr71.dll
    c:\windows\system32\URTTemp\regtlib.exe
    D:\Autorun.inf
    D:\Setup.exe
    H:\Autorun.inf
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-11-19 to 2012-12-19 )))))))))))))))))))))))))))))))
    .
    .
    2012-12-17 17:20 . 2012-11-28 15:35 93640 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2012-12-17 16:50 . 2012-12-17 16:50 -------- d-----w- c:\program files\Common Files\Java
    2012-11-29 23:51 . 2012-11-29 23:51 -------- d-----w- c:\program files\iPod
    2012-11-29 23:51 . 2012-11-29 23:52 -------- d-----w- c:\program files\iTunes
    2012-11-29 23:51 . 2012-11-29 23:52 -------- d-----w- c:\documents and settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
    2012-11-29 23:45 . 2012-11-29 23:45 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
    2012-11-29 23:45 . 2012-11-29 23:45 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
    2012-11-29 23:45 . 2012-11-29 23:45 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
    2012-11-29 23:45 . 2012-11-29 23:45 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
    2012-11-29 23:45 . 2012-11-29 23:45 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
    2012-11-29 23:45 . 2012-11-29 23:45 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
    2012-11-29 23:45 . 2012-11-29 23:45 -------- d-----w- c:\program files\QuickTime
    2012-11-20 20:04 . 2012-12-03 21:08 -------- d-----w- c:\program files\Mozilla Maintenance Service
    2012-11-20 17:52 . 2012-08-21 18:01 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
    2012-11-20 17:50 . 2012-11-20 17:50 -------- d-----w- c:\program files\Apple Software Update
    2012-11-20 17:49 . 2012-11-20 17:49 -------- d-----w- c:\documents and settings\LocalService\Application Data\Apple Computer
    2012-11-20 17:49 . 2012-11-20 17:49 -------- d-----w- c:\program files\Bonjour
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-12-17 16:47 . 2012-08-30 16:52 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
    2012-12-17 16:47 . 2010-04-19 14:08 746984 ----a-w- c:\windows\system32\deployJava1.dll
    2012-12-06 00:54 . 2012-08-03 20:14 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2012-12-06 00:54 . 2011-06-02 14:34 73656 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-11-13 01:25 . 2005-04-13 16:56 1866368 ----a-w- c:\windows\system32\win32k.sys
    2012-11-06 00:41 . 2005-04-13 16:55 290560 ----a-w- c:\windows\system32\atmfd.dll
    2012-11-02 02:02 . 2005-04-13 16:55 375296 ----a-w- c:\windows\system32\dpnet.dll
    2012-11-01 12:17 . 2005-04-13 16:56 916992 ----a-w- c:\windows\system32\wininet.dll
    2012-11-01 12:17 . 2005-04-13 16:55 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2012-11-01 12:17 . 2005-04-13 16:55 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2012-11-01 00:35 . 2005-04-13 16:55 385024 ----a-w- c:\windows\system32\html.iec
    2012-10-30 22:51 . 2011-03-20 16:42 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2012-10-30 22:51 . 2011-03-20 16:41 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2012-10-30 22:51 . 2011-03-20 16:41 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2012-10-30 22:51 . 2011-03-20 16:41 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2012-10-30 22:51 . 2011-03-20 16:41 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2012-10-30 22:51 . 2011-03-20 16:41 89752 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2012-10-30 22:51 . 2011-03-20 16:42 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2012-10-30 22:51 . 2011-03-20 16:41 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2012-10-30 22:51 . 2011-03-20 16:41 41224 ----a-w- c:\windows\avastSS.scr
    2012-10-30 22:50 . 2011-03-20 16:41 227648 ----a-w- c:\windows\system32\aswBoot.exe
    2012-10-25 08:12 . 2012-10-25 08:12 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2012-10-25 08:12 . 2012-10-25 08:12 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2012-10-02 18:04 . 2005-04-13 16:56 58368 ----a-w- c:\windows\system32\synceng.dll
    2012-09-29 23:54 . 2011-06-15 23:35 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-09-28 15:32 . 2010-02-15 16:46 5989776 ----a-w- c:\windows\system32\usbaaplrc.dll
    2012-09-28 15:32 . 2010-02-15 16:46 44544 ----a-w- c:\windows\system32\drivers\usbaapl.sys
    2012-12-01 21:15 . 2012-12-01 21:14 262112 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @= "{472083B0-C522-11CF-8763-00608CC02F24} "
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
    @= "{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} "
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
    2012-11-08 21:58 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
    @= "{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} "
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
    2012-11-08 21:58 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
    @= "{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} "
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
    2012-11-08 21:58 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
    @= "{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} "
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
    2012-11-08 21:58 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WinPatrol "= "c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2010-10-01 329096]
    "avast "= "c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
    "Memeo AutoSync "= "c:\program files\Memeo\AutoSync\MemeoLauncher2.exe" [2010-04-16 144608]
    "Seagate Dashboard "= "c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe" [2011-06-01 79112]
    "APSDaemon "= "c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe" [2012-11-29 151952]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg "= "c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-07 68856]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-4-9 323646]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @=" "
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
    backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
    backup=c:\windows\pss\BigFix.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
    backup=c:\windows\pss\Bluetooth.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp psc 2000 Series.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk
    backup=c:\windows\pss\hp psc 2000 Series.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
    backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
    backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
    2004-10-13 22:00 57344 -c--a-w- c:\windows\ALCMTR.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
    2004-10-21 23:44 2744832 -c--a-w- c:\windows\ALCWZRD.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
    2004-05-18 02:30 543232 -c--a-w- c:\windows\zHotkey.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
    2009-06-04 01:59 103720 -c----w- c:\program files\CyberLink\Power2Go\CLMLSvc.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
    2005-08-05 18:56 64512 -c--a-w- c:\windows\ehome\ehtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    2010-07-31 16:44 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2010-09-18 17:54 136176 -----tw- c:\documents and settings\Paul\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
    2004-08-13 01:45 61952 -c--a-w- c:\windows\system32\Hdaudpropshortcut.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2004-12-01 16:55 126976 -c--a-w- c:\windows\system32\hkcmd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2004-12-01 17:00 155648 -c--a-w- c:\windows\system32\igfxtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
    2010-02-24 00:07 557056 -c--a-w- c:\program files\lg_fwupdate\fwupdate.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
    2010-09-16 18:13 2736128 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memeo Send]
    2009-11-05 00:29 236816 -c--a-w- c:\program files\Memeo\Memeo Send\MemeoLauncher.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mixersel]
    2003-11-10 23:23 369664 -c--a-w- c:\program files\Realtek\InstallShield\mixersel.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
    2009-04-16 04:54 50472 -c----w- c:\program files\CyberLink\PowerDVD8\Language\Language.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2012-10-25 08:12 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
    2002-09-14 07:42 212992 -c--a-w- c:\windows\SMINST\Recguard.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
    2005-03-09 12:49 966656 -c--a-w- c:\windows\creator\remind_xp.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
    2004-11-03 04:24 32768 -c--a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
    2009-04-16 04:52 91432 -c----w- c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowWnd]
    2009-11-05 08:48 36864 -c--a-w- c:\windows\ShowWnd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    2004-10-21 20:20 77824 -c--a-w- c:\windows\SOUNDMAN.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunKistEM]
    2004-11-15 23:04 135168 -c--a-w- c:\program files\Digital Media Reader\shwiconEM.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2008-01-07 04:12 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "KodakCCS "=2 (0x2)
    "WMPNetworkSvc "=3 (0x3)
    "LightScribeService "=2 (0x2)
    "JavaQuickStarterService "=2 (0x2)
    "Apple Mobile Device "=2 (0x2)
    "iPod Service "=3 (0x3)
    "PrismXL "=2 (0x2)
    "Pml Driver HPZ12 "=2 (0x2)
    "McciCMService "=2 (0x2)
    "idsvc "=3 (0x3)
    "ppped "=2 (0x2)
    "gusvc "=3 (0x3)
    "GoogleDesktopManager-051210-111108 "=3 (0x3)
    "RichVideo "=2 (0x2)
    "Bonjour Service "=2 (0x2)
    "btwdins "=2 (0x2)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
    "UCam_Menu "= "c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "c:\program files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0 "
    "UpdateLBPShortCut "= "c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\program files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5 "
    "UpdateP2GoShortCut "= "c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\program files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0 "
    "UpdatePPShortCut "= "c:\program files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "c:\program files\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0 "
    "UpdatePSTShortCut "= "c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "c:\program files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter "
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe "
    "VMware hqtray "= "c:\program files\VMware\VMware Player\hqtray.exe "
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe "=
    "c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe "=
    "c:\\WINDOWS\\system32\\sessmgr.exe "=
    "c:\\WINDOWS\\system32\\mmc.exe "=
    "c:\\Documents and Settings\\Paul\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe "=
    "c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe "=
    "c:\\WINDOWS\\system32\\dpvsetup.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\iTunes\\iTunes.exe "=
    "c:\\Program Files\\Seagate\\Seagate Dashboard\\HipServAgent\\HipServAgent.exe "=
    "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "57973:TCP "= 57973:TCP:*:Disabled:pando P2P TCP Listening Port
    "57973:UDP "= 57973:UDP:*:Disabled:pando P2P UDP Listening Port
    .
    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 25680]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [3/20/2011 11:41 AM 738504]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/20/2011 11:42 AM 361032]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/12/2010 1:19 PM 299984]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/20/2011 11:42 AM 21256]
    R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackupPro\MemeoBackgroundService.exe [4/22/2010 7:49 PM 25824]
    R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [6/1/2011 11:42 AM 14088]
    R3 MOSUMAC;USB-Ethernet Driver;c:\windows\system32\drivers\MOSUMAC.SYS [9/28/2012 4:49 PM 40960]
    S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [10/8/2010 3:57 PM 100560]
    S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
    S4 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2/12/2010 8:41 PM 30192]
    S4 ldb;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2010-09-16 18:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-12-19 c:\windows\Tasks\avast! Emergency Update.job
    - c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-24 22:50]
    .
    2012-12-18 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-01-06 21:13]
    .
    2012-12-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2367648578-2664592681-1860400956-1009Core.job
    - c:\documents and settings\Paul\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-18 17:54]
    .
    2012-12-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2367648578-2664592681-1860400956-1009UA.job
    - c:\documents and settings\Paul\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-18 17:54]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.wral.com
    uInternet Settings,ProxyOverride = 127.0.0.1;*.local
    Trusted Zone: durhamtech.edu\blackboard
    TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
    FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\0gasbm2g.default\
    FF - ExtSQL: 2012-11-09 10:07; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
    FF - ExtSQL: !HIDDEN! 2010-04-21 17:12; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    SafeBoot-02167890.sys
    SafeBoot-53850255.sys
    MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    MSConfigStartUp-AOL Spyware Protection - c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    MSConfigStartUp-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
    MSConfigStartUp-NeroFilterCheck - c:\windows\system32\NeroCheck.exe
    MSConfigStartUp-PowerPanel Personal Edition User Interaction - c:\program files\CyberPower PowerPanel Personal Edition\pppeuser.exe
    MSConfigStartUp-sealmon - c:\program files\Oracle\Information Rights Management\Desktop\sealmon.exe
    MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_03\bin\jusched.exe
    MSConfigStartUp-Verizon_McciTrayApp - c:\program files\Verizon\McciTrayApp.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-12-18 23:21
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @= "FlashBroker "
    "LocalizedString "= "@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @= "c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @= "IFlashBroker5 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @= "{00020424-0000-0000-C000-000000000046} "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    "Version "= "1.0 "
    .
    Completion time: 2012-12-18 23:24:54
    ComboFix-quarantined-files.txt 2012-12-19 04:24
    .
    Pre-Run: 200,900,603,904 bytes free
    Post-Run: 200,982,343,680 bytes free
    .
    - - End Of File - - 9C5D4761A2EAF6F5F26215ECE44FC0E3
     
  18. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    Hi Broni:

    It's getting late out here on the East Coast, and I'd better get some shuteye. I've got an early morning appt., but will check back tomorrow as soon as I can.

    If you have suggestions for me I'll get to them ASAP tomorrow.

    Thanks again for all your help!
     
  19. 2012/12/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Combofix log looks good.

    Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    Next...

    • Double click on adwcleaner.exe to run the tool.
    • Click on Uninstall.
    • Confirm with yes.

    ===========================

    Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  20. 2012/12/18
    Paulie634

    Paulie634 Inactive Thread Starter

    Joined:
    2012/12/17
    Messages:
    56
    Likes Received:
    0
    AdwCleaner logfile

    Broni:

    I stayed up a little later to see if you'd respond before I actually hit the sack;

    Here are the results of the AdwCleaner scan:

    # AdwCleaner v2.101 - Logfile created 12/19/2012 at 00:06:18
    # Updated 16/12/2012 by Xplode
    # Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
    # User : Paul - PCDS-BUSINESS
    # Boot Mode : Normal
    # Running from : C:\Documents and Settings\Paul\Desktop\adwcleaner.exe
    # Option [Delete]


    ***** [Services] *****


    ***** [Files / Folders] *****


    ***** [Registry] *****

    Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
    Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
    Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
    Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
    Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
    Key Deleted : HKLM\Software\TENCENT
    Key Deleted : HKLM\Software\Viewpoint

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v8.0.6001.18702

    [OK] Registry is clean.

    -\\ Mozilla Firefox v17.0.1 (en-US)

    Profile name : default
    File : C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\0gasbm2g.default\prefs.js

    [OK] File is clean.

    -\\ Google Chrome v23.0.1271.97

    File : C:\Documents and Settings\Paul\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

    [OK] File is clean.

    *************************

    AdwCleaner[S1].txt - [1482 octets] - [19/12/2012 00:06:18]


    _____________________________________________________________

    I will await further instructions, sir, and get on them asap tomorrow.

    Again, thanks!

    Best, Paul
     
  21. 2012/12/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Otl?..
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.