Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

2 Instances Of Trojans-gen Found


  • This topic is locked This topic is locked
12 replies to this topic

#1 JBBIGQ

JBBIGQ

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:30 AM

Posted 18 September 2008 - 12:39 PM

Hi,
New here. My last 2 avast scans show Trojan virus present. I need assistance getting rid of them please.
I was going to include a list of the anti spyware programs I use but I don't know how to insert the .bmp image of that folder. Is that possible here? I run them on a fairly regular basis ( but apparently not often enough) mainly CCleaner, AdAware,Spybot, recently added Malwarebyte. Oh I think I figured it out how to upload the screenshot .bmp.

Attached File  cleaners.JPG   109.9KB   3 downloads


Thanks in advance for any assistance
JBBIGQ


From Sept 11 08

C:\WINDOWS\TrueProcess.exe [L] Win32:Trojan-gen {Other} (0)

from Sept 18 08
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\ RP572\A0065120.exe [L] Win32:Trojan-gen {Other} (0)

Does this mean the virus is embedded in the restore point and not working unless I activate it??? Is it the same one from 9/11/08?

Anyway here is my info HiJack this list to follow.
System Configuration Summary
================================================
Operating System Windows XP (5.01.2600)
Internet Explorer 7.00.5730.0011
MSN Client 9.50.0039.1900
MSN Market en-us
MSN Brand MSN [Q002]
MSN SKU Qwest Choice DSL with MSN
Default E-mail Program MSN Explorer

Amount of Memory 0.99 GB
Free Disk Space C: 80.1 GB, D: 20.9 GB

Component versions
================================================
msn.exe 9.50.0039.1900
msnmetal.dll 9.50.0039.1900
msnmtllc.dll 9.50.0039.1900
msdbx.dll 9.50.0039.1900
msnap.dat 9.05.6001.0001
msnap.dll 1.00.4611.0000
sqdll.dll 12.2002.1126.0001
update.exe 9.50.0039.1900
shdocvw.dll 6.00.2900.5512
qmgr.dll 6.07.2600.5512
dw15.exe 10.00.4413.0000
dwintl.dll 10.00.2625.0000
canvas.dll 2.00.0420.0000
connectr.dll 2.00.0420.0000
logonmgr.exe 2.00.0420.0000
msncc.exe 2.00.0420.0000
msnccore.dll 2.00.0420.0000
slhelper.dll 2.00.0420.0000
msninst.exe 9.50.0485.0000
msninst.dll 9.50.0485.0000
msnsign.dll 9.50.0485.0000
market.mar 9.2007.0320.01
brand.mar 9.50.0000.0000
Windows Media Player 11.00.5721.5145
Windows Live Messenger 8.01.0178.0000
Macromedia Flash 9.00.0124.0000

SQLLite Versions
================================================
jbbigq@msn.com 2.0
jblvswmn@msn.com 2.0
jdbigq@msn.com 2.0
mchughspools@msn.com 2.0
pgbook@msn.com 2.0

Network drivers
================================================
Intel® PRO/100 VE Network Connection (8.0.15.0)
e100b325.sys (8.00.0015.0000)
WAN Miniport (L2TP) (5.1.2535.0)
rasl2tp.sys (5.01.2600.5512)
WAN Miniport (IP) (5.1.2535.0)
ndiswan.sys (5.01.2600.5512)
WAN Miniport (PPPOE) (5.1.2535.0)
raspppoe.sys (5.01.2600.5512)
WAN Miniport (PPTP) (5.1.2535.0)
raspptp.sys (5.01.2600.5512)
Packet Scheduler Miniport (5.1.2535.0)
psched.sys (5.01.2600.5512)
Packet Scheduler Miniport (5.1.2535.0)
psched.sys (5.01.2600.5512)
Direct Parallel (5.1.2535.0)
raspti.sys (5.01.2600.0000)
WAN Miniport (ATW) (8.3.0.0)
wanatw4.sys (8.03.0000.0000)

Modem drivers
================================================
Conexant D850 56K V.9x DFVc Modem (7.6.0.50)
Modem.sys (5.01.2600.5512)

Auto-update status
================================================
Previous version: 9.20.0026.0800
Next version: (none)

Avast log from 9/11/08

Date/Time File/Object Status
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar10.zip\sbRecovery.reg [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar10.zip\sbRecovery.ini [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar12.zip\sbRecovery.reg [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar12.zip\sbRecovery.ini [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar13.zip\sbRecovery.reg [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar13.zip\sbRecovery.ini [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar7.zip\sbRecovery.reg [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar7.zip\sbRecovery.ini [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar8.zip\sbRecovery.reg [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar8.zip\sbRecovery.ini [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar9.zip\sbRecovery.reg [E] Archive is password protected. (42056)
1:17:51 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar9.zip\sbRecovery.ini [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-07-2008 - 17-08-11.SBU\ {83755133-B8A0-42A4-B62C-34DAB26C06B9} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-07-2008 - 17-08-11.SBU\ backup.db [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {09EA09E0-5D23-4125-A06A-C62CABBBF53E} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {0CB03655-2226-4E17-9EBE-8B617F1EA69E} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {2916C2B7-94B5-48C4-8A21-D7049C52CEAC} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {350CBC9F-44E6-4484-A3AC-70113A4E085E} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {37DF7913-315C-495C-A09E-7758D7445178} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {3A0F5B87-B70E-475D-B4C3-5FCBD201570A} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {3B5E9F9C-6336-44DC-B00A-15B53651ADB7} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {3D91C01C-BB3E-4FB5-98AD-DE56FF1A834B} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {438407BA-0B53-477B-A31D-805F97C6E887} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {5769BD92-A8EF-412C-BB0F-4439CEFC1D88} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {5A227DCC-903B-4CAF-981B-97F8D72F41B5} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {5B0E9AE3-E31F-409A-9CEA-225D09C66A73} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {62D4696A-2A22-4B01-BEA3-7146B18D9393} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {630E1AA3-416E-4239-B8E6-B80CAF10DB94} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {6BFA56FB-9457-44DC-9245-3D53AB1D8281} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {8F891942-BBC5-4BB5-A7C8-F1C898951E81} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {8FF41770-27D6-486D-B317-F8A690495C29} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {94F85B7E-B14A-4C99-9812-98A24C2EC721} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {97D40B8C-1813-4B44-96A7-658C3197104D} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {9864EF92-2B52-4FED-AF82-542D315B2642} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {9ADE2422-C683-4A80-8A0F-92454B29E43A} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {9D828168-FD5D-41DA-A6AE-2C6F0E4E9CEE} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {9DD56F1E-6583-42EE-8C44-54255452F84C} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {9FAA42C0-4AD6-4C09-9364-DE53BE79190F} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {A439A7B5-162E-44F9-8382-BBE7081BDA22} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {B1978428-04F7-487D-B5E0-ECDAFD0D29F4} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {B5279829-B184-4C68-BD8E-FB5E946D2AA7} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {B609DC89-FA53-42A7-8D24-9D7577FBC474} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {B9CDBDF4-DFD6-4C31-84D8-38285FD37ADB} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {D7E34B34-3524-421C-8191-5DCFF4362A65} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {D7FB6128-B43C-4D5A-9392-2511DA1B9D11} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {DB7F004D-DB9F-48EB-9792-59145C4BB7A8} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {E610D27B-5D63-4662-BC3A-1D65F80043FB} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ backup.db [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {0731C643-98E9-411B-9AA6-D38C4558BFC7} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {15B9ACEF-DEE2-43FD-B34D-876681DFED12} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {18E7E417-16C5-43F1-A43B-9872F1DA49E2} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {1A3043C0-A2D5-4F86-AE92-29E2CA23DA46} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {1BDCC9D3-BF3A-468E-A3C9-BD5BFED8D8C5} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {20FAD23C-B063-4E8B-95C7-61950DB5344C} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {4273D780-8FF9-4386-866C-C50355226F46} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {49451611-A7C3-4FA9-B9E7-D8C0C5372AC3} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {5FD286B1-9F3A-4FDE-BD3B-CCE918B3D144} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {69BBD0A3-FEA8-4D53-9965-07FFAACA538A} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {720953E8-C0C2-448A-B221-4887C760256D} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {7CBB4997-01C3-491E-83DF-2AA8FC111504} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {86870291-E0B9-4E2C-AB2D-C060C58625AB} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {92B7D29B-5E19-4197-B4EB-88C3B9AAC5B6} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {A81F8872-A736-4849-BFAA-4E19C270BAEF} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {AC168EF9-2090-4BE7-8430-E649A5F29170} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {C30F8E12-EB19-426F-9E8A-690890473A56} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {C5C97343-A661-4614-94C4-979DFE20753B} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {CCCAA6C0-ABF9-4DAC-8F9D-7E1331A9C1CF} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {CFAC06E7-E14E-45CA-9A34-F9E965766FEC} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {DFE02BAC-F3EE-4925-B3C0-63C66F059997} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {EA40B7BF-D4BF-40AB-B309-340BA7D227AE} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {F6DDCEF4-5290-4159-B9C1-899A006C9755} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {F881C65B-E44A-486B-A156-21304806A094} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {FD37A9C1-F810-4920-8B56-2085446F6145} [E] Archive is password protected. (42056)
1:22:46 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ backup.db [E] Archive is password protected. (42056)
1:56:59 AM C:\Documents and Settings\Jim\Local Settings\Application Data\Microsoft\ Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
1:56:59 AM C:\Documents and Settings\Jim\Local Settings\Application Data\Microsoft\ Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
2:14:14 AM C:\Documents and Settings\Jim\ntuser.dat [E] The process cannot access the file because it is being used by another process (32)
2:14:14 AM C:\Documents and Settings\Jim\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
2:14:17 AM C:\Documents and Settings\LocalService\Local Settings\Application Data\ Microsoft\Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
2:14:17 AM C:\Documents and Settings\LocalService\Local Settings\Application Data\ Microsoft\Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
2:14:18 AM C:\Documents and Settings\LocalService\NTUSER.DAT [E] The process cannot access the file because it is being used by another process (32)
2:14:18 AM C:\Documents and Settings\LocalService\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
2:14:18 AM C:\Documents and Settings\NetworkService\Local Settings\Application Data\ Microsoft\Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
2:14:18 AM C:\Documents and Settings\NetworkService\Local Settings\Application Data\ Microsoft\Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
2:14:18 AM C:\Documents and Settings\NetworkService\NTUSER.DAT [E] The process cannot access the file because it is being used by another process (32)
2:14:18 AM C:\Documents and Settings\NetworkService\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
2:14:24 AM C:\hiberfil.sys [E] The process cannot access the file because it is being used by another process (32)
2:22:12 AM C:\pagefile.sys [E] The process cannot access the file because it is being used by another process (32)
3:21:01 AM C:\WINDOWS\system32\config\DEFAULT [E] The process cannot access the file because it is being used by another process (32)
3:21:01 AM C:\WINDOWS\system32\config\default.LOG [E] The process cannot access the file because it is being used by another process (32)
3:21:01 AM C:\WINDOWS\system32\config\SAM [E] The process cannot access the file because it is being used by another process (32)
3:21:01 AM C:\WINDOWS\system32\config\SAM.LOG [E] The process cannot access the file because it is being used by another process (32)
3:21:01 AM C:\WINDOWS\system32\config\SECURITY [E] The process cannot access the file because it is being used by another process (32)
3:21:01 AM C:\WINDOWS\system32\config\SECURITY.LOG [E] The process cannot access the file because it is being used by another process (32)
3:21:01 AM C:\WINDOWS\system32\config\SOFTWARE [E] The process cannot access the file because it is being used by another process (32)
3:21:01 AM C:\WINDOWS\system32\config\software.LOG [E] The process cannot access the file because it is being used by another process (32)
3:21:04 AM C:\WINDOWS\system32\config\SYSTEM [E] The process cannot access the file because it is being used by another process (32)
3:21:04 AM C:\WINDOWS\system32\config\system.LOG [E] The process cannot access the file because it is being used by another process (32)
3:24:57 AM C:\WINDOWS\temp\Perflib_Perfdata_580.dat [E] The process cannot access the file because it is being used by another process (32)
3:24:57 AM C:\WINDOWS\temp\_avast4_\Webshlock.txt [E] The process cannot access the file because it is being used by another process (32)
3:24:58 AM C:\WINDOWS\TrueProcess.exe [L] Win32:Trojan-gen {Other} (0)



Start of testing: Thursday, September 11, 2008



Avast log 9/18/08


Avast Anti virus
Start of testing: Thursday, September 18, 2008 12:40:31 AM
End of testing: Thursday, September 18, 2008 7:37:12 AM
Virus Database:
Date/Time File/Object Status
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar10.zip\sbRecovery.reg [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar10.zip\sbRecovery.ini [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar12.zip\sbRecovery.reg [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar12.zip\sbRecovery.ini [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar13.zip\sbRecovery.reg [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar13.zip\sbRecovery.ini [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar7.zip\sbRecovery.reg [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar7.zip\sbRecovery.ini [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar8.zip\sbRecovery.reg [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar8.zip\sbRecovery.ini [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar9.zip\sbRecovery.reg [E] Archive is password protected. (42056)
12:42:58 AM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\ Recovery\CouponBar9.zip\sbRecovery.ini [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-07-2008 - 17-08-11.SBU\ {83755133-B8A0-42A4-B62C-34DAB26C06B9} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-07-2008 - 17-08-11.SBU\ backup.db [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {09EA09E0-5D23-4125-A06A-C62CABBBF53E} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {0CB03655-2226-4E17-9EBE-8B617F1EA69E} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {2916C2B7-94B5-48C4-8A21-D7049C52CEAC} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {350CBC9F-44E6-4484-A3AC-70113A4E085E} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {37DF7913-315C-495C-A09E-7758D7445178} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {3A0F5B87-B70E-475D-B4C3-5FCBD201570A} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {3B5E9F9C-6336-44DC-B00A-15B53651ADB7} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {3D91C01C-BB3E-4FB5-98AD-DE56FF1A834B} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {438407BA-0B53-477B-A31D-805F97C6E887} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {5769BD92-A8EF-412C-BB0F-4439CEFC1D88} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {5A227DCC-903B-4CAF-981B-97F8D72F41B5} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {5B0E9AE3-E31F-409A-9CEA-225D09C66A73} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {62D4696A-2A22-4B01-BEA3-7146B18D9393} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {630E1AA3-416E-4239-B8E6-B80CAF10DB94} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {6BFA56FB-9457-44DC-9245-3D53AB1D8281} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {8F891942-BBC5-4BB5-A7C8-F1C898951E81} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {8FF41770-27D6-486D-B317-F8A690495C29} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {94F85B7E-B14A-4C99-9812-98A24C2EC721} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {97D40B8C-1813-4B44-96A7-658C3197104D} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {9864EF92-2B52-4FED-AF82-542D315B2642} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {9ADE2422-C683-4A80-8A0F-92454B29E43A} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {9D828168-FD5D-41DA-A6AE-2C6F0E4E9CEE} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {9DD56F1E-6583-42EE-8C44-54255452F84C} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {9FAA42C0-4AD6-4C09-9364-DE53BE79190F} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {A439A7B5-162E-44F9-8382-BBE7081BDA22} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {B1978428-04F7-487D-B5E0-ECDAFD0D29F4} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {B5279829-B184-4C68-BD8E-FB5E946D2AA7} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {B609DC89-FA53-42A7-8D24-9D7577FBC474} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {B9CDBDF4-DFD6-4C31-84D8-38285FD37ADB} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {D7E34B34-3524-421C-8191-5DCFF4362A65} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {D7FB6128-B43C-4D5A-9392-2511DA1B9D11} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {DB7F004D-DB9F-48EB-9792-59145C4BB7A8} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ {E610D27B-5D63-4662-BC3A-1D65F80043FB} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 06-20-2008 - 09-03-27.SBU\ backup.db [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {0731C643-98E9-411B-9AA6-D38C4558BFC7} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {15B9ACEF-DEE2-43FD-B34D-876681DFED12} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {18E7E417-16C5-43F1-A43B-9872F1DA49E2} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {1A3043C0-A2D5-4F86-AE92-29E2CA23DA46} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {1BDCC9D3-BF3A-468E-A3C9-BD5BFED8D8C5} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {20FAD23C-B063-4E8B-95C7-61950DB5344C} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {4273D780-8FF9-4386-866C-C50355226F46} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {49451611-A7C3-4FA9-B9E7-D8C0C5372AC3} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {5FD286B1-9F3A-4FDE-BD3B-CCE918B3D144} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {69BBD0A3-FEA8-4D53-9965-07FFAACA538A} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {720953E8-C0C2-448A-B221-4887C760256D} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {7CBB4997-01C3-491E-83DF-2AA8FC111504} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {86870291-E0B9-4E2C-AB2D-C060C58625AB} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {92B7D29B-5E19-4197-B4EB-88C3B9AAC5B6} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {A81F8872-A736-4849-BFAA-4E19C270BAEF} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {AC168EF9-2090-4BE7-8430-E649A5F29170} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {C30F8E12-EB19-426F-9E8A-690890473A56} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {C5C97343-A661-4614-94C4-979DFE20753B} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {CCCAA6C0-ABF9-4DAC-8F9D-7E1331A9C1CF} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {CFAC06E7-E14E-45CA-9A34-F9E965766FEC} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {DFE02BAC-F3EE-4925-B3C0-63C66F059997} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {EA40B7BF-D4BF-40AB-B309-340BA7D227AE} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {F6DDCEF4-5290-4159-B9C1-899A006C9755} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {F881C65B-E44A-486B-A156-21304806A094} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ {FD37A9C1-F810-4920-8B56-2085446F6145} [E] Archive is password protected. (42056)
12:47:39 AM C:\Documents and Settings\Jim\Application Data\SUPERAntiSpyware.com\ SUPERAntiSpyware\Quarantine\Quarantine - 08-24-2008 - 17-12-08.SBU\ backup.db [E] Archive is password protected. (42056)
1:20:39 AM C:\Documents and Settings\Jim\Local Settings\Application Data\Microsoft\ Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
1:20:39 AM C:\Documents and Settings\Jim\Local Settings\Application Data\Microsoft\ Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
1:21:19 AM C:\Documents and Settings\Jim\Local Settings\Temp\tmp921.tmp [E] The process cannot access the file because it is being used by another process (32)
1:21:20 AM C:\Documents and Settings\Jim\Local Settings\Temp\~DF893F.tmp [E] The process cannot access the file because it is being used by another process (32)
1:37:33 AM C:\Documents and Settings\Jim\ntuser.dat [E] The process cannot access the file because it is being used by another process (32)
1:37:33 AM C:\Documents and Settings\Jim\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
1:37:36 AM C:\Documents and Settings\LocalService\Local Settings\Application Data\ Microsoft\Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
1:37:36 AM C:\Documents and Settings\LocalService\Local Settings\Application Data\ Microsoft\Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
1:37:36 AM C:\Documents and Settings\LocalService\NTUSER.DAT [E] The process cannot access the file because it is being used by another process (32)
1:37:36 AM C:\Documents and Settings\LocalService\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
1:37:36 AM C:\Documents and Settings\NetworkService\Local Settings\Application Data\ Microsoft\Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
1:37:36 AM C:\Documents and Settings\NetworkService\Local Settings\Application Data\ Microsoft\Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
1:37:37 AM C:\Documents and Settings\NetworkService\NTUSER.DAT [E] The process cannot access the file because it is being used by another process (32)
1:37:37 AM C:\Documents and Settings\NetworkService\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
1:37:42 AM C:\hiberfil.sys [E] The process cannot access the file because it is being used by another process (32)
1:45:00 AM C:\pagefile.sys [E] The process cannot access the file because it is being used by another process (32)
2:19:27 AM C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\ RP572\A0065120.exe [L] Win32:Trojan-gen {Other} (0)
7:32:54 AM C:\WINDOWS\SoftwareDistribution\EventCache\{87F057DB-8D18-43EB-B934-A9A648AE0B52}.bin [E] The process cannot access the file because it is being used by another process (32)
7:33:12 AM C:\WINDOWS\system32\CatRoot2\edb.log [E] The process cannot access the file because it is being used by another process (32)
7:33:12 AM C:\WINDOWS\system32\CatRoot2\tmp.edb [E] The process cannot access the file because it is being used by another process (32)
7:33:17 AM C:\WINDOWS\system32\config\DEFAULT [E] The process cannot access the file because it is being used by another process (32)
7:33:17 AM C:\WINDOWS\system32\config\default.LOG [E] The process cannot access the file because it is being used by another process (32)
7:33:17 AM C:\WINDOWS\system32\config\SAM [E] The process cannot access the file because it is being used by another process (32)
7:33:17 AM C:\WINDOWS\system32\config\SAM.LOG [E] The process cannot access the file because it is being used by another process (32)
7:33:17 AM C:\WINDOWS\system32\config\SECURITY [E] The process cannot access the file because it is being used by another process (32)
7:33:17 AM C:\WINDOWS\system32\config\SECURITY.LOG [E] The process cannot access the file because it is being used by another process (32)
7:33:17 AM C:\WINDOWS\system32\config\SOFTWARE [E] The process cannot access the file because it is being used by another process (32)
7:33:17 AM C:\WINDOWS\system32\config\software.LOG [E] The process cannot access the file because it is being used by another process (32)
7:33:20 AM C:\WINDOWS\system32\config\SYSTEM [E] The process cannot access the file because it is being used by another process (32)
7:33:20 AM C:\WINDOWS\system32\config\system.LOG [E] The process cannot access the file because it is being used by another process (32)
7:36:59 AM C:\WINDOWS\temp\Perflib_Perfdata_4d0.dat [E] The process cannot access the file because it is being used by another process (32)
7:36:59 AM C:\WINDOWS\temp\Perflib_Perfdata_580.dat [E] The process cannot access the file because it is being used by another process (32)
7:36:59 AM C:\WINDOWS\temp\_avast4_\Webshlock.txt [E] The process cannot access the file because it is being used by another process (32)

HJT LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:51:40 AM, on 9/18/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Documents and Settings\Jim\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\PermissionTV\bin\dmtray.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\PROGRA~1\PERMIS~1\bin\dm.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN\MSNCoreFiles\MSN.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\dlbucoms.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LxrAutorun] C:\Documents and Settings\Jim\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Pima County Public Library Tray App.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1156453173265
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://poolcorp.webex.com/client/T23L/support/ieatgpc.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PermissionTV Download Manager Service (PermissionTVDownloadManager) - PermissionTV - C:\PROGRA~1\PERMIS~1\bin\dm.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

--
End of file - 9595 bytes





How long should I leave or how often should I clean out the quarentine files of Spybot Adaware etc. Am I right in thinking leaving those file in there just causes my antivirus program to run longer determining they are archive and not readable???

Thanks again

BC AdBot (Login to Remove)

 


m

#2 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:30 AM

Posted 29 September 2008 - 07:14 PM

:thumbsup: to BleepingComputer.com

I want to apologise that it has taken so long to get back to you. We on the HJT Team are working as fast as possible to get your log answered.

If you would still like help, please post a new HiJack This log below, as things may have changed on your system.

If you do not still need help, please let me know, so that I can move on to other users who still need help.

Please take note of the following:
  • While a HJT Team member is working with you, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. :)
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Please reply using the Posted Image button in the lower left hand corner of your screen.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave, and if there is no contact for that amount of time I will have to assume you have "vanished" :).
Please do an online scan with Kaspersky WebScanner.
  • Please visit the Kaspersky Online Scanner website.
    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
In your next reply, please include the following:
  • Kaspersky's Log
  • A New HiJack This log

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#3 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:30 AM

Posted 02 October 2008 - 03:49 PM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#4 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:30 AM

Posted 11 October 2008 - 04:02 PM

Hello, JBBIGQ.

Please ignore the above instructions as I have changed them recently :)

:thumbsup: to BleepingComputer.com

My name is Billy O'Neal and I will be helping you. (Billy or Bill is fine, if you like.)

I want to apologise that it has taken so long to get back to you. We on the HJT Team are working as fast as possible to get your log answered.

If you do not still need help, please let me know, so that I can move on to other users who still need help.

Please take note of the following:
  • While a HJT Team member is working with you, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. :)
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Please reply using the Posted Image button in the lower left hand corner of your screen.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave, and if there is no contact for that amount of time I will have to assume you have "vanished" :).
If you would still like help, please follow the instructions below:

We need to create an OTViewIt Report
  • Please download OTViewIt by OldTimer.
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
  • OTViewIt.txt <-- Will be opened
  • Extra.txt <-- Will be minimized
Please do an online scan with Kaspersky WebScanner.
  • Please visit the Kaspersky Online Scanner website.
    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
In your next reply, please include the following:
  • OTViewIt.txt
  • Extra.txt
  • Kaspersky's Log


Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#5 JBBIGQ

JBBIGQ
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:30 AM

Posted 11 October 2008 - 04:16 PM

OK here's the new info + I have a question about something odd I found when I ran HJT. I was looking at the backups saved and there is one dated 11-05-08 ??? How is that possible. I will include a screenshot I took. Can you explain that? In looking at the HJT log nothing jumps out as a problem, but I will give in your expertise. Thanks again
JB

Attached File  strange_HJT_backup.JPG   93.23KB   4 downloads

Kaspersky

KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, October 11, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, October 11, 2008 07:50:39
Records in database: 1305009

Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area My Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\

Scan statistics
Files scanned 114593
Threat name 4
Infected objects 89
Suspicious objects 0
Duration of the scan 1:49:15

File name Threat name Threats count
csrss.exe\swpg.dat/csrss.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

C:\Program Files\Spyware Doctor\tools\swpg.dat/C:\Program Files\Spyware Doctor\tools\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 42

winlogon.exe\swpg.dat/winlogon.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

services.exe\swpg.dat/services.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

lsass.exe\swpg.dat/lsass.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

svchost.exe\swpg.dat/svchost.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 9

aawservice.exe\swpg.dat/aawservice.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

explorer.exe\swpg.dat/explorer.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

dlbubmgr.exe\swpg.dat/dlbubmgr.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

memcard.exe\swpg.dat/memcard.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

apdproxy.exe\swpg.dat/apdproxy.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

dlbubmon.exe\swpg.dat/dlbubmon.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

realsched.exe\swpg.dat/realsched.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

spoolsv.exe\swpg.dat/spoolsv.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

jusched.exe\swpg.dat/jusched.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

LxrAutorun.exe\swpg.dat/LxrAutorun.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

wmpnscfg.exe\swpg.dat/wmpnscfg.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

ehrecvr.exe\swpg.dat/ehrecvr.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

ehSched.exe\swpg.dat/ehSched.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

GoogleUpdaterService.exe\swpg.dat/GoogleUpdaterService.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

LxrSII1s.exe\swpg.dat/LxrSII1s.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

dm.exe\swpg.dat/dm.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

sdhelp.exe\swpg.dat/sdhelp.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

mcrdsvc.exe\swpg.dat/mcrdsvc.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

wmpnetwk.exe\swpg.dat/wmpnetwk.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

fxssvc.exe\swpg.dat/fxssvc.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

CALMAIN.exe\swpg.dat/CALMAIN.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

dllhost.exe\swpg.dat/dllhost.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

alg.exe\swpg.dat/alg.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

msn.exe\swpg.dat/msn.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

usnsvc.exe\swpg.dat/usnsvc.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

ashDisp.exe\swpg.dat/ashDisp.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

iexplore.exe\swpg.dat/iexplore.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

wscntfy.exe\swpg.dat/wscntfy.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

ScanningProcess.exe\swpg.dat/ScanningProcess.exe\swpg.dat Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

C:\Documents and Settings\Jim\.housecall6.6\Quarantine\backup-20061219-160320-691.dll.bac_a02940 Infected: not-a-virus:AdWare.Win32.Coupons.h 1

C:\Documents and Settings\Jim\Desktop\desktop stuff various folders\11-26-07\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1

C:\Program Files\MUSICMATCH\Common\ComponentMgr\HoldingArea\WebSys2\WebSys.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1

C:\Program Files\MUSICMATCH\Musicmatch Jukebox\WebSys\offline.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1

C:\Program Files\Spyware Doctor\tools\swpg.DAT Infected: not-a-virus:Monitor.Win32.KeyLogger.dq 1

The selected area was scanned.


Next HJT logfile
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:10:51 AM, on 10/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Documents and Settings\Jim\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\PROGRA~1\PERMIS~1\bin\dm.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN\MSNCoreFiles\MSN.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\mspaint.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LxrAutorun] C:\Documents and Settings\Jim\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O4 - Startup: Pima County Public Library Tray App.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1156453173265
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://poolcorp.webex.com/client/T23L/support/ieatgpc.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PermissionTV Download Manager Service (PermissionTVDownloadManager) - PermissionTV - C:\PROGRA~1\PERMIS~1\bin\dm.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

--
End of file - 9297 bytes

#6 JBBIGQ

JBBIGQ
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:30 AM

Posted 11 October 2008 - 04:21 PM

OTViewIt.txt
Extra.txt

Logs to follow
THX JB

#7 JBBIGQ

JBBIGQ
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:30 AM

Posted 11 October 2008 - 04:27 PM

The default setting in OTVIEW goes back 30 day's was that the correct setting to use?
Here are those reports.

OTViewIt logfile created on: 10/11/2008 2:17:00 PM - Run
OTViewIt by OldTimer - Version 1.0.11.0 Folder = C:\Documents and Settings\Jim\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.07 Mb Total Physical Memory | 458.52 Mb Available Physical Memory | 45.22% Memory free
2.38 Gb Paging File | 1.70 Gb Available in Paging File | 71.18% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.10 Gb Total Space | 80.44 Gb Free Space | 75.11% Space Free | Partition Type: NTFS
Drive D: | 37.24 Gb Total Space | 21.00 Gb Free Space | 56.39% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 232.88 Gb Total Space | 158.24 Gb Free Space | 67.95% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: D3SLJ0B1
Current User Name: Jim
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2008/07/07 08:15:18 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
[2008/07/19 07:25:06 | 00,016,056 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
[2008/07/19 07:38:28 | 00,147,640 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
[2005/04/28 03:08:14 | 00,294,912 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
[2004/07/27 10:08:22 | 00,262,144 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
[2005/06/06 23:46:24 | 00,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[2005/04/28 03:22:52 | 00,102,400 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
[2008/06/10 04:27:04 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[2006/11/09 11:00:44 | 00,024,576 | ---- | M] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
[2006/10/18 20:05:26 | 00,204,288 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
[2006/10/09 16:16:56 | 00,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehrecvr.exe
[2005/08/05 11:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehSched.exe
[2008/06/08 10:17:29 | 00,137,200 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[2006/01/09 13:56:04 | 00,049,152 | ---- | M] () -- C:\WINDOWS\system32\LxrSII1s.exe
[2007/08/07 17:07:22 | 00,213,053 | ---- | M] (PermissionTV) -- C:\Program Files\PermissionTV\bin\dm.exe
[2006/07/14 08:45:24 | 00,895,160 | ---- | M] (PC Tools Research Pty Ltd) -- C:\Program Files\Spyware Doctor\sdhelp.exe
[2005/08/05 11:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe
[2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe
[2006/03/30 09:15:44 | 00,096,341 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
[2008/05/22 17:29:11 | 00,098,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN\MSNCoreFiles\msn.exe
[2007/01/19 12:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe
[2008/07/19 07:38:34 | 00,078,008 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
[2008/07/19 07:38:04 | 00,250,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
[2008/07/23 07:25:45 | 00,348,344 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
[2006/09/17 10:42:10 | 00,185,784 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[2008/04/13 17:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\notepad.exe
[2008/09/28 14:52:53 | 00,307,712 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2007/01/19 12:54:56 | 05,674,352 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\msnmsgr.exe
[2008/06/23 02:20:52 | 00,625,664 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2008/10/11 14:14:29 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jim\Desktop\OTViewIt.exe

========== (O23) Win32 Services ==========

[2008/07/07 08:15:18 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice [Auto | Running])
File not found -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS [Auto | Stopped])
[2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2008/07/19 07:25:06 | 00,016,056 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
[2008/07/19 07:38:28 | 00,147,640 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
[2008/07/19 07:38:04 | 00,250,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
[2008/07/23 07:25:45 | 00,348,344 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
[2006/03/30 09:15:44 | 00,096,341 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8 [Auto | Running])
[2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2005/04/25 17:34:12 | 00,466,944 | ---- | M] (Dell) -- C:\WINDOWS\system32\dlbucoms.exe -- (dlbu_device [On_Demand | Stopped])
[2006/10/09 16:16:56 | 00,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehrecvr.exe -- (ehRecvr [Auto | Running])
[2005/08/05 11:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehSched.exe -- (ehSched [Auto | Running])
[2007/10/09 12:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
[2008/06/08 10:17:29 | 00,137,200 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Auto | Running])
[2004/10/22 03:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2007/10/11 09:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
[2006/01/09 13:56:04 | 00,049,152 | ---- | M] () -- C:\WINDOWS\system32\LxrSII1s.exe -- (LxrSII1s [Auto | Running])
[2005/08/05 11:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe -- (McrdSvc [Auto | Running])
[2004/11/19 09:26:40 | 00,147,456 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe -- (NetSvc [On_Demand | Stopped])
[2007/10/11 09:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
[2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2007/08/07 17:07:22 | 00,213,053 | ---- | M] (PermissionTV) -- C:\Program Files\PermissionTV\bin\dm.exe -- (PermissionTVDownloadManager [Auto | Running])
[2006/07/14 08:45:24 | 00,895,160 | ---- | M] (PC Tools Research Pty Ltd) -- C:\Program Files\Spyware Doctor\sdhelp.exe -- (SDhelper [Auto | Running])
[2007/01/19 12:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Running])
[2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [Auto | Running])

========== Driver Services ==========

[2008/07/19 07:32:15 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
[2001/08/17 11:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) -- C:\WINDOWS\system32\drivers\aliide.sys -- (AliIde [Disabled | Stopped])
[2008/04/13 11:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\system32\drivers\amdagp.sys -- (amdagp [Disabled | Stopped])
[2001/08/17 11:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\system32\drivers\asc.sys -- (asc [Disabled | Stopped])
[2001/08/17 11:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\system32\drivers\asc3550.sys -- (asc3550 [Disabled | Stopped])
[2008/07/19 07:37:42 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
[2008/07/19 07:37:21 | 00,094,416 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
[2008/07/19 07:33:42 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
[2008/07/19 07:35:18 | 00,078,416 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
[2008/07/19 07:32:36 | 00,042,912 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
[2001/08/17 11:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.) -- C:\WINDOWS\system32\drivers\cmdide.sys -- (CmdIde [Disabled | Stopped])
[2006/08/24 12:28:18 | 00,028,672 | ---- | M] () -- C:\WINDOWS\system32\drivers\CO_Mon.sys -- (CO_Mon [On_Demand | Stopped])
[2001/08/17 11:52:16 | 00,179,584 | ---- | M] (Mylex Corporation) -- C:\WINDOWS\system32\drivers\dac2w2k.sys -- (dac2w2k [Disabled | Stopped])
[2005/09/08 03:20:00 | 00,025,628 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM [Auto | Running])
[2005/08/25 10:16:52 | 00,005,628 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM [System | Running])
[2005/09/08 03:20:00 | 00,002,496 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN [Auto | Running])
[2005/09/08 03:20:00 | 00,086,524 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M [Auto | Running])
[2005/09/08 03:20:00 | 00,014,684 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM [Auto | Running])
[2005/09/08 03:20:00 | 00,006,364 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM [Auto | Running])
[2005/08/25 10:16:16 | 00,022,684 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N [System | Running])
[2005/09/08 03:20:00 | 00,094,332 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM [Auto | Running])
[2005/09/08 03:20:00 | 00,087,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M [Auto | Running])
[2005/09/12 01:30:00 | 00,089,264 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\DRVMCDB.SYS -- (DRVMCDB [Boot | Running])
[2005/08/12 03:20:00 | 00,040,544 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS -- (DRVNDDM [Auto | Running])
[2004/10/14 06:30:46 | 00,155,648 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\e100b325.sys -- (E100B [On_Demand | Running])
[2008/04/13 09:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus [On_Demand | Running])
[2003/11/17 19:59:20 | 00,212,224 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2 [On_Demand | Running])
[2003/11/17 19:56:26 | 01,042,432 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP [On_Demand | Running])
[2005/10/14 19:15:18 | 01,302,812 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\ialmnt5.sys -- (ialm [On_Demand | Running])
[2006/07/10 16:38:38 | 00,030,592 | ---- | M] (PCTools Research Pty Ltd.) -- C:\WINDOWS\system32\drivers\ikhfile.sys -- (ikhfile [System | Running])
[2006/08/24 11:40:36 | 00,051,072 | ---- | M] (PCTools Research Pty Ltd.) -- C:\WINDOWS\system32\drivers\ikhlayer.sys -- (ikhlayer [System | Running])
[2008/04/13 11:39:48 | 00,014,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\kbdhid.sys -- (kbdhid [System | Running])
[2006/12/14 09:37:40 | 00,072,672 | ---- | M] () -- C:\WINDOWS\system32\drivers\LxrSII1d.sys -- (LxrSII1d [Auto | Running])
[2003/04/09 16:48:08 | 00,011,043 | ---- | M] (Conexant) -- C:\WINDOWS\system32\drivers\mdmxsdk.sys -- (mdmxsdk [Auto | Running])
[2008/04/13 11:36:41 | 00,063,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\mf.sys -- (mf [On_Demand | Running])
[2001/08/17 11:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Running])
[2001/08/17 11:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.) -- C:\WINDOWS\system32\drivers\mraid35x.sys -- (mraid35x [Disabled | Stopped])
[2004/08/03 20:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Stopped])
[2004/08/10 03:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2008/02/22 19:38:33 | 00,043,872 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2001/08/17 11:52:20 | 00,040,320 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\drivers\ql1080.sys -- (ql1080 [Disabled | Stopped])
[2001/08/17 11:52:20 | 00,045,312 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\drivers\ql12160.sys -- (ql12160 [Disabled | Stopped])
[2001/08/17 11:52:18 | 00,049,024 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\drivers\ql1280.sys -- (ql1280 [Disabled | Stopped])
[2008/09/03 14:07:14 | 00,008,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV [System | Running])
[2008/09/03 14:07:16 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM [On_Demand | Stopped])
[2007/11/13 03:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2008/04/13 11:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\drivers\sisagp.sys -- (sisagp [Disabled | Stopped])
[2001/08/17 12:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.) -- C:\WINDOWS\system32\drivers\sparrow.sys -- (Sparrow [Disabled | Stopped])
[2005/11/16 19:36:00 | 01,047,816 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA [On_Demand | Running])
[2001/08/17 12:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.) -- C:\WINDOWS\system32\drivers\symc810.sys -- (symc810 [Disabled | Stopped])
[2001/08/17 12:07:36 | 00,032,640 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\drivers\symc8xx.sys -- (symc8xx [Disabled | Stopped])
[2001/08/17 12:07:40 | 00,028,384 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\drivers\sym_hi.sys -- (sym_hi [Disabled | Stopped])
[2001/08/17 12:07:42 | 00,030,688 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\drivers\sym_u3.sys -- (sym_u3 [Disabled | Stopped])
[2006/10/05 13:33:32 | 00,076,560 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\system32\drivers\tmcomm.sys -- (tmcomm [Auto | Running])
[2001/08/17 11:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\system32\drivers\ultra.sys -- (ultra [Disabled | Stopped])
[2003/01/10 13:13:04 | 00,033,588 | R--- | M] (America Online, Inc.) -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw [On_Demand | Running])
[2003/11/17 19:58:02 | 00,680,704 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf [On_Demand | Running])
[2004/08/10 03:00:00 | 00,012,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ws2ifsl.sys -- (WS2IFSL [System | Running])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"Default_Search_URL"=http://www.google.com/ie
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Page_Transitions"=
"Search Page"=http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
"SearchMigratedDefaultName"=Google
"SearchMigratedDefaultURL"=http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
"Start Page"=http://www.google.com/

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search]
"AutoSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/saautosearch.aspx
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = *.local

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\SOFTWARE\Microsoft\Internet Explorer\Main]
"Page_Transitions"=
"Search Page"=http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
"SearchMigratedDefaultName"=Google
"SearchMigratedDefaultURL"=http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
"Start Page"=http://www.google.com/

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\SOFTWARE\Microsoft\Internet Explorer\Search]
"AutoSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/saautosearch.aspx
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\Software\Microsoft\Internet Explorer\SearchURL]
""=http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = *.local

========== (O1) Hosts File ==========

HOSTS File = (736 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} (HKLM) -- C:\Program Files\Spyware Doctor\tools\iesdsg.dll (PC Tools)
{5CA3D70E-1895-11CF-8E15-001234567890} (HKLM) -- C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
{7E853D72-626A-48EC-A868-BA8D5E23E045} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{AA58ED58-01DD-4d91-8333-CF10577473F7} (HKLM) -- c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (HKLM) -- C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll (Google Inc.)
{B56A7D7D-6927-48C8-A975-17DF180C71AC} (HKLM) -- C:\Program Files\Spyware Doctor\tools\iesdpb.dll (PC Tools)

========== (O3) Toolbars ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{968631B6-4729-440D-9BF4-251F5593EC9A}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C5F7A735-70F1-477F-8C36-6FF3C736017B}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{968631B6-4729-440D-9BF4-251F5593EC9A}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C5F7A735-70F1-477F-8C36-6FF3C736017B}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
"Dell Photo AIO Printer 942"="C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe" ()
"DellMCM"="C:\Program Files\Dell Photo AIO Printer 942\memcard.exe" ()
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup (InstallShield Software Corporation)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LxrAutorun"=C:\Documents and Settings\Jim\Local Settings\Application Data\Lexar Media\LxrAutorun.exe ()
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (PC Tools Research Pty Ltd)

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (PC Tools Research Pty Ltd)

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LxrAutorun"=C:\Documents and Settings\Jim\Local Settings\Application Data\Lexar Media\LxrAutorun.exe ()
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)

========== (O4) Startup Folders ==========

File not found -- C:\Documents and Settings\Jim\Start Menu\Programs\Startup\Pima County Public Library Tray App.lnk

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\Software\policies\microsoft\internet explorer\Infodelivery\Restrictions]
"NoUpdateCheck"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"LinkResolveIgnoreLinkInfo"=0
"NoResolveSearch"=1
"NoCDBurning"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.mss -- File not found
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.the -- File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"LinkResolveIgnoreLinkInfo"=0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"LinkResolveIgnoreLinkInfo"=0

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
&AOL Toolbar search: Reg Error: Value does not exist or could not be read. File not found

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\Software\Microsoft\Internet Explorer\MenuExt\]
&AOL Toolbar search: Reg Error: Value does not exist or could not be read. File not found

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Menu: Spybot - Search & Destroy Configuration -- %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [2008/09/15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 11:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 17:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 17:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{39FD89BF-D3F1-45b6-BB56-3582CCF489E1} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 11:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 17:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{39FD89BF-D3F1-45b6-BB56-3582CCF489E1} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 17:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{39FD89BF-D3F1-45b6-BB56-3582CCF489E1} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 17:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{39FD89BF-D3F1-45b6-BB56-3582CCF489E1} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 11:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 17:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
musicmatch.com\online: https in Computer
34 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
//@mail.mar@/: msn in Local intranet
//@signup.mar@/: msn in My Computer
40 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
34 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
34 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
116 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
116 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
//@mail.mar@/: msn in Local intranet
//@signup.mar@/: msn in My Computer
40 domain(s) and sub-domain(s) not assigned to a zone.

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}: http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab -- QuickTime Object
{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}: http://download.microsoft.com/download/a/f...tualEarth3D.cab -- SentinelVE3D Class
{17492023-C23A-453E-A040-C7C580BBF700}: http://download.microsoft.com/download/8/b...heckControl.cab -- Windows Genuine Advantage Validation Tool
{233C1507-6A77-46A4-9443-F871F945D258}: http://fpdownload.macromedia.com/get/shock...director/sw.cab -- Shockwave ActiveX Control
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}: http://update.microsoft.com/microsoftupdat...b?1156453173265 -- MUWebControl Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_06
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{E06E2E99-0AA1-11D4-ABA6-0060082AA75C}: https://poolcorp.webex.com/client/T23L/support/ieatgpc.cab -- GpcContainer Class

========== (O17) DNS Name Servers ==========

{4D4B4659-C92A-4053-91F4-294EE53D09CA} (Servers: | Description: Intel® PRO/100 VE Network Connection)

========== (O20) Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
!SASWinLogon: "DllName" = C:\Program Files\SUPERAntiSpyware\SASWINLO.dll -- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
igfxcui: "DllName" = igfxdev.dll -- C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
WgaLogon: "DllName" = Reg Error: Value DLLName does not exist or could not be read. -- File not found

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) -- C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
[2005/08/16 02:43:04 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]

========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun]
""=Auto&Play


========== Files/Folders - Created Within 30 Days ==========

[2008/10/11 14:14:27 | 00,421,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jim\Desktop\OTViewIt.exe
[2008/10/11 13:51:45 | 01,001,638 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Table.jpg
[2008/10/11 13:42:41 | 00,007,261 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\trx-smly18.gif
[2008/10/11 12:17:24 | 00,210,416 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\zaSetup_en.exe
[2008/10/11 12:04:35 | 00,057,344 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\How To Resize Animated GIFs Without Installing Software.doc
[2008/10/11 11:26:37 | 08,394,802 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\ZillaTubeSetup.exe
[2008/10/11 10:13:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\INFO FOR BLEEPING COMPUTER FORUM
[2008/10/11 08:45:54 | 00,048,026 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\!cid_X_MA23_1223739855@aol.jpg
[2008/10/11 00:49:52 | 01,122,628 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\cabinet.jpg
[2008/10/10 11:52:06 | 00,023,323 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\9de1_1.jpg
[2008/10/10 11:49:57 | 00,005,612 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\1f31231g1ZZZZZZZZZ8a96ea564154bdc1d40.jpg
[2008/10/10 11:24:40 | 00,047,058 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\money.jpg
[2008/10/10 11:23:01 | 00,015,979 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\71014_MoneyHappiness_vl-vertical.jpg
[2008/10/10 10:01:55 | 16,998,963 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\planetearthforever.wmv
[2008/10/10 08:59:03 | 00,047,616 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Als wk 6 mstr.xls
[2008/10/09 21:54:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\10-10-08
[2008/10/08 16:50:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}
[2008/10/07 08:16:17 | 00,022,016 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\wk 6 Alan.xls
[2008/10/06 08:43:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Application Data\MSNInstaller
[2008/09/27 19:52:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\9-27-08
[2008/09/23 09:41:59 | 00,040,960 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Shetka Inv 9-22-08.xls
[2008/09/22 10:44:06 | 01,445,888 | ---- | C] (Option^Explicit Software Solutions) -- C:\Documents and Settings\Jim\Desktop\WinsockxpFix.exe
[2008/09/19 13:27:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\desktop 9-19-08
[2008/09/18 09:56:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\Virus 9-16-08
[2008/09/16 08:51:07 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2008/10/11 14:14:29 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jim\Desktop\OTViewIt.exe
[2008/10/11 13:51:36 | 01,001,638 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Table.jpg
[2008/10/11 13:42:12 | 00,007,261 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\trx-smly18.gif
[2008/10/11 13:32:45 | 00,000,156 | ---- | M] () -- C:\WINDOWS\Twunk001.MTX
[2008/10/11 13:32:45 | 00,000,006 | ---- | M] () -- C:\WINDOWS\Twain001.Mtx
[2008/10/11 12:17:25 | 00,210,416 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\zaSetup_en.exe
[2008/10/11 12:04:36 | 00,057,344 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\How To Resize Animated GIFs Without Installing Software.doc
[2008/10/11 11:26:37 | 08,394,802 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\ZillaTubeSetup.exe
[2008/10/11 08:45:53 | 00,048,026 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\!cid_X_MA23_1223739855@aol.jpg
[2008/10/11 00:49:44 | 01,122,628 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\cabinet.jpg
[2008/10/10 11:51:55 | 00,023,323 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\9de1_1.jpg
[2008/10/10 11:24:30 | 00,047,058 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\money.jpg
[2008/10/10 11:22:53 | 00,015,979 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\71014_MoneyHappiness_vl-vertical.jpg
[2008/10/10 10:18:37 | 00,005,612 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\1f31231g1ZZZZZZZZZ8a96ea564154bdc1d40.jpg
[2008/10/10 10:01:56 | 16,998,963 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\planetearthforever.wmv
[2008/10/10 08:59:03 | 00,047,616 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Als wk 6 mstr.xls
[2008/10/10 08:07:50 | 00,000,551 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\My Sharing Folders.lnk
[2008/10/10 08:05:08 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/10/10 08:04:56 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008/10/10 08:04:55 | 10,634,07616 | -HS- | M] () -- C:\hiberfil.sys
[2008/10/09 22:06:28 | 17,121,684 | -H-- | M] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\IconCache.db
[2008/10/09 21:48:19 | 00,022,016 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\wk 6 Alan.xls
[2008/10/07 07:24:15 | 00,000,840 | ---- | M] () -- C:\WINDOWS\dellstat.ini
[2008/10/05 22:26:51 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2008/10/05 22:26:51 | 00,000,232 | -H-- | M] () -- C:\sqmdata12.sqm
[2008/10/05 22:26:47 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2008/10/05 22:26:47 | 00,000,232 | -H-- | M] () -- C:\sqmdata11.sqm
[2008/10/05 22:25:41 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2008/10/05 22:25:41 | 00,000,232 | -H-- | M] () -- C:\sqmdata10.sqm
[2008/10/05 22:25:12 | 00,000,232 | -H-- | M] () -- C:\sqmdata09.sqm
[2008/10/05 22:25:11 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2008/10/05 22:25:09 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2008/10/05 22:25:09 | 00,000,232 | -H-- | M] () -- C:\sqmdata08.sqm
[2008/10/05 22:24:34 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2008/10/05 22:24:34 | 00,000,232 | -H-- | M] () -- C:\sqmdata07.sqm
[2008/10/05 22:24:32 | 00,000,232 | -H-- | M] () -- C:\sqmdata06.sqm
[2008/10/05 22:24:31 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2008/10/05 22:23:46 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2008/10/05 22:23:46 | 00,000,232 | -H-- | M] () -- C:\sqmdata05.sqm
[2008/10/05 22:23:42 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2008/10/05 22:23:42 | 00,000,232 | -H-- | M] () -- C:\sqmdata04.sqm
[2008/10/05 22:23:25 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2008/10/05 22:23:25 | 00,000,232 | -H-- | M] () -- C:\sqmdata03.sqm
[2008/10/05 22:22:57 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2008/10/05 22:22:57 | 00,000,232 | -H-- | M] () -- C:\sqmdata02.sqm
[2008/10/05 22:22:53 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2008/10/05 22:22:53 | 00,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2008/10/05 22:22:48 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2008/10/05 22:22:48 | 00,000,232 | -H-- | M] () -- C:\sqmdata00.sqm
[2008/10/05 22:22:37 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2008/10/05 22:22:37 | 00,000,232 | -H-- | M] () -- C:\sqmdata19.sqm
[2008/10/05 22:21:49 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2008/10/05 22:21:49 | 00,000,232 | -H-- | M] () -- C:\sqmdata18.sqm
[2008/10/05 22:20:28 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2008/10/05 22:20:28 | 00,000,232 | -H-- | M] () -- C:\sqmdata17.sqm
[2008/10/05 22:20:26 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2008/10/05 22:20:26 | 00,000,232 | -H-- | M] () -- C:\sqmdata16.sqm
[2008/10/02 07:16:21 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2008/10/02 07:16:21 | 00,000,232 | -H-- | M] () -- C:\sqmdata15.sqm
[2008/10/01 16:21:22 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2008/10/01 16:21:22 | 00,000,232 | -H-- | M] () -- C:\sqmdata14.sqm
[2008/10/01 16:21:13 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2008/10/01 16:21:13 | 00,000,232 | -H-- | M] () -- C:\sqmdata13.sqm
[2008/09/26 09:04:57 | 00,234,496 | ---- | M] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/23 16:12:52 | 00,197,976 | R--- | M] (Coupons, Inc.) -- C:\WINDOWS\System32\cpnprt2.cid
[2008/09/23 09:41:59 | 00,040,960 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Shetka Inv 9-22-08.xls
[2008/09/22 10:44:14 | 01,445,888 | ---- | M] (Option^Explicit Software Solutions) -- C:\Documents and Settings\Jim\Desktop\WinsockxpFix.exe
< End of report >


Extras
OTViewIt Extras logfile created on: 10/11/2008 2:17:00 PM - Run
OTViewIt by OldTimer - Version 1.0.11.0 Folder = C:\Documents and Settings\Jim\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.07 Mb Total Physical Memory | 458.52 Mb Available Physical Memory | 45.22% Memory free
2.38 Gb Paging File | 1.70 Gb Available in Paging File | 71.18% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.10 Gb Total Space | 80.44 Gb Free Space | 75.11% Space Free | Partition Type: NTFS
Drive D: | 37.24 Gb Total Space | 21.00 Gb Free Space | 56.39% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 232.88 Gb Total Space | 158.24 Gb Free Space | 67.95% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: D3SLJ0B1
Current User Name: Jim
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=1
"DisableNotifications"=0
"DoNotAllowExceptions"=1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 17:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
File not found -- C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
File not found -- C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
File not found -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL
[2008/04/13 11:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/01/19 12:54:56 | 05,674,352 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 16:10:02 | 00,297,752 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/13 17:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
File not found -- C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
[2008/04/13 17:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
File not found -- C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
File not found -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL
File not found -- C:\dNeL.eXe:*:Enabled:ipsec
File not found -- C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader
File not found -- C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon
File not found -- C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed
File not found -- C:\Program Files\Common Files\AOL\1156029216\EE\AOLServiceHost.exe:*:Enabled:AOL
File not found -- C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL
File not found -- C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL
File not found -- C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL
File not found -- C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL
[2008/04/13 11:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/09/28 14:52:53 | 00,307,712 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox
File not found -- C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2008/03/26 10:14:36 | 02,990,752 | ---- | M] (Joost Technologies B.V.) -- C:\Program Files\Joost\xulrunner\tvprunner.exe:*:Enabled:tvprunner
[2007/01/19 12:54:56 | 05,674,352 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 16:10:02 | 00,297,752 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

========== (O10) Winsock2 Catalogs ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] -- C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2008/04/13 17:11:58 | 00,532,480 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\msdaipp.dll ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - Microsoft OLE DB Moniker Binder for Internet Publishing]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/01/19 12:53:24 | 00,063,344 | ---- | M] (Microsoft Corporation) C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2008/04/13 17:11:58 | 00,532,480 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\msdaipp.dll msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - Microsoft OLE DB Moniker Binder for Internet Publishing]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2008/04/13 17:11:58 | 00,532,480 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\msdaipp.dll msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/01/19 12:53:24 | 00,063,344 | ---- | M] (Microsoft Corporation) C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}"=Microsoft Office 2000 Premium
"{00040409-78E1-11D2-B60F-006097C998E7}"=Microsoft Office 2000 Disc 2
"{075473F5-846A-448B-BCB3-104AA1760205}"=Roxio RecordNow Data
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}"=Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}"=Roxio DLA
"{178BAABD-0C95-4EB6-9E12-29A039EA27F6}"=Qwest eChat Support Tools
"{18525F55-9B32-4D49-BF03-D53B17A49D97}"=DellConnect
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}"=Adobe AIR
"{1CB92574-96F2-467B-B793-5CEB35C40C29}"=Image Resizer Powertoy for Windows XP
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}"=Google Earth
"{1EBB57D4-63FF-87CC-A0F0-D73982CF6008}"=Adobe Media Player
"{21657574-BD54-48A2-9450-EB03B2C7FC29}"=Roxio MyDVD LE
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=Google Toolbar for Internet Explorer
"{2BA00471-0328-3743-93BD-FA813353A783}"=Microsoft .NET Framework 3.0 Service Pack 1
"{2FBF04DC-404C-4FA4-BA28-99903080D2B9}"=Magnifier Powertoy for Windows XP
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}"=Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160060}"=Java™ 6 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java™ 6 Update 7
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}"=Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}"=NetWaiting
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}"=Dell CinePlayer
"{4667B940-BB01-428B-986E-A0CC46497BF7}"=ELIcon
"{4B66765B-8596-4698-A208-E23D11D84AA7}"=Canon Camera WIA Driver
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}"=Adobe® Photoshop® Album Starter Edition 3.0
"{4CE88F4D-B74E-4F92-9DA4-ECEB60ED362A}"=TBS WMP Plug-in
"{4E901875-0F15-44BA-89DE-94AA41A7F507}"=Clear Cache feature for Internet Explorer
"{4F1CECBC-670F-4daa-81D6-944B12450917}"=DIGReqEx
"{548EEA8E-8299-497F-8057-811D2D7097DC}"=Dell Support 3.1
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}"=Windows Live Messenger
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}"=Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}"=Sonic Activation Module
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}"=Windows Media Player Firefox Plugin
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}"=Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}"=Microsoft Plus! Digital Media Edition Installer
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}"=Dell System Restore
"{7F142D56-3326-11D5-B229-002078017FBF}"=Modem Helper
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}"=Intel® PROSet for Wired Connections
"{85D3CC30-8859-481A-9654-FD9B74310BEF}"=Musicmatch® Jukebox
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}"=Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}"=Intel® Graphics Media Accelerator Driver
"{90850409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Word Viewer 2003
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}"=QuickTime
"{9941F0AA-B903-4AF4-A055-83A9815CC011}"=Sonic Encoders
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}"=Microsoft Visual C++ 2005 Redistributable
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}"=Roxio RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A81200000003}"=Adobe Reader 8.1.2
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}"=Documentation & Support Launcher
"{B12665F4-4E93-4AB4-B7FC-37053B524629}"=Roxio RecordNow Copy
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1"=Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}"=Microsoft .NET Framework 2.0 Service Pack 1
"{B6884A07-0305-47AE-9969-8F26FADC17DE}"=Games, Music, & Photos Launcher
"{BAF78226-3200-4DB4-BE33-4D922A799840}"=Windows Presentation Foundation
"{C769B501-2BE8-46ed-9E69-118F008A0917}"=DIGOpt
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}"=SUPERAntiSpyware Free Edition
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}"=ABBYY FineReader 5.0 Sprint Plus
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}"=MCU
"{D76D1828-BBA0-4BD9-8181-5ACC617DC5F2}"=Virtual Earth 3D (Beta)
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}"=Ad-Aware
"{E646DCF0-5A68-11D5-B229-002078017FBF}"=Digital Line Detect
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}"=Musicmatch for Windows Media Player
"{FCC3BD6A-F118-475D-8748-7EE08EA0AF56}"=HDView for Internet Explorer
"ActiveTouchMeetingClient"=WebEx
"Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player Plugin
"Adobe Shockwave Player"=Adobe Shockwave Player 11
"Advanced WindowsCare V2 Personal_is1"=Advanced WindowsCare 2.40 Personal
"Aqualink RS System Simulator Rev MM"=Aqualink RS System Simulator Rev MM
"avast!"=avast! Antivirus
"CAL"=Canon Camera Access Library
"CamelCasino"=CamelCasino
"CameraWindowDVC5"=Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6"=Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC"=Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder"=Canon G.726 WMP-Decoder
"CCleaner"=CCleaner (remove only)
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1"=Conexant D850 56K V.9x DFVc Modem
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1"=Adobe Media Player
"Coupon Printer for Windows2.0"=Coupon Printer for Windows
"Coupon Printer for Windows4.0"=Coupon Printer for Windows
"CSCLIB"=Canon Camera Support Core Library
"Dell Digital Jukebox Driver"=Dell Digital Jukebox Driver
"Dell Photo AIO Printer 942"=Dell Photo AIO Printer 942
"EmailStripper_is1"=EmailStripper 2.2
"EmeraldQFE2"=Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"EOS Utility"=Canon Utilities EOS Utility
"Free and Easy Biorhythm Calculator_is1"=Free and Easy Biorhythm Calculator version 3.00
"Google Updater"=Google Updater
"GoogleVideoPlayer"=Google Video Player
"HijackThis"=HijackThis 2.0.2
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"InstallShield_{4CE88F4D-B74E-4F92-9DA4-ECEB60ED362A}"=TBS WMP Plug-in
"IrfanView"=IrfanView (remove only)
"Joost"=Joost ™ Beta 1.1.4
"KB835221WXP"=High Definition Audio Driver Package - KB835221
"KB900325"=Update Rollup 2 for Windows XP Media Center Edition 2005
"KB908246"=Windows XP Media Center Edition 2005 KB908246
"KB925766"=Windows XP Media Center Edition 2005 KB925766
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"MovieEditTask"=Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST"=MSN
"MVApplication1"=SureThing CD Labeler
"NetMos Technology"=NetMos Multi-IO Controller
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"Panda spyXposer"=Panda spyXposer
"PaperPort 6.5"=PaperPort 6.5
"PDA WIN32 System Simulator Rev 1.2"=PDA WIN32 System Simulator Rev 1.2
"PermissionTV Download Manager_is1"=PermissionTV Download Manager
"PhotoStitch"=Canon Utilities PhotoStitch
"Picasa2"=Picasa 2
"Pima County Public Library Player_is1"=PermissionTV Pima County Public Library Player 3.15
"PROSet"=Intel® PRO Network Connections Drivers
"RAW Image Task"=Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0"=RealPlayer
"RemoteCaptureTask"=Canon RemoteCapture Task for ZoomBrowser EX
"Space Photo Screensaver"=Space Photo Screensaver
"Spybot - Search & Destroy_is1"=Spybot - Search & Destroy 1.5.2.20
"Spyware Doctor_is1"=Spyware Doctor 4.0
"Unlocker"=Unlocker 1.8.7
"ViewpointMediaPlayer"=Viewpoint Media Player
"VLC media player"=VideoLAN VLC media player 0.8.6f
"WIC"=Windows Imaging Component
"Windows Live Safety Scanner"=Windows Live Safety Scanner
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Windows Media Player 11
"Windows XP Service Pack"=Windows XP Service Pack 3
"WinFax Merger_is1"=WinFax Merger version 2.1
"WinZip"=WinZip
"Wisdom-soft ScreenHunter 4.0 Free"=Wisdom-soft ScreenHunter 4.0 Free
"WMCSetup"=Windows Media Connect
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC"=XML Paper Specification Shared Components Pack 1.0
"XviD_is1"=XviD 1.1 final uninstall
"ZoomBrowser EX"=Canon Utilities ZoomBrowser EX

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1172676977-3301493229-2619026537-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 12/18/2006 4:11:02 AM | Computer Name = D3SLJ0B1 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://pagead2.googlesyndication.com/pagea...%3A%2F%2Fwww.ai
failed, 0000A474.

Error - 12/18/2006 4:18:44 AM | Computer Name = D3SLJ0B1 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://pagead2.googlesyndication.com/pagea...5&color_tex
failed, 0000A474.

Error - 12/18/2006 4:37:25 AM | Computer Name = D3SLJ0B1 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://pagead2.googlesyndication.com/pagea...5&color_tex
failed, 0000A474.

Error - 12/18/2006 4:53:12 AM | Computer Name = D3SLJ0B1 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://pagead2.googlesyndication.com/pagea...%3A%2F%2Fwww.ai
failed, 0000A474.

Error - 12/11/2007 8:47:11 PM | Computer Name = D3SLJ0B1 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Jim\Recent\%temp%dd_msxml_retMSI.lnk failed, 0000007B.


Error - 5/16/2008 9:37:12 AM | Computer Name = D3SLJ0B1 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Jim\Recent\%temp%dd_msxml_retMSI.lnk failed, 0000007B.


Error - 7/6/2008 4:49:30 PM | Computer Name = D3SLJ0B1 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\July 4th cropped\20080704_IMG_0278-1.JPG failed, 0000001E.

Error - 7/7/2008 7:16:57 PM | Computer Name = D3SLJ0B1 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
F:\UNC Jims pics Paige + Scotts wedding\Scary pano2.jpg failed, 0000001E.

Error - 7/7/2008 7:17:17 PM | Computer Name = D3SLJ0B1 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
F:\UNC Jims pics Paige + Scotts wedding\Scary pano2.jpg failed, 0000001E.

Error - 7/7/2008 7:42:16 PM | Computer Name = D3SLJ0B1 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
F:\UNC Jims pics Paige + Scotts wedding\IMG_0669.JPG failed, 0000001E.

[ Application Events ]
Error - 8/6/2008 12:02:48 PM | Computer Name = D3SLJ0B1 | Source = Microsoft Fax | ID = 32092
Description = The Fax service failed to receive a fax. From: . CallerId: . To: 520-748-7349.
Pages:
0. Device Name: Conexant D850 56K V.9x DFVc Modem.

Error - 8/6/2008 12:15:27 PM | Computer Name = D3SLJ0B1 | Source = Application Error | ID = 1000
Description = Faulting application msn.exe, version 9.50.39.1900, faulting module
seal.dll, version 9.50.39.1900, fault address 0x000346a4.

Error - 8/6/2008 12:20:05 PM | Computer Name = D3SLJ0B1 | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 8/6/2008 9:47:46 PM | Computer Name = D3SLJ0B1 | Source = Application Error | ID = 1000
Description = Faulting application msn.exe, version 9.50.39.1900, faulting module
mailui.dll, version 9.50.39.1900, fault address 0x0005012b.

Error - 8/16/2008 3:10:55 PM | Computer Name = D3SLJ0B1 | Source = Application Error | ID = 1000
Description = Faulting application msn.exe, version 9.50.39.1900, faulting module
msnmetal.dll, version 9.50.39.1900, fault address 0x0005ba5e.

Error - 8/28/2008 4:43:16 PM | Computer Name = D3SLJ0B1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 9/20/2008 11:44:31 AM | Computer Name = D3SLJ0B1 | Source = Application Error | ID = 1000
Description = Faulting application ad-aware.exe, version 7.1.0.11, faulting module
ad-aware.exe, version 7.1.0.11, fault address 0x0014b4ec.

Error - 9/20/2008 11:44:52 AM | Computer Name = D3SLJ0B1 | Source = Application Error | ID = 1000
Description = Faulting application ad-aware.exe, version 7.1.0.11, faulting module
ad-aware.exe, version 7.1.0.11, fault address 0x0014b4ec.

Error - 9/20/2008 11:45:14 AM | Computer Name = D3SLJ0B1 | Source = Application Error | ID = 1000
Description = Faulting application ad-aware.exe, version 7.1.0.11, faulting module
ad-aware.exe, version 7.1.0.11, fault address 0x0014b4ec.

Error - 10/10/2008 5:52:58 PM | Computer Name = D3SLJ0B1 | Source = Application Error | ID = 1000
Description = Faulting application winword.exe, version 9.0.0.2717, faulting module
winword.exe, version 9.0.0.2717, fault address 0x0048495e.

[ System Events ]
Error - 10/2/2008 10:13:32 AM | Computer Name = D3SLJ0B1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 10/2/2008 10:14:04 AM | Computer Name = D3SLJ0B1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.

Error - 10/2/2008 10:14:33 AM | Computer Name = D3SLJ0B1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.

Error - 10/2/2008 10:15:03 AM | Computer Name = D3SLJ0B1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.

Error - 10/2/2008 10:15:35 AM | Computer Name = D3SLJ0B1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.

Error - 10/2/2008 10:16:10 AM | Computer Name = D3SLJ0B1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.

Error - 10/6/2008 2:55:43 AM | Computer Name = D3SLJ0B1 | Source = Service Control Manager | ID = 7000
Description = The AOL Connectivity Service service failed to start due to the following
error: %%3

Error - 10/7/2008 12:19:23 AM | Computer Name = D3SLJ0B1 | Source = Print | ID = 6161
Description = The document INVoice S1 owned by Jim failed to print on printer Dell
Photo AIO Printer 942. Data type: LEMF. Size of the spool file in bytes: 185198.
Number of bytes printed: 185198. Total number of pages in the document: 1. Number
of pages printed: 0. Client machine: \\D3SLJ0B1. Win32 error code returned by the
print processor: 535 (0x217).

Error - 10/8/2008 4:44:52 PM | Computer Name = D3SLJ0B1 | Source = Service Control Manager | ID = 7000
Description = The SASDIFSV service failed to start due to the following error: %%183

Error - 10/10/2008 11:05:23 AM | Computer Name = D3SLJ0B1 | Source = Service Control Manager | ID = 7000
Description = The AOL Connectivity Service service failed to start due to the following
error: %%3


< End of report >

#8 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:30 AM

Posted 11 October 2008 - 05:12 PM

Hello, JBBIGQ.

The default setting in OTVIEW goes back 30 day's was that the correct setting to use?

Yup :thumbsup:

We need to uninstall one or more programs
Please click on Start > Control Panel > Add/Remove Programs and uninstall the following programs(if present):
Java™ 6 Update 6

We need to execute an OTMoveIt3 script
  • Please download OTMoveIt3 by OldTimer and save it to your desktop.
  • Double click the Posted Image icon on your desktop.
  • Paste the following code under the Posted Image area. Do not include the word "Code".
    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    [-HKEY_CLASSES_ROOT\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    :services
    AOL ACS
    :files
    C:\sqmdata??.sqm
    C:\sqmnoopt??.sqm
  • Push the large Posted Image button.
  • OTMI3 may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the Posted Image line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
We need to clear out some temporary data.
Please download ATF Cleaner by Atribune. (This program is for XP and Windows 2000 only)Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

I would like us to use ESET (NOD32)'s Online Scanner
  • Please go to ESET OnlineScan (NOD32)
  • You will then see the Terms of Use, tick the check-box infront of YES, I accept the Terms of Use
  • Now click Start
  • Should you face a Security Warning that asks if you want to install and run a file called "OnlineScanner.cab", click Yes
  • Click Start
    • Note: (the Onlinescanner will now prepare itself for running on your pc)
  • To do a full-scan, tick: "Remove found threats" and "Scan potentially unwanted applications"
  • Press Scan
  • The Onlinescan will now start and scan your pc (this could take a while)
  • When the scan has finished, it will show a screen with two tabs "overview" and "details" and the option to get information or buy software, just close the window
  • Click Start >> Run... >> type: C:\Program Files\EsetOnlineScanner\log.txt
  • The Scanresults will now open in Notepad
  • Click into the text area, right-click and chose "select all" (or use +A)
  • Right-click again and chose "Copy" (or +C)
  • Close/Exit Notepad
  • Navigate to this thread and post your log along with anything else requested from us, by right-clicking and "paste" (or ctrl+v) in the text area of the reply post you just created.
Note: For Vista Users: Eset is compatible but Internet Explorer must be run as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.)

In your next reply, please include the following:
  • OTMoveIt3's Log
  • ESET OnlineScan's Log

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#9 JBBIGQ

JBBIGQ
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:30 AM

Posted 11 October 2008 - 08:03 PM

What did you make of the HJT backup file dated 11-05-08 ??? A toast in your honor!!!


Attached File  champAGNE.gif   11.68KB   0 downloads



Here is
OTMoveIt3 log


========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\\ deleted successfully.
Registry key HKEY_CLASSES_ROOT\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\\ not found.
========== SERVICES/DRIVERS ==========
Service AOL ACS stopped successfully.
Service AOL ACS deleted successfully.
========== FILES ==========
C:\sqmdata00.sqm moved successfully.
C:\sqmdata01.sqm moved successfully.
C:\sqmdata02.sqm moved successfully.
C:\sqmdata03.sqm moved successfully.
C:\sqmdata04.sqm moved successfully.
C:\sqmdata05.sqm moved successfully.
C:\sqmdata06.sqm moved successfully.
C:\sqmdata07.sqm moved successfully.
C:\sqmdata08.sqm moved successfully.
C:\sqmdata09.sqm moved successfully.
C:\sqmdata10.sqm moved successfully.
C:\sqmdata11.sqm moved successfully.
C:\sqmdata12.sqm moved successfully.
C:\sqmdata13.sqm moved successfully.
C:\sqmdata14.sqm moved successfully.
C:\sqmdata15.sqm moved successfully.
C:\sqmdata16.sqm moved successfully.
C:\sqmdata17.sqm moved successfully.
C:\sqmdata18.sqm moved successfully.
C:\sqmdata19.sqm moved successfully.
C:\sqmnoopt00.sqm moved successfully.
C:\sqmnoopt01.sqm moved successfully.
C:\sqmnoopt02.sqm moved successfully.
C:\sqmnoopt03.sqm moved successfully.
C:\sqmnoopt04.sqm moved successfully.
C:\sqmnoopt05.sqm moved successfully.
C:\sqmnoopt06.sqm moved successfully.
C:\sqmnoopt07.sqm moved successfully.
C:\sqmnoopt08.sqm moved successfully.
C:\sqmnoopt09.sqm moved successfully.
C:\sqmnoopt10.sqm moved successfully.
C:\sqmnoopt11.sqm moved successfully.
C:\sqmnoopt12.sqm moved successfully.
C:\sqmnoopt13.sqm moved successfully.
C:\sqmnoopt14.sqm moved successfully.
C:\sqmnoopt15.sqm moved successfully.
C:\sqmnoopt16.sqm moved successfully.
C:\sqmnoopt17.sqm moved successfully.
C:\sqmnoopt18.sqm moved successfully.
C:\sqmnoopt19.sqm moved successfully.

OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 1011



Here is scan log
# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3515 (20081011)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=067f1609ea25a1489a32637c7423bd4a
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-10-12 12:33:33
# local_time=2008-10-11 05:33:33 (-0700, US Mountain Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=321390
# found=0
# scan_time=4645

#10 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:30 AM

Posted 11 October 2008 - 08:51 PM

What did you make of the HJT backup file dated 11-05-08 ??? A toast in your honor!!!

:thumbsup: What?

That looks good :)

How are things running?

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#11 JBBIGQ

JBBIGQ
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:30 AM

Posted 12 October 2008 - 12:05 PM

Billy,
Things appear to be running OK. Thanks for your help.
The question I had about my Hijack This thing /I added a screen shot above,about half way up with the entry highlighted. Here it is again.


Attached File  strange_HJT_backup.JPG   93.23KB   2 downloads


When I ran HJT and saved the log file ,I was looking at the other functions of HJT/ and in the backups saved portion of HijackThis it showed a backup from 11-05-08 /now since today is 10-13-08 I thought it odd it would be a month ahead.
Can you explain the time discrepancy? I was thinking it might indicate some sort of trouble/ virus?

I'll drop in to your guestbook + leave a thank you.
Again I appreciate it.
Jim M

#12 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:30 AM

Posted 12 October 2008 - 12:58 PM

Hello, JBBIGQ.
Oh.. I'm sorry.. I didn't notice that somehow :)

I'm not sure how that happened, it could be that the clock was set wrong when the entry was fixed. Either way.. I don't think its an issue you need to worry about :)

Congratulations! You now appear clean! :thumbsup:

Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware


We Need to Clean Up Our Mess
  • Please download OTCleanIt from one of the following mirrors and save it to your desktop:
  • Double click the Posted Image icon.
  • Push the large "Cleanup" button.
  • Allow your system to reboot.
Reset System Restore
Windows' "System Restore" feature can cause malware files to be cached and retained by your system. Resetting System Restore will clean these files from your system, and will allow you to use System Restore without fear of reinfection.
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Note: You should only do this once, not on a regular basis!
You will not be able to restore computer to any earlier than today!

Recommendations
Below are some recommendations to lower your chances of (re)infection.
  • Install and maintain an outbound firewall
  • Install Spyware Blaster and update it regularly
    If you wish, the commercial version provides automatic updating.
  • Install the MVPs hosts file, and update it regularly
    You can use the HostMan host file manager to do this automaticly if you wish.
    For more information on the hosts file, and what it can do for you, you can view the Tutorial on the Hosts file
  • Install an Anti-Spyware program, and update it regularly
    Malware Byte's Anti Malware is an excellent Anti-Spyware scanner. It's scan times are usually under ten minutes, and has excellent detection and removal rates.
    SUPERAntiSpyware is another good scanner with high detection and removal rates.
    Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.
  • Keep Windows (and your other Microsoft software) up to date!
    I cannot stress how important this is enough. Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.

    If you are using Windows XP or earlier
    Visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!

    If you are using Windows Vista
    • Click the "Start Menu" (or Windows Orb)
    • Click "All Programs"
    • Click "Windows Update"
    • On the left, choose "Change Settings"
    • Ensure that the checkbox "Use Microsoft Update" at the bottom of the window is checked.
    • Press OK and accept the UAC prompt.
      Note: You shouldn't need to check this checkbox every single time you update, only the first time.
    • Click "Check for Updates" in the upper left corner.
    • Follow the instructions to install the latest updates.
    • Reboot and repeat the "Check for Updates" until there are no more critical updates to install
  • Keep your other software up to date as well
    Software does not need to be made by Microsoft to be insecure. You can use the Secunia Online Software occasionally to help you check for out of date software on your machine.
  • Stay up to date!
    The MOST IMPORTANT part of any security setup is keeping the software up to date. Malware writers release new variants every single day. If your software updates don't keep up, then the malware will always be one step ahead. Not a good thing :).
Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#13 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:30 AM

Posted 15 October 2008 - 08:25 PM

Hello, JBBIGQ.
Since this issue appears resolved, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users