COMBOFIX LOG:ComboFix 09-05-25.A2 - Taj 05/26/2009 11:39.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1576 [GMT -7:00]
Running from: c:\documents and settings\Taj\Desktop\MALWARE\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Taj\Application Data\
020000009cf9695b583C.manifest
c:\documents and settings\Taj\Application Data\
020000009cf9695b583O.manifest
c:\documents and settings\Taj\Application Data\
020000009cf9695b583P.manifest
c:\documents and settings\Taj\Application Data\
020000009cf9695b583S.manifest
c:\program files\IEToolbar
c:\program files\IEToolbar\ECO Bar\basis.xml
c:\program files\IEToolbar\ECO Bar\icons.bmp
c:\program files\IEToolbar\ECO Bar\info.txt
c:\program files\IEToolbar\ECO Bar\uninstall.exe
c:\program files\IEToolbar\ECO Bar\version.txt
c:\program files\IEToolbar\ECO Bar\your_logo.png
c:\windows\dcxi6156.exe
c:\windows\system32\drivers\gaopdxyfilllnsyfxumkosrtasmcnthemqxnbe.sys.vir
c:\windows\system32\ghuvqqytpqdvmcgs.dll.vir
c:\windows\system32\MxJ19YzK7nEym.vbs
c:\windows\system32\TcY3nhrZZFfChyv.vbs
c:\windows\system32\tmp99.tmp
C:\xcrashdump.dat
.
((((((((((((((((((((((((( Files Created from 2009-04-26 to 2009-05-26 )))))))))))))))))))))))))))))))
.
2009-05-16 00:15 . 2009-05-24 21:33 -------- d-----w c:\documents and settings\Taj\Application Data\DVD Flick
2009-05-16 00:14 . 2003-01-26 19:41 40960 ----a-w c:\windows\system32\ssubtmr6.dll
2009-05-16 00:14 . 2009-05-16 00:15 -------- d-----w c:\program files\DVD Flick
2009-05-15 21:57 . 2009-05-15 21:58 -------- d-----w c:\documents and settings\Taj\Application Data\Move Networks
2009-05-15 21:57 . 2009-05-15 21:57 34062 ----a-w c:\documents and settings\Taj\Application Data\Move Networks\ie_bin\Uninst.exe
2009-05-12 23:00 . 2009-05-12 23:03 -------- d-----w c:\program files\MKVtoolnix
2009-05-12 21:57 . 2009-05-14 02:29 -------- d-----w c:\program files\Total Video Converter
2009-05-12 08:43 . 2009-05-12 08:43 -------- d-----w c:\documents and settings\All Users\Application Data\Azureus
2009-05-12 08:43 . 2009-05-25 01:10 -------- d-----w c:\documents and settings\Taj\Application Data\Azureus
2009-05-12 08:42 . 2009-05-26 15:49 -------- d-----w c:\program files\Vuze
2009-05-04 21:48 . 2009-05-04 21:48 -------- d-----w c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-05-04 21:48 . 2009-05-04 21:48 -------- d-----w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-05-04 21:48 . 2009-05-04 21:48 -------- d-----w c:\program files\SDHelper (Spybot - Search & Destroy)
2009-05-04 21:48 . 2009-05-04 21:48 -------- d-----w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-05-04 20:18 . 2009-05-04 20:18 2967799 ----a-w c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-04-30 10:08 . 2009-04-30 10:08 131072 ----a-r c:\documents and settings\Taj\Application Data\Microsoft\Installer\{FA0BC743-0C8D-40C1-A074-BD4825A75A77}\NewShortcut1_3A4BEF94179B43DC838076EEC6DB5EF4.exe
2009-04-30 10:08 . 2009-04-30 10:08 131072 ----a-r c:\documents and settings\Taj\Application Data\Microsoft\Installer\{FA0BC743-0C8D-40C1-A074-BD4825A75A77}\NewShortcut3_3A4BEF94179B43DC838076EEC6DB5EF4.exe
2009-04-30 10:08 . 2009-04-30 10:08 10134 ----a-r c:\documents and settings\Taj\Application Data\Microsoft\Installer\{FA0BC743-0C8D-40C1-A074-BD4825A75A77}\ARPPRODUCTICON.exe
2009-04-30 10:08 . 2009-04-30 10:08 -------- d-----w c:\program files\Neoretix
2009-04-30 09:26 . 2009-03-30 23:53 2929528 ----a-w c:\documents and settings\Taj\Application Data\Simply Super Software\Trojan Remover\avrBC.exe
2009-04-30 06:38 . 2009-04-30 08:50 -------- d-----w c:\documents and settings\Taj\Application Data\Sony
2009-04-30 06:37 . 2009-05-03 20:04 -------- d-----w c:\documents and settings\Taj\Local Settings\Application Data\Sony
2009-04-30 06:28 . 2009-04-30 06:28 -------- d-----w c:\program files\Vstplugins
2009-04-30 06:28 . 2009-04-30 06:28 -------- d-----w c:\documents and settings\All Users\Application Data\Sony
2009-04-29 07:29 . 2006-06-19 20:01 69632 ----a-w c:\windows\system32\ztvcabinet.dll
2009-04-29 07:29 . 2006-05-25 22:52 162304 ----a-w c:\windows\system32\ztvunrar36.dll
2009-04-29 07:29 . 2005-08-26 08:50 77312 ----a-w c:\windows\system32\ztvunace26.dll
2009-04-29 07:29 . 2003-02-03 03:06 153088 ----a-w c:\windows\system32\UNRAR3.dll
2009-04-29 07:29 . 2002-03-06 08:00 75264 ----a-w c:\windows\system32\unacev2.dll
2009-04-29 07:29 . 2009-04-29 07:35 -------- d-----w c:\program files\Trojan Remover
2009-04-29 07:29 . 2009-04-29 07:29 -------- d-----w c:\documents and settings\All Users\Application Data\Simply Super Software
2009-04-29 07:29 . 2009-04-29 07:29 -------- d-----w c:\documents and settings\Taj\Application Data\Simply Super Software
2009-04-29 06:29 . 2009-04-29 06:33 -------- d-----w c:\documents and settings\Taj\dwhelper
2009-04-29 06:01 . 2009-04-29 06:01 864256 ----a-w c:\windows\system32\etrhsmon.exe
2009-04-29 06:01 . 2009-04-29 06:01 385024 ----a-w c:\windows\phirg5524.exe
2009-04-29 06:00 . 2009-04-29 06:00 92519 ----a-w c:\windows\jsda35556.exe
2009-04-29 05:58 . 2009-04-29 05:58 -------- d-----w c:\documents and settings\Taj\Local Settings\Application Data\Mozilla
2009-04-29 02:17 . 2009-04-29 02:17 -------- d-----w c:\program files\Sonic Foundry
2009-04-29 02:12 . 2009-05-03 19:56 -------- d-----w c:\program files\Sony
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-26 18:18 . 2009-03-31 18:33 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-12 22:05 . 2008-12-11 21:04 110456 ----a-w c:\documents and settings\Taj\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-12 22:01 . 2008-12-19 23:30 -------- d-----w c:\documents and settings\Taj\Application Data\LimeWire
2009-05-04 21:54 . 2009-03-30 17:26 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-05-04 20:18 . 2009-03-28 09:41 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-03 19:56 . 2008-12-15 04:41 -------- d-----w c:\program files\Sony Setup
2009-04-30 09:28 . 2009-04-01 08:47 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-29 08:56 . 2009-03-30 09:14 -------- d-----w c:\program files\Symantec
2009-04-29 08:56 . 2009-02-13 20:55 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-10 23:57 . 2009-02-08 19:38 -------- d-----w c:\documents and settings\Taj\Application Data\Creative
2009-04-10 23:53 . 2008-12-11 21:07 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-10 23:52 . 2009-02-13 21:51 -------- d--h--w c:\program files\Creative Installation Information
2009-04-10 23:46 . 2008-12-12 21:31 -------- d-----w c:\program files\Creative
2009-04-08 20:28 . 2008-12-12 22:06 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-08 20:07 . 2009-04-08 20:06 -------- d-----w c:\program files\iTunes
2009-04-08 20:07 . 2009-04-08 20:06 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-08 20:07 . 2009-04-08 20:07 -------- d-----w c:\program files\iPod
2009-04-08 20:07 . 2008-12-12 22:06 -------- d-----w c:\program files\Common Files\Apple
2009-04-08 19:53 . 2009-04-08 19:53 75048 ----a-w c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-08 19:37 . 2009-04-08 19:37 -------- d-----w c:\program files\Xvid
2009-04-06 22:32 . 2009-03-28 09:41 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 22:32 . 2009-03-28 09:41 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-01 08:50 . 2009-03-27 03:39 389 --sha-r C:\autorun.inf.vir
2009-04-01 08:21 . 2009-04-01 08:21 -------- d-----w c:\program files\Trend Micro
2009-04-01 08:01 . 2009-02-08 21:53 -------- d-----w c:\program files\RegCure
2009-03-31 21:48 . 2009-03-31 21:48 29360 ----a-w c:\windows\_SETUPD_.EXE
2009-03-31 18:29 . 2009-03-31 18:29 -------- d-----w c:\program files\CCleaner
2009-03-31 18:29 . 2009-03-31 18:29 -------- d-----w c:\program files\Yahoo!
2009-03-31 18:29 . 2009-03-31 18:29 -------- d-----w c:\documents and settings\Taj\Application Data\Yahoo!
2009-03-31 18:29 . 2009-03-31 18:29 -------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-03-31 08:08 . 2009-03-30 09:14 -------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-30 23:12 . 2009-03-30 23:12 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-30 22:59 . 2009-03-30 22:19 -------- d-----w c:\documents and settings\Taj\Application Data\HouseCall 6.6
2009-03-30 22:20 . 2009-03-30 22:20 116048 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\TmEngDrv.dll
2009-03-30 22:20 . 2009-03-30 22:20 98304 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\getMac.exe
2009-03-30 22:20 . 2009-03-30 22:20 69632 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\mfcm80.dll
2009-03-30 22:20 . 2009-03-30 22:20 626688 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\msvcr80.dll
2009-03-30 22:20 . 2009-03-30 22:20 57344 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\mfcm80u.dll
2009-03-30 22:20 . 2009-03-30 22:20 548864 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\msvcp80.dll
2009-03-30 22:20 . 2009-03-30 22:20 479232 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\msvcm80.dll
2009-03-30 22:20 . 2009-03-30 22:20 1093632 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\mfc80.dll
2009-03-30 22:20 . 2009-03-30 22:20 1079808 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\mfc80u.dll
2009-03-30 22:19 . 2009-03-30 22:19 218736 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\patch.exe
2009-03-30 22:19 . 2009-03-30 22:19 189968 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\ciussi32.dll
2009-03-30 22:19 . 2009-03-30 22:19 170512 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\PATCHW32.DLL
2009-03-30 22:19 . 2009-03-30 22:19 1267320 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\TmUpdate.dll
2009-03-30 22:19 . 2009-03-30 22:19 832776 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\lea.dll
2009-03-30 22:19 . 2009-03-30 22:19 61440 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\Toolkit.dll
2009-03-30 22:19 . 2009-03-30 22:19 439560 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\jlea.dll
2009-03-30 22:19 . 2009-03-30 22:19 42320 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\dsvout.dll
2009-03-30 22:19 . 2009-03-30 22:19 183356 ----a-w c:\documents and settings\Taj\Application Data\HouseCall 6.6\Uninstaller.exe
2009-03-30 17:39 . 2009-03-18 23:48 -------- d-----w c:\program files\Bonjour
2009-03-30 09:36 . 2009-03-30 09:14 60808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-03-30 09:36 . 2009-03-30 09:14 124464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-30 09:36 . 2009-03-29 22:47 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-03-30 09:36 . 2009-03-29 22:47 10635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-28 09:48 . 2009-01-26 21:27 -------- d-----w c:\program files\GlobalSCAPE
2009-03-19 23:32 . 2009-04-08 20:07 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-19 23:32 . 2009-03-19 23:32 23400 ----a-w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-09 17:29 . 2009-03-09 17:29 97144 ----a-w c:\documents and settings\Taj\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-03-09 17:29 . 2009-03-09 17:29 1010552 ----a-w c:\documents and settings\Taj\Application Data\Move Networks\ie_bin\qsp2ie071303000006.dll
2009-03-06 14:22 . 2004-08-04 10:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2006-03-04 03:33 826368 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"CreativeTaskScheduler"="c:\program files\Creative\Shared Files\CTSched.exe" [2006-11-17 53341]
"AOL Fast Start"="c:\program files\AOL 9.1\AOL.EXE" [2008-11-06 50472]
"Creative Software Update"="c:\program files\Creative\Shared Files\Software Update\AutoUpdate.exe" [2007-01-04 481200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-19 136600]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-06-16 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-16 7323648]
"HostManager"="c:\program files\Common Files\AOL\1232749054\ee\AOLSoftware.exe" [2007-05-25 42032]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"CTSVolFE"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"CTAPR2"="c:\program files\Creative\Sound Blaster X-Fi\Console Launcher\CTAPR2.exe" [2007-01-16 57344]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 184320]
"etrhsmon"="c:\windows\system32\etrhsmon.exe" [2009-04-29 864256]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-03-30 1213320]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2005-11-09 16384]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\Ctxfihlp.exe [2008-10-08 23552]
"SPIRun"="SPIRun.dll" - c:\windows\system32\SPIRun.dll [2006-11-29 8704]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-11 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave4"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Old Dell\\SmartFTP\\SmartFTP.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\aol\\1232749054\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\aol\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/23/2009 3:21 PM 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/30/2009 2:37 AM 101936]
R3 t3;SB Xtreme Audio Notebook;c:\windows\system32\drivers\t3.sys [2/13/2009 2:50 PM 735744]
R3 t3filt;t3filt;c:\windows\system32\drivers\t3filt.sys [2/13/2009 2:50 PM 1656960]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2/11/2009 4:30 PM 79360]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [10/8/2008 2:21 AM 171032]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [10/8/2008 2:21 AM 171032]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [10/8/2008 2:21 AM 1324056]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [10/8/2008 2:21 AM 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [10/8/2008 2:21 AM 72728]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [10/8/2008 2:21 AM 72728]
S3 PPDrv;Protector Plus Driver (UnRegistered);\??\c:\protector plus\PPDrv.sys --> c:\protector plus\PPDrv.sys [?]
S3 PPEMSCAN;Protector Plus Email Scan Driver;\??\c:\protector plus\PPEMSCAN.sys --> c:\protector plus\PPEMSCAN.sys [?]
S3 Usblink;Usblink Driver;c:\windows\system32\drivers\ulink.sys [12/11/2008 5:01 PM 40788]
.
Contents of the 'Scheduled Tasks' folder
2009-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2009-05-26 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]
2009-05-24 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/uInternet Settings,ProxyOverride = *.local
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-26 11:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?
SPIRun = Rundll32 SPIRun.dll,RunDLLEntry?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-05-26 11:43
ComboFix-quarantined-files.txt 2009-05-26 18:43
Pre-Run: 213,464,084,480 bytes free
Post-Run: 214,926,131,200 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
248 --- E O F --- 2009-05-13 10:01
NEW DDS.TXT:DDS (Ver_09-05-14.01) - NTFSx86
Run by Taj at 12:13:43.29 on Tue 05/26/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1453 [GMT -7:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\AOL\1232749054\ee\AOLSoftware.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\etrhsmon.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Shared Files\CTSched.exe
C:\Program Files\Creative\Shared Files\Software Update\AutoUpdate.exe
svchost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Taj\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page =
hxxp://www.yahoo.com/uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0988.2\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0988.2\msneshellx.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US
ee://aol/imAppuRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [CreativeTaskScheduler] "c:\program files\creative\shared files\CTSched.exe" /logon
uRun: [AOL Fast Start] "c:\program files\aol 9.1\AOL.EXE" -b
uRun: [Creative Software Update] "c:\program files\creative\shared files\software update\AutoUpdate.exe" /Silent
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [HostManager] c:\program files\common files\aol\1232749054\ee\AOLSoftware.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [CTHelper] CTHELPER.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [CTSVolFE] "c:\program files\creative\mixer\CTSVolFE.exe" /r
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [SPIRun] Rundll32 SPIRun.dll,RunDLLEntry
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [CTAPR2] "c:\program files\creative\sound blaster x-fi\console launcher\CTAPR2.exe" /r
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r
mRun: [etrhsmon] "c:\windows\system32\etrhsmon.exe"
mRun: [TrojanScanner] c:\program files\trojan remover\Trjscan.exe /boot
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} -
hxxp://upload.facebook.com/controls/200 ... oader5.cabDPF: {17492023-C23A-453E-A040-C7C580BBF700} -
hxxp://go.microsoft.com/fwlink/?linkid=39204DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://javadl.sun.com/webapps/download/ ... leId=26688DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://download.macromedia.com/pub/shoc ... wflash.cabDPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} -
hxxp://www.creative.com/softwareupdate/ ... /CTPID.cabHandler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-1-23 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-3-30 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090330.022\NAVENG.SYS [2009-3-30 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090330.022\NAVEX15.SYS [2009-3-30 876144]
R3 t3;SB Xtreme Audio Notebook;c:\windows\system32\drivers\t3.sys [2009-2-13 735744]
R3 t3filt;t3filt;c:\windows\system32\drivers\t3filt.sys [2009-2-13 1656960]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2009-2-11 79360]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2008-10-8 171032]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2008-10-8 171032]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2008-10-8 1324056]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2008-10-8 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2008-10-8 72728]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2008-10-8 72728]
S3 PPDrv;Protector Plus Driver (UnRegistered);\??\c:\protector plus\ppdrv.sys --> c:\protector plus\PPDrv.sys [?]
S3 PPEMSCAN;Protector Plus Email Scan Driver;\??\c:\protector plus\ppemscan.sys --> c:\protector plus\PPEMSCAN.sys [?]
S3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2009-3-29 1245064]
S3 Usblink;Usblink Driver;c:\windows\system32\drivers\ulink.sys [2008-12-11 40788]
=============== Created Last 30 ================
2009-05-26 11:37 <DIR> a-dshr-- C:\cmdcons
2009-05-26 11:36 161,792 a------- c:\windows\SWREG.exe
2009-05-26 11:36 154,624 a------- c:\windows\PEV.exe
2009-05-26 11:36 98,816 a------- c:\windows\sed.exe
2009-05-26 11:36 <DIR> --ds---- C:\ComboFix
2009-05-15 17:15 <DIR> --d----- c:\docume~1\taj\applic~1\DVD Flick
2009-05-15 17:14 40,960 a------- c:\windows\system32\ssubtmr6.dll
2009-05-15 17:14 36,864 a------- c:\windows\system32\trayicon_handler.ocx
2009-05-15 17:14 212,240 a------- c:\windows\system32\richtx32.ocx
2009-05-15 17:14 164,144 a------- c:\windows\system32\comct232.ocx
2009-05-15 17:14 28,672 a------- c:\windows\system32\mousewheel.ocx
2009-05-15 17:14 <DIR> --d----- c:\program files\DVD Flick
2009-05-12 16:00 <DIR> --d----- c:\program files\MKVtoolnix
2009-05-12 14:57 608,448 a------- c:\windows\system32\comctl32.ocx
2009-05-12 14:57 <DIR> --d----- c:\program files\Total Video Converter
2009-05-12 01:43 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Azureus
2009-05-12 01:43 <DIR> --d----- c:\docume~1\taj\applic~1\Azureus
2009-05-12 01:42 <DIR> --d----- c:\program files\Vuze
2009-05-04 14:48 <DIR> --d----- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-05-04 14:48 <DIR> --d----- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-05-04 14:48 <DIR> --d----- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-05-04 14:48 <DIR> --d----- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-04-30 03:08 <DIR> --d----- c:\program files\Neoretix
2009-04-29 23:28 <DIR> --d----- c:\program files\Vstplugins
2009-04-29 00:29 162,304 a------- c:\windows\system32\ztvunrar36.dll
2009-04-29 00:29 153,088 a------- c:\windows\system32\UNRAR3.dll
2009-04-29 00:29 77,312 a------- c:\windows\system32\ztvunace26.dll
2009-04-29 00:29 75,264 a------- c:\windows\system32\unacev2.dll
2009-04-29 00:29 69,632 a------- c:\windows\system32\ztvcabinet.dll
2009-04-29 00:29 <DIR> --d----- c:\program files\Trojan Remover
2009-04-29 00:29 <DIR> --d----- c:\docume~1\taj\applic~1\Simply Super Software
2009-04-29 00:29 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Simply Super Software
2009-04-28 23:29 <DIR> --d----- c:\documents and settings\taj\dwhelper
2009-04-28 23:01 864,256 a------- c:\windows\system32\etrhsmon.exe
2009-04-28 23:01 385,024 a------- c:\windows\phirg5524.exe
2009-04-28 23:00 92,519 a------- c:\windows\jsda35556.exe
2009-04-28 19:17 <DIR> --d----- c:\program files\Sonic Foundry
2009-04-28 19:12 <DIR> --d----- c:\program files\Sony
==================== Find3M ====================
2009-04-06 15:32 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 15:32 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-01 01:50 389 a--shr-- C:\autorun.inf.vir
2009-03-31 14:48 29,360 a------- c:\windows\_SETUPD_.EXE
2009-03-30 02:36 124,464 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-30 02:36 60,808 a------- c:\windows\system32\S32EVNT1.DLL
2009-03-30 02:36 10,635 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-30 02:36 806 a------- c:\windows\system32\drivers\SYMEVENT.INF
2009-03-06 07:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-02 17:18 826,368 a------- c:\windows\system32\wininet.dll
============= FINISH: 12:14:06.09 ===============
JUST IN CASE NEW ATTACH.TXT:UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-05-14.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 12/11/2008 1:52:16 AM
System Uptime: 5/26/2009 11:21:24 AM (1 hours ago)
Motherboard: Dell Inc. | | 0FJ030
Processor: Intel(R) Pentium(R) D CPU 2.80GHz | Microprocessor | 2793/800mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 466 GiB total, 200.191 GiB free.
D: is CDROM ()
E: is CDROM ()
H: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP144: 2/26/2009 3:00:14 AM - Software Distribution Service 3.0
RP145: 2/27/2009 3:10:29 AM - System Checkpoint
RP146: 2/27/2009 4:46:50 PM - Installed CuteFTP 7 Home
RP147: 3/1/2009 10:42:30 AM - System Checkpoint
RP148: 3/2/2009 11:57:40 AM - System Checkpoint
RP149: 3/3/2009 12:16:28 PM - System Checkpoint
RP150: 3/4/2009 12:19:01 PM - System Checkpoint
RP151: 3/5/2009 1:28:31 PM - System Checkpoint
RP152: 3/6/2009 1:45:38 PM - System Checkpoint
RP153: 3/7/2009 2:12:41 PM - System Checkpoint
RP154: 3/8/2009 3:01:00 PM - System Checkpoint
RP155: 3/9/2009 3:03:20 PM - System Checkpoint
RP156: 3/10/2009 6:30:04 PM - System Checkpoint
RP157: 3/11/2009 2:00:13 AM - Software Distribution Service 3.0
RP158: 3/12/2009 2:10:50 AM - System Checkpoint
RP159: 3/13/2009 2:00:13 AM - Software Distribution Service 3.0
RP160: 3/14/2009 2:34:50 AM - System Checkpoint
RP161: 3/15/2009 4:34:50 AM - System Checkpoint
RP162: 3/16/2009 5:10:50 AM - System Checkpoint
RP163: 3/17/2009 6:10:50 AM - System Checkpoint
RP164: 3/18/2009 7:10:50 AM - System Checkpoint
RP165: 3/19/2009 7:10:53 AM - System Checkpoint
RP166: 3/20/2009 8:10:54 AM - System Checkpoint
RP167: 3/21/2009 9:10:55 AM - System Checkpoint
RP168: 3/22/2009 10:11:59 AM - System Checkpoint
RP169: 3/23/2009 11:32:36 AM - System Checkpoint
RP170: 3/24/2009 11:36:14 AM - System Checkpoint
RP171: 3/25/2009 3:30:05 PM - System Checkpoint
RP172: 3/26/2009 4:06:03 PM - System Checkpoint
RP173: 3/28/2009 2:48:12 AM - System Checkpoint
RP174: 4/1/2009 2:23:40 AM - System Checkpoint
RP175: 4/1/2009 1:17:35 PM - Spybot-S&D Spyware removal
RP176: 4/1/2009 1:18:16 PM - Removed Security Scanner Full
RP177: 4/2/2009 4:58:56 PM - System Checkpoint
RP178: 4/3/2009 5:38:51 PM - System Checkpoint
RP179: 4/4/2009 5:57:06 PM - System Checkpoint
RP180: 4/5/2009 6:14:55 PM - System Checkpoint
RP181: 4/6/2009 6:57:06 PM - System Checkpoint
RP182: 4/7/2009 7:57:06 PM - System Checkpoint
RP183: 4/8/2009 9:16:21 PM - System Checkpoint
RP184: 4/9/2009 10:03:34 PM - System Checkpoint
RP185: 4/10/2009 4:42:59 PM - Installed Sound Blaster X-Fi
RP186: 4/10/2009 4:51:48 PM - Configured Creative MediaSource 5
RP187: 4/10/2009 4:53:33 PM - Installed Creative Software AutoUpdate
RP188: 4/11/2009 6:22:37 PM - System Checkpoint
RP189: 4/12/2009 6:30:05 PM - System Checkpoint
RP190: 4/13/2009 7:30:05 PM - System Checkpoint
RP191: 4/14/2009 8:30:06 PM - System Checkpoint
RP192: 4/15/2009 3:00:14 AM - Software Distribution Service 3.0
RP193: 4/16/2009 3:14:11 AM - System Checkpoint
RP194: 4/17/2009 3:16:12 AM - System Checkpoint
RP195: 4/18/2009 4:07:21 AM - System Checkpoint
RP196: 4/19/2009 5:07:21 AM - System Checkpoint
RP197: 4/20/2009 9:44:34 AM - System Checkpoint
RP198: 4/21/2009 11:18:35 AM - System Checkpoint
RP199: 4/22/2009 11:38:08 AM - System Checkpoint
RP200: 4/23/2009 11:39:56 AM - System Checkpoint
RP201: 4/24/2009 11:44:33 AM - System Checkpoint
RP202: 4/25/2009 11:44:37 AM - System Checkpoint
RP203: 4/26/2009 12:44:37 PM - System Checkpoint
RP204: 4/27/2009 1:57:45 PM - System Checkpoint
RP205: 4/28/2009 2:37:34 PM - System Checkpoint
RP206: 4/28/2009 7:11:55 PM - Installed Sony Sound Forge 7.0
RP207: 4/28/2009 7:14:34 PM - Removed Sonic Foundry ACID 4.0e
RP208: 4/28/2009 7:17:32 PM - Installed Sonic Foundry ACID 4.0e
RP209: 4/29/2009 1:56:30 AM - Removed LiveUpdate (Symantec Corporation)
RP210: 4/29/2009 11:27:55 PM - Installed Vegas Movie Studio Platinum 9.0
RP211: 4/30/2009 3:08:00 AM - Installed TubeHunter Ultra
RP212: 5/1/2009 4:42:43 AM - System Checkpoint
RP213: 5/2/2009 5:34:02 AM - System Checkpoint
RP214: 5/3/2009 6:29:45 AM - System Checkpoint
RP215: 5/3/2009 12:56:36 PM - Installed Sony DVD Architect Studio 4.5
RP216: 5/4/2009 2:03:51 PM - System Checkpoint
RP217: 5/4/2009 3:31:17 PM - Spybot-S&D Spyware removal
RP218: 5/5/2009 3:57:13 PM - System Checkpoint
RP219: 5/6/2009 4:43:01 PM - System Checkpoint
RP220: 5/7/2009 5:26:20 PM - System Checkpoint
RP221: 5/8/2009 5:59:48 PM - System Checkpoint
RP222: 5/9/2009 9:32:37 PM - System Checkpoint
RP223: 5/10/2009 10:27:05 PM - System Checkpoint
RP224: 5/12/2009 2:17:38 AM - System Checkpoint
RP225: 5/13/2009 3:00:15 AM - Software Distribution Service 3.0
RP226: 5/14/2009 8:20:08 AM - System Checkpoint
RP227: 5/15/2009 8:36:37 AM - System Checkpoint
RP228: 5/16/2009 11:42:33 AM - System Checkpoint
RP229: 5/17/2009 11:53:59 AM - System Checkpoint
RP230: 5/18/2009 12:36:50 PM - System Checkpoint
RP231: 5/18/2009 6:44:03 PM - Spybot-S&D Spyware removal
RP232: 5/19/2009 7:00:37 PM - System Checkpoint
RP233: 5/20/2009 8:16:37 PM - System Checkpoint
RP234: 5/21/2009 8:21:39 PM - System Checkpoint
RP235: 5/22/2009 8:59:05 PM - System Checkpoint
RP236: 5/23/2009 10:32:20 PM - System Checkpoint
RP237: 5/25/2009 10:13:25 AM - System Checkpoint
RP238: 5/26/2009 10:15:28 AM - System Checkpoint
==== Installed Programs ======================
32 bit Windows Card Reader Driver
530TX+
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop 7.0
Adobe Reader 9
AGEIA PhysX v6.11.13
AIM 6
AOL Uninstaller (Choose which Products to Remove)
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Parental Control
Bonjour
CCleaner (remove only)
Conexant D850 56K V.9x DFVc Modem
Cool Edit Pro 2.0
Creative Audio Control Panel
Creative Diagnostics
Creative MediaSource 5
Creative Software AutoUpdate
Creative System Information
Creative WaveStudio 7
Critical Update for Windows Media Player 11 (KB959772)
CuteFTP
CuteFTP 7 Home
D-Link PCI Fast Ethernet Adapter
DVD Flick 1.3.0.6
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HouseCall 6.6
Intel(R) Matrix Storage Manager
Intel(R) PRO Network Connections Drivers
iTunes
Java(TM) 6 Update 11
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mixer
MKVtoolnix 2.8.0
Move Networks Media Player for Internet Explorer
MSN Toolbar
MSXML 6.0 Parser (KB925673)
NVIDIA Drivers
OpenAL
QuickTime
RegCure 1.5.2.7
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
SigmaTel Audio
Sonic DLA
Sonic Foundry ACID 4.0e
Sonic RecordNow!
Sonic Update Manager
Sony DVD Architect Studio 4.5
Sony Sound Forge 7.0
Sound Blaster Audigy ADVANCED MB Demo
Sound Blaster X-Fi
SoundFont Bank Manager
Spybot - Search & Destroy
Spybot - Search & Destroy 1.4
Symantec Real Time Storage Protection Component
Total Video Converter 3.10
Trojan Remover 6.7.8
TubeHunter Ultra
ULi USB2.0 Driver
Uninstall AOL Emergency Connect Utility 1.0
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
USB Super Link
Vegas Movie Studio Platinum 9.0
Viewpoint Media Player
WebFldrs XP
Winamp
Windows Communication Foundation
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
WinRAR archiver
XML Paper Specification Shared Components Pack 1.0
Xvid 1.1.3 final uninstall
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
5/26/2009 11:39:04 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
5/24/2009 6:09:58 PM, error: Service Control Manager [7000] - The PfModNT service failed to start due to the following error: The system cannot find the file specified.
5/21/2009 1:55:38 PM, error: Service Control Manager [7000] - The Creative Audio Service service failed to start due to the following error: The system cannot find the file specified.
5/21/2009 1:55:37 PM, error: DCOM [10005] - DCOM got error "%1055" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
5/21/2009 1:55:37 PM, error: DCOM [10005] - DCOM got error "%1055" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
5/21/2009 1:55:37 PM, error: DCOM [10005] - DCOM got error "%1055" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
==== End Of File ===========================