NineMilesHigh
Posts: 56 +0
Hi.
Thanks in advance for any help.
I opened a thread in the BSOD forum as after getting the System Tool virus, my Windows XP system was giving a blue screeen error and would not reboot - looked like disk corruption. I got some help from Route44. After running chdsk /r the system started to reboot ok, but I would like to check if all malware is gone, so I have run through the 8-part process recommended.
Below are the logs:-
MBAM:-
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5403
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
27/12/2010 20:01:05
mbam-log-2010-12-27 (20-01-05).txt
Scan type: Full scan (C:\|)
Objects scanned: 337923
Time elapsed: 3 hour(s), 49 minute(s), 43 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\RP2549\A0630966.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\RP2553\A0631265.dll (Adware.Agent) -> Quarantined and deleted successfully.
GMER:-
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2010-12-27 22:13:14
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 Maxtor_6Y080L0 rev.YAR41BW0
Running: kk2dyyhv.exe; Driver: C:\DOCUME~1\William\LOCALS~1\Temp\kwtdipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
DDS:- Attach
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 20/12/2003 18:58:12
System Uptime: 27/12/2010 20:02:10 (2 hours ago)
Motherboard: Dell Computer Corp. | | 0N2828
Processor: Intel(R) Pentium(R) 4 CPU 3.06GHz | Microprocessor | 3059/533mhz
Processor: Intel(R) Pentium(R) 4 CPU 3.06GHz | Microprocessor | 3059/533mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 74 GiB total, 4.124 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is FIXED (FAT) - 2 GiB total, 1.993 GiB free.
G: is FIXED (NTFS) - 26 GiB total, 15.175 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia 6303 classic
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 6303 classic
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd
==== System Restore Points ===================
RP2491: 13/11/2010 13:37:40 - Software Distribution Service 3.0
RP2492: 14/11/2010 01:36:46 - Software Distribution Service 3.0
RP2493: 15/11/2010 02:52:26 - System Checkpoint
RP2494: 15/11/2010 02:54:27 - Software Distribution Service 3.0
RP2495: 16/11/2010 04:09:05 - Software Distribution Service 3.0
RP2496: 17/11/2010 00:38:09 - Software Distribution Service 3.0
RP2497: 18/11/2010 00:53:39 - System Checkpoint
RP2498: 18/11/2010 03:01:14 - Software Distribution Service 3.0
RP2499: 19/11/2010 00:53:14 - Software Distribution Service 3.0
RP2500: 19/11/2010 21:20:51 - Removed Ask Toolbar.
RP2501: 20/11/2010 01:33:22 - Software Distribution Service 3.0
RP2502: 21/11/2010 01:36:46 - Software Distribution Service 3.0
RP2503: 21/11/2010 23:52:04 - Software Distribution Service 3.0
RP2504: 23/11/2010 00:18:25 - System Checkpoint
RP2505: 23/11/2010 03:37:11 - Software Distribution Service 3.0
RP2506: 24/11/2010 01:56:34 - Software Distribution Service 3.0
RP2507: 24/11/2010 14:29:19 - Installed Nitro PDF Professional
RP2508: 25/11/2010 01:36:28 - Software Distribution Service 3.0
RP2509: 25/11/2010 11:15:31 - Printer Driver CutePDF Writer Installed
RP2510: 25/11/2010 23:04:23 - Removed Ask Toolbar.
RP2511: 26/11/2010 01:04:57 - Software Distribution Service 3.0
RP2512: 27/11/2010 00:53:54 - Software Distribution Service 3.0
RP2513: 27/11/2010 23:29:13 - Software Distribution Service 3.0
RP2514: 28/11/2010 23:54:55 - System Checkpoint
RP2515: 29/11/2010 00:04:23 - Software Distribution Service 3.0
RP2516: 30/11/2010 00:37:06 - System Checkpoint
RP2517: 30/11/2010 00:53:28 - Software Distribution Service 3.0
RP2518: 30/11/2010 23:50:51 - Software Distribution Service 3.0
RP2519: 02/12/2010 02:21:20 - System Checkpoint
RP2520: 02/12/2010 02:30:27 - Software Distribution Service 3.0
RP2521: 02/12/2010 23:59:22 - Software Distribution Service 3.0
RP2522: 04/12/2010 00:20:56 - Software Distribution Service 3.0
RP2523: 04/12/2010 23:54:41 - Software Distribution Service 3.0
RP2524: 06/12/2010 00:07:15 - Software Distribution Service 3.0
RP2525: 07/12/2010 00:04:52 - Software Distribution Service 3.0
RP2526: 07/12/2010 22:59:45 - Software Distribution Service 3.0
RP2527: 08/12/2010 22:48:46 - Software Distribution Service 3.0
RP2528: 09/12/2010 11:36:50 - Installed Sibelius 6
RP2529: 10/12/2010 02:34:40 - Software Distribution Service 3.0
RP2530: 11/12/2010 00:15:22 - Software Distribution Service 3.0
RP2531: 12/12/2010 00:33:03 - System Checkpoint
RP2532: 12/12/2010 00:34:39 - Software Distribution Service 3.0
RP2533: 12/12/2010 23:31:31 - Software Distribution Service 3.0
RP2534: 13/12/2010 23:24:10 - Software Distribution Service 3.0
RP2535: 14/12/2010 00:05:05 - Software Distribution Service 3.0
RP2536: 15/12/2010 00:08:05 - Software Distribution Service 3.0
RP2537: 16/12/2010 01:02:40 - System Checkpoint
RP2538: 16/12/2010 03:04:29 - Software Distribution Service 3.0
RP2539: 17/12/2010 01:32:44 - Software Distribution Service 3.0
RP2540: 18/12/2010 00:45:54 - Software Distribution Service 3.0
RP2541: 19/12/2010 01:30:12 - System Checkpoint
RP2542: 19/12/2010 03:51:42 - Software Distribution Service 3.0
RP2543: 19/12/2010 23:42:39 - Software Distribution Service 3.0
RP2544: 21/12/2010 01:35:07 - Software Distribution Service 3.0
RP2545: 22/12/2010 00:03:35 - Software Distribution Service 3.0
RP2546: 23/12/2010 01:57:02 - Software Distribution Service 3.0
RP2547: 23/12/2010 23:52:04 - Software Distribution Service 3.0
RP2548: 24/12/2010 23:46:05 - Software Distribution Service 3.0
RP2549: 26/12/2010 01:45:08 - Software Distribution Service 3.0
RP2550: 27/12/2010 12:49:24 - Removed Microsoft Visual C++ 2005 Redistributable
RP2551: 27/12/2010 12:51:44 - Installed SeaTools for Windows
RP2552: 27/12/2010 14:27:56 - Installed Java(TM) 6 Update 23
RP2553: 27/12/2010 14:33:50 - Removed Adobe Reader 9.4.1.
==== Installed Programs ======================
1.6
32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop 6.0
Adobe Reader X
Adobe Shockwave Player 11.5
AOL Uninstaller (Choose which Products to Remove)
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Avira AntiVir Personal - Free Antivirus
BCM V.92 56K Modem
BitZipper 2010
Bonjour
BufferChm
Camera Window
Canon Camera Window for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities File Viewer Utility 1.3
Canon Utilities PhotoStitch 3.1
Canon Utilities RemoteCapture 2.7
CCleaner
CDBurnerXP Pro 3
CdCoverCreator 2.5.3
Chords & Scales
CIG
Copy
Corel VideoStudio 12
CutePDF Writer 2.8
DA920EN
Delta
Destinations
DeviceDiscovery
Digidesign D-Fi
Digidesign D-fx
DJ_AIO_06_F2400_SW_Min
DVDSentry
Easy CD and DVD Cover Creator 4.12
F2400
File Viewer Utility 1.3.2
Focusrite d3
FrostWire 4.21.1
getPlus(R) Download Manager for Corel
Google Update Helper
GPBaseService2
GrooveBox
Guitar Pro 5.2
HDDlife
HiJackThis
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB942288-v3)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6
HP Imaging Device Functions 13.0
HP Print Projects 1.0
HP Solution Center 13.0
HP Update
hpPrintProjects
HPProductAssistant
hpWLPGInstaller
Intel(R) PRO Network Adapters and Drivers
iPod for Windows 2005-03-23
iPod for Windows 2006-01-10
iTunes
Java Auto Updater
Java(TM) 6 Update 23
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.5
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MSVC80_x86
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
Nitro PDF Professional
NVIDIA Drivers
PC Connectivity Solution
PhotoStitch
Pinnacle Studio 14
Pinnacle Video Driver
PNY Vibe MP3 Player
QuickTime
RAW Image Task
Reason 3.0.4
RegScrubXP 3.25
RemoteCapture 2.7.5
RemoteCapture Task
SafeCast Shared Components
Scan
SeaTools for Windows
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Segoe UI
Sibelius 6
Sibelius Scorch (ActiveX Only)
SmartSound Quicktracks Plugin
SolutionCenter
SPT-667 Phrase Trainer 1
Status
Steinberg SX Unlocked VST Plugins Pack 1
Steinberg SX Unlocked VST Plugins Pack 2
System Requirements Lab
System Tool2011
Toolbox
TrayApp
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB925720)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
USB Device Driver 3.00P
VideoStudio
WebFldrs XP
WebReg
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Hotfix [See Q828026 for more information]
WinZip 14.0
XviD MPEG-4 Video Codec
==== Event Viewer Messages From Past Week ========
27/12/2010 14:08:39, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
27/12/2010 12:32:59, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the COM+ System Application service, but this action failed with the following error: An instance of the service is already running.
27/12/2010 12:32:58, error: Service Control Manager [7031] - The COM+ System Application service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
26/12/2010 22:56:17, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
26/12/2010 22:21:00, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
26/12/2010 22:20:54, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avgio avipbb Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss ssmdrv Tcpip
26/12/2010 22:20:54, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The QoS RSVP service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBT service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:44, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
26/12/2010 15:14:55, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
26/12/2010 15:05:06, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Apple Mobile Device service to connect.
26/12/2010 15:05:06, error: Service Control Manager [7000] - The Apple Mobile Device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
26/12/2010 15:04:04, error: Service Control Manager [7034] - The WMI Performance Adapter service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The WMDM PMSP Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The NLS Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The NitroPDFDriverCreatorReadSpool service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The LexBce Server service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The IMAPI CD-Burning COM Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The C-DillaCdaC11BA service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The AOL Connectivity Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
24/12/2010 23:46:12, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB954459).
24/12/2010 07:42:25, error: Service Control Manager [7000] - The Upload Manager service failed to start due to the following error: The account specified for this service is different from the account specified for other services running in the same process.
24/12/2010 07:42:25, error: Service Control Manager [7000] - The Panasonic Digital Palmcorder service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
23/12/2010 09:39:10, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
23/12/2010 09:39:10, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
23/12/2010 09:39:10, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
21/12/2010 11:17:18, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
21/12/2010 11:16:29, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.
==== End Of File ===========================
DDS:-
DDS (Ver_10-12-12.02) - NTFSx86
Run by William at 22:16:25.17 on 27/12/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2559.1919 [GMT 0:00]
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
C:\WINDOWS\system32\NLSSRV32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\DeltTray.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\AOL\1261605241\ee\AOLSoftware.exe
C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\William\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.bbc.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {2E608F70-C430-4BC5-96F6-608E02EBA5B2} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
{555d4d79-4bd2-4094-a395-cfc534424a05}
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [DeltTray] DeltTray.exe
mRun: [BCMSMMSG] BCMSMMSG.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HostManager] c:\program files\common files\aol\1261605241\ee\AOLSoftware.exe
mRun: [USBToolTip] c:\progra~1\pinnacle\shared~1\programs\usbtip\USBTip.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
uPolicies-explorer: NoSimpleStartMenu = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab
DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/msnmessengersetupdownloader.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-12-27 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-12-27 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-12-27 267944]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-12-27 61960]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\nitro pdf\professional\NitroPDFDriverService.exe [2010-10-20 196928]
R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2010-10-20 67904]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-8-26 133104]
S3 FTLUND;Lundinova Filter Driver;c:\windows\system32\drivers\ftlund.sys [2008-1-28 6828]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2009-8-3 17408]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2002-8-29 14336]
=============== Created Last 30 ================
2010-12-27 15:45:21 -------- d-----w- c:\docume~1\william\applic~1\Avira
2010-12-27 15:39:12 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-27 15:39:11 -------- d-----w- c:\program files\Avira
2010-12-27 15:39:11 -------- d-----w- c:\docume~1\alluse~1\applic~1\Avira
2010-12-27 14:28:43 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-27 12:51:52 11264 ----a-r- c:\docume~1\william\applic~1\microsoft\installer\{98613c99-1399-416c-a07c-1ee1c585d872}\Icon98613C992.exe
2010-12-27 12:51:46 -------- d-----w- c:\program files\Seagate
2010-12-27 12:49:01 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2010-12-26 14:56:21 0 ----a-w- c:\windows\Tsehahedil.bin
2010-12-26 14:56:16 -------- d-----w- c:\docume~1\william\locals~1\applic~1\{4F5CD3E9-C7BC-428B-AA17-6895598319D8}
2010-12-26 14:53:59 -------- d-----w- c:\docume~1\alluse~1\applic~1\mIcLl06511
2010-12-09 11:40:19 -------- d-----w- c:\docume~1\alluse~1\applic~1\Sibelius Software
2010-12-09 11:27:16 17464 ----a-w- c:\windows\gboxdrum.dat
2010-12-09 11:27:15 92728 ----a-w- c:\windows\gbox.dat
2010-12-09 11:27:02 -------- d-----w- c:\program files\GrooveBox
2010-12-09 11:23:35 -------- d-----w- c:\program files\Chords & Scales
2010-12-09 11:18:54 -------- d-----w- c:\program files\PhraseTrainer
2010-12-09 11:16:13 -------- d-----w- c:\program files\Desktop Metronome
==================== Find3M ====================
2010-11-12 16:34:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-10-20 17:41:22 67904 ----a-w- c:\windows\system32\NLSSRV32.EXE
2010-10-20 17:38:58 17728 ----a-w- c:\windows\system32\nitrolocalui.dll
2010-10-20 17:38:56 26432 ----a-w- c:\windows\system32\nitrolocalmon.dll
============= FINISH: 22:17:59.76 ===============
These look like long files - hope it is OK to paste them in as requested.
Thanks
William.
Thanks in advance for any help.
I opened a thread in the BSOD forum as after getting the System Tool virus, my Windows XP system was giving a blue screeen error and would not reboot - looked like disk corruption. I got some help from Route44. After running chdsk /r the system started to reboot ok, but I would like to check if all malware is gone, so I have run through the 8-part process recommended.
Below are the logs:-
MBAM:-
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5403
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
27/12/2010 20:01:05
mbam-log-2010-12-27 (20-01-05).txt
Scan type: Full scan (C:\|)
Objects scanned: 337923
Time elapsed: 3 hour(s), 49 minute(s), 43 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\RP2549\A0630966.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\RP2553\A0631265.dll (Adware.Agent) -> Quarantined and deleted successfully.
GMER:-
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2010-12-27 22:13:14
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 Maxtor_6Y080L0 rev.YAR41BW0
Running: kk2dyyhv.exe; Driver: C:\DOCUME~1\William\LOCALS~1\Temp\kwtdipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
DDS:- Attach
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 20/12/2003 18:58:12
System Uptime: 27/12/2010 20:02:10 (2 hours ago)
Motherboard: Dell Computer Corp. | | 0N2828
Processor: Intel(R) Pentium(R) 4 CPU 3.06GHz | Microprocessor | 3059/533mhz
Processor: Intel(R) Pentium(R) 4 CPU 3.06GHz | Microprocessor | 3059/533mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 74 GiB total, 4.124 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is FIXED (FAT) - 2 GiB total, 1.993 GiB free.
G: is FIXED (NTFS) - 26 GiB total, 15.175 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia 6303 classic
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 6303 classic
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd
==== System Restore Points ===================
RP2491: 13/11/2010 13:37:40 - Software Distribution Service 3.0
RP2492: 14/11/2010 01:36:46 - Software Distribution Service 3.0
RP2493: 15/11/2010 02:52:26 - System Checkpoint
RP2494: 15/11/2010 02:54:27 - Software Distribution Service 3.0
RP2495: 16/11/2010 04:09:05 - Software Distribution Service 3.0
RP2496: 17/11/2010 00:38:09 - Software Distribution Service 3.0
RP2497: 18/11/2010 00:53:39 - System Checkpoint
RP2498: 18/11/2010 03:01:14 - Software Distribution Service 3.0
RP2499: 19/11/2010 00:53:14 - Software Distribution Service 3.0
RP2500: 19/11/2010 21:20:51 - Removed Ask Toolbar.
RP2501: 20/11/2010 01:33:22 - Software Distribution Service 3.0
RP2502: 21/11/2010 01:36:46 - Software Distribution Service 3.0
RP2503: 21/11/2010 23:52:04 - Software Distribution Service 3.0
RP2504: 23/11/2010 00:18:25 - System Checkpoint
RP2505: 23/11/2010 03:37:11 - Software Distribution Service 3.0
RP2506: 24/11/2010 01:56:34 - Software Distribution Service 3.0
RP2507: 24/11/2010 14:29:19 - Installed Nitro PDF Professional
RP2508: 25/11/2010 01:36:28 - Software Distribution Service 3.0
RP2509: 25/11/2010 11:15:31 - Printer Driver CutePDF Writer Installed
RP2510: 25/11/2010 23:04:23 - Removed Ask Toolbar.
RP2511: 26/11/2010 01:04:57 - Software Distribution Service 3.0
RP2512: 27/11/2010 00:53:54 - Software Distribution Service 3.0
RP2513: 27/11/2010 23:29:13 - Software Distribution Service 3.0
RP2514: 28/11/2010 23:54:55 - System Checkpoint
RP2515: 29/11/2010 00:04:23 - Software Distribution Service 3.0
RP2516: 30/11/2010 00:37:06 - System Checkpoint
RP2517: 30/11/2010 00:53:28 - Software Distribution Service 3.0
RP2518: 30/11/2010 23:50:51 - Software Distribution Service 3.0
RP2519: 02/12/2010 02:21:20 - System Checkpoint
RP2520: 02/12/2010 02:30:27 - Software Distribution Service 3.0
RP2521: 02/12/2010 23:59:22 - Software Distribution Service 3.0
RP2522: 04/12/2010 00:20:56 - Software Distribution Service 3.0
RP2523: 04/12/2010 23:54:41 - Software Distribution Service 3.0
RP2524: 06/12/2010 00:07:15 - Software Distribution Service 3.0
RP2525: 07/12/2010 00:04:52 - Software Distribution Service 3.0
RP2526: 07/12/2010 22:59:45 - Software Distribution Service 3.0
RP2527: 08/12/2010 22:48:46 - Software Distribution Service 3.0
RP2528: 09/12/2010 11:36:50 - Installed Sibelius 6
RP2529: 10/12/2010 02:34:40 - Software Distribution Service 3.0
RP2530: 11/12/2010 00:15:22 - Software Distribution Service 3.0
RP2531: 12/12/2010 00:33:03 - System Checkpoint
RP2532: 12/12/2010 00:34:39 - Software Distribution Service 3.0
RP2533: 12/12/2010 23:31:31 - Software Distribution Service 3.0
RP2534: 13/12/2010 23:24:10 - Software Distribution Service 3.0
RP2535: 14/12/2010 00:05:05 - Software Distribution Service 3.0
RP2536: 15/12/2010 00:08:05 - Software Distribution Service 3.0
RP2537: 16/12/2010 01:02:40 - System Checkpoint
RP2538: 16/12/2010 03:04:29 - Software Distribution Service 3.0
RP2539: 17/12/2010 01:32:44 - Software Distribution Service 3.0
RP2540: 18/12/2010 00:45:54 - Software Distribution Service 3.0
RP2541: 19/12/2010 01:30:12 - System Checkpoint
RP2542: 19/12/2010 03:51:42 - Software Distribution Service 3.0
RP2543: 19/12/2010 23:42:39 - Software Distribution Service 3.0
RP2544: 21/12/2010 01:35:07 - Software Distribution Service 3.0
RP2545: 22/12/2010 00:03:35 - Software Distribution Service 3.0
RP2546: 23/12/2010 01:57:02 - Software Distribution Service 3.0
RP2547: 23/12/2010 23:52:04 - Software Distribution Service 3.0
RP2548: 24/12/2010 23:46:05 - Software Distribution Service 3.0
RP2549: 26/12/2010 01:45:08 - Software Distribution Service 3.0
RP2550: 27/12/2010 12:49:24 - Removed Microsoft Visual C++ 2005 Redistributable
RP2551: 27/12/2010 12:51:44 - Installed SeaTools for Windows
RP2552: 27/12/2010 14:27:56 - Installed Java(TM) 6 Update 23
RP2553: 27/12/2010 14:33:50 - Removed Adobe Reader 9.4.1.
==== Installed Programs ======================
1.6
32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop 6.0
Adobe Reader X
Adobe Shockwave Player 11.5
AOL Uninstaller (Choose which Products to Remove)
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Avira AntiVir Personal - Free Antivirus
BCM V.92 56K Modem
BitZipper 2010
Bonjour
BufferChm
Camera Window
Canon Camera Window for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities File Viewer Utility 1.3
Canon Utilities PhotoStitch 3.1
Canon Utilities RemoteCapture 2.7
CCleaner
CDBurnerXP Pro 3
CdCoverCreator 2.5.3
Chords & Scales
CIG
Copy
Corel VideoStudio 12
CutePDF Writer 2.8
DA920EN
Delta
Destinations
DeviceDiscovery
Digidesign D-Fi
Digidesign D-fx
DJ_AIO_06_F2400_SW_Min
DVDSentry
Easy CD and DVD Cover Creator 4.12
F2400
File Viewer Utility 1.3.2
Focusrite d3
FrostWire 4.21.1
getPlus(R) Download Manager for Corel
Google Update Helper
GPBaseService2
GrooveBox
Guitar Pro 5.2
HDDlife
HiJackThis
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB942288-v3)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6
HP Imaging Device Functions 13.0
HP Print Projects 1.0
HP Solution Center 13.0
HP Update
hpPrintProjects
HPProductAssistant
hpWLPGInstaller
Intel(R) PRO Network Adapters and Drivers
iPod for Windows 2005-03-23
iPod for Windows 2006-01-10
iTunes
Java Auto Updater
Java(TM) 6 Update 23
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.5
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MSVC80_x86
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
Nitro PDF Professional
NVIDIA Drivers
PC Connectivity Solution
PhotoStitch
Pinnacle Studio 14
Pinnacle Video Driver
PNY Vibe MP3 Player
QuickTime
RAW Image Task
Reason 3.0.4
RegScrubXP 3.25
RemoteCapture 2.7.5
RemoteCapture Task
SafeCast Shared Components
Scan
SeaTools for Windows
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Segoe UI
Sibelius 6
Sibelius Scorch (ActiveX Only)
SmartSound Quicktracks Plugin
SolutionCenter
SPT-667 Phrase Trainer 1
Status
Steinberg SX Unlocked VST Plugins Pack 1
Steinberg SX Unlocked VST Plugins Pack 2
System Requirements Lab
System Tool2011
Toolbox
TrayApp
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB925720)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
USB Device Driver 3.00P
VideoStudio
WebFldrs XP
WebReg
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Hotfix [See Q828026 for more information]
WinZip 14.0
XviD MPEG-4 Video Codec
==== Event Viewer Messages From Past Week ========
27/12/2010 14:08:39, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
27/12/2010 12:32:59, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the COM+ System Application service, but this action failed with the following error: An instance of the service is already running.
27/12/2010 12:32:58, error: Service Control Manager [7031] - The COM+ System Application service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
26/12/2010 22:56:17, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
26/12/2010 22:21:00, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
26/12/2010 22:20:54, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avgio avipbb Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss ssmdrv Tcpip
26/12/2010 22:20:54, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The QoS RSVP service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBT service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:54, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
26/12/2010 22:20:44, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
26/12/2010 15:14:55, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
26/12/2010 15:05:06, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Apple Mobile Device service to connect.
26/12/2010 15:05:06, error: Service Control Manager [7000] - The Apple Mobile Device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
26/12/2010 15:04:04, error: Service Control Manager [7034] - The WMI Performance Adapter service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The WMDM PMSP Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The NLS Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The NitroPDFDriverCreatorReadSpool service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The LexBce Server service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The IMAPI CD-Burning COM Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The C-DillaCdaC11BA service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7034] - The AOL Connectivity Service service terminated unexpectedly. It has done this 1 time(s).
26/12/2010 15:04:04, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
24/12/2010 23:46:12, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB954459).
24/12/2010 07:42:25, error: Service Control Manager [7000] - The Upload Manager service failed to start due to the following error: The account specified for this service is different from the account specified for other services running in the same process.
24/12/2010 07:42:25, error: Service Control Manager [7000] - The Panasonic Digital Palmcorder service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
23/12/2010 09:39:10, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
23/12/2010 09:39:10, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
23/12/2010 09:39:10, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
21/12/2010 11:17:18, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
21/12/2010 11:16:29, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.
==== End Of File ===========================
DDS:-
DDS (Ver_10-12-12.02) - NTFSx86
Run by William at 22:16:25.17 on 27/12/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2559.1919 [GMT 0:00]
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
C:\WINDOWS\system32\NLSSRV32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\DeltTray.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\AOL\1261605241\ee\AOLSoftware.exe
C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\William\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.bbc.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {2E608F70-C430-4BC5-96F6-608E02EBA5B2} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
{555d4d79-4bd2-4094-a395-cfc534424a05}
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [DeltTray] DeltTray.exe
mRun: [BCMSMMSG] BCMSMMSG.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HostManager] c:\program files\common files\aol\1261605241\ee\AOLSoftware.exe
mRun: [USBToolTip] c:\progra~1\pinnacle\shared~1\programs\usbtip\USBTip.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
uPolicies-explorer: NoSimpleStartMenu = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab
DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/msnmessengersetupdownloader.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-12-27 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-12-27 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-12-27 267944]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-12-27 61960]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\nitro pdf\professional\NitroPDFDriverService.exe [2010-10-20 196928]
R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2010-10-20 67904]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-8-26 133104]
S3 FTLUND;Lundinova Filter Driver;c:\windows\system32\drivers\ftlund.sys [2008-1-28 6828]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2009-8-3 17408]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2002-8-29 14336]
=============== Created Last 30 ================
2010-12-27 15:45:21 -------- d-----w- c:\docume~1\william\applic~1\Avira
2010-12-27 15:39:12 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-27 15:39:11 -------- d-----w- c:\program files\Avira
2010-12-27 15:39:11 -------- d-----w- c:\docume~1\alluse~1\applic~1\Avira
2010-12-27 14:28:43 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-27 12:51:52 11264 ----a-r- c:\docume~1\william\applic~1\microsoft\installer\{98613c99-1399-416c-a07c-1ee1c585d872}\Icon98613C992.exe
2010-12-27 12:51:46 -------- d-----w- c:\program files\Seagate
2010-12-27 12:49:01 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2010-12-26 14:56:21 0 ----a-w- c:\windows\Tsehahedil.bin
2010-12-26 14:56:16 -------- d-----w- c:\docume~1\william\locals~1\applic~1\{4F5CD3E9-C7BC-428B-AA17-6895598319D8}
2010-12-26 14:53:59 -------- d-----w- c:\docume~1\alluse~1\applic~1\mIcLl06511
2010-12-09 11:40:19 -------- d-----w- c:\docume~1\alluse~1\applic~1\Sibelius Software
2010-12-09 11:27:16 17464 ----a-w- c:\windows\gboxdrum.dat
2010-12-09 11:27:15 92728 ----a-w- c:\windows\gbox.dat
2010-12-09 11:27:02 -------- d-----w- c:\program files\GrooveBox
2010-12-09 11:23:35 -------- d-----w- c:\program files\Chords & Scales
2010-12-09 11:18:54 -------- d-----w- c:\program files\PhraseTrainer
2010-12-09 11:16:13 -------- d-----w- c:\program files\Desktop Metronome
==================== Find3M ====================
2010-11-12 16:34:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-10-20 17:41:22 67904 ----a-w- c:\windows\system32\NLSSRV32.EXE
2010-10-20 17:38:58 17728 ----a-w- c:\windows\system32\nitrolocalui.dll
2010-10-20 17:38:56 26432 ----a-w- c:\windows\system32\nitrolocalmon.dll
============= FINISH: 22:17:59.76 ===============
These look like long files - hope it is OK to paste them in as requested.
Thanks
William.