Solved System check virus and lost monitor signal

What's the story about your AV program?
I can see some McAfee items, but it doesn't seem to be running.

"Startup" seems to be a part of VPN Client..

=============================================================

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    DRV - [2007/11/14 16:05:16 | 000,394,952 | -H-- | M] (Zone Labs, LLC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
    [2011/12/30 17:36:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\IP0XC3\Start Menu\Programs\System Check
    [2011/12/30 18:15:44 | 000,000,839 | ---- | M] () -- C:\Documents and Settings\IP0XC3\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
    @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\All Users\Desktop\putty.exe:SummaryInformation
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.

============================================================

Last scans....

1. Download Security Check from HERE, and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

2. Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


3. Download Temp File Cleaner (TFC)
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


4. Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • NOTE. If Eset won't find any threats, it won't produce any log.
 
It is possible they never set McAfee to run.

I start to run OTL as instucted, at the bottom of OTL screen, it displayed "Killing process, do not interrupt". then my pc hangs. Task Manager would not work after a few minutes.

there is a small message box pop up behand of OTL window, displayed "MBAM Service termanated unexpectedly. See Eventlog for details"

I cannot shut down pc, I have to push the power button.
 
log file of running OTL:

All processes killed
========== OTL ==========
Service vsdatant stopped successfully!
Service vsdatant deleted successfully!
C:\WINDOWS\system32\vsdatant.sys moved successfully.
C:\Documents and Settings\IP0XC3\Start Menu\Programs\System Check folder moved successfully.
C:\Documents and Settings\IP0XC3\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk moved successfully.
ADS C:\Documents and Settings\All Users\Desktop\putty.exe:SummaryInformation deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Administrator.SHERRYG12PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78991 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 681 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56468 bytes

User: IP0XC3
->Temp folder emptied: 21378 bytes
->Temporary Internet Files folder emptied: 23389000 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 66912 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 33251 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 23.00 mb


[EMPTYFLASH]

User: Administrator

User: Administrator.SHERRYG12PC
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: IP0XC3
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 01102012_140556

Files\Folders moved on Reboot...
C:\Documents and Settings\IP0XC3\Local Settings\Temporary Internet Files\Content.IE5\60AG2M7A\topic175668-2[1].htm moved successfully.
C:\Documents and Settings\IP0XC3\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully.

Registry entries deleted on Reboot..

-------------------------

while trying to remove McAfee agaent, get error: "McAfee agent cannot be removed while it is in managed mode". It seems I have to remove it before I can run MCPR.exe.
 
I have administrator right on my computer, is that count?

Can I run the last scans from your post #26 now?
 
Well, we need to do something about McAfee.
See if McAfee is listed in Add\Remove.
 
OTL log:

OTL logfile created on: 1/11/2012 9:22:00 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\IP0XC3\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.97 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 74.98% Memory free
3.81 Gb Paging File | 3.43 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.00 Gb Total Space | 134.72 Gb Free Space | 90.41% Space Free | Partition Type: NTFS

Computer Name: SHERRYG12PC | User Name: ip0xc3 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/09 15:29:35 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\IP0XC3\Desktop\OTL.exe
PRC - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/12/24 17:50:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/06/08 03:06:00 | 000,345,408 | -H-- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2011/06/08 03:06:00 | 000,333,120 | -H-- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2011/06/08 03:06:00 | 000,132,416 | -H-- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2011/06/08 03:06:00 | 000,075,072 | -H-- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\McTray.exe
PRC - [2011/04/08 11:59:52 | 000,507,624 | -H-- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2011/03/03 10:57:54 | 000,032,768 | -H-- | M] (IBM Corporation) -- C:\WINDOWS\system32\drivers\trcboot.exe
PRC - [2011/03/03 10:57:53 | 000,040,960 | -H-- | M] (IBM Corporation) -- C:\WINDOWS\system32\drivers\ldlcserv6.exe
PRC - [2011/03/03 10:57:53 | 000,028,672 | -H-- | M] (IBM Corporation) -- C:\WINDOWS\system32\drivers\ldlcserv.exe
PRC - [2011/03/03 10:57:08 | 000,028,672 | -H-- | M] () -- C:\Program Files\IBM\Personal Communications\tpam.exe
PRC - [2011/03/03 10:55:05 | 000,036,864 | -H-- | M] (IBM Corporation) -- C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE
PRC - [2010/03/04 21:38:00 | 000,071,096 | -H-- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2009/11/12 20:59:02 | 000,132,392 | -H-- | M] (Juniper Networks) -- C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe
PRC - [2009/09/18 03:00:00 | 000,764,768 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\CCM\CcmExec.exe
PRC - [2008/08/29 12:58:16 | 001,528,608 | -H-- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2008/08/11 13:16:40 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002/01/11 14:35:13 | 000,454,928 | -H-- | M] (Peregrine Systems, Inc.) -- C:\Program Files\Peregrine\InfraTools Remote Control\bin\iftlsnr.exe


========== Modules (No Company Name) ==========

MOD - [2011/03/03 10:57:08 | 000,028,672 | -H-- | M] () -- C:\Program Files\IBM\Personal Communications\tpam.exe
MOD - [2011/03/03 10:54:50 | 000,485,376 | -H-- | M] () -- C:\Program Files\IBM\Personal Communications\OOCSVCS2.DLL
MOD - [2010/03/04 21:38:00 | 000,071,096 | -H-- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
MOD - [2009/11/05 07:39:40 | 000,087,552 | -H-- | M] () -- C:\WINDOWS\system32\cpwmon2k.dll
MOD - [2008/08/29 12:58:26 | 000,197,408 | -H-- | M] () -- C:\WINDOWS\system32\vpnapi.dll
MOD - [2007/04/18 19:30:46 | 000,471,040 | -H-- | M] () -- C:\Program Files\McAfee\Common Framework\ccme_base.dll
MOD - [2007/04/18 19:30:46 | 000,393,216 | -H-- | M] () -- C:\Program Files\McAfee\Common Framework\cryptocme2.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/06/08 03:06:00 | 000,132,416 | -H-- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2011/03/03 10:57:55 | 000,032,768 | -H-- | M] (IBM Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\appnnode.exe -- (AppnNode)
SRV - [2011/03/03 10:57:54 | 000,032,768 | -H-- | M] (IBM Corporation) [Auto | Running] -- C:\WINDOWS\system32\drivers\trcboot.exe -- (TrcBoot)
SRV - [2011/03/03 10:57:53 | 000,040,960 | -H-- | M] (IBM Corporation) [Auto | Running] -- C:\WINDOWS\system32\drivers\ldlcserv6.exe -- (ldlcserv6) IBM Enterprise Extender (IPv6)
SRV - [2011/03/03 10:57:53 | 000,036,864 | -H-- | M] (IBM Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cstrcser.exe -- (cstrcser)
SRV - [2011/03/03 10:57:53 | 000,028,672 | -H-- | M] (IBM Corporation) [Auto | Running] -- C:\WINDOWS\system32\drivers\ldlcserv.exe -- (ldlcserv) IBM Enterprise Extender (IPv4)
SRV - [2011/03/03 10:54:46 | 000,049,152 | -H-- | M] (IBM Corporation) [On_Demand | Stopped] -- C:\Program Files\IBM\Personal Communications\csrcmds.exe -- (csrcmds)
SRV - [2010/03/04 21:38:00 | 000,071,096 | -H-- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
SRV - [2009/11/12 20:59:02 | 000,132,392 | -H-- | M] (Juniper Networks) [Auto | Running] -- C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe -- (JuniperAccessService)
SRV - [2009/09/18 03:00:00 | 000,764,768 | -H-- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\CCM\CcmExec.exe -- (CcmExec)
SRV - [2009/09/18 03:00:00 | 000,246,624 | -H-- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\System32\CCM\TSManager.exe -- (smstsmgr)
SRV - [2008/08/29 12:58:16 | 001,528,608 | -H-- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2002/01/11 14:35:13 | 000,454,928 | -H-- | M] (Peregrine Systems, Inc.) [Auto | Running] -- C:\Program Files\Peregrine\InfraTools Remote Control\bin\iftlsnr.exe -- (iftlsnr)


========== Driver Services (SafeList) ==========

DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/07/08 03:12:48 | 007,023,104 | -H-- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2011/03/03 10:57:57 | 000,208,928 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\AppnBase.sys -- (AppnBase)
DRV - [2011/03/03 10:57:57 | 000,058,432 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnsx25.sys -- (pdlnsx25)
DRV - [2011/03/03 10:57:57 | 000,054,416 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnsv25.sys -- (pdlnsv25)
DRV - [2011/03/03 10:57:57 | 000,022,384 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnslea.sys -- (pdlnslea)
DRV - [2011/03/03 10:57:56 | 000,067,184 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnemap.sys -- (pdlnemap)
DRV - [2011/03/03 10:57:56 | 000,067,072 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndsdl.sys -- (pdlndsdl)
DRV - [2011/03/03 10:57:56 | 000,059,504 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnshay.sys -- (pdlnshay)
DRV - [2011/03/03 10:57:56 | 000,053,248 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndqll.sys -- (pdlndqll)
DRV - [2011/03/03 10:57:56 | 000,050,336 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnecfg.sys -- (pdlnecfg)
DRV - [2011/03/03 10:57:56 | 000,019,984 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnepkt.sys -- (pdlnepkt)
DRV - [2011/03/03 10:57:56 | 000,018,944 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndoem.sys -- (pdlndoem)
DRV - [2011/03/03 10:57:56 | 000,012,768 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnemsg.sys -- (pdlnemsg)
DRV - [2011/03/03 10:57:56 | 000,008,608 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnebas.sys -- (pdlnebas)
DRV - [2011/03/03 10:57:55 | 000,160,288 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlncfwk.sys -- (pdlncfwk)
DRV - [2011/03/03 10:57:55 | 000,075,200 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnacom.sys -- (pdlnacom)
DRV - [2011/03/03 10:57:55 | 000,070,144 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndlpb.sys -- (pdlndlpb)
DRV - [2011/03/03 10:57:55 | 000,064,512 | -H-- | M] (IBM Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\pdlndldl.sys -- (pdlndldl) IBM Enterprise Extender (HPR/IPv4)
DRV - [2011/03/03 10:57:55 | 000,036,048 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnafac.sys -- (pdlnafac)
DRV - [2011/03/03 10:57:55 | 000,012,800 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndint.sys -- (pdlndint)
DRV - [2011/03/03 10:57:55 | 000,006,784 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlncbas.sys -- (pdlncbas)
DRV - [2011/03/03 10:57:54 | 001,322,080 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\appn.sys -- (Appn)
DRV - [2011/03/03 10:57:54 | 000,120,224 | -H-- | M] (IBM Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\appnapi.sys -- (AppnApi)
DRV - [2011/03/03 10:57:54 | 000,101,696 | -H-- | M] (IBM Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\llc2.sys -- (IBM_LLC2)
DRV - [2011/03/03 10:57:54 | 000,072,704 | -H-- | M] (IBM Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\pdlndldl6.sys -- (pdlndldl6) IBM Enterprise Extender (HPR/IPv6)
DRV - [2011/03/03 10:57:54 | 000,038,280 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\anydlc.sys -- (Anydlc)
DRV - [2011/03/03 10:57:53 | 000,024,588 | -H-- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\klognt.sys -- (KLOGNT)
DRV - [2011/03/03 10:57:53 | 000,012,028 | -H-- | M] (IBM Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\nstrcnt.sys -- (NsTrcNT)
DRV - [2010/04/05 23:35:56 | 000,168,616 | -H-- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\e1k5132.sys -- (e1kexpress) Intel(R)
DRV - [2009/11/12 12:48:56 | 000,007,168 | -H-- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009/09/18 03:00:00 | 000,020,848 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CCM\PrepDrv.sys -- (prepdrvr)
DRV - [2008/10/20 19:08:06 | 000,012,448 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smsmdm.sys -- (smsmdd)
DRV - [2008/08/29 12:57:18 | 000,306,299 | -H-- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2008/08/21 05:38:10 | 000,020,480 | RH-- | M] (Dell Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
DRV - [2008/03/29 16:36:28 | 000,125,328 | -H-- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE)
DRV - [2007/05/11 23:00:14 | 000,045,056 | -H-- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (HECI) Intel(R)
DRV - [2007/01/18 17:28:02 | 000,005,275 | -H-- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA)
DRV - [2005/11/30 21:30:14 | 000,010,880 | -H-- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\vmscsi.sys -- (vmscsi)
DRV - [2005/08/12 11:46:42 | 000,062,080 | -H-- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SI3112.sys -- (SI3112)
DRV - [2005/08/12 09:14:20 | 000,004,736 | -H-- | M] (Silicon Image, Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\SiRemFil.sys -- (SiRemFil)
DRV - [2004/11/01 11:21:32 | 000,010,368 | -H-- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys -- (SiFilter)
DRV - [2001/04/19 02:58:05 | 000,006,097 | -H-- | M] (Peregrine Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Peregrine\InfraTools Remote Control\bin\iftrcdrv.sys -- (iftrcdrv)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sdolintranet:81/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



O1 HOSTS File: ([2012/01/06 10:36:23 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [GPUpdate] C:\WINDOWS\System32\gpupdate.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PinAInfo] C:\WINDOWS\system32\ai.vbs ()
O4 - HKLM..\Run: [SetDefaultPrinter] C:\WINDOWS\system32\dp.vbs ()
O4 - HKLM..\Run: [SetGrammaticaLicense] C:\WINDOWS\system32\gl.vbs ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\WINDOWS\Installer\{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}\Icon3E5562ED7.ico ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylockeduserid = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.72.126.59 10.72.126.26
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Grid12NT.nysdol.us
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E48819ED-8852-43E7-8370-81B6FFA49C09}: DhcpNameServer = 10.72.126.59 10.72.126.26
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/08/12 17:19:37 | 000,000,000 | -H-- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/10 14:26:05 | 001,832,544 | ---- | C] (McAfee, Inc.) -- C:\Documents and Settings\IP0XC3\Desktop\MCPR.exe
[2012/01/10 14:16:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2012/01/10 14:06:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/01/10 12:24:26 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/01/09 15:29:35 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\IP0XC3\Desktop\OTL.exe
[2012/01/06 13:01:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\IP0XC3\Application Data\Malwarebytes
[2012/01/06 13:01:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/06 13:01:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/01/06 13:01:47 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/01/06 13:01:47 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/06 12:55:38 | 000,066,896 | ---- | C] (Malwarebytes Corporation) -- C:\Documents and Settings\IP0XC3\Desktop\mbam-clean.exe
[2012/01/06 12:26:44 | 004,704,768 | ---- | C] (AVAST Software) -- C:\Documents and Settings\IP0XC3\Desktop\aswMBR.exe
[2012/01/06 10:33:40 | 000,483,328 | ---- | C] (Simon Tatham) -- C:\Documents and Settings\All Users\Desktop\putty.exe
[2012/01/06 10:24:03 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/01/06 10:15:10 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/01/06 10:15:10 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/01/06 10:15:10 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/01/06 10:15:10 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/01/06 10:15:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/01/06 10:15:03 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/06 10:15:01 | 000,000,000 | R--D | C] -- C:\Documents and Settings\IP0XC3\My Documents\My Videos
[2012/01/06 10:08:58 | 004,376,389 | R--- | C] (Swearware) -- C:\Documents and Settings\IP0XC3\Desktop\ComboFix.exe
[2012/01/05 11:52:56 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\IP0XC3\Recent
[2011/12/22 16:37:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\IP0XC3\My Documents\Personal
[2011/12/22 12:06:29 | 000,000,000 | R--D | C] -- C:\Documents and Settings\IP0XC3\Start Menu\Programs\Administrative Tools

========== Files - Modified Within 30 Days ==========

[2012/01/11 09:16:16 | 000,021,660 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
[2012/01/11 09:16:12 | 000,000,630 | RHS- | M] () -- C:\Documents and Settings\IP0XC3\ntuser.pol
[2012/01/11 09:16:11 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
[2012/01/11 09:16:07 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/11 08:38:19 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/11 08:38:14 | 2111,422,464 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/10 14:26:10 | 001,832,544 | ---- | M] (McAfee, Inc.) -- C:\Documents and Settings\IP0XC3\Desktop\MCPR.exe
[2012/01/09 15:29:35 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\IP0XC3\Desktop\OTL.exe
[2012/01/09 14:35:15 | 004,376,389 | R--- | M] (Swearware) -- C:\Documents and Settings\IP0XC3\Desktop\ComboFix.exe
[2012/01/06 13:01:48 | 000,000,808 | ---- | M] () -- C:\Documents and Settings\IP0XC3\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/01/06 13:01:48 | 000,000,790 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/06 12:55:31 | 000,066,896 | ---- | M] (Malwarebytes Corporation) -- C:\Documents and Settings\IP0XC3\Desktop\mbam-clean.exe
[2012/01/06 12:32:25 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\IP0XC3\My Documents\MBR.dat
[2012/01/06 12:26:44 | 004,704,768 | ---- | M] (AVAST Software) -- C:\Documents and Settings\IP0XC3\Desktop\aswMBR.exe
[2012/01/06 10:36:23 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/01/06 10:24:06 | 000,000,311 | RHS- | M] () -- C:\boot.ini
[2011/12/30 13:27:13 | 000,000,664 | -H-- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/12/22 11:56:19 | 000,509,030 | -H-- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/12/22 11:56:19 | 000,089,494 | -H-- | M] () -- C:\WINDOWS\System32\perfc009.dat

========== Files Created - No Company Name ==========

[2012/01/10 14:46:46 | 2111,422,464 | -HS- | C] () -- C:\hiberfil.sys
[2012/01/06 13:01:48 | 000,000,808 | ---- | C] () -- C:\Documents and Settings\IP0XC3\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/01/06 13:01:48 | 000,000,790 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/06 12:32:25 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\IP0XC3\My Documents\MBR.dat
[2012/01/06 10:33:45 | 000,002,447 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
[2012/01/06 10:33:45 | 000,001,793 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2012/01/06 10:33:41 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/06 10:33:41 | 000,001,809 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Search.lnk
[2012/01/06 10:33:41 | 000,001,562 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\CDBurnerXP.lnk
[2012/01/06 10:33:41 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2012/01/06 10:33:41 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2012/01/06 10:33:40 | 000,002,329 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Office Outlook 2007.lnk
[2012/01/06 10:33:40 | 000,001,777 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VPN Client.lnk
[2012/01/06 10:33:40 | 000,000,821 | ---- | C] () -- C:\Documents and Settings\IP0XC3\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/06 10:33:40 | 000,000,750 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\UGent VPN.lnk
[2012/01/06 10:33:40 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\IP0XC3\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/01/06 10:24:06 | 000,000,195 | ---- | C] () -- C:\Boot.bak
[2012/01/06 10:24:04 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/01/06 10:15:10 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/01/06 10:15:10 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/01/06 10:15:10 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/01/06 10:15:10 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/01/06 10:15:10 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/12/15 12:50:57 | 000,000,664 | -H-- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/08/25 11:28:01 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\IP0XC3\Local Settings\Application Data\PUTTY.RND
[2011/08/12 17:38:18 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\ativpsrm.bin
[2011/08/12 17:35:18 | 000,887,724 | -H-- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2011/08/12 17:35:18 | 000,234,142 | -H-- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2011/08/12 17:35:18 | 000,000,003 | -H-- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2011/08/12 14:17:33 | 000,004,764 | -H-- | C] () -- C:\WINDOWS\System32\CcmFramework.ini
[2011/05/02 11:52:04 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2011/05/02 11:52:04 | 000,509,030 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2011/05/02 11:52:04 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2011/05/02 11:52:04 | 000,089,494 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2011/05/02 11:52:04 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2011/05/02 11:52:04 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2011/05/02 11:52:04 | 000,004,463 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2011/05/02 11:52:04 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
[2011/05/02 11:52:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2011/05/02 11:52:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2011/05/02 11:51:59 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2011/05/02 11:51:59 | 000,001,804 | -H-- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2011/05/02 10:32:02 | 000,000,393 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2011/05/02 09:46:29 | 000,316,416 | -H-- | C] () -- C:\WINDOWS\System32\ct_corct.dll
[2011/05/02 09:46:29 | 000,272,384 | -H-- | C] () -- C:\WINDOWS\System32\ct_bar.dll
[2011/05/02 09:46:29 | 000,176,640 | -H-- | C] () -- C:\WINDOWS\System32\ct_file.dll
[2011/05/02 09:46:29 | 000,025,088 | -H-- | C] () -- C:\WINDOWS\System32\ct_zset.dll
[2011/05/02 09:46:28 | 000,022,944 | -H-- | C] () -- C:\WINDOWS\System32\ci_file.dll
[2011/05/02 09:46:28 | 000,007,680 | -H-- | C] () -- C:\WINDOWS\System32\ci_corct.dll
[2011/05/02 09:46:28 | 000,005,888 | -H-- | C] () -- C:\WINDOWS\System32\ci_srv.dll
[2011/05/02 09:46:28 | 000,003,968 | -H-- | C] () -- C:\WINDOWS\System32\ci_bar.dll
[2011/05/02 09:41:41 | 000,000,261 | -H-- | C] () -- C:\WINDOWS\iftagt.ini
[2011/05/02 09:41:40 | 000,000,072 | -H-- | C] () -- C:\WINDOWS\iftlsnr.ini
[2011/05/02 09:40:46 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\pcsmig.INI
[2011/05/02 09:39:53 | 000,411,391 | -H-- | C] () -- C:\WINDOWS\System32\Info.exe
[2011/05/02 09:04:37 | 000,007,168 | -H-- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/05/02 09:03:49 | 000,000,078 | -H-- | C] () -- C:\WINDOWS\init.ini
[2011/05/02 09:03:00 | 000,028,672 | -H-- | C] () -- C:\WINDOWS\System32\ps2pdf.dll
[2011/05/02 08:54:33 | 000,087,552 | -H-- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2011/05/02 08:53:30 | 012,832,768 | -H-- | C] () -- C:\WINDOWS\System32\gsdll32.dll
[2011/05/02 08:01:27 | 000,000,051 | -H-- | C] () -- C:\WINDOWS\smsts.ini
[2011/05/02 08:00:24 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/05/02 07:57:59 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/05/02 07:57:47 | 000,001,793 | -H-- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2011/05/02 03:56:23 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/05/02 03:55:55 | 000,267,800 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/03 10:57:53 | 000,000,251 | -H-- | C] () -- C:\WINDOWS\System32\drivers\hlldrvr.com
[2010/09/20 09:09:50 | 000,495,616 | -H-- | C] () -- C:\WINDOWS\System32\softcoin.dll
[2010/09/20 09:09:50 | 000,356,352 | -H-- | C] () -- C:\WINDOWS\System32\gencoin.dll
[2008/08/29 12:58:26 | 000,197,408 | -H-- | C] () -- C:\WINDOWS\System32\vpnapi.dll
[2008/08/29 12:58:16 | 000,193,312 | -H-- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2008/05/26 20:59:42 | 000,018,904 | -H-- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | -H-- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2007/09/27 09:51:02 | 000,020,698 | -H-- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | -H-- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | -H-- | C] () -- C:\WINDOWS\System32\gthrctr.ini

========== LOP Check ==========

[2011/08/12 13:55:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\GroupPolicy
[2011/05/02 09:10:34 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\IBM
[2011/05/02 09:04:27 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2011/08/25 08:29:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\IP0XC3\Application Data\Windows Desktop Search

========== Purity Check ==========



< End of report >
 
Run the fix listed below from safe mode....

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    PRC - [2011/06/08 03:06:00 | 000,345,408 | -H-- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
    PRC - [2011/06/08 03:06:00 | 000,333,120 | -H-- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
    PRC - [2011/06/08 03:06:00 | 000,132,416 | -H-- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    PRC - [2011/06/08 03:06:00 | 000,075,072 | -H-- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\McTray.exe
    MOD - [2007/04/18 19:30:46 | 000,471,040 | -H-- | M] () -- C:\Program Files\McAfee\Common Framework\ccme_base.dll
    MOD - [2007/04/18 19:30:46 | 000,393,216 | -H-- | M] () -- C:\Program Files\McAfee\Common Framework\cryptocme2.dll
    SRV - [2011/06/08 03:06:00 | 000,132,416 | -H-- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
    O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
    [2012/01/10 14:26:05 | 001,832,544 | ---- | C] (McAfee, Inc.) -- C:\Documents and Settings\IP0XC3\Desktop\MCPR.exe
    
    :Files
    C:\Program Files\McAfee
    
    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.
 
OTL log:

All processes killed
========== OTL ==========
No active process named naPrdMgr.exe was found!
No active process named UdaterUI.exe was found!
No active process named FrameworkService.exe was found!
No active process named McTray.exe was found!
Service McAfeeFramework stopped successfully!
Service McAfeeFramework deleted successfully!
C:\Program Files\McAfee\Common Framework\FrameworkService.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\McAfeeUpdaterUI deleted successfully.
C:\Program Files\McAfee\Common Framework\UdaterUI.exe moved successfully.
C:\Documents and Settings\IP0XC3\Desktop\MCPR.exe moved successfully.
========== FILES ==========
C:\Program Files\McAfee\Common Framework\Microsoft.VC80.CRT folder moved successfully.
C:\Program Files\McAfee\Common Framework\McTray\Images\McAfee folder moved successfully.
C:\Program Files\McAfee\Common Framework\McTray\Images folder moved successfully.
C:\Program Files\McAfee\Common Framework\McTray folder moved successfully.
C:\Program Files\McAfee\Common Framework\LpcRT_424IRZZT\Microsoft.VC80.CRT folder moved successfully.
C:\Program Files\McAfee\Common Framework\LpcRT_424IRZZT folder moved successfully.
C:\Program Files\McAfee\Common Framework\0804 folder moved successfully.
C:\Program Files\McAfee\Common Framework\041D folder moved successfully.
C:\Program Files\McAfee\Common Framework\0419 folder moved successfully.
C:\Program Files\McAfee\Common Framework\0416 folder moved successfully.
C:\Program Files\McAfee\Common Framework\0415 folder moved successfully.
C:\Program Files\McAfee\Common Framework\0413 folder moved successfully.
C:\Program Files\McAfee\Common Framework\0412 folder moved successfully.
C:\Program Files\McAfee\Common Framework\0411 folder moved successfully.
C:\Program Files\McAfee\Common Framework\0410 folder moved successfully.
C:\Program Files\McAfee\Common Framework\040C folder moved successfully.
C:\Program Files\McAfee\Common Framework\040A folder moved successfully.
C:\Program Files\McAfee\Common Framework\0409 folder moved successfully.
C:\Program Files\McAfee\Common Framework\0407 folder moved successfully.
C:\Program Files\McAfee\Common Framework\0404 folder moved successfully.
C:\Program Files\McAfee\Common Framework folder moved successfully.
C:\Program Files\McAfee folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Administrator.SHERRYG12PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: IP0XC3
->Temp folder emptied: 5670908 bytes
->Temporary Internet Files folder emptied: 11000097 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 776 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 66019 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 16.00 mb


[EMPTYJAVA]

User: Administrator

User: Administrator.SHERRYG12PC
->Java cache emptied: 0 bytes

User: All Users

User: Default User

User: IP0XC3
->Java cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Java Files Cleaned = 0.00 mb


[EMPTYFLASH]

User: Administrator

User: Administrator.SHERRYG12PC
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: IP0XC3
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 01112012_120358

Files\Folders moved on Reboot...
C:\Documents and Settings\IP0XC3\Local Settings\Temporary Internet Files\Content.IE5\SH8SOZTI\partner[2].htm moved successfully.
C:\Documents and Settings\IP0XC3\Local Settings\Temporary Internet Files\Content.IE5\Q5KXLRIN\918[1].htm moved successfully.
C:\Documents and Settings\IP0XC3\Local Settings\Temporary Internet Files\Content.IE5\9JJ2LNYT\partner[2].htm moved successfully.
C:\Documents and Settings\IP0XC3\Local Settings\Temporary Internet Files\Content.IE5\65GXF1YE\partner[2].htm moved successfully.
C:\Documents and Settings\IP0XC3\Local Settings\Temporary Internet Files\Content.IE5\65GXF1YE\topic175668-2[1].htm moved successfully.
C:\Documents and Settings\IP0XC3\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully.

Registry entries deleted on Reboot...

--------------------
I still have "McAfee agent" listed in add/remove and I cannot remove it.
 
Good.

Now install one of AV programs I recommended and continue with other steps from my reply #26.
 
1. Installed Microsoft Security Essentials and ran a full scan, no threats were detected.

2. Security Check log:
Results of screen317's Security Check version 0.99.24
Windows XP Service Pack 3 x86
Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
McAfee Agent
Microsoft Security Essentials
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

Java(TM) 6 Update 26
Out of date Java installed!
Adobe Reader X (10.1.0) Adobe Reader Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Malwarebytes' Anti-Malware mbamservice.exe
Malwarebytes' Anti-Malware mbamgui.exe
Microsoft Security Essentials msseces.exe
Microsoft Security Client Antimalware MsMpEng.exe
``````````End of Log````````````

will continue other scans and report back.
 
FSS log:

Farbar Service Scanner
Ran by ip0xc3 (administrator) on 11-01-2012 at 14:40:19
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is OK.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.
Checking LEGACY_wscsvc: Attention! Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist.


Windows Update:
===========

File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
DNE(10) Gpc(6) IPSec(4) NetBT(5) PSched(8) Tcpip(3)
0x0A0000000400000001000000020000000300000007000000050000000600000008000000090000000A000000
IpSec Tag value is correct.

**** End of log ****
 
while trying to run TFC.exe, it made the computer hang. I have to push the power button to shut it down.
 
finished TFC.exe in safe mode. It rebooted. I am not sure where is the log file?
run online ESET scanner. No threat found. infetced files:0; cleaned files:0.
 
Update Internet Explorer to version 8.

Update Adobe Reader

You can download it from https://www.techspot.com/downloads/2083-adobe-reader-dc.html
After installing the latest Adobe Reader, uninstall all previous versions (if present).
Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
It's a much smaller file to download and uses a lot less resources than Adobe Reader.
Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage.

1. Update your Java version here: http://www.java.com/en/download/installed.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

2. Now, we need to remove old Java version and its remnants...

Download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Do NOT post JavaRa log.

=============================================================

Security Center is not running because of missing registry key.

Following steps involve registry editing. Please create new restore point before proceeding!!!
How to:
XP - http://support.microsoft.com/kb/948247
Vista and Seven - http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/



Please go to Start=>Run (alternatively use Windows key+R), type regedit and click OK.
Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root
Right-Click Root and select Permissions...
Under Security type while Everyone is selected put a check mark in the box under Allow next to Full Control.
Click Apply and OK.
Download XP.zip file from here: http://www.smartestcomputing.us.com/files/download/9-registry-network-keys/
Unzip downloaded file.
You'll find several files inside.
Double-click legacy_wscsvc.reg and confirm the prompt.
Please go back to the the Root key again while Everyone is selected remove check mark in the box under Allow next to Full Control and close the registry.
Restart computer.

See if you can access Security Center.
Post new FSS log.
 
the link "Download XP.zip file from here: http://www.smartestcomputing.us.com/...-network-keys/"

leads to an empty screen. If click "downloads", display "error on page" on message bar.
 
FSS log:

Farbar Service Scanner
Ran by ip0xc3 (administrator) on 12-01-2012 at 15:20:59
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.


Windows Firewall:
=============
sharedaccess Service is not running. Checking service configuration:
The start type of sharedaccess service is set to Disabled. The default start type is Auto.
The ImagePath of sharedaccess service is OK.
The ServiceDll of sharedaccess service is OK.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is OK.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.


Windows Update:
===========
BITS Service is not running. Checking service configuration:
The start type of BITS service is set to Demand. The default start type is Auto.
The ImagePath of BITS service is OK.
The ServiceDll of BITS service is OK.


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
DNE(10) Gpc(6) IPSec(4) NetBT(5) PSched(8) Tcpip(3)
0x0A0000000400000001000000020000000300000007000000050000000600000008000000090000000A000000
IpSec Tag value is correct.

**** End of log ****

I am not sure what to expect: when I click start->control panel->security center
a window opened, titled as Windows Security Center, there are 3 parts on the window, on the left is resource, on the top of right is Security Essentials, on the buttom right is "Manage Security Setting for:internet options, window firewall and automatic updates"

on the right side of teskbar, I have a window Security Essential icon, when I move mouse over, it show Computer status-proctected.
 
That's fine. I just wanted to make sure you can access Security Center.

Now we have one Windows updates service disabled.

Go Start>Run, type in:
services.msc.
Click OK.

Services window will open.
Find Background Intelligent Transfer Service, right click on it, click "Properties" and under "Startup type" select "Automatic" from drop-down menu.
Restart computer.

Post new FSS log.
 
FSS log:

Farbar Service Scanner
Ran by ip0xc3 (administrator) on 12-01-2012 at 16:27:31
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.


Windows Firewall:
=============
sharedaccess Service is not running. Checking service configuration:
The start type of sharedaccess service is set to Disabled. The default start type is Auto.
The ImagePath of sharedaccess service is OK.
The ServiceDll of sharedaccess service is OK.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is OK.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.


Windows Update:
===========

File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
DNE(10) Gpc(6) IPSec(4) NetBT(5) PSched(8) Tcpip(3)
0x0A0000000400000001000000020000000300000007000000050000000600000008000000090000000A000000
IpSec Tag value is correct.

**** End of log ****
 
I got twice "jusched.exe has encountered a proble and needs to close. we are sorry...", not sure if this is something relevent.
 
Back