dds.log and attach.log
.
DDS (Ver_2011-06-03.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23
Run by owner at 11:52:51 on 2011-06-06
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3317.2656 [GMT -4:00]
.
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\connect.exe
C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe
C:\Program Files\Belkin\Router Setup and Monitor\dlnaPlugin.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Vid HD\Vid.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Encore\Common\RaUI.exe
C:\Program Files\Encore\Common\RegistryWriter.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
mDefault_Page_URL = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messen~1\YahooMessenger.exe" -quiet
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Logitech Vid] "c:\program files\logitech\vid hd\Vid.exe" -bootmode
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [InstaLAN] "c:\program files\belkin\router setup and monitor\BelkinRouterMonitor.exe" startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\encore~1.lnk - c:\program files\encore\common\RaUI.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
IE: Free YouTube Download - c:\documents and settings\owner\application data\dvdvideosoftiehelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\documents and settings\owner\application data\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
TCP: Interfaces\{0D9932C2-E208-431B-A4D8-83AC2A2D47CC} : DhcpNameServer = 192.168.2.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Notify: igfxcui - igfxdev.dll
Notify: itlntfy - itlnfw32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 64.34.212.90
www.google.com
Hosts: 64.34.212.90
www.google.com.au
Hosts: 64.34.212.90
www.google.be
Hosts: 64.34.212.90
www.google.com.br
Hosts: 64.34.212.90
www.google.ca
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\hm48fgqk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 60283
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\hm48fgqk.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: DVDVideoSoftTB Community Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Ext: Java Quick Starter:
[email protected] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: avast! WebRep:
[email protected] - c:\program files\avast software\avast\webrep\FF
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-5 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-4-5 307928]
R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2011-2-19 1872320]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-4-5 19544]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-4-5 42184]
R2 Belkin Local Backup Service;Belkin Local Backup Service;c:\program files\belkin\belkin usb print and storage center\BkBackupScheduler.exe [2010-5-16 152064]
R2 Belkin Network USB Helper;Belkin Network USB Helper;c:\program files\belkin\belkin usb print and storage center\Bkapcs.exe [2010-5-16 49152]
R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\encore\common\RegistryWriter.exe [2010-5-13 75040]
R3 sxuptp;SXUPTP Driver;c:\windows\system32\drivers\sxuptp.sys [2010-5-16 246936]
S0 cerc6;cerc6; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-9 136176]
S2 itlperf;Intel CPU;c:\windows\system32\svchost.exe -k itlsvc [2008-4-13 14336]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-5-13 1684736]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-1-9 136176]
S3 RAPIProtocol;Ralink RAPI Protocol Driver;c:\windows\system32\drivers\RAPIProtocol.sys [2010-5-13 16512]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2010-5-13 719616]
.
=============== Created Last 30 ================
.
2011-05-18 11:18:17 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-15 01:07:27 5632 ----a-w- c:\windows\system32\ptpusb.dll
2011-05-15 01:07:26 159232 ----a-w- c:\windows\system32\ptpusd.dll
2011-05-15 01:07:26 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2011-05-15 01:07:26 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
.
==================== Find3M ====================
.
2011-05-10 12:10:59 40112 ----a-w- c:\windows\avastSS.scr
2011-05-10 12:03:54 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: Hitachi_HDS721075KLA330 rev.GK8OA97A -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A5FF6F0]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a605a10]; MOV EAX, [0x8a605a8c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8A680AB8]
3 CLASSPNP[0xBA0E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000068[0x8A6E7508]
5 ACPI[0xB9F7F620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x8A63E940]
\Driver\atapi[0x8A6A8A08] -> IRP_MJ_CREATE -> 0x8A5FF6F0
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A5FF53B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 11:54:33.95 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-03.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 5/13/2010 12:55:18 PM
System Uptime: 6/6/2011 9:35:50 AM (2 hours ago)
.
Motherboard: Dell Inc. | | 0G679R
Processor: Intel Pentium III Xeon processor | Socket 775 | 2792/266mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 699 GiB total, 682.545 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP151: 3/8/2011 5:27:47 PM - Installed Windows KB954550-v5.
RP152: 3/8/2011 5:27:52 PM - Printer Driver Microsoft XPS Document Writer Installed
RP153: 3/8/2011 5:27:59 PM - Printer Driver Microsoft XPS Document Writer Installed
RP154: 3/9/2011 3:00:12 AM - Software Distribution Service 3.0
RP155: 3/10/2011 3:00:12 AM - Software Distribution Service 3.0
RP156: 3/11/2011 3:00:16 AM - Software Distribution Service 3.0
RP157: 3/12/2011 3:29:02 AM - System Checkpoint
RP158: 3/13/2011 4:29:16 AM - System Checkpoint
RP159: 3/14/2011 5:29:16 AM - System Checkpoint
RP160: 3/15/2011 8:40:14 AM - System Checkpoint
RP161: 3/16/2011 3:00:12 AM - Software Distribution Service 3.0
RP162: 3/17/2011 3:01:12 AM - System Checkpoint
RP163: 3/18/2011 3:58:51 AM - System Checkpoint
RP164: 3/19/2011 4:58:55 AM - System Checkpoint
RP165: 3/20/2011 4:59:03 AM - System Checkpoint
RP166: 3/21/2011 5:59:03 AM - System Checkpoint
RP167: 3/22/2011 6:47:03 AM - System Checkpoint
RP168: 3/23/2011 8:18:25 AM - System Checkpoint
RP169: 3/23/2011 2:11:00 PM - Installed Windows Media Player 11
RP170: 3/23/2011 2:11:28 PM - Software Distribution Service 3.0
RP171: 3/24/2011 3:00:12 AM - Software Distribution Service 3.0
RP172: 3/25/2011 3:18:31 AM - System Checkpoint
RP173: 3/26/2011 4:18:31 AM - System Checkpoint
RP174: 3/27/2011 4:35:14 AM - System Checkpoint
RP175: 3/28/2011 5:35:14 AM - System Checkpoint
RP176: 3/29/2011 6:35:14 AM - System Checkpoint
RP177: 3/30/2011 7:33:56 AM - System Checkpoint
RP178: 3/31/2011 9:55:48 AM - System Checkpoint
RP179: 4/1/2011 10:33:56 AM - System Checkpoint
RP180: 4/3/2011 11:04:16 PM - System Checkpoint
RP181: 4/4/2011 11:15:49 PM - System Checkpoint
RP182: 4/5/2011 3:12:54 PM - Installed AVG 2011
RP183: 4/5/2011 3:16:04 PM - Installed AVG 2011
RP184: 4/5/2011 3:16:16 PM - Removed AVG 2011
RP185: 4/5/2011 3:26:52 PM - Installed AVG 2011
RP186: 4/5/2011 3:34:19 PM - Installed AVG 2011
RP187: 4/5/2011 3:34:31 PM - Removed AVG 2011
RP188: 4/5/2011 3:48:06 PM - Removed Symantec AntiVirus
RP189: 4/5/2011 4:24:39 PM - avast! Free Antivirus Setup
RP190: 4/5/2011 5:32:23 PM - Restore Operation
RP191: 4/5/2011 6:55:12 PM - Removed Ask Toolbar.
RP192: 4/5/2011 6:57:58 PM - Removed Skype Toolbars
RP193: 4/5/2011 6:58:23 PM - Removed Symantec AntiVirus
RP194: 4/5/2011 7:13:38 PM - avast! Free Antivirus Setup
RP195: 4/6/2011 7:38:06 PM - System Checkpoint
RP196: 4/7/2011 8:38:03 PM - System Checkpoint
RP197: 4/8/2011 10:56:03 PM - System Checkpoint
RP198: 4/9/2011 11:38:02 PM - System Checkpoint
RP199: 4/11/2011 1:51:03 AM - System Checkpoint
RP200: 4/12/2011 1:56:48 AM - System Checkpoint
RP201: 4/13/2011 1:57:04 AM - System Checkpoint
RP202: 4/14/2011 3:00:13 AM - Software Distribution Service 3.0
RP203: 4/15/2011 3:00:16 AM - Software Distribution Service 3.0
RP204: 4/16/2011 3:23:59 AM - System Checkpoint
RP205: 4/17/2011 4:23:59 AM - System Checkpoint
RP206: 4/18/2011 5:23:59 AM - System Checkpoint
RP207: 4/19/2011 6:38:29 AM - System Checkpoint
RP208: 4/20/2011 6:57:43 AM - System Checkpoint
RP209: 4/21/2011 7:49:18 AM - System Checkpoint
RP210: 4/22/2011 10:02:19 AM - System Checkpoint
RP211: 4/25/2011 9:10:39 AM - System Checkpoint
RP212: 4/26/2011 9:59:17 AM - System Checkpoint
RP213: 4/27/2011 11:02:36 AM - System Checkpoint
RP214: 4/28/2011 3:00:12 AM - Software Distribution Service 3.0
RP215: 4/29/2011 3:58:24 AM - System Checkpoint
RP216: 4/30/2011 4:58:24 AM - System Checkpoint
RP217: 5/1/2011 5:02:15 AM - System Checkpoint
RP218: 5/2/2011 6:02:15 AM - System Checkpoint
RP219: 5/3/2011 7:02:15 AM - System Checkpoint
RP220: 5/3/2011 9:31:29 PM - Removed Skype™ 5.1
RP221: 5/4/2011 9:47:27 PM - System Checkpoint
RP222: 5/5/2011 9:50:42 PM - System Checkpoint
RP223: 5/7/2011 8:47:23 AM - Restore Operation
RP224: 5/8/2011 9:04:30 AM - System Checkpoint
RP225: 5/9/2011 9:13:36 AM - System Checkpoint
RP226: 5/10/2011 9:20:15 AM - System Checkpoint
RP227: 5/11/2011 9:22:59 AM - System Checkpoint
RP228: 5/12/2011 12:57:25 PM - System Checkpoint
RP229: 5/13/2011 1:25:31 PM - System Checkpoint
RP230: 5/14/2011 2:00:49 PM - System Checkpoint
RP231: 5/15/2011 3:00:49 PM - System Checkpoint
RP232: 5/16/2011 4:06:49 PM - System Checkpoint
RP233: 5/17/2011 5:44:15 PM - System Checkpoint
RP234: 5/18/2011 5:46:08 PM - System Checkpoint
RP235: 5/20/2011 9:10:29 AM - System Checkpoint
RP236: 5/21/2011 10:51:01 AM - System Checkpoint
RP237: 5/22/2011 11:43:40 AM - System Checkpoint
RP238: 5/23/2011 12:43:40 PM - System Checkpoint
RP239: 5/24/2011 1:43:40 PM - System Checkpoint
RP240: 5/25/2011 1:43:52 PM - System Checkpoint
RP241: 5/26/2011 2:43:52 PM - System Checkpoint
RP242: 5/27/2011 9:15:07 PM - System Checkpoint
RP243: 5/30/2011 12:05:28 PM - System Checkpoint
RP244: 5/31/2011 1:03:22 PM - System Checkpoint
RP245: 6/1/2011 2:37:24 PM - System Checkpoint
RP246: 6/2/2011 4:48:56 PM - System Checkpoint
RP247: 6/3/2011 5:24:56 PM - System Checkpoint
RP248: 6/4/2011 7:48:56 PM - System Checkpoint
RP249: 6/5/2011 8:24:56 PM - System Checkpoint
.
==== Hosts File Hijack ======================
.
Hosts: 64.34.212.90
www.google.com
Hosts: 64.34.212.90
www.google.com.au
Hosts: 64.34.212.90
www.google.be
Hosts: 64.34.212.90
www.google.com.br
Hosts: 64.34.212.90
www.google.ca
Hosts: 64.34.212.90
www.google.ch
Hosts: 64.34.212.90
www.google.de
Hosts: 64.34.212.90
www.google.dk
Hosts: 64.34.212.90
www.google.fr
Hosts: 64.34.212.90
www.google.ie
Hosts: 64.34.212.90
www.google.it
Hosts: 64.34.212.90
www.google.co.jp
Hosts: 64.34.212.90
www.google.nl
Hosts: 64.34.212.90
www.google.no
Hosts: 64.34.212.90
www.google.co.nz
Hosts: 64.34.212.90
www.google.pl
Hosts: 64.34.212.90
www.google.se
Hosts: 64.34.212.90
www.google.co.uk
Hosts: 64.34.212.90
www.google.co.za
Hosts: 64.34.212.90
www.bing.com
Hosts: 64.34.212.90 search.yahoo.com
Hosts: 64.34.212.90 uk.search.yahoo.com
Hosts: 64.34.212.90 ca.search.yahoo.com
Hosts: 64.34.212.90 de.search.yahoo.com
Hosts: 64.34.212.90 fr.search.yahoo.com
Hosts: 64.34.212.90 au.search.yahoo.com
Hosts: 64.34.212.90
www.google-analytics.com
.
==== Installed Programs ======================
.
a-squared Free 4.5
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.4
avast! Free Antivirus
Belkin Daily DJ
Belkin Music Labeler
Belkin Setup and Router Monitor
Belkin USB Print and Storage Center
CCleaner
CDDRV_Installer
CleanUp!
Conexant D850 56K V.9x DFVc Modem
Encore 802.11n Wireless Adapter ENUWI-N3
Fotosizer 1.31
Free Studio version 5.0.6
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Intel(R) Graphics Media Accelerator Driver
Java Auto Updater
Java(TM) 6 Update 23
KhalSetup
KONICA MINOLTA magicolor 2430DL
LiveUpdate 3.1 (Symantec Corporation)
Logitech Desktop Messenger
Logitech SetPoint
Logitech Vid HD
Logitech Webcam Software
Logitech Webcam Software Driver Package
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office 2000 SR-1 Premium
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox (3.6.17)
Music Mover
Nero OEM
PowerDVD
QuickBooks Pro Edition 2004
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2183461)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360131)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982381)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Uninstall 1.0.0.1
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB980182)
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Yahoo! BrowserPlus 2.9.8
Yahoo! Messenger
Yahoo! Software Update
.
==== Event Viewer Messages From Past Week ========
.
6/6/2011 7:29:52 AM, error: Dhcp [1008] - Your computer was unable to initialize a Network Interface attached to the system. The error code is: Insufficient system resources exist to complete the requested service. .
6/1/2011 6:52:26 AM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0024E8128A7D. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
6/1/2011 6:52:24 AM, error: Dhcp [1002] - The IP address lease 192.168.2.2 for the Network Card with network address 0024E8128A7D has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
6/1/2011 6:28:12 AM, error: Dhcp [1002] - The IP address lease 192.168.2.3 for the Network Card with network address 0024E8128A7D has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
5/30/2011 7:29:04 PM, error: Service Control Manager [7023] - The Intel CPU service terminated with the following error: The specified module could not be found.
.
==== End Of File ===========================