User's pc has been performing this google redirect for more than six months now, through multiple "fixes" with support technicians, but apparently the fixes aren't taking.
Please note, I do not have the machine in my possession but am helping a friend, so response time may be poor. I will respond, but cannot necessarily immediately implement advice.
At any rate, here are our logs:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6199
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
3/28/2011 8:18:55 PM
mbam-log-2011-03-28 (20-18-55).txt
Scan type: Quick scan
Objects scanned: 141919
Time elapsed: 3 minute(s), 39 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit quick scan 2011-03-28 20:22:04
Windows 5.1.2600 Service Pack 3 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-e ST3500418AS rev.CC34
Running: 1c26sekq.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\awdyqaoc.sys
---- System - GMER 1.0.15 ----
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xB7EAF0E0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xB7EAF0F4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB7EAF120]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB7EAF176]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xB7EAF0CC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB7EAF0A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB7EAF0B8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xB7EAF10A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xB7EAF14C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xB7EAF136]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB7EAF1A0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB7EAF18C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xB7EAF160]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Administrator at 20:23:00.76 on Mon 03/28/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2044.1156 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\McAfee Online Backup\MOBKbackup.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\GoZone\GoZone_iSync.exe
C:\Program Files\Common Files\Skyscape\SmartUpdate.exe
C:\Program Files\Skyscape\Desktop\smARTalerts\smARTalerts.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\1c26sekq.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110112072820.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [QuickFinder Scheduler] "c:\program files\wordperfect office 11\programs\QFSCHD110.EXE"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\gozone~1.lnk - c:\program files\gozone\GoZone_iSync.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\palmre~1.lnk - c:\program files\palm\register.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\skysca~1.lnk - c:\program files\common files\skyscape\SmartUpdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\datavi~1.lnk - c:\program files\common files\dataviz\DvzIncMsgr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\eventr~1.lnk - c:\program files\printmaster platinum 17\Remind.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: intuit.com\ttlc
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1287507160671
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://esource.ohiohealth.com/dana-cached/sc/JuniperSetupClient.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\0jji56st.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\mcafee\SiteAdvisor
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-10-13 386840]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-12-31 84072]
R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2010-12-31 54776]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 165264]
R1 MpKsl03e1eca8;MpKsl03e1eca8;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d973a635-5e0c-4a40-aa8b-c63ba4baeddd}\MpKsl03e1eca8.sys [2011-3-28 28752]
R1 MpKsl14298079;MpKsl14298079;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{53be1125-75c8-4bfe-8294-3794cdef45d4}\mpksl14298079.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{53be1125-75c8-4bfe-8294-3794cdef45d4}\MpKsl14298079.sys [?]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-2-5 98392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-12-31 271480]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-12-31 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-12-31 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-12-31 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-12-31 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-12-31 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-12-31 141792]
R2 MOBKbackup;McAfee Online Backup;c:\program files\mcafee online backup\MOBKbackup.exe [2010-4-13 229688]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-12-31 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-12-31 152960]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-12-31 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-12-31 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-12-31 88544]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-10-19 1691480]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-12-31 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-12-31 84264]
.
=============== Created Last 30 ================
.
2011-03-29 00:22:42 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{d973a635-5e0c-4a40-aa8b-c63ba4baeddd}\MpKsl03e1eca8.sys
2011-03-29 00:22:36 6792528 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{d973a635-5e0c-4a40-aa8b-c63ba4baeddd}\mpengine.dll
2011-03-28 23:55:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-28 23:55:48 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2011-03-28 23:47:01 -------- d-----w- c:\program files\TweakNow RegCleaner 2011
2011-03-28 23:47:01 -------- d-----w- c:\docume~1\admini~1\applic~1\TweakNow RegCleaner 2011
2011-03-28 23:28:40 98816 ----a-w- c:\windows\sed.exe
2011-03-28 23:28:40 89088 ----a-w- c:\windows\MBR.exe
2011-03-28 23:28:40 256512 ----a-w- c:\windows\PEV.exe
2011-03-28 23:28:40 161792 ----a-w- c:\windows\SWREG.exe
2011-03-28 23:28:35 -------- d-----w- C:\ComboFix
.
==================== Find3M ====================
.
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 20:23:53.62 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 10/19/2010 11:11:31 AM
System Uptime: 3/28/2011 8:12:55 PM (0 hours ago)
.
Motherboard: Intel Corporation | | DG41TY
Processor: Intel Pentium III Xeon processor | LGA775 | 2933/266mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 466 GiB total, 434.298 GiB free.
D: is CDROM ()
E: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP155: 12/29/2010 1:43:42 AM - Software Distribution Service 3.0
RP156: 12/30/2010 1:43:39 AM - Software Distribution Service 3.0
RP157: 12/31/2010 1:43:04 AM - Software Distribution Service 3.0
RP158: 1/1/2011 1:43:23 AM - Software Distribution Service 3.0
RP159: 1/2/2011 1:43:33 AM - Software Distribution Service 3.0
RP160: 1/2/2011 7:45:02 PM - Installed TurboTax 2010 wrapper
RP161: 1/3/2011 1:43:16 AM - Software Distribution Service 3.0
RP162: 1/4/2011 1:43:10 AM - Software Distribution Service 3.0
RP163: 1/5/2011 1:43:07 AM - Software Distribution Service 3.0
RP164: 1/6/2011 1:36:52 AM - Software Distribution Service 3.0
RP165: 1/6/2011 9:44:30 AM - Software Distribution Service 3.0
RP166: 1/7/2011 1:36:45 AM - Software Distribution Service 3.0
RP167: 1/7/2011 9:44:33 AM - Software Distribution Service 3.0
RP168: 1/7/2011 7:37:31 PM - Printer Driver Amyuni Document Converter 400 Installed
RP169: 1/8/2011 1:36:53 AM - Software Distribution Service 3.0
RP170: 1/8/2011 9:44:35 AM - Software Distribution Service 3.0
RP171: 1/9/2011 1:37:01 AM - Software Distribution Service 3.0
RP172: 1/9/2011 9:44:30 AM - Software Distribution Service 3.0
RP173: 1/10/2011 1:37:20 AM - Software Distribution Service 3.0
RP174: 1/10/2011 9:44:33 AM - Software Distribution Service 3.0
RP175: 1/11/2011 1:37:25 AM - Software Distribution Service 3.0
RP176: 1/11/2011 9:44:33 AM - Software Distribution Service 3.0
RP177: 1/12/2011 1:37:14 AM - Software Distribution Service 3.0
RP178: 1/12/2011 3:00:13 AM - Software Distribution Service 3.0
RP179: 1/13/2011 2:30:43 AM - Software Distribution Service 3.0
RP180: 1/14/2011 2:30:10 AM - Software Distribution Service 3.0
RP181: 1/15/2011 2:30:49 AM - Software Distribution Service 3.0
RP182: 1/16/2011 2:30:09 AM - Software Distribution Service 3.0
RP183: 1/17/2011 2:30:07 AM - Software Distribution Service 3.0
RP184: 1/18/2011 2:30:38 AM - Software Distribution Service 3.0
RP185: 1/19/2011 2:30:27 AM - Software Distribution Service 3.0
RP186: 1/20/2011 2:30:27 AM - Software Distribution Service 3.0
RP187: 1/21/2011 2:30:41 AM - Software Distribution Service 3.0
RP188: 1/22/2011 1:36:17 AM - Software Distribution Service 3.0
RP189: 1/22/2011 11:31:44 AM - Software Distribution Service 3.0
RP190: 1/23/2011 1:36:27 AM - Software Distribution Service 3.0
RP191: 1/23/2011 11:31:15 AM - Software Distribution Service 3.0
RP192: 1/23/2011 7:24:12 PM - Software Distribution Service 3.0
RP193: 1/24/2011 1:36:03 AM - Software Distribution Service 3.0
RP194: 1/24/2011 11:31:40 AM - Software Distribution Service 3.0
RP195: 1/25/2011 1:35:51 AM - Software Distribution Service 3.0
RP196: 1/25/2011 11:31:40 AM - Software Distribution Service 3.0
RP197: 1/26/2011 2:08:12 AM - Software Distribution Service 3.0
RP198: 1/26/2011 4:26:51 PM - Software Distribution Service 3.0
RP199: 1/27/2011 2:08:06 AM - Software Distribution Service 3.0
RP200: 1/30/2011 5:23:59 PM - Software Distribution Service 3.0
RP201: 1/31/2011 2:18:16 AM - Software Distribution Service 3.0
RP202: 1/31/2011 5:19:23 PM - Software Distribution Service 3.0
RP203: 1/31/2011 9:26:30 PM - Installed TurboTax 2010 wohiper
RP204: 2/1/2011 8:19:30 PM - Software Distribution Service 3.0
RP205: 2/2/2011 9:18:43 PM - System Checkpoint
RP206: 2/3/2011 1:42:31 AM - Software Distribution Service 3.0
RP207: 2/3/2011 11:49:37 AM - Software Distribution Service 3.0
RP208: 2/4/2011 1:42:03 AM - Software Distribution Service 3.0
RP209: 2/4/2011 11:49:47 AM - Software Distribution Service 3.0
RP210: 2/5/2011 1:42:24 AM - Software Distribution Service 3.0
RP211: 2/5/2011 11:49:44 AM - Software Distribution Service 3.0
RP212: 2/6/2011 1:42:00 AM - Software Distribution Service 3.0
RP213: 2/6/2011 11:49:45 AM - Software Distribution Service 3.0
RP214: 2/7/2011 1:41:45 AM - Software Distribution Service 3.0
RP215: 2/7/2011 11:49:42 AM - Software Distribution Service 3.0
RP216: 2/8/2011 1:42:12 AM - Software Distribution Service 3.0
RP217: 2/8/2011 11:42:16 AM - Software Distribution Service 3.0
RP218: 2/9/2011 1:45:37 AM - Software Distribution Service 3.0
RP219: 2/9/2011 11:48:58 AM - Software Distribution Service 3.0
RP220: 2/10/2011 1:44:21 AM - Software Distribution Service 3.0
RP221: 2/10/2011 3:00:20 AM - Software Distribution Service 3.0
RP222: 2/11/2011 2:08:40 AM - Software Distribution Service 3.0
RP223: 2/12/2011 2:08:37 AM - Software Distribution Service 3.0
RP224: 2/13/2011 2:07:42 AM - Software Distribution Service 3.0
RP225: 2/14/2011 2:09:10 AM - Software Distribution Service 3.0
RP226: 2/15/2011 2:08:46 AM - Software Distribution Service 3.0
RP227: 2/16/2011 2:10:15 AM - Software Distribution Service 3.0
RP228: 2/16/2011 1:20:34 PM - Software Distribution Service 3.0
RP229: 2/17/2011 2:09:50 AM - Software Distribution Service 3.0
RP230: 2/17/2011 1:20:46 PM - Software Distribution Service 3.0
RP231: 2/18/2011 2:10:02 AM - Software Distribution Service 3.0
RP232: 2/18/2011 1:20:48 PM - Software Distribution Service 3.0
RP233: 2/19/2011 2:10:28 AM - Software Distribution Service 3.0
RP234: 2/19/2011 1:20:18 PM - Software Distribution Service 3.0
RP235: 2/20/2011 2:12:00 AM - Software Distribution Service 3.0
RP236: 2/20/2011 1:20:37 PM - Software Distribution Service 3.0
RP237: 2/21/2011 2:10:13 AM - Software Distribution Service 3.0
RP238: 2/21/2011 1:20:34 PM - Software Distribution Service 3.0
RP239: 2/22/2011 2:14:36 AM - Software Distribution Service 3.0
RP240: 2/22/2011 9:34:15 PM - Software Distribution Service 3.0
RP241: 2/23/2011 2:13:57 AM - Software Distribution Service 3.0
RP242: 2/23/2011 9:34:44 PM - Software Distribution Service 3.0
RP243: 2/24/2011 2:14:03 AM - Software Distribution Service 3.0
RP244: 2/24/2011 9:34:36 PM - Software Distribution Service 3.0
RP245: 2/25/2011 2:14:28 AM - Software Distribution Service 3.0
RP246: 2/25/2011 9:35:22 PM - Software Distribution Service 3.0
RP247: 2/26/2011 2:14:08 AM - Software Distribution Service 3.0
RP248: 2/26/2011 9:34:45 PM - Software Distribution Service 3.0
RP249: 2/27/2011 2:14:07 AM - Software Distribution Service 3.0
RP250: 2/28/2011 7:49:15 AM - Software Distribution Service 3.0
RP251: 3/1/2011 2:25:18 AM - Software Distribution Service 3.0
RP252: 3/2/2011 2:25:06 AM - Software Distribution Service 3.0
RP253: 3/3/2011 2:25:46 AM - Software Distribution Service 3.0
RP254: 3/4/2011 2:24:55 AM - Software Distribution Service 3.0
RP255: 3/5/2011 2:25:00 AM - Software Distribution Service 3.0
RP256: 3/6/2011 2:25:39 AM - Software Distribution Service 3.0
RP257: 3/7/2011 2:25:31 AM - Software Distribution Service 3.0
RP258: 3/8/2011 2:25:14 AM - Software Distribution Service 3.0
RP259: 3/9/2011 2:25:14 AM - Software Distribution Service 3.0
RP260: 3/10/2011 2:25:06 AM - Software Distribution Service 3.0
RP261: 3/10/2011 3:00:19 AM - Software Distribution Service 3.0
RP262: 3/11/2011 2:25:10 AM - Software Distribution Service 3.0
RP263: 3/12/2011 2:25:24 AM - Software Distribution Service 3.0
RP264: 3/13/2011 3:42:13 AM - System Checkpoint
RP265: 3/13/2011 8:49:28 AM - Software Distribution Service 3.0
RP266: 3/14/2011 2:24:44 AM - Software Distribution Service 3.0
RP267: 3/15/2011 2:26:12 AM - Software Distribution Service 3.0
RP268: 3/16/2011 2:25:49 AM - Software Distribution Service 3.0
RP269: 3/17/2011 2:25:13 AM - Software Distribution Service 3.0
RP270: 3/17/2011 3:00:14 AM - Software Distribution Service 3.0
RP271: 3/18/2011 2:23:27 AM - Software Distribution Service 3.0
RP272: 3/19/2011 1:36:17 AM - Software Distribution Service 3.0
RP273: 3/19/2011 6:01:22 AM - Software Distribution Service 3.0
RP274: 3/20/2011 1:35:43 AM - Software Distribution Service 3.0
RP275: 3/20/2011 6:00:56 AM - Software Distribution Service 3.0
RP276: 3/21/2011 1:36:25 AM - Software Distribution Service 3.0
RP277: 3/21/2011 6:00:58 AM - Software Distribution Service 3.0
RP278: 3/22/2011 1:35:31 AM - Software Distribution Service 3.0
RP279: 3/22/2011 6:01:22 AM - Software Distribution Service 3.0
RP280: 3/23/2011 1:36:25 AM - Software Distribution Service 3.0
RP281: 3/23/2011 6:01:36 AM - Software Distribution Service 3.0
RP282: 3/24/2011 1:36:36 AM - Software Distribution Service 3.0
RP283: 3/24/2011 6:00:44 AM - Software Distribution Service 3.0
RP284: 3/25/2011 1:36:31 AM - Software Distribution Service 3.0
RP285: 3/25/2011 3:00:14 AM - Software Distribution Service 3.0
RP286: 3/25/2011 6:00:51 AM - Software Distribution Service 3.0
RP287: 3/26/2011 1:36:09 AM - Software Distribution Service 3.0
RP288: 3/26/2011 6:01:18 AM - Software Distribution Service 3.0
RP289: 3/27/2011 1:36:31 AM - Software Distribution Service 3.0
RP290: 3/27/2011 6:01:21 AM - Software Distribution Service 3.0
RP291: 3/28/2011 1:36:45 AM - Software Distribution Service 3.0
RP292: 3/28/2011 6:01:16 AM - Software Distribution Service 3.0
.
==== Installed Programs ======================
.
.
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.0.1)
Adobe Shockwave Player 11.5
AnswerWorks 5.0 English Runtime
ArcSoft PhotoBase
ArcSoft PhotoStudio 2000
Caere Scan Manager 5.1
Canon ScanGear Toolbox CS 2.2
Documents To Go
EncryptPDF v2.3
End It All
Epocrates Essentials
Garmin USB Drivers
Garmin WebUpdater
GoZone iSync
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Jigsaw Puzzle Player
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
McAfee Online Backup
McAfee Security Scan Plus
McAfee Total Protection
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Standard Edition 2003
Microsoft Office Word MUI (English) 2007
Microsoft Security Client
Microsoft Security Essentials
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Web Publishing Wizard 1.52
mobilePDR (Palm) v 13.13.0 by Skyscape
mobilePDR (Palm) v 13.17.1 by Skyscape
mobilePDR (Palm) v 14.1.0 by Skyscape
mobilePDR (Palm) v 14.4.0 by Skyscape
Mozilla Firefox (3.6.16)
MSN
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB925673)
NVIDIA Control Panel 260.89
NVIDIA Graphics Driver 260.89
NVIDIA Install Application
NVIDIA nView 135.36
NVIDIA nView Desktop Manager
NVIDIA PhysX
NVIDIA PhysX System Software 9.10.0514
OGA Notifier 2.0.0048.0
OmniPage Pro 9.0
Palm
PocketMirror (Standard Edition) 4.3.2
PrintMaster Platinum 17
Quicken 2011
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360131)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
smARTupdate
Spybot - Search & Destroy
StockFinder 5.0
TeleChart 2007
TurboTax 2010
TurboTax 2010 WinPerFedFormset
TurboTax 2010 WinPerReleaseEngine
TurboTax 2010 WinPerTaxSupport
TurboTax 2010 wohiper
TurboTax 2010 wrapper
TweakNow RegCleaner 2011
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Windows Internet Explorer 8 (KB2362765)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Value Line Investment Analyzer v3.0
WebFldrs XP
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
WordPerfect Office 11
XML Paper Specification Shared Components Pack 1.0
.
==== Event Viewer Messages From Past Week ========
.
3/28/2011 8:11:45 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 1 time(s).
3/28/2011 8:11:45 PM, error: Service Control Manager [7034] - The Intuit Update Service service terminated unexpectedly. It has done this 1 time(s).
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee VirusScan Announcer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:43 PM, error: Service Control Manager [7034] - The McAfee Online Backup service terminated unexpectedly. It has done this 1 time(s).
3/28/2011 8:11:42 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
3/28/2011 8:11:42 PM, error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
3/21/2011 5:55:34 AM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 001CC0C36369 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
Please note, I do not have the machine in my possession but am helping a friend, so response time may be poor. I will respond, but cannot necessarily immediately implement advice.
At any rate, here are our logs:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6199
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
3/28/2011 8:18:55 PM
mbam-log-2011-03-28 (20-18-55).txt
Scan type: Quick scan
Objects scanned: 141919
Time elapsed: 3 minute(s), 39 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit quick scan 2011-03-28 20:22:04
Windows 5.1.2600 Service Pack 3 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-e ST3500418AS rev.CC34
Running: 1c26sekq.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\awdyqaoc.sys
---- System - GMER 1.0.15 ----
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xB7EAF0E0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xB7EAF0F4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB7EAF120]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB7EAF176]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xB7EAF0CC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB7EAF0A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB7EAF0B8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xB7EAF10A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xB7EAF14C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xB7EAF136]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB7EAF1A0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB7EAF18C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xB7EAF160]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Administrator at 20:23:00.76 on Mon 03/28/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2044.1156 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\McAfee Online Backup\MOBKbackup.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\GoZone\GoZone_iSync.exe
C:\Program Files\Common Files\Skyscape\SmartUpdate.exe
C:\Program Files\Skyscape\Desktop\smARTalerts\smARTalerts.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\1c26sekq.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110112072820.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [QuickFinder Scheduler] "c:\program files\wordperfect office 11\programs\QFSCHD110.EXE"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\gozone~1.lnk - c:\program files\gozone\GoZone_iSync.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\palmre~1.lnk - c:\program files\palm\register.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\skysca~1.lnk - c:\program files\common files\skyscape\SmartUpdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\datavi~1.lnk - c:\program files\common files\dataviz\DvzIncMsgr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\eventr~1.lnk - c:\program files\printmaster platinum 17\Remind.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: intuit.com\ttlc
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1287507160671
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://esource.ohiohealth.com/dana-cached/sc/JuniperSetupClient.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\0jji56st.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\mcafee\SiteAdvisor
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-10-13 386840]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-12-31 84072]
R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2010-12-31 54776]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 165264]
R1 MpKsl03e1eca8;MpKsl03e1eca8;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d973a635-5e0c-4a40-aa8b-c63ba4baeddd}\MpKsl03e1eca8.sys [2011-3-28 28752]
R1 MpKsl14298079;MpKsl14298079;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{53be1125-75c8-4bfe-8294-3794cdef45d4}\mpksl14298079.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{53be1125-75c8-4bfe-8294-3794cdef45d4}\MpKsl14298079.sys [?]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-2-5 98392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-12-31 271480]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-12-31 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-12-31 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-12-31 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-12-31 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-12-31 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-12-31 141792]
R2 MOBKbackup;McAfee Online Backup;c:\program files\mcafee online backup\MOBKbackup.exe [2010-4-13 229688]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-12-31 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-12-31 152960]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-12-31 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-12-31 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-12-31 88544]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-10-19 1691480]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-12-31 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-12-31 84264]
.
=============== Created Last 30 ================
.
2011-03-29 00:22:42 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{d973a635-5e0c-4a40-aa8b-c63ba4baeddd}\MpKsl03e1eca8.sys
2011-03-29 00:22:36 6792528 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{d973a635-5e0c-4a40-aa8b-c63ba4baeddd}\mpengine.dll
2011-03-28 23:55:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-28 23:55:48 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2011-03-28 23:47:01 -------- d-----w- c:\program files\TweakNow RegCleaner 2011
2011-03-28 23:47:01 -------- d-----w- c:\docume~1\admini~1\applic~1\TweakNow RegCleaner 2011
2011-03-28 23:28:40 98816 ----a-w- c:\windows\sed.exe
2011-03-28 23:28:40 89088 ----a-w- c:\windows\MBR.exe
2011-03-28 23:28:40 256512 ----a-w- c:\windows\PEV.exe
2011-03-28 23:28:40 161792 ----a-w- c:\windows\SWREG.exe
2011-03-28 23:28:35 -------- d-----w- C:\ComboFix
.
==================== Find3M ====================
.
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 20:23:53.62 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 10/19/2010 11:11:31 AM
System Uptime: 3/28/2011 8:12:55 PM (0 hours ago)
.
Motherboard: Intel Corporation | | DG41TY
Processor: Intel Pentium III Xeon processor | LGA775 | 2933/266mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 466 GiB total, 434.298 GiB free.
D: is CDROM ()
E: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP155: 12/29/2010 1:43:42 AM - Software Distribution Service 3.0
RP156: 12/30/2010 1:43:39 AM - Software Distribution Service 3.0
RP157: 12/31/2010 1:43:04 AM - Software Distribution Service 3.0
RP158: 1/1/2011 1:43:23 AM - Software Distribution Service 3.0
RP159: 1/2/2011 1:43:33 AM - Software Distribution Service 3.0
RP160: 1/2/2011 7:45:02 PM - Installed TurboTax 2010 wrapper
RP161: 1/3/2011 1:43:16 AM - Software Distribution Service 3.0
RP162: 1/4/2011 1:43:10 AM - Software Distribution Service 3.0
RP163: 1/5/2011 1:43:07 AM - Software Distribution Service 3.0
RP164: 1/6/2011 1:36:52 AM - Software Distribution Service 3.0
RP165: 1/6/2011 9:44:30 AM - Software Distribution Service 3.0
RP166: 1/7/2011 1:36:45 AM - Software Distribution Service 3.0
RP167: 1/7/2011 9:44:33 AM - Software Distribution Service 3.0
RP168: 1/7/2011 7:37:31 PM - Printer Driver Amyuni Document Converter 400 Installed
RP169: 1/8/2011 1:36:53 AM - Software Distribution Service 3.0
RP170: 1/8/2011 9:44:35 AM - Software Distribution Service 3.0
RP171: 1/9/2011 1:37:01 AM - Software Distribution Service 3.0
RP172: 1/9/2011 9:44:30 AM - Software Distribution Service 3.0
RP173: 1/10/2011 1:37:20 AM - Software Distribution Service 3.0
RP174: 1/10/2011 9:44:33 AM - Software Distribution Service 3.0
RP175: 1/11/2011 1:37:25 AM - Software Distribution Service 3.0
RP176: 1/11/2011 9:44:33 AM - Software Distribution Service 3.0
RP177: 1/12/2011 1:37:14 AM - Software Distribution Service 3.0
RP178: 1/12/2011 3:00:13 AM - Software Distribution Service 3.0
RP179: 1/13/2011 2:30:43 AM - Software Distribution Service 3.0
RP180: 1/14/2011 2:30:10 AM - Software Distribution Service 3.0
RP181: 1/15/2011 2:30:49 AM - Software Distribution Service 3.0
RP182: 1/16/2011 2:30:09 AM - Software Distribution Service 3.0
RP183: 1/17/2011 2:30:07 AM - Software Distribution Service 3.0
RP184: 1/18/2011 2:30:38 AM - Software Distribution Service 3.0
RP185: 1/19/2011 2:30:27 AM - Software Distribution Service 3.0
RP186: 1/20/2011 2:30:27 AM - Software Distribution Service 3.0
RP187: 1/21/2011 2:30:41 AM - Software Distribution Service 3.0
RP188: 1/22/2011 1:36:17 AM - Software Distribution Service 3.0
RP189: 1/22/2011 11:31:44 AM - Software Distribution Service 3.0
RP190: 1/23/2011 1:36:27 AM - Software Distribution Service 3.0
RP191: 1/23/2011 11:31:15 AM - Software Distribution Service 3.0
RP192: 1/23/2011 7:24:12 PM - Software Distribution Service 3.0
RP193: 1/24/2011 1:36:03 AM - Software Distribution Service 3.0
RP194: 1/24/2011 11:31:40 AM - Software Distribution Service 3.0
RP195: 1/25/2011 1:35:51 AM - Software Distribution Service 3.0
RP196: 1/25/2011 11:31:40 AM - Software Distribution Service 3.0
RP197: 1/26/2011 2:08:12 AM - Software Distribution Service 3.0
RP198: 1/26/2011 4:26:51 PM - Software Distribution Service 3.0
RP199: 1/27/2011 2:08:06 AM - Software Distribution Service 3.0
RP200: 1/30/2011 5:23:59 PM - Software Distribution Service 3.0
RP201: 1/31/2011 2:18:16 AM - Software Distribution Service 3.0
RP202: 1/31/2011 5:19:23 PM - Software Distribution Service 3.0
RP203: 1/31/2011 9:26:30 PM - Installed TurboTax 2010 wohiper
RP204: 2/1/2011 8:19:30 PM - Software Distribution Service 3.0
RP205: 2/2/2011 9:18:43 PM - System Checkpoint
RP206: 2/3/2011 1:42:31 AM - Software Distribution Service 3.0
RP207: 2/3/2011 11:49:37 AM - Software Distribution Service 3.0
RP208: 2/4/2011 1:42:03 AM - Software Distribution Service 3.0
RP209: 2/4/2011 11:49:47 AM - Software Distribution Service 3.0
RP210: 2/5/2011 1:42:24 AM - Software Distribution Service 3.0
RP211: 2/5/2011 11:49:44 AM - Software Distribution Service 3.0
RP212: 2/6/2011 1:42:00 AM - Software Distribution Service 3.0
RP213: 2/6/2011 11:49:45 AM - Software Distribution Service 3.0
RP214: 2/7/2011 1:41:45 AM - Software Distribution Service 3.0
RP215: 2/7/2011 11:49:42 AM - Software Distribution Service 3.0
RP216: 2/8/2011 1:42:12 AM - Software Distribution Service 3.0
RP217: 2/8/2011 11:42:16 AM - Software Distribution Service 3.0
RP218: 2/9/2011 1:45:37 AM - Software Distribution Service 3.0
RP219: 2/9/2011 11:48:58 AM - Software Distribution Service 3.0
RP220: 2/10/2011 1:44:21 AM - Software Distribution Service 3.0
RP221: 2/10/2011 3:00:20 AM - Software Distribution Service 3.0
RP222: 2/11/2011 2:08:40 AM - Software Distribution Service 3.0
RP223: 2/12/2011 2:08:37 AM - Software Distribution Service 3.0
RP224: 2/13/2011 2:07:42 AM - Software Distribution Service 3.0
RP225: 2/14/2011 2:09:10 AM - Software Distribution Service 3.0
RP226: 2/15/2011 2:08:46 AM - Software Distribution Service 3.0
RP227: 2/16/2011 2:10:15 AM - Software Distribution Service 3.0
RP228: 2/16/2011 1:20:34 PM - Software Distribution Service 3.0
RP229: 2/17/2011 2:09:50 AM - Software Distribution Service 3.0
RP230: 2/17/2011 1:20:46 PM - Software Distribution Service 3.0
RP231: 2/18/2011 2:10:02 AM - Software Distribution Service 3.0
RP232: 2/18/2011 1:20:48 PM - Software Distribution Service 3.0
RP233: 2/19/2011 2:10:28 AM - Software Distribution Service 3.0
RP234: 2/19/2011 1:20:18 PM - Software Distribution Service 3.0
RP235: 2/20/2011 2:12:00 AM - Software Distribution Service 3.0
RP236: 2/20/2011 1:20:37 PM - Software Distribution Service 3.0
RP237: 2/21/2011 2:10:13 AM - Software Distribution Service 3.0
RP238: 2/21/2011 1:20:34 PM - Software Distribution Service 3.0
RP239: 2/22/2011 2:14:36 AM - Software Distribution Service 3.0
RP240: 2/22/2011 9:34:15 PM - Software Distribution Service 3.0
RP241: 2/23/2011 2:13:57 AM - Software Distribution Service 3.0
RP242: 2/23/2011 9:34:44 PM - Software Distribution Service 3.0
RP243: 2/24/2011 2:14:03 AM - Software Distribution Service 3.0
RP244: 2/24/2011 9:34:36 PM - Software Distribution Service 3.0
RP245: 2/25/2011 2:14:28 AM - Software Distribution Service 3.0
RP246: 2/25/2011 9:35:22 PM - Software Distribution Service 3.0
RP247: 2/26/2011 2:14:08 AM - Software Distribution Service 3.0
RP248: 2/26/2011 9:34:45 PM - Software Distribution Service 3.0
RP249: 2/27/2011 2:14:07 AM - Software Distribution Service 3.0
RP250: 2/28/2011 7:49:15 AM - Software Distribution Service 3.0
RP251: 3/1/2011 2:25:18 AM - Software Distribution Service 3.0
RP252: 3/2/2011 2:25:06 AM - Software Distribution Service 3.0
RP253: 3/3/2011 2:25:46 AM - Software Distribution Service 3.0
RP254: 3/4/2011 2:24:55 AM - Software Distribution Service 3.0
RP255: 3/5/2011 2:25:00 AM - Software Distribution Service 3.0
RP256: 3/6/2011 2:25:39 AM - Software Distribution Service 3.0
RP257: 3/7/2011 2:25:31 AM - Software Distribution Service 3.0
RP258: 3/8/2011 2:25:14 AM - Software Distribution Service 3.0
RP259: 3/9/2011 2:25:14 AM - Software Distribution Service 3.0
RP260: 3/10/2011 2:25:06 AM - Software Distribution Service 3.0
RP261: 3/10/2011 3:00:19 AM - Software Distribution Service 3.0
RP262: 3/11/2011 2:25:10 AM - Software Distribution Service 3.0
RP263: 3/12/2011 2:25:24 AM - Software Distribution Service 3.0
RP264: 3/13/2011 3:42:13 AM - System Checkpoint
RP265: 3/13/2011 8:49:28 AM - Software Distribution Service 3.0
RP266: 3/14/2011 2:24:44 AM - Software Distribution Service 3.0
RP267: 3/15/2011 2:26:12 AM - Software Distribution Service 3.0
RP268: 3/16/2011 2:25:49 AM - Software Distribution Service 3.0
RP269: 3/17/2011 2:25:13 AM - Software Distribution Service 3.0
RP270: 3/17/2011 3:00:14 AM - Software Distribution Service 3.0
RP271: 3/18/2011 2:23:27 AM - Software Distribution Service 3.0
RP272: 3/19/2011 1:36:17 AM - Software Distribution Service 3.0
RP273: 3/19/2011 6:01:22 AM - Software Distribution Service 3.0
RP274: 3/20/2011 1:35:43 AM - Software Distribution Service 3.0
RP275: 3/20/2011 6:00:56 AM - Software Distribution Service 3.0
RP276: 3/21/2011 1:36:25 AM - Software Distribution Service 3.0
RP277: 3/21/2011 6:00:58 AM - Software Distribution Service 3.0
RP278: 3/22/2011 1:35:31 AM - Software Distribution Service 3.0
RP279: 3/22/2011 6:01:22 AM - Software Distribution Service 3.0
RP280: 3/23/2011 1:36:25 AM - Software Distribution Service 3.0
RP281: 3/23/2011 6:01:36 AM - Software Distribution Service 3.0
RP282: 3/24/2011 1:36:36 AM - Software Distribution Service 3.0
RP283: 3/24/2011 6:00:44 AM - Software Distribution Service 3.0
RP284: 3/25/2011 1:36:31 AM - Software Distribution Service 3.0
RP285: 3/25/2011 3:00:14 AM - Software Distribution Service 3.0
RP286: 3/25/2011 6:00:51 AM - Software Distribution Service 3.0
RP287: 3/26/2011 1:36:09 AM - Software Distribution Service 3.0
RP288: 3/26/2011 6:01:18 AM - Software Distribution Service 3.0
RP289: 3/27/2011 1:36:31 AM - Software Distribution Service 3.0
RP290: 3/27/2011 6:01:21 AM - Software Distribution Service 3.0
RP291: 3/28/2011 1:36:45 AM - Software Distribution Service 3.0
RP292: 3/28/2011 6:01:16 AM - Software Distribution Service 3.0
.
==== Installed Programs ======================
.
.
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.0.1)
Adobe Shockwave Player 11.5
AnswerWorks 5.0 English Runtime
ArcSoft PhotoBase
ArcSoft PhotoStudio 2000
Caere Scan Manager 5.1
Canon ScanGear Toolbox CS 2.2
Documents To Go
EncryptPDF v2.3
End It All
Epocrates Essentials
Garmin USB Drivers
Garmin WebUpdater
GoZone iSync
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Jigsaw Puzzle Player
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
McAfee Online Backup
McAfee Security Scan Plus
McAfee Total Protection
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Standard Edition 2003
Microsoft Office Word MUI (English) 2007
Microsoft Security Client
Microsoft Security Essentials
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Web Publishing Wizard 1.52
mobilePDR (Palm) v 13.13.0 by Skyscape
mobilePDR (Palm) v 13.17.1 by Skyscape
mobilePDR (Palm) v 14.1.0 by Skyscape
mobilePDR (Palm) v 14.4.0 by Skyscape
Mozilla Firefox (3.6.16)
MSN
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB925673)
NVIDIA Control Panel 260.89
NVIDIA Graphics Driver 260.89
NVIDIA Install Application
NVIDIA nView 135.36
NVIDIA nView Desktop Manager
NVIDIA PhysX
NVIDIA PhysX System Software 9.10.0514
OGA Notifier 2.0.0048.0
OmniPage Pro 9.0
Palm
PocketMirror (Standard Edition) 4.3.2
PrintMaster Platinum 17
Quicken 2011
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360131)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
smARTupdate
Spybot - Search & Destroy
StockFinder 5.0
TeleChart 2007
TurboTax 2010
TurboTax 2010 WinPerFedFormset
TurboTax 2010 WinPerReleaseEngine
TurboTax 2010 WinPerTaxSupport
TurboTax 2010 wohiper
TurboTax 2010 wrapper
TweakNow RegCleaner 2011
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Windows Internet Explorer 8 (KB2362765)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Value Line Investment Analyzer v3.0
WebFldrs XP
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
WordPerfect Office 11
XML Paper Specification Shared Components Pack 1.0
.
==== Event Viewer Messages From Past Week ========
.
3/28/2011 8:11:45 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 1 time(s).
3/28/2011 8:11:45 PM, error: Service Control Manager [7034] - The Intuit Update Service service terminated unexpectedly. It has done this 1 time(s).
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee VirusScan Announcer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:45 PM, error: Service Control Manager [7031] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/28/2011 8:11:43 PM, error: Service Control Manager [7034] - The McAfee Online Backup service terminated unexpectedly. It has done this 1 time(s).
3/28/2011 8:11:42 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
3/28/2011 8:11:42 PM, error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
3/21/2011 5:55:34 AM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 001CC0C36369 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================