I went through the 8 steps that you guys provided and am still having troubles with my computer saying that one of the csrss.exe files cannot be located, which is limiting my usage of my computer, or so I think. Below are the requested logs:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6346
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
4/12/2011 4:50:32 PM
mbam-log-2011-04-12 (16-50-32).txt
Scan type: Quick scan
Objects scanned: 1372
Time elapsed: 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\6to4v32.dll (Backdoor.Agent) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent.Gen) -> Bad: (C:\DOCUME~1\me\LOCALS~1\Temp\csrss.exe) Good: () -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\6to4v32.dll (Backdoor.Agent) -> Delete on reboot.
c:\Documents and Settings\me\Local Settings\Temp\csrss.exe (Trojan.Agent.Gen) -> Delete on reboot.
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-04-13 13:03:59
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 SAMSUNG_HD080HJ/P rev.ZH100-51
Running: 0ibsqt44.exe; Driver: C:\DOCUME~1\me\LOCALS~1\Temp\awrcyfod.sys
---- System - GMER 1.0.15 ----
SSDT BA7BBE8E ZwCreateKey
SSDT BA7BBE84 ZwCreateThread
SSDT BA7BBE93 ZwDeleteKey
SSDT BA7BBE9D ZwDeleteValueKey
SSDT BA7BBEA2 ZwLoadKey
SSDT BA7BBE70 ZwOpenProcess
SSDT BA7BBE75 ZwOpenThread
SSDT BA7BBEAC ZwReplaceKey
SSDT BA7BBEA7 ZwRestoreKey
SSDT BA7BBE98 ZwSetValueKey
---- User code sections - GMER 1.0.15 ----
? C:\DOCUME~1\me\LOCALS~1\Temp\csrss.exe[1992] number of sections mismatch; time/date stamp mismatch; unknown module: OLEAUT32.dllunknown module: RASAPI32.dllunknown module: WINHTTP.dll
.tls C:\DOCUME~1\me\LOCALS~1\Temp\csrss.exe[1992] C:\DOCUME~1\me\LOCALS~1\Temp\csrss.exe unknown last section [0x0042C000, 0x3D000, 0x40000040]
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!GetSysColor 77D48E50 5 Bytes JMP 00419330 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!GetSysColorBrush 77D48E83 5 Bytes JMP 004193A0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!SetScrollInfo 77D4902C 7 Bytes JMP 00419220 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!GetScrollPos 77D4F66F 5 Bytes JMP 004191B0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!SetScrollRange 77D4F6BB 5 Bytes JMP 004192A0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!SetScrollPos 77D4F780 5 Bytes JMP 00419260 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!GetScrollRange 77D4F7B7 5 Bytes JMP 004191E0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!ShowScrollBar 77D50142 5 Bytes JMP 004192F0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!GetScrollInfo 77D53A2F 7 Bytes JMP 00419170 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!EnableScrollBar 77D97BAD 7 Bytes JMP 00419130 C:\WINDOWS\SMINST\Scheduler.exe
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\MacOS\AELicensingPlugin 16128 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\French.lproj 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\French.lproj\LicensePlugin.nib 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\French.lproj\LicensePlugin.nib\keyedobjects.nib 14846 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\German.lproj 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\German.lproj\Localizable.strings 125 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\Japanese.lproj 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\Japanese.lproj\LicensePlugin.nib 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\Japanese.lproj\LicensePlugin.nib\keyedobjects.nib 15796 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\zh_CN.lproj 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\zh_CN.lproj\LicensePlugin.nib 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\zh_CN.lproj\LicensePlugin.nib\keyedobjects.nib 15626 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\_CodeSignature\CodeResources 187 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by me at 14:05:33.90 on Wed 04/13/2011
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2039.1476 [GMT -5:00]
.
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\PDF Complete\pdfsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\me\Application Data\dwm.exe
C:\Documents and Settings\me\Application Data\Microsoft\conhost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\PDF Complete\pdfsty.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\me\My Documents\Downloads\dds(3).scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.hp.com
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
uInternet Settings,ProxyServer = http=127.0.0.1:58323
mWinlogon: Userinit=userinit.exe,
uWinlogon: Shell=explorer.exe,c:\documents and settings\me\application data\dwm.exe
uWindows: load=c:\docume~1\me\locals~1\temp\csrss.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: WhiteSmoke Toolbar: {52794457-af6c-4c50-9def-f2e24f4c8889} - c:\program files\whitesmoketoolbar\whitesmoketoolbarX.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: GamePlayLabsBHO Class: {984a9162-8891-4d19-8cfe-17648bb4e1ec} - c:\program files\browser plugin\BHO.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
TB: WhiteSmoke Toolbar: {52794457-af6c-4c50-9def-f2e24f4c8889} - c:\program files\whitesmoketoolbar\whitesmoketoolbarX.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [PDF Complete] "c:\program files\pdf complete\pdfsty.exe"
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [Recguard] c:\windows\sminst\Recguard.exe
mRun: [Reminder] c:\windows\creator\Remind_XP.exe
mRun: [Scheduler] c:\windows\sminst\Scheduler.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [conhost] c:\documents and settings\me\application data\microsoft\conhost.exe
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\me\applic~1\mozilla\firefox\profiles\pvzyfs5o.default\
FF - prefs.js: browser.startup.homepage - hxxp://u.northwestern.edu/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 58323
FF - prefs.js: network.proxy.type - 1
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-4-12 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-4-12 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-4-12 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-4-12 61960]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\pdf complete\pdfsvc.exe [2007-6-20 540448]
S0 gxiwzd;gxiwzd;c:\windows\system32\drivers\rehufqgl.sys [2011-1-20 53888]
S3 EraserUtilDrv11010;EraserUtilDrv11010;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv11010.sys --> c:\program files\common files\symantec shared\eengine\EraserUtilDrv11010.sys [?]
.
=============== Created Last 30 ================
.
2011-04-13 18:07:59 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-04-13 18:07:59 215920 ----a-w- c:\windows\system32\muweb.dll
2011-04-13 18:07:59 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2011-04-13 17:03:53 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-13 17:03:52 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-04-13 17:03:52 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-04-13 17:03:51 728024 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-04-13 17:03:51 1975768 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-04-13 17:03:51 1893336 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-04-13 17:03:51 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-04-13 17:03:51 142296 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2011-04-12 22:00:36 -------- d-----w- c:\windows\system32\NtmsData
2011-04-12 21:59:13 -------- d-----w- c:\docume~1\me\applic~1\Avira
2011-04-12 21:57:56 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-04-12 21:57:55 -------- d-----w- c:\program files\Avira
2011-04-12 21:57:55 -------- d-----w- c:\docume~1\alluse~1\applic~1\Avira
2011-04-12 21:40:00 -------- d-----w- c:\docume~1\me\applic~1\Malwarebytes
2011-04-12 21:39:57 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-12 21:39:56 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-04-12 21:39:53 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-12 21:39:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-12 18:22:20 -------- d-----w- c:\docume~1\me\locals~1\applic~1\Adobe
2011-04-12 17:49:15 6200 ----a-w- c:\windows\system32\INT13EXT.VXD
2011-04-12 17:49:14 -------- d-----w- c:\program files\PC Inspector File Recovery
2011-04-12 15:25:45 180224 ----a-w- c:\docume~1\me\applic~1\dwm.exe
2011-04-12 15:22:35 -------- d-----w- c:\docume~1\me\locals~1\applic~1\Mozilla
2011-04-12 15:20:43 -------- d-----w- c:\docume~1\me\applic~1\Piiw
2011-04-12 15:20:42 -------- d-----w- c:\docume~1\me\applic~1\Ikruy
2011-04-12 15:18:42 -------- d-----w- c:\docume~1\me\applic~1\whitesmoketoolbar
2011-04-04 19:51:09 -------- d-----w- c:\program files\IrfanView
2011-03-16 19:14:38 -------- d-----w- c:\program files\iPod
2011-03-16 19:14:34 -------- d-----w- c:\program files\iTunes
.
==================== Find3M ====================
.
2011-01-31 14:44:44 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-01-20 22:28:07 18297 ----a-w- c:\windows\system32\MAI374.tmp
.
============= FINISH: 14:06:00.68 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 7/10/2007 1:53:57 PM
System Uptime: 4/13/2011 1:33:23 PM (1 hours ago)
.
Motherboard: Hewlett-Packard | | 0A60h
Processor: Intel(R) Pentium(R) 4 CPU 3.20GHz | XU1 PROCESSOR | 3192/800mhz
Processor: Intel(R) Pentium(R) 4 CPU 3.20GHz | XU2 PROCESSOR | 3192/mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 65 GiB total, 14.474 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 4.827 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: Network Controller
Device ID: PCI\VEN_14E4&DEV_4329&SUBSYS_7D001385&REV_01\4&3721BFB3&0&48F0
Manufacturer:
Name: Network Controller
PNP Device ID: PCI\VEN_14E4&DEV_4329&SUBSYS_7D001385&REV_01\4&3721BFB3&0&48F0
Service:
.
Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: PS/2 Compatible Mouse
Device ID: ACPI\PNP0F13\4&DE53A73&0
Manufacturer: Microsoft
Name: PS/2 Compatible Mouse
PNP Device ID: ACPI\PNP0F13\4&DE53A73&0
Service: i8042prt
.
Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
Device ID: ACPI\PNP0303\4&DE53A73&0
Manufacturer: (Standard keyboards)
Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
PNP Device ID: ACPI\PNP0303\4&DE53A73&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP1: 1/21/2011 9:37:53 PM - System Checkpoint
RP2: 1/26/2011 6:00:47 PM - System Checkpoint
RP3: 1/27/2011 9:48:27 PM - System Checkpoint
RP4: 1/28/2011 10:29:02 PM - System Checkpoint
RP5: 1/29/2011 11:29:02 PM - System Checkpoint
RP6: 1/30/2011 11:55:57 PM - System Checkpoint
RP7: 2/1/2011 3:00:06 PM - System Checkpoint
RP8: 2/3/2011 11:37:12 AM - System Checkpoint
RP9: 2/6/2011 1:03:46 PM - System Checkpoint
RP10: 2/7/2011 2:00:48 PM - System Checkpoint
RP11: 2/8/2011 3:00:48 PM - System Checkpoint
RP12: 2/9/2011 4:00:48 PM - System Checkpoint
RP13: 2/10/2011 5:01:54 PM - System Checkpoint
RP14: 2/11/2011 6:00:48 PM - System Checkpoint
RP15: 2/12/2011 8:14:48 PM - System Checkpoint
RP16: 2/13/2011 9:00:48 PM - System Checkpoint
RP17: 2/14/2011 10:00:48 PM - System Checkpoint
RP18: 2/15/2011 11:00:48 PM - System Checkpoint
RP19: 2/17/2011 9:36:51 AM - System Checkpoint
RP20: 2/18/2011 10:00:50 AM - System Checkpoint
RP21: 2/19/2011 4:18:52 PM - System Checkpoint
RP22: 2/21/2011 2:59:50 AM - System Checkpoint
RP23: 2/23/2011 1:57:11 AM - System Checkpoint
RP24: 2/23/2011 3:00:14 AM - Software Distribution Service 3.0
RP25: 2/24/2011 3:22:27 AM - System Checkpoint
RP26: 2/25/2011 3:53:29 AM - System Checkpoint
RP27: 2/26/2011 4:53:29 AM - System Checkpoint
RP28: 2/27/2011 6:29:29 AM - System Checkpoint
RP29: 2/28/2011 6:53:29 AM - System Checkpoint
RP30: 3/1/2011 7:53:30 AM - System Checkpoint
RP31: 3/2/2011 7:53:35 AM - System Checkpoint
RP32: 3/3/2011 8:53:35 AM - System Checkpoint
RP33: 3/4/2011 8:09:52 PM - System Checkpoint
RP34: 3/5/2011 8:21:46 PM - System Checkpoint
RP35: 3/6/2011 8:52:23 PM - System Checkpoint
RP36: 3/7/2011 8:53:35 PM - System Checkpoint
RP37: 3/8/2011 9:53:35 PM - System Checkpoint
RP38: 3/10/2011 1:01:21 AM - System Checkpoint
RP39: 3/10/2011 3:00:14 AM - Software Distribution Service 3.0
RP40: 3/11/2011 3:53:35 AM - System Checkpoint
RP41: 3/12/2011 3:53:45 AM - System Checkpoint
RP42: 3/13/2011 5:53:45 AM - System Checkpoint
RP43: 3/14/2011 6:52:28 AM - System Checkpoint
RP44: 3/15/2011 6:53:45 AM - System Checkpoint
RP45: 3/16/2011 2:08:30 PM - Removed Apple Application Support
RP46: 3/16/2011 2:09:43 PM - Removed Apple Mobile Device Support
RP47: 3/17/2011 3:20:41 PM - System Checkpoint
RP48: 3/18/2011 4:06:12 PM - System Checkpoint
RP49: 3/19/2011 5:06:11 PM - System Checkpoint
RP50: 3/20/2011 6:06:11 PM - System Checkpoint
RP51: 3/21/2011 7:06:11 PM - System Checkpoint
RP52: 3/22/2011 8:06:11 PM - System Checkpoint
RP53: 3/23/2011 9:06:11 PM - System Checkpoint
RP54: 3/24/2011 10:06:11 PM - System Checkpoint
RP55: 3/25/2011 11:06:11 PM - System Checkpoint
RP56: 3/27/2011 12:04:16 AM - System Checkpoint
RP57: 3/27/2011 5:56:24 PM - Software Distribution Service 3.0
RP58: 3/29/2011 6:06:16 PM - System Checkpoint
RP59: 3/30/2011 9:56:56 PM - System Checkpoint
RP60: 3/31/2011 10:56:01 PM - System Checkpoint
RP61: 4/1/2011 11:56:01 PM - System Checkpoint
RP62: 4/3/2011 2:38:29 AM - System Checkpoint
RP63: 4/4/2011 2:56:01 AM - System Checkpoint
RP64: 4/6/2011 11:59:54 AM - System Checkpoint
RP65: 4/7/2011 12:52:28 PM - System Checkpoint
RP66: 4/8/2011 1:52:28 PM - System Checkpoint
RP67: 4/9/2011 6:32:57 PM - System Checkpoint
RP68: 4/10/2011 7:29:20 PM - System Checkpoint
RP69: 4/12/2011 12:49:14 PM - Installed PC Inspector File Recovery
RP70: 4/12/2011 4:57:55 PM - Avira AntiVir Personal - 4/12/2011 16:57
.
==== Installed Programs ======================
.
.
µTorrent
2007 Microsoft Office system
7-Zip 4.57
Activation Assistant for the 2007 Microsoft Office suites
Adobe Flash Player 10 Plugin
Adobe Reader 7.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Avira AntiVir Personal - Free Antivirus
Bonjour
Broadcom Management Programs
Broadcom TPM Driver Installer
Business Contact Manager for Outlook 2007
Convert AVI to MP4 1.3
High Definition Audio Driver Package - KB888111
HijackThis 1.99.1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB895246)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB923232)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB981793)
HP Backup and Recovery Manager
HP Help and Support
HpSdpAppCoreApp
iMPEG Converter 3.8
Intel(R) Graphics Media Accelerator Driver
InterVideo Register Manager
InterVideo WinDVD
IrfanView (remove only)
iTunes
IZArc 4.1.2
J2SE Runtime Environment 5.0 Update 6
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Office 2003 Web Components
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business Connectivity Components
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox 4.0 (x86 en-US)
MSXML 6 Service Pack 2 (KB973686)
PC Inspector File Recovery
PDF Complete
PowerISO
Programmer's Notepad 2
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Secret Crush Revealer
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981350)
Security Update for Windows XP (KB982381)
Skype Toolbars
Skype™ 5.0
SSH Secure Shell
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Office System 2007 Setup (KB929722)
Update for Windows XP (KB898461)
Update for Windows XP (KB911164)
Update for Windows XP (KB925720)
Update for Windows XP (KB931836)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VLC media player 1.0.1
Warcraft III
WebFldrs XP
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB815304
Windows XP Hotfix - KB885222
Windows XP Hotfix - KB886199
Windows XP Hotfix - KB889673
.
==== Event Viewer Messages From Past Week ========
.
4/8/2011 5:39:13 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer JACK-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{30AC4706-B8C4-4EC9-A. The master browser is stopping or an election is being forced.
4/13/2011 12:09:30 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
4/12/2011 9:48:48 AM, error: Service Control Manager [7034] - The SQL Server (MSSMLBIZ) service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 9:41:03 AM, error: Service Control Manager [7034] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 9:41:03 AM, error: Service Control Manager [7034] - The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 9:41:03 AM, error: Service Control Manager [7034] - The DNS Client service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 9:41:03 AM, error: Service Control Manager [7031] - The Remote Registry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
4/12/2011 9:41:03 AM, error: Service Control Manager [7031] - The Remote Procedure Call (RPC) service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
4/12/2011 9:41:03 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
4/12/2011 4:57:17 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. .
4/12/2011 4:57:17 PM, error: SideBySide [59] - Generate Activation Context failed for C:\DOCUME~1\me\LOCALS~1\Temp\RarSFX0\redist.dll. Reference error message: The operation completed successfully. .
4/12/2011 4:57:17 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
4/12/2011 4:53:59 PM, error: Service Control Manager [7023] - The Network Security service terminated with the following error: The specified module could not be found.
4/12/2011 4:53:58 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 897e9da0, parameter3 897e9f14, parameter4 805d1658.
4/12/2011 4:51:39 PM, error: Service Control Manager [7034] - The IviRegMgr service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 4:51:39 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 10:21:52 AM, error: Service Control Manager [7034] - The PC Angel service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 10:21:52 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: eeCtrl
4/12/2011 10:21:52 AM, error: Service Control Manager [7000] - The Print Spooler service failed to start due to the following error: The system cannot find the file specified.
4/12/2011 1:40:36 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
.
==== End Of File ===========================
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6346
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
4/12/2011 4:50:32 PM
mbam-log-2011-04-12 (16-50-32).txt
Scan type: Quick scan
Objects scanned: 1372
Time elapsed: 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\6to4v32.dll (Backdoor.Agent) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent.Gen) -> Bad: (C:\DOCUME~1\me\LOCALS~1\Temp\csrss.exe) Good: () -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\6to4v32.dll (Backdoor.Agent) -> Delete on reboot.
c:\Documents and Settings\me\Local Settings\Temp\csrss.exe (Trojan.Agent.Gen) -> Delete on reboot.
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-04-13 13:03:59
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 SAMSUNG_HD080HJ/P rev.ZH100-51
Running: 0ibsqt44.exe; Driver: C:\DOCUME~1\me\LOCALS~1\Temp\awrcyfod.sys
---- System - GMER 1.0.15 ----
SSDT BA7BBE8E ZwCreateKey
SSDT BA7BBE84 ZwCreateThread
SSDT BA7BBE93 ZwDeleteKey
SSDT BA7BBE9D ZwDeleteValueKey
SSDT BA7BBEA2 ZwLoadKey
SSDT BA7BBE70 ZwOpenProcess
SSDT BA7BBE75 ZwOpenThread
SSDT BA7BBEAC ZwReplaceKey
SSDT BA7BBEA7 ZwRestoreKey
SSDT BA7BBE98 ZwSetValueKey
---- User code sections - GMER 1.0.15 ----
? C:\DOCUME~1\me\LOCALS~1\Temp\csrss.exe[1992] number of sections mismatch; time/date stamp mismatch; unknown module: OLEAUT32.dllunknown module: RASAPI32.dllunknown module: WINHTTP.dll
.tls C:\DOCUME~1\me\LOCALS~1\Temp\csrss.exe[1992] C:\DOCUME~1\me\LOCALS~1\Temp\csrss.exe unknown last section [0x0042C000, 0x3D000, 0x40000040]
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!GetSysColor 77D48E50 5 Bytes JMP 00419330 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!GetSysColorBrush 77D48E83 5 Bytes JMP 004193A0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!SetScrollInfo 77D4902C 7 Bytes JMP 00419220 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!GetScrollPos 77D4F66F 5 Bytes JMP 004191B0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!SetScrollRange 77D4F6BB 5 Bytes JMP 004192A0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!SetScrollPos 77D4F780 5 Bytes JMP 00419260 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!GetScrollRange 77D4F7B7 5 Bytes JMP 004191E0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!ShowScrollBar 77D50142 5 Bytes JMP 004192F0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!GetScrollInfo 77D53A2F 7 Bytes JMP 00419170 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[3328] USER32.dll!EnableScrollBar 77D97BAD 7 Bytes JMP 00419130 C:\WINDOWS\SMINST\Scheduler.exe
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\MacOS\AELicensingPlugin 16128 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\French.lproj 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\French.lproj\LicensePlugin.nib 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\French.lproj\LicensePlugin.nib\keyedobjects.nib 14846 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\German.lproj 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\German.lproj\Localizable.strings 125 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\Japanese.lproj 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\Japanese.lproj\LicensePlugin.nib 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\Japanese.lproj\LicensePlugin.nib\keyedobjects.nib 15796 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\zh_CN.lproj 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\zh_CN.lproj\LicensePlugin.nib 0 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\Resources\zh_CN.lproj\LicensePlugin.nib\keyedobjects.nib 15626 bytes
File C:\Documents and Settings\Administrator\My Documents\Downloads\Logic Studio 9\Logic Pro 9 Patches\WaveBurner_1.6 Intel noSN Patch.app\LogicStudio_noSN Installer Patch.app\Contents\Resources\Patch1\Data\Contents\Plugins\AELicensingPlugin.bundle\Contents\_CodeSignature\CodeResources 187 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by me at 14:05:33.90 on Wed 04/13/2011
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2039.1476 [GMT -5:00]
.
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\PDF Complete\pdfsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\me\Application Data\dwm.exe
C:\Documents and Settings\me\Application Data\Microsoft\conhost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\PDF Complete\pdfsty.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\me\My Documents\Downloads\dds(3).scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.hp.com
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
uInternet Settings,ProxyServer = http=127.0.0.1:58323
mWinlogon: Userinit=userinit.exe,
uWinlogon: Shell=explorer.exe,c:\documents and settings\me\application data\dwm.exe
uWindows: load=c:\docume~1\me\locals~1\temp\csrss.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: WhiteSmoke Toolbar: {52794457-af6c-4c50-9def-f2e24f4c8889} - c:\program files\whitesmoketoolbar\whitesmoketoolbarX.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: GamePlayLabsBHO Class: {984a9162-8891-4d19-8cfe-17648bb4e1ec} - c:\program files\browser plugin\BHO.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
TB: WhiteSmoke Toolbar: {52794457-af6c-4c50-9def-f2e24f4c8889} - c:\program files\whitesmoketoolbar\whitesmoketoolbarX.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [PDF Complete] "c:\program files\pdf complete\pdfsty.exe"
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [Recguard] c:\windows\sminst\Recguard.exe
mRun: [Reminder] c:\windows\creator\Remind_XP.exe
mRun: [Scheduler] c:\windows\sminst\Scheduler.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [conhost] c:\documents and settings\me\application data\microsoft\conhost.exe
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\me\applic~1\mozilla\firefox\profiles\pvzyfs5o.default\
FF - prefs.js: browser.startup.homepage - hxxp://u.northwestern.edu/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 58323
FF - prefs.js: network.proxy.type - 1
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-4-12 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-4-12 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-4-12 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-4-12 61960]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\pdf complete\pdfsvc.exe [2007-6-20 540448]
S0 gxiwzd;gxiwzd;c:\windows\system32\drivers\rehufqgl.sys [2011-1-20 53888]
S3 EraserUtilDrv11010;EraserUtilDrv11010;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv11010.sys --> c:\program files\common files\symantec shared\eengine\EraserUtilDrv11010.sys [?]
.
=============== Created Last 30 ================
.
2011-04-13 18:07:59 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-04-13 18:07:59 215920 ----a-w- c:\windows\system32\muweb.dll
2011-04-13 18:07:59 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2011-04-13 17:03:53 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-13 17:03:52 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-04-13 17:03:52 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-04-13 17:03:51 728024 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-04-13 17:03:51 1975768 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-04-13 17:03:51 1893336 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-04-13 17:03:51 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-04-13 17:03:51 142296 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2011-04-12 22:00:36 -------- d-----w- c:\windows\system32\NtmsData
2011-04-12 21:59:13 -------- d-----w- c:\docume~1\me\applic~1\Avira
2011-04-12 21:57:56 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-04-12 21:57:55 -------- d-----w- c:\program files\Avira
2011-04-12 21:57:55 -------- d-----w- c:\docume~1\alluse~1\applic~1\Avira
2011-04-12 21:40:00 -------- d-----w- c:\docume~1\me\applic~1\Malwarebytes
2011-04-12 21:39:57 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-12 21:39:56 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-04-12 21:39:53 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-12 21:39:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-12 18:22:20 -------- d-----w- c:\docume~1\me\locals~1\applic~1\Adobe
2011-04-12 17:49:15 6200 ----a-w- c:\windows\system32\INT13EXT.VXD
2011-04-12 17:49:14 -------- d-----w- c:\program files\PC Inspector File Recovery
2011-04-12 15:25:45 180224 ----a-w- c:\docume~1\me\applic~1\dwm.exe
2011-04-12 15:22:35 -------- d-----w- c:\docume~1\me\locals~1\applic~1\Mozilla
2011-04-12 15:20:43 -------- d-----w- c:\docume~1\me\applic~1\Piiw
2011-04-12 15:20:42 -------- d-----w- c:\docume~1\me\applic~1\Ikruy
2011-04-12 15:18:42 -------- d-----w- c:\docume~1\me\applic~1\whitesmoketoolbar
2011-04-04 19:51:09 -------- d-----w- c:\program files\IrfanView
2011-03-16 19:14:38 -------- d-----w- c:\program files\iPod
2011-03-16 19:14:34 -------- d-----w- c:\program files\iTunes
.
==================== Find3M ====================
.
2011-01-31 14:44:44 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-01-20 22:28:07 18297 ----a-w- c:\windows\system32\MAI374.tmp
.
============= FINISH: 14:06:00.68 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 7/10/2007 1:53:57 PM
System Uptime: 4/13/2011 1:33:23 PM (1 hours ago)
.
Motherboard: Hewlett-Packard | | 0A60h
Processor: Intel(R) Pentium(R) 4 CPU 3.20GHz | XU1 PROCESSOR | 3192/800mhz
Processor: Intel(R) Pentium(R) 4 CPU 3.20GHz | XU2 PROCESSOR | 3192/mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 65 GiB total, 14.474 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 4.827 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: Network Controller
Device ID: PCI\VEN_14E4&DEV_4329&SUBSYS_7D001385&REV_01\4&3721BFB3&0&48F0
Manufacturer:
Name: Network Controller
PNP Device ID: PCI\VEN_14E4&DEV_4329&SUBSYS_7D001385&REV_01\4&3721BFB3&0&48F0
Service:
.
Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: PS/2 Compatible Mouse
Device ID: ACPI\PNP0F13\4&DE53A73&0
Manufacturer: Microsoft
Name: PS/2 Compatible Mouse
PNP Device ID: ACPI\PNP0F13\4&DE53A73&0
Service: i8042prt
.
Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
Device ID: ACPI\PNP0303\4&DE53A73&0
Manufacturer: (Standard keyboards)
Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
PNP Device ID: ACPI\PNP0303\4&DE53A73&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP1: 1/21/2011 9:37:53 PM - System Checkpoint
RP2: 1/26/2011 6:00:47 PM - System Checkpoint
RP3: 1/27/2011 9:48:27 PM - System Checkpoint
RP4: 1/28/2011 10:29:02 PM - System Checkpoint
RP5: 1/29/2011 11:29:02 PM - System Checkpoint
RP6: 1/30/2011 11:55:57 PM - System Checkpoint
RP7: 2/1/2011 3:00:06 PM - System Checkpoint
RP8: 2/3/2011 11:37:12 AM - System Checkpoint
RP9: 2/6/2011 1:03:46 PM - System Checkpoint
RP10: 2/7/2011 2:00:48 PM - System Checkpoint
RP11: 2/8/2011 3:00:48 PM - System Checkpoint
RP12: 2/9/2011 4:00:48 PM - System Checkpoint
RP13: 2/10/2011 5:01:54 PM - System Checkpoint
RP14: 2/11/2011 6:00:48 PM - System Checkpoint
RP15: 2/12/2011 8:14:48 PM - System Checkpoint
RP16: 2/13/2011 9:00:48 PM - System Checkpoint
RP17: 2/14/2011 10:00:48 PM - System Checkpoint
RP18: 2/15/2011 11:00:48 PM - System Checkpoint
RP19: 2/17/2011 9:36:51 AM - System Checkpoint
RP20: 2/18/2011 10:00:50 AM - System Checkpoint
RP21: 2/19/2011 4:18:52 PM - System Checkpoint
RP22: 2/21/2011 2:59:50 AM - System Checkpoint
RP23: 2/23/2011 1:57:11 AM - System Checkpoint
RP24: 2/23/2011 3:00:14 AM - Software Distribution Service 3.0
RP25: 2/24/2011 3:22:27 AM - System Checkpoint
RP26: 2/25/2011 3:53:29 AM - System Checkpoint
RP27: 2/26/2011 4:53:29 AM - System Checkpoint
RP28: 2/27/2011 6:29:29 AM - System Checkpoint
RP29: 2/28/2011 6:53:29 AM - System Checkpoint
RP30: 3/1/2011 7:53:30 AM - System Checkpoint
RP31: 3/2/2011 7:53:35 AM - System Checkpoint
RP32: 3/3/2011 8:53:35 AM - System Checkpoint
RP33: 3/4/2011 8:09:52 PM - System Checkpoint
RP34: 3/5/2011 8:21:46 PM - System Checkpoint
RP35: 3/6/2011 8:52:23 PM - System Checkpoint
RP36: 3/7/2011 8:53:35 PM - System Checkpoint
RP37: 3/8/2011 9:53:35 PM - System Checkpoint
RP38: 3/10/2011 1:01:21 AM - System Checkpoint
RP39: 3/10/2011 3:00:14 AM - Software Distribution Service 3.0
RP40: 3/11/2011 3:53:35 AM - System Checkpoint
RP41: 3/12/2011 3:53:45 AM - System Checkpoint
RP42: 3/13/2011 5:53:45 AM - System Checkpoint
RP43: 3/14/2011 6:52:28 AM - System Checkpoint
RP44: 3/15/2011 6:53:45 AM - System Checkpoint
RP45: 3/16/2011 2:08:30 PM - Removed Apple Application Support
RP46: 3/16/2011 2:09:43 PM - Removed Apple Mobile Device Support
RP47: 3/17/2011 3:20:41 PM - System Checkpoint
RP48: 3/18/2011 4:06:12 PM - System Checkpoint
RP49: 3/19/2011 5:06:11 PM - System Checkpoint
RP50: 3/20/2011 6:06:11 PM - System Checkpoint
RP51: 3/21/2011 7:06:11 PM - System Checkpoint
RP52: 3/22/2011 8:06:11 PM - System Checkpoint
RP53: 3/23/2011 9:06:11 PM - System Checkpoint
RP54: 3/24/2011 10:06:11 PM - System Checkpoint
RP55: 3/25/2011 11:06:11 PM - System Checkpoint
RP56: 3/27/2011 12:04:16 AM - System Checkpoint
RP57: 3/27/2011 5:56:24 PM - Software Distribution Service 3.0
RP58: 3/29/2011 6:06:16 PM - System Checkpoint
RP59: 3/30/2011 9:56:56 PM - System Checkpoint
RP60: 3/31/2011 10:56:01 PM - System Checkpoint
RP61: 4/1/2011 11:56:01 PM - System Checkpoint
RP62: 4/3/2011 2:38:29 AM - System Checkpoint
RP63: 4/4/2011 2:56:01 AM - System Checkpoint
RP64: 4/6/2011 11:59:54 AM - System Checkpoint
RP65: 4/7/2011 12:52:28 PM - System Checkpoint
RP66: 4/8/2011 1:52:28 PM - System Checkpoint
RP67: 4/9/2011 6:32:57 PM - System Checkpoint
RP68: 4/10/2011 7:29:20 PM - System Checkpoint
RP69: 4/12/2011 12:49:14 PM - Installed PC Inspector File Recovery
RP70: 4/12/2011 4:57:55 PM - Avira AntiVir Personal - 4/12/2011 16:57
.
==== Installed Programs ======================
.
.
µTorrent
2007 Microsoft Office system
7-Zip 4.57
Activation Assistant for the 2007 Microsoft Office suites
Adobe Flash Player 10 Plugin
Adobe Reader 7.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Avira AntiVir Personal - Free Antivirus
Bonjour
Broadcom Management Programs
Broadcom TPM Driver Installer
Business Contact Manager for Outlook 2007
Convert AVI to MP4 1.3
High Definition Audio Driver Package - KB888111
HijackThis 1.99.1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB895246)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB923232)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB981793)
HP Backup and Recovery Manager
HP Help and Support
HpSdpAppCoreApp
iMPEG Converter 3.8
Intel(R) Graphics Media Accelerator Driver
InterVideo Register Manager
InterVideo WinDVD
IrfanView (remove only)
iTunes
IZArc 4.1.2
J2SE Runtime Environment 5.0 Update 6
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Office 2003 Web Components
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business Connectivity Components
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox 4.0 (x86 en-US)
MSXML 6 Service Pack 2 (KB973686)
PC Inspector File Recovery
PDF Complete
PowerISO
Programmer's Notepad 2
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Secret Crush Revealer
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981350)
Security Update for Windows XP (KB982381)
Skype Toolbars
Skype™ 5.0
SSH Secure Shell
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Office System 2007 Setup (KB929722)
Update for Windows XP (KB898461)
Update for Windows XP (KB911164)
Update for Windows XP (KB925720)
Update for Windows XP (KB931836)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VLC media player 1.0.1
Warcraft III
WebFldrs XP
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB815304
Windows XP Hotfix - KB885222
Windows XP Hotfix - KB886199
Windows XP Hotfix - KB889673
.
==== Event Viewer Messages From Past Week ========
.
4/8/2011 5:39:13 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer JACK-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{30AC4706-B8C4-4EC9-A. The master browser is stopping or an election is being forced.
4/13/2011 12:09:30 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
4/12/2011 9:48:48 AM, error: Service Control Manager [7034] - The SQL Server (MSSMLBIZ) service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 9:41:03 AM, error: Service Control Manager [7034] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 9:41:03 AM, error: Service Control Manager [7034] - The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 9:41:03 AM, error: Service Control Manager [7034] - The DNS Client service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 9:41:03 AM, error: Service Control Manager [7031] - The Remote Registry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
4/12/2011 9:41:03 AM, error: Service Control Manager [7031] - The Remote Procedure Call (RPC) service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
4/12/2011 9:41:03 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
4/12/2011 4:57:17 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. .
4/12/2011 4:57:17 PM, error: SideBySide [59] - Generate Activation Context failed for C:\DOCUME~1\me\LOCALS~1\Temp\RarSFX0\redist.dll. Reference error message: The operation completed successfully. .
4/12/2011 4:57:17 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
4/12/2011 4:53:59 PM, error: Service Control Manager [7023] - The Network Security service terminated with the following error: The specified module could not be found.
4/12/2011 4:53:58 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 897e9da0, parameter3 897e9f14, parameter4 805d1658.
4/12/2011 4:51:39 PM, error: Service Control Manager [7034] - The IviRegMgr service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 4:51:39 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 10:21:52 AM, error: Service Control Manager [7034] - The PC Angel service terminated unexpectedly. It has done this 1 time(s).
4/12/2011 10:21:52 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: eeCtrl
4/12/2011 10:21:52 AM, error: Service Control Manager [7000] - The Print Spooler service failed to start due to the following error: The system cannot find the file specified.
4/12/2011 1:40:36 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
.
==== End Of File ===========================