Hello,
I believe I have some sort of virus or malware infecting my computer. I've tried system restore a couple of times but to no avail.
My logs from the UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions are posted below
Thanks in advance for the help,
Jeremy
•Malwarebytes Anti-Malware log
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Database version: 5309
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
12/13/2010 8:57:37 PM
mbam-log-2010-12-13 (20-57-37).txt
Scan type: Quick scan
Objects scanned: 247226
Time elapsed: 12 minute(s), 36 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486} (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files\Shared\_lib.sig (Adware.Deepdive) -> Quarantined and deleted successfully.
c:\program files\Shared\lib.sig (Adware.Deepdive) -> Quarantined and deleted successfully.
c:\documents and settings\jeremy.jeremy-95d7c127\application data\chkntfs.dat (Malware.Trace) -> Quarantined and deleted successfully.
•GMER log
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-14 06:46:23
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 HDS728080PLA380 rev.PF2OA63A
Running: 3s3wl8ik.exe; Driver: C:\DOCUME~1\JEREMY~1.JER\LOCALS~1\Temp\kfedifoc.sys
---- System - GMER 1.0.15 ----
SSDT F8B0F22E ZwCreateKey
SSDT F8B0F224 ZwCreateThread
SSDT F8B0F233 ZwDeleteKey
SSDT F8B0F23D ZwDeleteValueKey
SSDT F8B0F242 ZwLoadKey
SSDT F8B0F210 ZwOpenProcess
SSDT F8B0F215 ZwOpenThread
SSDT F8B0F24C ZwReplaceKey
SSDT F8B0F247 ZwRestoreKey
SSDT F8B0F238 ZwSetValueKey
---- Kernel code sections - GMER 1.0.15 ----
? bkasfh.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
•DDS logs: both DDS.txt and Attach.txt
DDS (Ver_10-12-12.02) - NTFSx86
Run by Jeremy at 19:41:38.93 on Tue 12/14/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.164 [GMT -6:00]
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Jeremy.JEREMY-95D7C127\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.cnn.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: TTB000000 Class: {62960d20-6d0d-1ab4-4bf1-95b0b5b8783a} - c:\windows\COUPON~1.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: CouponBar: {5bed3930-2e9e-76d8-bacc-80df2188d455} - c:\windows\CouponBarIE.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus NX400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiega.exe /fu "c:\windows\temp\E_SA0.tmp" /EF "HKCU"
uRun: [Google Update] "c:\documents and settings\jeremy.jeremy-95d7c127\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Vjunejemilape] rundll32.exe "c:\windows\werdenf.dll",Startup
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [EverioService] "c:\program files\cyberlink\pcm4everio\EverioService.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/F/D/9/FD9E437D-5BC8-4264-A093-DFA2C39D197E/LegitCheckControl.cab
DPF: {28B66320-9687-4B13-8757-36F901887AB5} - hxxp://www.seehere.com/ips-opdata/layout/fujius02/objects/jordan-canvasx.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} - hxxp://www.seehere.com/ips-opdata/layout/fujius02/objects/jordan-canvasx.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
Filter: text/html - {8f5ee846-7264-4d63-a054-a6cfaa19f7c5} -
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-12-6 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-12-6 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-12-6 267944]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-12-6 61960]
=============== Created Last 30 ================
2010-12-14 02:39:44 -------- d-----w- c:\docume~1\jeremy~1.jer\applic~1\Malwarebytes
2010-12-14 02:39:36 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-14 02:39:34 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2010-12-14 02:39:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-14 02:39:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-07 03:07:45 -------- d-----w- c:\windows\system32\NtmsData
2010-12-07 03:05:45 -------- d-----w- c:\docume~1\jeremy~1.jer\applic~1\Avira
2010-12-07 03:02:53 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-07 03:02:48 -------- d-----w- c:\program files\Avira
2010-12-07 03:02:48 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Avira
2010-12-07 02:34:44 -------- d-----w- c:\docume~1\jeremy~1.jer\applic~1\SWF.max
2010-12-07 02:22:15 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-07 01:42:35 -------- d-----w- c:\docume~1\jeremy~1.jer\locals~1\applic~1\Temp
2010-12-07 01:41:50 -------- d-----w- c:\docume~1\jeremy~1.jer\locals~1\applic~1\Deployment
2010-12-01 02:25:26 1024 ----a-w- c:\docume~1\alluse~1.win\applic~1\1doc2pdf.dll
2010-12-01 02:21:58 116224 ----a-w- c:\windows\system32\pdfmonnt.dll
2010-12-01 02:21:57 -------- d-----w- c:\program files\8848Soft
2010-11-16 01:51:19 1288192 -c----w- c:\windows\system32\dllcache\ole32.dll
2010-11-16 01:39:43 -------- d-----w- c:\windows\system32\wbem\repository\FS
2010-11-16 01:39:43 -------- d-----w- c:\windows\system32\wbem\Repository
==================== Find3M ====================
2010-09-18 17:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
============= FINISH: 19:42:53.23 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 7/8/2008 9:28:31 PM
System Uptime: 12/13/2010 8:59:12 PM (23 hours ago)
Motherboard: Dell Inc. | | 0JC474
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | Microprocessor | 2793/800mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 51 GiB total, 13.953 GiB free.
D: is FIXED (NTFS) - 19 GiB total, 1.116 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is FIXED (FAT32) - 931 GiB total, 879.966 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Video Controller (VGA Compatible)
Device ID: PCI\VEN_8086&DEV_2582&SUBSYS_01C41028&REV_04\3&172E68DD&0&10
Manufacturer:
Name: Video Controller (VGA Compatible)
PNP Device ID: PCI\VEN_8086&DEV_2582&SUBSYS_01C41028&REV_04\3&172E68DD&0&10
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_14F1&DEV_2F20&SUBSYS_200F14F1&REV_00\4&10BD256C&0&10F0
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_14F1&DEV_2F20&SUBSYS_200F14F1&REV_00\4&10BD256C&0&10F0
Service:
==== System Restore Points ===================
RP1036: 10/9/2010 9:17:56 PM - System Checkpoint
RP1037: 10/9/2010 11:17:47 PM - Software Distribution Service 3.0
RP1038: 10/10/2010 9:29:06 PM - Software Distribution Service 3.0
RP1039: 10/11/2010 9:44:48 PM - Software Distribution Service 3.0
RP1040: 10/12/2010 9:53:37 PM - System Checkpoint
RP1041: 10/12/2010 10:05:30 PM - Software Distribution Service 3.0
RP1042: 10/13/2010 9:57:46 PM - Software Distribution Service 3.0
RP1043: 10/14/2010 10:05:21 PM - Software Distribution Service 3.0
RP1044: 10/15/2010 4:01:32 PM - Software Distribution Service 3.0
RP1045: 10/17/2010 2:47:01 PM - System Checkpoint
RP1046: 10/17/2010 9:26:11 PM - Software Distribution Service 3.0
RP1047: 10/18/2010 9:34:06 PM - Software Distribution Service 3.0
RP1048: 10/19/2010 9:53:10 PM - Software Distribution Service 3.0
RP1049: 10/20/2010 9:38:52 PM - Software Distribution Service 3.0
RP1050: 10/21/2010 9:45:59 PM - Software Distribution Service 3.0
RP1051: 10/22/2010 8:51:45 PM - Software Distribution Service 3.0
RP1052: 10/24/2010 2:51:32 PM - System Checkpoint
RP1053: 10/24/2010 10:05:57 PM - Software Distribution Service 3.0
RP1054: 10/25/2010 10:06:16 PM - Software Distribution Service 3.0
RP1055: 10/26/2010 9:31:00 PM - Software Distribution Service 3.0
RP1056: 10/27/2010 9:11:22 PM - Software Distribution Service 3.0
RP1057: 10/28/2010 9:14:49 PM - System Checkpoint
RP1058: 10/29/2010 3:00:18 AM - Software Distribution Service 3.0
RP1059: 10/29/2010 10:52:50 PM - Software Distribution Service 3.0
RP1060: 10/30/2010 9:37:49 PM - Software Distribution Service 3.0
RP1061: 10/31/2010 8:44:31 PM - Software Distribution Service 3.0
RP1062: 11/1/2010 9:20:00 PM - System Checkpoint
RP1063: 11/1/2010 9:58:03 PM - Software Distribution Service 3.0
RP1064: 11/2/2010 10:20:23 PM - Software Distribution Service 3.0
RP1065: 11/3/2010 9:57:58 PM - Software Distribution Service 3.0
RP1066: 11/4/2010 9:51:48 PM - Software Distribution Service 3.0
RP1067: 11/5/2010 8:12:17 PM - Restore Operation
RP1068: 11/5/2010 8:23:49 PM - Software Distribution Service 3.0
RP1069: 11/5/2010 9:47:30 PM - Software Distribution Service 3.0
RP1070: 11/6/2010 9:37:54 PM - System Checkpoint
RP1071: 11/6/2010 9:43:22 PM - Software Distribution Service 3.0
RP1072: 11/7/2010 10:04:33 PM - Software Distribution Service 3.0
RP1073: 11/8/2010 10:07:24 PM - Software Distribution Service 3.0
RP1074: 11/9/2010 10:07:40 PM - Software Distribution Service 3.0
RP1075: 11/10/2010 9:57:49 PM - Software Distribution Service 3.0
RP1076: 11/14/2010 7:55:35 PM - System Checkpoint
RP1077: 11/14/2010 9:17:15 PM - Software Distribution Service 3.0
RP1078: 11/15/2010 7:27:56 PM - Restore Operation
RP1079: 11/15/2010 7:42:29 PM - Software Distribution Service 3.0
RP1080: 11/15/2010 8:14:06 PM - Installed Connect Service
RP1081: 11/16/2010 3:00:33 AM - Software Distribution Service 3.0
RP1082: 11/16/2010 10:09:52 PM - Software Distribution Service 3.0
RP1083: 11/17/2010 9:57:50 PM - Software Distribution Service 3.0
RP1084: 11/18/2010 10:10:58 PM - Software Distribution Service 3.0
RP1085: 11/19/2010 7:26:27 PM - Software Distribution Service 3.0
RP1086: 11/21/2010 4:41:55 PM - System Checkpoint
RP1087: 11/21/2010 9:34:44 PM - Software Distribution Service 3.0
RP1088: 11/22/2010 10:05:43 PM - Software Distribution Service 3.0
RP1089: 11/23/2010 10:14:41 PM - Software Distribution Service 3.0
RP1090: 11/24/2010 5:49:18 PM - Software Distribution Service 3.0
RP1091: 11/29/2010 11:07:50 AM - System Checkpoint
RP1092: 11/29/2010 9:12:08 PM - Software Distribution Service 3.0
RP1093: 11/30/2010 8:22:15 PM - Printer Driver PDFConverter Installed
RP1094: 11/30/2010 8:22:25 PM - Printer Driver PDFConverter Installed
RP1095: 11/30/2010 8:22:32 PM - Printer Driver PDFConverter Installed
RP1096: 11/30/2010 10:00:57 PM - Software Distribution Service 3.0
RP1097: 12/1/2010 10:33:16 PM - Software Distribution Service 3.0
RP1098: 12/2/2010 10:00:49 PM - Software Distribution Service 3.0
RP1099: 12/3/2010 10:07:55 PM - Software Distribution Service 3.0
RP1100: 12/4/2010 9:38:32 PM - Software Distribution Service 3.0
RP1101: 12/5/2010 8:58:50 PM - Software Distribution Service 3.0
RP1102: 12/6/2010 8:21:12 PM - Installed Java(TM) 6 Update 22
RP1103: 12/6/2010 8:39:12 PM - Removed Mixer
RP1104: 12/6/2010 8:39:23 PM - Configured Engine Installer
RP1105: 12/7/2010 3:00:27 AM - Software Distribution Service 3.0
RP1106: 12/7/2010 10:39:17 PM - Software Distribution Service 3.0
RP1107: 12/8/2010 9:36:46 PM - Software Distribution Service 3.0
RP1108: 12/9/2010 9:58:33 PM - Software Distribution Service 3.0
RP1109: 12/10/2010 9:07:33 PM - Software Distribution Service 3.0
RP1110: 12/11/2010 9:10:43 PM - System Checkpoint
RP1111: 12/11/2010 10:06:35 PM - Software Distribution Service 3.0
RP1112: 12/12/2010 9:45:40 PM - Software Distribution Service 3.0
RP1113: 12/13/2010 10:01:19 PM - System Checkpoint
RP1114: 12/14/2010 3:00:16 AM - Software Distribution Service 3.0
==== Installed Programs ======================
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player Plugin
Adobe Media Player
Adobe Reader 9.4.1
Adobe Shockwave Player 11
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Print Creations
ArcSoft Print Creations - Greeting Card
ATT-AACE
Avira AntiVir Personal - Free Antivirus
Bonjour
Choice Guard
Citrix XenApp Web Plugin
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
CouponBar
Digital Photo Navigator 1.5
EPSON NX400 User's Guide
EPSON Scan
EPSON Stylus NX400 Series Printer Uninstall
ESPNMotion
GemMaster Mystic
Google Chrome
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Image Resizer Powertoy for Windows XP
InstallMgr
Intel(R) PRO Network Connections Drivers
iTunes
Java Auto Updater
Java(TM) 6 Update 22
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.0 Hotfix (KB979904)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Default Manager
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Basic Edition 2003
Microsoft Office Outlook Connector
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Move Media Player
MSN Toolbar
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Otto
Picasa 2
PowerCinema NE for Everio
PowerDirector Express
PowerDVD
PowerProducer
QuickTime
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Segoe UI
SigmaTel Audio
Sonic Encoders
Sound Blaster Audigy ADVANCED MB Demo
Stream Torrent 1.0
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB973874)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Imaging Component
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Communications Platform
Windows Live Essentials
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
Yahoo! Install Manager
==== Event Viewer Messages From Past Week ========
12/9/2010 9:59:18 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1.
12/9/2010 9:27:56 AM, error: Dhcp [1002] - The IP address lease 68.255.108.183 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/9/2010 4:59:50 PM, error: Dhcp [1002] - The IP address lease 76.217.61.214 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/9/2010 1:59:01 PM, error: Dhcp [1002] - The IP address lease 69.209.233.186 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/8/2010 8:45:48 AM, error: Dhcp [1002] - The IP address lease 69.209.202.11 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/8/2010 4:52:46 PM, error: Dhcp [1002] - The IP address lease 69.209.230.58 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/7/2010 6:55:07 PM, error: Dhcp [1002] - The IP address lease 76.237.198.130 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/14/2010 9:43:16 AM, error: Dhcp [1002] - The IP address lease 76.217.62.174 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/14/2010 4:13:29 PM, error: Dhcp [1002] - The IP address lease 75.3.148.166 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/13/2010 9:08:42 PM, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period.
12/13/2010 9:00:59 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
12/13/2010 8:50:03 AM, error: Dhcp [1002] - The IP address lease 69.209.206.110 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/13/2010 8:18:54 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7034] - The ArcSoft Connect Daemon service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/13/2010 6:20:07 PM, error: Dhcp [1002] - The IP address lease 69.209.238.111 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/13/2010 2:55:05 PM, error: Dhcp [1002] - The IP address lease 75.3.153.150 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/12/2010 7:21:11 PM, error: Dhcp [1002] - The IP address lease 76.237.192.235 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/11/2010 10:27:00 AM, error: Dhcp [1002] - The IP address lease 76.237.200.43 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/10/2010 8:22:54 AM, error: Dhcp [1002] - The IP address lease 192.168.1.64 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/10/2010 3:57:03 PM, error: Dhcp [1002] - The IP address lease 76.237.193.173 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/10/2010 12:21:44 PM, error: Dhcp [1002] - The IP address lease 69.209.236.154 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
==== End Of File ===========================
I believe I have some sort of virus or malware infecting my computer. I've tried system restore a couple of times but to no avail.
My logs from the UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions are posted below
Thanks in advance for the help,
Jeremy
•Malwarebytes Anti-Malware log
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Database version: 5309
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
12/13/2010 8:57:37 PM
mbam-log-2010-12-13 (20-57-37).txt
Scan type: Quick scan
Objects scanned: 247226
Time elapsed: 12 minute(s), 36 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486} (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files\Shared\_lib.sig (Adware.Deepdive) -> Quarantined and deleted successfully.
c:\program files\Shared\lib.sig (Adware.Deepdive) -> Quarantined and deleted successfully.
c:\documents and settings\jeremy.jeremy-95d7c127\application data\chkntfs.dat (Malware.Trace) -> Quarantined and deleted successfully.
•GMER log
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-14 06:46:23
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 HDS728080PLA380 rev.PF2OA63A
Running: 3s3wl8ik.exe; Driver: C:\DOCUME~1\JEREMY~1.JER\LOCALS~1\Temp\kfedifoc.sys
---- System - GMER 1.0.15 ----
SSDT F8B0F22E ZwCreateKey
SSDT F8B0F224 ZwCreateThread
SSDT F8B0F233 ZwDeleteKey
SSDT F8B0F23D ZwDeleteValueKey
SSDT F8B0F242 ZwLoadKey
SSDT F8B0F210 ZwOpenProcess
SSDT F8B0F215 ZwOpenThread
SSDT F8B0F24C ZwReplaceKey
SSDT F8B0F247 ZwRestoreKey
SSDT F8B0F238 ZwSetValueKey
---- Kernel code sections - GMER 1.0.15 ----
? bkasfh.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3500] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[3552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
•DDS logs: both DDS.txt and Attach.txt
DDS (Ver_10-12-12.02) - NTFSx86
Run by Jeremy at 19:41:38.93 on Tue 12/14/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.164 [GMT -6:00]
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Jeremy.JEREMY-95D7C127\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.cnn.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: TTB000000 Class: {62960d20-6d0d-1ab4-4bf1-95b0b5b8783a} - c:\windows\COUPON~1.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: CouponBar: {5bed3930-2e9e-76d8-bacc-80df2188d455} - c:\windows\CouponBarIE.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus NX400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiega.exe /fu "c:\windows\temp\E_SA0.tmp" /EF "HKCU"
uRun: [Google Update] "c:\documents and settings\jeremy.jeremy-95d7c127\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Vjunejemilape] rundll32.exe "c:\windows\werdenf.dll",Startup
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [EverioService] "c:\program files\cyberlink\pcm4everio\EverioService.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/F/D/9/FD9E437D-5BC8-4264-A093-DFA2C39D197E/LegitCheckControl.cab
DPF: {28B66320-9687-4B13-8757-36F901887AB5} - hxxp://www.seehere.com/ips-opdata/layout/fujius02/objects/jordan-canvasx.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} - hxxp://www.seehere.com/ips-opdata/layout/fujius02/objects/jordan-canvasx.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
Filter: text/html - {8f5ee846-7264-4d63-a054-a6cfaa19f7c5} -
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-12-6 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-12-6 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-12-6 267944]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-12-6 61960]
=============== Created Last 30 ================
2010-12-14 02:39:44 -------- d-----w- c:\docume~1\jeremy~1.jer\applic~1\Malwarebytes
2010-12-14 02:39:36 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-14 02:39:34 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2010-12-14 02:39:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-14 02:39:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-07 03:07:45 -------- d-----w- c:\windows\system32\NtmsData
2010-12-07 03:05:45 -------- d-----w- c:\docume~1\jeremy~1.jer\applic~1\Avira
2010-12-07 03:02:53 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-07 03:02:48 -------- d-----w- c:\program files\Avira
2010-12-07 03:02:48 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Avira
2010-12-07 02:34:44 -------- d-----w- c:\docume~1\jeremy~1.jer\applic~1\SWF.max
2010-12-07 02:22:15 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-07 01:42:35 -------- d-----w- c:\docume~1\jeremy~1.jer\locals~1\applic~1\Temp
2010-12-07 01:41:50 -------- d-----w- c:\docume~1\jeremy~1.jer\locals~1\applic~1\Deployment
2010-12-01 02:25:26 1024 ----a-w- c:\docume~1\alluse~1.win\applic~1\1doc2pdf.dll
2010-12-01 02:21:58 116224 ----a-w- c:\windows\system32\pdfmonnt.dll
2010-12-01 02:21:57 -------- d-----w- c:\program files\8848Soft
2010-11-16 01:51:19 1288192 -c----w- c:\windows\system32\dllcache\ole32.dll
2010-11-16 01:39:43 -------- d-----w- c:\windows\system32\wbem\repository\FS
2010-11-16 01:39:43 -------- d-----w- c:\windows\system32\wbem\Repository
==================== Find3M ====================
2010-09-18 17:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
============= FINISH: 19:42:53.23 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 7/8/2008 9:28:31 PM
System Uptime: 12/13/2010 8:59:12 PM (23 hours ago)
Motherboard: Dell Inc. | | 0JC474
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | Microprocessor | 2793/800mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 51 GiB total, 13.953 GiB free.
D: is FIXED (NTFS) - 19 GiB total, 1.116 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is FIXED (FAT32) - 931 GiB total, 879.966 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Video Controller (VGA Compatible)
Device ID: PCI\VEN_8086&DEV_2582&SUBSYS_01C41028&REV_04\3&172E68DD&0&10
Manufacturer:
Name: Video Controller (VGA Compatible)
PNP Device ID: PCI\VEN_8086&DEV_2582&SUBSYS_01C41028&REV_04\3&172E68DD&0&10
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_14F1&DEV_2F20&SUBSYS_200F14F1&REV_00\4&10BD256C&0&10F0
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_14F1&DEV_2F20&SUBSYS_200F14F1&REV_00\4&10BD256C&0&10F0
Service:
==== System Restore Points ===================
RP1036: 10/9/2010 9:17:56 PM - System Checkpoint
RP1037: 10/9/2010 11:17:47 PM - Software Distribution Service 3.0
RP1038: 10/10/2010 9:29:06 PM - Software Distribution Service 3.0
RP1039: 10/11/2010 9:44:48 PM - Software Distribution Service 3.0
RP1040: 10/12/2010 9:53:37 PM - System Checkpoint
RP1041: 10/12/2010 10:05:30 PM - Software Distribution Service 3.0
RP1042: 10/13/2010 9:57:46 PM - Software Distribution Service 3.0
RP1043: 10/14/2010 10:05:21 PM - Software Distribution Service 3.0
RP1044: 10/15/2010 4:01:32 PM - Software Distribution Service 3.0
RP1045: 10/17/2010 2:47:01 PM - System Checkpoint
RP1046: 10/17/2010 9:26:11 PM - Software Distribution Service 3.0
RP1047: 10/18/2010 9:34:06 PM - Software Distribution Service 3.0
RP1048: 10/19/2010 9:53:10 PM - Software Distribution Service 3.0
RP1049: 10/20/2010 9:38:52 PM - Software Distribution Service 3.0
RP1050: 10/21/2010 9:45:59 PM - Software Distribution Service 3.0
RP1051: 10/22/2010 8:51:45 PM - Software Distribution Service 3.0
RP1052: 10/24/2010 2:51:32 PM - System Checkpoint
RP1053: 10/24/2010 10:05:57 PM - Software Distribution Service 3.0
RP1054: 10/25/2010 10:06:16 PM - Software Distribution Service 3.0
RP1055: 10/26/2010 9:31:00 PM - Software Distribution Service 3.0
RP1056: 10/27/2010 9:11:22 PM - Software Distribution Service 3.0
RP1057: 10/28/2010 9:14:49 PM - System Checkpoint
RP1058: 10/29/2010 3:00:18 AM - Software Distribution Service 3.0
RP1059: 10/29/2010 10:52:50 PM - Software Distribution Service 3.0
RP1060: 10/30/2010 9:37:49 PM - Software Distribution Service 3.0
RP1061: 10/31/2010 8:44:31 PM - Software Distribution Service 3.0
RP1062: 11/1/2010 9:20:00 PM - System Checkpoint
RP1063: 11/1/2010 9:58:03 PM - Software Distribution Service 3.0
RP1064: 11/2/2010 10:20:23 PM - Software Distribution Service 3.0
RP1065: 11/3/2010 9:57:58 PM - Software Distribution Service 3.0
RP1066: 11/4/2010 9:51:48 PM - Software Distribution Service 3.0
RP1067: 11/5/2010 8:12:17 PM - Restore Operation
RP1068: 11/5/2010 8:23:49 PM - Software Distribution Service 3.0
RP1069: 11/5/2010 9:47:30 PM - Software Distribution Service 3.0
RP1070: 11/6/2010 9:37:54 PM - System Checkpoint
RP1071: 11/6/2010 9:43:22 PM - Software Distribution Service 3.0
RP1072: 11/7/2010 10:04:33 PM - Software Distribution Service 3.0
RP1073: 11/8/2010 10:07:24 PM - Software Distribution Service 3.0
RP1074: 11/9/2010 10:07:40 PM - Software Distribution Service 3.0
RP1075: 11/10/2010 9:57:49 PM - Software Distribution Service 3.0
RP1076: 11/14/2010 7:55:35 PM - System Checkpoint
RP1077: 11/14/2010 9:17:15 PM - Software Distribution Service 3.0
RP1078: 11/15/2010 7:27:56 PM - Restore Operation
RP1079: 11/15/2010 7:42:29 PM - Software Distribution Service 3.0
RP1080: 11/15/2010 8:14:06 PM - Installed Connect Service
RP1081: 11/16/2010 3:00:33 AM - Software Distribution Service 3.0
RP1082: 11/16/2010 10:09:52 PM - Software Distribution Service 3.0
RP1083: 11/17/2010 9:57:50 PM - Software Distribution Service 3.0
RP1084: 11/18/2010 10:10:58 PM - Software Distribution Service 3.0
RP1085: 11/19/2010 7:26:27 PM - Software Distribution Service 3.0
RP1086: 11/21/2010 4:41:55 PM - System Checkpoint
RP1087: 11/21/2010 9:34:44 PM - Software Distribution Service 3.0
RP1088: 11/22/2010 10:05:43 PM - Software Distribution Service 3.0
RP1089: 11/23/2010 10:14:41 PM - Software Distribution Service 3.0
RP1090: 11/24/2010 5:49:18 PM - Software Distribution Service 3.0
RP1091: 11/29/2010 11:07:50 AM - System Checkpoint
RP1092: 11/29/2010 9:12:08 PM - Software Distribution Service 3.0
RP1093: 11/30/2010 8:22:15 PM - Printer Driver PDFConverter Installed
RP1094: 11/30/2010 8:22:25 PM - Printer Driver PDFConverter Installed
RP1095: 11/30/2010 8:22:32 PM - Printer Driver PDFConverter Installed
RP1096: 11/30/2010 10:00:57 PM - Software Distribution Service 3.0
RP1097: 12/1/2010 10:33:16 PM - Software Distribution Service 3.0
RP1098: 12/2/2010 10:00:49 PM - Software Distribution Service 3.0
RP1099: 12/3/2010 10:07:55 PM - Software Distribution Service 3.0
RP1100: 12/4/2010 9:38:32 PM - Software Distribution Service 3.0
RP1101: 12/5/2010 8:58:50 PM - Software Distribution Service 3.0
RP1102: 12/6/2010 8:21:12 PM - Installed Java(TM) 6 Update 22
RP1103: 12/6/2010 8:39:12 PM - Removed Mixer
RP1104: 12/6/2010 8:39:23 PM - Configured Engine Installer
RP1105: 12/7/2010 3:00:27 AM - Software Distribution Service 3.0
RP1106: 12/7/2010 10:39:17 PM - Software Distribution Service 3.0
RP1107: 12/8/2010 9:36:46 PM - Software Distribution Service 3.0
RP1108: 12/9/2010 9:58:33 PM - Software Distribution Service 3.0
RP1109: 12/10/2010 9:07:33 PM - Software Distribution Service 3.0
RP1110: 12/11/2010 9:10:43 PM - System Checkpoint
RP1111: 12/11/2010 10:06:35 PM - Software Distribution Service 3.0
RP1112: 12/12/2010 9:45:40 PM - Software Distribution Service 3.0
RP1113: 12/13/2010 10:01:19 PM - System Checkpoint
RP1114: 12/14/2010 3:00:16 AM - Software Distribution Service 3.0
==== Installed Programs ======================
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player Plugin
Adobe Media Player
Adobe Reader 9.4.1
Adobe Shockwave Player 11
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Print Creations
ArcSoft Print Creations - Greeting Card
ATT-AACE
Avira AntiVir Personal - Free Antivirus
Bonjour
Choice Guard
Citrix XenApp Web Plugin
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
CouponBar
Digital Photo Navigator 1.5
EPSON NX400 User's Guide
EPSON Scan
EPSON Stylus NX400 Series Printer Uninstall
ESPNMotion
GemMaster Mystic
Google Chrome
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Image Resizer Powertoy for Windows XP
InstallMgr
Intel(R) PRO Network Connections Drivers
iTunes
Java Auto Updater
Java(TM) 6 Update 22
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.0 Hotfix (KB979904)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Default Manager
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Basic Edition 2003
Microsoft Office Outlook Connector
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Move Media Player
MSN Toolbar
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Otto
Picasa 2
PowerCinema NE for Everio
PowerDirector Express
PowerDVD
PowerProducer
QuickTime
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Segoe UI
SigmaTel Audio
Sonic Encoders
Sound Blaster Audigy ADVANCED MB Demo
Stream Torrent 1.0
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB973874)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Imaging Component
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Communications Platform
Windows Live Essentials
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
Yahoo! Install Manager
==== Event Viewer Messages From Past Week ========
12/9/2010 9:59:18 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1.
12/9/2010 9:27:56 AM, error: Dhcp [1002] - The IP address lease 68.255.108.183 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/9/2010 4:59:50 PM, error: Dhcp [1002] - The IP address lease 76.217.61.214 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/9/2010 1:59:01 PM, error: Dhcp [1002] - The IP address lease 69.209.233.186 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/8/2010 8:45:48 AM, error: Dhcp [1002] - The IP address lease 69.209.202.11 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/8/2010 4:52:46 PM, error: Dhcp [1002] - The IP address lease 69.209.230.58 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/7/2010 6:55:07 PM, error: Dhcp [1002] - The IP address lease 76.237.198.130 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/14/2010 9:43:16 AM, error: Dhcp [1002] - The IP address lease 76.217.62.174 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/14/2010 4:13:29 PM, error: Dhcp [1002] - The IP address lease 75.3.148.166 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/13/2010 9:08:42 PM, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period.
12/13/2010 9:00:59 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
12/13/2010 8:50:03 AM, error: Dhcp [1002] - The IP address lease 69.209.206.110 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/13/2010 8:18:54 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7034] - The ArcSoft Connect Daemon service terminated unexpectedly. It has done this 1 time(s).
12/13/2010 8:18:52 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/13/2010 6:20:07 PM, error: Dhcp [1002] - The IP address lease 69.209.238.111 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/13/2010 2:55:05 PM, error: Dhcp [1002] - The IP address lease 75.3.153.150 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/12/2010 7:21:11 PM, error: Dhcp [1002] - The IP address lease 76.237.192.235 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/11/2010 10:27:00 AM, error: Dhcp [1002] - The IP address lease 76.237.200.43 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/10/2010 8:22:54 AM, error: Dhcp [1002] - The IP address lease 192.168.1.64 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/10/2010 3:57:03 PM, error: Dhcp [1002] - The IP address lease 76.237.193.173 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/10/2010 12:21:44 PM, error: Dhcp [1002] - The IP address lease 69.209.236.154 for the Network Card with network address 0016765BE669 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
==== End Of File ===========================