Hi. I have tried to follow some of the suggestions on similar posts (of people with similar problems to mine), but without help. I was unable to run HIJackthis nor Malwarebyte. I was able to run RSIT, and DDs. Here are the logs below:
Logfile of random's system information tool 1.06 (written by random/random) Run by Fadi at 2009-09-04 23:51:27 Microsoft Windows XP Professional Service Pack 3 System drive C: has 22 GB (31%) free of 70 GB Total RAM: 1014 MB (57% free)
info.txt logfile of random's system information tool 1.06 2009-09-04 23:52:23
======Uninstall list======
-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 -->C:\Program Files\InstallShield Installation Information\{02FB2C63-5763-4CDD-99E6-566C57189742}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{1CA432A0-DBC7-4C5D-A6B6-5DF0E2E44BB0}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{28B97CAB-828F-49D8-A30A-675476F9BA92}\setup.exe -runfromtemp -l0x0009/cont -removeonly -->C:\Program Files\InstallShield Installation Information\{3475FBEC-E0F5-4A3F-823E-6C1DEA10F1AF}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{3881DD58-780F-4FCF-8A16-6E6800C2FEE0}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{4067A0B5-FB0B-479C-8735-6F48F8E21872}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{4E7DC12A-3597-4A94-9429-F6C6987361B1}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{6813C983-427E-4511-8456-E98FCAA1A125}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{7DADB304-AF20-48C3-A780-4B4133A08817}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{9225EABF-4457-403B-A82B-91614C9DDDF7}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{ACE66099-E18E-4037-83C8-9D182E5B9FA8}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{B34B6E67-FCDD-4E03-8742-B5701427FAFB}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{C9EFF51A-C925-4F1A-9DEB-DB5F970DE983}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{E8581ECC-8BEA-4E91-AB5E-587654EBB2A7}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{E9CCEA28-3608-4078-8A07-997646E1A357}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\Program Files\InstallShield Installation Information\{FD7FF74D-0AB5-48D6-929C-7E93A5162521}\setup.exe -runfromtemp -l0x0009 -removeonly -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205} -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6} -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382} -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629} -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf 7-Zip 4.57-->"C:\Program Files\7-Zip\Uninstall.exe" Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 7.0.5 Language Support-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-7050000000A7} Adobe Reader 7.0.9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002} Adobe Reader Chinese Traditional Fonts-->MsiExec.exe /I{AC76BA86-7AD7-2448-0000-705000000001} Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log ARTEuro-->MsiExec.exe /I{1D3C662A-F6C6-4767-A788-7AA43A9A1317} Azureus-->C:\Program Files\Azureus\Uninstall.exe Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6} Broadcom Management Programs-->MsiExec.exe /I{26E1BFB0-E87E-4696-9F89-B467F01F81E5} ccCommon-->MsiExec.exe /I{1248C09A-BD6B-47F5-BF3F-CD2B700D9FCB} CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe" Commandos Strike Force-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{544DB849-AB59-4C12-A333-2F214E24870F}\Setup.exe" -l0x9 -removeonly Conexant HDA D110 MDC V.92 Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3\HXFSETUP.EXE -U -Idel1028p.inf Critical Update for Windows Media Player 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe" Defraggler (remove only)-->"C:\Program Files\Defraggler\uninst.exe" Dell Driver Reset Tool-->MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76} Dell Support 5.0.0 (630)-->rundll32 C:\PROGRA~1\DELLSU~1\AUInst.dll,ExUninstall Digital Line Detect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel GemMaster Mystic-->"C:\Program Files\GemMaster\uninstallgemmaster.exe" High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT="" Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT="" Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe" Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe" Hotfix for Windows Media Player 10 (KB903157)-->"C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe" Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe" Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe" Hotfix for Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe" Huawei SmartAX MT810-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}\Setup.exe" -l0x9 -L0x9 Intel(R) Graphics Media Accelerator Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_27A6 PCI\VEN_8086&DEV_27A2 Intel(R) PROSet/Wireless Software-->C:\WINDOWS\Installer\iProInst.exe Internal Network Card Power Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F528948-0E80-4C96-B455-DE4167CB1DF7}\setup.exe" -l0x9 UNINSTALL APPDRVNT4 iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371} Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030} Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060} Learn2 Player (Uninstall Only)-->C:\Program Files\Learn2.com\StRunner\stuninst.exe Magic ISO Maker v5.4 (build 0251)-->C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG MATLAB 6.5-->C:\MATLAB6p5\uninstall\uninstall.exe C:\MATLAB6p5 mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779} mDrWiFi-->MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49} mHlpDell-->MsiExec.exe /I{49D687E5-6784-431B-A0A2-2F23B8CC5A1B} Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp" Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7} Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} Microsoft Base Smart Card Cryptographic Service Provider Package-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe" Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe" Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe" Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe" Microsoft Office Professional Edition 2003-->MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9} Microsoft User-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe" Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} mIWA-->MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F} mLogView-->MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7} mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5} Modem Helper-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5} mPfWiz-->MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9} mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83} MSN Messenger 7.5-->MsiExec.exe /I{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5} MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP MSRedist-->MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69} mSSO-->MsiExec.exe /I{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB} MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27} MSXML 4.0 SP2 (KB925672)-->MsiExec.exe /I{A9CF9052-F4A0-475D-A00F-A8388C62DD63} MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F} MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E} mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4} mWMI-->MsiExec.exe /I{63DB9CCD-2B56-4217-9A3D-507AC78320CA} mXML-->MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401} mZConfig-->MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023} NetWaiting-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel Nokia Connectivity Cable Driver-->MsiExec.exe /X{B3164E9E-BE08-4F3B-94BC-C6D09C0205E1} Nokia PC Suite-->MsiExec.exe /I{D5577624-0626-4C4B-87AA-D966DA1739D6} Norton Internet Security 2006-->"C:\Program Files\Common Files\Symantec Shared\SymSetup\Temp{A93C9E60-29B6-49da-BA21-F70AC6AADE20}.exe" /X Otto-->"C:\Program Files\EnglishOtto\uninstallotto.exe" PC Connectivity Solution-->MsiExec.exe /I{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C} PowerDVD 5.7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall QuickSet-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C5074CC4-0E26-4716-A307-960272A90040}\setup.exe" -l0x9 APPDRVNT4 QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4} RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 Recuva (remove only)-->"C:\Program Files\Recuva\uninst.exe" Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe" Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe" Security Update for Windows Media Player 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe" Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe" Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe" Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe" Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe" Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe" Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe" Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe" Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe" Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe" Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe" Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe" Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe" Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe" Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe" Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe" Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe" Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe" Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe" Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe" Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe" Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe" Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe" Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe" Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe" Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe" Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe" Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe" Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe" Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe" Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe" Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe" Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe" Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe" Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe" Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe" Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe" Security Update for Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe" Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe" Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe" Security Update for Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe" Security Update for Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe" Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe" Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe" Security Update for Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe" Sonic DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6} Sonic Encoders-->MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011} Sonic MyDVD LE-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29} Sonic RecordNow Audio-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382} Sonic RecordNow Copy-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629} Sonic RecordNow Data-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205} Sony Picture Utility-->C:\Program Files\InstallShield Installation Information\{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe -runfromtemp -l0x0009 /removeonly uninstall -removeonly Sony USB Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}\setup.exe" -l0x9 UNINSTALL -removeonly Symantec KB-DocID:2003093015493306-->MsiExec.exe /I{08C5815C-2C6E-44f8-8748-0E61BC9AFB68} Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall Tcl/Tk 8.3.0 for Windows-->C:\PROGRA~1\Tcl\UNWISE.EXE C:\PROGRA~1\Tcl\INSTALL.LOG Update for Windows Internet Explorer 8 (KB969497)-->"C:\WINDOWS\ie8updates\KB969497-IE8\spuninst\spuninst.exe" Update for Windows Media Player 10 (KB910393)-->"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe" Update for Windows Media Player 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe" Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe" Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe" Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe" Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe" Update Rollup 2 for Windows XP Media Center Edition 2005-->C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe VideoLAN VLC media player 0.8.4a-->C:\Program Files\VideoLAN\VLC\uninstall.exe Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u Virtual DJ - Atomix Productions-->C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG Vuze-->C:\Program Files\Azureus\uninstall.exe Windows Driver Package - Nokia Modem (05/22/2008 3.8)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia_blue_6F90B0F4A73A2F780A1010B5D6CB5DDFB098181E\nokia_bluetooth.inf Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_E68D50F7E25BFE399D47C864C3B52557346242A9\nokbtmdm.inf Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccsmcfd_4A1E30386F4D0DEC8F5DF262CFBD8845EEBAB175\pccsmcfd.inf Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe" Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe" Windows Media Connect-->"C:\WINDOWS\$NtUninstallWMCSetup$\spuninst\spuninst.exe" Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe" Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]-->C:\WINDOWS\$NtUninstallEmeraldQFE2$\spuninst\spuninst.exe Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe" Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840} Windows XP Media Center Edition 2005 KB908246-->"C:\WINDOWS\$NtUninstallKB908246$\spuninst\spuninst.exe" Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe" Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe" WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe XviD 1.1 final uninstall-->"C:\Program Files\XviD\unins000.exe"
======Security center information======
FW: Norton Internet Worm Protection (disabled)
======System event log======
Computer Name: ATLANTIS Event Code: 4226 Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Record Number: 638 Source Name: Tcpip Time Written: 20090603134139.000000+180 Event Type: warning User:
Computer Name: ATLANTIS Event Code: 4226 Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Record Number: 637 Source Name: Tcpip Time Written: 20090603132800.000000+180 Event Type: warning User:
Computer Name: ATLANTIS Event Code: 36 Message: The time service has not been able to synchronize the system time for 49152 seconds because none of the time providers has been able to provide a usable time stamp. The system clock is unsynchronized.
Record Number: 632 Source Name: W32Time Time Written: 20090603055222.000000+180 Event Type: warning User:
Computer Name: ATLANTIS Event Code: 7000 Message: The General Purpose USB Driver (adildr.sys) service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 612 Source Name: Service Control Manager Time Written: 20090602160648.000000+180 Event Type: error User:
Computer Name: ATLANTIS Event Code: 7000 Message: The General Purpose USB Driver (adildr.sys) service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 591 Source Name: Service Control Manager Time Written: 20090602123715.000000+180 Event Type: error User:
=====Application event log=====
Computer Name: ATLANTIS Event Code: 1000 Message: Faulting application acrord32.exe, version 7.0.8.218, faulting module acrord32.dll, version 7.0.8.218, fault address 0x000811a6.
Record Number: 3361 Source Name: Application Error Time Written: 20090629125749.000000+180 Event Type: error User:
Computer Name: ATLANTIS Event Code: 1000 Message: Faulting application acrord32.exe, version 7.0.8.218, faulting module acrord32.dll, version 7.0.8.218, fault address 0x00385fb4.
Record Number: 3311 Source Name: Application Error Time Written: 20090624123203.000000+180 Event Type: error User:
Record Number: 3163 Source Name: Application Hang Time Written: 20090613171508.000000+180 Event Type: error User:
Computer Name: ATLANTIS Event Code: 1002 Message: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Record Number: 3162 Source Name: Application Hang Time Written: 20090613171504.000000+180 Event Type: error User:
Computer Name: ATLANTIS Event Code: 2000 Message: Accepted Safe Mode action : Microsoft Office Word.
Record Number: 3050 Source Name: Microsoft Office 11 Time Written: 20090605143154.000000+180 Event Type: error User:
DDS (Ver_09-07-30.01) - NTFSx86 Run by Fadi at 22:43:07.85 on 04/09/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.464 [GMT 3:00]
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-07-30.01)
Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 16/03/2006 11:40:10 PM System Uptime: 09/04/2009 10:40:00 PM (3552 hours ago)
Motherboard: Dell Inc. | | 0FF049 Processor: Genuine Intel(R) CPU T2300 @ 1.66GHz | Microprocessor | 1664/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 68 GiB total, 21.441 GiB free. D: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: 1394 Net Adapter Device ID: V1394\NIC1394\1BB99050424FC000 Manufacturer: Microsoft Name: 1394 Net Adapter PNP Device ID: V1394\NIC1394\1BB99050424FC000 Service: NIC1394
Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Nokia Windows Portable Device Driver Device ID: ROOT\WPD\0000 Manufacturer: Nokia Name: Fadi 6300 PNP Device ID: ROOT\WPD\0000 Service: WUDFRd
Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Fadi 6500c Device ID: ROOT\WPD\0001 Manufacturer: Nokia Name: Fadi 6500c PNP Device ID: ROOT\WPD\0001 Service: WUDFRd
==== System Restore Points ===================
RP854: 07/06/2009 06:51:10 PM - System Checkpoint RP855: 08/06/2009 07:32:06 PM - System Checkpoint RP856: 09/06/2009 08:53:54 PM - System Checkpoint RP857: 10/06/2009 03:06:44 PM - Software Distribution Service 3.0 RP858: 11/06/2009 08:47:46 PM - System Checkpoint RP859: 13/06/2009 08:41:03 AM - System Checkpoint RP860: 14/06/2009 11:45:21 AM - System Checkpoint RP861: 15/06/2009 06:51:34 PM - System Checkpoint RP862: 16/06/2009 10:45:10 PM - System Checkpoint RP863: 18/06/2009 02:42:53 AM - System Checkpoint RP864: 19/06/2009 03:56:47 PM - System Checkpoint RP865: 20/06/2009 07:55:28 PM - System Checkpoint RP866: 21/06/2009 11:49:01 PM - System Checkpoint RP867: 23/06/2009 03:49:50 AM - System Checkpoint RP868: 24/06/2009 07:48:18 AM - System Checkpoint RP869: 25/06/2009 07:46:54 PM - System Checkpoint RP870: 26/06/2009 11:37:02 PM - System Checkpoint RP871: 28/06/2009 03:03:10 AM - System Checkpoint RP872: 29/06/2009 07:04:05 AM - System Checkpoint RP873: 30/06/2009 11:02:49 AM - System Checkpoint RP874: 01/07/2009 11:03:46 AM - System Checkpoint RP875: 02/07/2009 11:53:24 AM - System Checkpoint RP876: 03/07/2009 04:51:58 PM - System Checkpoint RP877: 04/07/2009 07:48:47 PM - System Checkpoint RP878: 05/07/2009 09:33:07 PM - System Checkpoint RP879: 07/07/2009 01:31:43 AM - System Checkpoint RP880: 08/07/2009 09:29:30 AM - System Checkpoint RP881: 09/07/2009 02:03:07 PM - System Checkpoint RP882: 10/07/2009 06:03:52 PM - System Checkpoint RP883: 11/07/2009 07:47:42 PM - System Checkpoint RP884: 13/07/2009 01:00:18 AM - System Checkpoint RP885: 14/07/2009 08:56:44 AM - System Checkpoint RP886: 15/07/2009 10:10:33 AM - System Checkpoint RP887: 16/07/2009 03:00:33 AM - Software Distribution Service 3.0 RP888: 17/07/2009 09:56:27 AM - System Checkpoint RP889: 18/07/2009 01:02:27 PM - System Checkpoint RP890: 19/07/2009 01:41:20 PM - System Checkpoint RP891: 20/07/2009 05:53:58 PM - System Checkpoint RP892: 21/07/2009 08:12:17 PM - System Checkpoint RP893: 22/07/2009 03:14:01 PM - Removed Apple Mobile Device Support RP894: 22/07/2009 04:25:23 PM - Installed AVG Free 8.5 RP895: 22/07/2009 07:43:46 PM - Removed Bonjour RP896: 22/07/2009 07:44:58 PM - Removed Apple Software Update RP897: 22/07/2009 07:49:34 PM - Removed AVG Free 8.5 RP898: 22/07/2009 07:50:37 PM - Installed AVG Free 8.5 RP899: 22/07/2009 10:22:55 PM - Restore Operation RP900: 24/07/2009 10:21:10 AM - System Checkpoint RP901: 25/07/2009 10:21:32 AM - System Checkpoint RP902: 04/09/2009 08:21:40 PM - System Checkpoint
==== Installed Programs ======================
7-Zip 4.57 Adobe Flash Player 10 ActiveX Adobe Reader 7.0.5 Language Support Adobe Reader 7.0.9 Adobe Reader Chinese Traditional Fonts Adobe Shockwave Player 11 ARTEuro Azureus Bluetooth Stack for Windows by Toshiba Broadcom Management Programs ccCommon CCleaner (remove only) Commandos Strike Force Conexant HDA D110 MDC V.92 Modem Critical Update for Windows Media Player 11 (KB959772) Defraggler (remove only) Dell Driver Reset Tool Dell Support 5.0.0 (630) Dell System Restore Digital Line Detect GemMaster Mystic High Definition Audio Driver Package - KB835221 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Huawei SmartAX MT810 Intel(R) Graphics Media Accelerator Driver Intel(R) PROSet/Wireless Software Internal Network Card Power Management iTunes Java 2 Runtime Environment, SE v1.4.2_03 Java(TM) 6 Update 6 Learn2 Player (Uninstall Only) Magic ISO Maker v5.4 (build 0251) MATLAB 6.5 mCore mDrWiFi mHlpDell Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.5 Microsoft Visual C++ 2005 Redistributable mIWA mLogView mMHouse Modem Helper mPfMgr mPfWiz mProSafe MSN MSN Messenger 7.5 MSRedist mSSO MSVC80_x86 MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser (KB933579) mWlsSafe mWMI mXML mZConfig NetWaiting Nokia Connectivity Cable Driver Nokia PC Suite Norton Internet Security 2006 Otto PC Connectivity Solution PowerDVD 5.7 QuickSet QuickTime RealPlayer Recuva (remove only) Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB973346) Sonic DLA Sonic Encoders Sonic MyDVD LE Sonic RecordNow Audio Sonic RecordNow Copy Sonic RecordNow Data Sony Picture Utility Sony USB Driver Symantec KB-DocID:2003093015493306 Synaptics Pointing Device Driver Tcl/Tk 8.3.0 for Windows Update for Windows Internet Explorer 8 (KB969497) Update for Windows Media Player 10 (KB910393) Update for Windows Media Player 10 (KB913800) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update Rollup 2 for Windows XP Media Center Edition 2005 VideoLAN VLC media player 0.8.4a Viewpoint Media Player Virtual DJ - Atomix Productions Vuze WebFldrs XP Windows Driver Package - Nokia Modem (05/22/2008 3.8) Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1) Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Connect Windows Media Format 11 runtime Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] Windows Media Player 11 Windows Presentation Foundation Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB925766 Windows XP Service Pack 3 WinRAR archiver XML Paper Specification Shared Components Pack 1.0 XviD 1.1 final uninstall
==== Event Viewer Messages From Past Week ========
04/09/2009 10:04:07 PM, error: Service Control Manager [7031] - The Remote Procedure Call (RPC) service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: . 04/09/2009 10:04:05 PM, error: Service Control Manager [7034] - The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 10:04:03 PM, error: Service Control Manager [7034] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 10:04:03 PM, error: Service Control Manager [7031] - The Universal Plug and Play Device Host service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: . 04/09/2009 10:04:03 PM, error: Service Control Manager [7031] - The Remote Registry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: . 04/09/2009 10:03:45 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 10:03:36 PM, error: Service Control Manager [7034] - The Intel(R) PROSet/Wireless Event Log service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 10:03:28 PM, error: Service Control Manager [7034] - The Media Center Scheduler Service service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 10:03:00 PM, error: Service Control Manager [7034] - The Symantec Settings Manager service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 10:02:56 PM, error: Service Control Manager [7034] - The Symantec Event Manager service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 10:02:53 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 10:02:48 PM, error: Service Control Manager [7034] - The HTTP SSL service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 09:33:00 PM, error: PlugPlayManager [11] - The device Root\legacy_104285d206768488f5210915c300db5b\0000 disappeared from the system without first being prepared for removal. 04/09/2009 08:52:22 PM, error: PlugPlayManager [12] - The device 'Fips' (Root\LEGACY_FIPS\0000) disappeared from the system without first being prepared for removal. 04/09/2009 08:52:22 PM, error: PlugPlayManager [11] - The device Root\legacy_sfxdrv\0000 disappeared from the system without first being prepared for removal. 04/09/2009 08:37:25 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. 04/09/2009 08:30:15 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 08:30:15 PM, error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: . 04/09/2009 08:24:25 PM, error: DCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. 04/09/2009 08:03:34 PM, error: Service Control Manager [7034] - The MATLAB Server service terminated unexpectedly. It has done this 1 time(s). 04/09/2009 07:55:46 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Network Data Management System Service service to connect. 04/09/2009 07:54:47 PM, error: Service Control Manager [7031] - The Media Center Receiver Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: . 04/09/2009 07:54:47 PM, error: Service Control Manager [7000] - The General Purpose USB Driver (adildr.sys) service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 04/09/2009 07:54:47 PM, error: Service Control Manager [7000] - The Automatic Updates service failed to start due to the following error: The system cannot find the file specified.
If on it's opening scan Gmer locates items shown in red or indicates "hidden" or "rootkit", stop there, and click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please. We don't want any crashes just from taking an initial look at things.
If not, then click on Scan (before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan).
When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please, along with C:\avenger.txt
You can break logs into parts and use separate posts here when replying and posting the log files, if needed.
The link you provided downloaded avenger.zip - which contained avenger.exe and NOT avenger2.exe. I tried to run avenger.exe but get a window which closes very very quickly. I tried renaming the avenger.exe to anger.com but got the same result.
I downloaded Gmer as per your suggestion and got the RED lines and hence stopped. Here is its result:
GMER 1.0.15.15077 [f9xfzhbj.exe] - http://www.gmer.net Rootkit quick scan 2009-09-05 17:48:53 Windows 5.1.2600 Service Pack 3
The instant I click on the link (http://www.eset.com/onlinescan), all ie sessions shut down! I tried it several times - Internet Explorer just closes immediately.
Return to OTM, right-click in the open text box labeled "Paste Instructions for Items to be Moved" (under the yellow bar) and choose Paste.
Click the red MoveIt! button.
The list will be processed and the results will be displayed in the right-hand pane.
Highlight everything in the Results window (under the green bar), press CTRL+C or right-click, choose Copy, right-click again and Paste it in your next reply.
Click Exit when done.
A log of the results is automatically created and saved to C:\_OTM\MovedFiles \mmddyyyy_hhmmss.log <- the date/time the tool was run.
-- Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. After the reboot, open Notepad, click File > Open, in the File Name box type *.log and press the Enter key. Navigate to the C:\_OTM\MovedFiles folder, open the newest .log file and copy/paste the contents in your next reply. If not asked, reboot anyway.
All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== FILES ========== File/Folder c:\documents and settings\fadi\start menu\programs\startup\ihaupd32.exe not found. File/Folder c:\documents and settings\fadi\start menu\programs\startup\uecupd32.exe not found. File/Folder c:\windows\system32\drivers\jgi05d7.sys not found. File/Folder c:\windows\system32\drivers\fse6ea6.sys not found. File/Folder c:\windows\system32\drivers\nkla0fd.sys not found. File/Folder C:\qseoqy.exe not found. File/Folder C:\ybdvlwme.exe not found. File/Folder C:\otcw.exe not found. File/Folder C:\lqjbmsj.exe not found. File/Folder C:\uputc.exe not found. File/Folder C:\hmgol.exe not found. File/Folder c:\windows\system32\drivers\smss.exe_ not found. File/Folder C:\rqhldhc.exe not found. File/Folder C:\gxqd.exe not found. File/Folder c:\windows\system32\drivers\a058083c.sys not found. File/Folder C:\udjnn.exe not found. File/Folder C:\uudoam.exe not found. File/Folder C:\errigh.exe not found. File/Folder c:\windows\system32\drivers\jgi05d7.sys not found. File/Folder C:\luqkal.exe not found. File/Folder c:\windows\system32\drivers\fse6ea6.sys not found. File/Folder c:\windows\system32\drivers\nkla0fd.sys not found. File/Folder C:\cnhtlnsc.exe not found. File/Folder c:\windows\system32\sysstsdw.exe not found. LoadLibrary failed for c:\windows\system32\bdeaffdbe.dll c:\windows\system32\bdeaffdbe.dll NOT unregistered. File move failed. c:\windows\system32\bdeaffdbe.dll scheduled to be moved on reboot. File/Folder C:\WINDOWS\System32\drivers\c724ffa8.sys not found. File/Folder C:\WINDOWS\system32\104285d206768488f5210915c300db5b.sys not found. Error: Unable to interpret <:driver > in the current context! Error: Unable to interpret <fse6ea6 > in the current context! Error: Unable to interpret <jgi05d7 > in the current context! Error: Unable to interpret <nkla0fd > in the current context! ========== COMMANDS ==========
User: LocalService ->Temp folder emptied: 65536 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32902 bytes
OTM by OldTimer - Version 3.0.0.6 log created on 09092009_093722
Files moved on Reboot... LoadLibrary failed for c:\windows\system32\bdeaffdbe.dll c:\windows\system32\bdeaffdbe.dll NOT unregistered. File move failed. c:\windows\system32\bdeaffdbe.dll scheduled to be moved on reboot.
OTL logfile created on: 11/09/2009 06:30:35 PM - Run 1 OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Fadi\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1014.37 Mb Total Physical Memory | 529.60 Mb Available Physical Memory | 52.21% Memory free 2.38 Gb Paging File | 2.01 Gb Available in Paging File | 84.47% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 68.41 Gb Total Space | 21.13 Gb Free Space | 30.89% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded
Computer Name: ATLANTIS Current User Name: Fadi Logged in as Administrator.
Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86 < End of report >
OTL Extras logfile created on: 11/09/2009 06:30:35 PM - Run 1 OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Fadi\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1014.37 Mb Total Physical Memory | 529.60 Mb Available Physical Memory | 52.21% Memory free 2.38 Gb Paging File | 2.01 Gb Available in Paging File | 84.47% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 68.41 Gb Total Space | 21.13 Gb Free Space | 30.89% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded
Computer Name: ATLANTIS Current User Name: Fadi Logged in as Administrator.
Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- File not found "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- File not found "C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL -- File not found "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 -- (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO "{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data "{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306 "{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView "{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA "{1248c09a-bd6b-47f5-bf3f-cd2b700d9fcb}" = ccCommon "{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}" = PC Connectivity Solution "{1D3C662A-F6C6-4767-A788-7AA43A9A1317}" = ARTEuro "{1F528948-0E80-4C96-B455-DE4167CB1DF7}" = Internal Network Card Power Management "{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86 "{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE "{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe "{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs "{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes "{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java(TM) 6 Update 6 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell "{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}" = Huawei SmartAX MT810 "{544DB849-AB59-4C12-A333-2F214E24870F}" = Commandos Strike Force "{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool "{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver "{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7 "{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver "{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr "{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz "{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig "{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders "{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio "{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9 "{AC76BA86-7AD7-2448-0000-705000000001}" = Adobe Reader Chinese Traditional Fonts "{AC76BA86-7AD7-5464-3428-7050000000A7}" = Adobe Reader 7.0.5 Language Support "{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy "{B3164E9E-BE08-4F3B-94BC-C6D09C0205E1}" = Nokia Connectivity Cable Driver "{b7c61755-db48-4003-948f-3d34db8eaf69}" = MSRedist "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}" = MSN Messenger 7.5 "{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba "{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility "{D5577624-0626-4C4B-87AA-D966DA1739D6}" = Nokia PC Suite "{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect "{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore "{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse "{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi "{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime "{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe "12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic "3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0) "7-Zip" = 7-Zip 4.57 "9CD348AE9C64C4B939B624E8E24F3903EFDFC82B" = Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1) "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player 11 "Azureus" = Azureus "B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto "C5A76DC11BABDA0A881E7BE8DDEB641365A77FFD" = Windows Driver Package - Nokia Modem (05/22/2008 3.8) "CCleaner" = CCleaner (remove only) "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem "Defraggler" = Defraggler (remove only) "DellSupport" = Dell Support 5.0.0 (630) "EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "Magic ISO Maker v5.4 (build 0251)" = Magic ISO Maker v5.4 (build 0251) "Matlab 6.5" = MATLAB 6.5 "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MSNINST" = MSN "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "ProInst" = Intel(R) PROSet/Wireless Software "RealPlayer 6.0" = RealPlayer "Recuva" = Recuva (remove only) "StreetPlugin" = Learn2 Player (Uninstall Only) "symsetuptemp.{a93c9e60-29b6-49da-ba21-f70ac6aade20}" = Norton Internet Security 2006 "SynTPDeinstKey" = Synaptics Pointing Device Driver "Tcl/Tk 8.3.0 for Windows" = Tcl/Tk 8.3.0 for Windows "ViewpointMediaPlayer" = Viewpoint Media Player "Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions "VLC media player" = VideoLAN VLC media player 0.8.4a "Vuze" = Vuze "WIC" = Windows Imaging Component "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = WinRAR archiver "WMCSetup" = Windows Media Connect "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01005" = Microsoft User-Mode Driver Framework Feature Pack 1.5 "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 "XviD_is1" = XviD 1.1 final uninstall
========== Last 10 Event Log Errors ==========
[ Application Events ] Error - 04/09/2009 03:08:39 PM | Computer Name = ATLANTIS | Source = Application Error | ID = 1000 Description = Faulting application ihaupd32.exe, version 45.72.427.3, faulting module ihaupd32.exe, version 45.72.427.3, fault address 0x000018cc.
Error - 04/09/2009 03:25:09 PM | Computer Name = ATLANTIS | Source = Application Hang | ID = 1002 Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 04/09/2009 03:25:09 PM | Computer Name = ATLANTIS | Source = Application Hang | ID = 1002 Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 04/09/2009 03:26:40 PM | Computer Name = ATLANTIS | Source = Application Hang | ID = 1001 Description = Fault bucket 1180947459.
Error - 04/09/2009 03:26:40 PM | Computer Name = ATLANTIS | Source = Application Hang | ID = 1001 Description = Fault bucket 1180947459.
Error - 04/09/2009 03:41:06 PM | Computer Name = ATLANTIS | Source = Application Error | ID = 1000 Description = Faulting application ihaupd32.exe, version 45.72.427.3, faulting module ihaupd32.exe, version 45.72.427.3, fault address 0x000018cc.
Error - 04/09/2009 04:40:40 PM | Computer Name = ATLANTIS | Source = Application Error | ID = 1000 Description = Faulting application ihaupd32.exe, version 45.72.427.3, faulting module ihaupd32.exe, version 45.72.427.3, fault address 0x000018cc.
Error - 05/09/2009 10:33:28 AM | Computer Name = ATLANTIS | Source = Application Error | ID = 1000 Description = Faulting application ihaupd32.exe, version 45.72.427.3, faulting module ihaupd32.exe, version 45.72.427.3, fault address 0x000018cc.
Error - 06/09/2009 08:48:33 AM | Computer Name = ATLANTIS | Source = Application Error | ID = 1000 Description = Faulting application ihaupd32.exe, version 45.72.427.3, faulting module ihaupd32.exe, version 45.72.427.3, fault address 0x000018cc.
Error - 06/09/2009 09:03:43 AM | Computer Name = ATLANTIS | Source = Application Error | ID = 1000 Description = Faulting application ihaupd32.exe, version 45.72.427.3, faulting module ihaupd32.exe, version 45.72.427.3, fault address 0x000018cc.
[ System Events ] Error - 22/07/2009 07:04:27 AM | Computer Name = ATLANTIS | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
Error - 22/07/2009 07:06:28 AM | Computer Name = ATLANTIS | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
Error - 22/07/2009 07:08:28 AM | Computer Name = ATLANTIS | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
Error - 22/07/2009 07:10:28 AM | Computer Name = ATLANTIS | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
Error - 22/07/2009 07:12:28 AM | Computer Name = ATLANTIS | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
Error - 22/07/2009 07:14:28 AM | Computer Name = ATLANTIS | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
Error - 22/07/2009 07:16:28 AM | Computer Name = ATLANTIS | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
Error - 22/07/2009 07:18:28 AM | Computer Name = ATLANTIS | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
Error - 22/07/2009 07:20:28 AM | Computer Name = ATLANTIS | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
Error - 22/07/2009 07:22:28 AM | Computer Name = ATLANTIS | Source = DCOM | ID = 10010 Description = The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
< End of report >
Results of screen317's Security Check version 0.98.9 Windows XP Service Pack 3 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! Norton Internet Security 2006
WMIC entry does not exist for antivirus; attempting automatic update. `````````````````````````````` Anti-malware/Other Utilities Check: CCleaner (remove only) Java(TM) 6 Update 6 Java 2 Runtime Environment, SE v1.4.2_03 Out of date Java installed! Adobe Flash Player 10 Adobe Reader 7.0.9 Adobe Reader Chinese Traditional Fonts Adobe Reader 7.0.5 Language Support Out of date Adobe Reader installed! `````````````````````````````` Process Check: objlist.exe by Laurent
`````````````````````````````` DNS Vulnerability Check: POOR! (Vulnerable to DNS cache poisoning!!-- Consider OPENDNS)
Disable the DNS cache permanently in Windows, use the Service Controller tool or the Services tool to set the DNS Client service startup type to Disabled. Note that the name of the Windows DNS Client service may also appear as "Dnscache."
It is very important not only to keep Sun Java up to date, but also to remove older versions which have security holes and can be exploited by malware.
Download exefix_xp utility and save to Desktop. Double-click the file to run it. This utility fixes the exefile association in the registry automatically.
See if you can run malwarebyte and hijackthis now ?
Memory Processes Infected: (No malicious items detected)
Memory Modules Infected: (No malicious items detected)
Registry Keys Infected: HKEY_CLASSES_ROOT\TypeLib\{df058c45-cd18-453e-8745-5a77f60722ab} (Adware.Gdown) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{b5a33c35-7298-4d15-8753-a2e851e2eab3} (Adware.Gdown) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{f0d2b812-752d-4af1-a2fb-968c4d8446db} (Adware.Gdown) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{e856b973-45fd-4559-8f82-eab539144667} (Adware.Gdown) -> Quarantined and deleted successfully.
Registry Values Infected: (No malicious items detected)
Registry Data Items Infected: (No malicious items detected)
Folders Infected: (No malicious items detected)
Files Infected: C:\WINDOWS\system32\GTDownDE_87.ocx (Adware.Gdown) -> Quarantined and deleted successfully. C:\.security (Rogue.Multiple) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\etc\.security (Rogue.Multiple) -> Quarantined and deleted successfully. C:\WINDOWS\.security (Rogue.Multiple) -> Quarantined and deleted successfully.
-----------------
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:48:08 AM, on 22/09/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal
Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any): O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - (no file)
Install it and double-click the icon on your desktop to run it. It will ask if you want to update the program definitions, click Yes, Let it through your firewall! Under Configuration and Preferences, click the Preferences button. Click the Scanning Control tab. Under Scanner Options make sure the following are checked:
Close browsers before scanning Scan for tracking cookies Terminate memory threats before quarantining. Ignore System Restore/Volume Information on ME and XP Please leave the others unchecked.
On the main screen, under Scan for Harmful Software click Scan your computer. On the left check C:\Fixed Drive. On the right, under Complete Scan, choose Perform Complete Scan. Click Next to start the scan. Please be patient while it scans your computer. After the scan is complete a summary box will appear. Click OK. Make sure everything in the white box has a check next to it, then click Next. It will quarantine what it found and if it asks if you want to reboot, click Yes.
Reboot normally.
After reboot, double-click the SUPERAntispyware icon on your desktop.
Click Preferences . Click the Statistics/Logs tab .
Under Scanner Logs , double-click SUPERAntiSpyware Scan Log .
It will open in your default text editor (such as Notepad/Wordpad).
Please highlight everything , then right-click and choose copy.
Click close and close again to exit the program.
Post Superantispyware log, along with new hijackthis log and tell how things are running ?
Adware.Tracking Cookie C:\Documents and Settings\Fadi\Cookies\fadi@site4find.txt C:\Documents and Settings\Fadi\Cookies\fadi@domefind.txt C:\Documents and Settings\Fadi\Cookies\fadi@atdmt.txt C:\Documents and Settings\Jaco\Cookies\jaco@2o7.txt C:\Documents and Settings\Jaco\Cookies\jaco@ad.uk.tangozebra.txt C:\Documents and Settings\Jaco\Cookies\jaco@ads.pointroll.txt C:\Documents and Settings\Jaco\Cookies\jaco@bizrate.txt C:\Documents and Settings\Jaco\Cookies\jaco@bravenet.txt C:\Documents and Settings\Jaco\Cookies\jaco@clickaider.txt C:\Documents and Settings\Jaco\Cookies\jaco@cneteurope.122.2o7.txt C:\Documents and Settings\Jaco\Cookies\jaco@content.yieldmanager.txt C:\Documents and Settings\Jaco\Cookies\jaco@content.yieldmanager.txt C:\Documents and Settings\Jaco\Cookies\jaco@counter.hitslink.txt C:\Documents and Settings\Jaco\Cookies\jaco@counter2.hitslink.txt C:\Documents and Settings\Jaco\Cookies\jaco@data.coremetrics.txt C:\Documents and Settings\Jaco\Cookies\jaco@data3.perf.overture.txt C:\Documents and Settings\Jaco\Cookies\jaco@dealnews.122.2o7.txt C:\Documents and Settings\Jaco\Cookies\jaco@digitalhomediscountptyltd.122.2o7.txt C:\Documents and Settings\Jaco\Cookies\jaco@ehg-bestbuy.hitbox.txt C:\Documents and Settings\Jaco\Cookies\jaco@ehg-foxsports.hitbox.txt C:\Documents and Settings\Jaco\Cookies\jaco@ehg-ioffer.hitbox.txt C:\Documents and Settings\Jaco\Cookies\jaco@ehg-techtarget.hitbox.txt C:\Documents and Settings\Jaco\Cookies\jaco@ehg-ti.hitbox.txt C:\Documents and Settings\Jaco\Cookies\jaco@ehg.hitbox.txt C:\Documents and Settings\Jaco\Cookies\jaco@hc2.humanclick.txt C:\Documents and Settings\Jaco\Cookies\jaco@iacas.adbureau.txt C:\Documents and Settings\Jaco\Cookies\jaco@indexstats.txt C:\Documents and Settings\Jaco\Cookies\jaco@insightexpressai.txt C:\Documents and Settings\Jaco\Cookies\jaco@interclick.txt C:\Documents and Settings\Jaco\Cookies\jaco@mathworks.112.2o7.txt C:\Documents and Settings\Jaco\Cookies\jaco@media.adrevolver.txt C:\Documents and Settings\Jaco\Cookies\jaco@media.fastclick.txt C:\Documents and Settings\Jaco\Cookies\jaco@media6degrees.txt C:\Documents and Settings\Jaco\Cookies\jaco@msnaccountservices.112.2o7.txt C:\Documents and Settings\Jaco\Cookies\jaco@primediabusiness.122.2o7.txt C:\Documents and Settings\Jaco\Cookies\jaco@server.iad.liveperson.txt C:\Documents and Settings\Jaco\Cookies\jaco@specificclick.txt C:\Documents and Settings\Jaco\Cookies\jaco@statcounter.txt C:\Documents and Settings\Jaco\Cookies\jaco@stats1.reliablestats.txt C:\Documents and Settings\Jaco\Cookies\jaco@supermediastore.txt C:\Documents and Settings\Jaco\Cookies\jaco@wimedia.txt C:\Documents and Settings\Jaco\Cookies\jaco@www.supermediastore.txt C:\Documents and Settings\Jaco\Cookies\jaco@www.winantivirus.txt
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 04:46:08 PM, on 22/09/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal
My pc is running very well now - MANY THANKS. Can you tell me which of these tools should I keep, and which I should uninstall/delete? I will uninstall Norton, and install Avast. But do I still need SuperAntispy, hijackthis, Malwarebytes, avenger, ritter, combofix... etc... ?
Go to your desktop and double click on the removal tool and then click Setup. Once open Click Next Accept the license agreement and click Next Type in the letters/numbers that you see into the text box then click Next. Then click Next and the tool will start running. Once finished restart the PC and run the tool again to ensure everything has been removed. Delete Nortonremoval tool from your Desktop.
You should Create a New Restore Point to prevent possible reinfection from an old one. The easiest and safest way to do this is:
Go to Start > All Programs > Accessories > System Tools > System Restore Select Create a restore point, and Ok it. Next, go to Start > Run and type in cleanmgr Select the More options tab Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created.
Click START then RUN
Now type Combofix /u in the runbox and click OK.
Note the space between the X and the U, it needs to be there.
The above procedure will:
Delete the following: ComboFix and its associated files and folders. VundoFix backups, if present. The C:\Deckard folder, if present. The C:_OtMoveIt folder, if present. Reset the clock settings. Hide file extensions, if required. Hide System/Hidden files, if required.
I suggest you keep Ccleaner and malwarebyte. Then delete the other tools.
Currently it is Monday, March 15, 2010 8:46 PM (GMT +1) There are a total of 76.223 posts in 17.603 threads. In the last 3 days there were 11 new threads and 78 reply posts. View Active Threads
Who's Online
This forum has 31141 registered members. Please welcome our newest member, bippedibopp. 27 Guest(s), 1 Registered Member(s) are currently online. Details markusg