Something you might try, if you can, is connect your hard drive to another computer by means of a USB cable. IDE to USB or install the hard drive inside another computer as a secondary hard drive, so you don't boot on it.
The idea here is not to transfer a virus to the other computer and NOT to boot on the hard drive you are having trouble with. What you need is to have a healthy hard drive system with a good virus protector and / or a connection to the internet to use a good on-line malware detector and scan the hard drive you are having trouble with.
Many time, I have used the external hard drive USB connector to scan a suspicious hard drive and find viruses or malware and clean it.
If you find something and clean it then re-install the drive in the first computer and it won't boot at all or a different problem occurs, you may try a partial operating system re-install or total, but use windows2 as an install directory so you don't loose everything. If you back up everything first, you also back up the problem causer. You see, this could get complicated to preserve all your data and fix the computer. Take it a step at a time.
====== Files under "\System32\Drivers" Last 60 Days======
9/22/2009 10:46:37 AM 19160 32 C:\WINDOWS\system32\drivers\mbam.sys 9/22/2009 10:46:39 AM 38224 32 C:\WINDOWS\system32\drivers\mbamswissarmy.sys
====== Files Deleted under "%Temp%" ======
149 Files deleted
====== Files and Folders under "All Users\Application Data" Last 60 Days======
7/30/2009 2:27:05 PM 16382351 C:\Documents and Settings\All Users\Application Data\AOL Downloads 7/30/2009 2:27:05 PM 16382351 C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4426 7/30/2009 2:27:05 PM 213285 C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4426\html 7/30/2009 2:27:05 PM 2224 C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4426\html\images 8/31/2009 7:18:32 PM 1676118985 C:\Documents and Settings\All Users\Application Data\GARMIN 8/31/2009 7:18:32 PM 1676118985 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps 8/31/2009 7:19:07 PM 1676118985 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap 8/31/2009 7:19:57 PM 473991476 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\CNNANT_2010_20_mdr 8/31/2009 7:19:07 PM 1179837589 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1 8/31/2009 7:21:14 PM 6344323 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323483 8/31/2009 7:21:12 PM 11550146 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323484 8/31/2009 7:21:10 PM 6709671 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323485 8/31/2009 7:21:09 PM 4129177 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323486 8/31/2009 7:21:09 PM 319942 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323487 8/31/2009 7:21:10 PM 717131 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323488 8/31/2009 7:21:10 PM 1296953 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323489 8/31/2009 7:19:53 PM 7642162 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323490 8/31/2009 7:19:53 PM 1903759 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323491 8/31/2009 7:19:54 PM 848751 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323492 8/31/2009 7:19:54 PM 2963052 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323493 8/31/2009 7:19:53 PM 6256278 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323494 8/31/2009 7:19:51 PM 4399460 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323495 8/31/2009 7:19:51 PM 7212834 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323496 8/31/2009 7:19:52 PM 12357791 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323497 8/31/2009 7:19:51 PM 7229362 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323498 8/31/2009 7:19:54 PM 662081 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323499 8/31/2009 7:19:56 PM 13094097 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323500 8/31/2009 7:19:56 PM 1424856 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323501 8/31/2009 7:19:57 PM 269658 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323502 8/31/2009 7:19:57 PM 1185977 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323503 8/31/2009 7:19:56 PM 6619005 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323504 8/31/2009 7:19:54 PM 2664727 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323505 8/31/2009 7:19:54 PM 8006970 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323506 8/31/2009 7:19:55 PM 8714754 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323507 8/31/2009 7:19:55 PM 8215278 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323508 8/31/2009 7:21:54 PM 5008732 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323509 8/31/2009 7:21:53 PM 11586988 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323510 8/31/2009 7:21:55 PM 6636204 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323511 8/31/2009 7:21:55 PM 6173104 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323512 8/31/2009 7:21:50 PM 9292224 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323513 8/31/2009 7:21:45 PM 14153540 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323514 8/31/2009 7:21:44 PM 15928731 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323515 8/31/2009 7:21:48 PM 15871417 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323516 8/31/2009 7:21:46 PM 13704229 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323518 8/31/2009 7:21:56 PM 16368816 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323519 8/31/2009 7:22:07 PM 22510732 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323520 8/31/2009 7:22:06 PM 13720123 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323521 8/31/2009 7:22:26 PM 20129048 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323522 8/31/2009 7:22:19 PM 18608315 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323523 8/31/2009 7:22:04 PM 17060578 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323524 8/31/2009 7:22:01 PM 15367788 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323525 8/31/2009 7:21:58 PM 16452075 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323526 8/31/2009 7:22:03 PM 9457832 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323527 8/31/2009 7:22:02 PM 12093755 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323528 8/31/2009 7:21:27 PM 18400672 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323529 8/31/2009 7:21:22 PM 14281138 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323530 8/31/2009 7:21:35 PM 9991437 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323531 8/31/2009 7:21:31 PM 16089448 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323532 8/31/2009 7:21:20 PM 16230633 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323533 8/31/2009 7:21:18 PM 6496702 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323534 8/31/2009 7:21:15 PM 10025424 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323535 8/31/2009 7:21:20 PM 4149884 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323536 8/31/2009 7:21:19 PM 4294703 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323537 8/31/2009 7:21:38 PM 10804057 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323538 8/31/2009 7:21:41 PM 10147385 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323539 8/31/2009 7:21:41 PM 11161270 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323540 8/31/2009 7:21:43 PM 19629962 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323541 8/31/2009 7:21:42 PM 8092052 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323542 8/31/2009 7:21:41 PM 5584845 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323543 8/31/2009 7:21:40 PM 5119664 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323544 8/31/2009 7:21:39 PM 9312834 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323545 8/31/2009 7:21:40 PM 4004221 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323546 8/31/2009 7:21:40 PM 4065497 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323547 8/31/2009 7:19:51 PM 4990143 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323548 8/31/2009 7:19:26 PM 3686938 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323549 8/31/2009 7:19:24 PM 12915754 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323550 8/31/2009 7:19:27 PM 9222973 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323551 8/31/2009 7:19:27 PM 1449830 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323552 8/31/2009 7:19:24 PM 6663467 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323553 8/31/2009 7:19:23 PM 1215995 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323554 8/31/2009 7:19:22 PM 9598927 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323555 8/31/2009 7:19:23 PM 7879312 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323556 8/31/2009 7:19:23 PM 2988718 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323557 8/31/2009 7:19:27 PM 6243408 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323558 8/31/2009 7:19:31 PM 19411327 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323559 8/31/2009 7:19:31 PM 5735950 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323560 8/31/2009 7:19:32 PM 5390407 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323561 8/31/2009 7:19:32 PM 233711 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323562 8/31/2009 7:19:30 PM 2744107 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323563 8/31/2009 7:19:29 PM 2948276 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323564 8/31/2009 7:19:28 PM 7649632 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323565 8/31/2009 7:19:29 PM 17198695 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323566 8/31/2009 7:19:29 PM 3241624 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323567 8/31/2009 7:19:12 PM 7910516 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323568 8/31/2009 7:19:12 PM 1659369 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323569 8/31/2009 7:19:14 PM 15790185 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323570 8/31/2009 7:19:13 PM 23465724 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323571 8/31/2009 7:19:11 PM 14890800 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323572 8/31/2009 7:19:08 PM 555581 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323573 8/31/2009 7:19:07 PM 8381302 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323574 8/31/2009 7:19:10 PM 14382491 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323575 8/31/2009 7:19:08 PM 16660042 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323576 8/31/2009 7:19:15 PM 4768368 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323577 8/31/2009 7:19:19 PM 10901590 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323578 8/31/2009 7:19:18 PM 3653618 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323579 8/31/2009 7:19:21 PM 14800430 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323580 8/31/2009 7:19:19 PM 14638814 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323581 8/31/2009 7:19:18 PM 10529009 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323582 8/31/2009 7:19:16 PM 17996874 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323583 8/31/2009 7:19:15 PM 1600593 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323584 8/31/2009 7:19:17 PM 13074100 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323585 8/31/2009 7:19:17 PM 8141695 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323586 8/31/2009 7:19:44 PM 5885239 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323587 8/31/2009 7:19:43 PM 1373166 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323588 8/31/2009 7:19:45 PM 4051564 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323589 8/31/2009 7:19:44 PM 14188217 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323590 8/31/2009 7:19:43 PM 3654246 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323591 8/31/2009 7:19:40 PM 4249528 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323592 8/31/2009 7:19:39 PM 10300809 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323593 8/31/2009 7:19:41 PM 19862776 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323594 8/31/2009 7:19:41 PM 8080702 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323595 8/31/2009 7:19:45 PM 22676458 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323596 8/31/2009 7:19:49 PM 8779989 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323597 8/31/2009 7:19:49 PM 1171411 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323598 8/31/2009 7:19:50 PM 4270350 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323599 8/31/2009 7:19:50 PM 6467322 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323600 8/31/2009 7:19:49 PM 6493764 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323601 8/31/2009 7:19:48 PM 3003055 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323602 8/31/2009 7:19:47 PM 15693218 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323603 8/31/2009 7:19:48 PM 9676201 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323604 8/31/2009 7:19:48 PM 4774445 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323605 8/31/2009 7:19:35 PM 141534 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323606 8/31/2009 7:19:35 PM 147668 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323607 8/31/2009 7:19:35 PM 176685 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323608 8/31/2009 7:19:35 PM 7014137 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323933 8/31/2009 7:19:35 PM 4088543 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323934 8/31/2009 7:19:32 PM 12634694 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323935 8/31/2009 7:19:32 PM 2683883 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323936 8/31/2009 7:19:34 PM 15884643 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323937 8/31/2009 7:19:33 PM 6194218 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323938 8/31/2009 7:19:36 PM 10659573 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323939 8/31/2009 7:19:37 PM 13925515 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323940 8/31/2009 7:19:37 PM 13143203 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323974 8/31/2009 7:19:38 PM 12569984 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323975 8/31/2009 7:19:36 PM 9836987 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\CNNANT_2010_20 8/31/2009 7:19:37 PM 12950 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\Logos 9/17/2009 10:50:58 AM 2825154 C:\Documents and Settings\All Users\Application Data\Malwarebytes 9/17/2009 10:50:58 AM 2825154 C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware 9/18/2009 9:42:46 PM 3835 C:\Documents and Settings\All Users\Application Data\Simply Super Software 9/18/2009 9:42:46 PM 3835 C:\Documents and Settings\All Users\Application Data\Simply Super Software\Trojan Remover 9/18/2009 9:42:46 PM 3835 C:\Documents and Settings\All Users\Application Data\Simply Super Software\Trojan Remover\Data 9/17/2009 4:02:34 PM 0 C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 9/17/2009 4:02:34 PM 0 C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware 9/18/2009 2:00:03 PM 0 C:\Documents and Settings\All Users\Application Data\TEMP
====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0) ABC (remove only) Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Shockwave Player 11.5 AIM 6 Business Contact Manager for Outlook 2007 CCleaner (remove only) Conexant D850 56K V.9x DFVc Modem Comcast High-Speed Internet Install Wizard Intel(R) Graphics Media Accelerator Driver HijackThis 2.0.2 HP Document Viewer 7.0 HP Imaging Device Functions 7.0 HP Photosmart Premier Software 6.5 HP Solution Center 7.0 HP Customer Participation Program 7.0 OCR Software by I.R.I.S 7.0 Microsoft Internationalized Domain Names Mitigation APIs Windows Internet Explorer 7 Canon Utilities PhotoStitch 3.1 Canon Camera Window for ZoomBrowser EX Canon Utilities RemoteCapture 2.7 Canon Utilities File Viewer Utility 1.2 High Definition Audio Driver Package - KB835221 Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Hotfix for Windows Media Format SDK (KB902344) Security Update for Windows Media Player (KB911564) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows XP (KB923789) Security Update for Windows Media Player 6.4 (KB925398) Hotfix for Windows Media Format 11 SDK (KB929399) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows XP (KB938464) Security Update for Windows Internet Explorer 7 (KB939653) Hotfix for Windows Media Player 11 (KB939683) Security Update for Windows XP (KB941569) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows XP (KB946648) Hotfix for Windows Internet Explorer 7 (KB947864) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Update for Windows XP (KB951072-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Update for Windows XP (KB951978) Security Update for Windows XP (KB952004) Security Update for Windows Media Player (KB952069) Hotfix for Windows XP (KB952287) Security Update for Windows XP (KB952954) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Hotfix for Windows XP (KB954550-v5) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Update for Windows XP (KB955839) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Critical Update for Windows Media Player 11 (KB959772) Security Update for Windows XP (KB960225) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Hotfix for Windows XP (KB961118) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows Internet Explorer 7 (KB963027) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Security Update for Windows XP (KB968537) Security Update for Windows Media Player (KB968816) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Hotfix for Windows XP (KB970653-v3) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows Media Player (KB973540) Update for Windows XP (KB973815) Security Update for Windows XP (KB973869) Microsoft .NET Framework 1.1 Hotfix (KB928366) Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 3.5 SP1 Microsoft SQL Server 2005 Mozilla Firefox (3.0.14) McAfee SecurityCenter Microsoft Compression Client Pack 1.0 for Windows XP Microsoft National Language Support Downlevel APIs Canon PhotoRecord Picasa 3 Intel(R) PRO Network Connections Drivers RealPlayer Microsoft Office Small Business 2007 Windows Genuine Advantage Validation Tool (KB892130) Windows Genuine Advantage Notifications (KB905474) Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 Windows Media Format 11 runtime Windows Media Player 11 Microsoft User-Mode Driver Framework Feature Pack 1.0 Roxio Creator Tools PhotoStitch Bonjour Camera Window SlideShow MSXML 6.0 Parser (KB933579) Roxio Creator Data Microsoft Plus! Photo Story 2 LE cp_OnlineProjectsConfig HPPhotoSmartExpress PowerDVD Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) Dell DataSafe Online Roxio Drag-to-Disc Sonic_PrimoSDK Roxio Update Manager Windows Media Player 10 SkinsHP1 WebFldrs XP Sonic Activation Module PanoStandAlone HP Product Assistant RCT High Value - Standalone NetWaiting CP_Package_Basic1 BufferChm Banctec Service Agreement HPProductAssistant Microsoft Office 2007 Primary Interop Assemblies Microsoft SQL Server Native Client FullDPAppQFolder Microsoft SQL Server Setup Support Files (English) c4100_Help Dell Driver Reset Tool iTunes Roxio Creator Copy Browser Address Error Redirector Roxio Express Labeler WebReg RandMap eSupportQFolder AiOSoftwareNPI Toolbox Apple Software Update Microsoft Plus! Digital Media Edition Installer CustomerResearchQFolder Readme Dell System Restore DocumentViewerQFolder ProductContextNPI DellSupport Status Apple Mobile Device Support Roxio Creator Audio MSXML 4.0 SP2 (KB954430) DocProcQFolder Roxio Creator BDAV Plugin DocProc Unload Microsoft Software Update for Web Folders (English) 12 Microsoft Office Excel MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office 2003 Web Components Microsoft Office Small Business 2007 Residential Component Technology - Standalone ScannerCopy InstantShareDevices Microsoft .NET Framework 3.0 Service Pack 2 Microsoft Office Small Business Connectivity Components HP Photosmart and Deskjet 7.0.A DeviceManagementQFolder Adobe Reader 8.1.3 Documentation & Support Launcher Garmin USB Drivers cp_PosterPrintConfig Business Contact Manager for Outlook 2007 Garmin Communicator Plugin CueTour Games, Music, & Photos Launcher CP_Panorama1Config RemoteCapture 2.7.0 MSXML 4.0 SP2 (KB936181) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft SQL Server VSS Writer PhotoGallery Canon Utilities ZoomBrowser EX Modem Diagnostic Tool Garmin City Navigator North America NT 2010.20 QuickTime SolutionCenter C4100 AiO_Scan_CDA Roxio Creator DE HP Update Microsoft .NET Framework 1.1 SUPERAntiSpyware Free Edition Microsoft .NET Framework 3.5 SP1 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Roxio MyDVD DE Desktop Doctor TrayApp AnswerWorks 5.0 English Runtime MobileMe Control Panel MarketResearch Dell Support Center (Support Software) Internet Service Offers Launcher Digital Line Detect Yahoo! Music Jukebox Quicken 2009 CP_CalendarTemplates1 File Viewer Utility 1.2 Realtek High Definition Audio Driver InstantShareDevicesMFC Scan Fax_CDA Destinations NewCopy_CDA DocumentViewer
======== Other Info ========
TOTAL PHYSICAL RAM: 1062 MB
Boot Info
[boot loader] timeout=3 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
OS Type: Microsoft Windows XP Professional Build: 5.1.2600 Service Pack: 3.0
====== Files with Hidden Attributes======
C:\hiberfil.sys C:\IO.SYS C:\MSDOS.SYS C:\pagefile.sys C:\NTDETECT.COM C:\dell\ZbThumbnail.info C:\Documents and Settings\Administrator\NTUSER.DAT C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
ComboFix 09-09-17.04 - Justin Lafond 09/17/2009 20:45.1.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.572 [GMT -4:00] Running from: c:\combofix\ComboFix.exe Command switches used :: ComboFix AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} * Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
c:\documents and settings\Justin Lafond\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe c:\documents and settings\Justin Lafond\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe c:\documents and settings\Justin Lafond\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe c:\documents and settings\Justin Lafond\My Documents\ZbThumbnail.info c:\windows\ALCMTR.EXE c:\windows\Installer\4b240c0.msi c:\windows\ppp3.dat c:\windows\ppp4.dat c:\windows\system32\bennuar.old c:\windows\system32\bincd32.dat c:\windows\system32\desot.exe c:\windows\system32\drivers\rotscxxypylbjt.sys c:\windows\system32\MSHC.DLL c:\windows\system32\rotscxbomigukb.dll c:\windows\system32\rotscxdiuuwfpx.dat c:\windows\system32\rotscxdjnkoowl.dat c:\windows\system32\rotscxiostenkr.dll c:\windows\system32\rotscxipooylns.dll c:\windows\system32\sonhelp.htm c:\windows\system32\sysnet.dat
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) .
c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-10-10 24576] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472] HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
1. Open
NotePad (not wordpad). Copy and paste the following into Notepad
Driver:: AntipPolice_
Save the File as
CFScript(exactly as shown no spaces) ->> Save it to your
Desktop
Using the Image as a reference, drag
CFScript into
ComboFix.exe
You will be prompted to run Combofix again, Do so Following the same rules as indicated in my first post Then post the contents of the C:\ComboFix.txt log in your reply
ComboFix 09-09-23.02 - Justin Lafond 09/24/2009 17:37.2.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.473 [GMT -4:00] Running from: c:\documents and settings\Justin Lafond\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Justin Lafond\Desktop\CFScript.txt AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} * Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-10-10 24576] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472] HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
No, I am still unable to boot in safe mode. The only other issue I am experiencing now is getting redirected when I search in a browser. Mcafee can now run scans and login time is much faster.
bamajim
10.4K Posts
0
September 23rd, 2009 08:00
1. Go HERE and download File Lister.
Copy and paste the contents of that log in your reply.
speedy1147
3 Posts
0
September 23rd, 2009 10:00
Something you might try, if you can, is connect your hard drive to another computer by means of a USB cable. IDE to USB or install the hard drive inside another computer as a secondary hard drive, so you don't boot on it.
The idea here is not to transfer a virus to the other computer and NOT to boot on the hard drive you are having trouble with. What you need is to have a healthy hard drive system with a good virus protector and / or a connection to the internet to use a good on-line malware detector and scan the hard drive you are having trouble with.
Many time, I have used the external hard drive USB connector to scan a suspicious hard drive and find viruses or malware and clean it.
If you find something and clean it then re-install the drive in the first computer and it won't boot at all or a different problem occurs, you may try a partial operating system re-install or total, but use windows2 as an install directory so you don't loose everything. If you back up everything first, you also back up the problem causer. You see, this could get complicated to preserve all your data and fix the computer. Take it a step at a time.
speedy1147
lafond0822
5 Posts
0
September 23rd, 2009 17:00
Here is the log from FileLister. Thanks for helping me out.
+++++++++++++++++++++++++++++++++
+ File Lister Version 1.1.1 +
+ +
+ By bamajim / SpywareHammer.com +
+++++++++++++++++++++++++++++++++
Report ran on --->>> 9/23/2009 7:29:30 PM
====== Running Processes ======
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
====== BHO's ======
BHO: (NO NAME) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: (NO NAME) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
====== HKLM\~\Run Keys ======
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[IgfxTray] = C:\WINDOWS\system32\igfxtray.exe
[HotKeysCmds] = C:\WINDOWS\system32\hkcmd.exe
[Persistence] = C:\WINDOWS\system32\igfxpers.exe
[RTHDCPL] = RTHDCPL.EXE
[ISUSPM Startup] = C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
[ISUSScheduler] = "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[RoxWatchTray] = "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
[RoxioDragToDisc] = "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
[PDVDDXSrv] = "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
[dscactivate] = "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
[HP Software Update] = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[mcagent_exe] = "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
[AppleSyncNotifier] = C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[Adobe Reader Speed Launcher] = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[ddoctorv2] = "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
[iTunesHelper] = "C:\Program Files\iTunes\iTunesHelper.exe"
[DellSupportCenter] = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
[Malwarebytes Anti-Malware (reboot)] = "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
====== HKCU\~\Run Keys ======
[DellSupport] = "C:\Program Files\DellSupport\DSAgnt.exe" /startup
[Aim6] = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
[DellSupportCenter] = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
[ctfmon.exe] = C:\WINDOWS\system32\ctfmon.exe
[SUPERAntiSpyware] = C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
====== DNS Info (List may be empty) ======
HKEY_LOCAL_MACHINE\CCS\~\{36DC6E7A-15AD-4572-AFCD-341C882D056C}\ NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{36DC6E7A-15AD-4572-AFCD-341C882D056C}\ NameServer=
HKEY_LOCAL_MACHINE\CS002\~\{36DC6E7A-15AD-4572-AFCD-341C882D056C}\ NameServer=
====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======
9/17/2009 8:34:51 PM 8122230 C:\cmdcons
9/17/2009 8:34:52 PM 860672 C:\cmdcons\SYSTEM32
9/21/2009 2:15:11 PM 6848898 C:\ComboFix
9/21/2009 2:15:12 PM 24 C:\ComboFix\N_
8/31/2009 7:18:23 PM 68246263 C:\Garmin
8/31/2009 7:18:32 PM 5236282 C:\Garmin\WebUpdater
9/17/2009 9:35:28 PM 4711901 C:\MGtools
9/10/2009 10:31:24 PM 2083584 C:\MGtools\temp
9/10/2009 11:35:48 PM 787456 C:\MGtools\temp\VSP1
9/10/2009 10:31:20 PM 0 C:\MGtools\temp\VSP2
9/10/2009 10:30:06 PM 647296 C:\MGtools\temp\XPSP2
9/10/2009 10:30:06 PM 648832 C:\MGtools\temp\XPSP3
9/17/2009 8:16:41 PM 2410904 C:\Qoobox
9/17/2009 8:17:52 PM 15282 C:\Qoobox\BackEnv
9/21/2009 2:15:13 PM 0 C:\Qoobox\LastRun
9/17/2009 8:16:41 PM 1191599 C:\Qoobox\Quarantine
9/17/2009 8:37:18 PM 1183500 C:\Qoobox\Quarantine\C
9/17/2009 9:02:39 PM 111120 C:\Qoobox\Quarantine\C\Documents and Settings
9/17/2009 9:02:39 PM 111120 C:\Qoobox\Quarantine\C\Documents and Settings\Justin Lafond
9/17/2009 9:02:39 PM 89088 C:\Qoobox\Quarantine\C\Documents and Settings\Justin Lafond\Application Data
9/17/2009 9:02:39 PM 89088 C:\Qoobox\Quarantine\C\Documents and Settings\Justin Lafond\Application Data\Microsoft
9/17/2009 9:02:39 PM 89088 C:\Qoobox\Quarantine\C\Documents and Settings\Justin Lafond\Application Data\Microsoft\Installer
9/17/2009 9:02:39 PM 89088 C:\Qoobox\Quarantine\C\Documents and Settings\Justin Lafond\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
9/17/2009 9:02:47 PM 22032 C:\Qoobox\Quarantine\C\Documents and Settings\Justin Lafond\My Documents
9/17/2009 8:38:35 PM 1072380 C:\Qoobox\Quarantine\C\WINDOWS
9/17/2009 9:02:53 PM 532992 C:\Qoobox\Quarantine\C\WINDOWS\Installer
9/17/2009 8:38:35 PM 469695 C:\Qoobox\Quarantine\C\WINDOWS\system32
9/17/2009 8:39:15 PM 70656 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers
9/17/2009 8:16:41 PM 7565 C:\Qoobox\Quarantine\Registry_backups
9/21/2009 2:15:13 PM 0 C:\Qoobox\Test
9/21/2009 2:15:13 PM 0 C:\Qoobox\TestC
9/17/2009 9:58:34 PM 29769 C:\RECYCLER
9/21/2009 11:50:20 AM 85 C:\RECYCLER\S-1-5-21-1516691382-577858434-3916346065-1008
9/21/2009 11:24:32 AM 85 C:\RECYCLER\S-1-5-21-1516691382-577858434-3916346065-1009
9/17/2009 10:21:46 PM 85 C:\RECYCLER\S-1-5-21-1516691382-577858434-3916346065-1010
9/17/2009 9:58:34 PM 29429 C:\RECYCLER\S-1-5-21-1516691382-577858434-3916346065-1011
9/23/2009 10:11:15 AM 28544 C:\RECYCLER\S-1-5-21-1516691382-577858434-3916346065-1011\Dc15
9/21/2009 11:57:08 AM 85 C:\RECYCLER\S-1-5-21-1516691382-577858434-3916346065-1012
9/17/2009 8:35:01 PM 211 32 C:\Boot.bak
9/17/2009 8:34:53 PM 260272 32 C:\cmldr
9/23/2009 7:29:30 PM 2891 32 C:\Files.txt
9/17/2009 3:58:46 PM 2381452 32 C:\MGtools.exe
9/18/2009 1:44:16 PM 2817024 32 C:\mvt_en-us.msi
9/18/2009 1:59:08 PM 26709200 32 C:\sdsetup_aff.exe
9/22/2009 9:41:51 AM 47616 32 C:\Win32kDiag.exe
8/16/2009 5:17:47 PM 2715100 C:\WINDOWS\$NtUninstallKB956744$
8/16/2009 5:17:47 PM 628700 C:\WINDOWS\$NtUninstallKB956744$\spuninst
9/13/2009 5:01:11 PM 778714 C:\WINDOWS\$NtUninstallKB956844$
9/13/2009 5:01:11 PM 625626 C:\WINDOWS\$NtUninstallKB956844$\spuninst
8/16/2009 5:18:42 PM 779522 C:\WINDOWS\$NtUninstallKB960859$
8/16/2009 5:18:42 PM 625410 C:\WINDOWS\$NtUninstallKB960859$\spuninst
8/16/2009 5:18:11 PM 1713059 C:\WINDOWS\$NtUninstallKB961118$
8/16/2009 5:18:11 PM 624219 C:\WINDOWS\$NtUninstallKB961118$\spuninst
9/20/2009 5:00:52 PM 2133612 C:\WINDOWS\$NtUninstallKB968389$
9/20/2009 5:00:52 PM 629228 C:\WINDOWS\$NtUninstallKB968389$\spuninst
9/13/2009 5:01:17 PM 3083292 C:\WINDOWS\$NtUninstallKB968816_WM9$
9/13/2009 5:01:17 PM 625180 C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst
8/30/2009 5:00:20 PM 837761 C:\WINDOWS\$NtUninstallKB970653-v3$
8/30/2009 5:00:20 PM 639617 C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst
8/16/2009 5:18:04 PM 709787 C:\WINDOWS\$NtUninstallKB971557$
8/16/2009 5:18:04 PM 624795 C:\WINDOWS\$NtUninstallKB971557$\spuninst
8/16/2009 5:18:36 PM 756978 C:\WINDOWS\$NtUninstallKB971657$
8/16/2009 5:18:36 PM 624882 C:\WINDOWS\$NtUninstallKB971657$\spuninst
9/13/2009 5:01:01 PM 1140715 C:\WINDOWS\$NtUninstallKB971961$
9/13/2009 5:01:01 PM 628715 C:\WINDOWS\$NtUninstallKB971961$\spuninst
8/16/2009 5:16:10 PM 1939550 C:\WINDOWS\$NtUninstallKB973354$
8/16/2009 5:16:10 PM 624734 C:\WINDOWS\$NtUninstallKB973354$\spuninst
8/16/2009 5:16:57 PM 683490 C:\WINDOWS\$NtUninstallKB973507$
8/16/2009 5:16:57 PM 624610 C:\WINDOWS\$NtUninstallKB973507$\spuninst
8/16/2009 5:15:16 PM 11777851 C:\WINDOWS\$NtUninstallKB973540_WM9$
8/16/2009 5:15:16 PM 624955 C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst
8/16/2009 5:11:01 PM 828632 C:\WINDOWS\$NtUninstallKB973815$
8/16/2009 5:11:01 PM 624856 C:\WINDOWS\$NtUninstallKB973815$\spuninst
8/16/2009 5:17:34 PM 753427 C:\WINDOWS\$NtUninstallKB973869$
8/16/2009 5:17:34 PM 624915 C:\WINDOWS\$NtUninstallKB973869$\spuninst
9/17/2009 8:17:52 PM 134123304 C:\WINDOWS\ERDNT
9/17/2009 9:18:41 PM 21269544 C:\WINDOWS\ERDNT\cache
9/17/2009 8:41:37 PM 56417609 C:\WINDOWS\ERDNT\Hiv-backup
9/17/2009 8:43:15 PM 4878336 C:\WINDOWS\ERDNT\Hiv-backup\Users
9/17/2009 8:43:15 PM 237568 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000001
9/17/2009 8:43:15 PM 8192 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000002
9/17/2009 8:43:15 PM 237568 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000003
9/17/2009 8:43:15 PM 8192 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000004
9/17/2009 8:43:15 PM 4206592 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000005
9/17/2009 8:43:15 PM 180224 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000006
9/17/2009 9:07:47 PM 56436041 C:\WINDOWS\ERDNT\subs
9/17/2009 9:07:48 PM 4878336 C:\WINDOWS\ERDNT\subs\Users
9/17/2009 9:07:48 PM 237568 C:\WINDOWS\ERDNT\subs\Users\00000001
9/17/2009 9:07:48 PM 8192 C:\WINDOWS\ERDNT\subs\Users\00000002
9/17/2009 9:07:48 PM 237568 C:\WINDOWS\ERDNT\subs\Users\00000003
9/17/2009 9:07:48 PM 8192 C:\WINDOWS\ERDNT\subs\Users\00000004
9/17/2009 9:07:48 PM 4206592 C:\WINDOWS\ERDNT\subs\Users\00000005
9/17/2009 9:07:49 PM 180224 C:\WINDOWS\ERDNT\subs\Users\00000006
9/22/2009 2:17:05 PM 0 C:\WINDOWS\LastGood
9/22/2009 2:17:05 PM 0 C:\WINDOWS\LastGood\INF
9/17/2009 1:18:57 PM 1134 C:\WINDOWS\pss
8/9/2009 5:08:53 PM 0 C:\WINDOWS\SxsCaPendDel
9/21/2009 1:19:38 PM 0 32 C:\WINDOWS\0.log
9/17/2009 8:30:46 PM 80412 32 C:\WINDOWS\grep.exe
9/17/2009 8:30:46 PM 31232 32 C:\WINDOWS\NIRCMD.exe
9/17/2009 8:30:46 PM 229888 32 C:\WINDOWS\PEV.exe
9/17/2009 8:30:46 PM 98816 32 C:\WINDOWS\sed.exe
9/21/2009 2:24:54 PM 19550 32 C:\WINDOWS\setupapi.log
9/17/2009 8:30:46 PM 161792 32 C:\WINDOWS\SWREG.exe
9/17/2009 8:30:46 PM 136704 32 C:\WINDOWS\SWSC.exe
9/17/2009 8:30:46 PM 212480 32 C:\WINDOWS\SWXCACLS.exe
9/17/2009 8:30:46 PM 68096 32 C:\WINDOWS\zip.exe
9/7/2009 2:23:48 PM 8635090 C:\WINDOWS\system32\Adobe
9/7/2009 2:23:48 PM 337996 C:\WINDOWS\system32\Adobe\Director
9/7/2009 2:23:49 PM 8297094 C:\WINDOWS\system32\Adobe\Shockwave 11
9/7/2009 2:23:49 PM 441435 C:\WINDOWS\system32\Adobe\Shockwave 11\Xtras
9/7/2009 2:32:38 PM 0 C:\WINDOWS\system32\Adobe\update
9/18/2009 9:09:25 PM 7899334 C:\WINDOWS\system32\CatRoot2
9/18/2009 9:09:25 PM 1056776 C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}
9/18/2009 9:09:27 PM 4202504 C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}
8/9/2009 5:10:10 PM 379588 C:\WINDOWS\system32\XPSViewer
8/9/2009 5:10:10 PM 3584 C:\WINDOWS\system32\XPSViewer\en-US
9/21/2009 2:15:07 PM 389120 32 C:\WINDOWS\system32\CF24962.exe
9/21/2009 2:12:07 PM 389120 32 C:\WINDOWS\system32\cmd.execf
9/18/2009 11:05:44 AM 6 32 C:\WINDOWS\system32\MSHC.DLL
8/9/2009 5:09:19 PM 117760 0 C:\WINDOWS\system32\prntvpt.dll
8/9/2009 5:09:19 PM 575488 0 C:\WINDOWS\system32\xpsshhdr.dll
8/9/2009 5:09:18 PM 1676288 0 C:\WINDOWS\system32\xpssvcs.dll
====== Files under "\Administrator\Startup" Last 60 Days======
====== Files under "\All Users\Startup" Last 60 Days======
====== Files and Folders under "\Program Files" Last 60 Days======
9/21/2009 11:21:52 AM 2752091 C:\Program Files\CCleaner
8/31/2009 6:40:53 PM 304608 C:\Program Files\DIFX
8/31/2009 6:40:51 PM 122949 C:\Program Files\Garmin
8/31/2009 6:40:55 PM 11097472 C:\Program Files\Garmin GPS Plugin
9/22/2009 10:46:37 AM 4088142 C:\Program Files\Malwarebytes' Anti-Malware
8/9/2009 5:10:06 PM 25757 C:\Program Files\MSBuild
8/9/2009 5:09:59 PM 36351745 C:\Program Files\Reference Assemblies
9/17/2009 4:02:22 PM 27879484 C:\Program Files\SUPERAntiSpyware
9/17/2009 12:05:42 PM 406424 C:\Program Files\Trend Micro
====== Files under "\System32\Drivers" Last 60 Days======
9/22/2009 10:46:37 AM 19160 32 C:\WINDOWS\system32\drivers\mbam.sys
9/22/2009 10:46:39 AM 38224 32 C:\WINDOWS\system32\drivers\mbamswissarmy.sys
====== Files Deleted under "%Temp%" ======
149 Files deleted
====== Files and Folders under "All Users\Application Data" Last 60 Days======
7/30/2009 2:27:05 PM 16382351 C:\Documents and Settings\All Users\Application Data\AOL Downloads
7/30/2009 2:27:05 PM 16382351 C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4426
7/30/2009 2:27:05 PM 213285 C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4426\html
7/30/2009 2:27:05 PM 2224 C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4426\html\images
8/31/2009 7:18:32 PM 1676118985 C:\Documents and Settings\All Users\Application Data\GARMIN
8/31/2009 7:18:32 PM 1676118985 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps
8/31/2009 7:19:07 PM 1676118985 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap
8/31/2009 7:19:57 PM 473991476 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\CNNANT_2010_20_mdr
8/31/2009 7:19:07 PM 1179837589 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1
8/31/2009 7:21:14 PM 6344323 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323483
8/31/2009 7:21:12 PM 11550146 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323484
8/31/2009 7:21:10 PM 6709671 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323485
8/31/2009 7:21:09 PM 4129177 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323486
8/31/2009 7:21:09 PM 319942 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323487
8/31/2009 7:21:10 PM 717131 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323488
8/31/2009 7:21:10 PM 1296953 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323489
8/31/2009 7:19:53 PM 7642162 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323490
8/31/2009 7:19:53 PM 1903759 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323491
8/31/2009 7:19:54 PM 848751 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323492
8/31/2009 7:19:54 PM 2963052 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323493
8/31/2009 7:19:53 PM 6256278 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323494
8/31/2009 7:19:51 PM 4399460 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323495
8/31/2009 7:19:51 PM 7212834 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323496
8/31/2009 7:19:52 PM 12357791 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323497
8/31/2009 7:19:51 PM 7229362 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323498
8/31/2009 7:19:54 PM 662081 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323499
8/31/2009 7:19:56 PM 13094097 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323500
8/31/2009 7:19:56 PM 1424856 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323501
8/31/2009 7:19:57 PM 269658 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323502
8/31/2009 7:19:57 PM 1185977 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323503
8/31/2009 7:19:56 PM 6619005 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323504
8/31/2009 7:19:54 PM 2664727 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323505
8/31/2009 7:19:54 PM 8006970 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323506
8/31/2009 7:19:55 PM 8714754 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323507
8/31/2009 7:19:55 PM 8215278 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323508
8/31/2009 7:21:54 PM 5008732 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323509
8/31/2009 7:21:53 PM 11586988 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323510
8/31/2009 7:21:55 PM 6636204 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323511
8/31/2009 7:21:55 PM 6173104 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323512
8/31/2009 7:21:50 PM 9292224 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323513
8/31/2009 7:21:45 PM 14153540 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323514
8/31/2009 7:21:44 PM 15928731 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323515
8/31/2009 7:21:48 PM 15871417 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323516
8/31/2009 7:21:46 PM 13704229 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323518
8/31/2009 7:21:56 PM 16368816 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323519
8/31/2009 7:22:07 PM 22510732 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323520
8/31/2009 7:22:06 PM 13720123 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323521
8/31/2009 7:22:26 PM 20129048 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323522
8/31/2009 7:22:19 PM 18608315 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323523
8/31/2009 7:22:04 PM 17060578 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323524
8/31/2009 7:22:01 PM 15367788 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323525
8/31/2009 7:21:58 PM 16452075 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323526
8/31/2009 7:22:03 PM 9457832 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323527
8/31/2009 7:22:02 PM 12093755 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323528
8/31/2009 7:21:27 PM 18400672 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323529
8/31/2009 7:21:22 PM 14281138 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323530
8/31/2009 7:21:35 PM 9991437 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323531
8/31/2009 7:21:31 PM 16089448 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323532
8/31/2009 7:21:20 PM 16230633 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323533
8/31/2009 7:21:18 PM 6496702 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323534
8/31/2009 7:21:15 PM 10025424 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323535
8/31/2009 7:21:20 PM 4149884 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323536
8/31/2009 7:21:19 PM 4294703 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323537
8/31/2009 7:21:38 PM 10804057 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323538
8/31/2009 7:21:41 PM 10147385 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323539
8/31/2009 7:21:41 PM 11161270 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323540
8/31/2009 7:21:43 PM 19629962 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323541
8/31/2009 7:21:42 PM 8092052 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323542
8/31/2009 7:21:41 PM 5584845 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323543
8/31/2009 7:21:40 PM 5119664 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323544
8/31/2009 7:21:39 PM 9312834 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323545
8/31/2009 7:21:40 PM 4004221 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323546
8/31/2009 7:21:40 PM 4065497 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323547
8/31/2009 7:19:51 PM 4990143 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323548
8/31/2009 7:19:26 PM 3686938 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323549
8/31/2009 7:19:24 PM 12915754 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323550
8/31/2009 7:19:27 PM 9222973 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323551
8/31/2009 7:19:27 PM 1449830 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323552
8/31/2009 7:19:24 PM 6663467 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323553
8/31/2009 7:19:23 PM 1215995 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323554
8/31/2009 7:19:22 PM 9598927 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323555
8/31/2009 7:19:23 PM 7879312 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323556
8/31/2009 7:19:23 PM 2988718 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323557
8/31/2009 7:19:27 PM 6243408 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323558
8/31/2009 7:19:31 PM 19411327 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323559
8/31/2009 7:19:31 PM 5735950 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323560
8/31/2009 7:19:32 PM 5390407 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323561
8/31/2009 7:19:32 PM 233711 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323562
8/31/2009 7:19:30 PM 2744107 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323563
8/31/2009 7:19:29 PM 2948276 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323564
8/31/2009 7:19:28 PM 7649632 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323565
8/31/2009 7:19:29 PM 17198695 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323566
8/31/2009 7:19:29 PM 3241624 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323567
8/31/2009 7:19:12 PM 7910516 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323568
8/31/2009 7:19:12 PM 1659369 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323569
8/31/2009 7:19:14 PM 15790185 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323570
8/31/2009 7:19:13 PM 23465724 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323571
8/31/2009 7:19:11 PM 14890800 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323572
8/31/2009 7:19:08 PM 555581 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323573
8/31/2009 7:19:07 PM 8381302 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323574
8/31/2009 7:19:10 PM 14382491 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323575
8/31/2009 7:19:08 PM 16660042 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323576
8/31/2009 7:19:15 PM 4768368 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323577
8/31/2009 7:19:19 PM 10901590 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323578
8/31/2009 7:19:18 PM 3653618 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323579
8/31/2009 7:19:21 PM 14800430 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323580
8/31/2009 7:19:19 PM 14638814 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323581
8/31/2009 7:19:18 PM 10529009 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323582
8/31/2009 7:19:16 PM 17996874 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323583
8/31/2009 7:19:15 PM 1600593 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323584
8/31/2009 7:19:17 PM 13074100 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323585
8/31/2009 7:19:17 PM 8141695 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323586
8/31/2009 7:19:44 PM 5885239 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323587
8/31/2009 7:19:43 PM 1373166 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323588
8/31/2009 7:19:45 PM 4051564 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323589
8/31/2009 7:19:44 PM 14188217 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323590
8/31/2009 7:19:43 PM 3654246 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323591
8/31/2009 7:19:40 PM 4249528 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323592
8/31/2009 7:19:39 PM 10300809 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323593
8/31/2009 7:19:41 PM 19862776 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323594
8/31/2009 7:19:41 PM 8080702 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323595
8/31/2009 7:19:45 PM 22676458 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323596
8/31/2009 7:19:49 PM 8779989 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323597
8/31/2009 7:19:49 PM 1171411 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323598
8/31/2009 7:19:50 PM 4270350 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323599
8/31/2009 7:19:50 PM 6467322 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323600
8/31/2009 7:19:49 PM 6493764 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323601
8/31/2009 7:19:48 PM 3003055 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323602
8/31/2009 7:19:47 PM 15693218 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323603
8/31/2009 7:19:48 PM 9676201 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323604
8/31/2009 7:19:48 PM 4774445 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323605
8/31/2009 7:19:35 PM 141534 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323606
8/31/2009 7:19:35 PM 147668 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323607
8/31/2009 7:19:35 PM 176685 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323608
8/31/2009 7:19:35 PM 7014137 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323933
8/31/2009 7:19:35 PM 4088543 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323934
8/31/2009 7:19:32 PM 12634694 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323935
8/31/2009 7:19:32 PM 2683883 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323936
8/31/2009 7:19:34 PM 15884643 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323937
8/31/2009 7:19:33 PM 6194218 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323938
8/31/2009 7:19:36 PM 10659573 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323939
8/31/2009 7:19:37 PM 13925515 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323940
8/31/2009 7:19:37 PM 13143203 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323974
8/31/2009 7:19:38 PM 12569984 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\00323975
8/31/2009 7:19:36 PM 9836987 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\CNNANT_2010_20
8/31/2009 7:19:37 PM 12950 C:\Documents and Settings\All Users\Application Data\GARMIN\Maps\City Navigator North America NT 2010.20.gmap\Product1\Logos
9/17/2009 10:50:58 AM 2825154 C:\Documents and Settings\All Users\Application Data\Malwarebytes
9/17/2009 10:50:58 AM 2825154 C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware
9/18/2009 9:42:46 PM 3835 C:\Documents and Settings\All Users\Application Data\Simply Super Software
9/18/2009 9:42:46 PM 3835 C:\Documents and Settings\All Users\Application Data\Simply Super Software\Trojan Remover
9/18/2009 9:42:46 PM 3835 C:\Documents and Settings\All Users\Application Data\Simply Super Software\Trojan Remover\Data
9/17/2009 4:02:34 PM 0 C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
9/17/2009 4:02:34 PM 0 C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware
9/18/2009 2:00:03 PM 0 C:\Documents and Settings\All Users\Application Data\TEMP
====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======
HKLM\Software\microsoft\shared tools\msconfig\startupreg\
====== Services ( Services that are Whitelisted are not shown) ======
DLABMFSM (DLABMFSM)- C:\WINDOWS\system32\DLA\DLABMFSM.SYS - Auto/Running
DLABOIOM (DLABOIOM)- C:\WINDOWS\system32\DLA\DLABOIOM.SYS - Auto/Running
DLACDBHM (DLACDBHM)- C:\WINDOWS\system32\Drivers\DLACDBHM.SYS - System/Running
DLADResM (DLADResM)- C:\WINDOWS\system32\DLA\DLADResM.SYS - Auto/Running
DLAIFS_M (DLAIFS_M)- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS - Auto/Running
DLAOPIOM (DLAOPIOM)- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS - Auto/Running
DLAPoolM (DLAPoolM)- C:\WINDOWS\system32\DLA\DLAPoolM.SYS - Auto/Running
DLARTL_M (DLARTL_M)- C:\WINDOWS\system32\Drivers\DLARTL_M.SYS - System/Running
DLAUDFAM (DLAUDFAM)- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS - Auto/Running
DLAUDF_M (DLAUDF_M)- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS - Auto/Running
DRVMCDB (DRVMCDB)- C:\WINDOWS\system32\Drivers\DRVMCDB.SYS - Boot/Running
DRVNDDM (DRVNDDM)- C:\WINDOWS\system32\Drivers\DRVNDDM.SYS - Auto/Running
DSproct (DSproct)- \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys - Manual/Running
dsunidrv (DellSupport UniDriver)- C:\WINDOWS\system32\DRIVERS\dsunidrv.sys - Auto/Running
E100B (Intel(R) PRO Adapter Driver)- C:\WINDOWS\system32\DRIVERS\e100b325.sys - Manual/Stopped
e1express (Intel(R) PRO/1000 PCI Express Network Connection Driver)- C:\WINDOWS\system32\DRIVERS\e1e5132.sys - Manual/Running
iaStor (Intel RAID Controller)- C:\WINDOWS\system32\drivers\iaStor.sys - Boot/Running
SASDIFSV (SASDIFSV)- \??\C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS - System/Running
SASENUM (SASENUM)- \??\C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS - Manual/Stopped
SASKUTIL (SASKUTIL)- \??\C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys - System/Running
USBAAPL (Apple Mobile USB Driver)- C:\WINDOWS\system32\Drivers\usbaapl.sys - Manual/Stopped
====== Uninstall List ======
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
ABC (remove only)
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Shockwave Player 11.5
AIM 6
Business Contact Manager for Outlook 2007
CCleaner (remove only)
Conexant D850 56K V.9x DFVc Modem
Comcast High-Speed Internet Install Wizard
Intel(R) Graphics Media Accelerator Driver
HijackThis 2.0.2
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
HP Photosmart Premier Software 6.5
HP Solution Center 7.0
HP Customer Participation Program 7.0
OCR Software by I.R.I.S 7.0
Microsoft Internationalized Domain Names Mitigation APIs
Windows Internet Explorer 7
Canon Utilities PhotoStitch 3.1
Canon Camera Window for ZoomBrowser EX
Canon Utilities RemoteCapture 2.7
Canon Utilities File Viewer Utility 1.2
High Definition Audio Driver Package - KB835221
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Hotfix for Windows Media Format SDK (KB902344)
Security Update for Windows Media Player (KB911564)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows XP (KB923789)
Security Update for Windows Media Player 6.4 (KB925398)
Hotfix for Windows Media Format 11 SDK (KB929399)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows Internet Explorer 7 (KB939653)
Hotfix for Windows Media Player 11 (KB939683)
Security Update for Windows XP (KB941569)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows XP (KB946648)
Hotfix for Windows Internet Explorer 7 (KB947864)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Update for Windows XP (KB951072-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Update for Windows XP (KB951978)
Security Update for Windows XP (KB952004)
Security Update for Windows Media Player (KB952069)
Hotfix for Windows XP (KB952287)
Security Update for Windows XP (KB952954)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Hotfix for Windows XP (KB954550-v5)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Update for Windows XP (KB955839)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Critical Update for Windows Media Player 11 (KB959772)
Security Update for Windows XP (KB960225)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Hotfix for Windows XP (KB961118)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows Internet Explorer 7 (KB963027)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Security Update for Windows XP (KB968537)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Hotfix for Windows XP (KB970653-v3)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows Media Player (KB973540)
Update for Windows XP (KB973815)
Security Update for Windows XP (KB973869)
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 3.5 SP1
Microsoft SQL Server 2005
Mozilla Firefox (3.0.14)
McAfee SecurityCenter
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft National Language Support Downlevel APIs
Canon PhotoRecord
Picasa 3
Intel(R) PRO Network Connections Drivers
RealPlayer
Microsoft Office Small Business 2007
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Notifications (KB905474)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Windows Media Format 11 runtime
Windows Media Player 11
Microsoft User-Mode Driver Framework Feature Pack 1.0
Roxio Creator Tools
PhotoStitch
Bonjour
Camera Window
SlideShow
MSXML 6.0 Parser (KB933579)
Roxio Creator Data
Microsoft Plus! Photo Story 2 LE
cp_OnlineProjectsConfig
HPPhotoSmartExpress
PowerDVD
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
Dell DataSafe Online
Roxio Drag-to-Disc
Sonic_PrimoSDK
Roxio Update Manager
Windows Media Player 10
SkinsHP1
WebFldrs XP
Sonic Activation Module
PanoStandAlone
HP Product Assistant
RCT High Value - Standalone
NetWaiting
CP_Package_Basic1
BufferChm
Banctec Service Agreement
HPProductAssistant
Microsoft Office 2007 Primary Interop Assemblies
Microsoft SQL Server Native Client
FullDPAppQFolder
Microsoft SQL Server Setup Support Files (English)
c4100_Help
Dell Driver Reset Tool
iTunes
Roxio Creator Copy
Browser Address Error Redirector
Roxio Express Labeler
WebReg
RandMap
eSupportQFolder
AiOSoftwareNPI
Toolbox
Apple Software Update
Microsoft Plus! Digital Media Edition Installer
CustomerResearchQFolder
Readme
Dell System Restore
DocumentViewerQFolder
ProductContextNPI
DellSupport
Status
Apple Mobile Device Support
Roxio Creator Audio
MSXML 4.0 SP2 (KB954430)
DocProcQFolder
Roxio Creator BDAV Plugin
DocProc
Unload
Microsoft Software Update for Web Folders (English) 12
Microsoft Office Excel MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office 2003 Web Components
Microsoft Office Small Business 2007
Residential Component Technology - Standalone
ScannerCopy
InstantShareDevices
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft Office Small Business Connectivity Components
HP Photosmart and Deskjet 7.0.A
DeviceManagementQFolder
Adobe Reader 8.1.3
Documentation & Support Launcher
Garmin USB Drivers
cp_PosterPrintConfig
Business Contact Manager for Outlook 2007
Garmin Communicator Plugin
CueTour
Games, Music, & Photos Launcher
CP_Panorama1Config
RemoteCapture 2.7.0
MSXML 4.0 SP2 (KB936181)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft SQL Server VSS Writer
PhotoGallery
Canon Utilities ZoomBrowser EX
Modem Diagnostic Tool
Garmin City Navigator North America NT 2010.20
QuickTime
SolutionCenter
C4100
AiO_Scan_CDA
Roxio Creator DE
HP Update
Microsoft .NET Framework 1.1
SUPERAntiSpyware Free Edition
Microsoft .NET Framework 3.5 SP1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Roxio MyDVD DE
Desktop Doctor
TrayApp
AnswerWorks 5.0 English Runtime
MobileMe Control Panel
MarketResearch
Dell Support Center (Support Software)
Internet Service Offers Launcher
Digital Line Detect
Yahoo! Music Jukebox
Quicken 2009
CP_CalendarTemplates1
File Viewer Utility 1.2
Realtek High Definition Audio Driver
InstantShareDevicesMFC
Scan
Fax_CDA
Destinations
NewCopy_CDA
DocumentViewer
======== Other Info ========
TOTAL PHYSICAL RAM: 1062 MB
Boot Info
[boot loader]
timeout=3
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
OS Type: Microsoft Windows XP Professional
Build: 5.1.2600
Service Pack: 3.0
====== Files with Hidden Attributes======
C:\hiberfil.sys
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\NTDETECT.COM
C:\dell\ZbThumbnail.info
C:\Documents and Settings\Administrator\NTUSER.DAT
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
==End of Report==
bamajim
10.4K Posts
0
September 24th, 2009 07:00
Your log shows that you ran Combofix. Please post the Combofix log in your reply (C:\ComboFix.txt)
lafond0822
5 Posts
0
September 24th, 2009 09:00
Here is my ComboFix log. Thanks.
ComboFix 09-09-17.04 - Justin Lafond 09/17/2009 20:45.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.572 [GMT -4:00]
Running from: c:\combofix\ComboFix.exe
Command switches used :: ComboFix
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Justin Lafond\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
c:\documents and settings\Justin Lafond\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
c:\documents and settings\Justin Lafond\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
c:\documents and settings\Justin Lafond\My Documents\ZbThumbnail.info
c:\windows\ALCMTR.EXE
c:\windows\Installer\4b240c0.msi
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\system32\bennuar.old
c:\windows\system32\bincd32.dat
c:\windows\system32\desot.exe
c:\windows\system32\drivers\rotscxxypylbjt.sys
c:\windows\system32\MSHC.DLL
c:\windows\system32\rotscxbomigukb.dll
c:\windows\system32\rotscxdiuuwfpx.dat
c:\windows\system32\rotscxdjnkoowl.dat
c:\windows\system32\rotscxiostenkr.dll
c:\windows\system32\rotscxipooylns.dll
c:\windows\system32\sonhelp.htm
c:\windows\system32\sysnet.dat
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_rotscxeqltbvsd
-------\Legacy_rotscxeqltbvsd
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-08-18 to 2009-09-18 )))))))))))))))))))))))))))))))
.
2009-09-17 21:22 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-17 21:22 . 2009-09-17 21:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-17 21:22 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-17 20:02 . 2009-09-17 20:02 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-17 20:02 . 2009-09-18 00:59 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-17 20:02 . 2009-09-17 20:02 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\SUPERAntiSpyware.com
2009-09-17 20:01 . 2009-09-17 20:01 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-17 19:58 . 2009-09-17 19:58 2381322 ----a-w- C:\MGtools.exe
2009-09-17 17:14 . 2009-09-17 17:14 -------- d-----w- c:\program files\CCleaner
2009-09-17 16:05 . 2009-09-17 16:05 -------- d-----w- c:\program files\Trend Micro
2009-09-17 14:51 . 2009-09-17 14:51 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\Malwarebytes
2009-09-17 14:50 . 2009-09-17 14:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-17 14:03 . 2009-09-17 21:09 0 ----a-w- c:\windows\win32k.sys
2009-09-07 18:23 . 2009-09-07 18:32 -------- d-----w- c:\windows\system32\Adobe
2009-08-31 23:18 . 2009-08-31 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\GARMIN
2009-08-31 23:18 . 2009-08-31 23:19 -------- d-----w- C:\Garmin
2009-08-31 22:43 . 2009-08-31 23:08 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\Download Manager
2009-08-31 22:41 . 2009-08-31 23:17 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\GARMIN
2009-08-31 22:40 . 2009-08-31 22:40 -------- d-----w- c:\program files\Garmin GPS Plugin
2009-08-31 22:40 . 2009-08-31 22:40 -------- d-----w- c:\program files\DIFX
2009-08-31 22:40 . 2009-08-31 22:40 -------- d-----w- c:\program files\Garmin
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-17 23:35 . 2007-10-27 01:14 -------- d-----w- c:\program files\McAfee
2009-09-17 21:08 . 2007-12-03 14:54 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-17 17:27 . 2007-10-27 01:01 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-09-17 17:11 . 2008-02-20 03:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-09-14 11:01 . 2007-10-26 23:21 89384 -c--a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-10 15:13 . 2007-10-10 07:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell
2009-09-10 15:00 . 2008-01-10 04:42 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\Apple Computer
2009-08-28 13:25 . 2009-07-20 22:55 -------- d-----w- c:\program files\RCT High Value
2009-08-09 23:34 . 2007-10-10 08:15 89384 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-09 21:10 . 2009-08-09 21:10 -------- d-----w- c:\program files\MSBuild
2009-08-09 21:09 . 2009-08-09 21:09 -------- d-----w- c:\program files\Reference Assemblies
2009-08-05 09:01 . 2004-08-11 22:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-30 18:27 . 2008-02-20 03:14 -------- d-----w- c:\program files\AIM6
2009-07-30 18:27 . 2009-07-30 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-07-20 22:55 . 2007-10-10 07:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-17 19:01 . 2004-08-11 22:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 16:32 . 2007-10-27 01:14 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-07-14 03:43 . 2004-08-11 22:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-08 17:44 . 2007-10-27 01:15 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-07-08 17:44 . 2007-10-27 01:15 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-07-08 17:44 . 2007-10-27 01:15 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-07-08 17:44 . 2007-10-27 01:15 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-07-08 17:43 . 2007-10-27 01:15 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-06-29 16:12 . 2004-08-11 22:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-11 22:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-11 22:00 17408 ------w- c:\windows\system32\corpol.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-01-03 50528]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-15 1998576]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-10 645328]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-09-08 185896]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-07-17 16132608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-10-10 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-06-11 19:00 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [4/14/2006 11:07 AM 28933976]
S2 AntipPolice_;AntiPol;c:\windows\svchast.exe --> c:\windows\svchast.exe [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-09-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]
2008-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-10-27 01:26]
2008-11-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-10-27 01:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Justin Lafond\Application Data\Mozilla\Firefox\Profiles\zj6iejmr.default\
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-17 21:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\WININET.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
- - - - - - - > 'lsass.exe'(788)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(1120)
c:\windows\system32\WININET.dll
tdlwsp.dll 10000000 36864 \\?\globalroot\Device\Ide\IdePort3\wentsppe\wentsppe\tdlwsp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\igfxsrvc.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-09-18 21:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-18 01:24
Pre-Run: 271,585,959,936 bytes free
Post-Run: 274,019,536,896 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
261 --- E O F --- 2009-09-13 21:03
bamajim
10.4K Posts
0
September 24th, 2009 12:00
1. Open NotePad (not wordpad). Copy and paste the following into Notepad
Driver::
AntipPolice_
Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop
Using the Image as a reference, drag CFScript into ComboFix.exe
Following the same rules as indicated in my first post
Then post the contents of the C:\ComboFix.txt log in your reply
lafond0822
5 Posts
0
September 24th, 2009 16:00
Here is the log. Thanks.
ComboFix 09-09-23.02 - Justin Lafond 09/24/2009 17:37.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.473 [GMT -4:00]
Running from: c:\documents and settings\Justin Lafond\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Justin Lafond\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ANTIPPOLICE_
((((((((((((((((((((((((( Files Created from 2009-08-24 to 2009-09-24 )))))))))))))))))))))))))))))))
.
2009-09-23 16:59 . 2009-09-23 16:59 -------- d-----w- c:\documents and settings\Lisa Lafond\Application Data\Malwarebytes
2009-09-22 14:48 . 2009-09-22 14:48 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-22 14:46 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-22 14:46 . 2009-09-22 14:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-22 14:46 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-22 13:41 . 2009-09-22 13:41 47616 ----a-w- C:\Win32kDiag.exe
2009-09-21 15:21 . 2009-09-21 15:21 -------- d-----w- c:\program files\CCleaner
2009-09-19 19:03 . 2009-09-19 19:03 -------- d-----w- c:\documents and settings\Anne Lafond\Application Data\Malwarebytes
2009-09-19 01:42 . 2009-09-19 01:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-09-19 01:09 . 2009-09-24 21:35 -------- d-----w- c:\windows\system32\CatRoot2
2009-09-18 18:00 . 2009-09-18 18:17 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-18 17:59 . 2009-09-18 17:59 26709200 ----a-w- C:\sdsetup_aff.exe
2009-09-18 17:44 . 2009-09-18 17:44 2817024 ----a-w- C:\mvt_en-us.msi
2009-09-18 01:35 . 2009-09-21 23:16 -------- d-----w- C:\MGtools
2009-09-18 01:31 . 2009-09-18 01:31 0 ----a-w- c:\documents and settings\Justin Lafond\settings.dat
2009-09-17 20:02 . 2009-09-17 20:02 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-17 20:02 . 2009-09-22 14:49 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-17 20:02 . 2009-09-22 14:48 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\SUPERAntiSpyware.com
2009-09-17 19:58 . 2009-09-21 16:15 2381452 ----a-w- C:\MGtools.exe
2009-09-17 16:05 . 2009-09-21 23:18 -------- d-----w- c:\program files\Trend Micro
2009-09-17 14:51 . 2009-09-17 14:51 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\Malwarebytes
2009-09-17 14:50 . 2009-09-17 14:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-07 18:23 . 2009-09-07 18:32 -------- d-----w- c:\windows\system32\Adobe
2009-08-31 23:18 . 2009-08-31 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\GARMIN
2009-08-31 23:18 . 2009-08-31 23:19 -------- d-----w- C:\Garmin
2009-08-31 22:43 . 2009-08-31 23:08 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\Download Manager
2009-08-31 22:41 . 2009-08-31 23:17 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\GARMIN
2009-08-31 22:40 . 2009-08-31 22:40 -------- d-----w- c:\program files\Garmin GPS Plugin
2009-08-31 22:40 . 2009-08-31 22:40 -------- d-----w- c:\program files\DIFX
2009-08-31 22:40 . 2009-08-31 22:40 -------- d-----w- c:\program files\Garmin
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-24 20:20 . 2007-10-27 01:14 -------- d-----w- c:\program files\McAfee
2009-09-19 01:06 . 2009-03-26 16:26 61480 -c--a-w- c:\documents and settings\Justin Lafond\GoToAssistDownloadHelper.exe
2009-09-18 17:45 . 2007-12-03 14:54 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\McAfee
2009-09-18 17:45 . 2007-10-27 01:01 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-09-17 21:08 . 2007-12-03 14:54 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-17 17:11 . 2008-02-20 03:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-09-14 11:01 . 2007-10-26 23:21 89384 -c--a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-10 15:13 . 2007-10-10 07:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell
2009-09-10 15:00 . 2008-01-10 04:42 -------- d-----w- c:\documents and settings\Justin Lafond\Application Data\Apple Computer
2009-08-28 13:25 . 2009-07-20 22:55 -------- d-----w- c:\program files\RCT High Value
2009-08-09 23:34 . 2007-10-10 08:15 89384 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-09 21:10 . 2009-08-09 21:10 -------- d-----w- c:\program files\MSBuild
2009-08-09 21:09 . 2009-08-09 21:09 -------- d-----w- c:\program files\Reference Assemblies
2009-08-05 09:01 . 2004-08-11 22:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-30 18:27 . 2008-02-20 03:14 -------- d-----w- c:\program files\AIM6
2009-07-30 18:27 . 2009-07-30 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-07-17 19:01 . 2004-08-11 22:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 16:32 . 2007-10-27 01:14 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-07-14 03:43 . 2004-08-11 22:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-08 17:44 . 2007-10-27 01:15 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-07-08 17:44 . 2007-10-27 01:15 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-07-08 17:44 . 2007-10-27 01:15 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-07-08 17:44 . 2007-10-27 01:15 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-07-08 17:43 . 2007-10-27 01:15 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-06-29 16:12 . 2004-08-11 22:00 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-11 22:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-11 22:00 17408 ------w- c:\windows\system32\corpol.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-24_21.21.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-10-26 23:12 . 2009-09-24 21:59 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-26 23:12 . 2009-09-24 21:13 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-10-26 23:12 . 2009-09-24 21:59 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-26 23:12 . 2009-09-24 21:13 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-10-26 23:12 . 2009-09-24 21:59 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-10-26 23:12 . 2009-09-24 21:13 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-01-03 50528]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-15 1998576]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-10 645328]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-07-17 16132608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-10-10 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [4/14/2006 11:07 AM 28933976]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\JUSTIN~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS --> c:\docume~1\JUSTIN~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\JUSTIN~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys --> c:\docume~1\JUSTIN~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys [?]
S2 0283751253812088mcinstcleanup;McAfee Application Installer Cleanup (0283751253812088);c:\windows\TEMP\028375~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\028375~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S3 SASENUM;SASENUM;\??\c:\docume~1\JUSTIN~1\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS --> c:\docume~1\JUSTIN~1\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS [?]
.
Contents of the 'Scheduled Tasks' folder
2009-09-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]
2008-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-10-27 01:26]
2008-11-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-10-27 01:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\documents and settings\Justin Lafond\Application Data\Mozilla\Firefox\Profiles\zj6iejmr.default\
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-24 18:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\WININET.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'lsass.exe'(788)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3344)
c:\windows\system32\WININET.dll
tdlwsp.dll 10000000 36864 \\?\globalroot\Device\Ide\IdePort3\tvpwibcr\tvpwibcr\tdlwsp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\igfxsrvc.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-09-24 18:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-24 22:12
ComboFix2.txt 2009-09-24 21:29
Pre-Run: 274,613,096,448 bytes free
Post-Run: 274,578,104,320 bytes free
241 --- E O F --- 2009-09-20 21:01
lafond0822
5 Posts
0
September 30th, 2009 11:00
No, I am still unable to boot in safe mode. The only other issue I am experiencing now is getting redirected when I search in a browser. Mcafee can now run scans and login time is much faster.
bamajim
10.4K Posts
0
September 30th, 2009 11:00
lafond0822
Are you able to boot into Safe Mode now?
bamajim
10.4K Posts
0
September 30th, 2009 15:00
Update Malwarebytes Anti-Malware (Open the program and Select the Update tab)
Then Rerun MBAM and post the results log.