It is currently Tue Sep 01, 2026 1:44 pm


Yet another Dropper.Agent.GIT

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Still getting pop-ups

Postby faithmrose » Wed Jan 30, 2008 12:12 am

The system is running much faster and the hard drive is no longer doing random things all the time; thank you!

IE is still getting pop-ups, even when I'm using Mozilla. I upped my settings to high security but things are still getting through with only an occasional block.

AVG is coming up with a file called "hosts" at C:\WINDOWS\system32\drivers\etc\hosts
faithmrose
Geek in Training
Geek in Training
 
Posts: 25
Joined: Fri Jan 25, 2008 8:11 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Wed Jan 30, 2008 12:30 am

faithmrose,

Start Hijackthis and click the Config... button then click the Misc Tools button.

Now click the Open Hosts file manager button and then the Open in Notepad button.

Copy and paste the contents of notepade into your reply.


Next run SDFix again from safe mode and post that log as well.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Just another note before I run the scans

Postby faithmrose » Wed Jan 30, 2008 1:48 am

faithmrose
Geek in Training
Geek in Training
 
Posts: 25
Joined: Fri Jan 25, 2008 8:11 pm

Thanks given:0
Thanks received:0
Top

HJT Hosts file manager content

Postby faithmrose » Wed Jan 30, 2008 1:53 am

faithmrose
Geek in Training
Geek in Training
 
Posts: 25
Joined: Fri Jan 25, 2008 8:11 pm

Thanks given:0
Thanks received:0
Top

New SDFix log

Postby faithmrose » Wed Jan 30, 2008 2:26 am

SDFix: Version 1.131

Run by Teacher on Tue 01/29/2008 at 08:00 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\Teacher\Desktop\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:



Could Not Remove C:\WINDOWS\system32\drivers\core.cache.dsk

Folder C:\Temp\tn3 - Removed


Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\explorer.exe
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
faithmrose
Geek in Training
Geek in Training
 
Posts: 25
Joined: Fri Jan 25, 2008 8:11 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Wed Jan 30, 2008 11:52 am

faithmrose,

It's back I thought so, I want to try a different scanner program to see if we can find the replicating file.

Download to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.

* Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
o In the Files Created Within group click 30 days
o In the Files Modified Within group select 30 days
o In the File String Search group select Non-Microsoft
o In the Drivers Services group select Non-Microsoft
* Now click the Run Scan button on the toolbar.
* When the scan is complete Notepad will open with the report file loaded in it.
* Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.


Please post the resulting log as a reply
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

WinPFind3 log

Postby faithmrose » Wed Jan 30, 2008 6:27 pm

WinPFind3 logfile created on: 1/30/2008 12:19:38 PM
WinPFind3U by OldTimer - Version 1.0.44 Folder = C:\Documents and Settings\Teacher\Desktop\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 7.0.5730.13)

446.98 Mb Total Physical Memory | 81.85 Mb Available Physical Memory | 18.31% Memory free
1.03 Gb Paging File | 0.75 Gb Available in Paging File | 72.82% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 44.19 Gb Free Space | 79.06% Space Free
Drive D: | 547.08 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free
Drive E: | 244.23 Mb Total Space | 0.01 Mb Free Space | 0.00% Space Free
Drive F: | 43.81 Gb Total Space | 32.81 Gb Free Space | 74.88% Space Free

Computer Name: LAPTOP1
Current User Name: Teacher
Logged in as Administrator.
Current Boot Mode: Normal


[Processes - Non-Microsoft Only]
aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/24/2008 11:54:14 PM | Attr = ]
agrsmmsg.exe -> %SystemRoot%\agrsmmsg.exe -> Agere Systems [Ver = 2.1.38 2.1.38 02/20/2004 15:00:27 | Size = 88363 bytes | Modified Date = 2/20/2004 5:00:28 PM | Attr = ]
avgamsvr.exe -> %ProgramFiles%\Grisoft\AVG7\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.496 | Size = 418816 bytes | Modified Date = 1/25/2008 12:39:24 AM | Attr = ]
avgcc.exe -> %ProgramFiles%\Grisoft\AVG7\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.504 | Size = 579072 bytes | Modified Date = 1/25/2008 12:43:50 AM | Attr = ]
avgemc.exe -> %ProgramFiles%\Grisoft\AVG7\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.510 | Size = 406528 bytes | Modified Date = 1/25/2008 12:43:50 AM | Attr = ]
avgupsvc.exe -> %ProgramFiles%\Grisoft\AVG7\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 1/25/2008 12:39:42 AM | Attr = ]
cfsvcs.exe -> %ProgramFiles%\Toshiba\ConfigFree\CFSvcs.exe -> TOSHIBA CORPORATION [Ver = 4, 60, 0, 2 | Size = 28672 bytes | Modified Date = 3/4/2004 6:41:08 PM | Attr = ]
clntrust.exe -> -> File not found
df5serv.exe -> %ProgramFiles%\Faronics\Deep Freeze\Install C-0\DF5Serv.exe -> Faronics Corporation [Ver = 6,00,220,1523 | Size = 822144 bytes | Modified Date = 8/21/2006 12:33:04 PM | Attr = ]
dvdramsv.exe -> %System32%\DVDRAMSV.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 2, 0, 7, 0 | Size = 106496 bytes | Modified Date = 5/23/2003 3:38:26 PM | Attr = ]
firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe -> Mozilla Corporation [Ver = 1.8.1.11: 2007112718 | Size = 7650416 bytes | Modified Date = 1/16/2008 4:12:16 PM | Attr = ]
frzstate2k.exe -> %ProgramFiles%\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe -> Faronics Corporation [Ver = 6,00,220,1523 | Size = 1029834 bytes | Modified Date = 1/30/2008 7:57:54 AM | Attr = ]
naldesk.exe -> %System32%\NALDESK.EXE -> Novell, Inc [Ver = 990603 | Size = 757760 bytes | Modified Date = 6/3/1999 3:43:44 PM | Attr = ]
nalexpld.exe -> Z:\NalExpLd.exe -> Novell, Inc [Ver = 4.0.1.4 | Size = 106496 bytes | Modified Date = 3/24/2003 2:08:44 PM | Attr = ]
nwtray.exe -> %System32%\nwtray.exe -> Novell, Inc. [Ver = v4.90 | Size = 28672 bytes | Modified Date = 3/12/2002 8:37:28 AM | Attr = ]
ramasst.exe -> %System32%\RAMASST.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 1, 0, 9, 0 | Size = 155648 bytes | Modified Date = 3/14/2003 1:38:12 PM | Attr = ]
swupdtmr.exe -> %SystemDrive%\TOSHIBA\Ivp\Swupdate\swupdtmr.exe -> [Ver = | Size = 53248 bytes | Modified Date = 5/13/2004 4:46:02 PM | Attr = ]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.44.0 | Size = 371200 bytes | Modified Date = 11/21/2007 9:19:46 AM | Attr = ]

[Win32 Services - Non-Microsoft Only]
(aawservice) Ad-Aware 2007 Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/24/2008 11:54:14 PM | Attr = ]
(ACS) Atheros Configuration Service [Win32_Own | Auto | Stopped] -> %System32%\ACS.exe -> File not found
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Stopped] -> %System32%\Ati2evxx.exe -> File not found
(Avg7Alrt) AVG7 Alert Manager Server [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.496 | Size = 418816 bytes | Modified Date = 1/25/2008 12:39:24 AM | Attr = ]
(Avg7UpdSvc) AVG7 Update Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 1/25/2008 12:39:42 AM | Attr = ]
(AVGEMS) AVG E-mail Scanner [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.510 | Size = 406528 bytes | Modified Date = 1/25/2008 12:43:50 AM | Attr = ]
(CFSvcs) ConfigFree Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Toshiba\ConfigFree\CFSvcs.exe -> TOSHIBA CORPORATION [Ver = 4, 60, 0, 2 | Size = 28672 bytes | Modified Date = 3/4/2004 6:41:08 PM | Attr = ]
(cusrvc) Client Update Service for Novell [Win32_Own | On_Demand | Stopped] -> %System32%\cusrvc.exe -> Novell, Inc. [Ver = v4.91 | Size = 28672 bytes | Modified Date = 8/11/2006 1:51:04 PM | Attr = ]
(DF5Serv) DF5Serv [Win32_Own | Auto | Running] -> %ProgramFiles%\Faronics\Deep Freeze\Install C-0\DF5Serv.exe -> Faronics Corporation [Ver = 6,00,220,1523 | Size = 822144 bytes | Modified Date = 8/21/2006 12:33:04 PM | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/3/2004 11:56:50 PM | Attr = ]
(DVD-RAM_Service) DVD-RAM_Service [Win32_Own | Auto | Running] -> %System32%\DVDRAMSV.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 2, 0, 7, 0 | Size = 106496 bytes | Modified Date = 5/23/2003 3:38:26 PM | Attr = ]
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.2.824.5515.beta | Size = 138680 bytes | Modified Date = 11/19/2007 12:01:40 PM | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 12:41:10 AM | Attr = ]
(PavPrSrv) Panda Process Protection Service [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Panda Software\PavShld\pavprsrv.exe -> File not found
(Swupdtmr) Swupdtmr [Win32_Own | Auto | Running] -> %SystemDrive%\TOSHIBA\Ivp\Swupdate\swupdtmr.exe -> [Ver = | Size = 53248 bytes | Modified Date = 5/13/2004 4:46:02 PM | Attr = ]

[Driver Services - Non-Microsoft Only]
(Abiosdsk) Abiosdsk [Kernel | Disabled | Stopped] -> -> File not found
(abp480n5) abp480n5 [Kernel | Disabled | Stopped] -> -> File not found
(adpu160m) adpu160m [Kernel | Disabled | Stopped] -> -> File not found
(AgereSoftModem) TOSHIBA V92 Software Modem [Kernel | On_Demand | Running] -> %System32%\drivers\AGRSM.sys -> Agere Systems [Ver = 2.1.38 2.1.38 02/20/2004 15:00:41 | Size = 1265388 bytes | Modified Date = 2/20/2004 5:00:44 PM | Attr = ]
(Aha154x) Aha154x [Kernel | Disabled | Stopped] -> -> File not found
(aic78u2) aic78u2 [Kernel | Disabled | Stopped] -> -> File not found
(aic78xx) aic78xx [Kernel | Disabled | Stopped] -> -> File not found
(ALCXSENS) Service for WDM 3D Audio Driver [Kernel | On_Demand | Running] -> %System32%\drivers\ALCXSENS.SYS -> Sensaura Ltd [Ver = 5.10.00.3511D | Size = 391424 bytes | Modified Date = 12/12/2003 1:54:14 AM | Attr = ]
(ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> %System32%\drivers\ALCXWDM.SYS -> Realtek Semiconductor Corp. [Ver = 5.10.5490 | Size = 610988 bytes | Modified Date = 2/19/2004 1:51:08 AM | Attr = ]
(AliIde) AliIde [Kernel | Disabled | Stopped] -> -> File not found
(amsint) amsint [Kernel | Disabled | Stopped] -> -> File not found
(ApfiltrService) Alps Pointing-device Filter Driver [Kernel | On_Demand | Running] -> %System32%\drivers\Apfiltr.sys -> Alps Electric Co., Ltd. [Ver = 6.0.301.196 | Size = 101833 bytes | Modified Date = 5/8/2004 10:38:06 PM | Attr = ]
(AR5211) Atheros Wireless Network Adapter Service [Kernel | On_Demand | Stopped] -> %System32%\drivers\ar5211.sys -> Atheros Communications, Inc. [Ver = 3.1.2.12 | Size = 390944 bytes | Modified Date = 5/28/2004 2:45:02 PM | Attr = ]
(asc) asc [Kernel | Disabled | Stopped] -> -> File not found
(asc3350p) asc3350p [Kernel | Disabled | Stopped] -> -> File not found
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> -> File not found
(Atdisk) Atdisk [Kernel | Disabled | Stopped] -> -> File not found
(ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %System32%\drivers\ati2mtag.sys -> ATI Technologies Inc. [Ver = 6.14.10.6444 | Size = 729088 bytes | Modified Date = 4/22/2004 1:11:06 AM | Attr = ]
(Avg7Core) AVG7 Kernel [Kernel | System | Running] -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.498 | Size = 821856 bytes | Modified Date = 1/25/2008 12:39:48 AM | Attr = ]
(Avg7RsNT) AVG7 Resident Driver NT [Kernel | System | Running] -> %System32%\drivers\avg7rsnt.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 26944 bytes | Modified Date = 1/25/2008 12:40:22 AM | Attr = ]
(Avg7RsW) AVG7 Wrap Driver [Kernel | System | Running] -> %System32%\drivers\avg7rsw.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,340 | Size = 4224 bytes | Modified Date = 1/25/2008 12:40:18 AM | Attr = ]
(AvgClean) AVG7 Clean Driver [Kernel | System | Running] -> %System32%\drivers\avgclean.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10760 bytes | Modified Date = 1/25/2008 12:43:52 AM | Attr = ]
(AvgTdi) AVG Network Redirector [Kernel | Auto | Running] -> %System32%\drivers\avgtdi.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,346 | Size = 4960 bytes | Modified Date = 1/25/2008 12:40:26 AM | Attr = ]
(BtAudio) Bluetooth Audio [Kernel | On_Demand | Stopped] -> system32\DRIVERS\btaudio.sys -> File not found
(BTDriver) Bluetooth Virtual Communications Driver [Kernel | On_Demand | Stopped] -> system32\DRIVERS\btport.sys -> File not found
(BVRPMPR5) BVRPMPR5 NDIS Protocol Driver [Kernel | On_Demand | Stopped] -> D:\INSTAL~E\Core\BVRPMPR5.SYS -> File not found
(C-Dilla) C-Dilla [Kernel | On_Demand | Stopped] -> %System32%\drivers\CDANT.SYS -> File not found
(caboagp) ATI Cabo AGP Filter [Kernel | Boot | Running] -> %System32%\drivers\atisgkaf.SYS -> ATI Technologies Inc. [Ver = 5.00.2195.1007 | Size = 13174 bytes | Modified Date = 4/23/2003 5:06:40 PM | Attr = ]
(catchme) catchme [Kernel | On_Demand | Stopped] -> %SystemDrive%\DOCUME~1\Teacher\LOCALS~1\Temp\catchme.sys -> File not found
(cd20xrnt) cd20xrnt [Kernel | Disabled | Stopped] -> -> File not found
(Cdr4_xp) Cdr4_xp [Kernel | System | Running] -> %System32%\drivers\cdr4_xp.sys -> Roxio [Ver = 6.2.0.132 | Size = 67024 bytes | Modified Date = 10/22/2003 10:15:02 PM | Attr = ]
(Cdralw2k) Cdralw2k [Kernel | System | Running] -> %System32%\drivers\cdralw2k.sys -> Roxio [Ver = 6.2.0.132 | Size = 24698 bytes | Modified Date = 10/22/2003 10:15:02 PM | Attr = ]
(Changer) Changer [Kernel | System | Stopped] -> -> File not found
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> -> File not found
(ComFiltr) Panda Anti-Dialer [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\COMFiltr.sys -> File not found
(Cpqarray) Cpqarray [Kernel | Disabled | Stopped] -> -> File not found
(dac960nt) dac960nt [Kernel | Disabled | Stopped] -> -> File not found
(DeepFrz) DeepFrz [Kernel | Boot | Running] -> %System32%\drivers\DeepFrz.sys -> Faronics Corporation [Ver = 6,00,220,1523 | Size = 119168 bytes | Modified Date = 7/22/2006 11:45:20 AM | Attr = ]
(DgiVecp) Team MFP Comm Driver [Kernel | Auto | Running] -> %System32%\drivers\DGIVECP.SYS -> DeviceGuys, Inc. [Ver = 1.1.1.30 | Size = 41984 bytes | Modified Date = 3/14/2005 12:01:38 AM | Attr = ]
(dmboot) dmboot [Kernel | Disabled | Stopped] -> %System32%\drivers\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 8/3/2004 10:07:18 PM | Attr = ]
(dmio) Logical Disk Manager Driver [Kernel | Boot | Running] -> %System32%\drivers\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 8/3/2004 10:07:18 PM | Attr = ]
(dmload) dmload [Kernel | Boot | Running] -> %System32%\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 3/31/2003 7:00:00 AM | Attr = ]
(dpti2o) dpti2o [Kernel | Disabled | Stopped] -> -> File not found
(el575nd5) 3Com Megahertz 10/100 LAN CardBus PC Card Driver [Kernel | On_Demand | Stopped] -> %System32%\drivers\el575ND5.sys -> 3Com Corporation [Ver = 2.60.5000.0020 | Size = 69692 bytes | Modified Date = 8/17/2001 2:10:58 PM | Attr = ]
(EMSCR) EMSCR [Kernel | On_Demand | Stopped] -> %System32%\drivers\EMS7SK.sys -> ENE Technology Inc. [Ver = 1.03.04 built by: WinDDK | Size = 57216 bytes | Modified Date = 5/18/2004 5:05:26 PM | Attr = ]
(EPOWER) Compal E-POWER Driver [Kernel | On_Demand | Stopped] -> System32\Drivers\hkdrv.sys -> File not found
(ESDCR) ESDCR [Kernel | On_Demand | Stopped] -> %System32%\drivers\ESD7SK.sys -> ENE Technology Inc. [Ver = 1.03.05 built by: WinDDK | Size = 36224 bytes | Modified Date = 5/18/2004 7:36:20 PM | Attr = ]
(ESMCR) ESMCR [Kernel | On_Demand | Stopped] -> %System32%\drivers\ESM7SK.sys -> ENE Technology Inc. [Ver = 1.03.04 built by: WinDDK | Size = 330496 bytes | Modified Date = 5/11/2004 11:53:44 AM | Attr = ]
(hpn) hpn [Kernel | Disabled | Stopped] -> -> File not found
(i2omgmt) i2omgmt [Kernel | System | Stopped] -> -> File not found
(i2omp) i2omp [Kernel | Disabled | Stopped] -> -> File not found
(ini910u) ini910u [Kernel | Disabled | Stopped] -> -> File not found
(IntelIde) IntelIde [Kernel | Disabled | Stopped] -> -> File not found
(lbrtfdc) lbrtfdc [Kernel | System | Stopped] -> -> File not found
(MCSTRM) MCSTRM [Kernel | Auto | Running] -> %System32%\drivers\mcstrm.sys -> RealNetworks, Inc. [Ver = 5.0.2195.8 | Size = 8413 bytes | Modified Date = 11/30/2007 3:45:44 PM | Attr = ]
(MDC8021X) AEGIS Protocol (IEEE 802.1x) v2.3.1.9 [Kernel | Auto | Running] -> %System32%\drivers\mdc8021x.sys -> Meetinghouse Data Communications [Ver = 2.3.1.9 | Size = 15781 bytes | Modified Date = 5/21/2004 5:30:36 PM | Attr = ]
(meiudf) meiudf [File_System | System | Running] -> %System32%\drivers\meiudf.sys -> Matsushita Electric Industrial Co.,Ltd. [Ver = 3.0.9.0 | Size = 90416 bytes | Modified Date = 10/24/2003 3:53:14 PM | Attr = ]
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> -> File not found
(Netdevio) TOSHIBA Network Device Usermode I/O Protocol [Kernel | Auto | Running] -> %System32%\drivers\Netdevio.sys -> TOSHIBA Corporation. [Ver = Version 5.00.01.00 built by: WinDDK | Size = 12032 bytes | Modified Date = 1/29/2003 4:35:00 PM | Attr = ]
(NetwareWorkstation) Novell Client for Windows [File_System | Auto | Running] -> %System32%\NetWare\NWFS.SYS -> Novell, Inc. [Ver = 4.91.4.5 | Size = 513536 bytes | Modified Date = 2/28/2007 3:17:00 AM | Attr = ]
(NICM) Novell InterService Communication Driver [Kernel | Boot | Running] -> %System32%\drivers\nicm.sys -> Novell, Inc. [Ver = 3.0.0.4 | Size = 38416 bytes | Modified Date = 3/3/2006 3:50:48 PM | Attr = ]
(NWDHCP) Novell DHCP Inform Client [File_System | Auto | Running] -> %System32%\NetWare\nwdhcp.sys -> Novell, Inc. [Ver = 4.91.3.0 | Size = 18353 bytes | Modified Date = 11/22/2005 8:51:22 AM | Attr = ]
(NWDNS) Novell DNS Name Space Service Provider [File_System | On_Demand | Running] -> %System32%\NetWare\NWDNS.SYS -> Novell, Inc. [Ver = 4.91.3.1 | Size = 43568 bytes | Modified Date = 10/27/2006 8:53:00 PM | Attr = ]
(NWFILTER) Novell UNC Path Filter [Kernel | Boot | Running] -> %System32%\NetWare\nwfilter.sys -> Novell, Inc. [Ver = 4.91.1.1 | Size = 15891 bytes | Modified Date = 5/26/2005 4:14:00 PM | Attr = ]
(NWHOST) Novell Host File Name Space Service Provider [File_System | On_Demand | Running] -> %System32%\NetWare\nwhost.sys -> Novell, Inc. [Ver = 4.91.1.1 | Size = 9297 bytes | Modified Date = 10/12/2005 11:12:18 AM | Attr = ]
(NWSAP) Novell SAP Name Space Provider [File_System | On_Demand | Running] -> %System32%\NetWare\nwsap.sys -> [Ver = | Size = 23232 bytes | Modified Date = 2/26/2003 12:51:18 PM | Attr = ]
(NWSIPX32) Novell NetWare IPX/SPX Transport Interface [File_System | Auto | Running] -> %System32%\NetWare\nwsipx32.sys -> Novell, Inc. [Ver = 4.91.1.1 | Size = 39731 bytes | Modified Date = 10/27/2005 2:15:14 PM | Attr = ]
(NWSLP) Novell SLP Name Space Service Provider [File_System | On_Demand | Running] -> %System32%\NetWare\nwslp.sys -> Novell, Inc. [Ver = 4.91.0.1 | Size = 20332 bytes | Modified Date = 1/3/2005 12:51:38 PM | Attr = ]
(NWSNS) Novell Simple Naming Services [File_System | On_Demand | Running] -> %System32%\NetWare\nwsns.sys -> Novell, Inc. [Ver = 4.91.1.1 | Size = 6128 bytes | Modified Date = 10/12/2005 11:11:32 AM | Attr = ]
(PavProc) Panda Process Protection Driver [Kernel | Auto | Stopped] -> %System32%\DRIVERS\PavProc.sys -> File not found
(PCIDump) PCIDump [Kernel | System | Stopped] -> -> File not found
(pciidexx) pciidexx [Kernel | System | Running] -> %System32%\drivers\pciidexx.sys -> [Ver = | Size = 86016 bytes | Modified Date = 1/14/2008 4:36:44 PM | Attr = ]
(PDCOMP) PDCOMP [Kernel | On_Demand | Stopped] -> -> File not found
(PDFRAME) PDFRAME [Kernel | On_Demand | Stopped] -> -> File not found
(PDRELI) PDRELI [Kernel | On_Demand | Stopped] -> -> File not found
(PDRFRAME) PDRFRAME [Kernel | On_Demand | Stopped] -> -> File not found
(perc2) perc2 [Kernel | Disabled | Stopped] -> -> File not found
(perc2hib) perc2hib [Kernel | Disabled | Stopped] -> -> File not found
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %System32%\drivers\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 3/31/2003 7:00:00 AM | Attr = ]
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> -> File not found
(Ql10wnt) Ql10wnt [Kernel | Disabled | Stopped] -> -> File not found
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> -> File not found
(ql1240) ql1240 [Kernel | Disabled | Stopped] -> -> File not found
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> -> File not found
(RESMGR) Novell NetWare Resource Manager [Kernel | Auto | Running] -> %System32%\NetWare\resmgr.sys -> Novell, Inc. [Ver = 4.90 | Size = 27249 bytes | Modified Date = 6/1/2004 4:19:34 PM | Attr = ]
(RTL8023) Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver [Kernel | On_Demand | Running] -> %System32%\drivers\Rtlnic51.sys -> Realtek Semiconductor Corporation [Ver = 5.606.811.2003 built by: WinDDK | Size = 65280 bytes | Modified Date = 8/13/2003 5:27:22 PM | Attr = ]
(rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %System32%\drivers\rtl8139.sys -> Realtek Semiconductor Corporation [Ver = 5.398.613.2003 built by: WinDDK | Size = 20992 bytes | Modified Date = 8/3/2004 9:31:34 PM | Attr = ]
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %System32%\drivers\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 11/13/2007 5:25:54 AM | Attr = ]
(ShldDrv) Panda File Shield Driver [Kernel | System | Stopped] -> -> File not found
(Simbad) Simbad [Kernel | Disabled | Stopped] -> -> File not found
(SMCIRDA) SMC IrCC Miniport Device Driver [Kernel | On_Demand | Stopped] -> %System32%\drivers\smcirda.sys -> SMC [Ver = 5.1.2462.0 | Size = 35913 bytes | Modified Date = 8/17/2001 2:10:28 PM | Attr = ]
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> -> File not found
(SrvcEKIOMngr) SrvcEKIOMngr [Kernel | System | Running] -> %System32%\drivers\EKIOMngr.sys -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 6 | Size = 6272 bytes | Modified Date = 5/5/2004 4:53:08 PM | Attr = ]
(SrvcSSIOMngr) SrvcSSIOMngr [Kernel | System | Running] -> %System32%\drivers\SSIOMngr.sys -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 6 | Size = 6272 bytes | Modified Date = 5/5/2004 4:53:10 PM | Attr = ]
(SrvcTPIOMngr) SrvcTPIOMngr [Kernel | System | Running] -> %System32%\drivers\TPIOMngr.sys -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 6 | Size = 6272 bytes | Modified Date = 5/5/2004 4:53:08 PM | Attr = ]
(SRVLOC) Novell Service Location [File_System | Auto | Running] -> %System32%\NetWare\srvloc.sys -> Novell, Inc. [Ver = 4.91.3.0 | Size = 160209 bytes | Modified Date = 9/25/2006 7:54:54 AM | Attr = ]
(symc810) symc810 [Kernel | Disabled | Stopped] -> -> File not found
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> -> File not found
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> -> File not found
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> -> File not found
(TBiosDrv) TBiosDrv [Kernel | Auto | Running] -> %System32%\drivers\tbiosdrv.sys -> [Ver = | Size = 6867 bytes | Modified Date = 6/11/2003 10:53:22 AM | Attr = ]
(ThwSpace) ThwSpace [Kernel | Boot | Running] -> %System32%\drivers\ThwSpace.sys -> Faronics Corporation [Ver = 6,00,220,1523 | Size = 68096 bytes | Modified Date = 7/22/2006 11:45:22 AM | Attr = ]
(TNET1130x) Wireless-G Notebook Adapter v.2.0 [Kernel | On_Demand | Running] -> %System32%\drivers\tnet1130x.sys -> Cisco-Linksys LLC. [Ver = 6.0.0.18 | Size = 385536 bytes | Modified Date = 3/10/2004 8:54:32 PM | Attr = ]
(TosIde) TosIde [Kernel | Disabled | Stopped] -> -> File not found
(ultra) ultra [Kernel | Disabled | Stopped] -> -> File not found
(ViaIde) ViaIde [Kernel | Disabled | Stopped] -> -> File not found
(wanatw) WAN Miniport (ATW) [Kernel | On_Demand | Stopped] -> System32\DRIVERS\wanatw4.sys -> File not found
(WDICA) WDICA [Kernel | On_Demand | Stopped] -> -> File not found

[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
AGRSMMSG -> %SystemRoot%\agrsmmsg.exe -> Agere Systems [Ver = 2.1.38 2.1.38 02/20/2004 15:00:27 | Size = 88363 bytes | Modified Date = 2/20/2004 5:00:28 PM | Attr = ]
Apoint -> %ProgramFiles%\Apoint2K\Apoint.exe -> File not found
ATIPTA -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe -> File not found
AVG7_CC -> %ProgramFiles%\Grisoft\AVG7\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.504 | Size = 579072 bytes | Modified Date = 1/25/2008 12:43:50 AM | Attr = ]
CeEKEY -> %ProgramFiles%\TOSHIBA\E-KEY\CeEKey.exe -> File not found
HostManager -> %CommonProgramFiles%\AOL\1139673470\ee\AOLSoftware.exe -> File not found
IPHSend -> %CommonProgramFiles%\AOL\IPHSend\IPHSend.exe -> File not found
NDPS -> %System32%\dpmw32.exe -> File not found
NWTRAY -> %System32%\nwtray.exe -> Novell, Inc. [Ver = v4.90 | Size = 28672 bytes | Modified Date = 3/12/2002 8:37:28 AM | Attr = ]
PadTouch -> %ProgramFiles%\TOSHIBA\Touch and Launch\PadExe.exe -> File not found
Pinger -> %SystemDrive%\toshiba\ivp\ism\pinger.exe -> File not found
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.4 | Size = 385024 bytes | Modified Date = 1/10/2008 3:27:36 PM | Attr = ]
TPNF -> %ProgramFiles%\TOSHIBA\TouchPad\TPTray.exe -> File not found
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL -> Installed = Reg Data - Value does not exist ->
MAPI -> Installed = Reg Data - Value does not exist ->
MSFS -> Installed = Reg Data - Value does not exist ->
< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
Aim6 -> -> File not found
TOSCDSPD -> %ProgramFiles%\TOSHIBA\TOSCDSPD\toscdspd.exe -> File not found
Uniblue SpyEraser -> %ProgramFiles%\Uniblue\SpyEraser\SpyEraser .exe -> File not found
< Common Startup > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersStartup%\RAMASST.lnk -> %System32%\RAMASST.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 1, 0, 9, 0 | Size = 155648 bytes | Modified Date = 3/14/2003 1:38:12 PM | Attr = ]
< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{B4870B70-F390-11d2-9FB9-F4ED725EA20D} [HKLM] -> %System32%\NALEXPEX.DLL [] -> Novell, Inc [Ver = 990428 | Size = 131072 bytes | Modified Date = 6/3/1999 3:46:02 PM | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*GinaDLL* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\GinaDLL ->
NWGINA.DLL -> %System32%\NWGINA.DLL -> Novell, Inc. [Ver = v6.5.1 (20070226) | Size = 389201 bytes | Modified Date = 2/27/2007 9:52:00 PM | Attr = ]
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
DfLogon -> %System32%\LogonDll.dll -> [Ver = | Size = 49152 bytes | Modified Date = 7/22/2006 11:52:12 AM | Attr = ]
< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 255 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\CompatibleRUPSecurity -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< HOSTS File > (686 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
127.0.0.1 localhost -> ->
< Internet Explorer Settings > -> ->
HKLM: Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKLM: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKLM: Local Page -> %SystemRoot%\system32\blank.htm ->
HKLM: Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKLM: Start Page -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
HKCU: Local Page -> C:\WINDOWS\system32\blank.htm ->
HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dl ... r=iesearch ->
HKCU: Start Page -> http://www.bishopmcdevitt.org/ ->
HKCU: ProxyEnable -> 1 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
msn.com [ - ] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 8.0.0.2006102200 | Size = 62080 bytes | Modified Date = 10/22/2006 11:08:42 PM | Attr = ]
{3049C3E9-B461-4BC5-8870-4C09146192CA} [HKLM] -> %ProgramFiles%\Real\RealPlayer\rpbrowserrecordplugin.dll [RealPlayer Download and Record Plugin for Internet Explorer] -> RealPlayer [Ver = 1.0.0.522 | Size = 370296 bytes | Modified Date = 11/19/2007 12:11:36 PM | Attr = ]
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 3, 0, 12 | Size = 744960 bytes | Modified Date = 5/12/2004 3:03:00 AM | Attr = ]
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\googletoolbar1.dll [Google Toolbar Helper] -> Google Inc. [Ver = 4, 0, 1602, 1060 | Size = 2554944 bytes | Modified Date = 11/19/2007 12:02:08 PM | Attr = R ]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> %ProgramFiles%\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll [Google Toolbar Notifier BHO] -> Google Inc. [Ver = 2, 1, 615, 5858 | Size = 654832 bytes | Modified Date = 11/19/2007 12:01:44 PM | Attr = ]
< Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1602, 1060 | Size = 2554944 bytes | Modified Date = 11/19/2007 12:02:08 PM | Attr = R ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1602, 1060 | Size = 2554944 bytes | Modified Date = 11/19/2007 12:02:08 PM | Attr = R ]
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> Reg Data - Key not found [MenuText: Sun Java Console] -> File not found
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -> Reg Data - Value does not exist [ButtonText: Real.com] -> File not found
{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> Reg Data - Key not found [MenuText: @xpsp3res.dll,-20001] -> File not found
< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> -> File not found
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{00511995-52F8-4161-A63C-7B7A92D1A739} -> () ->
{01AD8AB3-C14E-42A6-9BCC-6388E003E369} -> (1394 Net Adapter) ->
{201277D6-E61A-4FE3-B78F-AF2367E4968F} -> () ->
{2EF4AD70-B14A-413B-90C0-091E8B226284} -> () ->
{349DF0CF-C664-49D7-A63A-EB20C706DBEE} -> () ->
{51D662B2-9E40-4C52-80F2-28055DFA7773} -> () ->
{52857066-F113-4A85-B082-9ED9315EB0D4} -> () ->
{60D0885D-76D2-4812-9B97-E310458F70A7} -> (1394 Net Adapter) ->
{7ECD66B4-1677-45CD-9184-54BA1E6A07E4} -> (3Com Megahertz 10/100 LAN CardBus PC Card) ->
{80F2B74F-A692-434C-B547-545156571B91} -> (Wireless-G Notebook Adapter v.2.0) ->
{8CE12112-A5FA-4C09-B265-988960939285} -> (Atheros AR5004G Wireless Network Adapter) ->
{998D23CF-2226-4951-95EC-8862593535B3} -> () ->
{9F871661-8612-41FC-85D6-8E0DBF021297} -> () ->
{A1B8A82F-7D62-4ADF-B647-0C4612419CB9} -> () ->
{AA2EA583-36C9-4811-AD77-84D83764FFAF} -> () ->
{ADB01ED8-AF3E-4E7D-A95F-1CD8BBB1B387} -> () ->
{CE8C281E-36AC-4FAB-94CD-D8982DCB0C05} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) ->
< Winsock2 Catalogs [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ ->
NameSpace_Catalog5\Catalog_Entries\000000000004 [Novell Directory Services Name Provider] -> %System32%\NetWare\nwws2nds.dll -> Novell, Inc. [Ver = 4.91 | Size = 36947 bytes | Modified Date = 1/30/2006 2:40:26 PM | Attr = ]
NameSpace_Catalog5\Catalog_Entries\000000000005 [Novell IPX/SPX SAP Name Provider] -> %System32%\NetWare\nwws2sap.dll -> Novell, Inc. [Ver = 4.91 | Size = 32851 bytes | Modified Date = 10/27/2005 2:24:08 PM | Attr = ]
NameSpace_Catalog5\Catalog_Entries\000000000006 [Novell SLP Provider] -> %System32%\NetWare\nwws2slp.dll -> Novell, Inc. [Ver = 4.91 | Size = 49235 bytes | Modified Date = 1/30/2006 2:40:28 PM | Attr = ]
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{01111F00-3E00-11D2-8470-0060089874ED} -> Support.com Installer - CodeBase = http://supportsoft.adelphia.net/sdccomm ... ctlins.cab ->
{02BCC737-B171-4746-94C9-0D8A0B2C0089} -> - CodeBase = http://office.microsoft.com/templates/ieawsdc.cab ->
{166B1BCA-3F9C-11CF-8075-444553540000} -> Shockwave ActiveX Control - CodeBase = http://fpdownload.macromedia.com/get/sh ... tor/sw.cab ->
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -> Office Update Installation Engine - CodeBase = http://office.microsoft.com/officeupdat ... t/opuc.cab ->
{6414512B-B978-451D-A0D8-FCFDF33E833C} -> WUWebControl Class - CodeBase = http://www.update.microsoft.com/microso ... 8239107062 ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -> MUWebControl Class - CodeBase = http://www.update.microsoft.com/microso ... 8232323093 ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -> - CodeBase = http://fpdownload.macromedia.com/get/fl ... rashim.cab ->
{9F1C11AA-197B-4942-BA54-47A8489BB47F} -> - CodeBase = http://v4.windowsupdate.microsoft.com/C ... 3548611111 ->
{A4639D2F-774E-11D3-A490-00C04F6843FB} -> - CodeBase = http://download.microsoft.com/download/ ... msorun.cab ->
{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} -> Java Plug-in 1.4.2_03 - CodeBase = http://java.sun.com/products/plugin/aut ... s-i586.cab ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://download.macromedia.com/pub/shoc ... wflash.cab ->


[Files/Folders - Created Within 30 days]
$VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Created Date = 1/25/2008 6:57:43 AM | Attr = RH ]
avenger -> %SystemDrive%\avenger -> [Folder | Created Date = 1/29/2008 12:22:50 PM | Attr = ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 468766720 bytes | Created Date = 1/1/1601 5:00:00 AM | Attr = HS]
QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 1/25/2008 5:35:04 PM | Attr = ]
SDFix -> %SystemDrive%\SDFix -> [Folder | Created Date = 1/28/2008 11:52:21 AM | Attr = ]
Temp -> %SystemDrive%\Temp -> [Folder | Created Date = 1/14/2008 4:36:25 PM | Attr = ]
TrustedAntivirus -> %SystemDrive%\TrustedAntivirus -> [Folder | Created Date = 1/25/2008 2:35:36 PM | Attr = HS]
$NtUninstallKB937894$ -> %SystemRoot%\$NtUninstallKB937894$ -> [Folder | Created Date = 1/15/2008 3:30:56 PM | Attr = H ]
$NtUninstallKB941568$ -> %SystemRoot%\$NtUninstallKB941568$ -> [Folder | Created Date = 1/15/2008 3:28:46 PM | Attr = H ]
$NtUninstallKB941569$ -> %SystemRoot%\$NtUninstallKB941569$ -> [Folder | Created Date = 1/15/2008 3:35:34 PM | Attr = H ]
$NtUninstallKB941644$ -> %SystemRoot%\$NtUninstallKB941644$ -> [Folder | Created Date = 1/15/2008 3:35:50 PM | Attr = H ]
$NtUninstallKB942763$ -> %SystemRoot%\$NtUninstallKB942763$ -> [Folder | Created Date = 1/15/2008 3:28:22 PM | Attr = H ]
$NtUninstallKB943485$ -> %SystemRoot%\$NtUninstallKB943485$ -> [Folder | Created Date = 1/15/2008 3:35:59 PM | Attr = H ]
$NtUninstallKB944653$ -> %SystemRoot%\$NtUninstallKB944653$ -> [Folder | Created Date = 1/15/2008 3:30:46 PM | Attr = H ]
CeEKey .INI -> %SystemRoot%\CeEKey .INI -> [Ver = | Size = 0 bytes | Created Date = 1/17/2008 8:00:17 AM | Attr = ]
erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 1/25/2008 5:35:49 PM | Attr = ]
ERUNT -> %SystemRoot%\ERUNT -> [Folder | Created Date = 1/28/2008 12:21:50 PM | Attr = ]
Nircmd.exe -> %SystemRoot%\Nircmd.exe -> NirSoft [Ver = 2.00 | Size = 51200 bytes | Created Date = 1/25/2008 5:34:53 PM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Created Date = 1/17/2008 3:45:34 PM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 1/29/2008 9:44:32 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 1/29/2008 9:44:32 PM | Attr = H ]
TEMP -> %SystemRoot%\TEMP -> [Folder | Created Date = 1/27/2008 11:42:47 PM | Attr = ]
3-D_Dancing_Skeleton_Demo dir -> %System32%\3-D_Dancing_Skeleton_Demo dir -> [Folder | Created Date = 1/14/2008 11:44:43 AM | Attr = ]
dpmw32 .exe -> %System32%\dpmw32 .exe -> Novell, Inc. [Ver = v3.0.1 | Size = 32859 bytes | Created Date = 1/15/2008 7:50:00 AM | Attr = ]
nGpxx01 -> %System32%\nGpxx01 -> [Folder | Created Date = 1/25/2008 2:31:36 PM | Attr = ]
QuickTime.qts -> %System32%\QuickTime.qts -> Apple Inc. [Ver = 7.4 | Size = 57344 bytes | Created Date = 1/10/2008 3:27:44 PM | Attr = ]
QuickTimeVR.qtx -> %System32%\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.4 | Size = 90112 bytes | Created Date = 1/10/2008 3:27:46 PM | Attr = ]
swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.11 | Size = 156160 bytes | Created Date = 1/25/2008 5:34:53 PM | Attr = ]
swsc.exe -> %System32%\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Created Date = 1/25/2008 5:34:53 PM | Attr = ]
swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 1/25/2008 5:34:53 PM | Attr = ]
VFind.exe -> %System32%\VFind.exe -> [Ver = | Size = 49152 bytes | Created Date = 1/25/2008 5:34:53 PM | Attr = ]
avg7core.sys -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.498 | Size = 821856 bytes | Created Date = 1/25/2008 12:39:45 AM | Attr = ]
avg7rsnt.sys -> %System32%\drivers\avg7rsnt.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 26944 bytes | Created Date = 1/25/2008 12:40:20 AM | Attr = ]
avg7rsw.sys -> %System32%\drivers\avg7rsw.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,340 | Size = 4224 bytes | Created Date = 1/25/2008 12:40:16 AM | Attr = ]
avg7rsxp.sys -> %System32%\drivers\avg7rsxp.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 27776 bytes | Created Date = 1/25/2008 12:40:25 AM | Attr = ]
avgclean.sys -> %System32%\drivers\avgclean.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10760 bytes | Created Date = 1/25/2008 12:40:29 AM | Attr = ]
avgmfx86.sys -> %System32%\drivers\avgmfx86.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.510 | Size = 26952 bytes | Created Date = 1/25/2008 12:40:25 AM | Attr = ]
avgtdi.sys -> %System32%\drivers\avgtdi.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,346 | Size = 4960 bytes | Created Date = 1/25/2008 12:40:25 AM | Attr = ]
core.cache.dsk -> %System32%\drivers\core.cache.dsk -> [Ver = | Size = 167545 bytes | Created Date = 1/29/2008 8:13:33 PM | Attr = ]
pciidexx.sys -> %System32%\drivers\pciidexx.sys -> [Ver = | Size = 86016 bytes | Created Date = 1/14/2008 4:36:42 PM | Attr = ]

[Files/Folders - Modified Within 30 days]
$VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Modified Date = 1/27/2008 11:29:02 PM | Attr = RH ]
avenger -> %SystemDrive%\avenger -> [Folder | Modified Date = 1/29/2008 12:22:52 PM | Attr = ]
boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 211 bytes | Modified Date = 1/17/2008 3:52:08 PM | Attr = RHS]
DOCS -> %SystemDrive%\DOCS -> [Folder | Modified Date = 1/6/2008 7:51:02 PM | Attr = ]
GQWIN -> %SystemDrive%\GQWIN -> [Folder | Modified Date = 1/30/2008 8:05:34 AM | Attr = ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 468766720 bytes | Modified Date = 1/30/2008 7:57:18 AM | Attr = HS]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 1/29/2008 4:33:56 PM | Attr = R ]
QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 1/27/2008 11:42:46 PM | Attr = ]
SDFix -> %SystemDrive%\SDFix -> [Folder | Modified Date = 1/28/2008 11:52:22 AM | Attr = ]
Temp -> %SystemDrive%\Temp -> [Folder | Modified Date = 1/29/2008 8:22:08 PM | Attr = ]
TrustedAntivirus -> %SystemDrive%\TrustedAntivirus -> [Folder | Modified Date = 1/25/2008 2:35:38 PM | Attr = HS]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 1/29/2008 9:44:54 PM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 1/15/2008 3:26:56 PM | Attr = H ]
$NtUninstallKB937894$ -> %SystemRoot%\$NtUninstallKB937894$ -> [Folder | Modified Date = 1/15/2008 3:30:58 PM | Attr = H ]
$NtUninstallKB941568$ -> %SystemRoot%\$NtUninstallKB941568$ -> [Folder | Modified Date = 1/15/2008 3:28:48 PM | Attr = H ]
$NtUninstallKB941569$ -> %SystemRoot%\$NtUninstallKB941569$ -> [Folder | Modified Date = 1/15/2008 3:35:38 PM | Attr = H ]
$NtUninstallKB941644$ -> %SystemRoot%\$NtUninstallKB941644$ -> [Folder | Modified Date = 1/15/2008 3:35:52 PM | Attr = H ]
$NtUninstallKB942763$ -> %SystemRoot%\$NtUninstallKB942763$ -> [Folder | Modified Date = 1/15/2008 3:28:26 PM | Attr = H ]
$NtUninstallKB943485$ -> %SystemRoot%\$NtUninstallKB943485$ -> [Folder | Modified Date = 1/15/2008 3:36:02 PM | Attr = H ]
$NtUninstallKB944653$ -> %SystemRoot%\$NtUninstallKB944653$ -> [Folder | Modified Date = 1/15/2008 3:30:48 PM | Attr = H ]
CeEKey .INI -> %SystemRoot%\CeEKey .INI -> [Ver = | Size = 0 bytes | Modified Date = 1/17/2008 8:00:18 AM | Attr = ]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 1/4/2008 9:55:02 AM | Attr = S]
erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 1/27/2008 11:37:12 PM | Attr = ]
ERUNT -> %SystemRoot%\ERUNT -> [Folder | Modified Date = 1/28/2008 12:22:08 PM | Attr = ]
Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 1/16/2008 7:45:04 AM | Attr = R S]
ie7updates -> %SystemRoot%\ie7updates -> [Folder | Modified Date = 1/15/2008 3:29:04 PM | Attr = ]
imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 1/15/2008 3:35:56 PM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 1/26/2008 6:45:38 PM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 1/29/2008 8:44:24 PM | Attr = HS]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 1/30/2008 12:18:48 PM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Modified Date = 1/17/2008 3:47:16 PM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 1/29/2008 9:44:54 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 1/30/2008 10:24:54 AM | Attr = H ]
security -> %SystemRoot%\security -> [Folder | Modified Date = 1/25/2008 7:05:30 AM | Attr = ]
system -> %SystemRoot%\system -> [Folder | Modified Date = 1/25/2008 12:38:22 AM | Attr = ]
system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 246 bytes | Modified Date = 1/27/2008 11:40:10 PM | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 1/29/2008 8:44:04 PM | Attr = ]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 1/28/2008 1:32:30 PM | Attr = S]
TEMP -> %SystemRoot%\TEMP -> [Folder | Modified Date = 1/30/2008 7:59:24 AM | Attr = ]
vbaddin.ini -> %SystemRoot%\vbaddin.ini -> [Ver = | Size = 59 bytes | Modified Date = 1/29/2008 8:44:18 PM | Attr = ]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 705 bytes | Modified Date = 1/17/2008 3:52:08 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 1/30/2008 7:57:28 AM | Attr = H ]
3-D_Dancing_Skeleton_Demo dir -> %System32%\3-D_Dancing_Skeleton_Demo dir -> [Folder | Modified Date = 1/15/2008 9:01:24 AM | Attr = ]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 1/29/2008 5:37:58 PM | Attr = ]
config -> %System32%\config -> [Folder | Modified Date = 1/27/2008 11:37:26 PM | Attr = ]
dla -> %System32%\dla -> [Folder | Modified Date = 1/25/2008 12:33:22 AM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 1/25/2008 12:35:00 AM | Attr = RHS]
dpmw32 .exe -> %System32%\dpmw32 .exe -> Novell, Inc. [Ver = v3.0.1 | Size = 32859 bytes | Modified Date = 1/25/2008 12:34:52 AM | Attr = ]
drivers -> %System32%\drivers -> [Folder | Modified Date = 1/29/2008 8:13:34 PM | Attr = ]
FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 261432 bytes | Modified Date = 1/16/2008 2:53:02 PM | Attr = ]
FxsTmp -> %System32%\FxsTmp -> [Folder | Modified Date = 1/15/2008 11:47:42 AM | Attr = ]
lsdelete.exe -> %System32%\lsdelete.exe -> [Ver = | Size = 12632 bytes | Modified Date = 1/24/2008 11:55:48 PM | Attr = ]
Macromed -> %System32%\Macromed -> [Folder | Modified Date = 1/6/2008 5:06:44 PM | Attr = ]
nGpxx01 -> %System32%\nGpxx01 -> [Folder | Modified Date = 1/25/2008 2:32:24 PM | Attr = ]
QuickTime.qts -> %System32%\QuickTime.qts -> Apple Inc. [Ver = 7.4 | Size = 57344 bytes | Modified Date = 1/10/2008 3:27:44 PM | Attr = ]
QuickTimeVR.qtx -> %System32%\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.4 | Size = 90112 bytes | Modified Date = 1/10/2008 3:27:46 PM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 1158 bytes | Modified Date = 1/30/2008 7:57:54 AM | Attr = ]
avg7core.sys -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.498 | Size = 821856 bytes | Modified Date = 1/25/2008 12:39:48 AM | Attr = ]
avg7rsnt.sys -> %System32%\drivers\avg7rsnt.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 26944 bytes | Modified Date = 1/25/2008 12:40:22 AM | Attr = ]
avg7rsw.sys -> %System32%\drivers\avg7rsw.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,340 | Size = 4224 bytes | Modified Date = 1/25/2008 12:40:18 AM | Attr = ]
avg7rsxp.sys -> %System32%\drivers\avg7rsxp.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 27776 bytes | Modified Date = 1/25/2008 12:40:26 AM | Attr = ]
avgclean.sys -> %System32%\drivers\avgclean.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10760 bytes | Modified Date = 1/25/2008 12:43:52 AM | Attr = ]
avgmfx86.sys -> %System32%\drivers\avgmfx86.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.510 | Size = 26952 bytes | Modified Date = 1/25/2008 12:43:48 AM | Attr = ]
avgtdi.sys -> %System32%\drivers\avgtdi.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,346 | Size = 4960 bytes | Modified Date = 1/25/2008 12:40:26 AM | Attr = ]
core.cache.dsk -> %System32%\drivers\core.cache.dsk -> [Ver = | Size = 167545 bytes | Modified Date = 1/29/2008 8:13:36 PM | Attr = ]
etc -> %System32%\drivers\etc -> [Folder | Modified Date = 1/29/2008 8:01:14 PM | Attr = ]
pciidexx.sys -> %System32%\drivers\pciidexx.sys -> [Ver = | Size = 86016 bytes | Modified Date = 1/14/2008 4:36:44 PM | Attr = ]

[File String Scan - Non-Microsoft Only]
File scan skipped for file %SystemDrive%\$Persis0.dsk -> File size too big (1073741824 bytes) ->
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 3/31/2003 7:00:00 AM | Attr = ]
WSUD , -> %System32%\oembios.bin -> [Ver = | Size = 13107200 bytes | Modified Date = 9/2/2001 1:29:22 PM | Attr = ]
Thawte Consulting , -> %System32%\rmoc3260.dll -> RealNetworks, Inc. [Ver = 6.0.9.3084 | Size = 185944 bytes | Modified Date = 11/19/2007 12:11:26 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.11 | Size = 156160 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ]
UPX! , UPX0 , -> %System32%\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 3/31/2003 7:00:00 AM | Attr = ]
UPX! , FSG! , PEC2 , aspack , -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.498 | Size = 821856 bytes | Modified Date = 1/25/2008 12:39:48 AM | Attr = ]
PTech , -> %System32%\drivers\mtlstrm.sys -> Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 8/3/2004 9:41:38 PM | Attr = ]

< End of report >
faithmrose
Geek in Training
Geek in Training
 
Posts: 25
Joined: Fri Jan 25, 2008 8:11 pm

Thanks given:0
Thanks received:0
Top

Panda?

Postby faithmrose » Wed Jan 30, 2008 6:34 pm

Panda components keep showing up. I definitely don't have Panda installed and can't find it anywhere. Is that it?
faithmrose
Geek in Training
Geek in Training
 
Posts: 25
Joined: Fri Jan 25, 2008 8:11 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Thu Jan 31, 2008 12:17 am

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Avenger log

Postby faithmrose » Thu Jan 31, 2008 5:02 pm

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\iugvccis

*******************

Script file located at: \??\C:\pecc^rvf.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Driver catchme unloaded successfully.


Could not open file C:\Documents and Settings\Teacher\LocalService\Temp\catchme.sys for deletion
Deletion of file C:\Documents and Settings\Teacher\LocalService\Temp\catchme.sys failed!

Could not process line:
C:\Documents and Settings\Teacher\LocalService\Temp\catchme.sys
Status: 0xc000003a

File C:\WINDOWS\system32\drivers\core.cache.dsk deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
faithmrose
Geek in Training
Geek in Training
 
Posts: 25
Joined: Fri Jan 25, 2008 8:11 pm

Thanks given:0
Thanks received:0
Top

Post avenger HJT log

Postby faithmrose » Thu Jan 31, 2008 5:03 pm

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:03:15 AM, on 1/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bishopmcdevitt.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.17.2.244:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139673470\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [MP10_EnsureFileVer] C:\WINDOWS\inf\unregmp2.exe /EnsureFileVersions
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser .exe" -m
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccomm ... ctlins.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microso ... 8239107062
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 8232323093
O20 - Winlogon Notify: DfLogon - C:\WINDOWS\SYSTEM32\LogonDll.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\ACS.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\System32\cusrvc.exe
O23 - Service: DF5Serv - Faronics Corporation - C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe

--
End of file - 7870 bytes
faithmrose
Geek in Training
Geek in Training
 
Posts: 25
Joined: Fri Jan 25, 2008 8:11 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Fri Feb 01, 2008 2:10 am

faithmrose

siri has writen a new Smitfraud fix that is suppose to delete this core.cache.dsk infection.

Please download

1. Double click on SmitfraudFix.exe.
2. Press 1 then hit the Enter key.
3. It will create a report named rapport.txt, usually at C drive.
4. Please post back this log in your next reply.


Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool";
it is not a virus, but a program used to stop system processes.
Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Rappot log

Postby faithmrose » Fri Feb 01, 2008 5:20 pm

SmitFraudFix v2.277

Scan done at 10:59:33.25, Fri 02/01/2008
Run from C:\Documents and Settings\Teacher\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RAMASST.exe
\\lab1\sys\public\clntrust.exe
Z:\nalexpld.exe
C:\WINDOWS\system32\NALDESK.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Teacher


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Teacher\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Teacher\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Wireless-G Notebook Adapter v.2.0 - Packet Scheduler Miniport
DNS Server Search Order: 68.87.72.130
DNS Server Search Order: 68.87.77.130

HKLM\SYSTEM\CCS\Services\Tcpip\..\{80F2B74F-A692-434C-B547-545156571B91}: DhcpNameServer=68.87.72.130 68.87.77.130
HKLM\SYSTEM\CS1\Services\Tcpip\..\{80F2B74F-A692-434C-B547-545156571B91}: DhcpNameServer=68.87.72.130 68.87.77.130
HKLM\SYSTEM\CS2\Services\Tcpip\..\{80F2B74F-A692-434C-B547-545156571B91}: DhcpNameServer=68.87.72.130 68.87.77.130
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=68.87.72.130 68.87.77.130
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=68.87.72.130 68.87.77.130
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=68.87.72.130 68.87.77.130


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
faithmrose
Geek in Training
Geek in Training
 
Posts: 25
Joined: Fri Jan 25, 2008 8:11 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Fri Feb 01, 2008 10:16 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

avenger log

Postby faithmrose » Sun Feb 03, 2008 2:32 am

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\avwfxrxs

*******************

Script file located at: uopajpva

Could not open script file! Error

Could not open script file! Status: 0xc000003b Abort!
faithmrose
Geek in Training
Geek in Training
 
Posts: 25
Joined: Fri Jan 25, 2008 8:11 pm

Thanks given:0
Thanks received:0
Top

PreviousNext

Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron