McAfee Detected Trojan
-
McAfee Detected Trojan
Hi, McAfee detected a Trojan during a scheduled scan on my PC and I get pop up windows saying 'Your computer contains a variety of suspicious programs...'. I have followed your recommended procedure prior to posting and include the logs from Malwarebytes, MBRcheck and the two DDS logs below. I have been unable to post the log from GMER as I get repeated timeouts when I try. This appears to be due to the size of the log as I am able to post it in sections. Can you suggest another way of doing it, perhaps either as sections in reply to this post or as an attachment? Thanks in advance.
Last edited by broni; 23-01-2011 at 09:08 PM.
-
Welcome aboard 
Please, observe following rules:
- Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
- If you're stuck, or you're not sure about certain step, always ask before doing anything else.
- Please refrain from running tools or applying updates other than those I suggest.
- Never run more than one scan at a time.
- Keep updating me regarding your computer behavior, good, or bad.
- The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
- If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
- I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
================================================== ===================================
I'm not sure, what you did, but your logs are not readable.
Please, repost.
-
Thanks for your reply. I don't know what happened to the formatting, but I posted the logs by copying and pasting from Notepad and when I did a Post Preview it looked okay. I'll try again and see if it works this time. I still can't post GMER though as it times out due to the size.
Last edited by broni; 23-01-2011 at 09:09 PM.
-
No, it's still not worked. I'm copying and pasting from Notepad and it looks okay when I do a Post Preview. Is this correct or am I doing something wrong?
-
I'm going to try to post one log per reply and see if that works.
-
Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes
Database version: 5564
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
21/01/2011 09:20:23
mbam-log-2011-01-21 (09-20-23).txt
Scan type: Quick scan
Objects scanned: 161017
Time elapsed: 5 minute(s), 14 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\Windows Safety Alert (Trojan.Zlob) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
-
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003c
Kernel Drivers (total 207):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806FF000 \WINDOWS\system32\hal.dll
0xF7987000 \WINDOWS\system32\KDCOM.DLL
0xF7897000 \WINDOWS\system32\BOOTVID.dll
0xF75A8000 ACPI.sys
0xF7989000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF7597000 pci.sys
0xF75F7000 isapnp.sys
0xF7A4F000 pciide.sys
0xF7707000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF798B000 aliide.sys
0xF798D000 cmdide.sys
0xF798F000 toside.sys
0xF7991000 viaide.sys
0xF7993000 intelide.sys
0xF7607000 MountMgr.sys
0xF74D8000 ftdisk.sys
0xF770F000 PartMgr.sys
0xF7617000 VolSnap.sys
0xF789B000 cpqarray.sys
0xF74C0000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF74A8000 atapi.sys
0xF789F000 aha154x.sys
0xF7717000 sparrow.sys
0xF78A3000 symc810.sys
0xF7627000 aic78xx.sys
0xF78A7000 dac960nt.sys
0xF7637000 ql10wnt.sys
0xF78AB000 amsint.sys
0xF771F000 asc.sys
0xF78AF000 asc3550.sys
0xF7727000 mraid35x.sys
0xF772F000 i2omp.sys
0xF78B3000 ini910u.sys
0xF7647000 ql1240.sys
0xF7657000 aic78u2.sys
0xF7737000 symc8xx.sys
0xF773F000 sym_hi.sys
0xF7747000 sym_u3.sys
0xF774F000 ABP480N5.SYS
0xF7757000 asc3350p.sys
0xF7995000 cd20xrnt.sys
0xF7667000 ultra.sys
0xF787E000 adpu160m.sys
0xF775F000 dpti2o.sys
0xF7677000 ql1080.sys
0xF7687000 ql1280.sys
0xF7697000 ql12160.sys
0xF7767000 perc2.sys
0xF7997000 perc2hib.sys
0xF776F000 hpn.sys
0xF78B7000 cbidf2k.sys
0xF7852000 dac2w2k.sys
0xF76A7000 disk.sys
0xF76B7000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7832000 fltmgr.sys
0xF7975000 sr.sys
0xF7B82000 mfehidk.sys
0xF7960000 drvmcdb.sys
0xF7777000 PxHelp20.sys
0xF7A38000 KSecDD.sys
0xF7AF5000 Ntfs.sys
0xF7A0B000 NDIS.sys
0xF76C7000 sisagp.sys
0xF76D7000 viaagp.sys
0xF7ADB000 Mup.sys
0xF76E7000 agp440.sys
0xF76F7000 alim1541.sys
0xF7587000 amdagp.sys
0xF7577000 agpCPQ.sys
0xB9E2D000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB9D02000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
0xB9CEE000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF77B7000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB9CCA000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF77BF000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB9E1D000 \SystemRoot\system32\DRIVERS\IntelC53.sys
0xB9CA7000 \SystemRoot\system32\DRIVERS\ks.sys
0xB9B80000 \SystemRoot\system32\DRIVERS\IntelC51.sys
0xB9AEB000 \SystemRoot\system32\DRIVERS\IntelC52.sys
0xF77C7000 \SystemRoot\system32\DRIVERS\mohfilt.sys
0xF77CF000 \SystemRoot\System32\Drivers\Modem.SYS
0xB9E0D000 \SystemRoot\system32\DRIVERS\bcm4sbxp.sys
0xB9AAB000 \SystemRoot\system32\drivers\smwdm.sys
0xB9A87000 \SystemRoot\system32\drivers\portcls.sys
0xB9DED000 \SystemRoot\system32\drivers\drmk.sys
0xB99D4000 \SystemRoot\system32\drivers\senfilt.sys
0xB99C0000 \SystemRoot\system32\DRIVERS\parport.sys
0xB9DDD000 \SystemRoot\system32\DRIVERS\serial.sys
0xBA6A8000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF74F7000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF7498000 \SystemRoot\System32\Drivers\AFS2K.SYS
0xF79C5000 \SystemRoot\system32\drivers\sscdbhk5.sys
0xF7488000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF7478000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF7A8A000 \SystemRoot\system32\DRIVERS\audstub.sys
0xB9975000 \SystemRoot\system32\DRIVERS\mfendisk.sys
0xF7418000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xBA68B000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB995E000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF7408000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xBA7F0000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF77D7000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB994D000 \SystemRoot\system32\DRIVERS\psched.sys
0xBA7E0000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xB9929000 \SystemRoot\system32\drivers\mfeavfk.sys
0xB98B6000 \SystemRoot\system32\drivers\mfefirek.sys
0xF77DF000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF77E7000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF77EF000 \SystemRoot\system32\DRIVERS\wanatw4.sys
0xBA7D0000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF77F7000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF77FF000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF79DF000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB9808000 \SystemRoot\system32\DRIVERS\update.sys
0xBA364000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF7807000 \SystemRoot\system32\DRIVERS\omci.sys
0xBA7A0000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xBA790000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF79E3000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xBA6D0000 \SystemRoot\system32\drivers\MODEMCSA.sys
0xBA6BC000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xF79FB000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7ABA000 \SystemRoot\System32\Drivers\Null.SYS
0xF79FD000 \SystemRoot\System32\Drivers\Beep.SYS
0xF781F000 \SystemRoot\system32\drivers\ssrtln.sys
0xF7ABC000 \SystemRoot\System32\DRIVERS\AvgAsCln.sys
0xBA738000 \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys
0xBA730000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xBA728000 \SystemRoot\System32\drivers\vga.sys
0xF79FF000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7A01000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xBA720000 \SystemRoot\System32\Drivers\Msfs.SYS
0xBA718000 \SystemRoot\System32\Drivers\Npfs.SYS
0xBA6B0000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xB13AA000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xB1351000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xB133E000 \SystemRoot\system32\drivers\mfetdi2k.sys
0xB1318000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xB12F0000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF7527000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xB12CE000 \SystemRoot\System32\drivers\afd.sys
0xF7517000 \SystemRoot\system32\DRIVERS\netbios.sys
0xB12A3000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xF7A58000 \SystemRoot\System32\Drivers\PQNTDrv.SYS
0xB120B000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF7507000 \SystemRoot\System32\Drivers\Fips.SYS
0xF7A59000 \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
0xF7468000 \SystemRoot\system32\DRIVERS\alcaudsl.sys
0xF79EF000 \SystemRoot\system32\DRIVERS\alcawh.sys
0xBA598000 \SystemRoot\system32\DRIVERS\alcacr.sys
0xBA6F0000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xF7458000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xBA6C0000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF7448000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xF779F000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xF7438000 \SystemRoot\system32\DRIVERS\alcan5wn.sys
0xB0FDD000 \SystemRoot\system32\DRIVERS\LVMVDrv.sys
0xF7428000 \SystemRoot\system32\drivers\LVUSBSta.sys
0xB0EF9000 \SystemRoot\system32\DRIVERS\LV302V32.SYS
0xF79F5000 \SystemRoot\system32\DRIVERS\lv302af.sys
0xB14A9000 \SystemRoot\system32\drivers\usbaudio.sys
0xB0CBD000 \SystemRoot\system32\DRIVERS\LVcKap.sys
0xB129F000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xB1297000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xB1293000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xF77A7000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xF77AF000 \SystemRoot\system32\DRIVERS\HPZius12.sys
0xB1499000 \SystemRoot\system32\DRIVERS\HPZid412.sys
0xB127B000 \SystemRoot\system32\DRIVERS\HPZipr12.sys
0xB0C5A000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xB13C9000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB17D0000 \SystemRoot\System32\drivers\Dxapi.sys
0xB98AE000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA259000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF04A000 \SystemRoot\System32\ati2cqag.dll
0xBF084000 \SystemRoot\System32\ati3duag.dll
0xBF2A7000 \SystemRoot\System32\ativvaxx.dll
0xAFBE3000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xB0EE9000 \SystemRoot\system32\drivers\drvnddm.sys
0xB14F7000 \SystemRoot\system32\dla\tfsndres.sys
0xAFAB5000 \SystemRoot\system32\dla\tfsnifs.sys
0xB17D4000 \SystemRoot\system32\dla\tfsnopio.sys
0xB13C3000 \SystemRoot\system32\dla\tfsnpool.sys
0xB98A6000 \SystemRoot\system32\dla\tfsnboio.sys
0xB0ED9000 \SystemRoot\system32\dla\tfsncofs.sys
0xB14E9000 \SystemRoot\system32\dla\tfsndrct.sys
0xAFA9C000 \SystemRoot\system32\dla\tfsnudf.sys
0xAFA83000 \SystemRoot\system32\dla\tfsnudfa.sys
0xAFB3F000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xAF84E000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF79B3000 \SystemRoot\System32\Drivers\ASCTRM.SYS
0xAF967000 \SystemRoot\System32\Drivers\Aspi32.SYS
0xF79B5000 \SystemRoot\system32\DRIVERS\dsunidrv.sys
0xAF6B6000 \SystemRoot\system32\DRIVERS\srv.sys
0xAF32E000 \SystemRoot\system32\drivers\sysaudio.sys
0xAF0DD000 \SystemRoot\system32\drivers\wdmaud.sys
0xAF095000 \SystemRoot\system32\drivers\cfwids.sys
0xB988E000 \SystemRoot\system32\DRIVERS\LVPr2Mon.sys
0xAE784000 \SystemRoot\System32\Drivers\HTTP.sys
0xAE537000 \SystemRoot\system32\drivers\mfeapfk.sys
0xAE825000 \SystemRoot\system32\drivers\mfebopk.sys
0xADFFF000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\SYSTEM32\ntdll.dll
Processes (total 71):
0 System Idle Process
4 System
668 C:\WINDOWS\SYSTEM32\smss.exe
1048 csrss.exe
1072 C:\WINDOWS\SYSTEM32\winlogon.exe
1116 C:\WINDOWS\SYSTEM32\services.exe
1128 C:\WINDOWS\SYSTEM32\lsass.exe
1300 C:\WINDOWS\SYSTEM32\ati2evxx.exe
1316 C:\WINDOWS\SYSTEM32\svchost.exe
1416 svchost.exe
1456 C:\WINDOWS\SYSTEM32\svchost.exe
1604 svchost.exe
1692 C:\WINDOWS\SYSTEM32\spoolsv.exe
1732 C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
1780 svchost.exe
1816 C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
1828 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
1856 C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
1920 C:\WINDOWS\SYSTEM32\svchost.exe
1948 C:\Program Files\Java\jre6\bin\jqs.exe
2020 C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
240 C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
260 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
320 C:\WINDOWS\SYSTEM32\svchost.exe
340 C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
376 C:\WINDOWS\SYSTEM32\svchost.exe
436 C:\Program Files\Dell Support Center\bin\sprtsvc.exe
508 C:\WINDOWS\SYSTEM32\svchost.exe
588 C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
748 C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
2396 C:\WINDOWS\explorer.exe
2444 C:\WINDOWS\SYSTEM32\rundll32.exe
2652 C:\Program Files\Analog Devices\Core\smax4pnp.exe
2712 C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
2724 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
2732 C:\Program Files\Real\RealPlayer\realplay.exe
2768 C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
2804 C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
2828 C:\Program Files\Dell\Media Experience\DMXLauncher.exe
2844 C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
2860 C:\Program Files\Thomson\SpeedTouch USB\dragdiag.exe
2892 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
2904 C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
2956 C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
2976 C:\PROGRA~1\Yahoo!\browser\ycommon.exe
3020 C:\Program Files\Dell Support Center\bin\sprtcmd.exe
3076 C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
3192 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3212 C:\Program Files\McAfee.com\Agent\mcagent.exe
3304 C:\Program Files\Microsoft Money\System\Money Express.exe
3332 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
3360 C:\WINDOWS\SYSTEM32\ctfmon.exe
3368 C:\Program Files\Swift To-Do List\Swift To-Do List Lite.exe
3384 C:\Program Files\AOL 9.0\aoltray.exe
3440 C:\Program Files\FinePixViewer\QuickDCF.exe
3452 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
3728 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
3764 C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
3804 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
3972 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
3988 C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
4040 C:\Program Files\ClickTray Calendar\ClickTray.exe
2196 alg.exe
3424 C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
4024 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe
1616 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
2204 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
3280 C:\Program Files\Internet Explorer\iexplore.exe
2864 C:\WINDOWS\SYSTEM32\wuauclt.exe
4100 wmiprvse.exe
4416 C:\Downloads\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`036e8e00 (NTFS)
\\.\E: --> \\.\PhysicalDrive0 at offset 0x00000011`1e7ad400 (NTFS)
\\.\F: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32)
PhysicalDrive0 Model Number: Maxtor6Y160M0, Rev: YAR51HW0
PhysicalDrive1 Model Number: HitachiHTS543225L9A300, Rev:
Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Dell MBR code detected
SHA1: 84B95CE8A54B7C5C3AAF149934FC46FB70FF8365
232 GB \\.\PhysicalDrive1 RE: Unknown MBR code
SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98F
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done!
-
DDS (Ver_10-12-12.02) - NTFSx86
Run by Malc at 16:05:07.89 on 21/01/2011
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.1030 [GMT 0:00]
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Microsoft Money\System\Money Express.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Swift To-Do List\Swift To-Do List Lite.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\ClickTray Calendar\ClickTray.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe"
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: UberButton Class: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: YahooTaggedBM Class: {65d886a2-7ca7-479b-bb95-14d1efb7946a} - c:\program files\yahoo!\common\YIeTagBm.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20101106210637.dl l
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\s wg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: {84938242-5C5B-4A55-B6B9-A1507543B418} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MoneyAgent] c:\program files\microsoft money\system\Money Express.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Yahoo! Pager] c:\progra~1\yahoo!\messen~1\ypager.exe -quiet
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNo tifier.exe"
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SwiftToDoListLite] "c:\program files\swift to-do list\Swift To-Do List Lite.exe" minimized
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [<NO NAME>]
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [AOL Spyware Protection] "c:\progra~1\common~1\aol\aolspy~1\AOLSP Scheduler.exe"
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [GhostStartTrayApp] c:\program files\symantec\norton ghost 2003\GhostStartTrayApp.exe
mRun: [SpeedTouch USB Diagnostics] "c:\program files\thomson\speedtouch usb\Dragdiag.exe" /icon
mRun: [YBrowser] c:\progra~1\yahoo!\browser\ybrwicon.exe
mRun: [TaskPlus] c:\program files\taskplus\taskplus0.exe
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam10\QuickCam10.exe" /hide
mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe
mRun: [hpqSRMon] c:\program files\hewlett-packard\digital imaging\bin\hpqSRMon.exe
mRun: [NBKeyScan] "c:\program files\nero\nero backitup 4\NBKeyScan.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\malc\startm~1\programs\startup\clickt~ 1.lnk - c:\program files\clicktray calendar\ClickTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\aol 90t~1.lnk - c:\program files\aol 9.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bty aho~1.lnk - c:\program files\bt yahoo\bt yahoo help\bin\matcli.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\exi fla~1.lnk - c:\program files\finepixviewer\QuickDCF.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpd igi~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpp sc1~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpohmr08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpo ddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\log ite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger .exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mic ros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_BHO.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {A91F4526-6347-4F73-84F9-28F3057584F0} = 62.6.40.166 217.32.171.21
Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - c:\program files\tiscali\tiscali internet\dlls\tiscalifilter.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: CShellExecuteHookImpl Object: {57b86673-276a-48b2-bae7-c6dbb3020eb8} - c:\program files\grisoft\avg anti-spyware 7.5\shellexecutehook.dll
============= SERVICES / DRIVERS ===============
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-5-9 386840]
R1 AVG Anti-Spyware Driver;AVG Anti-Spyware Driver;c:\program files\grisoft\avg anti-spyware 7.5\guard.sys [2006-9-28 4096]
R1 AvgAsCln;AVG Anti-Spyware Clean Driver;c:\windows\system32\drivers\AvgAsCln.sys [2007-3-25 3968]
R1 GhPciScan;GhostPciScanner;c:\program files\symantec\norton ghost 2003\GhPciScan.sys [2002-8-14 5632]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-5-9 84072]
R2 AVG Anti-Spyware Guard;AVG Anti-Spyware Guard;c:\program files\grisoft\avg anti-spyware 7.5\guard.exe [2006-9-28 204800]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-5-9 271480]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-5-9 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-5-9 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-5-9 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-5-9 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-5-9 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-5-9 141792]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-5-9 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-5-9 152960]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-5-9 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-5-9 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\ mfendisk.sys [2010-5-9 88544]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-5-9 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-5-9 84264]
=============== Created Last 30 ================
2011-01-21 09:12:59 -------- d-----w- c:\docume~1\malc\applic~1\Malwarebytes
2011-01-21 09:12:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-21 09:12:41 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-01-21 09:12:38 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-21 09:12:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
==================== Find3M ====================
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52:35 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:34:12 832512 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:34:11 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-11-06 00:34:11 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-06 00:34:11 17408 ----a-w- c:\windows\system32\corpol.dll
2010-11-03 12:25:53 389120 ----a-w- c:\windows\system32\html.iec
2010-10-28 13:13:22 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25:00 1853312 ----a-w- c:\windows\system32\win32k.sys
2007-10-16 11:23:50 98526681 ----a-w- c:\program files\phoenixRC_demo_EN.exe
2007-04-07 16:54:53 2301007 ----a-w- c:\program files\swifttodolistlite.exe
2007-03-25 11:35:54 5037072 ----a-w- c:\program files\spybotsd14.exe
2007-03-25 11:24:35 218112 ----a-w- c:\program files\hijackthis.exe
============= FINISH: 16:12:07.14 ===============
-
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 08/04/2005 15:57:35
System Uptime: 21/01/2011 15:31:36 (1 hours ago)
Motherboard: Dell Inc. | | 0W5363
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Microprocessor | 2992/800mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 68 GiB total, 47.37 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 78 GiB total, 70.72 GiB free.
F: is FIXED (FAT32) - 233 GiB total, 174.393 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1862: 24/10/2010 01:04:37 - System Checkpoint
RP1863: 24/10/2010 08:50:57 - Pre Java Update
RP1864: 25/10/2010 09:20:02 - System Checkpoint
RP1865: 26/10/2010 10:28:30 - System Checkpoint
RP1866: 27/10/2010 12:24:17 - System Checkpoint
RP1867: 29/10/2010 08:08:55 - Pre Adobe Upgrade
RP1868: 30/10/2010 09:51:48 - System Checkpoint
RP1869: 31/10/2010 18:33:05 - System Checkpoint
RP1870: 01/11/2010 20:33:41 - System Checkpoint
RP1871: 03/11/2010 17:03:47 - System Checkpoint
RP1872: 04/11/2010 17:22:06 - System Checkpoint
RP1873: 05/11/2010 18:00:18 - System Checkpoint
RP1874: 06/11/2010 18:57:47 - System Checkpoint
RP1875: 08/11/2010 08:37:00 - System Checkpoint
RP1876: 09/11/2010 10:42:11 - System Checkpoint
RP1877: 10/11/2010 12:42:55 - System Checkpoint
RP1878: 11/11/2010 01:33:57 - Software Distribution Service 3.0
RP1879: 12/11/2010 19:41:07 - System Checkpoint
RP1880: 13/11/2010 20:57:35 - System Checkpoint
RP1881: 15/11/2010 08:32:35 - System Checkpoint
RP1882: 16/11/2010 09:11:41 - System Checkpoint
RP1883: 17/11/2010 11:46:19 - System Checkpoint
RP1884: 18/11/2010 12:20:30 - System Checkpoint
RP1885: 19/11/2010 14:22:49 - System Checkpoint
RP1886: 20/11/2010 18
47 - System Checkpoint
RP1887: 22/11/2010 07:29:58 - System Checkpoint
RP1888: 23/11/2010 10:25:47 - System Checkpoint
RP1889: 24/11/2010 12
15 - Pre Java Update
RP1890: 24/11/2010 12:22:18 - Installed Java(TM) 6 Update 22
RP1891: 25/11/2010 15:12:29 - System Checkpoint
RP1892: 26/11/2010 15:31:02 - System Checkpoint
RP1893: 27/11/2010 19:19:02 - System Checkpoint
RP1894: 28/11/2010 08:29:54 - Pre Adobe Flash upgrade
RP1895: 29/11/2010 13:50:08 - System Checkpoint
RP1896: 30/11/2010 15:12:42 - System Checkpoint
RP1897: 01/12/2010 16:27:34 - System Checkpoint
RP1898: 01/12/2010 19:38:04 - Pre Photorec5 install
RP1899: 03/12/2010 09:54:46 - System Checkpoint
RP1900: 04/12/2010 10:02:32 - Restore Operation
RP1901: 04/12/2010 10:12:51 - Restore Operation
RP1902: 04/12/2010 12:13:44 - Restore Operation
RP1903: 04/12/2010 12:28:09 - Restore Operation
RP1904: 05/12/2010 18:42:19 - System Checkpoint
RP1905: 06/12/2010 19:10:41 - System Checkpoint
RP1906: 08/12/2010 10:25:07 - System Checkpoint
RP1907: 09/12/2010 11:11:21 - System Checkpoint
RP1908: 10/12/2010 12:24:06 - System Checkpoint
RP1909: 11/12/2010 13:30:57 - System Checkpoint
RP1910: 12/12/2010 14:50:51 - System Checkpoint
RP1911: 13/12/2010 19:35:03 - System Checkpoint
RP1912: 15/12/2010 08:25:12 - System Checkpoint
RP1913: 16/12/2010 00:38:46 - Software Distribution Service 3.0
RP1914: 17/12/2010 10:15:17 - System Checkpoint
RP1915: 18/12/2010 11:00:05 - System Checkpoint
RP1916: 19/12/2010 12:31:36 - System Checkpoint
RP1917: 20/12/2010 12:53:40 - System Checkpoint
RP1918: 21/12/2010 15:16:59 - System Checkpoint
RP1919: 22/12/2010 15:23:38 - System Checkpoint
RP1920: 23/12/2010 16:39:15 - System Checkpoint
RP1921: 24/12/2010 17:35:55 - System Checkpoint
RP1922: 26/12/2010 12:40:33 - System Checkpoint
RP1923: 27/12/2010 16:36:37 - System Checkpoint
RP1924: 28/12/2010 11:06:08 - Pre Java Update
RP1925: 29/12/2010 11:06:25 - System Checkpoint
RP1926: 30/12/2010 12:14:07 - System Checkpoint
RP1927: 31/12/2010 12:15:02 - System Checkpoint
RP1928: 02/01/2011 09:20:59 - Software Distribution Service 3.0
RP1929: 03/01/2011 10:05:06 - System Checkpoint
RP1930: 04/01/2011 11:48:23 - System Checkpoint
RP1931: 05/01/2011 16:16:00 - System Checkpoint
RP1932: 06/01/2011 09:30:45 - Software Distribution Service 3.0
RP1933: 07/01/2011 10:32:39 - System Checkpoint
RP1934: 09/01/2011 10:42:16 - System Checkpoint
RP1935: 10/01/2011 11:42:58 - System Checkpoint
RP1936: 11/01/2011 15:04:50 - System Checkpoint
RP1937: 12/01/2011 15:16:20 - System Checkpoint
RP1938: 12/01/2011 23:02:38 - Software Distribution Service 3.0
RP1939: 14/01/2011 01
30 - System Checkpoint
RP1940: 15/01/2011 10:36:38 - System Checkpoint
RP1941: 16/01/2011 13:27:06 - System Checkpoint
RP1942: 17/01/2011 14:31:33 - System Checkpoint
RP1943: 18/01/2011 14:33:12 - System Checkpoint
RP1944: 19/01/2011 15:46:37 - System Checkpoint
RP1945: 20/01/2011 16:40:37 - System Checkpoint
==== Installed Programs ======================
32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Reader 8.2.5
Advertising Center
AOL Coach Version 1.0(Build:20040201.2 uk)
AOL Connectivity Services
AOL Spyware Protection
AOL UK (Choose which version to remove)
AOL You've Got Pictures Screensaver
ArcSoft VideoImpression 1.6FP
ATI Control Panel
ATI Display Driver
AVG Anti-Spyware 7.5
Broadcom Management Programs
BT Openworld Dell Signup
BT Yahoo! Applications
BT Yahoo! Broadband Internet Connection Manager 4.2
BT Yahoo! Help
BTOffer
BufferChm
Camera Window
Canon Camera Window for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon PhotoRecord
Canon Utilities File Viewer Utility 1.2
Canon Utilities PhotoStitch 3.1
Canon Utilities RemoteCapture 2.7
Canon Utilities ZoomBrowser EX
CIG
ClickTray Calendar
Compatibility Pack for the 2007 Office system
Copy
Critical Update for Windows Media Player 11 (KB959772)
CustomerResearchQFolder
Dell Driver Reset Tool
Dell Media Experience
Dell Support Center (Support Software)
Dell System Restore
DellSupport
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DJ_AIO_03_F4200_ProductContext
DJ_AIO_03_F4200_Software
DJ_AIO_03_F4200_Software_Min
eSupportQFolder
F4200
F4200_Help
File Viewer Utility 1.2.2
FinePixViewer Ver.3.0
FUJIFILM USB Driver
Google Earth
Google Toolbar for Internet Explorer
GPBaseService
GPBaseService2
HijackThis 1.99.1
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Customer Participation Program 10.0
HP Deskjet F4200 All-In-One Driver Software 10.0 Rel .3
HP Imaging Device Functions 10.0
hp instant support
HP Memories Disc
HP Photo and Imaging 2.0 - All-in-One
HP Photo and Imaging 2.0 - All-in-One Drivers
HP Photo and Imaging 2.0 - hp psc 1200 series
HP Photosmart Essential 2.5
hp psc 1200 series
HP Smart Web Printing
HP Solution Center 13.0
HP Update
HPProductAssistant
HPSSupply
Intel(R) 537EP V9x DF PCI Modem
Internet Explorer Default Page
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2_03
Java Auto Updater
Java(TM) 6 Update 2
Java(TM) 6 Update 22
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Runtime Environment 6 Update 1
Learn2 Player (Uninstall Only)
LiveReg (Symantec Corporation)
LiveUpdate 1.80 (Symantec Corporation)
Logitech Audio Echo Cancellation Component
Logitech Desktop Messenger
Logitech QuickCam
Logitech Video Enumerator
Logitech® Camera Driver
Malwarebytes' Anti-Malware
MarketResearch
McAfee Internet Security
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2001
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Premium
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 7.0
Modem Event Monitor
Modem Helper
Modem On Hold
MSN
MSVCSetup
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MVision
Nero BackItUp
Nero BackItUp 4 Essentials
Nero ControlCenter
Nero Installer
Norton Ghost
PartitionMagic
PhoenixRC
PhotoStitch
PowerDVD 5.3
PowerQuest PartitionMagic 8.0
PSSWCORE
QuickTime
RealPlayer Basic
Registry Mechanic 6.0
RemoteCapture 2.7.2
Scan
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB2183461)
Security Update for Windows Internet Explorer 7 (KB2360131)
Security Update for Windows Internet Explorer 7 (KB2416400)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Shop for HP Supplies
Skype™ 3.8
SmartWebPrintingOC
SolutionCenter
Sonic DLA
Sonic MyDVD
Sonic RecordNow!
Sonic Update Manager
SpeedTouch USB Software
Status
Swift To-Do List Lite 1.30
Tiscali Internet
Toolbox
TrayApp
UnloadSupport
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VideoToolkit01
Viewpoint Media Player
WebFldrs XP
WebReg
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
21/01/2011 12:36:37, error: System Error [1003] - Error code 10000050, parameter1 ae2aeb30, parameter2 00000001, parameter3 adb573a5, parameter4 00000000.
21/01/2011 09:31:53, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p asc3550 cbidf cd20xrnt CmdIde Cpqarray dac2w2k dac960nt dpti2o hpn i2omp ini910u IntelIde mraid35x perc2 perc2hib ql1080 Ql10wnt ql12160 ql1240 ql1280 sisagp Sparrow symc810 symc8xx sym_hi sym_u3 TosIde ultra viaagp ViaIde
21/01/2011 09:30:44, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
21/01/2011 08:50:29, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 1 time(s).
21/01/2011 08:50:29, error: Service Control Manager [7031] - The McAfee VirusScan Announcer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
21/01/2011 08:50:29, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
21/01/2011 08:50:29, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
21/01/2011 08:50:29, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
21/01/2011 08:50:29, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
21/01/2011 08:50:29, error: Service Control Manager [7031] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
21/01/2011 08:50:26, error: Service Control Manager [7034] - The SupportSoft Sprocket Service (dellsupportcenter) service terminated unexpectedly. It has done this 1 time(s).
21/01/2011 08:50:26, error: Service Control Manager [7034] - The PLFlash DeviceIoControl Service service terminated unexpectedly. It has done this 1 time(s).
21/01/2011 08:50:26, error: Service Control Manager [7031] - The Nero BackItUp Scheduler 4.0 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 500 milliseconds: Restart the service.
21/01/2011 08:50:25, error: Service Control Manager [7034] - The Process Monitor service terminated unexpectedly. It has done this 1 time(s).
21/01/2011 08:50:25, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
21/01/2011 08:50:25, error: Service Control Manager [7034] - The GhostStartService service terminated unexpectedly. It has done this 1 time(s).
21/01/2011 08:50:25, error: Service Control Manager [7034] - The AVG Anti-Spyware Guard service terminated unexpectedly. It has done this 1 time(s).
21/01/2011 08:50:25, error: Service Control Manager [7034] - The AOL Connectivity Service service terminated unexpectedly. It has done this 1 time(s).
21/01/2011 08:50:24, error: Service Control Manager [7034] - The Ati HotKey Poller service terminated unexpectedly. It has done this 1 time(s).
15/01/2011 09:53:22, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
==== End Of File ===========================
-
Well, posting one log per reply appears to have worked. I still can't post GMER in its entirety though as I think it's just too large. I'll try breaking it down into sections and posting one section per reply.