<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Re: [Trojan] Trojan detected, may be clean now, just making sure&#x27; in forum &#x27;Security Cleanup&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27313719</link>
<description></description>
<language>en</language>
<pubDate>Sun, 19 May 2013 01:49:49 EDT</pubDate>
<lastBuildDate>Sun, 19 May 2013 01:49:49 EDT</lastBuildDate>

<item>
<title>Re: [Trojan] Trojan detected, may be clean now, just making sure</title>
<link>http://www.dslreports.com/forum/Re-Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27318077</link>
<description><![CDATA[anon posted : Done, done, done, and done. Thanks so much, seriously. I wish more people would be so willing to freely give the use of their talents! The world would be much different.<br><br>Peace]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27318077</guid>
<pubDate>Wed, 11 Jul 2012 11:59:32 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] Trojan detected, may be clean now, just making sure</title>
<link>http://www.dslreports.com/forum/Re-Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27315907</link>
<description><![CDATA[LoPhatPhuud posted : Looks good from here. Time to cleanup and move on.....<br><br><b>Cleaning Up:</b><br><br><i>Delete TFC</i>:<br><ul><li> Delete the TFC icon on your Desktop</ul><br><i>Delete OTL</i>:<br><ul><li> Double click the OTL icon on your Desktop<br><li> Press the 'Cleanup' button</ul>&#9;<br><i>Delete Security Check</i>:<br><ul><li> Delete the SecurityCheck icon on your Desktop</ul><br><i>Delete Malware Bytes</i>:<br><ul><li> We recommend that you keep MalwareBytes (MBAM) and run it every week. There is no charge to keep the program however the real time protection will stop after the trial period. Be sure to update the definitions before each use. If you decide not to keep MBAM, use Add/Remove Programs to uninstall it.</ul><br><i>Delete Sophos AntiRootkit</i><br><ul><li>If we asked you to run Sophos AntiRootkit program, uninstall it thru Add/Remove Programs.</ul><br><i>Other Programs</i>:<br><ul><li> If we asked you to install any other programs that are not removed by the OTL cleanup procedure, we will provide separate removal instructions.</ul><br><small>--<br>When angry count four; when very angry, swear.<br>Microsoft MVP/Consumer Security 2005-2011<br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27315907</guid>
<pubDate>Tue, 10 Jul 2012 16:50:10 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] Trojan detected, may be clean now, just making sure</title>
<link>http://www.dslreports.com/forum/Re-Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27315417</link>
<description><![CDATA[anon posted : Thanks so much! Here are the two logs. Since the Sophos scan didn't come up with any removable files, I only ran it once.<br><br>All processes killed<br>========== OTL ==========<br>========== SERVICES/DRIVERS ==========<br>========== REGISTRY ==========<br>========== FILES ==========<br>C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\U folder moved successfully.<br>C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\L folder moved successfully.<br>C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff} folder moved successfully.<br>========== COMMANDS ==========<br><br>[EMPTYTEMP]<br><br>User: Administrator<br>->Temp folder emptied: 4420 bytes<br>->Temporary Internet Files folder emptied: 33170 bytes<br>->Java cache emptied: 0 bytes<br>->FireFox cache emptied: 50469013 bytes<br>->Flash cache emptied: 492 bytes<br><br>User: All Users<br><br>User: Default User<br>->Temp folder emptied: 0 bytes<br>->Temporary Internet Files folder emptied: 0 bytes<br><br>User: LocalService<br>->Temp folder emptied: 0 bytes<br>->Temporary Internet Files folder emptied: 0 bytes<br><br>User: NetworkService<br>->Temp folder emptied: 0 bytes<br>->Temporary Internet Files folder emptied: 33170 bytes<br><br>%systemdrive% .tmp files removed: 0 bytes<br>%systemroot% .tmp files removed: 0 bytes<br>%systemroot%\System32 .tmp files removed: 0 bytes<br>%systemroot%\System32\dllcache .tmp files removed: 0 bytes<br>%systemroot%\System32\drivers .tmp files removed: 0 bytes<br>Windows Temp folder emptied: 0 bytes<br>%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes<br>%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes<br>RecycleBin emptied: 0 bytes<br><br>Total Files Cleaned = 48.00 mb<br><br>[EMPTYFLASH]<br><br>User: Administrator<br>->Flash cache emptied: 0 bytes<br><br>User: All Users<br><br>User: Default User<br><br>User: LocalService<br><br>User: NetworkService<br><br>Total Flash Files Cleaned = 0.00 mb<br><br>OTL by OldTimer - Version 3.2.53.1 log created on 07102012_125720<br><br>Files\Folders moved on Reboot...<br><br>PendingFileRenameOperations files...<br><br>Registry entries deleted on Reboot...<br>_________________<br><br>Sophos Anti-Rootkit Version 1.5.20  (c) 2009 Sophos Plc<br>Started logging on 7/10/2012 at 13:04:01 PM<br>User "Administrator" on computer "LIFEBOOK"<br>Windows version 5.1 SP 3.0 Service Pack 3 build 2600 SM=0x100 PT=0x1 Win32<br>Info:&#9;Starting process scan.<br>Info:&#9;Starting registry scan.<br>Info:&#9;Starting disk scan of C: (NTFS).<br>Hidden:&#9;file C:\WINDOWS\I386\REGEDIT.EXE<br>Hidden:&#9;file C:\Documents and Settings\Administrator\My Documents\Downloads\Firefox Setup 7.0.1.exe<br>Hidden:&#9;file C:\Documents and Settings\Administrator\My Documents\Downloads\Firefox Setup 9.0.1.exe<br>Stopped logging on 7/10/2012 at 13:25:36 PM]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27315417</guid>
<pubDate>Tue, 10 Jul 2012 16:29:06 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] Trojan detected, may be clean now, just making sure</title>
<link>http://www.dslreports.com/forum/Re-Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27314594</link>
<description><![CDATA[LoPhatPhuud posted : It appears that MBAM has fremoved the trojan. It's a zero access trojan attempting to make your computer part of a botnet.<br><br>There is some cleanup to do, and I want to check for other rootkits.<br><br><b>First:</b><br>Run OTL<br><UL TYPE=SQUARE><br>[*]Under the <b>Custom Scans/Fixes</b> box at the bottom, copy and paste the contents of the following box:<br><br><div class="code"><span class="codetext"><br>:OTL<br><br>:Services<br><br>:Reg<br><br>:Files<br>C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\<br><br>:Commands<br>[purity]<br>[emptytemp]<br>[EMPTYFLASH]<br>[Reboot]<br></span></div><br><br>[*]Then click the <b>Run Fix</b> button at the top<br>[*]Let the program run unhindered, reboot the PC when it is done<br>[*]Once you see a message box "Fix complete! Click OK to open the fix log."<br>[*]Click the OK button<br>[*]The log will open in Notepad (your default text editor).<br>{*]Save the log. Post a copy of that log in your next reply.<br></UL><br><br>Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.<br><br>If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start-All Programs-Accessories-Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.<br><br><b>Second</b>:<br>Download and run Sophos AntiRootkit. Post the log in this thread, even if nothing is found.<br><br>You find link(s) and instructions here:<br>&raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/16564">Rootkit Detection Applications</A><br><small>--<br>When angry count four; when very angry, swear.<br>Microsoft MVP/Consumer Security 2005-2011<br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27314594</guid>
<pubDate>Tue, 10 Jul 2012 10:57:41 EDT</pubDate>
</item>

<item>
<title>[Trojan] Trojan detected, may be clean now, just making sure</title>
<link>http://www.dslreports.com/forum/Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27313719</link>
<description><![CDATA[anon posted : Here are the contents of the logs in the order requested. Please note there are two Malwarebytes logs as I started and stopped Malwarebytes before finishing the first run. This was before I decided to visit this forum, so the second log is the requested full run.<br><br>The pre-cleaning steps may have fixed the issue but I haven't restarted Avira yet to see...<br><br>By the way, thank you guys so much for what you do!<br><br>--------------<br><br>Malwarebytes Anti-Malware 1.61.0.1400<br>www.malwarebytes.org<br><br>Database version: v2012.07.10.01<br><br>Windows XP Service Pack 3 x86 NTFS<br>Internet Explorer 8.0.6001.18702<br>Administrator :: LIFEBOOK [administrator]<br><br>7/9/2012 9:16:03 PM<br>mbam-log-2012-07-09 (21-16-03).txt<br><br>Scan type: Full scan<br>Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br>Scan options disabled: P2P<br>Objects scanned: 44793<br>Time elapsed: 6 minute(s), 32 second(s) [aborted]<br><br>Memory Processes Detected: 0<br>(No malicious items detected)<br><br>Memory Modules Detected: 0<br>(No malicious items detected)<br><br>Registry Keys Detected: 0<br>(No malicious items detected)<br><br>Registry Values Detected: 0<br>(No malicious items detected)<br><br>Registry Data Items Detected: 0<br>(No malicious items detected)<br><br>Folders Detected: 0<br>(No malicious items detected)<br><br>Files Detected: 1<br>C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\19\785d84d3-537bcfab (Trojan.Phex.THAGen2) -> Quarantined and deleted successfully.<br><br>(end)<br><br>Malwarebytes Anti-Malware 1.61.0.1400<br>www.malwarebytes.org<br><br>Database version: v2012.07.10.01<br><br>Windows XP Service Pack 3 x86 NTFS<br>Internet Explorer 8.0.6001.18702<br>Administrator :: LIFEBOOK [administrator]<br><br>7/9/2012 9:52:42 PM<br>mbam-log-2012-07-09 (21-52-42).txt<br><br>Scan type: Full scan<br>Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br>Scan options disabled: P2P<br>Objects scanned: 243823<br>Time elapsed: 31 minute(s), 11 second(s)<br><br>Memory Processes Detected: 0<br>(No malicious items detected)<br><br>Memory Modules Detected: 0<br>(No malicious items detected)<br><br>Registry Keys Detected: 1<br>HKCU\SOFTWARE\CLASSES\CLSID\{42AEDC87-2188-41FD-B9A3-0C966FEABEC1}\INPROCSERVER32 (Trojan.Zaccess) -> Quarantined and deleted successfully.<br><br>Registry Values Detected: 1<br>HKCU\SOFTWARE\CLASSES\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32| (Trojan.Zaccess) -> Data: C:\Documents and Settings\Administrator\Local Settings\Application Data\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\n. -> Quarantined and deleted successfully.<br><br>Registry Data Items Detected: 1<br>HKCR\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32| (Trojan.Zaccess) -> Bad: (\\.\globalroot\systemroot\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\n.) Good: (wbemess.dll) -> Quarantined and repaired successfully.<br><br>Folders Detected: 0<br>(No malicious items detected)<br><br>Files Detected: 3<br>C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.<br>C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\U\80000000.@ (Trojan.Sirefef) -> Quarantined and deleted successfully.<br>C:\WINDOWS\assembly\GAC\Desktop.ini (Trojan.0access) -> Quarantined and deleted successfully.<br><br>(end)<br><br>OTL logfile created on: 7/9/2012 10:35:26 PM - Run 1<br>OTL by OldTimer - Version 3.2.53.1     Folder = C:\Documents and Settings\Administrator\Desktop<br>Windows XP Tablet PC Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br>Internet Explorer (Version = 8.0.6001.18702)<br>Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br><br>2.99 Gb Total Physical Memory | 2.43 Gb Available Physical Memory | 81.18% Memory free<br>4.32 Gb Paging File | 3.87 Gb Available in Paging File | 89.47% Paging File free<br>Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]<br><br>%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files<br>Drive C: | 55.88 Gb Total Space | 36.83 Gb Free Space | 65.90% Space Free | Partition Type: NTFS<br><br>Computer Name: LIFEBOOK | User Name: Administrator | Logged in as Administrator.<br>Boot Mode: Normal | Scan Mode: Current user<br>Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days<br><br>[color=#E56717]========== Processes (SafeList) ==========[/color]<br><br>PRC - [2012/07/09 22:34:16 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe<br>PRC - [2011/08/20 12:21:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe<br>PRC - [2011/08/20 12:21:03 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe<br>PRC - [2010/11/04 15:51:01 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe<br>PRC - [2010/01/14 23:11:00 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe<br>PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe<br>PRC - [2008/04/03 08:00:30 | 000,136,488 | ---- | M] (Wacom Technology, Corp.) -- C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe<br>PRC - [2008/04/03 07:59:48 | 003,024,168 | ---- | M] (Wacom Technology, Corp.) -- C:\WINDOWS\system32\Pen_Tablet.exe<br>PRC - [2006/04/16 01:57:28 | 000,020,480 | ---- | M] (Fujitsu Computer Systems Corporation) -- C:\Program Files\Fujitsu\Utils\FjDspMon.exe<br>PRC - [2006/04/12 00:52:30 | 000,020,480 | ---- | M] (Fujitsu Computer Systems Corporation) -- C:\Program Files\Fujitsu\Utils\FjEvents.exe<br>PRC - [2006/04/05 18:28:40 | 000,270,336 | ---- | M] (Knowles Acoustics) -- C:\WINDOWS\system32\KADxMain.exe<br>PRC - [2006/03/30 23:41:22 | 000,032,768 | ---- | M] (Fujitsu Computer Systems Corporation) -- C:\Program Files\Fujitsu\Utils\FjMnuIco.exe<br>PRC - [2006/03/27 15:59:02 | 000,061,440 | ---- | M] (WACOM) -- C:\WINDOWS\system32\digtizer.exe<br>PRC - [2006/01/27 23:17:44 | 000,073,728 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe<br>PRC - [2005/11/04 03:35:18 | 001,052,672 | ---- | M] (AuthenTec, Inc.) -- C:\Program Files\Fingerprint Sensor\ATSwpNav.exe<br>PRC - [2005/09/13 16:30:14 | 000,057,344 | ---- | M] (O2Micro International) -- C:\WINDOWS\system32\o2flash.exe<br>PRC - [2005/09/10 02:12:40 | 000,081,920 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe<br>PRC - [2003/08/20 20:24:08 | 000,061,440 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe<br><br>[color=#E56717]========== Modules (No Company Name) ==========[/color]<br><br>MOD - [2012/06/20 08:54:32 | 012,433,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll<br>MOD - [2012/06/20 08:54:19 | 001,592,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll<br>MOD - [2012/05/15 10:06:36 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll<br>MOD - [2012/05/15 10:06:33 | 000,025,600 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\016444dfc5f7e3d11c776f2fbc7a4594\Accessibility.ni.dll<br>MOD - [2012/05/15 10:01:28 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll<br>MOD - [2012/05/14 22:41:35 | 001,855,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.0.3705\system\1.0.3300.0__b77a5c561934e089_12d98dc0\system.dll<br>MOD - [2012/05/14 22:41:32 | 003,301,376 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.0.3705\mscorlib\1.0.3300.0__b77a5c561934e089_a657a97d\mscorlib.dll<br>MOD - [2012/05/14 22:41:26 | 001,179,648 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.3300.0__b77a5c561934e089\system.dll<br>MOD - [2012/05/14 22:40:50 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll<br>MOD - [2012/05/14 22:40:23 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll<br>MOD - [2011/11/02 00:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll<br>MOD - [2011/11/02 00:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll<br>MOD - [2010/04/10 01:38:53 | 000,110,592 | ---- | M] () -- C:\WINDOWS\assembly\GAC\SKLibrary\1.7.2600.5512__31bf3856ad364e35\SKLibrary.dll<br>MOD - [2010/04/10 01:38:53 | 000,012,800 | ---- | M] () -- C:\WINDOWS\assembly\GAC\SoftKeyboardLogic\1.7.2600.5512__31bf3856ad364e35\SoftKeyboardLogic.dll<br>MOD - [2010/04/10 01:38:53 | 000,009,216 | ---- | M] () -- C:\WINDOWS\assembly\GAC\Interop.SoftKeyboardInterface\1.7.2600.5512__31bf3856ad364e35\Interop.SoftKeyboardInterface.dll<br>MOD - [2010/03/15 12:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll<br>MOD - [2010/01/28 14:57:58 | 000,355,688 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll<br>MOD - [2006/05/17 14:33:54 | 000,045,056 | ---- | M] () -- c:\windows\assembly\gac\interop.tipcomponents\1.7.2600.2180__31bf3856ad364e35\interop.tipcomponents.dll<br>MOD - [2006/04/16 02:40:20 | 000,020,480 | ---- | M] () -- c:\Program Files\Fujitsu\Utils\Lib\FjFBUCmn.dll<br><br>[color=#E56717]========== Win32 Services (SafeList) ==========[/color]<br><br>SRV - [2012/06/25 19:53:43 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)<br>SRV - [2011/08/20 12:21:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)<br>SRV - [2011/08/20 12:21:03 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)<br>SRV - [2008/04/03 07:59:48 | 003,024,168 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\WINDOWS\system32\Pen_Tablet.exe -- (TabletServicePen)<br>SRV - [2006/03/27 15:59:02 | 000,061,440 | ---- | M] (WACOM) [Auto | Running] -- C:\WINDOWS\system32\digtizer.exe -- (Digitizer)<br>SRV - [2005/09/13 16:30:14 | 000,057,344 | ---- | M] (O2Micro International) [Auto | Running] -- C:\WINDOWS\system32\o2flash.exe -- (O2Flash)<br><br>[color=#E56717]========== Driver Services (SafeList) ==========[/color]<br><br>DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)<br>DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)<br>DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)<br>DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)<br>DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)<br>DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)<br>DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)<br>DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)<br>DRV - File not found [Kernel | System | Stopped] --  -- (Changer)<br>DRV - [2011/08/20 12:21:05 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)<br>DRV - [2011/08/20 12:21:05 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)<br>DRV - [2009/05/11 13:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)<br>DRV - [2009/05/11 11:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)<br>DRV - [2008/02/06 12:27:14 | 000,030,888 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wisdpen.sys -- (WISDPen)<br>DRV - [2007/02/16 11:12:36 | 000,011,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacommousefilter.sys -- (wacommousefilter)<br>DRV - [2007/02/16 10:30:12 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacomvhid.sys -- (wacomvhid)<br>DRV - [2007/02/15 16:11:28 | 000,011,440 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WacomVKHid.sys -- (WacomVKHid)<br>DRV - [2006/04/26 17:13:04 | 001,429,632 | ---- | M] (Intel&reg; Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel(R)<br>DRV - [2006/03/30 17:54:48 | 000,106,496 | ---- | M] (Knowles Acoustics) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dxec02.sys -- (DXEC02)<br>DRV - [2006/03/29 23:43:18 | 000,017,920 | R--- | M] (Fujitsu Computer Systems Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\FjBtnDrv.sys -- (Fjbtndrv)<br>DRV - [2006/02/21 17:05:40 | 000,036,352 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\o2media.sys -- (O2MDRDR)<br>DRV - [2006/02/21 14:07:14 | 001,106,952 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)<br>DRV - [2006/01/20 19:08:00 | 000,108,928 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (Tosrfbd)<br>DRV - [2006/01/20 18:56:40 | 001,158,816 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)<br>DRV - [2006/01/18 22:19:00 | 000,039,808 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)<br>DRV - [2006/01/11 20:21:54 | 000,010,496 | ---- | M] (FUJITSU LIMITED) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\FJGPNV.SYS -- (FJGPNV)<br>DRV - [2006/01/11 19:29:42 | 000,062,848 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfhid.sys -- (Tosrfhid)<br>DRV - [2005/12/09 10:48:00 | 000,243,712 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)<br>DRV - [2005/11/24 15:37:36 | 000,047,104 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte)<br>DRV - [2005/11/19 15:18:10 | 000,117,874 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATSwpDrv.sys -- (ATSWPDRV) AuthenTec TruePrint USB Driver (AES2500)<br>DRV - [2005/09/23 09:48:44 | 000,028,544 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\o2sd.sys -- (O2SDRDR)<br>DRV - [2005/08/01 18:45:08 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)<br>DRV - [2005/07/21 16:56:22 | 000,007,196 | ---- | M] (FUJITSU LIMITED) [Kernel | Auto | Running] -- C:\Program Files\Fujitsu\FlashAid\FlashDrv.sys -- (FlashDrv)<br>DRV - [2005/06/10 15:26:00 | 000,035,968 | ---- | M] (Infineon Technologies AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ifxtpm.sys -- (IFXTPM)<br>DRV - [2004/10/25 00:19:18 | 000,092,561 | ---- | M] (O2Micro) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ozscr.sys -- (O2SCBUS)<br>DRV - [2004/10/18 17:08:00 | 000,005,632 | ---- | M] (Fujitsu Limited) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FUJ02E1.sys -- (FUJ02E1)<br>DRV - [2004/08/02 19:35:48 | 000,031,104 | ---- | M] (Wacom Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hidpen.sys -- (hidpen)<br>DRV - [2004/01/17 22:15:20 | 000,004,864 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fuj02e3.sys -- (FUJ02E3)<br>DRV - [2003/08/20 20:24:08 | 000,019,712 | ---- | M] (FUJITSU LIMITED) [Kernel | Auto | Running] -- C:\Program Files\Fujitsu\BtnHnd\BtnHnd.sys -- (BtnHnd)<br>DRV - [2001/08/17 07:10:28 | 000,035,913 | ---- | M] (SMC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)<br>DRV - [2001/08/01 23:00:22 | 000,005,248 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fuj02b1.sys -- (FUJ02B1)<br><br>[color=#E56717]========== Standard Registry (SafeList) ==========[/color]<br><br>[color=#E56717]========== Internet Explorer ==========[/color]<br><br>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://www.google.com/ie" >www.google.com/ie</A><br>IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}<br>IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = &raquo;<A HREF="http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}" >search.live.com/results.aspx?q={&middot;&middot;&middot;source?}</A><br><br>IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://www.google.com/ie" >www.google.com/ie</A><br>IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://www.google.com" >www.google.com</A><br>IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://us.fujitsu.com/computers" >us.fujitsu.com/computers</A><br>IE - HKCU\..\SearchScopes,DefaultScope = {0DF6852F-7D6F-44AB-81B3-9A5009A279F8}<br>IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = &raquo;<A HREF="http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC" >search.live.com/results.aspx?q={&middot;&middot;&middot;m=IE8SRC</A><br>IE - HKCU\..\SearchScopes\{0DF6852F-7D6F-44AB-81B3-9A5009A279F8}: "URL" = &raquo;<A HREF="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" >www.google.com/search?q={searchT&middot;&middot;&middot;&oe=utf8</A><br>IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0<br>IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local<br><br>[color=#E56717]========== FireFox ==========[/color]<br><br>FF - prefs.js..browser.startup.homepage: "http://www.google.com"<br>FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26<br><br>FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()<br>FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found<br>FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()<br>FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)<br>FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)<br>FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)<br>FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)<br>FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)<br><br>FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/28 11:00:04 | 000,000,000 | ---D | M]<br>FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/14 00:12:53 | 000,000,000 | ---D | M]<br><br>[2010/04/07 12:42:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions<br>[2011/08/20 12:28:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gwu5o669.default\extensions<br>[2012/07/28 11:00:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions<br>[2010/09/19 10:39:39 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}<br>[2011/12/21 02:24:52 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll<br>[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll<br>[2011/12/20 23:30:41 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml<br>[2011/12/20 23:30:41 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml<br><br>O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts<br>O1 - Hosts: 127.0.0.1       localhost<br>O2 - BHO: (CNisExtBho Class) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll File not found<br>O2 - BHO: (CNavExtBho Class) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll File not found<br>O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)<br>O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)<br>O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)<br>O3 - HKCU\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll File not found<br>O3 - HKCU\..\Toolbar\WebBrowser: (Norton Internet Security 2006) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll File not found<br>O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)<br>O4 - HKLM..\Run: []  File not found<br>O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)<br>O4 - HKLM..\Run: [ATSwpNav] C:\Program Files\Fingerprint Sensor\ATSwpNav.exe (AuthenTec, Inc.)<br>O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)<br>O4 - HKLM..\Run: [FjStrtAp] c:\Program Files\Fujitsu\Utils\FjStrtAp.exe (Fujitsu Computer Systems)<br>O4 - HKLM..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (FUJITSU LIMITED)<br>O4 - HKLM..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe (Knowles Acoustics)<br>O4 - HKLM..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe (FUJITSU LIMITED)<br>O4 - HKLM..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED)<br>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1<br>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0<br>O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145<br>O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)<br>O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)<br>O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)<br>O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)<br>O8 - Extra context menu item: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)<br>O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)<br>O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)<br>O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found<br>O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} &raquo;<A HREF="http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab" >java.sun.com/update/1.6.0/jinsta&middot;&middot;&middot;i586.cab</A> (Java Plug-in 1.6.0_29)<br>O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} &raquo;<A HREF="http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab" >java.sun.com/update/1.6.0/jinsta&middot;&middot;&middot;i586.cab</A> (Java Plug-in 1.6.0_29)<br>O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} &raquo;<A HREF="http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab" >java.sun.com/update/1.6.0/jinsta&middot;&middot;&middot;i586.cab</A> (Java Plug-in 1.6.0_29)<br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.177.176.38 71.92.29.130 24.217.201.67<br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF719237-50ED-4298-AE3F-393BFEC87F4E}: DhcpNameServer = 24.177.176.38 71.92.29.130 24.217.201.67<br>O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)<br>O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)<br>O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)<br>O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)<br>O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp<br>O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp<br>O32 - HKLM CDRom: AutoRun - 1<br>O32 - AutoRun File - [2006/05/17 14:35:58 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]<br>O34 - HKLM BootExecute: (autocheck autochk *)<br>O35 - HKLM\..comfile [open] -- "%1" %*<br>O35 - HKLM\..exefile [open] -- "%1" %*<br>O37 - HKLM\...com [@ = comfile] -- "%1" %*<br>O37 - HKLM\...exe [@ = exefile] -- "%1" %*<br>O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)<br>O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)<br><br>[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]<br><br>[2012/07/09 22:34:14 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe<br>[2012/07/09 21:12:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes<br>[2012/07/09 21:11:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware<br>[2012/07/09 21:11:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>[2012/07/09 21:11:54 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys<br>[2012/07/09 21:11:54 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware<br>[2012/07/09 10:12:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles<br>[2012/06/17 10:21:01 | 000,521,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsdbgui.dll<br><br>[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]<br><br>[2012/07/28 11:00:07 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk<br>[2012/07/28 11:00:07 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk<br>[2012/07/26 00:32:42 | 002,003,259 | ---- | M] () -- C:\WINDOWS\iis6.BAK<br>[2012/07/09 22:34:16 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe<br>[2012/07/09 22:31:43 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat<br>[2012/07/09 21:53:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job<br>[2012/07/09 21:28:39 | 000,000,277 | ---- | M] () -- C:\fix.bat<br>[2012/07/09 21:11:57 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk<br>[2012/07/06 14:00:52 | 000,660,776 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Leave Rx.pdf<br>[2012/07/02 22:16:31 | 000,021,210 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Bertagnolli Birth Plan.odt<br>[2012/06/29 14:38:23 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl<br>[2012/06/25 20:16:49 | 000,013,040 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\baby names.odt<br>[2012/06/25 19:53:43 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe<br>[2012/06/25 19:53:42 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl<br>[2012/06/20 08:51:07 | 000,119,744 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT<br>[2012/06/19 15:04:01 | 000,443,482 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat<br>[2012/06/19 15:04:01 | 000,072,582 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat<br>[2012/06/19 14:58:33 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK<br>[2012/06/17 13:28:53 | 000,014,336 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br><br>[color=#E56717]========== Files Created - No Company Name ==========[/color]<br><br>[2012/07/09 21:28:39 | 000,000,277 | ---- | C] () -- C:\fix.bat<br>[2012/07/09 21:11:57 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk<br>[2012/07/09 21:11:13 | 000,095,744 | ---- | C] () -- C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\U\80000032.@<br>[2012/07/09 10:12:09 | 000,002,048 | ---- | C] () -- C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\U\00000004.@<br>[2012/07/09 10:12:09 | 000,001,632 | ---- | C] () -- C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\U\000000cb.@<br>[2012/07/06 14:00:51 | 000,660,776 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Leave Rx.pdf<br>[2012/07/02 21:44:47 | 000,021,210 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Bertagnolli Birth Plan.odt<br>[2012/06/09 21:13:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\autorun.INI<br>[2012/02/19 22:12:03 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll<br>[2012/02/19 21:32:31 | 000,393,256 | ---- | C] () -- C:\WINDOWS\System32\CNQ4809N.DAT<br>[2010/09/19 10:40:33 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat<br>[2010/05/07 18:42:03 | 000,014,336 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br>[2010/04/28 00:17:25 | 000,000,138 | ---- | C] () -- C:\Documents and Settings\Administrator\webct_upload_applet.properties<br>[2006/05/17 14:40:19 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat<br>[2006/05/17 06:54:58 | 000,002,048 | -HS- | C] () -- C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\@<br>[2006/05/17 06:54:58 | 000,002,048 | -HS- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\@<br><br>[color=#E56717]========== LOP Check ==========[/color]<br><br>[2012/01/19 14:30:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Amazon<br>[2010/04/07 15:57:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Ambient Design<br>[2012/02/19 21:45:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Canon<br>[2012/03/31 23:49:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\FileZilla<br>[2011/08/26 15:57:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Leadertech<br>[2010/04/07 15:35:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\OpenOffice.org<br>[2012/02/19 21:45:57 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJScan<br>[2012/02/13 17:50:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}<br><br>[color=#E56717]========== Purity Check ==========[/color]<br><br>OTL Extras logfile created on: 7/9/2012 10:35:26 PM - Run 1<br>OTL by OldTimer - Version 3.2.53.1     Folder = C:\Documents and Settings\Administrator\Desktop<br>Windows XP Tablet PC Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br>Internet Explorer (Version = 8.0.6001.18702)<br>Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br><br>2.99 Gb Total Physical Memory | 2.43 Gb Available Physical Memory | 81.18% Memory free<br>4.32 Gb Paging File | 3.87 Gb Available in Paging File | 89.47% Paging File free<br>Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]<br><br>%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files<br>Drive C: | 55.88 Gb Total Space | 36.83 Gb Free Space | 65.90% Space Free | Partition Type: NTFS<br><br>Computer Name: LIFEBOOK | User Name: Administrator | Logged in as Administrator.<br>Boot Mode: Normal | Scan Mode: Current user<br>Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days<br><br>[color=#E56717]========== Extra Registry (SafeList) ==========[/color]<br><br>[color=#E56717]========== File Associations ==========[/color]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]<br>.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*<br><br>[HKEY_CURRENT_USER\SOFTWARE\Classes\]<br>.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br><br>[color=#E56717]========== Shell Spawning ==========[/color]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]<br>batfile [open] -- "%1" %*<br>cmdfile [open] -- "%1" %*<br>comfile [open] -- "%1" %*<br>cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*<br>exefile [open] -- "%1" %*<br>htmlfile [edit] -- Reg Error: Key error.<br>piffile [open] -- "%1" %*<br>regfile [merge] -- Reg Error: Key error.<br>scrfile [config] -- "%1"<br>scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l<br>scrfile [open] -- "%1" /S<br>txtfile [edit] -- Reg Error: Key error.<br>Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1<br>Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()<br>Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br>Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()<br>Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)<br>Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)<br>Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br><br>[color=#E56717]========== Security Center Settings ==========[/color]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]<br>"FirstRunDisabled" = 1<br>"AntiVirusDisableNotify" = 0<br>"FirewallDisableNotify" = 0<br>"UpdatesDisableNotify" = 0<br>"AntiVirusOverride" = 1<br>"FirewallOverride" = 0<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring" = 1<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]<br>"DisableMonitoring" = 1<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]<br><br>[color=#E56717]========== System Restore Settings ==========[/color]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]<br>"DisableSR" = 0<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]<br>"Start" = 0<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]<br>"Start" = 2<br><br>[color=#E56717]========== Firewall Settings ==========[/color]<br><br>[color=#E56717]========== Authorized Applications List ==========[/color]<br><br>[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]<br>"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data<br>"{0CAD092C-5D1E-48AD-A845-E1EBA9AF1AF8}" = Tablet PC Tutorials for Microsoft Windows XP SP2<br>"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4809" = CanoScan LiDE 210 Scanner Driver<br>"{1E262F09-4E48-4911-9024-ACCEFE945900}" = Fujitsu System Extension Utility<br>"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br>"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer<br>"{24CF0DBF-FF47-42E5-A13F-1D4D773E8AC7}" = Security Panel Application<br>"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 29<br>"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com<br>"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support<br>"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP<br>"{3C3758FA-C2DF-4E10-9D29-0CC28DA9214A}" = FlashAid<br>"{479F7641-532C-4448-BEEB-74F92569AACA}" = IntelliSonic Speech Enhancement<br>"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater<br>"{5337BED2-73A0-4EB8-A33C-91DFD4C2F82D}" = Fujitsu Pen Service<br>"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD<br>"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2<br>"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update<br>"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour<br>"{792FBB04-5C13-47A1-9CD5-369A52BD47AA}" = Fujitsu Hotkey Utility<br>"{7A61142C-CA19-4F3C-BA66-FF8F131501F9}" = Paint.NET v3.5.9<br>"{7A85D628-B8BE-4BC5-BC5C-E4FD91D90502}" = Fujitsu Button Driver Component<br>"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support<br>"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight<br>"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver<br>"{8C26E186-E649-4A01-B8EC-DDEF5E454389}" = Fingerprint Sensor Minimum Install<br>"{93444A72-EEA4-43E9-A12C-372DCC126A9B}" = Security Panel Application for Supervisor<br>"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars<br>"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR<br>"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2<br>"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio<br>"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio<br>"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0<br>"{ADBACDF0-9D21-445A-92AF-78019EB1B7C3}" = ArtRage Studio Pro<br>"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy<br>"{B223DB66-E5EC-4F19-B8C8-274EB876094C}" = O2Micro Flash Memory Card Windows Driver<br>"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2<br>"{C5BED10B-42A9-4142-B4C2-008C0FDE27D5}" = O2Micro Smartcard Driver<br>"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver<br>"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1<br>"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1<br>"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype&#153; 4.2<br>"{E0FAA0BA-874E-47C8-9ECA-BB333006CF16}" = Fujitsu Driver Update<br>"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes<br>"{F94FD9EE-B0A7-47BE-8C96-72F693BE4299}" = Fujitsu Button Utilities<br>"Adobe AIR" = Adobe AIR<br>"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin<br>"Agere Systems Soft Modem" = Agere Systems HDA Modem<br>"Amazon Kindle" = Amazon Kindle<br>"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15<br>"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus<br>"CamStudio" = CamStudio<br>"FileZilla Client" = FileZilla Client 3.3.5.1<br>"fjbtndrv_2ba5b847cf34ba3d71166b42646303073a71e6b2" = Windows Driver Package - Fujitsu Computer Systems Corporation (FjBtnDrv) HIDClass 03/29/2006 2.0.0329.2006<br>"ie8" = Windows Internet Explorer 8<br>"InstallShield_{B223DB66-E5EC-4F19-B8C8-274EB876094C}" = O2Micro Flash Memory Card Windows Driver<br>"InstallShield_{C5BED10B-42A9-4142-B4C2-008C0FDE27D5}" = O2Micro Smartcard Driver<br>"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400<br>"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1<br>"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1<br>"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)<br>"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0<br>"Pen Tablet Driver" = Pen Tablet<br>"SynTPDeinstKey" = Synaptics Pointing Device Driver<br>"VLC media player" = VLC media player 1.0.0<br>"Windows Media Format Runtime" = Windows Media Format Runtime<br>"Windows Media Player" = Windows Media Player 10<br>"Windows XP Service Pack" = Windows XP Service Pack 3<br>"WinRAR archiver" = WinRAR archiver<br>"YTdetect" = Yahoo! Detect<br><br>[color=#E56717]========== Last 20 Event Log Errors ==========[/color]<br><br>[ Application Events ]<br>Error - 6/21/2012 1:48:09 PM | Computer Name = LIFEBOOK | Source = TabletServicePen | ID = 0<br>Description =<br><br>Error - 6/21/2012 1:48:09 PM | Computer Name = LIFEBOOK | Source = TabletServicePen | ID = 0<br>Description =<br><br>Error - 6/21/2012 1:48:10 PM | Computer Name = LIFEBOOK | Source = TabletServicePen | ID = 0<br>Description =<br><br>Error - 6/21/2012 1:48:10 PM | Computer Name = LIFEBOOK | Source = TabletServicePen | ID = 0<br>Description =<br><br>Error - 6/22/2012 1:29:24 PM | Computer Name = LIFEBOOK | Source = TabletServicePen | ID = 0<br>Description =<br><br>Error - 6/22/2012 1:29:25 PM | Computer Name = LIFEBOOK | Source = TabletServicePen | ID = 0<br>Description =<br><br>Error - 6/22/2012 1:29:25 PM | Computer Name = LIFEBOOK | Source = TabletServicePen | ID = 0<br>Description =<br><br>Error - 6/22/2012 1:29:25 PM | Computer Name = LIFEBOOK | Source = TabletServicePen | ID = 0<br>Description =<br><br>Error - 6/22/2012 1:29:25 PM | Computer Name = LIFEBOOK | Source = TabletServicePen | ID = 0<br>Description =<br><br>Error - 6/22/2012 1:29:25 PM | Computer Name = LIFEBOOK | Source = TabletServicePen | ID = 0<br>Description =<br><br>[ System Events ]<br>Error - 4/7/2012 11:16:37 PM | Computer Name = LIFEBOOK | Source = DCOM | ID = 10010<br>Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register<br> with DCOM within the required timeout.<br><br>Error - 4/8/2012 11:56:51 PM | Computer Name = LIFEBOOK | Source = DCOM | ID = 10010<br>Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register<br> with DCOM within the required timeout.<br><br>Error - 4/13/2012 11:14:42 AM | Computer Name = LIFEBOOK | Source = DCOM | ID = 10010<br>Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register<br> with DCOM within the required timeout.<br><br>Error - 4/13/2012 7:44:16 PM | Computer Name = LIFEBOOK | Source = DCOM | ID = 10010<br>Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register<br> with DCOM within the required timeout.<br><br>Error - 4/14/2012 11:13:39 AM | Computer Name = LIFEBOOK | Source = DCOM | ID = 10010<br>Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register<br> with DCOM within the required timeout.<br><br>Error - 4/14/2012 5:44:54 PM | Computer Name = LIFEBOOK | Source = DCOM | ID = 10010<br>Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register<br> with DCOM within the required timeout.<br><br>Error - 4/14/2012 5:49:05 PM | Computer Name = LIFEBOOK | Source = DCOM | ID = 10010<br>Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register<br> with DCOM within the required timeout.<br><br>Error - 4/14/2012 6:01:35 PM | Computer Name = LIFEBOOK | Source = DCOM | ID = 10010<br>Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register<br> with DCOM within the required timeout.<br><br>Error - 4/15/2012 10:44:03 PM | Computer Name = LIFEBOOK | Source = DCOM | ID = 10010<br>Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register<br> with DCOM within the required timeout.<br><br>Error - 4/21/2012 7:04:43 PM | Computer Name = LIFEBOOK | Source = Dhcp | ID = 1000<br>Description = Your computer has lost the lease to its IP address 192.168.1.100 on<br> the  Network Card with network address 001302E14E92.<br><br> Results of screen317's Security Check version 0.99.42<br> Windows XP Service Pack 3 x86<br> Internet Explorer 8<br><b>[u]``````````````Antivirus/Firewall Check:``````````````</b>[/u]<br> [color=red]<b>Windows Security Center service is not running! This report may not be accurate!</b>[/color]<br>AntiVir Desktop<br> [color=red]<b>Antivirus out of date!</b>[/color] (On Access scanning <b>disabled</b>!)<br><b>[u]`````````Anti-malware/Other Utilities Check:`````````</b>[/u]<br> Malwarebytes Anti-Malware version 1.61.0.1400<br> Java(TM) 6 Update 29<br> [color=red]<b>Java version out of Date!</b>[/color]<br> Adobe Flash Player &#9;11.3.300.262<br> Adobe Reader 9 [color=red]<b>Adobe Reader out of Date!</b>[/color]<br> Mozilla Firefox (9.0.1)<br><b>[u]````````Process Check: objlist.exe by Laurent````````</b>[/u]<br> Avira Antivir avgnt.exe<br> Avira Antivir avguard.exe<br><b>[u]`````````````````System Health check`````````````````</b>[/u]<br> Total Fragmentation on Drive C:: 16% [color=red]<b>Defragment your hard drive soon!</b>[/color]<br><b>[u]````````````````````End of Log``````````````````````</b>[/u]<br><br>ESETSmartInstaller@High as downloader log:<br>all ok<br># version=7<br># OnlineScannerApp.exe=1.0.0.1<br># OnlineScanner.ocx=1.0.0.6583<br># api_version=3.0.2<br># EOSSerial=b0d50a1ffc6bc94085497cb6fec1e67c<br># end=finished<br># remove_checked=true<br># archives_checked=false<br># unwanted_checked=true<br># unsafe_checked=false<br># antistealth_checked=true<br># utc_time=2012-07-10 04:24:59<br># local_time=2012-07-09 11:24:59 (-0600, Central Daylight Time)<br># country="United States"<br># lang=1033<br># osver=5.1.2600 NT Service Pack 3<br># compatibility_mode=1797 16775145 100 93 0 78314031 737881 0<br># compatibility_mode=8192 67108863 100 0 0 0 0 0<br># scanned=51379<br># found=1<br># cleaned=1<br># scan_time=1656<br>C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\U\80000032.@&#9;a variant of Win32/Sirefef.FD trojan (cleaned by deleting - quarantined)&#9;00000000000000000000000000000000&#9;C]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Trojan-Trojan-detected-may-be-clean-now-just-making-sure-27313719</guid>
<pubDate>Tue, 10 Jul 2012 00:43:06 EDT</pubDate>
</item>

</channel>
</rss>
