Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: "Application has been executed" problem.  (Read 26647 times)

0 Members and 1 Guest are viewing this topic.

csturgill

    Topic Starter


    Rookie

    "Application has been executed" problem.
    « on: February 08, 2010, 06:58:05 PM »
    My computer is giving me serious problems.  There are multiple threads with others having the same issue, but I continue to see that I should post my own thread.  Can someone please direct me in rectifying this virus.

    Thank you!!

    Dr Jay

    • Malware Removal Specialist


    • Specialist
    • Moderator emeritus
    • Thanked: 119
    • Experience: Guru
    • OS: Windows 10
    Re: "Application has been executed" problem.
    « Reply #1 on: February 09, 2010, 07:41:47 AM »
    Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.
    ~Dr Jay

    csturgill

      Topic Starter


      Rookie

      Re: "Application has been executed" problem.
      « Reply #2 on: February 10, 2010, 07:28:36 AM »
      My computer is not letting me download the CombiFix program.  I did run the Cheetah program and it came up with this.

      Cheetah-Anti-Rogue v1.2.17
      by DragonMaster Jay

      Microsoft Windows XP [Version 5.1.2600]
      Date: 02/08/2010 - Time: 21:58:48 - Arch.: x86

      Also I ran CCLEANER, it performed an analysis should I now let it "clean" my computer???

      I'm a little confused with all this.  I'm not too computer savvy.

      Dr Jay

      • Malware Removal Specialist


      • Specialist
      • Moderator emeritus
      • Thanked: 119
      • Experience: Guru
      • OS: Windows 10
      Re: "Application has been executed" problem.
      « Reply #3 on: February 10, 2010, 08:08:37 AM »
      Delete your copy of ComboFix; grab a fresh copy, except before you download it, rename it to blackpudding.bat


      Navigate to Start --> Run, and enter the following command exactly as shown:

      "%userprofile%\desktop\blackpudding.bat" /killall

      See if ComboFix will run now.
      ~Dr Jay

      csturgill

        Topic Starter


        Rookie

        Re: "Application has been executed" problem.
        « Reply #4 on: February 10, 2010, 12:10:19 PM »
        Thank you so much for your help!!  I was able to get CombiFix to run.  What do I do next??  Here is the log:

        ComboFix 10-02-10.01 - Christina 02/10/2010  13:50:48.1.1 - x86
        Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.502.199 [GMT -5:00]
        Running from: c:\documents and settings\Christina\My Documents\Downloads\ComboFix.exe
        AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
        AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Outdated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
        FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
        .

        (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\documents and settings\All Users\Start Menu\Programs\Power-Antivirus-2009
        c:\documents and settings\All Users\Start Menu\Programs\Power-Antivirus-2009\Purchase License.lnk
        c:\documents and settings\All Users\Start Menu\Programs\Power-Antivirus-2009\Support Page.lnk
        c:\documents and settings\Christina\Application Data\Power-Antivirus-2009
        c:\documents and settings\Christina\Application Data\Power-Antivirus-2009\Power-Antivirus-2009.ini
        c:\documents and settings\Christina\Local Settings\Application Data\wpilyw
        c:\documents and settings\Christina\Local Settings\Application Data\wpilyw\llwxsftav.exe
        c:\program files\Power-Antivirus-2009
        c:\program files\Power-Antivirus-2009\Buy.url
        c:\program files\Power-Antivirus-2009\Help.url
        c:\program files\Power-Antivirus-2009\HowToBuy.txt
        c:\program files\Power-Antivirus-2009\ID.dat
        c:\program files\Power-Antivirus-2009\License.txt
        c:\program files\TSC

        .
        (((((((((((((((((((((((((   Files Created from 2010-01-10 to 2010-02-10  )))))))))))))))))))))))))))))))
        .

        2010-02-09 02:09 . 2010-02-09 02:09   --------   d-----w-   c:\program files\Trend Micro
        2010-01-29 15:09 . 2010-02-01 12:25   --------   d-----w-   c:\documents and settings\All Users\Application Data\NOS
        2010-01-13 06:32 . 2009-11-21 15:51   471552   -c----w-   c:\windows\system32\dllcache\aclayers.dll

        .
        ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2010-02-04 15:00 . 2008-03-15 01:43   --------   d-----w-   c:\program files\dl_Cats
        2010-01-22 23:18 . 2009-08-20 14:52   --------   d-----w-   c:\program files\Microsoft Silverlight
        2010-01-03 19:39 . 2009-02-27 21:57   --------   d-----w-   c:\documents and settings\Christina\Application Data\U3
        2009-12-31 16:50 . 2004-08-12 13:30   353792   ----a-w-   c:\windows\system32\drivers\srv.sys
        2009-12-21 19:14 . 2004-08-12 13:33   916480   ----a-w-   c:\windows\system32\wininet.dll
        2009-12-16 18:43 . 2008-03-13 00:56   343040   ----a-w-   c:\windows\system32\mspaint.exe
        2009-12-14 07:08 . 2004-08-12 13:18   33280   ----a-w-   c:\windows\system32\csrsrv.dll
        2009-12-08 19:27 . 2004-08-12 13:25   2189184   ----a-w-   c:\windows\system32\ntoskrnl.exe
        2009-12-08 18:43 . 2004-08-03 22:59   2066048   ----a-w-   c:\windows\system32\ntkrnlpa.exe
        2009-12-04 18:22 . 2004-08-12 13:22   455424   ----a-w-   c:\windows\system32\drivers\mrxsmb.sys
        2009-11-27 17:11 . 2004-08-12 13:26   1291776   ----a-w-   c:\windows\system32\quartz.dll
        2009-11-27 17:11 . 2004-08-04 00:56   17920   ----a-w-   c:\windows\system32\msyuv.dll
        2009-11-27 16:07 . 2004-08-12 13:23   28672   ----a-w-   c:\windows\system32\msvidc32.dll
        2009-11-27 16:07 . 2001-08-17 22:36   8704   ----a-w-   c:\windows\system32\tsbyuv.dll
        2009-11-27 16:07 . 2004-08-12 13:23   11264   ----a-w-   c:\windows\system32\msrle32.dll
        2009-11-27 16:07 . 2004-08-12 13:17   84992   ----a-w-   c:\windows\system32\avifil32.dll
        2009-11-27 16:07 . 2004-08-04 00:56   48128   ----a-w-   c:\windows\system32\iyuv_32.dll
        2009-11-21 15:51 . 2004-08-12 13:17   471552   ----a-w-   c:\windows\AppPatch\aclayers.dll
        .

        (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
        "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
        "Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "DLBTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2007-02-22 73728]
        "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
        "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
        "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-05-06 155648]
        "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-05-06 118784]
        "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
        "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
        "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
        "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

        c:\documents and settings\All Users\Start Menu\Programs\Startup\
        Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-2-20 282624]
        KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
        @=""

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
        @=""

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
        @=""

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
        @=""

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
        "DisableMonitoring"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "c:\\WINDOWS\\system32\\dlbtcoms.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
        "c:\\Program Files\\AIM6\\aim6.exe"=
        "c:\\Program Files\\Messenger\\msmsgs.exe"=
        "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
        "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
        "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
        "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
        "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
        "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
        "c:\\Program Files\\iTunes\\iTunes.exe"=

        R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [9/5/2009 9:36 PM 206256]
        R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [8/20/2009 9:52 AM 54752]
        R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/24/2008 5:21 PM 24652]
        S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48 PM 704864]
        .
        Contents of the 'Scheduled Tasks' folder

        2010-02-03 c:\windows\Tasks\AppleSoftwareUpdate.job
        - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

        2010-01-15 c:\windows\Tasks\McDefragTask.job
        - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-08 16:22]

        2010-02-10 c:\windows\Tasks\McQcTask.job
        - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-08 16:22]
        .
        .
        ------- Supplementary Scan -------
        .
        uInternet Connection Wizard,ShellNext = iexplore
        IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUfox000
        IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
        IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
        Trusted Zone: jhmi.edu\nightingale
        FF - ProfilePath - c:\documents and settings\Christina\Application Data\Mozilla\Firefox\Profiles\qqgpynxh.default\
        FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
        FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
        FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
        FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
        FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
        .
        - - - - ORPHANS REMOVED - - - -

        HKCU-Run-erglbxmr - c:\documents and settings\Christina\Local Settings\Application Data\wpilyw\llwxsftav.exe
        HKLM-Run-erglbxmr - c:\documents and settings\Christina\Local Settings\Application Data\wpilyw\llwxsftav.exe



        **************************************************************************

        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2010-02-10 13:56
        Windows 5.1.2600 Service Pack 3 NTFS

        scanning hidden processes ... 

        scanning hidden autostart entries ...

        HKLM\Software\Microsoft\Windows\CurrentVersion\Run
          DLBTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

        scanning hidden files ... 

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        --------------------- LOCKED REGISTRY KEYS ---------------------

        [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\561ad301-8580-f5a9-8032-b648c64ea2d]
        @Denied: (Full) (AuthenticatedUsers)
        @Denied: (Full) (Administrators)
        "1x6up7px0albw"=hex:62,37,38,36,65,33,39,63,2d,66,37,65,38,2d,34,62,63,62,2d,
           38,61,33,33,2d,32,32,37,34,38,62,62,65,30,31,65,33
        "18ji1vpdfytsl"=hex:65,00,00,00,f8,00,00,00,cc,f7,86,eb,66,69,72,65,63,68,61,
           73,65,72,32,37,33,00,00,00,9c,e3,86,b7,e8,f7,cb,4b,8a,33,22,74,8b,be,01,e3,\
        .
        --------------------- DLLs Loaded Under Running Processes ---------------------

        - - - - - - - > 'lsass.exe'(760)
        c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
        .
        Completion time: 2010-02-10  14:00:03
        ComboFix-quarantined-files.txt  2010-02-10 18:59

        Pre-Run: 61,048,250,368 bytes free
        Post-Run: 61,423,726,592 bytes free

        WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
        [boot loader]
        timeout=2
        default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
        [operating systems]
        c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
        multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

        - - End Of File - - 16FD7A69A95D0F5A1024E7753A25F803

        Dr Jay

        • Malware Removal Specialist


        • Specialist
        • Moderator emeritus
        • Thanked: 119
        • Experience: Guru
        • OS: Windows 10
        Re: "Application has been executed" problem.
        « Reply #5 on: February 10, 2010, 08:36:01 PM »
        • Download random's system information tool (RSIT) by random/random from here.
        • It is important that is saved to your desktop.
        • Double click on RSIT.exe to run RSIT.
        • Click Continue at the disclaimer screen.
        • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
        ~Dr Jay

        csturgill

          Topic Starter


          Rookie

          Re: "Application has been executed" problem.
          « Reply #6 on: February 11, 2010, 06:46:47 AM »
          Here are the logs from RSIT:

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Christina at 2010-02-11 08:42:08
          Microsoft Windows XP Professional Service Pack 3
          System drive C: has 59 GB (77%) free of 76 GB
          Total RAM: 502 MB (51% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 8:42:36 AM, on 2/11/2010
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\McAfee.com\Agent\mcagent.exe
          C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\WINDOWS\System32\DLA\DLACTRLW.EXE
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\AIM6\aim6.exe
          C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
          C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
          C:\Program Files\AIM6\aolsoftware.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\system32\dlbtcoms.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
          c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
          c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
          C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
          C:\Program Files\McAfee\MPF\MPFSrv.exe
          C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Viewpoint\Common\ViewpointService.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
          C:\Documents and Settings\Christina\My Documents\Downloads\RSIT.exe
          C:\Program Files\trend micro\Christina.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
          O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
          O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
          O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUfox000
          O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O15 - Trusted Zone: http://nightingale.jhmi.edu
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1205449978031
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: dlbt_device -   - C:\WINDOWS\system32\dlbtcoms.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
          O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
          O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
          O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
          O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
          O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
          O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
          O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
          O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

          --
          End of file - 7513 bytes

          ======Scheduled tasks folder======

          C:\WINDOWS\tasks\AppleSoftwareUpdate.job
          C:\WINDOWS\tasks\McDefragTask.job
          C:\WINDOWS\tasks\McQcTask.job

          ======Registry dump======

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
          Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
          scriptproxy - C:\Program Files\McAfee\VirusScan\scriptsn.dll [2009-09-16 62784]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
          Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
          JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-08-29 73728]

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
          "DLBTCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16 []
          "mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2009-10-29 1218008]
          "ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-07-27 81920]
          "IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2004-05-06 155648]
          "HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2004-05-06 118784]
          "DLA"=C:\WINDOWS\System32\DLA\DLACTRLW.EXE [2005-09-08 122940]
          "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-09-05 417792]
          "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-09-21 305440]
          "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]

          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
          "MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
          "MsnMsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
          "Aim6"=C:\Program Files\AIM6\aim6.exe [2009-05-19 49968]

          C:\Documents and Settings\All Users\Start Menu\Programs\Startup
          Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
          KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
          C:\WINDOWS\system32\igfxsrvc.dll [2004-05-06 344064]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
          C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
          WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
          "dontdisplaylastusername"=0
          "legalnoticecaption"=
          "legalnoticetext"=
          "shutdownwithoutlogon"=1
          "undockwithoutlogon"=1

          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
          "NoDriveTypeAutoRun"=323
          "NoDriveAutoRun"=67108863
          "NoDrives"=0

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
          "HonorAutoRunSetting"=
          "NoDriveAutoRun"=
          "NoDriveTypeAutoRun"=
          "NoDrives"=

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
          "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "C:\WINDOWS\system32\dlbtcoms.exe"="C:\WINDOWS\system32\dlbtcoms.exe:*:Enabled:Photo AIO Printer 922 Server"
          "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
          "C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
          "C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"
          "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
          "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
          "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
          "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
          "C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"
          "C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"="C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"
          "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
          "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
          "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
          "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
          "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
          "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
          "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"

          ======List of files/folders created in the last 1 months======

          2010-02-11 08:42:08 ----D---- C:\rsit
          2010-02-10 14:00:04 ----A---- C:\ComboFix.txt
          2010-02-10 13:49:26 ----A---- C:\Boot.bak
          2010-02-10 13:49:21 ----RASHD---- C:\cmdcons
          2010-02-10 13:47:24 ----A---- C:\WINDOWS\zip.exe
          2010-02-10 13:47:24 ----A---- C:\WINDOWS\SWXCACLS.exe
          2010-02-10 13:47:24 ----A---- C:\WINDOWS\SWSC.exe
          2010-02-10 13:47:24 ----A---- C:\WINDOWS\SWREG.exe
          2010-02-10 13:47:24 ----A---- C:\WINDOWS\sed.exe
          2010-02-10 13:47:24 ----A---- C:\WINDOWS\PEV.exe
          2010-02-10 13:47:24 ----A---- C:\WINDOWS\NIRCMD.exe
          2010-02-10 13:47:24 ----A---- C:\WINDOWS\MBR.exe
          2010-02-10 13:47:24 ----A---- C:\WINDOWS\grep.exe
          2010-02-10 13:47:14 ----D---- C:\WINDOWS\ERDNT
          2010-02-10 13:40:19 ----D---- C:\Qoobox
          2010-02-10 03:07:22 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
          2010-02-10 03:06:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
          2010-02-10 03:04:07 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
          2010-02-10 03:03:58 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
          2010-02-10 03:03:48 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
          2010-02-10 03:03:38 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
          2010-02-10 03:03:23 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
          2010-02-10 03:01:54 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
          2010-02-10 03:01:30 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
          2010-02-08 21:09:10 ----D---- C:\Program Files\Trend Micro
          2010-01-29 10:09:40 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
          2010-01-13 03:04:49 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
          2010-01-13 03:03:31 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$

          ======List of files/folders modified in the last 1 months======

          2010-02-11 08:42:23 ----D---- C:\WINDOWS\Temp
          2010-02-11 08:42:12 ----D---- C:\WINDOWS\Prefetch
          2010-02-11 08:17:16 ----D---- C:\Program Files\Mozilla Firefox
          2010-02-11 08:16:06 ----D---- C:\WINDOWS
          2010-02-10 20:41:51 ----A---- C:\WINDOWS\SchedLgU.Txt
          2010-02-10 15:22:21 ----D---- C:\Program Files\Common Files
          2010-02-10 15:22:21 ----D---- C:\Program Files
          2010-02-10 15:21:28 ----D---- C:\WINDOWS\system32
          2010-02-10 15:21:27 ----D---- C:\WINDOWS\system32\CatRoot2
          2010-02-10 15:14:40 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
          2010-02-10 15:13:59 ----D---- C:\WINDOWS\system32\drivers
          2010-02-10 15:11:23 ----SHD---- C:\WINDOWS\Installer
          2010-02-10 13:56:31 ----A---- C:\WINDOWS\system.ini
          2010-02-10 13:53:46 ----D---- C:\WINDOWS\AppPatch
          2010-02-10 13:49:26 ----RASH---- C:\boot.ini
          2010-02-10 03:07:35 ----HD---- C:\WINDOWS\inf
          2010-02-10 03:07:17 ----HD---- C:\WINDOWS\$hf_mig$
          2010-02-10 03:06:35 ----A---- C:\WINDOWS\imsins.BAK
          2010-02-10 03:06:30 ----RSHDC---- C:\WINDOWS\system32\dllcache
          2010-02-04 10:00:51 ----D---- C:\Program Files\dl_Cats
          2010-02-01 14:26:20 ----A---- C:\WINDOWS\system32\MRT.exe
          2010-02-01 07:25:14 ----SD---- C:\WINDOWS\Downloaded Program Files
          2010-01-31 13:26:46 ----D---- C:\WINDOWS\system32\Adobe
          2010-01-23 03:01:38 ----D---- C:\Program Files\Internet Explorer
          2010-01-23 03:01:30 ----D---- C:\WINDOWS\ie8updates
          2010-01-22 18:18:55 ----D---- C:\Program Files\Microsoft Silverlight

          ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

          R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2005-08-25 5628]
          R1 DLARTL_N;DLARTL_N; C:\WINDOWS\System32\Drivers\DLARTL_N.SYS [2005-08-25 22684]
          R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
          R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2009-09-16 214664]
          R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2009-07-16 120136]
          R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
          R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2005-09-08 25628]
          R2 DLADResN;DLADResN; C:\WINDOWS\System32\DLA\DLADResN.SYS [2005-09-08 2496]
          R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2005-09-08 86524]
          R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS [2005-09-08 14684]
          R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2005-09-08 6364]
          R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2005-09-08 87036]
          R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2005-09-08 94332]
          R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2005-08-12 40544]
          R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-08-05 54752]
          R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
          R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2004-02-10 154112]
          R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
          R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
          R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-05-06 711005]
          R3 IntelC51;IntelC51; C:\WINDOWS\system32\DRIVERS\IntelC51.sys [2004-03-05 1233525]
          R3 IntelC52;IntelC52; C:\WINDOWS\system32\DRIVERS\IntelC52.sys [2004-03-05 647929]
          R3 IntelC53;IntelC53; C:\WINDOWS\system32\DRIVERS\IntelC53.sys [2004-03-05 60949]
          R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2009-09-16 79816]
          R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2009-09-16 35272]
          R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2009-09-16 40552]
          R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
          R3 mohfilt;mohfilt; C:\WINDOWS\system32\DRIVERS\mohfilt.sys [2004-03-05 37048]
          R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-12 12160]
          R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-12 5888]
          R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-04-09 612352]
          R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
          R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
          R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
          S3 catchme;catchme; \??\C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\catchme.sys []
          S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2009-09-16 34248]
          S3 QCDonner;Logitech QuickCam Express; C:\WINDOWS\system32\DRIVERS\OVCD.sys [2001-08-17 28032]
          S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
          S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-08-28 40448]
          S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
          S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
          S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
          S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
          S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
          S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
          S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-12 12032]

          ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

          R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-06-05 144712]
          R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
          R2 dlbt_device;dlbt_device; C:\WINDOWS\system32\dlbtcoms.exe [2007-06-07 538096]
          R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-08-29 153376]
          R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2009-07-09 865832]
          R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2009-07-07 2482848]
          R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2009-07-08 359952]
          R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2009-09-16 144704]
          R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2009-10-27 895696]
          R2 spkrmon;spkrmon; C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe [2003-08-28 61440]
          R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
          R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-09-21 545568]
          R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2009-09-16 606736]
          S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
          S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
          S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
          S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
          S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
          S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2009-09-16 365072]
          S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
          S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
          S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
          S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

          -----------------EOF-----------------


          csturgill

            Topic Starter


            Rookie

            Re: "Application has been executed" problem.
            « Reply #7 on: February 11, 2010, 06:47:36 AM »
            Here is the second log from RSIT:

            info.txt logfile of random's system information tool 1.06 2010-02-11 08:42:41

            ======Uninstall list======

            -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
            -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
            -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
            -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Reader 8.1.7-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
            Adobe Shockwave Player 11.5-->"C:\WINDOWS\system32\Adobe\Shockwave 11\uninstaller.exe"
            AIM 6-->C:\Program Files\AIM6\uninst.exe
            Apple Application Support-->MsiExec.exe /I{0C34B801-6AEC-4667-B053-03A67E2D0415}
            Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
            Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
            CCleaner-->"C:\Documents and Settings\Christina\Desktop\CCleaner\uninst.exe"
            CCScore-->MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
            Comcast High-Speed Internet Install Wizard-->C:\Program Files\support.com\uninstall\chsi_uninstaller.exe
            Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
            Critical Update for Windows Media Player 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
            Dell ResourceCD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
            Diner Dash - Flo on the Go-->C:\PROGRA~1\PLAYFI~1\DINERD~2\UNWISE.EXE C:\PROGRA~1\PLAYFI~1\DINERD~2\INSTALL.LOG
            Diner Dash-->C:\PROGRA~1\PLAYFI~1\DINERD~1\UNWISE.EXE C:\PROGRA~1\PLAYFI~1\DINERD~1\INSTALL.LOG
            Download Updater (AOL LLC)-->C:\Program Files\Common Files\Software Update Utility\uninstall.exe
            ESSCDBK-->MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
            ESScore-->MsiExec.exe /I{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}
            ESSgui-->MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
            ESSini-->MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
            ESSPCD-->MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
            ESSSONIC-->MsiExec.exe /I{073F22CE-9A5B-4A40-A604-C7270AC6BF34}
            ESSTOOLS-->MsiExec.exe /I{8A502E38-29C9-49FA-BCFA-D727CA062589}
            essvatgt-->MsiExec.exe /I{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}
            HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall  /qb+ REBOOTPROMPT=""
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
            Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
            Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
            Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
            Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
            Hotfix for Windows XP (KB954708)-->"C:\WINDOWS\$NtUninstallKB954708$\spuninst\spuninst.exe"
            Hotfix for Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
            Hotfix for Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
            Hotfix for Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
            Intel(R) 537EP V9x DF PCI Modem-->rundll32 IntelCci.dll,iSMUninstallation "Intel(R) 537EP V9x DF PCI Modem"
            Intel(R) Graphics Media Accelerator Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2782 PCI\VEN_8086&DEV_2582
            Intel(R) PRO Network Adapters and Drivers-->Prounstl.exe
            iTunes-->MsiExec.exe /I{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}
            Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216015FF}
            Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
            JS3DPreSchool-->MsiExec.exe /I{478A4971-68B3-4BD9-A379-4EDD111A6BA7}
            JumpStart 3D Ages 3-5-->C:\Program Files\Common Files\Knowledge Adventure\Uninstall\JSW3D3-5Un.exe
            Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
            kgcbaby-->MsiExec.exe /I{E18B549C-5D15-45DA-8D8F-8FD2BD946344}
            kgcbase-->MsiExec.exe /I{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}
            kgchday-->MsiExec.exe /I{11F3F858-4131-4FFA-A560-3FE282933B6E}
            kgchlwn-->MsiExec.exe /I{03EDED24-8375-407D-A721-4643D9768BE1}
            kgcinvt-->MsiExec.exe /I{9BD54685-1496-46A5-AB62-357CD140ED8B}
            kgckids-->MsiExec.exe /I{693C08A7-9E76-43FF-B11E-9A58175474C4}
            kgcmove-->MsiExec.exe /I{A1588373-1D86-4D44-86C9-78ABD190F9CC}
            kgcvday-->MsiExec.exe /I{8A8664E1-84C8-4936-891C-BC1F07797549}
            Kodak EasyShare software-->C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140002_14f361f0\Setup.exe /APR-REMOVE
            KSU-->MsiExec.exe /I{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}
            McAfee SecurityCenter-->C:\Program Files\McAfee\MSC\mcuninst.exe
            Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
            Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
            Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
            Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
            Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
            Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
            Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
            Microsoft Office Professional Edition 2003-->MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9}
            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
            Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
            Microsoft VC9 runtime libraries-->MsiExec.exe /I{C4124E95-5061-4776-8D5D-E3D931C778E1}
            Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Mozilla Firefox (3.5.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
            MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
            netbrdg-->MsiExec.exe /I{56AB063D-1450-4BDE-9F0D-E9C693429C51}
            Notifier-->MsiExec.exe /I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}
            OfotoXMI-->MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
            OpenOffice.org Installer 1.0-->MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
            PCDADDIN-->MsiExec.exe /I{65D85050-5610-4A91-A3B1-D5C744291AD4}
            PCDHELP-->MsiExec.exe /I{C99DCDA4-7407-4F72-A77E-C81C551D0C4E}
            Plantasia-->C:\PROGRA~1\PLAYFI~1\PLANTA~1\UNWISE.EXE C:\PROGRA~1\PLAYFI~1\PLANTA~1\INSTALL.LOG
            QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}
            Roxio DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
            Roxio Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
            Roxio RecordNow Audio-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
            Roxio RecordNow Copy-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
            Roxio RecordNow Data-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
            Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
            Security Update for Windows Internet Explorer 8 (KB978207)-->"C:\WINDOWS\ie8updates\KB978207-IE8\spuninst\spuninst.exe"
            Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
            Security Update for Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
            Security Update for Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
            Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
            Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
            Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB977165)-->"C:\WINDOWS\$NtUninstallKB977165$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
            Security Update for Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
            Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
            SFR-->MsiExec.exe /I{DB02F716-6275-42E9-B8D2-83BA2BF5100B}
            SHASTA-->MsiExec.exe /I{605A4E39-613C-4A12-B56F-DEFBE6757237}
            SKIN0001-->MsiExec.exe /I{FDF9943A-3D5C-46B3-9679-586BD237DDEE}
            SKINXSDK-->MsiExec.exe /I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}
            Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
            SoundMAX-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe"
            staticcr-->MsiExec.exe /I{8943CE61-53BD-475E-90E1-A580869E98A2}
            tooltips-->MsiExec.exe /I{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}
            Unity Web Player-->C:\Program Files\Unity\WebPlayer\Uninstall.exe
            Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
            Update for Windows Internet Explorer 8 (KB971180)-->"C:\WINDOWS\ie8updates\KB971180-IE8\spuninst\spuninst.exe"
            Update for Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
            Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
            Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
            Update for Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
            Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
            Update for Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
            Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
            Update for Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
            Update for Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
            Update for Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
            Update for Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
            Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
            VPRINTOL-->MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370}
            Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
            Windows Live Call-->MsiExec.exe /I{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
            Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
            Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
            Windows Live Essentials-->MsiExec.exe /I{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}
            Windows Live Family Safety-->MsiExec.exe /X{139E303E-1050-497F-98B1-9AE87B15C463}
            Windows Live Mail-->MsiExec.exe /I{6412CECE-8172-4BE5-935B-6CECACD2CA87}
            Windows Live Messenger-->MsiExec.exe /X{A85FD55B-891B-4314-97A5-EA96C0BD80B5}
            Windows Live Photo Gallery-->MsiExec.exe /X{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}
            Windows Live Sign-in Assistant-->MsiExec.exe /I{45338B07-A236-4270-9A77-EBB4115517B5}
            Windows Live Sync-->MsiExec.exe /X{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}
            Windows Live Upload Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            Windows Live Writer-->MsiExec.exe /X{178832DE-9DE0-4C87-9F82-9315A9B03985}
            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
            Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
            Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
            Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
            WIRELESS-->MsiExec.exe /I{F9593CFB-D836-49BC-BFF1-0E669A411D9F}
            Xara Xtreme Pro 5-->MsiExec.exe /X{2BF52D77-1DF7-4391-85B3-AE45CEE8BD86}

            ======Security center information======

            AV: McAfee VirusScan
            FW: McAfee Personal Firewall

            ======System event log======

            Computer Name: HOMEPC-34F003EA
            Event Code: 51
            Message: An error was detected on device \Device\CdRom0 during a paging operation.

            Record Number: 6328
            Source Name: Cdrom
            Time Written: 20090908203000.000000-240
            Event Type: warning
            User:

            Computer Name: HOMEPC-34F003EA
            Event Code: 51
            Message: An error was detected on device \Device\CdRom0 during a paging operation.

            Record Number: 6327
            Source Name: Cdrom
            Time Written: 20090908203000.000000-240
            Event Type: warning
            User:

            Computer Name: HOMEPC-34F003EA
            Event Code: 51
            Message: An error was detected on device \Device\CdRom0 during a paging operation.

            Record Number: 6326
            Source Name: Cdrom
            Time Written: 20090908202956.000000-240
            Event Type: warning
            User:

            Computer Name: HOMEPC-34F003EA
            Event Code: 51
            Message: An error was detected on device \Device\CdRom0 during a paging operation.

            Record Number: 6325
            Source Name: Cdrom
            Time Written: 20090908202956.000000-240
            Event Type: warning
            User:

            Computer Name: HOMEPC-34F003EA
            Event Code: 51
            Message: An error was detected on device \Device\CdRom0 during a paging operation.

            Record Number: 6324
            Source Name: Cdrom
            Time Written: 20090908202956.000000-240
            Event Type: warning
            User:

            =====Application event log=====

            Computer Name: HOMEPC-34F003EA
            Event Code: 485
            Message: svchost (1112) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb" failed with system error 1392 (0x00000570): "The file or directory is corrupted and unreadable. ".  The delete file operation will fail with error -1022 (0xfffffc02).

            Record Number: 3637
            Source Name: ESENT
            Time Written: 20090928195726.000000-240
            Event Type: error
            User:

            Computer Name: HOMEPC-34F003EA
            Event Code: 485
            Message: svchost (1112) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb" failed with system error 1392 (0x00000570): "The file or directory is corrupted and unreadable. ".  The delete file operation will fail with error -1022 (0xfffffc02).

            Record Number: 3636
            Source Name: ESENT
            Time Written: 20090928195726.000000-240
            Event Type: error
            User:

            Computer Name: HOMEPC-34F003EA
            Event Code: 485
            Message: svchost (1112) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb" failed with system error 1392 (0x00000570): "The file or directory is corrupted and unreadable. ".  The delete file operation will fail with error -1022 (0xfffffc02).

            Record Number: 3635
            Source Name: ESENT
            Time Written: 20090928195726.000000-240
            Event Type: error
            User:

            Computer Name: HOMEPC-34F003EA
            Event Code: 485
            Message: svchost (1112) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb" failed with system error 1392 (0x00000570): "The file or directory is corrupted and unreadable. ".  The delete file operation will fail with error -1022 (0xfffffc02).

            Record Number: 3634
            Source Name: ESENT
            Time Written: 20090928195726.000000-240
            Event Type: error
            User:

            Computer Name: HOMEPC-34F003EA
            Event Code: 485
            Message: svchost (1112) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb" failed with system error 1392 (0x00000570): "The file or directory is corrupted and unreadable. ".  The delete file operation will fail with error -1022 (0xfffffc02).

            Record Number: 3633
            Source Name: ESENT
            Time Written: 20090928195726.000000-240
            Event Type: error
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\QuickTime\QTSystem
            "windir"=%SystemRoot%
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=15
            "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 3 Stepping 4, GenuineIntel
            "PROCESSOR_REVISION"=0304
            "NUMBER_OF_PROCESSORS"=1
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "SonicCentral"=C:\Program Files\Common Files\Sonic Shared\Sonic Central\
            "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
            "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

            -----------------EOF-----------------

            Dr Jay

            • Malware Removal Specialist


            • Specialist
            • Moderator emeritus
            • Thanked: 119
            • Experience: Guru
            • OS: Windows 10
            Re: "Application has been executed" problem.
            « Reply #8 on: February 11, 2010, 03:58:45 PM »
            Please download: HijackThis to your Desktop.
            2.0.3 (Beta): http://go.trendmicro.com/free-tools/hijackthis/beta/HijackThis.msi
            2.0.2 (Stable): http://go.trendmicro.com/free-tools/hijackthis/HijackThisInstaller.exe
            • Double Click the HijackThis icon, located on your Desktop.
            • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis

                 It will also create a shortcut on your Desktop.
            • Accept the license agreement.
            • Click Do a System Scan and Save a Logfile.
            • Please post the log in your next reply.
            ~Dr Jay

            csturgill

              Topic Starter


              Rookie

              Re: "Application has been executed" problem.
              « Reply #9 on: February 12, 2010, 04:51:46 AM »
              Here is the log file from HijackThis:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 6:50:59 AM, on 2/12/2010
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\McAfee.com\Agent\mcagent.exe
              C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
              C:\WINDOWS\system32\hkcmd.exe
              C:\WINDOWS\System32\DLA\DLACTRLW.EXE
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\AIM6\aim6.exe
              C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
              C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
              C:\Program Files\AIM6\aolsoftware.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\WINDOWS\system32\dlbtcoms.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
              c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
              c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
              C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
              C:\Program Files\McAfee\MPF\MPFSrv.exe
              C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Viewpoint\Common\ViewpointService.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
              c:\PROGRA~1\mcafee\msc\mcshell.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Documents and Settings\Christina\My Documents\Downloads\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
              O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
              O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
              O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
              O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
              O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUfox000
              O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O15 - Trusted Zone: http://nightingale.jhmi.edu
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1205449978031
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: dlbt_device -   - C:\WINDOWS\system32\dlbtcoms.exe
              O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
              O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
              O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
              O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
              O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
              O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
              O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
              O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
              O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

              --
              End of file - 7606 bytes

              Dr Jay

              • Malware Removal Specialist


              • Specialist
              • Moderator emeritus
              • Thanked: 119
              • Experience: Guru
              • OS: Windows 10
              Re: "Application has been executed" problem.
              « Reply #10 on: February 12, 2010, 12:19:00 PM »
              Download [color="#FF0000"]OTL.exe[/color][/url] by OldTimer to your Desktop.
              • Close all windows and double click OTL.exe.
              • Click Run Scan and let the program run uninterrupted.
              • It will produce two logs for you, one will pop up - OTL.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.
              • You may need to use two posts to get it all.
              ~Dr Jay

              csturgill

                Topic Starter


                Rookie

                Re: "Application has been executed" problem.
                « Reply #11 on: February 12, 2010, 01:00:33 PM »
                Ok, I have the two logs from OLT.  Can you give me any insight?  What's up with my computer?  What are all these logs telling you?  Also on the HijackThis should I have ever hit the "Fix" button or anything??

                Here is the first log:

                OTL logfile created on: 2/12/2010 2:45:28 PM - Run 1
                OTL by OldTimer - Version 3.1.28.0     Folder = C:\Documents and Settings\Christina\My Documents\Downloads
                Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
                Internet Explorer (Version = 8.0.6001.18702)
                Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
                 
                502.00 Mb Total Physical Memory | 272.00 Mb Available Physical Memory | 54.00% Memory free
                1.00 Gb Paging File | 1.00 Gb Available in Paging File | 62.00% Paging File free
                Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
                 
                %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
                Drive C: | 74.50 Gb Total Space | 57.17 Gb Free Space | 76.74% Space Free | Partition Type: NTFS
                Drive D: | 564.14 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
                E: Drive not present or media not loaded
                F: Drive not present or media not loaded
                G: Drive not present or media not loaded
                H: Drive not present or media not loaded
                I: Drive not present or media not loaded
                 
                Computer Name: HOMEPC-34F003EA
                Current User Name: Christina
                Logged in as Administrator.
                 
                Current Boot Mode: Normal
                Scan Mode: Current user
                Company Name Whitelist: Off
                Skip Microsoft Files: Off
                File Age = 30 Days
                Output = Standard
                 
                ========== Processes (SafeList) ==========
                 
                PRC - [2010/02/12 14:43:25 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Christina\My Documents\Downloads\OTL.exe
                PRC - [2009/10/29 06:54:44 | 001,218,008 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
                PRC - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MpfSrv.exe
                PRC - [2009/09/21 15:36:12 | 000,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
                PRC - [2009/09/21 15:36:02 | 000,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
                PRC - [2009/09/16 09:22:08 | 000,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe
                PRC - [2009/09/16 08:28:38 | 000,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe
                PRC - [2009/08/29 07:47:26 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
                PRC - [2009/07/09 23:26:20 | 000,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe
                PRC - [2009/07/08 10:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
                PRC - [2009/07/07 18:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
                PRC - [2009/06/05 10:48:14 | 000,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                PRC - [2009/05/19 00:23:16 | 000,049,968 | ---- | M] (AOL LLC) -- C:\Program Files\AIM6\aim6.exe
                PRC - [2008/12/12 10:17:38 | 000,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
                PRC - [2008/11/06 12:33:00 | 000,041,264 | ---- | M] (AOL LLC) -- C:\Program Files\AIM6\aolsoftware.exe
                PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
                PRC - [2007/06/07 00:50:14 | 000,538,096 | ---- | M] ( ) -- C:\WINDOWS\system32\dlbtcoms.exe
                PRC - [2007/02/20 04:10:26 | 000,282,624 | ---- | M] (Eastman Kodak Company) -- C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                PRC - [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
                PRC - [2005/09/08 04:20:00 | 000,122,940 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXE
                PRC - [2004/07/27 15:50:18 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
                PRC - [2004/05/06 15:48:06 | 000,118,784 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\hkcmd.exe
                PRC - [2004/02/13 13:12:08 | 000,016,423 | ---- | M] () -- C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
                PRC - [2003/08/28 14:01:22 | 000,061,440 | ---- | M] () -- C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
                 
                 
                ========== Modules (SafeList) ==========
                 
                MOD - [2010/02/12 14:43:25 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Christina\My Documents\Downloads\OTL.exe
                MOD - [2004/02/11 15:58:16 | 000,024,613 | ---- | M] (BackWeb) -- C:\Documents and Settings\Christina\Local Settings\temp\IadHide5.dll
                 
                 
                ========== Win32 Services (SafeList) ==========
                 
                SRV - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
                SRV - [2009/09/21 15:36:02 | 000,545,568 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
                SRV - [2009/09/16 10:23:32 | 000,365,072 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
                SRV - [2009/09/16 09:22:08 | 000,144,704 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
                SRV - [2009/09/16 08:28:38 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
                SRV - [2009/08/29 07:47:26 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
                SRV - [2009/08/05 21:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
                SRV - [2009/07/09 23:26:20 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
                SRV - [2009/07/08 10:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
                SRV - [2009/07/07 18:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
                SRV - [2009/06/05 10:48:14 | 000,144,712 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
                SRV - [2008/12/12 10:17:38 | 000,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
                SRV - [2007/06/07 00:50:14 | 000,538,096 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\dlbtcoms.exe -- (dlbt_device)
                SRV - [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
                SRV - [2003/08/28 14:01:22 | 000,061,440 | ---- | M] () [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe -- (spkrmon)
                SRV - [2003/07/28 11:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
                 
                 
                ========== Driver Services (SafeList) ==========
                 
                DRV - [2009/09/16 09:22:48 | 000,214,664 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
                DRV - [2009/09/16 09:22:48 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
                DRV - [2009/09/16 09:22:48 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfesmfk.sys -- (mfesmfk)
                DRV - [2009/09/16 09:22:48 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
                DRV - [2009/09/16 09:22:14 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mferkdk.sys -- (mferkdk)
                DRV - [2009/08/28 18:42:52 | 000,040,448 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaapl.sys -- (USBAAPL)
                DRV - [2009/08/05 21:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
                DRV - [2009/07/16 11:32:26 | 000,120,136 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Mpfp.sys -- (MPFP)
                DRV - [2009/05/18 13:17:00 | 000,026,600 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
                DRV - [2007/11/13 05:25:53 | 000,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
                DRV - [2006/10/18 02:00:00 | 000,036,624 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)
                DRV - [2005/09/12 02:30:00 | 000,089,264 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS -- (DRVMCDB)
                DRV - [2005/09/08 04:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
                DRV - [2005/09/08 04:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
                DRV - [2005/09/08 04:20:00 | 000,086,524 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
                DRV - [2005/09/08 04:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
                DRV - [2005/09/08 04:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
                DRV - [2005/09/08 04:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
                DRV - [2005/09/08 04:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
                DRV - [2005/08/25 11:16:52 | 000,005,628 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
                DRV - [2005/08/25 11:16:16 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
                DRV - [2005/08/12 04:20:00 | 000,040,544 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS -- (DRVNDDM)
                DRV - [2004/08/12 08:27:22 | 000,005,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rootmdm.sys -- (ROOTMODEM)
                DRV - [2004/08/12 08:26:42 | 000,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
                DRV - [2004/05/06 16:14:28 | 000,711,005 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ialmnt5.sys -- (ialm)
                DRV - [2004/04/09 12:41:30 | 000,612,352 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm)
                DRV - [2004/03/05 22:15:34 | 000,647,929 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntelC52.sys -- (IntelC52)
                DRV - [2004/03/05 22:14:42 | 001,233,525 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntelC51.sys -- (IntelC51)
                DRV - [2004/03/05 22:13:52 | 000,060,949 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntelC53.sys -- (IntelC53)
                DRV - [2004/03/05 22:13:38 | 000,037,048 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mohfilt.sys -- (mohfilt)
                DRV - [2004/02/10 15:49:14 | 000,154,112 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e100b325.sys -- (E100B) Intel(R)
                DRV - [2002/04/01 13:15:00 | 000,004,816 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (aeaudio)
                DRV - [2001/08/22 08:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)
                DRV - [2001/08/17 13:57:38 | 000,016,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA)
                DRV - [2001/08/17 13:05:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\OVCD.sys -- (QCDonner)
                 
                 
                ========== Standard Registry (SafeList) ==========
                 
                 
                ========== Internet Explorer ==========
                 
                 
                IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
                IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
                IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F6 AD 73 EA 80 AB CA 01  [binary data]
                IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
                 
                ========== FireFox ==========
                 
                FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
                FF - prefs.js..extensions.enabledItems: [email protected]:1.0
                FF - prefs.js..network.proxy.ftp: ":0"
                FF - prefs.js..network.proxy.gopher: ":0"
                FF - prefs.js..network.proxy.http: ":0"
                FF - prefs.js..network.proxy.share_proxy_set tings: true
                FF - prefs.js..network.proxy.socks: ":0"
                FF - prefs.js..network.proxy.ssl: ":0"
                 
                FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/19 11:02:25 | 000,000,000 | ---D | M]
                FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/01 07:25:15 | 000,000,000 | ---D | M]
                 
                [2009/09/08 16:59:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Christina\Application Data\Mozilla\Extensions
                [2010/02/11 08:27:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\qqgpynxh.default\extensions
                [2009/09/08 16:58:40 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
                 
                O1 HOSTS File: ([2004/08/12 08:19:39 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
                O1 - Hosts: 127.0.0.1       localhost
                O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
                O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
                O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
                O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
                O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
                O4 - HKLM..\Run: [DLBTCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.DLL ()
                O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
                O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
                O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
                O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
                O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
                O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
                O4 - HKCU..\Run: [Aim6] C:\Program Files\AIM6\aim6.exe (AOL LLC)
                O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
                O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
                O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
                O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
                O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
                O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
                O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
                O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
                O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
                O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
                O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
                O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
                O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
                O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
                O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
                O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
                O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
                O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
                O15 - HKCU\..Trusted Domains: jhmi.edu ([nightingale] http in Trusted sites)
                O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
                O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
                O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1205449978031 (MUWebControl Class)
                O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
                O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
                O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
                O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
                O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.73.246 68.87.71.230
                O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
                O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
                O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
                O24 - Desktop WallPaper: C:\Documents and Settings\Christina\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
                O24 - Desktop BackupWallPaper: C:\Documents and Settings\Christina\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
                O32 - HKLM CDRom: AutoRun - 1
                O32 - AutoRun File - [2008/03/12 20:00:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
                O32 - AutoRun File - [2004/01/29 09:43:25 | 000,000,037 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
                O33 - MountPoints2\{d11f6442-f069-11dc-b311-806d6172696f}\Shell - "" = AutoRun
                O33 - MountPoints2\{d11f6442-f069-11dc-b311-806d6172696f}\Shell\AutoRun - "" = Auto&Play
                O33 - MountPoints2\{d11f6442-f069-11dc-b311-806d6172696f}\Shell\AutoRun\command - "" = D:\winopen.exe \EC10.exe -- File not found
                O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
                O35 - comfile [open] -- "%1" %*
                O35 - exefile [open] -- "%1" %*
                 
                ========== Files/Folders - Created Within 30 Days ==========
                 
                [2010/02/12 07:19:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Christina\Application Data\McAfee
                [2010/02/12 01:00:01 | 000,000,000 | -HSD | C] -- C:\RECYCLER
                [2010/02/11 08:42:08 | 000,000,000 | ---D | C] -- C:\rsit
                [2010/02/10 13:49:21 | 000,000,000 | RHSD | C] -- C:\cmdcons
                [2010/02/10 13:47:24 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
                [2010/02/10 13:47:24 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
                [2010/02/10 13:47:24 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
                [2010/02/10 13:47:24 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
                [2010/02/10 13:47:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
                [2010/02/10 13:40:19 | 000,000,000 | ---D | C] -- C:\Qoobox
                [2010/02/08 21:38:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Christina\Desktop\CCleaner
                [2010/02/08 21:09:10 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
                [2010/02/08 21:01:55 | 000,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Christina\Desktop\sniper.exe.exe
                [2010/01/29 10:09:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS
                [2009/09/10 02:01:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
                [2008/12/17 17:14:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
                [2008/08/23 15:37:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
                [2008/07/21 17:13:23 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
                [2008/03/12 19:59:55 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
                [2007/01/30 13:47:52 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbtpmui.dll
                [2007/01/30 13:46:00 | 001,224,704 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbtserv.dll
                [2007/01/30 13:38:18 | 000,421,888 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbtcomm.dll
                [2007/01/30 13:36:30 | 000,585,728 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbtlmpm.dll
                [2007/01/30 13:35:00 | 000,397,312 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbtiesc.dll
                [2007/01/30 13:32:06 | 000,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbtpplc.dll
                [2007/01/30 13:31:08 | 000,684,032 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbtcomc.dll
                [2007/01/30 13:30:30 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbtprox.dll
                [2007/01/30 13:22:32 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbtinpa.dll
                [2007/01/30 13:21:46 | 000,995,328 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbtusb1.dll
                [2007/01/30 13:17:02 | 000,696,320 | ---- | C] ( ) -- C:\WINDOWS\System32\dlbthbn3.dll
                [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
                [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
                 
                ========== Files - Modified Within 30 Days ==========
                 
                [2010/02/12 14:44:10 | 000,000,641 | ---- | M] () -- C:\Documents and Settings\Christina\Desktop\Shortcut to OTL.lnk
                [2010/02/12 07:17:30 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Virtual Technician.lnk
                [2010/02/12 06:50:38 | 000,001,618 | ---- | M] () -- C:\Documents and Settings\Christina\Desktop\HijackThis.lnk
                [2010/02/12 06:48:41 | 000,000,697 | ---- | M] () -- C:\Documents and Settings\Christina\Desktop\Shortcut to HJTInstall(2).lnk
                [2010/02/12 06:48:28 | 000,000,727 | ---- | M] () -- C:\Documents and Settings\Christina\Desktop\Shortcut to HijackThisInstaller.lnk
                [2010/02/12 01:01:03 | 000,000,332 | ---- | M] () -- C:\WINDOWS\tasks\McQcTask.job
                [2010/02/12 01:00:10 | 000,001,475 | ---- | M] () -- C:\Documents and Settings\Christina\Desktop\Windows Explorer.lnk
                [2010/02/11 08:41:32 | 000,000,648 | ---- | M] () -- C:\Documents and Settings\Christina\Desktop\Shortcut to RSIT.lnk
                [2010/02/11 08:21:21 | 000,022,604 | ---- | M] () -- C:\logfile
                [2010/02/11 08:17:03 | 003,801,088 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb
                [2010/02/11 08:17:01 | 001,898,496 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb
                [2010/02/11 08:16:25 | 000,005,117 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF
                [2010/02/11 08:16:14 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
                [2010/02/11 08:14:59 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
                [2010/02/11 08:14:57 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
                [2010/02/10 20:41:38 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Christina\ntuser.ini
                [2010/02/10 20:41:37 | 004,980,736 | -H-- | M] () -- C:\Documents and Settings\Christina\NTUSER.DAT
                [2010/02/10 17:14:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
                [2010/02/10 13:56:31 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
                [2010/02/10 13:49:26 | 000,000,281 | RHS- | M] () -- C:\boot.ini
                [2010/02/10 13:38:25 | 000,000,672 | ---- | M] () -- C:\Documents and Settings\Christina\Desktop\blackpudding.bat.lnk
                [2010/02/10 11:20:21 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
                [2010/02/10 03:06:35 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
                [2010/02/08 21:38:58 | 000,001,506 | ---- | M] () -- C:\Documents and Settings\Christina\Desktop\CCleaner.lnk
                [2010/02/08 21:01:57 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Christina\Desktop\sniper.exe.exe
                [2010/02/05 22:08:28 | 000,075,583 | ---- | M] () -- C:\Documents and Settings\Christina\Desktop\Cheetah-Anti-Rogue.cmd
                [2010/01/15 01:10:26 | 000,000,348 | ---- | M] () -- C:\WINDOWS\tasks\McDefragTask.job
                [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
                [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
                 
                ========== Files Created - No Company Name ==========
                 
                [2010/02/12 14:44:10 | 000,000,641 | ---- | C] () -- C:\Documents and Settings\Christina\Desktop\Shortcut to OTL.lnk
                [2010/02/12 07:17:30 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Virtual Technician.lnk
                [2010/02/12 06:50:38 | 000,001,618 | ---- | C] () -- C:\Documents and Settings\Christina\Desktop\HijackThis.lnk
                [2010/02/12 06:48:41 | 000,000,697 | ---- | C] () -- C:\Documents and Settings\Christina\Desktop\Shortcut to HJTInstall(2).lnk
                [2010/02/12 06:48:28 | 000,000,727 | ---- | C] () -- C:\Documents and Settings\Christina\Desktop\Shortcut to HijackThisInstaller.lnk
                [2010/02/11 08:41:32 | 000,000,648 | ---- | C] () -- C:\Documents and Settings\Christina\Desktop\Shortcut to RSIT.lnk
                [2010/02/10 13:49:26 | 000,000,211 | ---- | C] () -- C:\Boot.bak
                [2010/02/10 13:49:22 | 000,260,272 | ---- | C] () -- C:\cmldr
                [2010/02/10 13:47:24 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
                [2010/02/10 13:47:24 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
                [2010/02/10 13:47:24 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
                [2010/02/10 13:47:24 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
                [2010/02/10 13:47:24 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
                [2010/02/10 13:38:25 | 000,000,672 | ---- | C] () -- C:\Documents and Settings\Christina\Desktop\blackpudding.bat.lnk
                [2010/02/08 21:38:58 | 000,001,506 | ---- | C] () -- C:\Documents and Settings\Christina\Desktop\CCleaner.lnk
                [2010/02/05 22:08:28 | 000,075,583 | ---- | C] () -- C:\Documents and Settings\Christina\Desktop\Cheetah-Anti-Rogue.cmd
                [2008/12/27 10:19:37 | 000,000,062 | ---- | C] () -- C:\WINDOWS\ka.ini
                [2008/10/01 19:55:03 | 000,000,175 | ---- | C] () -- C:\WINDOWS\wininit.ini
                [2008/04/30 15:41:48 | 000,012,288 | ---- | C] () -- C:\Documents and Settings\Christina\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
                [2008/03/13 18:01:19 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
                [2008/03/12 21:21:46 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
                [2007/08/06 10:07:30 | 000,008,784 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
                [2007/04/27 10:43:58 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
                [2007/02/19 06:20:28 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\dlbtinsr.dll
                [2007/02/19 06:20:24 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\dlbtcur.dll
                [2007/02/19 06:20:02 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\dlbtjswr.dll
                [2007/02/19 06:17:06 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlbtinsb.dll
                [2007/02/19 06:17:00 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dlbtcub.dll
                [2007/02/19 06:16:52 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\dlbtcu.dll
                [2007/02/19 06:16:48 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\dlbtins.dll
                [2007/02/19 06:15:34 | 000,434,176 | ---- | C] () -- C:\WINDOWS\System32\dlbtutil.dll
                [2007/02/07 16:57:16 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\dlbtcoin.dll
                [2007/01/22 01:18:28 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\dlbtcfg.dll
                [2005/11/18 13:47:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
                [2005/08/18 09:26:46 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbtvs.dll
                [2005/05/25 08:07:26 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\dlbtcnv4.dll
                [2003/01/07 14:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
                 
                ========== Alternate Data Streams ==========
                 
                @Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E36F5B57
                @Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8E29393
                @Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
                @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
                < End of report >

                csturgill

                  Topic Starter


                  Rookie

                  Re: "Application has been executed" problem.
                  « Reply #12 on: February 12, 2010, 01:01:42 PM »
                  And the second log:

                  OTL Extras logfile created on: 2/12/2010 2:45:32 PM - Run 1
                  OTL by OldTimer - Version 3.1.28.0     Folder = C:\Documents and Settings\Christina\My Documents\Downloads
                  Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
                  Internet Explorer (Version = 8.0.6001.18702)
                  Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
                   
                  502.00 Mb Total Physical Memory | 272.00 Mb Available Physical Memory | 54.00% Memory free
                  1.00 Gb Paging File | 1.00 Gb Available in Paging File | 62.00% Paging File free
                  Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
                   
                  %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
                  Drive C: | 74.50 Gb Total Space | 57.17 Gb Free Space | 76.74% Space Free | Partition Type: NTFS
                  Drive D: | 564.14 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
                  E: Drive not present or media not loaded
                  F: Drive not present or media not loaded
                  G: Drive not present or media not loaded
                  H: Drive not present or media not loaded
                  I: Drive not present or media not loaded
                   
                  Computer Name: HOMEPC-34F003EA
                  Current User Name: Christina
                  Logged in as Administrator.
                   
                  Current Boot Mode: Normal
                  Scan Mode: Current user
                  Company Name Whitelist: Off
                  Skip Microsoft Files: Off
                  File Age = 30 Days
                  Output = Standard
                   
                  ========== Extra Registry (SafeList) ==========
                   
                   
                  ========== File Associations ==========
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
                  .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
                   
                  [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
                  .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
                   
                  ========== Shell Spawning ==========
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
                  batfile [open] -- "%1" %*
                  cmdfile [open] -- "%1" %*
                  comfile [open] -- "%1" %*
                  exefile [open] -- "%1" %*
                  htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
                  htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
                  htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
                  http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
                  https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
                  piffile [open] -- "%1" %*
                  regfile [merge] -- Reg Error: Key error.
                  scrfile [config] -- "%1"
                  scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
                  scrfile [open] -- "%1" /S
                  txtfile [edit] -- Reg Error: Key error.
                  Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
                  Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
                  Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
                  Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
                  Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
                  Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
                  CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)
                   
                  ========== Security Center Settings ==========
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                  "FirstRunDisabled" = 
                  "FirewallDisableNotify" = 0
                  "UpdatesDisableNotify" = 0
                  "AntiVirusOverride" = 0
                  "FirewallOverride" = 0
                  "AntiVirusDisableNotify" = 0
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
                  "DisableMonitoring" = 1
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
                  "DisableMonitoring" = 1
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
                   
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
                   
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
                  "EnableFirewall" = 0
                  "DoNotAllowExceptions" = 0
                   
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
                   
                  ========== Authorized Applications List ==========
                   
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
                  "C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- File not found
                  "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
                  "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
                   
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
                  "C:\WINDOWS\system32\dlbtcoms.exe" = C:\WINDOWS\system32\dlbtcoms.exe:*:Enabled:Photo AIO Printer 922 Server -- ( )
                  "C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC)
                  "C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- (AOL LLC)
                  "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
                  "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
                  "C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent -- (McAfee, Inc.)
                  "C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare -- (Eastman Kodak Company)
                  "C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
                  "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
                   
                   
                  ========== HKEY_LOCAL_MACHINE Uninstall List ==========
                   
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
                  "{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
                  "{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
                  "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
                  "{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
                  "{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
                  "{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
                  "{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
                  "{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
                  "{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
                  "{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
                  "{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
                  "{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
                  "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
                  "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
                  "{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java(TM) 6 Update 15
                  "{2BF52D77-1DF7-4391-85B3-AE45CEE8BD86}" = Xara Xtreme Pro 5
                  "{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
                  "{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
                  "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
                  "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
                  "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
                  "{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
                  "{478A4971-68B3-4BD9-A379-4EDD111A6BA7}" = JS3DPreSchool
                  "{49FA793C-785E-47E9-93DF-BD442B0B45D1}" = McAfee Virtual Technician
                  "{56AB063D-1450-4BDE-9F0D-E9C693429C51}" = netbrdg
                  "{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
                  "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
                  "{65D85050-5610-4A91-A3B1-D5C744291AD4}" = PCDADDIN
                  "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
                  "{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
                  "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
                  "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
                  "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
                  "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
                  "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
                  "{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
                  "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
                  "{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
                  "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver
                  "{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
                  "{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
                  "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
                  "{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
                  "{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
                  "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
                  "{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
                  "{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
                  "{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
                  "{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
                  "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
                  "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
                  "{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
                  "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
                  "{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
                  "{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
                  "{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.7
                  "{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
                  "{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
                  "{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
                  "{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
                  "{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
                  "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
                  "{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
                  "{C99DCDA4-7407-4F72-A77E-C81C551D0C4E}" = PCDHELP
                  "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
                  "{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
                  "{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
                  "{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
                  "{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
                  "{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
                  "{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
                  "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
                  "{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
                  "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
                  "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
                  "{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
                  "{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
                  "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
                  "{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
                  "{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
                  "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
                  "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
                  "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
                  "AIM_6" = AIM 6
                  "CCleaner" = CCleaner
                  "ComcastHSI" = Comcast High-Speed Internet Install Wizard
                  "Diner Dash" = Diner Dash
                  "Diner Dash - Flo on the Go" = Diner Dash - Flo on the Go
                  "HijackThis" = HijackThis 2.0.2
                  "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
                  "ie7" = Windows Internet Explorer 7
                  "ie8" = Windows Internet Explorer 8
                  "Intel(R) 537EP V9x DF PCI Modem" = Intel(R) 537EP V9x DF PCI Modem
                  "JumpStart 3D Ages 3-5" = JumpStart 3D Ages 3-5
                  "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
                  "Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
                  "MSC" = McAfee SecurityCenter
                  "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
                  "MSNINST" = MSN
                  "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
                  "PROSet" = Intel(R) PRO Network Adapters and Drivers
                  "SoftwareUpdUtility" = Download Updater (AOL LLC)
                  "UnityWebPlayer" = Unity Web Player
                  "ViewpointMediaPlayer" = Viewpoint Media Player
                  "Windows Media Format Runtime" = Windows Media Format 11 runtime
                  "Windows Media Player" = Windows Media Player 11
                  "Windows XP Service Pack" = Windows XP Service Pack 3
                  "WinLiveSuite_Wave3" = Windows Live Essentials
                  "WMFDist11" = Windows Media Format 11 runtime
                  "wmp11" = Windows Media Player 11
                  "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
                   
                  ========== Last 10 Event Log Errors ==========
                   
                  [ Application Events ]
                  Error - 2/8/2010 7:58:51 PM | Computer Name = HOMEPC-34F003EA | Source = crypt32 | ID = 131080
                  Description = Failed auto update retrieval of third-party root list sequence number
                   from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
                   with error: This network connection does not exist. 
                   
                  Error - 2/8/2010 7:58:53 PM | Computer Name = HOMEPC-34F003EA | Source = crypt32 | ID = 131080
                  Description = Failed auto update retrieval of third-party root list sequence number
                   from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
                   with error: This network connection does not exist. 
                   
                  Error - 2/8/2010 7:58:53 PM | Computer Name = HOMEPC-34F003EA | Source = crypt32 | ID = 131080
                  Description = Failed auto update retrieval of third-party root list sequence number
                   from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
                   with error: This network connection does not exist. 
                   
                  Error - 2/9/2010 10:36:24 AM | Computer Name = HOMEPC-34F003EA | Source = ESENT | ID = 489
                  Description = wuauclt (1816) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
                   for read only access failed with system error 32 (0x00000020): "The process cannot
                   access the file because it is being used by another process. ".  The open file
                  operation will fail with error -1032 (0xfffffbf8).
                   
                  Error - 2/9/2010 10:36:24 AM | Computer Name = HOMEPC-34F003EA | Source = ESENT | ID = 455
                  Description = wuaueng.dll (1816) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
                  occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
                   
                  Error - 2/9/2010 10:36:34 AM | Computer Name = HOMEPC-34F003EA | Source = ESENT | ID = 489
                  Description = wuauclt (1816) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
                   for read only access failed with system error 32 (0x00000020): "The process cannot
                   access the file because it is being used by another process. ".  The open file
                  operation will fail with error -1032 (0xfffffbf8).
                   
                  Error - 2/9/2010 10:36:34 AM | Computer Name = HOMEPC-34F003EA | Source = ESENT | ID = 455
                  Description = wuaueng.dll (1816) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
                  occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
                   
                  Error - 2/10/2010 10:13:48 AM | Computer Name = HOMEPC-34F003EA | Source = Application Hang | ID = 1002
                  Description = Hanging application firefox.exe, version 1.9.1.3642, hang module hungapp,
                   version 0.0.0.0, hang address 0x00000000.
                   
                  Error - 2/10/2010 10:13:50 AM | Computer Name = HOMEPC-34F003EA | Source = Application Hang | ID = 1002
                  Description = Hanging application firefox.exe, version 1.9.1.3642, hang module hungapp,
                   version 0.0.0.0, hang address 0x00000000.
                   
                  Error - 2/10/2010 4:13:54 PM | Computer Name = HOMEPC-34F003EA | Source = pctsSvc.exe | ID = 0
                  Description =
                   
                  [ System Events ]
                  Error - 2/9/2010 9:31:07 AM | Computer Name = HOMEPC-34F003EA | Source = DCOM | ID = 10010
                  Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
                   with DCOM within the required timeout.
                   
                  Error - 2/9/2010 9:48:16 AM | Computer Name = HOMEPC-34F003EA | Source = DCOM | ID = 10010
                  Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
                   with DCOM within the required timeout.
                   
                  Error - 2/9/2010 9:50:31 AM | Computer Name = HOMEPC-34F003EA | Source = DCOM | ID = 10010
                  Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
                   with DCOM within the required timeout.
                   
                  Error - 2/9/2010 10:06:14 AM | Computer Name = HOMEPC-34F003EA | Source = DCOM | ID = 10010
                  Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
                   with DCOM within the required timeout.
                   
                  Error - 2/9/2010 11:08:28 AM | Computer Name = HOMEPC-34F003EA | Source = DCOM | ID = 10010
                  Description = The server {B44D92F9-978C-42F3-9382-6EAD817BA0AE} did not register
                   with DCOM within the required timeout.
                   
                  Error - 2/9/2010 11:09:00 AM | Computer Name = HOMEPC-34F003EA | Source = DCOM | ID = 10010
                  Description = The server {B44D92F9-978C-42F3-9382-6EAD817BA0AE} did not register
                   with DCOM within the required timeout.
                   
                  Error - 2/9/2010 11:09:31 AM | Computer Name = HOMEPC-34F003EA | Source = DCOM | ID = 10010
                  Description = The server {B44D92F9-978C-42F3-9382-6EAD817BA0AE} did not register
                   with DCOM within the required timeout.
                   
                  Error - 2/9/2010 11:10:22 AM | Computer Name = HOMEPC-34F003EA | Source = DCOM | ID = 10010
                  Description = The server {B44D92F9-978C-42F3-9382-6EAD817BA0AE} did not register
                   with DCOM within the required timeout.
                   
                  Error - 2/10/2010 12:18:29 PM | Computer Name = HOMEPC-34F003EA | Source = Print | ID = 54
                  Description = Document Microsoft Word - ATI%20Readings.doc%20%202%201%2010.doc was
                   corrupted and has been deleted.  The associated driver is: HP DeskJet 712C.
                   
                  Error - 2/11/2010 9:15:53 AM | Computer Name = HOMEPC-34F003EA | Source = DCOM | ID = 10010
                  Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
                   with DCOM within the required timeout.
                   
                   
                  < End of report >

                  Dr Jay

                  • Malware Removal Specialist


                  • Specialist
                  • Moderator emeritus
                  • Thanked: 119
                  • Experience: Guru
                  • OS: Windows 10
                  Re: "Application has been executed" problem.
                  « Reply #13 on: February 12, 2010, 07:56:18 PM »
                  Please run OTL.exe.
                  • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


                    :otl
                    O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
                    O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
                    O15 - HKCU\..Trusted Domains: jhmi.edu ([nightingale] http in Trusted sites)
                    O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
                    O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
                    O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.



                  • Return to OTL.exe, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.

                  • Click the red Run Fix button.
                  • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
                  • Close OTL.exe
                  If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
                  ~Dr Jay

                  csturgill

                    Topic Starter


                    Rookie

                    Re: "Application has been executed" problem.
                    « Reply #14 on: February 12, 2010, 08:10:15 PM »
                    Fix log:

                    ========== OTL ==========
                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\msn.com\ deleted successfully.
                    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ deleted successfully.
                    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\jhmi.edu\nightingale\ deleted successfully.
                    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ deleted successfully.
                    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
                    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\jhmi.edu\ deleted successfully.
                     
                    OTL by OldTimer - Version 3.1.28.0 log created on 02122010_220925