This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] lsass.exe virus with HijackThis log

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been having an issue with my laptop. My computer recently had the Digital Protection Virus, fake anti virus software that causes a lot of pop ups. I ran into some trouble removing it and had to reghost the computer. Now, I cannot start my computer normally. When I do, after the load up screen completes and my desktop appears, a blue screen appears with text and my computer immediately reboots. I have entered into Safe Mode and have run Ad-Aware SE Personal, Malewarebytes' Anti-Malware, and Trojan Remover 6.8.1. Each program recognizes and removes C:\lsass.exe. After I restart, I have the same problem with the blue screen and I go back into Safe Mode to run another scan, only to find C:\lsass.exe was not removed. I was able get into the mode "Last Known Good Configuration (your most recent settings that worked)" but there are still some issues. Here is my HijackThis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:43:22 PM, on 5/5/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hummingbird\Connectivity\9.00\Exceed\HumDisplayServer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
D:\DOCUME~1\CLASS2~1\LOCALS~1\Temp\uxq9by.exe
D:\DOCUME~1\CLASS2~1\LOCALS~1\Temp\bisqgwy.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\System32\svchost.exe
D:\DOCUME~1\CLASS2~1\LOCALS~1\Temp\uxq9by.exe
D:\Documents and Settings\Class2008\Desktop\HiJackThis.exe
c:\lsass.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.stevens.edu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: C:\WINDOWS\system32\ufajm4vsox.dll - {A2BA40A0-74F1-52BD-F411-00B15A2C8953} - C:\WINDOWS\system32\ufajm4vsox.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [5607] D:\DOCUME~1\CLASS2~1\LOCALS~1\Temp\bisqgwy.exe
O4 - HKLM\..\Policies\Explorer\Run: [50pfo] D:\DOCUME~1\CLASS2~1\LOCALS~1\Temp\uxq9by.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/01e187f7a53083…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1272988333568
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: kjsfi8sjefiuoshiefyhiusdhfdf - {A2BA40A0-74F1-52BD-F411-00B15A2C8953} - C:\WINDOWS\system32\ufajm4vsox.dll
O23 - Service: Hummingbird Exceed Display Management (HumDisplayServer) - Hummingbird Ltd. - C:\Program Files\Hummingbird\Connectivity\9.00\Exceed\HumDisplayServer.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 4795 bytes

I would greatly appreciate any feedback. Please let me know if more information is required. Thank you.
Hello rgilbert and welcome to WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.

I am looking through your log now and will reply as soon as possible.

Satchfan
Hello again rgilbert

You still have some pretty nasty infections on there.

I’d like you to run a couple of scans that will take a deeper look at what’s on your computer.


Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply


Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done, click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



Logs to include with next post:

DDS.txt
Attach.txt
Gmer.txt


Thanks

Satchfan
Satchfan, I greatly appreciate your help. I downloaded DDS.scr to my desktop from the link you provided. When I run the program, the command window opens and runs the program. Once it finishes, a new window opens saying "These 2 log files shall disappear when you close them. So, save them to your Desktop now …" However, the two log files never appear. I ran the program while in Safe Mode, and I am pretty sure that my Anti-Malware Scanners have been turned off. I had no problem running GMER. The GMER.txt file has been attached. If you have any suggestions for the DDS.scr program, I will gladly try anything. Thanks again for your help.

Attachments:

Hi rgilbert

We’ll try downloading and running another tool instead.


Run OTL

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    • netsvcs
      %SYSTEMDRIVE%\*.exe
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      ahcix86.sys
      KR10N.sys
      nvstor32.sys
      ahcix86s.sys
      nvrd32.sys
      symmpi.sys
      adp3132.sys
      /md5stop
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\System32\config\*.sav
      %systemroot%\system32\drivers\*.sys /90
      [CREATERESTOREPOINT]
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.

Logs to include:

OTL.Txt
Extras.Txt
Satchfan,

I ran OTL while in "Last Known Good Configuration (your most recent settings that worked)", but I ran GMER while in Safe Mode. Does this make a difference in your assessment?

Here are the results from OTL:
OTL.txt
OTL logfile created on: 5/10/2010 12:23:22 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = D:\Documents and Settings\Class2008\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 613.00 Mb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.17 Gb Total Space | 24.79 Gb Free Space | 63.30% Space Free | Partition Type: NTFS
Drive D: | 72.62 Gb Total Space | 71.01 Gb Free Space | 97.78% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D687
Current User Name: Class2008
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - D:\Documents and Settings\Class2008\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Documents and Settings\Class2008\Local Settings\Temp\bisqgwy.exe ()
PRC - D:\Documents and Settings\Class2008\Local Settings\Temp\uxq9by.exe ()
PRC - D:\Documents and Settings\Class2008\Local Settings\Temp\notepad.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\Hummingbird\Connectivity\9.00\Exceed\HumDisplayServer.exe (Hummingbird Ltd.)
PRC - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)


========== Modules (SafeList) ==========

MOD - D:\Documents and Settings\Class2008\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (McShield) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (McAfeeFramework) – C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (HumDisplayServer) – C:\Program Files\Hummingbird\Connectivity\9.00\Exceed\HumDisplayServer.exe (Hummingbird Ltd.)


========== Driver Services (SafeList) ==========

DRV - (euccu) – C:\WINDOWS\system32\drivers\euccu.sys ()
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (GTICARD) – C:\WINDOWS\system32\drivers\gticard.sys (Texas Instruments)
DRV - (DevUpper) – C:\WINDOWS\System32\DRIVERS\tiumflt.sys (Texas Instruments Inc.)
DRV - (gv3) – C:\WINDOWS\system32\drivers\gv3.sys (Microsoft Corporation)
DRV - (StreamDispatcher) – C:\WINDOWS\system32\drivers\strmdisp.sys (Conexant Systems)
DRV - (tiumfwl) – C:\WINDOWS\system32\drivers\tiumfwl.sys (Texas Instruments Inc.)
DRV - (PASCO) PASCO PASPORT USB Driver (PSSensor.sys) – C:\WINDOWS\system32\drivers\PSSensor.sys (PASCO scientific)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.stevens.edu
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/04 15:23:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/04 15:23:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/05/04 15:27:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2010/05/04 15:27:57 | 000,000,000 | —D | M] – D:\Documents and Settings\Class2008\Application Data\Mozilla\Extensions
[2010/05/04 15:27:57 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Class2008\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/05/04 15:23:51 | 000,000,000 | —D | M] – D:\Documents and Settings\Class2008\Application Data\Mozilla\Firefox\Profiles\1jj8j96z.default\extensions
[2010/05/04 15:23:33 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/05/10 12:22:42 | 000,000,713 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (C:\WINDOWS\system32\ufajm4vsox.dll) - {A2BA40A0-74F1-52BD-F411-00B15A2C8953} - C:\WINDOWS\system32\ufajm4vsox.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [21969] D:\Documents and Settings\Class2008\Local Settings\Temp\bisqgwy.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 50pfo = D:\DOCUME~1\CLASS2~1\LOCALS~1\Temp\uxq9by.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} http://software-dl.real.com/01e187f7a53083…ip/RdxIE601.cab (RdxIE Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1272988333568 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8152.3513194444 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_05)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-9902097169-9984355565-366679224-7864\hdav.exe) - C:\RECYCLER\S-1-5-21-9902097169-9984355565-366679224-7864\hdav.exe ()
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\RECYCLER\S-1-5-21-9902097169-9984355565-366679224-7864\hdav.exe) - C:\RECYCLER\S-1-5-21-9902097169-9984355565-366679224-7864\hdav.exe ()
O22 - SharedTaskScheduler: {A2BA40A0-74F1-52BD-F411-00B15A2C8953} - kjsfi8sjefiuoshiefyhiusdhfdf - C:\WINDOWS\system32\ufajm4vsox.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/06/11 13:09:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{0f9331b1-57b2-11df-8305-009096be2050}\Shell\AutoRun\command - "" = G:\MYFOLDER\myfile.exe – File not found
O33 - MountPoints2\{0f9331b1-57b2-11df-8305-009096be2050}\Shell\open\command - "" = G:\MYFOLDER\myfile.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: AppSecDll - (C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Windows Server\akwqyi.dll) - C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Windows Server\akwqyi.dll ()
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/06/11 13:09:05 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: Ip6FwHlp - File not found
Unable to start service SrService!

========== Files/Folders - Created Within 90 Days ==========

[2010/05/10 12:21:22 | 000,570,880 | —- | C] (OldTimer Tools) – D:\Documents and Settings\Class2008\Desktop\OTL.exe
[2010/05/07 06:27:41 | 000,000,000 | —D | C] – D:\Documents and Settings\NetworkService\Local Settings\Application Data\Windows Server
[2010/05/06 11:15:04 | 000,000,000 | —D | C] – D:\Documents and Settings\LocalService\Local Settings\Application Data\Windows Server
[2010/05/06 10:05:49 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\Application Data\GetRightToGo
[2010/05/05 10:28:56 | 000,388,608 | —- | C] (Trend Micro Inc.) – D:\Documents and Settings\Class2008\Desktop\HiJackThis.exe
[2010/05/05 07:10:59 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\My Documents\Simply Super Software
[2010/05/05 07:10:17 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\Application Data\Simply Super Software
[2010/05/05 07:10:17 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Simply Super Software
[2010/05/05 07:06:21 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\Application Data\WinRAR
[2010/05/04 23:44:37 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2010/05/04 16:00:23 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/05/04 15:35:16 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\Application Data\Malwarebytes
[2010/05/04 15:35:11 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/04 15:27:38 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\Local Settings\Application Data\Thunderbird
[2010/05/04 15:27:38 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\Application Data\Thunderbird
[2010/05/04 15:27:16 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\Local Settings\Application Data\Windows Server
[2010/05/04 15:27:04 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Thunderbird
[2010/05/04 15:26:29 | 000,000,000 | -HSD | C] – D:\Documents and Settings\Class2008\PrivacIE
[2010/05/04 15:26:03 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\Local Settings\Application Data\rochchlvm
[2010/05/04 15:25:40 | 000,182,784 | —- | C] (Macromedia, Inc.) – C:\WINDOWS\System32\regedit.exe
[2010/05/04 15:24:11 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\My Documents\Downloads
[2010/05/04 15:23:42 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\Local Settings\Application Data\Mozilla
[2010/05/04 15:23:31 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/05/04 15:19:56 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/05/04 15:16:47 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/05/04 13:04:30 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood.Tmp
[2010/05/04 12:59:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2010/05/04 12:59:15 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2010/05/04 12:59:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2010/05/04 12:53:03 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2010/05/04 12:33:55 | 000,000,000 | -HSD | C] – D:\Documents and Settings\Class2008\IECompatCache
[2010/05/04 12:30:43 | 000,000,000 | -HSD | C] – D:\Documents and Settings\Class2008\IETldCache
[2010/05/04 12:18:25 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2010/05/04 12:18:09 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2010/05/04 12:16:54 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/05/04 12:16:54 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2010/05/04 12:06:03 | 000,033,664 | —- | C] (CACE Technologies) – C:\WINDOWS\System32\drivers\BCMWLNPF.SYS
[2010/05/04 12:06:01 | 000,069,632 | —- | C] (CACE Technologies) – C:\WINDOWS\System32\bcmwlpkt.dll
[2010/05/04 12:05:59 | 002,129,920 | —- | C] (BCGSoft Ltd) – C:\WINDOWS\System32\WLBCGCBPRO731.DLL
[2010/05/04 11:54:34 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Sun
[2010/05/04 11:52:24 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Real
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/05/10 12:22:18 | 000,446,012 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/10 12:22:18 | 000,385,266 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/05/10 12:22:18 | 000,054,930 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/05/10 12:21:16 | 000,570,880 | —- | M] (OldTimer Tools) – D:\Documents and Settings\Class2008\Desktop\OTL.exe
[2010/05/10 12:18:22 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/10 12:18:20 | 000,091,159 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2010/05/10 12:17:09 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/10 12:17:08 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/09 18:47:28 | 003,670,016 | -H– | M] () – D:\Documents and Settings\Class2008\NTUSER.DAT
[2010/05/09 18:47:28 | 000,000,278 | -HS- | M] () – D:\Documents and Settings\Class2008\ntuser.ini
[2010/05/09 03:46:39 | 004,208,656 | -H– | M] () – D:\Documents and Settings\Class2008\Local Settings\Application Data\IconCache.db
[2010/05/09 03:44:46 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/05/09 03:27:29 | 000,069,632 | —- | M] () – D:\Documents and Settings\Class2008\Desktop\CoD Titles.xls
[2010/05/08 15:20:44 | 000,284,915 | —- | M] () – D:\Documents and Settings\Class2008\Desktop\gmer.zip
[2010/05/08 15:13:34 | 000,525,824 | —- | M] () – D:\Documents and Settings\Class2008\Desktop\dds.scr
[2010/05/08 15:02:38 | 000,017,112 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/05/08 03:58:14 | 000,091,159 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2010/05/07 11:55:43 | 000,000,183 | —- | M] () – C:\WINDOWS\hpbafd.ini
[2010/05/07 07:01:10 | 000,048,128 | —- | M] () – D:\Documents and Settings\Class2008\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/06 16:51:55 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/05/06 11:03:28 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/05/06 10:25:53 | 005,729,360 | —- | M] () – D:\Documents and Settings\Class2008\Desktop\Challenge_list.rar
[2010/05/05 12:15:12 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/05/05 10:29:47 | 000,026,112 | —- | M] () – C:\lsass.exe
[2010/05/05 10:28:52 | 000,388,608 | —- | M] (Trend Micro Inc.) – D:\Documents and Settings\Class2008\Desktop\HiJackThis.exe
[2010/05/05 10:03:56 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/05/05 09:57:27 | 000,000,076 | —- | M] () – D:\Documents and Settings\Class2008\default.pls
[2010/05/05 07:11:33 | 000,823,808 | —- | M] () – C:\WINDOWS\System32\drivers\euccu.sys
[2010/05/05 06:58:59 | 000,247,104 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/04 23:46:40 | 000,061,328 | —- | M] () – D:\Documents and Settings\Class2008\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/05/04 18:47:37 | 000,000,747 | —- | M] () – D:\Documents and Settings\All Users\Desktop\STELLA 9.0.2 30-Day Workshop.lnk
[2010/05/04 18:44:50 | 000,001,321 | —- | M] () – D:\Documents and Settings\Class2008\Desktop\Local Users and Groups.lnk
[2010/05/04 15:28:06 | 000,030,000 | —- | M] () – C:\WINDOWS\System32\ltdn4poi.dll
[2010/05/04 15:28:03 | 000,026,624 | —- | M] () – D:\Documents and Settings\Class2008\reader_s.exe
[2010/05/04 15:27:45 | 000,000,001 | —- | M] () – D:\Documents and Settings\Class2008\oashdihasidhasuidhiasdhiashdiuasdhasd
[2010/05/04 15:27:13 | 000,001,550 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Mozilla Thunderbird.lnk
[2010/05/04 15:26:36 | 000,187,392 | —- | M] () – C:\WINDOWS\System32\cooper.mine
[2010/05/04 15:25:39 | 000,182,784 | —- | M] (Macromedia, Inc.) – C:\WINDOWS\System32\regedit.exe
[2010/05/04 15:25:33 | 000,030,000 | —- | M] () – C:\WINDOWS\System32\ufajm4vsox.dll
[2010/05/04 15:23:35 | 000,001,500 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/05/04 15:19:10 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010/05/04 12:52:32 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/05/03 11:40:22 | 013,103,902 | —- | M] () – D:\Documents and Settings\Class2008\Desktop\TrojanRemover.681.2594.rar
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/08 16:30:53 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/05/08 15:23:25 | 000,293,376 | —- | C] () – D:\Documents and Settings\Class2008\Desktop\gmer.exe
[2010/05/08 15:20:55 | 000,284,915 | —- | C] () – D:\Documents and Settings\Class2008\Desktop\gmer.zip
[2010/05/08 15:13:43 | 000,525,824 | —- | C] () – D:\Documents and Settings\Class2008\Desktop\dds.scr
[2010/05/06 10:25:14 | 005,729,360 | —- | C] () – D:\Documents and Settings\Class2008\Desktop\Challenge_list.rar
[2010/05/06 10:12:17 | 000,069,632 | —- | C] () – D:\Documents and Settings\Class2008\Desktop\CoD Titles.xls
[2010/05/05 10:03:56 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/05/05 10:03:56 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/05/05 09:49:36 | 000,026,112 | —- | C] () – C:\lsass.exe
[2010/05/05 07:10:18 | 000,162,304 | —- | C] () – C:\WINDOWS\System32\ztvunrar36.dll
[2010/05/05 07:10:18 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNRAR3.dll
[2010/05/05 07:10:18 | 000,077,312 | —- | C] () – C:\WINDOWS\System32\ztvunace26.dll
[2010/05/05 07:10:18 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll
[2010/05/05 07:07:14 | 000,112,383 | —- | C] () – D:\Documents and Settings\Class2008\Desktop\Spyware Doctor 5.0.0.179.rar
[2010/05/05 07:06:55 | 013,103,902 | —- | C] () – D:\Documents and Settings\Class2008\Desktop\TrojanRemover.681.2594.rar
[2010/05/04 18:47:37 | 000,000,747 | —- | C] () – D:\Documents and Settings\All Users\Desktop\STELLA 9.0.2 30-Day Workshop.lnk
[2010/05/04 16:11:59 | 000,000,076 | —- | C] () – D:\Documents and Settings\Class2008\default.pls
[2010/05/04 15:55:38 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/05/04 15:55:37 | 000,048,128 | —- | C] () – D:\Documents and Settings\Class2008\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/04 15:28:06 | 000,030,000 | —- | C] () – C:\WINDOWS\System32\ltdn4poi.dll
[2010/05/04 15:27:45 | 000,000,001 | —- | C] () – D:\Documents and Settings\Class2008\oashdihasidhasuidhiasdhiashdiuasdhasd
[2010/05/04 15:27:13 | 000,001,550 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Mozilla Thunderbird.lnk
[2010/05/04 15:26:59 | 000,187,392 | —- | C] () – C:\WINDOWS\System32\cooper.mine
[2010/05/04 15:26:55 | 000,823,808 | —- | C] () – C:\WINDOWS\System32\drivers\euccu.sys
[2010/05/04 15:25:43 | 000,026,624 | —- | C] () – D:\Documents and Settings\Class2008\reader_s.exe
[2010/05/04 15:25:33 | 000,030,000 | —- | C] () – C:\WINDOWS\System32\ufajm4vsox.dll
[2010/05/04 15:23:35 | 000,001,500 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/05/04 12:06:01 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2010/05/04 12:05:59 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2009/04/01 10:30:44 | 000,000,280 | —- | C] () – C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2004/08/04 15:43:43 | 000,000,045 | —- | C] () – C:\WINDOWS\EPSONC64.ini
[2004/07/15 13:47:27 | 000,639,052 | —- | C] () – C:\WINDOWS\System32\BBPDFPortMon.dll
[2004/07/01 16:02:19 | 000,000,192 | —- | C] () – C:\WINDOWS\winamp.ini
[2004/06/30 15:04:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\SDelete.dll
[2004/06/25 15:15:33 | 000,000,043 | —- | C] () – C:\WINDOWS\gswin32.ini
[2004/06/22 15:59:13 | 000,000,156 | —- | C] () – C:\WINDOWS\matlab.ini
[2004/06/22 11:29:41 | 000,000,183 | —- | C] () – C:\WINDOWS\hpbafd.ini
[2004/06/17 09:54:48 | 000,000,520 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/06/14 09:59:18 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/03/07 13:51:00 | 000,024,924 | —- | C] () – C:\WINDOWS\System32\openports.dll
[2004/01/30 15:36:19 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2003/12/08 23:08:20 | 002,539,520 | —- | C] () – C:\WINDOWS\System32\Bbgspdf.dll
[2003/12/02 12:39:08 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\InstallPrinter.dll
[2003/01/30 05:04:00 | 000,618,496 | —- | C] () – C:\WINDOWS\System32\stlpmt45.dll
[2001/07/31 03:17:12 | 000,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL

========== LOP Check ==========

[2004/07/15 13:46:34 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Bluebeam Software
[2004/07/06 12:17:10 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Hummingbird
[2005/10/05 11:27:57 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Network Associates
[2010/05/05 07:10:17 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Simply Super Software
[2004/07/07 14:38:12 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/05/06 10:07:38 | 000,000,000 | —D | M] – D:\Documents and Settings\Class2008\Application Data\GetRightToGo
[2004/07/06 12:19:56 | 000,000,000 | —D | M] – D:\Documents and Settings\Class2008\Application Data\Hummingbird
[2004/06/22 14:22:38 | 000,000,000 | —D | M] – D:\Documents and Settings\Class2008\Application Data\InterVideo
[2010/05/05 07:10:17 | 000,000,000 | —D | M] – D:\Documents and Settings\Class2008\Application Data\Simply Super Software
[2004/06/22 14:15:03 | 000,000,000 | —D | M] – D:\Documents and Settings\Class2008\Application Data\TextPad
[2010/05/04 15:27:45 | 000,000,000 | —D | M] – D:\Documents and Settings\Class2008\Application Data\Thunderbird

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2010/05/05 10:29:47 | 000,026,112 | —- | M] () – C:\lsass.exe


< MD5 for: AGP440.SYS >
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/05/04 12:42:18 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010/05/04 12:42:18 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2010/05/04 12:42:18 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2001/08/17 13:58:00 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2002/08/29 03:50:10 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/05/04 12:42:18 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2002/08/29 03:50:10 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp1.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010/05/04 12:42:18 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2010/05/04 12:42:18 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\sp3.cab:atapi.sys
[2002/08/29 01:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[1999/10/02 10:24:46 | 000,017,408 | —- | M] () MD5=1363337A5301619F00F8033835EF30E9 – C:\MATLAB7\sys\perl\win32\site\lib\auto\Win32\EventLog\EventLog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 00:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\SoftwareDistribution\Download\78cf8552430e25a8f24bc1e4dfb1970e\sp2qfe\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\SoftwareDistribution\Download\de81b460c3abcfc5b8494c785a5f3944\sp2qfe\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 20:12:00 | 001,384,479 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\msvbvm60.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2004/06/11 09:00:31 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/06/11 09:00:31 | 000,630,784 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/06/11 09:00:31 | 000,405,504 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/05/05 07:11:33 | 000,823,808 | —- | M] () – C:\WINDOWS\system32\drivers\euccu.sys
[2010/02/24 09:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2010/05/04 15:28:05 | 000,182,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\ndis.sys
[2010/02/11 08:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\tcpip6.sys
< End of report >

Extra.txt
OTL Extras logfile created on: 5/10/2010 12:23:22 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = D:\Documents and Settings\Class2008\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 613.00 Mb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.17 Gb Total Space | 24.79 Gb Free Space | 63.30% Space Free | Partition Type: NTFS
Drive D: | 72.62 Gb Total Space | 71.01 Gb Free Space | 97.78% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D687
Current User Name: Class2008
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.reg [@ = regfile] – C:\WINDOWS\System32\regedit.exe (Macromedia, Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [open] – regedit.exe "%1" (Macromedia, Inc.)
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Network Associates\Common Framework\FrameworkService.exe" = C:\Program Files\Network Associates\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service – (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1676AD48-7350-46B9-A48B-9586BC1BFADB}" = Hummingbird Exceed 3D V9.0
"{17B66E83-1BC9-11D5-A54A-0090278A1BB8}" = Microsoft FrontPage Client - English
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{20610409-CA18-41A6-9E21-A93AE82EE7C5}" = Visual Studio .NET Professional 2003 - English
"{252F9FB9-FC12-4B08-ADEB-F402BA3A8D28}" = CardBus
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2AC619CD-AB80-4607-AC27-9F53E2AD46BF}" = Hummingbird Exceed V9.0
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35A3A4F4-B792-11D6-A78A-00B0D0142040}" = Java 2 SDK, SE v1.4.2_04
"{35C03C04-3F1F-42C2-A989-A757EE691F65}" = McAfee VirusScan Enterprise
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Dell Modem-On-Hold
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{53CBBD51-88E8-44AD-9F3F-D072743E835E}" = DataStudio
"{5757AE1A-1DB4-4898-9806-09F77FBD5E57}" = MSDN Library for Visual Studio .NET 2003
"{588F9A05-FC5B-4C1A-9B49-FE2252A43B0B}" = SolidWorks 2004 SP03.1
"{621186F1-520B-4DE5-8807-560194C186AC}" = COSMOSFloWorks 2004 SP2.0
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{7148F0A8-6813-11D6-A77B-00B0D0142050}" = Java 2 Runtime Environment, SE v1.4.2_05
"{7959721D-8268-4565-9E0E-C41A9F4848A9}" = SigmaTel AC97 Audio Drivers
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8124E207-3F38-4E7D-8579-28E2A7C31267}" = Scientific Notebook 5.0
"{83F7144B-CE67-483B-BB16-AE66902439E4}" = eDrawings 2004 SP03
"{8BB0BF49-2841-4E5C-9BA4-85A0266655AB}" = COSMOSMotion 2004 SP2.1
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{903B0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Project Professional 2003
"{90510409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio Professional 2003
"{9431A631-BFCC-488F-AD74-364A943D4529}" = Microsoft WSE 1.0
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A624D696-47B5-4898-AB9A-7B7E41BC9830}" = COSMOSWorks 2004 SP3.1
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{B510A987-487E-4C66-9F4F-D386AC275715}" = TextPad 4.7
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Gigabit Integrated Controller
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D4D24FE5-FAB3-4FE2-AFFC-623955F4DF3A}" = Visual Studio.NET Baseline - English
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{F6651F06-EE33-406E-BAC3-A7E567FA7609}" = STELLA 9.0.2 30-Day Workshop
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"265ee61839e741e0a2fedd697c40b6c6" = NetBeans IDE 3.6
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AFPL Ghostscript 8.14" = AFPL Ghostscript 8.14
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CNXT_MODEM_PCI_VEN_8086&DEV_24x6&SUBSYS_542214F1" = Conexant D480 MDC V.92 Modem
"EPSON Printer and Utilities" = EPSON Printer Software
"GSview 4.6" = GSview 4.6
"ie8" = Windows Internet Explorer 8
"InstallShield_{252F9FB9-FC12-4B08-ADEB-F402BA3A8D28}" = PCI 7510 CardBus Controller with SmartCard and Software
"InstallShield_{53CBBD51-88E8-44AD-9F3F-D072743E835E}" = DataStudio
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Gigabit Integrated Controller
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"MatlabR14" = MATLAB Family of Products Release 14
"McAfee Anti-Spyware Enterprise Module" = McAfee AntiSpyware Enterprise Module
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Mozilla Thunderbird (3.0.4)" = Mozilla Thunderbird (3.0.4)
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NeroVision!UninstallKey" = NeroVision Express 2
"NMIX!UninstallKey" = NeroMIX
"NVIDIA Display Driver" = NVIDIA Display Driver
"NVIDIA Drivers" = NVIDIA Drivers
"PHAROS" = PHAROS for Higher Education
"QuickTime" = QuickTime
"Tweak UI 2.10" = Tweak UI
"ViewpointMediaPlayer" = Viewpoint Media Player
"Visual Studio .NET Professional 2003 - English" = Microsoft Visual Studio .NET Professional 2003 - English
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"winscp3_is1" = WinSCP 3.6.1

========== Last 10 Event Log Errors ==========

[ System Events ]
Error - 5/9/2010 11:06:36 AM | Computer Name = D687 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 5/9/2010 11:07:20 AM | Computer Name = D687 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm

Error - 5/9/2010 2:22:58 PM | Computer Name = D687 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 5/9/2010 5:35:39 PM | Computer Name = D687 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 5/9/2010 5:36:44 PM | Computer Name = D687 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm

Error - 5/9/2010 6:47:28 PM | Computer Name = D687 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 5/10/2010 12:17:51 PM | Computer Name = D687 | Source = System Error | ID = 1003
Description = Error code 000000f4, parameter1 00000003, parameter2 875b81c0, parameter3
875b8334, parameter4 805fb146.

Error - 5/10/2010 12:18:50 PM | Computer Name = D687 | Source = Service Control Manager | ID = 7000
Description = The PASCO PASPORT USB Driver (PSSensor.sys) service failed to start
due to the following error: %%1058

Error - 5/10/2010 12:18:56 PM | Computer Name = D687 | Source = System Error | ID = 1003
Description = Error code 00000024, parameter1 001902fe, parameter2 f78de94c, parameter3
f78de648, parameter4 f5abd1f2.

Error - 5/10/2010 12:23:34 PM | Computer Name = D687 | Source = SRService | ID = 104
Description = The System Restore initialization process failed.


< End of report >

Once again, thank you for your help.
rgilbert

You have some bad infections on your computer. To find out how serious these infections are, I’d like you to send some of Windows’ core files for closer inspection.

NOTE: - use Internet Explorer for this• Please go to Virscan
• Copy and paste the following file path, one at a time, into the Suspicious files to scan box on the top of the page
• make sure the scan is complete and the results saved before submitting the next one.

D:\Documents and Settings\Class2008\reader_s.exe
c:\windows\system32\userinit.exe
c:\windows\system32\svchost.exe
c:\windows\explorer.exe
c:\windows\system32\ctfmon.exe
c:\windows\system32\spoolsv.exe

• Click on the Upload button
• If a pop-up appears saying the file has been scanned already, please select the ReScan button.
• Once the Scan is completed, click on the Copy to Clipboard button. This will copy the link of the report into the Clipboard.
Paste the contents of the Clipboard in your next reply.

Satchfan
Hi rgilbert.

As you can’t find Reader_s.exe, please go back to Virscan and submit the file by copying it and pasting it:

D:\Documents and Settings\Class2008\reader_s.exe

Do the same for this file:

C:\WINDOWS\System32\regedit.exe


Download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :dir
    D:\Documents and Settings\LocalService\Local Settings\Application Data\Windows Server
    :filefind
    *regedit*

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - D:\Documents and Settings\Class2008\Local Settings\Temp\bisqgwy.exe 
    PRC - D:\Documents and Settings\Class2008\Local Settings\Temp\uxq9by.exe ()
    PRC - D:\Documents and Settings\Class2008\Local Settings\Temp\notepad.exe ()
    DRV - (euccu) – C:\WINDOWS\system32\drivers\euccu.sys ()
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
    O2 - BHO: (C:\WINDOWS\system32\ufajm4vsox.dll) - {A2BA40A0-74F1-52BD-F411-00B15A2C8953} - C:\WINDOWS\system32\ufajm4vsox.dll ()
    O4 - HKLM..\Run: [21969] D:\Documents and Settings\Class2008\Local Settings\Temp\bisqgwy.exe ()
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 50pfo = D:\DOCUME~1\CLASS2~1\LOCALS~1\Temp\uxq9by.exe ()
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
    O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-9902097169-9984355565-366679224-7864\hdav.exe) - C:\RECYCLER\S-1-5-21-9902097169-9984355565-366679224-7864\hdav.exe ()
    O22 - SharedTaskScheduler: {A2BA40A0-74F1-52BD-F411-00B15A2C8953} - kjsfi8sjefiuoshiefyhiusdhfdf - C:\WINDOWS\system32\ufajm4vsox.dll ()
    O33 - MountPoints2\{0f9331b1-57b2-11df-8305-009096be2050}\Shell\AutoRun\command - "" = G:\MYFOLDER\myfile.exe – File not found
    O33 - MountPoints2\{0f9331b1-57b2-11df-8305-009096be2050}\Shell\open\command - "" = G:\MYFOLDER\myfile.exe – File not found
    O36 - AppCertDlls: AppSecDll - (C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Windows Server\akwqyi.dll) - C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Windows Server\akwqyi.dll ()
    [2010/05/04 15:26:03 | 000,000,000 | —D | C] – D:\Documents and Settings\Class2008\Local Settings\Application Data\rochchlvm
    [2010/05/05 10:29:47 | 000,026,112 | —- | M] () – C:\lsass.exe
    [2010/05/05 07:11:33 | 000,823,808 | —- | M] () – C:\WINDOWS\System32\drivers\euccu.sys
    [2010/05/04 15:28:06 | 000,030,000 | —- | M] () – C:\WINDOWS\System32\ltdn4poi.dll
    [2010/05/04 15:28:03 | 000,026,624 | —- | M] () – D:\Documents and Settings\Class2008\reader_s.exe
    [2010/05/04 15:27:45 | 000,000,001 | —- | M] () – D:\Documents and Settings\Class2008\oashdihasidhasuidhiasdhiashdiuasdhasd
    [2010/05/04 15:26:36 | 000,187,392 | —- | M] () – C:\WINDOWS\System32\cooper.mine
    [2010/05/04 15:25:39 | 000,182,784 | —- | M] (Macromedia, Inc.) – C:\WINDOWS\System32\regedit.exe
    [2010/05/04 15:25:33 | 000,030,000 | —- | M] () – C:\WINDOWS\System32\ufajm4vsox.dll
    
    :Files
    D:\Documents and Settings\Class2008\Local Settings\Temp\bisqgwy.exe
    D:\Documents and Settings\Class2008\Local Settings\Temp\uxq9by.exe
    D:\Documents and Settings\Class2008\Local Settings\Temp\notepad.exe
    
    :Commands
    [purity]
    [emptytemp]
    [resethosts]
    [start explorer]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Restore your Proxy settings

In Internet Explorer: Tools, -> Internet Options -> Connections Tab ->Lan Settings > uncheck use a proxy server and check to Automatically detect settings.

In Firefox in Tools Menu -> Options… -> Advanced Tab -> Network Tab -> Settings under Connection, make sure No proxy is checked.


To include in next post:

virscan results
SystemLook.txt
OTL.txt


Thanks

Satchfan
Satchfan, I had a few problems with your last instructions. I was able to scan regedit.exe but I still could not scan reader_s.exe. Here is what I did: I went to Virscan and clicked on the "Browse…" button. A window opened to “Choose File to Upload”. In the “File name:” field, I copied and pasted “D:\Documents and Settings\Class2008\reader_s.exe” and clicked on “Open”. Another window opened stating “D:\Documents and Settings\Class2008\reader_s.exe File not found. Please verify the correct file name was given.” I had no problem using this method for “C:\WINDOWS\System32\regedit.exe”. The log from the regedit.exe file is attached. When I ran SystemLook, the following window appeared: “The application or DLL C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Windows Server\akwqyi.dll is not a valid Windows image. Please check this against your installation diskette.” I clicked on the "OK" button and the program proceeded to run. The log is attached. I could not run OTL. I let OTL run 3 separate times, each for multiple hours and it seemed that the program would keep freezing up. I would check Task Manager and every time it said "Not Responding" for OTL. I even tried to run OTL in Safe Mode, but there was no success. It seemed that OTL could not get passed PRC - D:\Documents and Settings\Class2008\Local Settings\Temp\bisqgwy.exe I restored my proxy settings as you indicated. -rgilbert
Hi rgilbert

Rogue programs like Digital Protection can sometimes affect the execution of legitimate programs which may be why you are having problems running OTL.
Please download exeHelper by Raktor to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up; press any key to close it once the fix is completed.
Post the contents of exehelperlog.txt, (it will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
After running this, please try to follow the previous instructions to run OTL and let me know what happens.

Satchfan
Hello rgilbert It has been several days since I sent my last post with instructions to help with your computer problem.. Please let me know if you are having problems and still require help. Thanks Satchfan
I'm sorry that I have not yet responded. I've been having a few issues with your last instructions. I will post the logs and a more detailed description of what has occurred. Thank you.
rgilbert Are you still with me? If you are still having problems with the instructions, please let me know otherwise I shall assume that you no longer want help and this will be closed in 24 hours. Regards Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI