This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect - Baseline

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello!

My computer was infected with the following:

Trojan.Mebroot
JS.Skyipot
Bloodhound.Exploit.289
Trojan.Malscript!html

After installing Norton Internet Security, it found and quarantined these issues and told me no further action was needed. However, the following is still occurring…

Google Redirect
Most times I do a google search, when I try and click on links on the Google results pages, I get sent to ad sites that are hijacking my links.
These are some of the sites I get redirected to…

Adwords.secureonline
7search.com
Ave99.com

SUPER annoying.

I also ran Spybot, it found nothing. Further scans with Norton also reveal nothing. But while Nortong doesn't turn up anything else, it routinely logs “Unauthorized access logged (Access Thread Data)”. Not sure what these are, except they look like programs are trying to access things they shouldn’t? Here are some examples:

Actor: Winword.exe
Actor PID: 4684
Target: C:\Program Files\Common Files\Symantic Shared\ccSetMgr.exe
Target PID: 1584
Action: Access Thread Data
Reaction: Unauthorized access logged

This happens numerous times, with always the same target (the symantic file, which I assume is my Norton), but the actor is always changing:
Actor: Outlook.exe
Actor: Notepad.exe
Actor: Realupgrade.exe
Actor: IExplorer.exe

The recommended action from Norton? “No Action Required”. That’s funny. You mean that all these programs of mine are just trying to access my data, but I don’t need to do anything? Feel like someone is shooting BB’s through my living room window, and my security system is saying, “Hey, someone is shooting BBs through your living room, and it’s your neighbors, but don’t worry about anything. Gotcha covered.” Hmm. Perhaps there’s a bad guy over at my neighbor’s house and really want to do something other than just sit here…

So below is my HiJack This Log. Any help is greatly appreciated! The log is also attached. Thanks for looking!

Nathan

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:03:30 PM, on 5/13/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\VMware\VMware Player\hqtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
D:\My Downloads\HiJack This 2.0.4\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\coIEPlg.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; OfficeLiveConnector.1.4; OfficeLivePatch.1.3)" -"http://www.escapegames.com/playgame/561/hostel-part-2-the-killing-floor.html"
O4 - Startup: Picaboo.lnk = C:\Program Files\Picaboo\Picaboo\PicabooMain.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware player\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware player\vsocklib.dll
O15 - Trusted Zone: http://*.lcgcm13web
O15 - Trusted Zone: http://p6.lcgpence.com
O15 - Trusted Zone: stconference.oracle.com
O15 - Trusted IP range: http://173.11.21.30
O16 - DPF: {00191E4B-49C2-48E2-A548-8F702D75622A} - https://strtc.oracle.com/imtapp/res/jar/cnsload.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1257165895140
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1257165992890
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://ldmattson.webex.com/client/T27L/webex/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/da2/PCPitStop2.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Contract Manager - Alexandria Software Consulting - C:\CM11\jboss\bin\ExpService.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe

–
End of file - 13563 bytes
Hello NathanH and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hi JonTom, Thanks for your help! I appreciate it. This morning, my Norton Anti Virus found this… adgredy.class contained threat Trojan Horse It had attached itself to my Java (I'm running a version of Java 6_14). Yes, this is a WAY outdated java, but I run a particular set of business applicatations that are all built around a specific Java platform. These business applications are all related to Primavera, a project management software tool for the constrution industry. So I realize that your solution may be to strip out all this Java, but after the clean, I will need to reinstall this version of Java. Thanks again for the help. Nathan
Hello NathanH

Thank you for the log.

I run a particular set of business applicatations


Is this a company machine?

I would like to take a closer look at your system with some additional scans. Please work your way through the following steps. If you encounter any difficulties come back and let me know.


Did you run HJT from a flash drive (USB storage device)?

If the answer is yes:


  • Please download Flash Disinfector


    • Click here to download Flash Disinfector and save the file (called Flash_Disinfector.exe) to your desktop.
    • Double click on the Flash_Disinfector.exe icon to run the program and follow any prompts that may appear.
    • The program may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so if prompted.
    • Wait until Flash disinfector has finished scanning and then exit the program.
    • Reboot your computer.

  • Download and run OTL by Oldtimer


    • Please download OTL by Oldtimer by clicking here and save the file (called OTL.exe) to your desktop.
    • Close all open windows on your computer then Double click on the OTL.exe icon to run the program.
    • When OTL opens, underneath "Output" (at the top) select "Minimal Output".
    • Check the boxes beside "LOP Check" and "Purity Check".
    • Under Custom Scan paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT


    • Click the "Run Scan" button. Do not change any settings unless specifically told to do so. The scan will not take long.

    • When the scan completes, it will open two notepad windows: OTL.Txt and Extras.Txt.
    • Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please Copy and Paste the contents of both files in your next reply. You may need two posts to fit them both in.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please provide the OTL logs and the GMER log in your next reply.
This is my machine, not a company's machine (I'm an independant consultant). I did NOT run Hijack This from a flash drive. However, I use flash drives all the time. Can I have your permission to run the Flash Disinfector on all my flash drives (i've got quite a few of them…). will add logs shortly.
OTL.TXT
OTL logfile created on: 5/14/2010 10:49:19 AM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\Nathan\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 250.93 Gb Free Space | 84.18% Space Free | Partition Type: NTFS
Drive D: | 298.08 Gb Total Space | 218.05 Gb Free Space | 73.15% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 232.83 Gb Total Space | 62.51 Gb Free Space | 26.85% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
Drive I: | 698.64 Gb Total Space | 356.21 Gb Free Space | 50.99% Space Free | Partition Type: NTFS

Computer Name: NHHPLPTP
Current User Name: Nathan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Nathan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\iTunes\iTunes.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
PRC - C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware Player\hqtray.exe (VMware, Inc.)
PRC - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.)
PRC - C:\Program Files\TechSmith\Snagit 9\TscHelp.exe (TechSmith Corporation)
PRC - C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe (TechSmith Corporation)
PRC - C:\Program Files\TechSmith\Snagit 9\SnagitEditor.exe (TechSmith Corporation)
PRC - C:\Program Files\TechSmith\Snagit 9\Snagit32.exe (TechSmith Corporation)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Norton Ghost\Agent\VProSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Ghost\Agent\GhostTray.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\gearsec.exe (GEAR Software)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Nathan\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\asoehook.dll (Symantec Corporation)
MOD - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\microsoft.vc90.crt\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\microsoft.vc90.crt\msvcp90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (VMware NAT Service) – C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
SRV - (VMAuthdService) – C:\Program Files\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
SRV - (VMnetDHCP) – C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMUSBArbService) – C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.)
SRV - (ufad-ws60) – C:\Program Files\VMware\VMware Player\vmware-ufad.exe (VMware, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (MSSQL$PRIMAVERA) SQL Server (PRIMAVERA) – C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (SQLWriter) – C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) – C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) – C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (Contract Manager) – C:\CM11\jboss\bin\ExpService.exe (Alexandria Software Consulting)
SRV - (Norton Ghost) – C:\Program Files\Norton Ghost\Agent\VProSvc.exe (Symantec Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100513.041\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100513.041\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100429.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NIS\1106000.020\Ironx86.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\NIS\1106000.020\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NIS\1106000.020\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\NIS\1106000.020\ccHPx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\NIS\1106000.020\SYMTDI.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NIS\1106000.020\SYMEFA.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100505.001\IDSXpx86.sys (Symantec Corporation)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (VMnetBridge) – C:\WINDOWS\system32\drivers\vmnetbridge.sys (VMware, Inc.)
DRV - (vmx86) – C:\WINDOWS\system32\drivers\vmx86.sys (VMware, Inc.)
DRV - (vmci) – C:\WINDOWS\system32\drivers\vmci.sys (VMware, Inc.)
DRV - (vmkbd) – C:\WINDOWS\system32\drivers\VMkbd.sys (VMware, Inc.)
DRV - (VMnetuserif) – C:\WINDOWS\system32\drivers\vmnetuserif.sys (VMware, Inc.)
DRV - (hcmon) – C:\WINDOWS\system32\drivers\hcmon.sys (VMware, Inc.)
DRV - (VMnetAdapter) – C:\WINDOWS\system32\drivers\vmnetadapter.sys (VMware, Inc.)
DRV - (vstor2-ws60) – C:\Program Files\VMware\VMware Player\vstor2-ws60.sys (VMware, Inc.)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NIS\1106000.020\SYMDS.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (adfs) – C:\WINDOWS\system32\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (dsload) – C:\WINDOWS\system32\drivers\dsload.sys (Oracle Corp.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (SymSnap) – C:\WINDOWS\system32\drivers\SymSnap.sys (StorageCraft)
DRV - (V2IMount) – C:\WINDOWS\system32\drivers\V2iMount.sys (Symantec Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWATI) – C:\WINDOWS\system32\drivers\HSFHWATI.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (CAMCHALA) – C:\WINDOWS\system32\drivers\camc6hal.sys (Conexant Systems Inc.)
DRV - (CAMCAUD) – C:\WINDOWS\system32\drivers\camc6aud.sys (Conexant Systems Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/08 11:45:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\ [2010/04/29 13:45:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\ [2010/04/29 13:42:06 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/05/13 13:18:09 | 000,395,194 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13648 more lines…
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.6.0.32\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Norton Ghost 10.0] C:\Program Files\Norton Ghost\Agent\GhostTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files\VMware\VMware Player\hqtray.exe (VMware, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla\4.0 ( File not found
O4 - Startup: C:\Documents and Settings\Nathan\Start Menu\Programs\Startup\Picaboo.lnk = C:\Program Files\Picaboo\Picaboo\PicabooMain.exe (Picaboo)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_14.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O15 - HKCU\..Trusted Domains: lcgcm13web ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: lcgpence.com ([p6] http in Trusted sites)
O15 - HKCU\..Trusted Domains: oracle.com ([stconference] * in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Trusted sites)
O16 - DPF: {00191E4B-49C2-48E2-A548-8F702D75622A} https://strtc.oracle.com/imtapp/res/jar/cnsload.cab (Reg Error: Value error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1257165895140 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1257165992890 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://ldmattson.webex.com/client/T27L/webex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/da2/PCPitStop2.cab (PCPitstop Exam)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/02 05:27:34 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{02f87f37-c83d-11de-8464-e43d4e8124d8}\Shell - "" = AutoRun
O33 - MountPoints2\{02f87f37-c83d-11de-8464-e43d4e8124d8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/11/01 21:15:29 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/14 10:39:23 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Nathan\Desktop\OTL.exe
[2010/05/13 15:13:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\Desktop\HOA Docs
[2010/05/13 12:54:13 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/05/13 12:54:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/05/13 11:52:36 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/08 23:17:18 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/05/08 23:17:14 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/05/08 23:17:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/05/08 23:11:48 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/05/08 23:07:09 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/05/04 19:01:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\Desktop\Funk Wedding docs
[2010/05/03 13:41:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\Desktop\LCG Pence Projects
[2010/05/03 10:21:40 | 000,000,000 | —D | C] – C:\Program Files\Citrix
[2010/05/03 10:10:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\Desktop\Barry Cassell Schedules
[2010/04/30 16:04:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ALM
[2010/04/30 15:50:26 | 000,000,000 | —D | C] – C:\Program Files\Adobe Media Player
[2010/04/30 14:36:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\Desktop\Scott Mattson schedule
[2010/04/29 13:42:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\My Documents\Symantec
[2010/04/29 13:41:41 | 000,124,976 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/29 13:41:41 | 000,060,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/29 13:41:32 | 000,362,032 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NIS\1106000.020\symtdi.sys
[2010/04/29 13:41:32 | 000,340,016 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NIS\1106000.020\symtdiv.sys
[2010/04/29 13:41:32 | 000,328,752 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NIS\1106000.020\symds.sys
[2010/04/29 13:41:32 | 000,325,680 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NIS\1106000.020\srtsp.sys
[2010/04/29 13:41:32 | 000,172,592 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NIS\1106000.020\symefa.sys
[2010/04/29 13:41:32 | 000,116,784 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NIS\1106000.020\ironx86.sys
[2010/04/29 13:41:32 | 000,043,696 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NIS\1106000.020\srtspx.sys
[2010/04/29 13:41:31 | 000,501,888 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NIS\1106000.020\cchpx86.sys
[2010/04/29 13:40:59 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NIS\1106000.020
[2010/04/29 13:40:34 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2010/04/29 13:40:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NIS
[2010/04/29 13:40:32 | 000,000,000 | —D | C] – C:\Program Files\Norton Internet Security
[2010/04/29 13:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Norton
[2010/04/29 13:29:39 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2010/04/29 13:29:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/04/28 10:40:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\PrimaveraLogs
[2010/04/28 10:35:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\Desktop\Barry P6 files
[2010/04/28 10:35:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\Desktop\New Folder
[2010/04/20 17:41:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\Desktop\PreMarital - Nate Miranda Reports
[2010/04/16 12:06:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Nathan\Desktop\Joovy
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Nathan\*.tmp files -> C:\Documents and Settings\Nathan\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/14 10:49:12 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1454471165-1965331169-839522115-1003.job
[2010/05/14 10:49:12 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1454471165-1965331169-839522115-1003.job
[2010/05/14 10:40:34 | 000,284,915 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\gmer.zip
[2010/05/14 10:39:28 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Nathan\Desktop\OTL.exe
[2010/05/14 10:38:50 | 000,132,597 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\Flash_Disinfector.exe
[2010/05/14 00:16:35 | 000,035,436 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/05/13 23:21:10 | 011,010,048 | -H– | M] () – C:\Documents and Settings\Nathan\NTUSER.DAT
[2010/05/13 22:51:50 | 000,052,736 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\Google Redirect Post.doc
[2010/05/13 13:18:09 | 000,395,194 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/05/13 12:54:21 | 000,000,933 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\Spybot - Search & Destroy.lnk
[2010/05/13 11:52:38 | 000,001,734 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\HijackThis.lnk
[2010/05/13 10:29:04 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/13 10:27:41 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/13 10:27:37 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/11 21:33:23 | 000,753,632 | —- | M] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\Cat.DB
[2010/05/11 21:31:14 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Nathan\ntuser.ini
[2010/05/11 18:53:22 | 000,116,143 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\EXP_GBI_PCBOILR.JAR
[2010/05/11 18:42:05 | 000,493,988 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/05/11 18:42:05 | 000,091,098 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/05/11 18:42:04 | 000,595,840 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/10 09:44:02 | 000,026,624 | —- | M] () – C:\Documents and Settings\Nathan\My Documents\Ling Ling sister-in-law info.doc
[2010/05/09 11:42:11 | 005,023,232 | —- | M] () – C:\Documents and Settings\Nathan\My Documents\Darlene Mom's dad massage certificate.doc
[2010/05/08 23:18:15 | 000,001,804 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\iTunes.lnk
[2010/05/08 23:12:10 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/05/05 15:22:15 | 000,000,062 | —- | M] () – C:\WINDOWS\iltwain.ini
[2010/05/05 05:11:53 | 000,018,244 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\P6 Global Profiles.xlsx
[2010/05/05 05:11:50 | 000,025,697 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\P6 Global Profiles2.xlsx
[2010/05/05 04:43:04 | 000,016,605 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\P6 New User Notes.docx
[2010/05/05 02:48:29 | 000,001,830 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\LCG Pence Citrix 2.RDP
[2010/05/03 11:04:48 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Nathan\Desktop\~$G Pence.doc
[2010/05/03 11:04:42 | 000,010,752 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\LCG Pence.doc
[2010/05/03 10:22:01 | 000,002,116 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\s Quick Connect.lnk
[2010/05/03 10:21:04 | 000,072,080 | —- | M] () – C:\Documents and Settings\Nathan\g2mdlhlpx.exe
[2010/05/02 11:22:59 | 002,060,680 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/04/30 16:40:22 | 000,044,424 | —- | M] () – C:\Documents and Settings\Nathan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/29 13:41:41 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/29 13:41:41 | 000,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/29 13:41:41 | 000,007,443 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/29 13:41:41 | 000,000,805 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/04/29 13:41:34 | 000,001,973 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2010/04/28 12:32:34 | 000,025,088 | —- | M] () – C:\Documents and Settings\Nathan\My Documents\Contract Manager 12 Java Type.doc
[2010/04/28 11:16:46 | 000,000,552 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/04/21 22:29:11 | 000,104,953 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\GBC RFI Test.pdf
[2010/04/21 22:17:31 | 000,138,848 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\GBC logo RGB.jpg
[2010/04/21 21:45:49 | 000,138,848 | —- | M] () – C:\GBC logo RGB.jpg
[2010/04/20 14:16:26 | 000,000,175 | —- | M] () – C:\Documents and Settings\Nathan\Application Data\default.rss
[2010/04/20 14:16:26 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/04/19 10:00:45 | 000,011,776 | —- | M] () – C:\Documents and Settings\Nathan\Desktop\To Do List April 2010.xls
[2010/04/17 03:04:29 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/16 08:33:36 | 003,003,680 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Nathan\*.tmp files -> C:\Documents and Settings\Nathan\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/14 10:40:32 | 000,284,915 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\gmer.zip
[2010/05/14 10:38:50 | 000,132,597 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\Flash_Disinfector.exe
[2010/05/13 22:51:49 | 000,052,736 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\Google Redirect Post.doc
[2010/05/13 12:54:21 | 000,000,933 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\Spybot - Search & Destroy.lnk
[2010/05/13 11:52:37 | 000,001,734 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\HijackThis.lnk
[2010/05/10 10:00:15 | 000,001,804 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\iTunes.lnk
[2010/05/10 09:43:42 | 000,026,624 | —- | C] () – C:\Documents and Settings\Nathan\My Documents\Ling Ling sister-in-law info.doc
[2010/05/09 11:14:14 | 005,023,232 | —- | C] () – C:\Documents and Settings\Nathan\My Documents\Darlene Mom's dad massage certificate.doc
[2010/05/08 23:12:10 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/05/06 17:29:37 | 005,719,552 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\Granddad's Business Cards 5-27-02.doc
[2010/05/05 03:32:17 | 000,025,697 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\P6 Global Profiles2.xlsx
[2010/05/05 03:32:16 | 000,016,605 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\P6 New User Notes.docx
[2010/05/05 02:49:48 | 000,018,244 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\P6 Global Profiles.xlsx
[2010/05/05 02:48:29 | 000,001,830 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\LCG Pence Citrix 2.RDP
[2010/05/03 11:04:48 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Nathan\Desktop\~$G Pence.doc
[2010/05/03 11:04:42 | 000,010,752 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\LCG Pence.doc
[2010/05/03 10:22:00 | 000,002,116 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\s Quick Connect.lnk
[2010/05/03 10:21:04 | 000,072,080 | —- | C] () – C:\Documents and Settings\Nathan\g2mdlhlpx.exe
[2010/04/29 13:41:45 | 000,753,632 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\Cat.DB
[2010/04/29 13:41:41 | 000,007,443 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/29 13:41:41 | 000,000,805 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/04/29 13:41:34 | 000,001,973 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2010/04/29 13:41:32 | 000,007,787 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\symnetv.cat
[2010/04/29 13:41:32 | 000,007,444 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\symefa.cat
[2010/04/29 13:41:32 | 000,007,442 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\srtspx.cat
[2010/04/29 13:41:32 | 000,007,438 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\srtsp.cat
[2010/04/29 13:41:32 | 000,007,425 | R— | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\symds.cat
[2010/04/29 13:41:32 | 000,007,368 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\symnet.cat
[2010/04/29 13:41:32 | 000,003,374 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\symefa.inf
[2010/04/29 13:41:32 | 000,002,793 | R— | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\symds.inf
[2010/04/29 13:41:32 | 000,001,473 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\symnetv.inf
[2010/04/29 13:41:32 | 000,001,445 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\symnet.inf
[2010/04/29 13:41:32 | 000,001,388 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\srtspx.inf
[2010/04/29 13:41:32 | 000,001,382 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\srtsp.inf
[2010/04/29 13:41:32 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\iron.inf
[2010/04/29 13:41:32 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\isolate.ini
[2010/04/29 13:41:31 | 000,007,438 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\iron.cat
[2010/04/29 13:41:31 | 000,007,396 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\cchpx86.cat
[2010/04/29 13:41:31 | 000,001,754 | —- | C] () – C:\WINDOWS\System32\drivers\NIS\1106000.020\cchpx86.inf
[2010/04/28 12:32:34 | 000,025,088 | —- | C] () – C:\Documents and Settings\Nathan\My Documents\Contract Manager 12 Java Type.doc
[2010/04/21 22:29:11 | 000,104,953 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\GBC RFI Test.pdf
[2010/04/21 22:17:31 | 000,138,848 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\GBC logo RGB.jpg
[2010/04/21 21:45:49 | 000,138,848 | —- | C] () – C:\GBC logo RGB.jpg
[2010/04/19 10:00:35 | 000,011,776 | —- | C] () – C:\Documents and Settings\Nathan\Desktop\To Do List April 2010.xls
[2010/01/17 21:33:49 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/04 03:25:17 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\BioPdf.PdfWriter.Lib.dll
[2009/12/18 22:20:53 | 000,004,767 | —- | C] () – C:\WINDOWS\Irremote.ini
[2009/11/12 21:35:10 | 000,335,872 | —- | C] () – C:\WINDOWS\System32\ldf252.dll
[2009/11/03 18:00:54 | 000,000,079 | —- | C] () – C:\WINDOWS\ricdb.ini
[2009/11/03 18:00:53 | 000,000,023 | —- | C] () – C:\WINDOWS\System32\RPCS.ini
[2009/11/03 02:58:17 | 000,000,062 | —- | C] () – C:\WINDOWS\iltwain.ini
[2009/11/02 21:04:30 | 000,327,168 | —- | C] () – C:\WINDOWS\System32\cutil32.dll
[2009/11/02 17:58:43 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\tifmicon.dll
[2009/11/02 05:43:47 | 000,000,552 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/03/05 13:48:16 | 000,618,496 | R— | C] () – C:\WINDOWS\System32\stlpmt45.dll
[2009/03/03 13:18:04 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2006/07/31 17:45:20 | 000,086,528 | —- | C] () – C:\WINDOWS\System32\libjnbzip2.dll
[2006/06/01 19:31:22 | 000,009,136 | R— | C] () – C:\WINDOWS\System32\Inetwh16.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/12/19 00:35:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/11/02 20:53:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/01/04 03:27:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PDF Writer
[2009/11/09 22:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/05/08 23:18:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/04 18:15:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/11/12 21:35:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Nathan\Application Data\ACD Systems
[2009/11/12 21:32:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Nathan\Application Data\ACDInTouch
[2009/11/05 19:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Nathan\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/01/04 03:27:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Nathan\Application Data\PDF Writer
[2009/11/27 15:39:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Nathan\Application Data\Picaboo
[2010/05/13 11:37:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Nathan\Application Data\webex

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/11/02 11:09:30 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/11/02 12:18:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/11/02 11:09:30 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/11/02 12:18:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2002/08/29 05:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2009/11/02 11:09:30 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/11/02 12:18:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/11/02 11:09:30 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/11/02 12:18:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 00:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 00:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/11/01 21:18:53 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/11/01 21:18:53 | 000,626,688 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/11/01 21:18:53 | 000,417,792 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/02/24 06:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2010/04/29 13:41:41 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS
[2010/04/16 08:33:36 | 000,041,472 | —- | M] (Apple, Inc.) – C:\WINDOWS\system32\drivers\usbaapl.sys
< End of report >

Attachments:

OTL Extras.txt
OTL Extras logfile created on: 5/14/2010 10:49:19 AM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\Nathan\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 250.93 Gb Free Space | 84.18% Space Free | Partition Type: NTFS
Drive D: | 298.08 Gb Total Space | 218.05 Gb Free Space | 73.15% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 232.83 Gb Total Space | 62.51 Gb Free Space | 26.85% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
Drive I: | 698.64 Gb Total Space | 356.21 Gb Free Space | 50.99% Space Free | Partition Type: NTFS

Computer Name: NHHPLPTP
Current User Name: Nathan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\PROGRA~1\ACDSYS~1\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services
"1992:TCP" = 1992:TCP:*:Enabled:Services
"2484:TCP" = 2484:TCP:*:Enabled:Services
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1433:TCP" = 1433:TCP:*:Enabled:Primavera P6
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services
"1992:TCP" = 1992:TCP:*:Enabled:Services
"2484:TCP" = 2484:TCP:*:Enabled:Services
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Java\jdk1.6.0_14\bin\java.exe" = C:\Program Files\Java\jdk1.6.0_14\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\VMware\VMware Player\vmware-authd.exe" = C:\Program Files\VMware\VMware Player\vmware-authd.exe:*:Enabled:VMware Authd – (VMware, Inc.)
"C:\WINDOWS\system32\ftp.exe" = C:\WINDOWS\system32\ftp.exe:*:Enabled:File Transfer Program – (Microsoft Corporation)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{02627EE5-EACA-4742-A9CC-E687631773E4}" = Nero ShowTime
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{086A7D8C-0A38-4C7F-819A-620275550D5C}" = Nero Burning ROM Help
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1C00C7C5-E615-4139-B817-7F4003DE68C0}" = Nero PhotoSnap Help
"{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (PRIMAVERA)
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{32A3A4F4-B792-11D6-A78A-00B0D0150050}" = J2SE Development Kit 5.0 Update 5
"{32A3A4F4-B792-11D6-A78A-00B0D0160140}" = Java™ SE Development Kit 6 Update 14
"{32F720F5-2D0D-4245-A2B0-9EB3CECF8101}" = Norton Ghost 10.0
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 J1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4C8FA718-EE71-4324-8265-D55DB0336509}" = Contract Manager
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{56ABA277-EE53-4478-A607-FA42208FF5A9}" = Menu Templates - Pack 1
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57250E78-F6E2-4DCE-9A84-50B28A70AB84}" = Menu Templates - Pack 3
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5C47C8B6-77FF-4FC7-A388-66FCF9CFC24C}" = Snagit 9.1.3
"{5D9BE3C1-8BA4-4E7E-82FD-9F74FA6815D1}" = Nero Vision Help
"{5E08ECD1-C98E-4711-BF65-8FD736B3F969}" = Nero RescueAgent Help
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{6DE33BFA-CF21-439E-80E0-3A24F03E3643}" = Sybase InfoMaker 10.5
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{77E33D87-255E-413E-9C8D-EED2A7F9BEBF}" = Nero Live Help
"{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
"{7A9EECF9-6E50-4149-A992-223CF0B447C7}" = EvoBotSetup
"{7BA8F80D-6870-4109-B5DD-18D4AD45CB0F}" = InfoMaker 10.5
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{861C1D63-222F-4865-AF3A-9D116C42C219}" = Primavera P6 v7.0
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8C525C3E-00C9-4A77-9F76-D22939DB53C0}" = Picaboo 2.5
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{913A0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Project Standard 2003
"{926C96FB-9D0A-4504-8000-C6D3A4A3118E}" = Java DB 10.4.2.1
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98A67610-A3B5-4098-A423-3708040026D3}" = "Nero SoundTrax Help
"{9966A5DB-8BB0-4D89-A701-386ED84E79B8}" = Adobe Creative Suite 4 Master Collection
"{9AB8E6CE-CE6D-43A0-B54E-422425524FF9}" = Menu Templates - Pack 2
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A4512736-8D63-4298-9271-5329931FA46B}" = Microsoft SQL Server Management Studio Express
"{A53A11EA-0095-493F-86FA-A15E8A86A405}" = VMware Player
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{AD6BC5CC-2EF0-49C4-B33D-CDC8B2C4DC80}" = Nero Recode Help
"{AD7914E1-6453-4440-AEC7-02C72AD6FE5F}" = TIPCI
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BCEEDC10-441F-4E4E-8590-0955C4C6B3F6}" = Adobe Setup
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE96F5A5-584D-4F8F-AA3E-9BAED413DB72}" = Nero CoverDesigner Help
"{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{d71d9c30-5478-473d-9ef5-ac5f4279d2fc}" = Nero 9
"{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
"{DF6A95F5-ADC1-406A-BDC6-2AA7CC0182AA}" = Nero Live
"{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
"{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{F425DD1D-0097-41C3-B545-B79E3D51100E}" = Movie Templates - Pack 1
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F6BDD7C5-89ED-4569-9318-469AA9732572}" = Nero BurnRights Help
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"ACDSee" = ACDSee
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_7e74552a59eaf9fafd13f90894ac9bd" = Adobe Creative Suite 4 Master Collection
"All ATI Software" = ATI - Software Uninstall Utility
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.5
"ATI Display Driver" = ATI Display Driver
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 7.1.0.1082
"CNXT_AUDIO" = Conexant AC-Link Audio
"CNXT_MODEM_PCI_VEN_1002&DEV_4378" = Soft Data Fax Modem with SmartCP
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Contract Manager 11.0" = Primavera Contract Manager 11.0
"Dave Ramsey's Financial Peace Financial Software5.3" = Dave Ramsey's Financial Peace Financial Software
"GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.70
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{861C1D63-222F-4865-AF3A-9D116C42C219}" = Primavera P6 v7.0
"InstallShield_{AD7914E1-6453-4440-AEC7-02C72AD6FE5F}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"Island Wars 2 demo_is1" = Island Wars 2 demo v2.50
"Island Wars_is1" = Island Wars v1.20
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NIS" = Norton Internet Security
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OracleRTCClient" = Oracle Web Conferencing Console
"PC Wizard 2009_is1" = PC Wizard 2009.1.91
"Quicken WillMaker Plus 2008" = Quicken WillMaker Plus 2008
"RealPlayer 12.0" = RealPlayer
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VMware_Player" = VMware Player
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.5.0.452

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/13/2010 1:54:40 PM | Computer Name = NHHPLPTP | Source = Application Hang | ID = 1001
Description = Fault bucket 1780371397.

Error - 5/13/2010 1:54:56 PM | Computer Name = NHHPLPTP | Source = Application Hang | ID = 1001
Description = Fault bucket 1780371397.

Error - 5/13/2010 1:54:57 PM | Computer Name = NHHPLPTP | Source = Application Hang | ID = 1001
Description = Fault bucket 1780371397.

Error - 5/13/2010 1:54:59 PM | Computer Name = NHHPLPTP | Source = Application Hang | ID = 1001
Description = Fault bucket 1780371397.

Error - 5/13/2010 1:55:00 PM | Computer Name = NHHPLPTP | Source = Application Hang | ID = 1001
Description = Fault bucket 1780371397.

Error - 5/13/2010 1:55:00 PM | Computer Name = NHHPLPTP | Source = Application Hang | ID = 1001
Description = Fault bucket 1780371397.

Error - 5/13/2010 1:55:18 PM | Computer Name = NHHPLPTP | Source = Application Hang | ID = 1001
Description = Fault bucket 1780371397.

Error - 5/13/2010 1:56:05 PM | Computer Name = NHHPLPTP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17023, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/13/2010 1:56:09 PM | Computer Name = NHHPLPTP | Source = Application Hang | ID = 1001
Description = Fault bucket 1780371397.

Error - 5/14/2010 3:10:21 AM | Computer Name = NHHPLPTP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17023, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 4/30/2010 3:38:56 PM | Computer Name = NHHPLPTP | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 60 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 4/30/2010 3:38:56 PM | Computer Name = NHHPLPTP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 59 minutes. NtpClient has no source of accurate
time.

Error - 5/5/2010 2:08:46 AM | Computer Name = NHHPLPTP | Source = Service Control Manager | ID = 7034
Description = The Contract Manager service terminated unexpectedly. It has done
this 1 time(s).

Error - 5/11/2010 11:06:34 AM | Computer Name = NHHPLPTP | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NIS service.

Error - 5/11/2010 11:12:26 AM | Computer Name = NHHPLPTP | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{3F754085-A32D-4218-AE1F-5038ECD0EA69}
because another computer on the network has the same name. The server could not
start.

Error - 5/11/2010 10:47:41 PM | Computer Name = NHHPLPTP | Source = Service Control Manager | ID = 7034
Description = The Contract Manager service terminated unexpectedly. It has done
this 1 time(s).

Error - 5/11/2010 10:47:41 PM | Computer Name = NHHPLPTP | Source = Service Control Manager | ID = 7034
Description = The SQL Server (PRIMAVERA) service terminated unexpectedly. It has
done this 1 time(s).

Error - 5/11/2010 10:47:41 PM | Computer Name = NHHPLPTP | Source = Service Control Manager | ID = 7031
Description = The Windows Live ID Sign-in Assistant service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
10000 milliseconds: Restart the service.

Error - 5/11/2010 10:47:49 PM | Computer Name = NHHPLPTP | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).

Error - 5/13/2010 1:49:22 PM | Computer Name = NHHPLPTP | Source = Service Control Manager | ID = 7034
Description = The Contract Manager service terminated unexpectedly. It has done
this 1 time(s).


< End of report >

Attachments:

Hello NathanH

This is my machine, not a company's machine

:thumbup: Thanks for letting me know.

Can I have your permission to run the Flash Disinfector on all my flash drives (i've got quite a few of them…).

:D

Feel free.

I will wait for the GMER log. Let me know if you run into any problems.
Here's the GMER.log

Sorry it took so long to post. My computer crashed during the first GMER scan. Second time took about 4 hours, and then when the scan was complete, i had a whole host of errors on my screen (things like "the memory at 0x023439 blah blah could not be read) and things like that. It didn't even save the log. I was able to click the "save" button and save the log, but then I couldn't open any applicatations to read it (Word and Notepad would not open, kept telling me the apps didn't exist). After a reboot, I was able to open the log. Hope it's everything you need.

Nathan

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-14 17:38:46
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Nathan\LOCALS~1\Temp\pxliqpow.sys


—- System - GMER 1.0.15 —-

SSDT 89C58F10 ZwAlertResumeThread
SSDT 89C58FD0 ZwAlertThread
SSDT 899948C0 ZwAllocateVirtualMemory
SSDT 89C65608 ZwAssignProcessToJobObject
SSDT 89BA46D8 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xB1330210]
SSDT 89C5D6B8 ZwCreateMutant
SSDT 89C5AC38 ZwCreateSymbolicLinkObject
SSDT 89AA55A0 ZwCreateThread
SSDT 89C656E8 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xB1330490]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB13309F0]
SSDT 8990EAA0 ZwDuplicateObject
SSDT 899233C8 ZwFreeVirtualMemory
SSDT 898F4C08 ZwImpersonateAnonymousToken
SSDT 89B85A28 ZwImpersonateThread
SSDT 89AA5008 ZwLoadDriver
SSDT 89A93D30 ZwMapViewOfSection
SSDT 89C5D5D8 ZwOpenEvent
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwOpenKey [0xB13307A0]
SSDT 89CE8008 ZwOpenProcess
SSDT 89904F00 ZwOpenProcessToken
SSDT 89C65898 ZwOpenSection
SSDT 89CE76F8 ZwOpenThread
SSDT 89C72710 ZwProtectVirtualMemory
SSDT 898FB988 ZwResumeThread
SSDT 8994C7F8 ZwSetContextThread
SSDT 899FA670 ZwSetInformationProcess
SSDT 89C86EE0 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB1330C40]
SSDT 89C65978 ZwSuspendProcess
SSDT 89CDF490 ZwSuspendThread
SSDT 89C7A650 ZwTerminateProcess
SSDT 89A39B70 ZwTerminateThread
SSDT 89AD10A8 ZwUnmapViewOfSection
SSDT 89989510 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2450 80501C88 4 Bytes CALL 8CD9E2E3
.text ntkrnlpa.exe!ZwCallbackReturn + 247C 80501CB4 4 Bytes JMP 30E28990
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\iTunes\iTunes.exe[204] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 051C2862
.text C:\Program Files\iTunes\iTunes.exe[204] WS2_32.dll!send 71AB4C27 5 Bytes JMP 051C26EE
.text C:\Program Files\iTunes\iTunes.exe[204] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 051C27E0
.text C:\Program Files\iTunes\iTunes.exe[204] WS2_32.dll!recv 71AB676F 5 Bytes JMP 051C2726
.text C:\Program Files\iTunes\iTunes.exe[204] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 051C275E
.text C:\Program Files\Bonjour\mDNSResponder.exe[328] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E12862
.text C:\Program Files\Bonjour\mDNSResponder.exe[328] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E126EE
.text C:\Program Files\Bonjour\mDNSResponder.exe[328] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E127E0
.text C:\Program Files\Bonjour\mDNSResponder.exe[328] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E12726
.text C:\Program Files\Bonjour\mDNSResponder.exe[328] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E1275E
.text C:\Program Files\Java\jre6\bin\jqs.exe[644] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 017A2862
.text C:\Program Files\Java\jre6\bin\jqs.exe[644] WS2_32.dll!send 71AB4C27 5 Bytes JMP 017A26EE
.text C:\Program Files\Java\jre6\bin\jqs.exe[644] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 017A27E0
.text C:\Program Files\Java\jre6\bin\jqs.exe[644] WS2_32.dll!recv 71AB676F 5 Bytes JMP 017A2726
.text C:\Program Files\Java\jre6\bin\jqs.exe[644] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 017A275E
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[764] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00962862
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[764] WS2_32.dll!send 71AB4C27 5 Bytes JMP 009626EE
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[764] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 009627E0
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[764] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00962726
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[764] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0096275E
.text C:\WINDOWS\system32\Ati2evxx.exe[1228] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01102862
.text C:\WINDOWS\system32\Ati2evxx.exe[1228] WS2_32.dll!send 71AB4C27 5 Bytes JMP 011026EE
.text C:\WINDOWS\system32\Ati2evxx.exe[1228] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 011027E0
.text C:\WINDOWS\system32\Ati2evxx.exe[1228] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01102726
.text C:\WINDOWS\system32\Ati2evxx.exe[1228] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0110275E
.text C:\Program Files\iTunes\iTunesHelper.exe[1500] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01BB2862
.text C:\Program Files\iTunes\iTunesHelper.exe[1500] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01BB26EE
.text C:\Program Files\iTunes\iTunesHelper.exe[1500] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01BB27E0
.text C:\Program Files\iTunes\iTunesHelper.exe[1500] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01BB2726
.text C:\Program Files\iTunes\iTunesHelper.exe[1500] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01BB275E
.text C:\WINDOWS\Explorer.EXE[1524] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01692862
.text C:\WINDOWS\Explorer.EXE[1524] WS2_32.dll!send 71AB4C27 5 Bytes JMP 016926EE
.text C:\WINDOWS\Explorer.EXE[1524] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 016927E0
.text C:\WINDOWS\Explorer.EXE[1524] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01692726
.text C:\WINDOWS\Explorer.EXE[1524] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0169275E
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1584] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00822862
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1584] WS2_32.dll!send 71AB4C27 5 Bytes JMP 008226EE
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1584] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 008227E0
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1584] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00822726
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1584] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0082275E
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1608] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00822862
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1608] WS2_32.dll!send 71AB4C27 5 Bytes JMP 008226EE
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1608] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 008227E0
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1608] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00822726
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1608] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0082275E
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[1620] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 011C2862
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[1620] WS2_32.dll!send 71AB4C27 5 Bytes JMP 011C26EE
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[1620] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 011C27E0
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[1620] WS2_32.dll!recv 71AB676F 5 Bytes JMP 011C2726
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[1620] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 011C275E
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2112] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00932862
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2112] WS2_32.dll!send 71AB4C27 5 Bytes JMP 009326EE
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2112] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 009327E0
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2112] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00932726
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2112] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0093275E
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[2120] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01442862
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[2120] WS2_32.dll!send 71AB4C27 5 Bytes JMP 014426EE
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[2120] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 014427E0
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[2120] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01442726
.text C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe[2120] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0144275E
.text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2196] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 009A2862
.text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2196] WS2_32.dll!send 71AB4C27 5 Bytes JMP 009A26EE
.text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2196] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 009A27E0
.text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2196] WS2_32.dll!recv 71AB676F 5 Bytes JMP 009A2726
.text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2196] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 009A275E
.text C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe[2288] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01612862
.text C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe[2288] WS2_32.dll!send 71AB4C27 5 Bytes JMP 016126EE
.text C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe[2288] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 016127E0
.text C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe[2288] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01612726
.text C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe[2288] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0161275E
.text C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe[2388] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00F12862
.text C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe[2388] ws2_32.dll!send 71AB4C27 5 Bytes JMP 00F126EE
.text C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe[2388] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00F127E0
.text C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe[2388] ws2_32.dll!recv 71AB676F 5 Bytes JMP 00F12726
.text C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe[2388] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00F1275E
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2404] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00FD2862
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2404] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00FD26EE
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2404] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00FD27E0
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2404] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00FD2726
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2404] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00FD275E
.text C:\Program Files\Norton Ghost\Agent\VProSvc.exe[2556] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01882862
.text C:\Program Files\Norton Ghost\Agent\VProSvc.exe[2556] WS2_32.dll!send 71AB4C27 5 Bytes JMP 018826EE
.text C:\Program Files\Norton Ghost\Agent\VProSvc.exe[2556] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 018827E0
.text C:\Program Files\Norton Ghost\Agent\VProSvc.exe[2556] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01882726
.text C:\Program Files\Norton Ghost\Agent\VProSvc.exe[2556] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0188275E
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[2592] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01142862
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[2592] WS2_32.dll!send 71AB4C27 5 Bytes JMP 011426EE
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[2592] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 011427E0
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[2592] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01142726
.text C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe[2592] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0114275E
.text C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe[2632] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01942862
.text C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe[2632] WS2_32.dll!send 71AB4C27 5 Bytes JMP 019426EE
.text C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe[2632] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 019427E0
.text C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe[2632] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01942726
.text C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe[2632] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0194275E
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2704] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 013B2862
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2704] WS2_32.dll!send 71AB4C27 5 Bytes JMP 013B26EE
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2704] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 013B27E0
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2704] WS2_32.dll!recv 71AB676F 5 Bytes JMP 013B2726
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2704] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 013B275E
.text C:\Program Files\Norton Ghost\Agent\GhostTray.exe[2744] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 02552862
.text C:\Program Files\Norton Ghost\Agent\GhostTray.exe[2744] WS2_32.dll!send 71AB4C27 5 Bytes JMP 025526EE
.text C:\Program Files\Norton Ghost\Agent\GhostTray.exe[2744] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 025527E0
.text C:\Program Files\Norton Ghost\Agent\GhostTray.exe[2744] WS2_32.dll!recv 71AB676F 5 Bytes JMP 02552726
.text C:\Program Files\Norton Ghost\Agent\GhostTray.exe[2744] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0255275E
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2848] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 011E2862
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2848] WS2_32.dll!send 71AB4C27 5 Bytes JMP 011E26EE
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2848] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 011E27E0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2848] WS2_32.dll!recv 71AB676F 5 Bytes JMP 011E2726
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2848] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 011E275E
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2896] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01002862
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2896] WS2_32.dll!send 71AB4C27 5 Bytes JMP 010026EE
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2896] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 010027E0
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2896] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01002726
.text C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe[2896] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0100275E
.text C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe[2900] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00A12862
.text C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe[2900] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00A126EE
.text C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe[2900] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00A127E0
.text C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe[2900] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00A12726
.text C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe[2900] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00A1275E
.text C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe[3080] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01FB2862
.text C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe[3080] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01FB26EE
.text C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe[3080] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01FB27E0
.text C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe[3080] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01FB2726
.text C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe[3080] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01FB275E
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[3128] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00AA2862
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[3128] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00AA26EE
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[3128] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00AA27E0
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[3128] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00AA2726
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[3128] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00AA275E
.text C:\Program Files\VMware\VMware Player\vmware-authd.exe[3624] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 014F2862
.text C:\Program Files\VMware\VMware Player\vmware-authd.exe[3624] WS2_32.dll!send 71AB4C27 5 Bytes JMP 014F26EE
.text C:\Program Files\VMware\VMware Player\vmware-authd.exe[3624] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 014F27E0
.text C:\Program Files\VMware\VMware Player\vmware-authd.exe[3624] WS2_32.dll!recv 71AB676F 5 Bytes JMP 014F2726
.text C:\Program Files\VMware\VMware Player\vmware-authd.exe[3624] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 014F275E
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3636] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 012A2862
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3636] WS2_32.dll!send 71AB4C27 5 Bytes JMP 012A26EE
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3636] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 012A27E0
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3636] WS2_32.dll!recv 71AB676F 5 Bytes JMP 012A2726
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3636] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 012A275E
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3844] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01782862
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3844] WS2_32.dll!send 71AB4C27 5 Bytes JMP 017826EE
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3844] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 017827E0
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3844] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01782726
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3844] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0178275E
.text C:\Program Files\VMware\VMware Player\hqtray.exe[4048] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01632862
.text C:\Program Files\VMware\VMware Player\hqtray.exe[4048] WS2_32.dll!send 71AB4C27 5 Bytes JMP 016326EE
.text C:\Program Files\VMware\VMware Player\hqtray.exe[4048] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 016327E0
.text C:\Program Files\VMware\VMware Player\hqtray.exe[4048] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01632726
.text C:\Program Files\VMware\VMware Player\hqtray.exe[4048] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0163275E
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[4092] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DC2862
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[4092] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DC26EE
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[4092] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00DC27E0
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[4092] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00DC2726
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[4092] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00DC275E
.text C:\WINDOWS\System32\alg.exe[4280] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00CE2862
.text C:\WINDOWS\System32\alg.exe[4280] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00CE26EE
.text C:\WINDOWS\System32\alg.exe[4280] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00CE27E0
.text C:\WINDOWS\System32\alg.exe[4280] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00CE2726
.text C:\WINDOWS\System32\alg.exe[4280] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00CE275E
.text C:\Program Files\iPod\bin\iPodService.exe[4552] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00D42862
.text C:\Program Files\iPod\bin\iPodService.exe[4552] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00D426EE
.text C:\Program Files\iPod\bin\iPodService.exe[4552] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00D427E0
.text C:\Program Files\iPod\bin\iPodService.exe[4552] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00D42726
.text C:\Program Files\iPod\bin\iPodService.exe[4552] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00D4275E
.text C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe[4576] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01032862
.text C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe[4576] ws2_32.dll!send 71AB4C27 5 Bytes JMP 010326EE
.text C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe[4576] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 010327E0
.text C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe[4576] ws2_32.dll!recv 71AB676F 5 Bytes JMP 01032726
.text C:\Program Files\Norton Internet Security\Engine\17.6.0.32\ccSvcHst.exe[4576] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0103275E
.text C:\Program Files\TechSmith\Snagit 9\Snagit32.exe[5268] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01D32862
.text C:\Program Files\TechSmith\Snagit 9\Snagit32.exe[5268] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01D326EE
.text C:\Program Files\TechSmith\Snagit 9\Snagit32.exe[5268] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01D327E0
.text C:\Program Files\TechSmith\Snagit 9\Snagit32.exe[5268] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01D32726
.text C:\Program Files\TechSmith\Snagit 9\Snagit32.exe[5268] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01D3275E
.text C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe[5532] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00FA2862
.text C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe[5532] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00FA26EE
.text C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe[5532] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00FA27E0
.text C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe[5532] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00FA2726
.text C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe[5532] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00FA275E
.text C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe[5852] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E62862
.text C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe[5852] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E626EE
.text C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe[5852] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E627E0
.text C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe[5852] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E62726
.text C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe[5852] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E6275E
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[5928] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01582862
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[5928] WS2_32.dll!send 71AB4C27 5 Bytes JMP 015826EE
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[5928] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 015827E0
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[5928] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01582726
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[5928] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0158275E
.text C:\Documents and Settings\Nathan\Desktop\gmer.exe[6020] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01172862
.text C:\Documents and Settings\Nathan\Desktop\gmer.exe[6020] WS2_32.dll!send 71AB4C27 5 Bytes JMP 011726EE
.text C:\Documents and Settings\Nathan\Desktop\gmer.exe[6020] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 011727E0
.text C:\Documents and Settings\Nathan\Desktop\gmer.exe[6020] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01172726
.text C:\Documents and Settings\Nathan\Desktop\gmer.exe[6020] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0117275E

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 VMkbd.sys (VMware keyboard filter driver (32-bit)/VMware, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 VMkbd.sys (VMware keyboard filter driver (32-bit)/VMware, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\usbohci \Device\USBPDO-0 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbohci \Device\USBPDO-1 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbehci \Device\USBPDO-2 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\ACPI \Device\00000054 881A2290
Device \Driver\usbhub \Device\USBPDO-3 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\ACPI \Device\00000055 881A2290
Device \Driver\ACPI \Device\00000061 881A2290
Device \Driver\usbhub \Device\USBPDO-4 hcmon.sys (VMware USB monitor/VMware, Inc.)

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\ACPI \Device\00000062 881A2290
Device \Driver\ACPI \Device\00000070 881A2290
Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)
Device ftdisk.sys (FT Disk Driver/Microsoft Corporation)

AttachedDevice SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)

Device \Driver\ACPI \Device\00000058 881A2290
Device \Driver\ACPI \Device\00000059 881A2290
Device \Driver\ACPI \Device\00000072 881A2290
Device \Driver\ACPI \Device\00000073 881A2290
Device \Driver\ACPI \Device\00000067 881A2290
Device \Driver\ACPI \Device\00000085 881A2290
Device \Driver\ACPI \Device\00000086 881A2290
Device \Driver\ACPI \Device\00000087 881A2290

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\ACPI \Device\0000006a 881A2290
Device \Driver\ACPI \Device\0000005e 881A2290
Device \Driver\ACPI \Device\0000006b 881A2290
Device \Driver\usbohci \Device\USBFDO-0 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbohci \Device\USBFDO-1 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbehci \Device\USBFDO-2 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\ACPI \Device\0000006e 881A2290
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device \Driver\ACPI \Device\0000006f 881A2290
Device \Driver\usbhub \Device\0000008a hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\0000008b hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\0000008c hcmon.sys (VMware USB monitor/VMware, Inc.)

—- Files - GMER 1.0.15 —-

File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\AbstractLDBEngine.class 6968 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BaseCreateWrapper.class 2298 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BaseUpdateWrapper.class 7843 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BatchCreateEngine.class 4421 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BatchUpdateEngine.class 14175 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BlindPagingParam.class 515 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BlobDocumentBase64Translator.class 1245 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BlobToFieldTranslator.class 10115 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BODefaults.class 3484 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BOEngine.class 551 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BOEngineFactory.class 6941 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BOFieldException.class 6474 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BOMarker.class 236 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BONotFoundException.class 1306 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\Brand.class 340 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\BusinessRuleException.class 549 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CalculateEngine.class 1746 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CalculateEngineImpl$DataProvider.class 2965 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CalculateEngineImpl$GroupedFieldWithValues.class 1238 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CalculateEngineImpl$GroupProjectMapKey.class 1123 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CalculateEngineImpl$JoinedFieldInfo.class 532 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CalculateEngineImpl$RollupFieldsInfo.class 1070 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CalculateEngineImpl$RollupRowSetCache.class 1775 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CalculateEngineImpl.class 132706 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CboQueryMgr.class 5453 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client 0 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\BusinessObject$1.class 205 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\BusinessObject$EnumComparator.class 1389 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\BusinessObject$StdComparator.class 1625 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\BusinessObject.class 54424 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\CalendarBase.class 11257 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\ClientActivityDocumentDAOImpl.class 2681 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\ClientBOCreator.class 3081 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\ClientDAO.class 6657 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\ClientDAOFactory.class 1036 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\ClientDAOImpl.class 22038 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\ClientProjwbsDAOImpl.class 2224 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\ClientWPDocumentDAOImpl.class 5726 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\PmClientDAOFactory.class 2638 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\client\UdfBO.class 11911 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CreateEngineImpl.class 13746 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr 0 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\AbstractDateMgr.class 8364 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\CalculatedDateMgr$1.class 972 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\CalculatedDateMgr.class 5531 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\DateItem.class 2632 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\DateMgr.class 2022 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\DateMgrFactory.class 7696 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\DateMgrUtil.class 12266 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\OrderedDateItem.class 988 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\OrderedDateItemList.class 7075 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\PeriodDateMgr.class 6253 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\RateMgr.class 2063 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\ResourceShiftMgr$DAOServerSideShiftPeriodRateProvider.class 2835 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\ResourceShiftMgr$ListServerSideShiftPeriodRateProvider.class 3456 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\ResourceShiftMgr$ServerSideShiftPeriodRateProvider.class 455 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\ResourceShiftMgr.class 8390 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\SPRateMgr$DAOResourceRateProvider.class 2009 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\SPRateMgr$ListResourceRateProvider.class 1142 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\SPRateMgr$ResourceRateProvider.class 348 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\datemgr\SPRateMgr.class 7594 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\DBEngine.class 1671 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\DBEngineImpl.class 28240 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\DeleteEngine.class 543 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\DeleteEngineImpl$1.class 759 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\DeleteEngineImpl$SqlStatement.class 648 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\DeleteEngineImpl.class 42645 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\EngineUtils.class 28187 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\ExcelFormatter.class 5468 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\FinancialPeriodSpreadOutOfSyncException.class 1467 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\FinancialSpreadCalcEngine.class 11484 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\FormatterHelper.class 2395 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\GenericUE.class 1204 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\groupandsort 0 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\groupandsort\GroupColumnHelper.class 7251 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\groupandsort\GroupedQueryUtil.class 7142 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\IconManager.class 16328 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CalculateEngineImpl$1.class 1599 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\CreateEngine.class 520 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\EmailSettingsManager.class 1407 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\RemoteTransactionManager.class 5362 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\IntegrityConstraintException.class 525 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\LDBEngine.class 2180 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\LDBEngineImpl$UpdateClobStatement.class 823 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\LDBEngineImpl$UpdateStatement.class 576 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\LDBEngineImpl.class 42598 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\NoAvailableConnectionException.class 571 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\PagingParam.class 1465 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\PrmCache.class 496 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\PrmCacheImpl.class 2337 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\PSessionCommands.class 1893 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\PSessionCommandsAdapter.class 4045 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\PTransaction.class 2068 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\PTransactionFactory.class 2021 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\PTransactionImpl.class 9001 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\PTStatus.class 1071 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\RemoteTransactionManager$DeadRemoteTXChecker.class 2876 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\RemoteTransactionManager$TransactionInfo.class 536 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\RemoteTXId.class 1005 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\RollupDetails.class 1676 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\RollupEngine$1.class 962 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\RollupEngine.class 15796 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server 0 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\BusinessObject.class 36091 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\PmServerDAOFactory.class 2566 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerBOCalendarDAO$1.class 751 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerBOCalendarDAO.class 5318 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerBOCreator.class 4709 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerDAO.class 4655 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerDAOFactory.class 1036 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerDAOImpl.class 19240 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerFinancialPeriodDAO.class 765 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerGlobalPrivilegeDAO.class 1929 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerMSPTemplateDAO.class 749 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerProjectCodeTypeDAO.class 2946 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerTimesheetPeriodDAO.class 764 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\server\ServerUserDAO.class 1675 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\SimpleFormatter.class 10488 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\SpreadParam.class 2166 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\sql 0 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\sql\BatchDMLSQLClause.class 696 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\sql\BOClobDMLSQLClause.class 1341 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\sql\BODMLSQLClause.class 1650 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\sql\DMLSQLClause.class 1627 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\sql\OracleClobDMLSQLClause.class 467 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\SQLStatementUtil.class 8651 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\UDFCalculations$UDFTypeCalcInfo.class 602 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\UDFCalculations.class 10013 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\UpdateEngine.class 1532 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\UpdateEngineImpl.class 33929 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util 0 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\ColumnList.class 8954 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\AsyncJob.class 4186 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\AsyncTimeoutJob.class 945 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\AsyncUtil.class 1794 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\Base64Encoder.class 3397 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\Base64URLEncoder.class 1359 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\BOFieldValuesCache.class 1651 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\ColumnData.class 5158 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\ColumnFinder.class 923 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\ColumnList$ColumnDataTransformer.class 274 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\ColumnListIterator.class 860 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\FinancialPeriodCache.class 2310 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\GuidHelper.class 617 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\PerfData.class 721 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\PerfManager$CommandListener.class 1477 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\PerfManager.class 3631 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\PhxRunnable.class 169 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\PrmDateUtil.class 711 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\SelParams.class 1191 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\SequenceNumberHelper$SNGroup.class 3542 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\SequenceNumberHelper.class 16552 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql 0 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\CommCenterQueryParam.class 2254 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\ExprState.class 742 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlBinExp.class 1577 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlCompExp.class 1278 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlExpr.class 708 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlExprWithOrderByClause.class 2211 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlFieldTokenizer.class 1324 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlIdentExpr.class 573 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlInExpr.class 1773 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlIsNullExpr.class 985 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlLex.class 7745 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlLikeExpr.class 1073 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlLitExpr.class 723 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlNotExpr.class 735 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlParser.class 6645 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\sql\SqlToken.class 2059 bytes
File C:\jboss-5.0.1.GA\server\p6web\tmp\5c4o12x-58eww0-g1ucso7d-1-g1ucv6v9-9m\primaveraweb.war\WEB-INF\classes\com\primavera\bo\base\util\UniqueValueHelper.class 6786 bytes

—- EOF - GMER 1.0.15 —-

Attachments:

BTW, I noticed a lot of JBOSS files. JBOSS is the webserver that i use to run the Construction apps that I was telling you about. The program works as a webserver to hose access to the program which stores it's data in a MS SQL server. We use JBOSS because it's free :-) I know that most people probably don't have JBOSS on their machines. Hope this helps! Thanks again for your time. Nathan
Hello NathanH

Thank you for the logs.

Please work your way through the following steps. If you encounter any difficulties, come back and let me know.

  • Please disable Spybot Teatimer


    • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
    • On the left hand side, click "Tools", then click on the "Resident" icon in the list.
    • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active" box.
    • Click the "System Startup" icon in the List.
    • Uncheck the "TeaTimer" box and "OK" any prompts.
    • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
    • Exit Spybot S&D when done.

  • Please open OTL


    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
      O4 - HKLM..\Run: [] File not found
      O15 - HKCU\..Trusted Domains: lcgcm13web ([]http in Trusted sites)
      O15 - HKCU\..Trusted Domains: lcgpence.com ([p6] http in Trusted sites)
      O15 - HKCU\..Trusted Domains: oracle.com ([stconference] * in Trusted sites)
      O15 - HKCU\..Trusted Ranges: Range1 ([http] in Trusted sites)
      O16 - DPF: {00191E4B-49C2-48E2-A548-8F702D75622A} https://strtc.oracle.com/imtapp/res/jar/cnsload.cab (Reg Error: Value error.)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
      O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
      O33 - MountPoints2\{02f87f37-c83d-11de-8464-e43d4e8124d8}\Shell - "" = AutoRun
      O33 - MountPoints2\{02f87f37-c83d-11de-8464-e43d4e8124d8}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\H\Shell - "" = AutoRun
      O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Pl
      [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
      [2 C:\Documents and Settings\Nathan\*.tmp files -> C:\Documents and Settings\Nathan\*.tmp -> ]
      [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [start explorer]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

  • HelpAsst_mebroot_fix.exe


    • Please download HelpAsst_mebroot_fix.exe and save it to your desktop.
    • Close all other open programs and windows.
    • Double click the file to run it. Follow any prompts that you receive.
    • If the tool detects an mbr infection, please allow it to run mbr -f and shut down your computer.
    • Upon restarting, please wait about 5 minutes, the click on "Start", "Run" and type the following bolded command, then hit Enter.

    helpasst -mbrt

    • Note: Make sure you leave a space between helpasst and -mbrt!
    • When it completes, a log will open.
    • Please post the contents of that log.


    • In the event the tool does not detect an mbr infection and completes, click on "Start", "Run" and type the following bolded command, then hit Enter.

    mbr -f

    • Now, please perform the "Start", "Run", mbr -f command a second time.
    • Now shut down the computer (do not restart, but shut it down), wait a few minutes then start it back up.
    • Give it about 5 minutes, then click on "Start", "Run" and type the following bolded command, then hit Enter.

    helpasst -mbrt

    • Note: Make sure you leave a space between helpasst and -mbrt!
    • When it completes, a log will open.
    • Please post the contents of that log.

    **Important note to Dell users - fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not allow the tool to execute mbr -f nor execute the command manually, and you will either need to restore your computer to a factory state or allow your computer to remain having an infected mbr (the latter not recommended).

    Please post the OTL log and the HelpAsst_mebroot_fix log in your next reply.
Hey JonTom, I was able to to everything except for the following… Under the Disabling TeaTimer, I could not do the following: * Click the "System Startup" icon in the List. * Uncheck the "TeaTimer" box and "OK" any prompts. I didn't see any Teatimner in the System Startup items. Here is the OTL Fix log: All processes killed ========== OTL ========== No active process named explorer.exe was found! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\lcgcm13web\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\lcgpence.com\p6\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\oracle.com\stconference\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1\\http deleted successfully. Starting removal of ActiveX control {00191E4B-49C2-48E2-A548-8F702D75622A} C:\WINDOWS\Downloaded Program Files\cnsload.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00191E4B-49C2-48E2-A548-8F702D75622A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00191E4B-49C2-48E2-A548-8F702D75622A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{00191E4B-49C2-48E2-A548-8F702D75622A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00191E4B-49C2-48E2-A548-8F702D75622A}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. File Animation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab not found. Starting removal of ActiveX control DirectAnimation Java Classes Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\DirectAnimation Java Classes\ not found. File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found. Starting removal of ActiveX control Microsoft XML Parser for Java Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{02f87f37-c83d-11de-8464-e43d4e8124d8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02f87f37-c83d-11de-8464-e43d4e8124d8}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{02f87f37-c83d-11de-8464-e43d4e8124d8}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02f87f37-c83d-11de-8464-e43d4e8124d8}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ not found. C:\WINDOWS\002373_.tmp deleted successfully. C:\WINDOWS\005687_.tmp deleted successfully. C:\WINDOWS\SET3.tmp deleted successfully. C:\WINDOWS\SETA.tmp deleted successfully. C:\Documents and Settings\Nathan\cnsload_1259096521796.tmp deleted successfully. C:\Documents and Settings\Nathan\cnsload_1271107590687.tmp deleted successfully. C:\WINDOWS\System32\CONFIG.TMP deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41044 bytes User: HelpAssistant ->Temp folder emptied: 121346457 bytes ->Temporary Internet Files folder emptied: 199550329 bytes ->Java cache emptied: 22998000 bytes ->Flash cache emptied: 315677 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 34462 bytes User: Nathan ->Temp folder emptied: 7836136 bytes ->Temporary Internet Files folder emptied: 17000153 bytes ->Java cache emptied: 60086766 bytes ->Flash cache emptied: 2277549 bytes User: NetworkService ->Temp folder emptied: 163840 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 967851 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 139677 bytes RecycleBin emptied: 797808391 bytes Total Files Cleaned = 1,174.00 mb [EMPTYFLASH] User: All Users User: Default User ->Flash cache emptied: 0 bytes User: HelpAssistant ->Flash cache emptied: 0 bytes User: LocalService User: Nathan ->Flash cache emptied: 0 bytes User: NetworkService Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.4.1 log created on 05152010_101525 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Nathan\Local Settings\Temp\Perflib_Perfdata_d9c.dat not found! C:\WINDOWS\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-1864.log moved successfully. File move failed. C:\WINDOWS\temp\$$$dq3e scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\$67we.$ scheduled to be moved on reboot. C:\WINDOWS\temp\Perflib_Perfdata_c2c.dat moved successfully. File\Folder C:\WINDOWS\temp\Perflib_Perfdata_cd4.dat not found! Registry entries deleted on Reboot…
Here are the two help assist logs:

Help Assist Log #1:
C:\Documents and Settings\Nathan\Desktop\HelpAsst_mebroot_fix.exe
Sat 05/15/2010 at 10:38:02.62

HelpAssistant account Inactive

~~ Checking for termsrv32.dll ~~

termsrv32.dll present! ~ attempting to remove
Remove on reboot: C:\WINDOWS\system32\termsrv32.dll

~~ Checking firewall ports ~~

HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list

HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking mbr ~~

mbr infection detected! ~ running mbr -f

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\ACPI -> 0x898df998
NDIS: Broadcom 802.11a/b/g WLAN -> SendCompleteHandler -> 0x886fb5c0
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x025429800
malicious code @ sector 0x025429803 !
PE file found in sector at 0x025429819 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
original MBR restored successfully !

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\ACPI -> 0x898df998
NDIS: Broadcom 802.11a/b/g WLAN -> SendCompleteHandler -> 0x886fb5c0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
copy of MBR has been found in sector 0x025429800
malicious code @ sector 0x025429803 !
PE file found in sector at 0x025429819 !
Use "Recovery Console" command "fixmbr" to clear infection !

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on Sat 05/15/2010 at 10:50:01.50

Account active No
Local Group Memberships

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x025429800
malicious code @ sector 0x025429803 !
PE file found in sector at 0x025429819 !

~~ Checking for termsrv32.dll ~~

termsrv32.dll not found


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %systemroot%\System32\termsrv.dll

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking for HelpAssistant directories ~~

HelpAssistant

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


~~ EOF ~~


Help Assist Log #2:
C:\Documents and Settings\Nathan\Desktop\HelpAsst_mebroot_fix.exe
Sat 05/15/2010 at 10:38:02.62

HelpAssistant account Inactive

~~ Checking for termsrv32.dll ~~

termsrv32.dll present! ~ attempting to remove
Remove on reboot: C:\WINDOWS\system32\termsrv32.dll

~~ Checking firewall ports ~~

HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list

HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking mbr ~~

mbr infection detected! ~ running mbr -f

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\ACPI -> 0x898df998
NDIS: Broadcom 802.11a/b/g WLAN -> SendCompleteHandler -> 0x886fb5c0
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x025429800
malicious code @ sector 0x025429803 !
PE file found in sector at 0x025429819 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
original MBR restored successfully !

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\ACPI -> 0x898df998
NDIS: Broadcom 802.11a/b/g WLAN -> SendCompleteHandler -> 0x886fb5c0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
copy of MBR has been found in sector 0x025429800
malicious code @ sector 0x025429803 !
PE file found in sector at 0x025429819 !
Use "Recovery Console" command "fixmbr" to clear infection !

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on Sat 05/15/2010 at 10:50:01.50

Account active No
Local Group Memberships

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x025429800
malicious code @ sector 0x025429803 !
PE file found in sector at 0x025429819 !

~~ Checking for termsrv32.dll ~~

termsrv32.dll not found


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %systemroot%\System32\termsrv.dll

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking for HelpAssistant directories ~~

HelpAssistant

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


~~ EOF ~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on Sat 05/15/2010 at 11:04:04.50

Account active No
Local Group Memberships

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x025429800
malicious code @ sector 0x025429803 !
PE file found in sector at 0x025429819 !

~~ Checking for termsrv32.dll ~~

termsrv32.dll not found


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %systemroot%\System32\termsrv.dll

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking for HelpAssistant directories ~~

HelpAssistant

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


~~ EOF ~~
Hello NathanH

Thank you for the logs.

  • Please run the following Command


  • Click on "Start" and then on "Run".
  • Copy and Paste the following command into the Run box:

helpasst -folder


  • Click on "OK".
  • A log will be produced.
  • Please post this log in your next reply.
Thanks for your help JonTom, I followed your instructions and received the following reponse… The directory C:\DOCUME~1\HelpAssistant was found. Remove? When I hit yes, the program says "Please wait", but nothing happens. When I hit no, it says, "Done! Press any key to continue" and then the program terminates. What am I doing wrong? Thanks again! Nathan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI