This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Problems with Start-UP

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:27:48 AM, on 8/17/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask2.exe
C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\Common Files\AntiVirus\SBAMSvc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\D-Link AirPlus Xtreme G\AirPlus.exe
C:\Program Files\Cricket\Cricket Broadband 1.0\Cricket Broadband.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Jim Bromwell\Local Settings\Temporary Internet Files\Content.IE5\NI867ETZ\HiJackThis[1].exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.2.0.12\IPSBHO.DLL
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - Global Startup: D-Link AirPlus Xtreme G Configuration Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1231455143113
O17 - HKLM\System\CCS\Services\Tcpip\..\{D4AEBF4A-8CA5-4932-B919-AFE778C1B29A}: NameServer = 172.28.221.53 172.28.221.54
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Fix-It Task Manager - Avanquest North America, Inc. - C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: Fix-It (SBAMSvc) - Sunbelt Software - C:\Program Files\Common Files\AntiVirus\SBAMSvc.exe

–
End of file - 5373 bytes
Hello there, golfman8

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)

——————————————————————————————————

While waiting for more instructions, please describe the problems more precisely on bad startups you are experiencing from your computer.

——————————————————————————————————
I just takes forever to start. It seems like my HD will run for over an hour before it stops. I noticed today that SBAAM was taking over 142,000K and then I finally after 2.5 hours I got a timeout error. HELP!!!!
Hi,

Multiple AntiVirus Running

I see you have more than one Anti-Virus program installed, ( Norton 360 ) and ( Sunbelt AV ).

While this may seem like greater protection, it can cause problems including slowdowns, system hangs or even crashes. This can happen if both AntiVirus applications attempt to access the same file at the same time. This may cause the applications to interfere with each other, or cause the system to lock up. It can also be a drain on system resources, making a machine run slower than it should.

I would assume that your Norton 360 license is still valid (let me know if it's not) and therefore you are strongly urged to uninstall Sunbelt to prevent conflicts.

Any antivirus program must be removed via add/remove program.
For any program that doesn't have an add/remove entry, you will have to do this:

Re-install the program -> Reboot -> Uninstall

Once you have uninstall Sunbelt AV, please follow the link provided for a complete removal of the software.

http://www.sunbelt-software.com/ihs/cs&vclean.exe

A reboot is required for this.

===================================================

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
OTL log
GMER log

Good Day!
Yes, I definitly need help. I could not find and Sunbelt anti-virus on my add/remove programs. I see SBAMSvc.exe running in my task manager but cannot find out how to remove it. Plus it take about 30 minutes to get to the point that can open anything and the HD continues to run.
I found the Sunbelt file. It was in my Fix-it Utilities application. I remvoed it and here are the OTL.Txt file.


OTL logfile created on: 8/24/2010 8:48:06 AM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Jim Bromwell\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.00 Mb Total Physical Memory | 36.00 Mb Available Physical Memory | 14.00% Memory free
618.00 Mb Paging File | 138.00 Mb Available in Paging File | 22.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.59 Gb Total Space | 6.17 Gb Free Space | 33.16% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JIMLAPTOP
Current User Name: Jim Bromwell
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jim Bromwell\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
PRC - C:\Program Files\Norton 360\Engine\4.2.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\SkyGolf\SkyCaddie Desktop\CaddieSyncLauncher.exe (SkyHawke Inc.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Pure Networks, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Pure Networks, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\D-Link AirPlus Xtreme G\AIRPLUS.exe (D-Link)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jim Bromwell\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton 360\Engine\4.2.0.12\asoehook.dll (Symantec Corporation)
MOD - C:\Program Files\Norton 360\Engine\4.2.0.12\microsoft.vc90.crt\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton 360\Engine\4.2.0.12\microsoft.vc90.crt\msvcp90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (N360) – C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (nmraapache) – C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe (Pure Networks, Inc.)
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Pure Networks, Inc.)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()


========== Driver Services (SafeList) ==========

DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100810.004\BHDrvx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100823.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100823.002\NAVENG.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100820.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\N360\0402000.00C\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0402000.00C\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0402000.00C\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\N360\0402000.00C\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0402000.00C\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\N360\0402000.00C\ccHPx86.sys (Symantec Corporation)
DRV - (SBFWIMCL) – C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0402000.00C\SYMDS.SYS (Symantec Corporation)
DRV - (ATMFNVsp) – C:\WINDOWS\system32\drivers\ATMFNVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFCVsp) – C:\WINDOWS\system32\drivers\ATMFCVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFVsp) – C:\WINDOWS\system32\drivers\ATMFVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFMdm) – C:\WINDOWS\system32\drivers\ATMFMdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ATMFNET) – C:\WINDOWS\system32\drivers\ATMFNET.sys (DEVGURU Co., LTD.)
DRV - (ATMFBUS) – C:\WINDOWS\system32\drivers\ATMFBUS.sys (DEVGURU Co., LTD.)
DRV - (ATMFFLT) – C:\WINDOWS\system32\drivers\ATMFFLT.sys (DEVGURU Co., LTD.)
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (MxlW2k) – C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Pure Networks, Inc.)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Pure Networks, Inc.)
DRV - (SaiH0461) – C:\WINDOWS\system32\drivers\SaiH0461.sys (Saitek)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (D-Link )
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (slabbus) CP2101 USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\slabbus.sys (MCCI)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)
DRV - (ac97intc) Intel® 82801 Audio Driver Install Service (WDM) – C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (EL90XBC) – C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search…"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www2.counton2.com/"
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: playbox@toolbar:1.0.0
FF - prefs.js..keyword.URL: "http://playbox.toolbarhome.com/search.aspx?srch=ku&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/08/01 15:52:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/07/31 22:35:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/08 07:33:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/03 09:35:42 | 000,000,000 | —D | M]

[2009/03/03 12:49:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\Mozilla\Extensions
[2010/08/20 08:17:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\Mozilla\Firefox\Profiles\r7atxwgy.default\extensions
[2010/01/18 12:16:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jim Bromwell\Application Data\Mozilla\Firefox\Profiles\r7atxwgy.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/08/18 12:03:56 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Jim Bromwell\Application Data\Mozilla\Firefox\Profiles\r7atxwgy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/18 09:41:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\Mozilla\Firefox\Profiles\r7atxwgy.default\extensions\playbox@toolbar
[2010/01/18 09:41:33 | 000,001,586 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Application Data\Mozilla\Firefox\Profiles\r7atxwgy.default\searchplugins\web-search.xml
[2009/03/03 12:49:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2008/09/24 14:40:30 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.2.0.12\ipsbho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [CaddieSyncLauncher] C:\Program Files\SkyGolf\SkyCaddie Desktop\CaddieSyncLauncher.exe (SkyHawke Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Pure Networks, Inc.)
O4 - HKLM..\Run: [RCScheduleCheck] C:\Program Files\VCOM\Recovery Commander\RCSCHED.EXE (imagine LAN, Inc.)
O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\D-Link AirPlus Xtreme G Configuration Utility.lnk = C:\Program Files\D-Link AirPlus Xtreme G\AIRPLUS.exe (D-Link)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\D-Link REG Utility.lnk = C:\Program Files\D-Link AirPlus Xtreme G\Reg.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} http://www.srtest.com/srl_bin/sysreqlab_ind.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1231455143113 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Pure Networks, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {a5780613-492e-4a2a-a7fd-549610edf6cc} - C:\Program Files\VCOM\Recovery Commander\RCHOOK.DLL ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/08 10:17:20 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{bda1a2d0-9f03-11df-82dd-00065bd9d384}\Shell - "" = AutoRun
O33 - MountPoints2\{bda1a2d0-9f03-11df-82dd-00065bd9d384}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{bda1a2d0-9f03-11df-82dd-00065bd9d384}\Shell\AutoRun\command - "" = E:\start.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55182706186649600)

========== Files/Folders - Created Within 30 Days ==========

[2010/08/24 08:30:55 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jim Bromwell\Desktop\OTL.exe
[2010/08/24 07:21:05 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/08/23 16:32:21 | 000,000,000 | —D | C] – C:\Temp
[2010/08/20 10:58:19 | 000,067,800 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\SbFwIm.sys
[2010/08/19 16:25:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Jim Bromwell\Application Data\.kde
[2010/08/19 14:22:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Jim Bromwell\Desktop\New Folder
[2010/08/19 14:19:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Jim Bromwell\Application Data\KDE
[2010/08/19 14:18:24 | 000,000,000 | —D | C] – C:\Program Files\KDE
[2010/08/18 15:23:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Jim Bromwell\My Documents\New Folder
[2010/08/18 13:22:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Jim Bromwell\My Documents\Hijackthis
[2010/08/18 12:18:28 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/18 12:16:07 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Jim Bromwell\Desktop\HijackThis.exe
[2010/08/17 10:09:02 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Jim Bromwell\My Documents\HiJackThis.exe
[2010/08/17 07:05:49 | 000,000,000 | —D | C] – C:\Program Files\SystemRequirementsLab
[2010/08/16 15:55:50 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Bootvis
[2010/08/16 10:37:53 | 000,000,000 | —D | C] – C:\Program Files\Safer Networking
[2010/08/14 18:07:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Jim Bromwell\Application Data\IObit
[2010/08/14 18:07:09 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2010/08/14 10:23:32 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/08/14 10:23:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/08/14 10:10:48 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Jim Bromwell\Desktop\spybotsd162.exe
[2010/08/11 13:43:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Jim Bromwell\My Documents\Quicken
[2010/08/11 11:48:36 | 004,199,784 | —- | C] (Amyuni Technologies
http://www.amyuni.com) – C:\WINDOWS\System32\cdintf400.dll
[2010/08/11 11:43:46 | 000,000,000 | —D | C] – C:\Program Files\Quicken
[2010/08/11 11:43:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Jim Bromwell\Application Data\Intuit
[2010/08/10 10:02:58 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/10 10:02:49 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/10 10:02:49 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/10 09:23:26 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Jim Bromwell\Desktop\mbam-setup-1.46.exe
[2010/08/10 08:23:56 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/08/10 08:20:56 | 003,420,304 | —- | C] (Piriform Ltd) – C:\Documents and Settings\Jim Bromwell\Desktop\ccsetup234.exe
[2010/08/10 05:19:55 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/08/07 23:49:38 | 000,486,144 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\officexp-kb892841-client-enu.exe
[2010/08/06 22:43:00 | 123,368,360 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\Office2003SP3-KB923618-FullFile-ENU.exe
[2010/08/04 21:07:07 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Events
[2010/08/03 13:22:50 | 000,024,192 | —- | C] (Bytemobile, Inc.) – C:\WINDOWS\System32\drivers\tcpipBM.sys
[2010/08/03 13:22:50 | 000,013,184 | —- | C] (Bytemobile, Inc.) – C:\WINDOWS\System32\drivers\BMLoad.sys
[2010/08/03 13:22:49 | 000,013,712 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sporder.dll
[2010/08/03 13:22:48 | 000,724,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bmutil.dll
[2010/08/03 13:22:47 | 000,480,384 | —- | C] (Bytemobile, Inc.) – C:\WINDOWS\System32\bmnet.dll
[2010/08/03 13:22:46 | 000,312,448 | —- | C] (Bytemobile, Inc.) – C:\WINDOWS\System32\bminstall.dll
[2010/08/03 13:22:46 | 000,132,224 | —- | C] (Bytemobile, Inc.) – C:\WINDOWS\System32\bmdumpd.bin
[2010/08/03 13:09:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Jim Bromwell\Application Data\Cricket
[2010/08/03 09:39:57 | 000,013,312 | —- | C] (DEVGURU Co., LTD.) – C:\WINDOWS\System32\drivers\ATMFFLT.sys
[2010/08/03 09:39:55 | 000,153,472 | —- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) – C:\WINDOWS\System32\drivers\ATMFVsp.sys
[2010/08/03 09:39:53 | 000,103,424 | —- | C] (DEVGURU Co., LTD.) – C:\WINDOWS\System32\drivers\ATMFNET.sys
[2010/08/03 09:39:51 | 000,153,600 | —- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) – C:\WINDOWS\System32\drivers\ATMFNVsp.sys
[2010/08/03 09:39:49 | 000,153,600 | —- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) – C:\WINDOWS\System32\drivers\ATMFCVsp.sys
[2010/08/03 09:39:47 | 000,153,472 | —- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) – C:\WINDOWS\System32\drivers\ATMFMdm.sys
[2010/08/03 09:39:42 | 000,047,360 | —- | C] (DEVGURU Co., LTD.) – C:\WINDOWS\System32\drivers\ATMFBUS.sys
[2010/08/03 09:39:28 | 000,319,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\DIFxAPI.dll
[2010/08/03 09:36:17 | 000,000,000 | —D | C] – C:\Program Files\Cricket
[2010/08/01 17:14:01 | 035,677,984 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\USMoneyDlxSunset.exe
[2010/08/01 07:21:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Jim Bromwell\Desktop\Autoruns
[2010/08/01 06:03:43 | 000,339,504 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0402000.00C\symtdiv.sys
[2010/08/01 06:03:42 | 000,361,904 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0402000.00C\symtdi.sys
[2010/08/01 06:03:41 | 000,328,752 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0402000.00C\symds.sys
[2010/08/01 06:03:41 | 000,173,104 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.sys
[2010/08/01 06:03:40 | 000,325,680 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.sys
[2010/08/01 06:03:40 | 000,043,696 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.sys
[2010/08/01 06:03:39 | 000,116,784 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0402000.00C\ironx86.sys
[2010/08/01 06:03:38 | 000,501,888 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0402000.00C\cchpx86.sys
[2010/08/01 06:01:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360\0402000.00C
[2010/07/31 22:34:19 | 000,107,368 | R— | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2010/07/31 22:32:45 | 000,060,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/07/31 22:32:44 | 000,124,976 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/07/31 22:32:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/07/31 22:32:42 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/07/31 22:28:26 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360
[2010/07/31 22:27:51 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2010/07/31 22:27:50 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2010/07/31 22:27:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Norton
[2010/07/31 22:20:23 | 132,049,776 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\TT_165_SYMTB_CNET.exe
[2010/07/31 17:44:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/07/31 17:44:17 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2010/07/28 17:34:48 | 000,000,000 | —D | C] – C:\Program Files\MiShellSoft
[2010/07/27 06:24:10 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/07/25 20:51:26 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Money Plus
[2010/07/25 12:50:21 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/25 12:47:22 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/24 08:47:17 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/24 08:31:22 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jim Bromwell\Desktop\OTL.exe
[2010/08/24 08:12:15 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/24 08:12:13 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/24 08:11:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/24 08:09:57 | 002,883,584 | —- | M] () – C:\Documents and Settings\Jim Bromwell\ntuser.dat
[2010/08/24 08:09:57 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Jim Bromwell\ntuser.ini
[2010/08/24 08:09:40 | 006,936,816 | -H– | M] () – C:\Documents and Settings\Jim Bromwell\Local Settings\Application Data\IconCache.db
[2010/08/24 06:38:06 | 000,000,320 | —- | M] () – C:\WINDOWS\tasks\Scheduled Checkpoint.job
[2010/08/23 15:26:11 | 000,432,924 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/23 15:26:10 | 000,067,714 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/23 15:26:08 | 000,508,956 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/23 14:59:01 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/23 14:58:54 | 000,633,956 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\Cat.DB
[2010/08/20 10:12:16 | 000,002,557 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\Cricket Broadband.lnk
[2010/08/20 09:43:50 | 000,000,573 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/20 09:43:50 | 000,000,256 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/20 09:43:50 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/20 08:27:28 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/19 14:16:42 | 002,073,088 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\kdewin-installer-gui-latest.exe
[2010/08/18 15:16:05 | 000,002,461 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\HiJackThis.lnk
[2010/08/18 12:16:08 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jim Bromwell\Desktop\HijackThis.exe
[2010/08/18 12:15:39 | 001,402,880 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\HiJackThis.msi
[2010/08/17 10:09:19 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jim Bromwell\My Documents\HiJackThis.exe
[2010/08/16 16:55:58 | 000,001,917 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/14 20:49:07 | 000,247,904 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/14 18:13:36 | 000,000,160 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\IObit Freeware.url
[2010/08/14 18:13:35 | 000,000,892 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/08/14 18:13:27 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2010/08/14 10:25:00 | 000,000,951 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/14 10:24:56 | 000,000,933 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\Spybot - Search & Destroy.lnk
[2010/08/14 10:11:32 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Jim Bromwell\Desktop\spybotsd162.exe
[2010/08/14 10:02:59 | 017,215,488 | —- | M] () – C:\Documents and Settings\Jim Bromwell\My Money.mny
[2010/08/14 10:02:59 | 000,000,256 | —- | M] () – C:\Documents and Settings\Jim Bromwell\My Money.lrd
[2010/08/11 11:48:21 | 000,001,569 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Quicken Starter Edition 2010.lnk
[2010/08/11 11:48:20 | 000,000,240 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Free Credit Report and Score.url
[2010/08/11 11:47:21 | 000,000,120 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2010/08/10 10:03:16 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/10 09:24:22 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Jim Bromwell\Desktop\mbam-setup-1.46.exe
[2010/08/10 08:24:10 | 000,000,682 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\CCleaner.lnk
[2010/08/10 08:20:56 | 003,420,304 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Jim Bromwell\Desktop\ccsetup234.exe
[2010/08/07 23:49:43 | 000,486,144 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\officexp-kb892841-client-enu.exe
[2010/08/06 22:45:06 | 123,368,360 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\Office2003SP3-KB923618-FullFile-ENU.exe
[2010/08/06 22:14:59 | 003,469,312 | —- | M] () – C:\Documents and Settings\Jim Bromwell\My Documents\My Money.mny
[2010/08/03 21:20:57 | 019,702,854 | R— | M] () – C:\My Money Backup_2010-08-03_212023.mbf
[2010/08/03 13:14:34 | 015,983,616 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Cricket Broadband Setup-v1.0 (build 1950).msi
[2010/08/03 09:42:55 | 000,000,012 | —- | M] () – C:\WINDOWS\sms.db
[2010/08/02 21:50:10 | 003,145,728 | —- | M] () – C:\Documents and Settings\Jim Bromwell\ntuser.BAK
[2010/08/01 17:15:30 | 035,677,984 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\USMoneyDlxSunset.exe
[2010/08/01 08:38:53 | 000,001,900 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/08/01 07:17:19 | 000,618,945 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\Autoruns.zip
[2010/07/31 22:32:43 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/07/31 22:32:43 | 000,007,443 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/07/31 22:32:43 | 000,000,805 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/07/31 22:32:42 | 000,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/07/31 22:24:52 | 132,049,776 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\TT_165_SYMTB_CNET.exe
[2010/07/30 05:39:50 | 018,367,230 | R— | M] () – C:\My Money Backup_2010-07-30_053903.mbf
[2010/07/29 06:11:22 | 000,001,757 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2010/07/28 17:46:07 | 000,001,666 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\Budget.lnk
[2010/07/27 08:06:49 | 019,022,750 | R— | M] () – C:\My Money Backup_2010-07-27_080607.mbf
[2010/07/27 07:26:55 | 000,001,010 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\Money Plus (2).lnk
[2010/07/27 02:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/20 09:43:32 | 000,000,533 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\D-Link AirPlus Xtreme G Configuration Utility.lnk
[2010/08/20 09:43:24 | 000,000,513 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\D-Link REG Utility.lnk
[2010/08/20 09:43:18 | 000,001,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2010/08/20 09:43:13 | 000,001,660 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2010/08/19 14:16:18 | 002,073,088 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\kdewin-installer-gui-latest.exe
[2010/08/18 12:18:38 | 000,002,461 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\HiJackThis.lnk
[2010/08/18 12:15:19 | 001,402,880 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\HiJackThis.msi
[2010/08/18 07:56:14 | 000,001,757 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2010/08/14 20:27:57 | 002,883,584 | —- | C] () – C:\Documents and Settings\Jim Bromwell\ntuser.dat
[2010/08/14 18:13:36 | 000,000,160 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\IObit Freeware.url
[2010/08/14 18:13:34 | 000,000,892 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/08/14 18:13:25 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2010/08/14 18:08:08 | 000,001,917 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/08/14 10:24:57 | 000,000,951 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/14 10:24:52 | 000,000,933 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\Spybot - Search & Destroy.lnk
[2010/08/14 08:38:10 | 000,000,256 | —- | C] () – C:\Documents and Settings\Jim Bromwell\My Money.lrd
[2010/08/11 11:48:20 | 000,001,569 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Quicken Starter Edition 2010.lnk
[2010/08/11 11:48:20 | 000,000,240 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Free Credit Report and Score.url
[2010/08/11 11:43:24 | 000,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2010/08/10 10:03:15 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/10 08:24:08 | 000,000,682 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\CCleaner.lnk
[2010/08/06 22:15:48 | 017,215,488 | —- | C] () – C:\Documents and Settings\Jim Bromwell\My Money.mny
[2010/08/04 06:00:52 | 000,000,803 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\Internet Explorer.lnk
[2010/08/03 21:20:55 | 019,702,854 | R— | C] () – C:\My Money Backup_2010-08-03_212023.mbf
[2010/08/03 13:16:52 | 015,983,616 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Cricket Broadband Setup-v1.0 (build 1950).msi
[2010/08/03 09:42:55 | 000,000,012 | —- | C] () – C:\WINDOWS\sms.db
[2010/08/03 09:37:31 | 000,002,557 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\Cricket Broadband.lnk
[2010/08/03 08:16:55 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/01 08:37:14 | 000,633,956 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\Cat.DB
[2010/08/01 07:17:13 | 000,618,945 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\Autoruns.zip
[2010/08/01 06:03:42 | 000,007,787 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\symnetv.cat
[2010/08/01 06:03:42 | 000,007,368 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\symnet.cat
[2010/08/01 06:03:42 | 000,001,473 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\symnetv.inf
[2010/08/01 06:03:42 | 000,001,445 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\symnet.inf
[2010/08/01 06:03:41 | 000,007,873 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.cat
[2010/08/01 06:03:41 | 000,007,425 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\symds.cat
[2010/08/01 06:03:41 | 000,003,373 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.inf
[2010/08/01 06:03:41 | 000,002,793 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\symds.inf
[2010/08/01 06:03:40 | 000,007,442 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.cat
[2010/08/01 06:03:40 | 000,001,388 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.inf
[2010/08/01 06:03:40 | 000,001,382 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.inf
[2010/08/01 06:03:39 | 000,007,438 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.cat
[2010/08/01 06:03:39 | 000,007,438 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\iron.cat
[2010/08/01 06:03:39 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\iron.inf
[2010/08/01 06:03:38 | 000,007,396 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\cchpx86.cat
[2010/08/01 06:03:38 | 000,001,754 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\cchpx86.inf
[2010/08/01 06:01:57 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0402000.00C\isolate.ini
[2010/07/31 22:32:44 | 000,007,443 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/07/31 22:32:44 | 000,000,805 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/07/31 22:31:46 | 000,001,900 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/07/30 05:39:48 | 018,367,230 | R— | C] () – C:\My Money Backup_2010-07-30_053903.mbf
[2010/07/28 17:46:07 | 000,001,666 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\Budget.lnk
[2010/07/27 08:06:45 | 019,022,750 | R— | C] () – C:\My Money Backup_2010-07-27_080607.mbf
[2010/07/27 07:26:55 | 000,001,010 | —- | C] () – C:\Documents and Settings\Jim Bromwell\Desktop\Money Plus (2).lnk
[2010/07/25 20:56:08 | 003,469,312 | —- | C] () – C:\Documents and Settings\Jim Bromwell\My Documents\My Money.mny
[2010/01/22 19:08:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/03/26 11:47:30 | 001,052,672 | —- | C] () – C:\WINDOWS\System32\SaiC0461.Dll
[2008/03/26 11:47:30 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\SaiC0461_0C.dll
[2008/03/26 11:47:30 | 000,008,192 | —- | C] () – C:\WINDOWS\System32\SaiC0461_10.dll
[2008/03/26 11:47:30 | 000,008,192 | —- | C] () – C:\WINDOWS\System32\SaiC0461_0A.dll
[2008/03/26 11:47:30 | 000,008,192 | —- | C] () – C:\WINDOWS\System32\SaiC0461_07.dll
[2008/03/26 11:47:30 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\SaiC0461_09.dll
[2008/03/26 11:47:30 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\SaiC0461_0402.dll
[2008/03/26 11:47:30 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\SaiC0461_11.dll
[2004/08/04 06:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 06:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 06:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 06:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 06:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/04/23 15:17:02 | 000,000,061 | —- | C] () – C:\WINDOWS\System32\uninstall.ini

========== LOP Check ==========

[2009/10/12 06:20:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avanquest
[2010/03/16 12:17:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/01/09 13:08:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/01/24 13:18:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Saitek
[2010/01/20 14:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SkyGolf
[2010/01/18 12:10:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/08/19 16:25:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\.kde
[2009/10/12 08:06:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\Avanquest
[2010/08/03 13:09:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\Cricket
[2010/01/18 12:23:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\GARMIN
[2010/08/15 08:33:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\IObit
[2010/08/19 14:19:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\KDE
[2010/03/16 11:23:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\Sammsoft
[2010/01/20 14:50:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\SkyGolf
[2009/03/03 19:12:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Jim Bromwell\Application Data\VCOM
[2010/08/24 06:38:06 | 000,000,320 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Checkpoint.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/01/08 10:17:20 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/03/03 19:06:21 | 000,000,053 | -HS- | M] () – C:\boot.inh
[2010/08/20 09:43:50 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/01/08 10:17:20 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2009/01/08 10:17:20 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/08 10:17:20 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/07/27 08:06:49 | 019,022,750 | R— | M] () – C:\My Money Backup_2010-07-27_080607.mbf
[2010/07/30 05:39:50 | 018,367,230 | R— | M] () – C:\My Money Backup_2010-07-30_053903.mbf
[2010/08/03 21:20:57 | 019,702,854 | R— | M] () – C:\My Money Backup_2010-08-03_212023.mbf
[2009/01/08 17:45:47 | 000,000,950 | —- | M] () – C:\net_save.dna
[2009/03/03 19:06:21 | 000,000,053 | -HS- | M] () – C:\ntdetect.col
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/03/03 19:06:21 | 000,000,053 | -HS- | M] () – C:\ntldp
[2009/01/08 19:47:37 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/24 08:11:48 | 402,653,184 | -HS- | M] () – C:\pagefile.sys
[2010/08/24 06:36:43 | 000,000,264 | —- | M] () – C:\RCINFO.TXT
[2009/03/03 19:06:21 | 000,000,000 | —- | M] () – C:\SFCFILES.TXT
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/01/08 10:16:11 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/01/08 18:12:05 | 000,001,706 | -H– | M] () – C:\Documents and Settings\Jim Bromwell\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/01/08 04:38:39 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/08 04:38:39 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/08 04:38:38 | 000,880,640 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/01/08 19:59:03 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/01/08 21:24:36 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Jim Bromwell\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/01/08 10:28:49 | 000,000,079 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/10/13 07:44:42 | 003,097,280 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Jim Bromwell\Desktop\A13-I41.EXE
[2010/03/16 11:17:43 | 005,153,344 | —- | M] (Sammsoft ) – C:\Documents and Settings\Jim Bromwell\Desktop\ARO2010_mt.exe
[2010/03/16 11:53:20 | 000,891,248 | —- | M] (AVG Technologies) – C:\Documents and Settings\Jim Bromwell\Desktop\avg_free_stb_all_9_40_cnet.exe
[2010/01/20 14:38:41 | 005,185,400 | —- | M] (SkyHawke Technologies, LLC) – C:\Documents and Settings\Jim Bromwell\Desktop\CaddieSyncSetupE.exe
[2010/08/10 08:20:56 | 003,420,304 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Jim Bromwell\Desktop\ccsetup234.exe
[2010/08/18 12:16:08 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jim Bromwell\Desktop\HijackThis.exe
[2009/03/03 13:08:11 | 001,878,888 | —- | M] (Adobe Systems Incorporated) – C:\Documents and Settings\Jim Bromwell\Desktop\install_flash_player.exe
[2010/08/19 14:16:42 | 002,073,088 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\kdewin-installer-gui-latest.exe
[2010/01/18 15:14:03 | 001,027,072 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\mapupload.exe
[2010/08/10 09:24:22 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Jim Bromwell\Desktop\mbam-setup-1.46.exe
[2009/03/03 13:10:18 | 002,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Jim Bromwell\Desktop\mbam-setup.exe
[2010/08/06 22:45:06 | 123,368,360 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\Office2003SP3-KB923618-FullFile-ENU.exe
[2010/08/07 23:49:43 | 000,486,144 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\officexp-kb892841-client-enu.exe
[2010/08/24 08:31:22 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jim Bromwell\Desktop\OTL.exe
[2009/03/03 17:53:47 | 001,332,417 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\quickwiper_wizard.exe
[2010/08/14 10:11:32 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Jim Bromwell\Desktop\spybotsd162.exe
[2009/04/09 12:21:44 | 006,237,728 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\SUPERAntiSpyware.exe
[2010/07/31 22:24:52 | 132,049,776 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\TT_165_SYMTB_CNET.exe
[2010/08/01 17:15:30 | 035,677,984 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Jim Bromwell\Desktop\USMoneyDlxSunset.exe
[2010/01/18 11:53:34 | 014,452,040 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\winzip140.exe
[2010/01/18 10:33:50 | 001,362,010 | —- | M] () – C:\Documents and Settings\Jim Bromwell\Desktop\wrar391.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-17 19:59:26
< End of report >
Here are the Extra.Txt files.
Thanks again for your help.


OTL Extras logfile created on: 8/24/2010 8:48:07 AM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Jim Bromwell\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.00 Mb Total Physical Memory | 36.00 Mb Available Physical Memory | 14.00% Memory free
618.00 Mb Paging File | 138.00 Mb Available in Paging File | 22.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.59 Gb Total Space | 6.17 Gb Free Space | 33.16% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JIMLAPTOP
Current User Name: Jim Bromwell
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [File Finder…] – C:\Program Files\VCOM\PowerDesk\pdfind.exe /PATH:%1 (V Communications, Inc.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [QuickWiper] – "C:\Program Files\QuickWiper\QuickWiper.exe" "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2B9B1B9E-45E5-4A76-9CA8-E06F897A3201}" = Cricket Broadband 1.0
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{52A5F706-2FCC-4C14-9E9A-345C2DCB25E9}" = D-Link AirPlus Xtreme G Adapter
"{578B6EF9-119B-4FB8-8377-7DAFA9588B97}" = Network Magic
"{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{7F1B3341-A94E-4F5C-B587-CA0EB964221E}" = Microsoft Money Shared Libraries
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{9DBCF56A-CDF0-41bf-BE0F-E00A88B18F56}" = Cricket EVDO Modem
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C084BC61-E537-11DE-8616-005056806466}" = Google Earth
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9507D0D-1A9C-486E-91D6-33A71CCA55F2}" = Pure Networks Platform
"{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}" = WinZip 14.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"CCleaner" = CCleaner
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Flight Simulator 9.0" = Microsoft Flight Simulator 2004 A Century of Flight
"Google Chrome" = Google Chrome
"ie8" = Windows Internet Explorer 8
"InstallShield_{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MiShell_Budget" = MiShell*Budget (remove only)
"Money2008b" = Microsoft Money Plus
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"N360" = Norton 360
"Network MagicUninstall" = Network Magic
"PowerDesk5.0" = PowerDesk 5.0
"QuickWiper" = QuickWiper
"QuickWiper_is1" = QuickWiper 7.8
"Recovery Commander" = Recovery Commander
"SkyCaddieDesktop" = SkyCaddie Desktop
"SystemRequirementsLab" = System Requirements Lab
"TurboTax 2008" = TurboTax 2008
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"309a46b1dc89b774" = Dell Driver Download Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/20/2010 11:05:05 AM | Computer Name = JIMLAPTOP | Source = Application Error | ID = 1001
Description = Fault bucket 754673369.

Error - 8/20/2010 11:06:15 AM | Computer Name = JIMLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module pdshext.dll, version 5.0.1.3, fault address 0x000197f3.

Error - 8/23/2010 3:01:41 PM | Computer Name = JIMLAPTOP | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 8/23/2010 3:19:44 PM | Computer Name = JIMLAPTOP | Source = WmiAdapter | ID = 4099
Description = Open of service failed.

Error - 8/23/2010 4:43:25 PM | Computer Name = JIMLAPTOP | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 8/24/2010 6:25:15 AM | Computer Name = JIMLAPTOP | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 8/24/2010 6:30:18 AM | Computer Name = JIMLAPTOP | Source = WmiAdapter | ID = 4099
Description = Open of service failed.

Error - 8/24/2010 7:08:33 AM | Computer Name = JIMLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module pdshext.dll, version 5.0.1.3, fault address 0x000197f3.

Error - 8/24/2010 7:37:13 AM | Computer Name = JIMLAPTOP | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 8/24/2010 8:16:41 AM | Computer Name = JIMLAPTOP | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

[ System Events ]
Error - 8/24/2010 7:28:43 AM | Computer Name = JIMLAPTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 8/24/2010 7:28:43 AM | Computer Name = JIMLAPTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 8/24/2010 7:28:43 AM | Computer Name = JIMLAPTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 8/24/2010 7:31:59 AM | Computer Name = JIMLAPTOP | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1058

Error - 8/24/2010 7:31:59 AM | Computer Name = JIMLAPTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Update Service
(gupdate) service to connect.

Error - 8/24/2010 7:31:59 AM | Computer Name = JIMLAPTOP | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
the following error: %%1053

Error - 8/24/2010 8:13:12 AM | Computer Name = JIMLAPTOP | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1058

Error - 8/24/2010 8:13:12 AM | Computer Name = JIMLAPTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Update Service
(gupdate) service to connect.

Error - 8/24/2010 8:13:12 AM | Computer Name = JIMLAPTOP | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
the following error: %%1053

Error - 8/24/2010 8:15:39 AM | Computer Name = JIMLAPTOP | Source = Service Control Manager | ID = 7022
Description = The Pure Networks Platform Service service hung on starting.


< End of report >
Here is the Gmer.txt document.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-24 09:34:11
Windows 5.1.2600 Service Pack 3
Running: 4ow97bxy.exe; Driver: C:\DOCUME~1\JIMBRO~1\LOCALS~1\Temp\uxldrpod.sys


—- System - GMER 1.0.15 —-

SSDT 819DE768 ZwAlertResumeThread
SSDT 819DE848 ZwAlertThread
SSDT 81A50C18 ZwAllocateVirtualMemory
SSDT 81997570 ZwAssignProcessToJobObject
SSDT 81A4ABF8 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xF4280210]
SSDT 81973578 ZwCreateMutant
SSDT 819973B0 ZwCreateSymbolicLinkObject
SSDT 816956C8 ZwCreateThread
SSDT 8197F748 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xF4280490]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xF42809F0]
SSDT 819EB090 ZwDuplicateObject
SSDT 81877008 ZwFreeVirtualMemory
SSDT 81973668 ZwImpersonateAnonymousToken
SSDT 819DE668 ZwImpersonateThread
SSDT 819A6660 ZwLoadDriver
SSDT 81877260 ZwMapViewOfSection
SSDT 81973498 ZwOpenEvent
SSDT 819EB270 ZwOpenProcess
SSDT 81A50D08 ZwOpenProcessToken
SSDT 8197F970 ZwOpenSection
SSDT 819EB180 ZwOpenThread
SSDT 819974A0 ZwProtectVirtualMemory
SSDT 8197ACA8 ZwResumeThread
SSDT 8197AF48 ZwSetContextThread
SSDT 81877090 ZwSetInformationProcess
SSDT 8197F828 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xF4280C40]
SSDT 819733B8 ZwSuspendProcess
SSDT 8197AD88 ZwSuspendThread
SSDT 81BD4BB8 ZwTerminateProcess
SSDT 8197AE68 ZwTerminateThread
SSDT 81877180 ZwUnmapViewOfSection
SSDT 81A50B28 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
? C:\DOCUME~1\JIMBRO~1\LOCALS~1\Temp\uxldrpob.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[2852] ntdll.dll!RtlValidateUnicodeString + 554 7C9163BE 10 Bytes JMP 03A0003A
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215501 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9AD5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD135 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254666 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4B6F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4AA1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4B0C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4972 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E49D4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4BD2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4A36 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] ole32.dll!OleInitialize + E37 77500521 7 Bytes JMP 03A000F3
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] ole32.dll!CoImpersonateClient + 51 775156C0 7 Bytes JMP 03A001A9
.text C:\Program Files\Internet Explorer\iexplore.exe[2852] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4EF0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215501 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4B6F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4AA1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4B0C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4972 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E49D4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4BD2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4A36 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device F2B79D20

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi,

Apologize for the late reply.

Download Combofix from any of the links below but rename it to ConspireCF before saving it to your desktop.

Link 1
Link 2


==================================

Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Conspire, it did not let me rename it before saving it to the desktop. Sorry, Thanks for your HELP>

ComboFix 10-08-26.02 - Jim Bromwell 08/26/2010 16:18:49.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.255.95 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Install.exe
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\uninstall.exe

.
((((((((((((((((((((((((( Files Created from 2010-07-26 to 2010-08-26 )))))))))))))))))))))))))))))))
.

2010-08-23 20:32 . 2010-08-24 12:12 ——– d—–w- C:\Temp
2010-08-20 14:58 . 2010-01-14 09:42 67800 —-a-w- c:\windows\system32\drivers\SbFwIm.sys
2010-08-19 20:25 . 2010-08-19 20:25 ——– d—–w- c:\documents and settings\Jim Bromwell\Application Data\.kde
2010-08-19 18:19 . 2010-08-19 18:19 ——– d—–w- c:\documents and settings\Jim Bromwell\Application Data\KDE
2010-08-19 18:18 . 2010-08-19 20:16 ——– d—–w- c:\program files\KDE
2010-08-18 16:18 . 2010-08-18 16:18 ——– d—–w- c:\program files\Trend Micro
2010-08-17 11:08 . 2010-08-17 11:08 ——– d—–w- c:\windows\system32\wbem\Repository
2010-08-17 11:05 . 2010-08-17 11:05 ——– d—–w- c:\program files\SystemRequirementsLab
2010-08-16 19:55 . 2010-08-17 11:05 ——– d—–w- c:\program files\Microsoft Bootvis
2010-08-16 14:37 . 2010-08-16 14:37 ——– d—–w- c:\program files\Safer Networking
2010-08-15 09:31 . 2010-08-15 09:31 ——– d—–w- c:\documents and settings\LocalService\IETldCache
2010-08-14 22:07 . 2010-08-15 12:33 ——– d—–w- c:\documents and settings\Jim Bromwell\Application Data\IObit
2010-08-14 22:07 . 2010-08-14 22:07 ——– d—–w- c:\program files\IObit
2010-08-14 14:23 . 2010-08-17 11:10 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-08-14 14:23 . 2010-08-14 21:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-11 15:48 . 2010-01-13 14:30 4199784 —-a-w- c:\windows\system32\cdintf400.dll
2010-08-11 15:43 . 2010-08-11 15:48 ——– d—–w- c:\program files\Quicken
2010-08-11 15:43 . 2010-08-11 15:43 ——– d—–w- c:\documents and settings\Jim Bromwell\Application Data\Intuit
2010-08-10 14:02 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-10 14:02 . 2010-08-10 14:03 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-10 14:02 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-10 12:23 . 2010-08-10 12:24 ——– d—–w- c:\program files\CCleaner
2010-08-10 09:17 . 2010-08-10 09:17 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2010-08-10 01:36 . 2010-08-10 01:36 ——– d—–w- c:\documents and settings\Administrator\Application Data\Avanquest
2010-08-10 01:34 . 2010-08-10 01:34 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-08-10 01:34 . 2010-08-10 01:34 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-08-05 01:07 . 2010-08-05 01:07 ——– d—–w- c:\windows\system32\Events
2010-08-03 17:22 . 2009-10-20 07:24 24192 —-a-w- c:\windows\system32\drivers\tcpipBM.sys
2010-08-03 17:22 . 2009-10-20 07:24 13184 —-a-w- c:\windows\system32\drivers\BMLoad.sys
2010-08-03 17:22 . 2009-10-20 07:24 13712 —-a-w- c:\windows\system32\sporder.dll
2010-08-03 17:22 . 2009-10-20 07:24 724608 —-a-w- c:\windows\system32\bmutil.dll
2010-08-03 17:22 . 2009-10-20 07:24 480384 —-a-w- c:\windows\system32\bmnet.dll
2010-08-03 17:22 . 2009-10-20 07:24 312448 —-a-w- c:\windows\system32\bminstall.dll
2010-08-03 17:22 . 2009-10-20 07:24 132224 —-a-w- c:\windows\system32\bmdumpd.bin
2010-08-03 17:16 . 2010-08-03 17:14 15983616 —-a-w- c:\documents and settings\Jim Bromwell\Cricket Broadband Setup-v1.0 (build 1950).msi
2010-08-03 17:09 . 2010-08-03 17:09 ——– d—–w- c:\documents and settings\Jim Bromwell\Application Data\Cricket
2010-08-03 13:39 . 2009-10-01 10:51 13312 —-a-w- c:\windows\system32\drivers\ATMFFLT.sys
2010-08-03 13:39 . 2009-10-01 10:51 153472 —-a-w- c:\windows\system32\drivers\ATMFVsp.sys
2010-08-03 13:39 . 2009-10-01 10:51 103424 —-a-w- c:\windows\system32\drivers\ATMFNET.sys
2010-08-03 13:39 . 2009-10-01 10:51 153600 —-a-w- c:\windows\system32\drivers\ATMFNVsp.sys
2010-08-03 13:39 . 2009-10-01 10:51 153600 —-a-w- c:\windows\system32\drivers\ATMFCVsp.sys
2010-08-03 13:39 . 2009-10-01 10:51 153472 —-a-w- c:\windows\system32\drivers\ATMFMdm.sys
2010-08-03 13:39 . 2009-10-01 10:51 47360 —-a-w- c:\windows\system32\drivers\ATMFBUS.sys
2010-08-03 13:39 . 2008-07-01 21:48 319456 —-a-w- c:\windows\system32\DIFxAPI.dll
2010-08-03 13:36 . 2010-08-03 13:39 ——– d—–w- c:\program files\Cricket
2010-08-03 12:16 . 2010-08-20 12:27 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-08-01 02:34 . 2008-04-17 21:12 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2010-08-01 02:34 . 2009-05-18 22:17 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-08-01 02:32 . 2010-08-01 02:32 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2010-08-01 02:32 . 2010-08-01 02:32 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-08-01 02:32 . 2010-08-01 13:17 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-08-01 02:32 . 2010-08-01 02:32 ——– d—–w- c:\program files\Symantec
2010-08-01 02:28 . 2010-08-01 12:41 ——– d—–w- c:\windows\system32\drivers\N360
2010-08-01 02:27 . 2010-08-01 02:28 ——– d—–w- c:\program files\Norton 360
2010-08-01 02:27 . 2010-08-01 02:27 ——– d—–w- c:\program files\Windows Sidebar
2010-08-01 02:27 . 2010-08-01 02:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-07-31 21:44 . 2010-08-01 02:27 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-07-31 21:44 . 2010-08-01 02:26 ——– d—–w- c:\program files\NortonInstaller
2010-07-28 21:34 . 2010-07-28 21:34 ——– d—–w- c:\program files\MiShellSoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-24 11:25 . 2009-10-11 21:57 ——– d—–w- c:\program files\Common Files\AntiVirus
2010-08-24 09:36 . 2009-01-08 15:08 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-18 16:18 . 2010-08-18 16:18 388096 —-a-r- c:\documents and settings\Jim Bromwell\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-14 14:41 . 2009-04-09 16:26 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-08-11 15:49 . 2009-03-18 15:09 ——– d—–w- c:\program files\Common Files\AnswerWorks 5.0
2010-08-11 15:42 . 2009-03-18 14:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Intuit
2010-08-03 21:22 . 2010-07-26 00:51 ——– d—–w- c:\program files\Microsoft Money Plus
2010-08-03 17:19 . 2010-08-03 17:19 295606 —-a-r- c:\documents and settings\Jim Bromwell\Application Data\Microsoft\Installer\{2B9B1B9E-45E5-4A76-9CA8-E06F897A3201}\_3A20CF231F6F0812B6B942.exe
2010-08-03 17:19 . 2010-08-03 17:19 5222 —-a-r- c:\documents and settings\Jim Bromwell\Application Data\Microsoft\Installer\{2B9B1B9E-45E5-4A76-9CA8-E06F897A3201}\_EC348ADB6AC3A2B2EA675D.exe
2010-08-03 17:19 . 2010-08-03 17:19 5222 —-a-r- c:\documents and settings\Jim Bromwell\Application Data\Microsoft\Installer\{2B9B1B9E-45E5-4A76-9CA8-E06F897A3201}\_34779EA62C4957E16DBB3E.exe
2010-08-03 17:19 . 2010-08-03 17:19 295606 —-a-r- c:\documents and settings\Jim Bromwell\Application Data\Microsoft\Installer\{2B9B1B9E-45E5-4A76-9CA8-E06F897A3201}\_B5F2DCEFB6AA5671D1D39E.exe
2010-08-03 17:19 . 2010-08-03 17:19 295606 —-a-r- c:\documents and settings\Jim Bromwell\Application Data\Microsoft\Installer\{2B9B1B9E-45E5-4A76-9CA8-E06F897A3201}\_28B7E701AB5EA204F8C52F.exe
2010-08-01 02:32 . 2010-08-01 02:32 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-08-01 02:32 . 2010-08-01 02:32 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-07-29 09:37 . 2009-01-08 16:05 ——– d—–w- c:\documents and settings\Jim Bromwell\Application Data\AdobeUM
2010-06-30 12:31 . 2004-08-04 10:00 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2004-08-04 10:00 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-04 10:00 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-08-04 10:00 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2009-01-08 14:11 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2004-08-04 10:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-07-02 2347216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RCScheduleCheck"="c:\program files\VCOM\Recovery Commander\RCSCHED.EXE" [2003-10-21 151552]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-05-16 648504]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-05-21 451896]
"MMTray"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" [2004-04-20 131072]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-20 53248]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"CaddieSyncLauncher"="c:\program files\SkyGolf\SkyCaddie Desktop\CaddieSyncLauncher.exe" [2009-11-19 95744]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{a5780613-492e-4a2a-a7fd-549610edf6cc}"= "c:\program files\VCOM\Recovery Commander\RCHOOK.DLL" [2003-07-08 102400]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0402000.00C\symds.sys [8/1/2010 6:03 AM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0402000.00C\symefa.sys [8/1/2010 6:03 AM 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100810.004\BHDrvx86.sys [8/9/2010 9:11 PM 692272]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0402000.00C\cchpx86.sys [8/1/2010 6:03 AM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0402000.00C\ironx86.sys [8/1/2010 6:03 AM 116784]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/15/2010 5:45 AM 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100820.001\IDSXpx86.sys [8/23/2010 4:08 PM 331640]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [8/20/2010 10:58 AM 67800]
S3 ATMFBUS;A600 USB Composite Device Driver;c:\windows\system32\drivers\ATMFBUS.sys [8/3/2010 9:39 AM 47360]
S3 ATMFCVsp;A600 Cricket CM Port;c:\windows\system32\drivers\ATMFCVsp.sys [8/3/2010 9:39 AM 153600]
S3 ATMFFLT;A600 USB Modem Installation CD;c:\windows\system32\drivers\ATMFFLT.sys [8/3/2010 9:39 AM 13312]
S3 ATMFMdm;A600 Cricket EVDO Modem;c:\windows\system32\drivers\ATMFMdm.sys [8/3/2010 9:39 AM 153472]
S3 ATMFNET;A600 Cricket EVDO Network Adapter;c:\windows\system32\drivers\ATMFNET.sys [8/3/2010 9:39 AM 103424]
S3 ATMFNVsp;A600 Cricket NMEA Port Serial Port;c:\windows\system32\drivers\ATMFNVsp.sys [8/3/2010 9:39 AM 153600]
S3 ATMFVsp;A600 Cricket Diagnostics Port;c:\windows\system32\drivers\ATMFVsp.sys [8/3/2010 9:39 AM 153472]
S3 SaiH0461;SaiH0461;c:\windows\system32\drivers\SaiH0461.sys [3/26/2008 11:47 AM 136832]

— Other Services/Drivers In Memory —

*NewlyCreated* - UXLDRPOB
*NewlyCreated* - UXLDRPOD
*Deregistered* - uxldrpob
*Deregistered* - uxldrpod
.
Contents of the 'Scheduled Tasks' folder

2010-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-18 14:30]

2010-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-18 14:30]

2010-08-24 c:\windows\Tasks\Scheduled Checkpoint.job
- c:\program files\VCOM\Recovery Commander\RCSCHED.EXE [2009-03-03 17:20]
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jim Bromwell\Application Data\Mozilla\Firefox\Profiles\r7atxwgy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www2.counton2.com/
FF - prefs.js: keyword.URL - hxxp://playbox.toolbarhome.com/search.aspx?srch=ku&q=
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\Jim Bromwell\Application Data\Mozilla\Firefox\Profiles\r7atxwgy.default\extensions\playbox@toolbar\components\toolbarhomewmp.dll
FF - plugin: c:\documents and settings\Jim Bromwell\Application Data\Mozilla\Firefox\Profiles\r7atxwgy.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-26 16:38
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\4.2.0.12\diMaster.dll\" /prefetch:1"
.
Completion time: 2010-08-26 16:48:56
ComboFix-quarantined-files.txt 2010-08-26 20:48

Pre-Run: 6,538,014,720 bytes free
Post-Run: 6,509,694,976 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - CFB1FAABFB89D50D87FD89D6033EB1CC
Please go to Start -> Select Run -> Type in "sfc /scannow" without quotation marks -> Hit enter. If it asks you to put in a XP CD, please do so. Then tell me if you are still having a slow start up time.
I am getting the following message: Windows cannot find 'sfc/scannow'.Make sure you typed the name correctly, and then try again. To search for a file, click the jStart button, and then click Search. I tried this several times. It is taking about 35 minutes to fully start.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI