madscien
Topic Starter
This was posted 8/17/10 on Norton’s Internet Security Board (edited with recent knowledge)
I was told by them, I have Tidserev, and to come here for help.
I will be SO grateful if you can help. My business PC is down.
Embedded questions below.
“Bit torrent killed XP Pro explorer.exe”
My Bad! I used Bit Torrent to download a replacement for some broken old software and something ugly came with it. Tough lesson!
I left the PC running, went to bed, got up and the screen was blank with the desktop background and cursor. On reboot, Windows XP Pro boots, plays the welcome music, puts up my desktop background and the cursor..and that's it. Then, if the network is connected, every few minutes I get a Norton message saying a threat was found and fixed (not), then that Suspicious.Mystic was detected, only to have it repeat endlessly. Norton AV 2010 (I believe) Version 17.7.0.12 everything turned on, WIN XP Pro SP3 A Gateway Hyperthreaded 2.4GHz P4 loaded.
So I did some digging and explorer.exe is deleted from the c:\windows dir, and if I replace it, Norton immediately says it detected Suspicious.Mystic immediately takes it out. It seems that instead, svchost.exe may be run (not certain about that part).
I then discovered I could put explorer.exe on a thumb drive and run it from that using File Run from task manager. Yay, I think, I'll get the beast running and hook up with Symantec for a scan. Well guess what, it doesn’t work when the net is connected, it just reboots in a minute or 2 after some sort of attempted intrusion detection by Norton (fortunately, leaving the explorer.exe on the thumb drive).
Norton gives me that message about Suspicious. Mystic every time, and I now (since the bit torrent incident) get repeated hits from an attack from various Trojans, sometimes several in a minute now. Looking back at Norton history, seems like this has happened once in a while, for several days in the past, and I ignored it as all were "resolved", but the attacks are hundreds of times worse now…what a mess.
Pretty much same thing happens in safe mode. Hmmm Is Norton out to lunch?
Sometimes, it runs for several minutes with the net connected and I actually managed a Norton live update then ran a quick scan, exporting 17 resolved items (text file of Norton activity is available). Exported some older Norton history (also available if you want it). In fact, looking at the Norton text files, lots of stuff is detected as Suspicious.Mystic and blocked, deleted or quarantined, yet Norton virus scans didn't remove whatever is causing this.
The guys in the Norton forum universally think this is “HTTPS Tidserv Request2”.
I have a lot of business data on this PC (I know, I’m an idiot) including software that came with it I have no backup discs for , massive video files and a ton of CAD and Simulation data, and software I bought and downloaded over a couple years. I HAVE to revive this PC.
FIRST, before I start disinfection, I bought a Seagate Free Agent USB drive, and need advice before backing up.
1. Should I use the FreeAgent software to back up everything (way faster) or just get all the data files (will take a day or so, a zillion programs and directories to sift thru).
2. OR, can I copy everything, then do a search of the USB drive and delete all exe, dll, script, java files?
3. I have 3 drives, should I disinfect the PC with all 3 connected (as they were when the infection caught)
4. Curiosity…Since the downloaded software was never actually run, and the infection happened during the end of the download, how was the infection passed to my PC (I have a router with a firewall and Norton 2010 everything is enabled)?
5. What’s the chance Norton’s firewall actually prevented theft of data from my PC (this is actually pretty important here)?
Then I need help, bigtime! (I already know what an idiot I am for doing this!)
I am not comfortable with registry edits, but can follow detailed instructions. I have been around PCs since the 8080 but this stuff is scary!
I just ran OTL per instructions, one error on my part, I forgot to connect one of the SATA drives, is that OK? Should I reconnect and run or reconnect for disinfecting?
Here is th OTL output text file:
OTL logfile created on: 8/19/2010 12:54:38 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Administrator\Desktop\A1
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 4095 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 94.98 Gb Free Space | 31.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 74.52 Gb Total Space | 27.32 Gb Free Space | 36.66% Space Free | Partition Type: NTFS
Drive G: | 2.73 Gb Total Space | 2.72 Gb Free Space | 99.82% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
Drive I: | 7.45 Gb Total Space | 7.44 Gb Free Space | 99.94% Space Free | Partition Type: FAT32
Computer Name: DEN
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Administrator\Desktop\A1\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (Seagate LLC)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - I:\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Nero\Nero 7\Core\nero.exe (Nero AG)
PRC - C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe (Nero AG)
PRC - C:\WINDOWS\system32\BRSS01A.EXE (brother Industries Ltd)
PRC - C:\WINDOWS\system32\BRSVC01A.EXE (brother Industries Ltd)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Administrator\Desktop\A1\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (SolidWorks Licensing Service) – C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (AdobeActiveFileMonitor8.0) – C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (Brother XP spl Service) – C:\WINDOWS\system32\BRSVC01A.EXE (brother Industries Ltd)
========== Driver Services (SafeList) ==========
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMNDIS.SYS File not found
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMIDS.SYS File not found
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMFW.SYS File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100817.008\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100817.008\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\BASHDefs\20100719.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100816.001\IDSXpx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1107000.00C\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\Ironx86.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1107000.00C\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\ccHPx86.sys (Symantec Corporation)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) QuickCam for Notebooks Deluxe(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (lvpopflt) – C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\SYMDS.SYS (Symantec Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (ArcCD) – C:\WINDOWS\System32\drivers\ArcCD.sys (ArcSoft Inc.)
DRV - (ArcUdfs) – C:\WINDOWS\System32\drivers\ArcUdfs.sys (ArcSoft Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (Nbf) – C:\WINDOWS\system32\drivers\NBF.SYS (Microsoft Corporation)
DRV - (PQNTDrv) – C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\IPSFFPlgn\ [2010/05/26 08:38:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/24 16:03:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/26 23:47:40 | 000,000,000 | —D | M]
[2009/11/12 10:58:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/08/16 11:48:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qltff2qb.default\extensions
[2010/06/24 10:06:36 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qltff2qb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/17 15:15:59 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/14 12:54:26 | 000,274,432 | —- | M] (Dassault Systèmes SolidWorks Corp.) – C:\Program Files\Mozilla Firefox\plugins\npEModelPlugin.dll
O1 HOSTS File: ([2002/12/31 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/23 16:43:28 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/04/23 16:43:28 | 000,000,000 | —- | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{6fa617fb-09bf-11df-8a21-0007e946bf6f}\Shell - "" = AutoRun
O33 - MountPoints2\{6fa617fb-09bf-11df-8a21-0007e946bf6f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6fa617fb-09bf-11df-8a21-0007e946bf6f}\Shell\AutoRun\command - "" = H:\MI.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (68130555115339776)
========== Files/Folders - Created Within 30 Days ==========
[2010/08/19 12:42:35 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Desktop\A1
[2010/08/19 09:23:42 | 000,000,000 | —D | C] – C:\src
[2010/08/17 20:11:38 | 001,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\Copy of zexplorer.exe
[2010/08/17 15:07:50 | 001,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\explorer.exe
[2010/08/17 00:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/08/17 00:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/08/17 00:26:27 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2010/08/16 10:37:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Windows Server
[2010/08/16 10:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\A0F2B4576AD8BCE58806D40B0DCDAEE3
[2010/08/15 12:35:50 | 000,000,000 | —D | C] – C:\EWB5
[2010/08/15 12:34:41 | 000,245,248 | —- | C] (Stirling Technologies, Inc.) – C:\WINDOWS\UNINST16.EXE
[2010/08/07 19:43:31 | 000,000,000 | —D | C] – C:\mikepida
[2010/08/06 11:46:48 | 000,000,000 | —D | C] – C:\New Folder (11)
[2010/08/06 09:45:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\test
[2010/07/28 19:09:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Ed T Rodriguez
[2010/07/28 00:29:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\IACT July
[2010/07/28 00:00:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\CREE
[2010/07/27 16:05:56 | 000,000,000 | —D | C] – C:\mold
[2010/07/27 10:39:54 | 000,000,000 | —D | C] – C:\New Folder (10)
[2010/07/26 13:25:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\EDrawings
[2010/07/26 13:23:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SolidWorks Shared
[2010/07/26 13:23:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\eDrawings2010
[2010/07/26 11:01:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\0710 Atlanta videos
[2010/07/23 10:50:18 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/19 11:31:29 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/19 11:31:13 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/19 11:31:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/19 10:39:07 | 008,126,464 | —- | M] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/08/19 10:39:07 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2010/08/19 10:04:41 | 000,139,776 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/19 09:53:02 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/18 17:54:16 | 000,000,490 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Administrator.job
[2010/08/18 14:27:20 | 000,346,132 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Droot share3.nri
[2010/08/18 13:25:25 | 000,242,910 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\droot share2.nri
[2010/08/18 12:41:48 | 000,676,740 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Droot share1.nru
[2010/08/18 11:57:22 | 000,676,740 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Dshare1.nru
[2010/08/17 13:50:29 | 000,000,507 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/17 13:50:29 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/17 13:50:29 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/08/16 10:26:29 | 000,021,443 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\solidworks 2005 tor.docx
[2010/08/16 08:10:13 | 000,014,306 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Website hits.xlsx
[2010/08/15 14:34:09 | 000,024,175 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\UNEMP 2010.xlsx
[2010/08/15 12:36:04 | 000,000,000 | —- | M] () – C:\WINDOWS\System\Win32s.ini
[2010/08/13 10:55:46 | 000,011,073 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\LED footcandles and color temperature.docx
[2010/08/13 09:18:00 | 000,010,751 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\LED contacts 081310.docx
[2010/08/13 08:18:28 | 000,297,256 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/13 00:28:04 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/13 00:27:05 | 000,488,244 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/13 00:27:05 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/13 00:27:05 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/02 17:03:31 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\YouSendIt.lnk
[2010/07/30 16:08:28 | 000,062,611 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\TestDocument.pdf
[2010/07/30 16:06:02 | 000,063,192 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Test Document.pdf
[2010/07/27 13:21:21 | 000,034,816 | —- | M] () – C:\resume 072710.doc
[2010/07/27 13:12:57 | 000,029,184 | —- | M] () – C:\general cover 072710.doc
[2010/07/27 02:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2010/07/26 23:47:41 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/07/26 14:47:14 | 000,035,569 | —- | M] () – C:\COPPER1.DXF
[2010/07/26 14:41:57 | 000,072,382 | —- | M] () – C:\PATTERN.DXF
[2010/07/26 14:01:22 | 000,052,342 | —- | M] () – C:\SLOTPLAT.DXF
[2010/07/26 13:30:57 | 000,015,588 | —- | M] () – C:\COPPER4.GCD
[2010/07/26 13:30:52 | 000,066,267 | —- | M] () – C:\COPPER4.DXF
[2010/07/26 13:23:37 | 000,000,000 | —- | M] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2010/07/26 13:23:23 | 000,001,902 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk
[2010/07/26 13:23:23 | 000,001,884 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SolidWorks eDrawings 2010.lnk
[2010/07/26 12:52:17 | 000,015,902 | —- | M] () – C:\COPPER3.BMP
[2010/07/26 12:46:29 | 000,038,528 | —- | M] () – C:\COPPER3.TIF
[2010/07/26 12:45:57 | 000,067,686 | —- | M] () – C:\COPPER3.DXF
[2010/07/26 12:45:42 | 000,015,888 | —- | M] () – C:\COPPER3.GCD
[2010/07/24 16:25:11 | 000,035,288 | —- | M] () – C:\COPPER.DXF
[2010/07/24 16:13:49 | 000,038,528 | —- | M] () – C:\COPPER.TIF
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/08/18 14:27:20 | 000,346,132 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Droot share3.nri
[2010/08/18 13:25:24 | 000,242,910 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\droot share2.nri
[2010/08/18 12:41:47 | 000,676,740 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Droot share1.nru
[2010/08/18 11:57:21 | 000,676,740 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Dshare1.nru
[2010/08/17 07:13:56 | 008,126,464 | —- | C] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/08/16 10:26:28 | 000,021,443 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\solidworks 2005 tor.docx
[2010/08/15 12:36:04 | 000,000,000 | —- | C] () – C:\WINDOWS\System\Win32s.ini
[2010/08/15 11:30:32 | 000,014,306 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Website hits.xlsx
[2010/08/13 16:12:21 | 000,024,175 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\UNEMP 2010.xlsx
[2010/08/13 10:50:04 | 000,011,073 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\LED footcandles and color temperature.docx
[2010/08/13 09:08:22 | 000,010,751 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\LED contacts 081310.docx
[2010/07/30 16:08:28 | 000,062,611 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\TestDocument.pdf
[2010/07/30 16:06:02 | 000,063,192 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Test Document.pdf
[2010/07/27 12:49:19 | 000,029,184 | —- | C] () – C:\general cover 072710.doc
[2010/07/27 12:42:42 | 000,034,816 | —- | C] () – C:\resume 072710.doc
[2010/07/26 14:47:14 | 000,035,569 | —- | C] () – C:\COPPER1.DXF
[2010/07/26 14:41:56 | 000,072,382 | —- | C] () – C:\PATTERN.DXF
[2010/07/26 13:57:45 | 000,052,342 | —- | C] () – C:\SLOTPLAT.DXF
[2010/07/26 13:30:57 | 000,015,588 | —- | C] () – C:\COPPER4.GCD
[2010/07/26 13:30:52 | 000,066,267 | —- | C] () – C:\COPPER4.DXF
[2010/07/26 13:23:37 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2010/07/26 13:23:23 | 000,001,902 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk
[2010/07/26 13:23:23 | 000,001,884 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SolidWorks eDrawings 2010.lnk
[2010/07/26 12:46:49 | 000,015,902 | —- | C] () – C:\COPPER3.BMP
[2010/07/26 12:46:26 | 000,038,528 | —- | C] () – C:\COPPER3.TIF
[2010/07/26 12:45:56 | 000,067,686 | —- | C] () – C:\COPPER3.DXF
[2010/07/26 10:40:09 | 000,015,888 | —- | C] () – C:\COPPER3.GCD
[2010/07/24 16:13:47 | 000,038,528 | —- | C] () – C:\COPPER.TIF
[2010/07/24 16:00:06 | 000,035,288 | —- | C] () – C:\COPPER.DXF
[2010/02/27 19:28:40 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/02/27 18:02:13 | 000,010,593 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2010/02/26 16:48:09 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/01/28 18:52:10 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/12/31 18:57:28 | 000,000,416 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/11/29 15:45:17 | 000,082,289 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/11/16 19:02:01 | 000,139,776 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/16 18:47:09 | 000,006,818 | —- | C] () – C:\WINDOWS\COOL.INI
[2009/11/16 13:55:48 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2009/11/11 19:44:45 | 000,000,000 | —- | C] () – C:\WINDOWS\Brohl144.ini
[2009/11/11 19:44:22 | 000,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2009/11/11 19:44:22 | 000,000,039 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2009/11/11 19:44:22 | 000,000,023 | —- | C] () – C:\WINDOWS\Brownie.ini
[2009/11/11 19:44:01 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\BRVPDNTA.DLL
[2009/11/11 19:44:00 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2009/11/11 19:44:00 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2009/11/11 19:44:00 | 000,011,568 | —- | C] () – C:\WINDOWS\HL-1440.INI
[2009/11/11 19:44:00 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2009/11/11 19:42:01 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_1440.ini
[2009/11/11 19:41:42 | 000,000,068 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2009/11/11 19:39:44 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2009/11/11 19:39:42 | 000,000,861 | —- | C] () – C:\WINDOWS\brwmark.ini
[2009/11/11 19:39:41 | 000,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/11/11 17:58:52 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\CNMVS5c.DLL
[2009/10/07 02:46:36 | 000,025,752 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 02:23:08 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2004/02/18 15:40:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[1996/12/04 01:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1996/12/04 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/03 15:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2010/08/16 10:36:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\A0F2B4576AD8BCE58806D40B0DCDAEE3
[2010/05/15 14:32:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AlpCAD Software
[2010/08/17 07:09:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\BitTorrent
[2009/12/31 19:12:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Canon
[2010/07/26 13:25:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\EDrawings
[2010/03/24 16:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ImgBurn
[2009/11/29 15:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Leadertech
[2010/02/23 17:18:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\No Company Name
[2010/02/22 16:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Publish Providers
[2009/12/31 18:57:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ScanSoft
[2010/02/22 18:20:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Sony
[2010/04/22 20:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Tific
[2010/06/16 11:45:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\YouSendIt
[2010/01/21 17:47:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2010/03/24 15:31:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2010/07/12 09:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/12/31 18:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/07/12 10:01:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2010/02/23 16:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/03/09 11:39:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2002/12/31 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2002/12/31 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2002/12/31 08:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2002/12/31 08:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: IASTOR.SYS >
[2002/12/31 08:00:00 | 000,467,200 | —- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 – C:\WINDOWS\dell\iastor\iastor.sys
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2002/12/31 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2002/12/31 08:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009/04/23 12:33:28 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/04/23 12:33:28 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/04/23 12:33:28 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Administrator\Desktop\Generic CADD.pif:SummaryInformation
< End of report >
Here is the extras text file:
OTL Extras logfile created on: 8/19/2010 12:54:38 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Administrator\Desktop\A1
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 4095 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 94.98 Gb Free Space | 31.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 74.52 Gb Total Space | 27.32 Gb Free Space | 36.66% Space Free | Partition Type: NTFS
Drive G: | 2.73 Gb Total Space | 2.72 Gb Free Space | 99.82% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
Drive I: | 7.45 Gb Total Space | 7.44 Gb Free Space | 99.94% Space Free | Partition Type: FAT32
Computer Name: DEN
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe File not found
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L File not found
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L File not found
Drive [find] – %SystemRoot%\Explorer.exe File not found
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"4369:TCP" = 4369:TCP:LocalSubNet:Enabled:enerGdot
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\SevenGens\EGDremote\EGDremote.exe" = C:\Program Files\SevenGens\EGDremote\EGDremote.exe:*:Enabled:EGDremote – ()
"C:\Program Files\NetworkView\NetworkView.exe" = C:\Program Files\NetworkView\NetworkView.exe:*:Enabled:NetworkView – (NetworkView Software)
"C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2411" = CanoScan LiDE 70
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{17C4A35A-2041-42C0-8D10-DEF55B47BE56}" = Adobe Premiere Elements 8.0 Templates
"{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
"{20207CCE-A8FA-44A7-AA3D-1E43EB307B27}" = Sony Sound Forge Audio Studio 9.0
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F5CFC1C-653B-4B22-9153-2BDDF2E03C0E}" = Seagate Manager Installer
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4685A344-6718-4923-AA9D-158A0A2E1CFB}" = SmartSound Quicktracks for Premiere Elements 8.0
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5C104E56-A441-429D-A609-D8A46EB92EA1}" = PCMark05
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{97E038E1-41AD-4C93-BCDC-6A2394AEE352}" = Vegas Movie Studio Platinum 9.0
"{9EDE7573-F2B0-4FAC-8928-A7E9381BCB91}" = ArcSoft MediaImpression for Kodak
"{A0E583D1-23F7-4C35-9620-B169D7715E4B}" = Adobe Premiere Elements 8.0
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5670-0000-900000000003}" = Korean Fonts Support For Adobe Reader 9
"{AFEA2EBC-E0CA-4A0D-BAB6-03B663B753AD}" = SolidWorks eDrawings 2010
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{CA72A82C-7DBC-4814-8CCB-E5BFAC59FAEF}" = ArcSoft MediaImpression for Kodak
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DDF9EE-C67F-368B-EB42-ECB44FD7556D}" = Adobe Photoshop.com Inspiration Browser
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E40CE517-0D42-4198-96B4-C8232B257EB5}" = Data Lifeguard Diagnostic for Windows
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{FC98FBE9-E931-494C-8717-497185371033}" = Nero 7 Ultra Edition
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
"Aide PDF to DXF Converter_is1" = Aide PDF to DXF Converter 9.5
"Any DWG to PDF Converter_is1" = Any DWG to PDF Converter 2010
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BitTorrent" = BitTorrent
"Brother 1440" = Brother 1440
"BROWNIE" = Brownie
"Canon CanoScan LiDE 70 User Registration" = Canon CanoScan LiDE 70 User Registration
"CanoScan Toolbox 5.0" = Canon CanoScan Toolbox 5.0
"Carbonite Setup Lite" = Carbonite Online Backup Setup
"Cool Edit 96" = Cool Edit 96
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"EnerGDot" = EnerGDot 1106
"EnerGDot Remote" = EnerGDot Remote 1.003
"HammerHead Rhythm Station" = HammerHead Rhythm Station
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Hot CPU Tester Lite_is1" = Hot CPU Tester Lite
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"InstallShield_{3F5CFC1C-653B-4B22-9153-2BDDF2E03C0E}" = Seagate Manager Installer
"InstallShield_{4685A344-6718-4923-AA9D-158A0A2E1CFB}" = SmartSound Quicktracks for Premiere Elements 8.0
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"InstallShield_{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NAV" = Norton AntiVirus
"NetworkView_is1" = NetworkView Version 1.4
"NSS" = Norton Security Scan
"PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.
1" = Adobe Photoshop.com Inspiration Browser
"PremElem80" = Adobe Premiere Elements 8.0
"PremElem80Templates" = Adobe Premiere Elements 8.0 Templates
"PROSet" = Intel® PRO Network Adapters and Drivers
"RarZilla Free Unrar" = RarZilla Free Unrar
"SpeedFan" = SpeedFan (remove only)
"ThumbsPlus 3.0f-S" = ThumbsPlus 3.0f-S
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WM Capture" = WM Capture
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Cadlibrary2009" = Cadlibrary2009
"GoToMeeting" = GoToMeeting 4.0.0.320
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/19/2010 9:37:01 AM | Computer Name = DEN | Source = Application Error | ID = 1000
Description = Faulting application divxupdate.exe, version 1.0.1.10, faulting module
msvcp80.dll, version 8.0.50727.4053, fault address 0x000100b5.
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
I was told by them, I have Tidserev, and to come here for help.
I will be SO grateful if you can help. My business PC is down.
Embedded questions below.
“Bit torrent killed XP Pro explorer.exe”
My Bad! I used Bit Torrent to download a replacement for some broken old software and something ugly came with it. Tough lesson!
I left the PC running, went to bed, got up and the screen was blank with the desktop background and cursor. On reboot, Windows XP Pro boots, plays the welcome music, puts up my desktop background and the cursor..and that's it. Then, if the network is connected, every few minutes I get a Norton message saying a threat was found and fixed (not), then that Suspicious.Mystic was detected, only to have it repeat endlessly. Norton AV 2010 (I believe) Version 17.7.0.12 everything turned on, WIN XP Pro SP3 A Gateway Hyperthreaded 2.4GHz P4 loaded.
So I did some digging and explorer.exe is deleted from the c:\windows dir, and if I replace it, Norton immediately says it detected Suspicious.Mystic immediately takes it out. It seems that instead, svchost.exe may be run (not certain about that part).
I then discovered I could put explorer.exe on a thumb drive and run it from that using File Run from task manager. Yay, I think, I'll get the beast running and hook up with Symantec for a scan. Well guess what, it doesn’t work when the net is connected, it just reboots in a minute or 2 after some sort of attempted intrusion detection by Norton (fortunately, leaving the explorer.exe on the thumb drive).
Norton gives me that message about Suspicious. Mystic every time, and I now (since the bit torrent incident) get repeated hits from an attack from various Trojans, sometimes several in a minute now. Looking back at Norton history, seems like this has happened once in a while, for several days in the past, and I ignored it as all were "resolved", but the attacks are hundreds of times worse now…what a mess.
Pretty much same thing happens in safe mode. Hmmm Is Norton out to lunch?
Sometimes, it runs for several minutes with the net connected and I actually managed a Norton live update then ran a quick scan, exporting 17 resolved items (text file of Norton activity is available). Exported some older Norton history (also available if you want it). In fact, looking at the Norton text files, lots of stuff is detected as Suspicious.Mystic and blocked, deleted or quarantined, yet Norton virus scans didn't remove whatever is causing this.
The guys in the Norton forum universally think this is “HTTPS Tidserv Request2”.
I have a lot of business data on this PC (I know, I’m an idiot) including software that came with it I have no backup discs for , massive video files and a ton of CAD and Simulation data, and software I bought and downloaded over a couple years. I HAVE to revive this PC.
FIRST, before I start disinfection, I bought a Seagate Free Agent USB drive, and need advice before backing up.
1. Should I use the FreeAgent software to back up everything (way faster) or just get all the data files (will take a day or so, a zillion programs and directories to sift thru).
2. OR, can I copy everything, then do a search of the USB drive and delete all exe, dll, script, java files?
3. I have 3 drives, should I disinfect the PC with all 3 connected (as they were when the infection caught)
4. Curiosity…Since the downloaded software was never actually run, and the infection happened during the end of the download, how was the infection passed to my PC (I have a router with a firewall and Norton 2010 everything is enabled)?
5. What’s the chance Norton’s firewall actually prevented theft of data from my PC (this is actually pretty important here)?
Then I need help, bigtime! (I already know what an idiot I am for doing this!)
I am not comfortable with registry edits, but can follow detailed instructions. I have been around PCs since the 8080 but this stuff is scary!
I just ran OTL per instructions, one error on my part, I forgot to connect one of the SATA drives, is that OK? Should I reconnect and run or reconnect for disinfecting?
Here is th OTL output text file:
OTL logfile created on: 8/19/2010 12:54:38 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Administrator\Desktop\A1
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 4095 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 94.98 Gb Free Space | 31.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 74.52 Gb Total Space | 27.32 Gb Free Space | 36.66% Space Free | Partition Type: NTFS
Drive G: | 2.73 Gb Total Space | 2.72 Gb Free Space | 99.82% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
Drive I: | 7.45 Gb Total Space | 7.44 Gb Free Space | 99.94% Space Free | Partition Type: FAT32
Computer Name: DEN
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Administrator\Desktop\A1\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (Seagate LLC)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - I:\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Nero\Nero 7\Core\nero.exe (Nero AG)
PRC - C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe (Nero AG)
PRC - C:\WINDOWS\system32\BRSS01A.EXE (brother Industries Ltd)
PRC - C:\WINDOWS\system32\BRSVC01A.EXE (brother Industries Ltd)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Administrator\Desktop\A1\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (SolidWorks Licensing Service) – C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (AdobeActiveFileMonitor8.0) – C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (Brother XP spl Service) – C:\WINDOWS\system32\BRSVC01A.EXE (brother Industries Ltd)
========== Driver Services (SafeList) ==========
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMNDIS.SYS File not found
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMIDS.SYS File not found
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMFW.SYS File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100817.008\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100817.008\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\BASHDefs\20100719.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100816.001\IDSXpx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1107000.00C\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\Ironx86.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1107000.00C\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\ccHPx86.sys (Symantec Corporation)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) QuickCam for Notebooks Deluxe(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (lvpopflt) – C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\SYMDS.SYS (Symantec Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (ArcCD) – C:\WINDOWS\System32\drivers\ArcCD.sys (ArcSoft Inc.)
DRV - (ArcUdfs) – C:\WINDOWS\System32\drivers\ArcUdfs.sys (ArcSoft Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (Nbf) – C:\WINDOWS\system32\drivers\NBF.SYS (Microsoft Corporation)
DRV - (PQNTDrv) – C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\IPSFFPlgn\ [2010/05/26 08:38:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/24 16:03:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/26 23:47:40 | 000,000,000 | —D | M]
[2009/11/12 10:58:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/08/16 11:48:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qltff2qb.default\extensions
[2010/06/24 10:06:36 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qltff2qb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/17 15:15:59 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/14 12:54:26 | 000,274,432 | —- | M] (Dassault Systèmes SolidWorks Corp.) – C:\Program Files\Mozilla Firefox\plugins\npEModelPlugin.dll
O1 HOSTS File: ([2002/12/31 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/23 16:43:28 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/04/23 16:43:28 | 000,000,000 | —- | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{6fa617fb-09bf-11df-8a21-0007e946bf6f}\Shell - "" = AutoRun
O33 - MountPoints2\{6fa617fb-09bf-11df-8a21-0007e946bf6f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6fa617fb-09bf-11df-8a21-0007e946bf6f}\Shell\AutoRun\command - "" = H:\MI.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (68130555115339776)
========== Files/Folders - Created Within 30 Days ==========
[2010/08/19 12:42:35 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Desktop\A1
[2010/08/19 09:23:42 | 000,000,000 | —D | C] – C:\src
[2010/08/17 20:11:38 | 001,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\Copy of zexplorer.exe
[2010/08/17 15:07:50 | 001,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\explorer.exe
[2010/08/17 00:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/08/17 00:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/08/17 00:26:27 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2010/08/16 10:37:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Windows Server
[2010/08/16 10:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\A0F2B4576AD8BCE58806D40B0DCDAEE3
[2010/08/15 12:35:50 | 000,000,000 | —D | C] – C:\EWB5
[2010/08/15 12:34:41 | 000,245,248 | —- | C] (Stirling Technologies, Inc.) – C:\WINDOWS\UNINST16.EXE
[2010/08/07 19:43:31 | 000,000,000 | —D | C] – C:\mikepida
[2010/08/06 11:46:48 | 000,000,000 | —D | C] – C:\New Folder (11)
[2010/08/06 09:45:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\test
[2010/07/28 19:09:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Ed T Rodriguez
[2010/07/28 00:29:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\IACT July
[2010/07/28 00:00:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\CREE
[2010/07/27 16:05:56 | 000,000,000 | —D | C] – C:\mold
[2010/07/27 10:39:54 | 000,000,000 | —D | C] – C:\New Folder (10)
[2010/07/26 13:25:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\EDrawings
[2010/07/26 13:23:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SolidWorks Shared
[2010/07/26 13:23:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\eDrawings2010
[2010/07/26 11:01:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\0710 Atlanta videos
[2010/07/23 10:50:18 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/19 11:31:29 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/19 11:31:13 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/19 11:31:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/19 10:39:07 | 008,126,464 | —- | M] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/08/19 10:39:07 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2010/08/19 10:04:41 | 000,139,776 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/19 09:53:02 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/18 17:54:16 | 000,000,490 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Administrator.job
[2010/08/18 14:27:20 | 000,346,132 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Droot share3.nri
[2010/08/18 13:25:25 | 000,242,910 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\droot share2.nri
[2010/08/18 12:41:48 | 000,676,740 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Droot share1.nru
[2010/08/18 11:57:22 | 000,676,740 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Dshare1.nru
[2010/08/17 13:50:29 | 000,000,507 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/17 13:50:29 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/17 13:50:29 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/08/16 10:26:29 | 000,021,443 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\solidworks 2005 tor.docx
[2010/08/16 08:10:13 | 000,014,306 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Website hits.xlsx
[2010/08/15 14:34:09 | 000,024,175 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\UNEMP 2010.xlsx
[2010/08/15 12:36:04 | 000,000,000 | —- | M] () – C:\WINDOWS\System\Win32s.ini
[2010/08/13 10:55:46 | 000,011,073 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\LED footcandles and color temperature.docx
[2010/08/13 09:18:00 | 000,010,751 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\LED contacts 081310.docx
[2010/08/13 08:18:28 | 000,297,256 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/13 00:28:04 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/13 00:27:05 | 000,488,244 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/13 00:27:05 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/13 00:27:05 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/02 17:03:31 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\YouSendIt.lnk
[2010/07/30 16:08:28 | 000,062,611 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\TestDocument.pdf
[2010/07/30 16:06:02 | 000,063,192 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Test Document.pdf
[2010/07/27 13:21:21 | 000,034,816 | —- | M] () – C:\resume 072710.doc
[2010/07/27 13:12:57 | 000,029,184 | —- | M] () – C:\general cover 072710.doc
[2010/07/27 02:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2010/07/26 23:47:41 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/07/26 14:47:14 | 000,035,569 | —- | M] () – C:\COPPER1.DXF
[2010/07/26 14:41:57 | 000,072,382 | —- | M] () – C:\PATTERN.DXF
[2010/07/26 14:01:22 | 000,052,342 | —- | M] () – C:\SLOTPLAT.DXF
[2010/07/26 13:30:57 | 000,015,588 | —- | M] () – C:\COPPER4.GCD
[2010/07/26 13:30:52 | 000,066,267 | —- | M] () – C:\COPPER4.DXF
[2010/07/26 13:23:37 | 000,000,000 | —- | M] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2010/07/26 13:23:23 | 000,001,902 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk
[2010/07/26 13:23:23 | 000,001,884 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SolidWorks eDrawings 2010.lnk
[2010/07/26 12:52:17 | 000,015,902 | —- | M] () – C:\COPPER3.BMP
[2010/07/26 12:46:29 | 000,038,528 | —- | M] () – C:\COPPER3.TIF
[2010/07/26 12:45:57 | 000,067,686 | —- | M] () – C:\COPPER3.DXF
[2010/07/26 12:45:42 | 000,015,888 | —- | M] () – C:\COPPER3.GCD
[2010/07/24 16:25:11 | 000,035,288 | —- | M] () – C:\COPPER.DXF
[2010/07/24 16:13:49 | 000,038,528 | —- | M] () – C:\COPPER.TIF
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/08/18 14:27:20 | 000,346,132 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Droot share3.nri
[2010/08/18 13:25:24 | 000,242,910 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\droot share2.nri
[2010/08/18 12:41:47 | 000,676,740 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Droot share1.nru
[2010/08/18 11:57:21 | 000,676,740 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Dshare1.nru
[2010/08/17 07:13:56 | 008,126,464 | —- | C] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/08/16 10:26:28 | 000,021,443 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\solidworks 2005 tor.docx
[2010/08/15 12:36:04 | 000,000,000 | —- | C] () – C:\WINDOWS\System\Win32s.ini
[2010/08/15 11:30:32 | 000,014,306 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Website hits.xlsx
[2010/08/13 16:12:21 | 000,024,175 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\UNEMP 2010.xlsx
[2010/08/13 10:50:04 | 000,011,073 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\LED footcandles and color temperature.docx
[2010/08/13 09:08:22 | 000,010,751 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\LED contacts 081310.docx
[2010/07/30 16:08:28 | 000,062,611 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\TestDocument.pdf
[2010/07/30 16:06:02 | 000,063,192 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Test Document.pdf
[2010/07/27 12:49:19 | 000,029,184 | —- | C] () – C:\general cover 072710.doc
[2010/07/27 12:42:42 | 000,034,816 | —- | C] () – C:\resume 072710.doc
[2010/07/26 14:47:14 | 000,035,569 | —- | C] () – C:\COPPER1.DXF
[2010/07/26 14:41:56 | 000,072,382 | —- | C] () – C:\PATTERN.DXF
[2010/07/26 13:57:45 | 000,052,342 | —- | C] () – C:\SLOTPLAT.DXF
[2010/07/26 13:30:57 | 000,015,588 | —- | C] () – C:\COPPER4.GCD
[2010/07/26 13:30:52 | 000,066,267 | —- | C] () – C:\COPPER4.DXF
[2010/07/26 13:23:37 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2010/07/26 13:23:23 | 000,001,902 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk
[2010/07/26 13:23:23 | 000,001,884 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SolidWorks eDrawings 2010.lnk
[2010/07/26 12:46:49 | 000,015,902 | —- | C] () – C:\COPPER3.BMP
[2010/07/26 12:46:26 | 000,038,528 | —- | C] () – C:\COPPER3.TIF
[2010/07/26 12:45:56 | 000,067,686 | —- | C] () – C:\COPPER3.DXF
[2010/07/26 10:40:09 | 000,015,888 | —- | C] () – C:\COPPER3.GCD
[2010/07/24 16:13:47 | 000,038,528 | —- | C] () – C:\COPPER.TIF
[2010/07/24 16:00:06 | 000,035,288 | —- | C] () – C:\COPPER.DXF
[2010/02/27 19:28:40 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/02/27 18:02:13 | 000,010,593 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2010/02/26 16:48:09 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/01/28 18:52:10 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/12/31 18:57:28 | 000,000,416 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/11/29 15:45:17 | 000,082,289 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/11/16 19:02:01 | 000,139,776 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/16 18:47:09 | 000,006,818 | —- | C] () – C:\WINDOWS\COOL.INI
[2009/11/16 13:55:48 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2009/11/11 19:44:45 | 000,000,000 | —- | C] () – C:\WINDOWS\Brohl144.ini
[2009/11/11 19:44:22 | 000,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2009/11/11 19:44:22 | 000,000,039 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2009/11/11 19:44:22 | 000,000,023 | —- | C] () – C:\WINDOWS\Brownie.ini
[2009/11/11 19:44:01 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\BRVPDNTA.DLL
[2009/11/11 19:44:00 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2009/11/11 19:44:00 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2009/11/11 19:44:00 | 000,011,568 | —- | C] () – C:\WINDOWS\HL-1440.INI
[2009/11/11 19:44:00 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2009/11/11 19:42:01 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_1440.ini
[2009/11/11 19:41:42 | 000,000,068 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2009/11/11 19:39:44 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2009/11/11 19:39:42 | 000,000,861 | —- | C] () – C:\WINDOWS\brwmark.ini
[2009/11/11 19:39:41 | 000,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/11/11 17:58:52 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\CNMVS5c.DLL
[2009/10/07 02:46:36 | 000,025,752 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 02:23:08 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2004/02/18 15:40:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[1996/12/04 01:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1996/12/04 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/03 15:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2010/08/16 10:36:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\A0F2B4576AD8BCE58806D40B0DCDAEE3
[2010/05/15 14:32:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AlpCAD Software
[2010/08/17 07:09:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\BitTorrent
[2009/12/31 19:12:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Canon
[2010/07/26 13:25:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\EDrawings
[2010/03/24 16:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ImgBurn
[2009/11/29 15:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Leadertech
[2010/02/23 17:18:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\No Company Name
[2010/02/22 16:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Publish Providers
[2009/12/31 18:57:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ScanSoft
[2010/02/22 18:20:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Sony
[2010/04/22 20:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Tific
[2010/06/16 11:45:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\YouSendIt
[2010/01/21 17:47:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2010/03/24 15:31:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2010/07/12 09:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/12/31 18:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/07/12 10:01:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2010/02/23 16:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/03/09 11:39:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2002/12/31 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2002/12/31 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2002/12/31 08:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2002/12/31 08:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: IASTOR.SYS >
[2002/12/31 08:00:00 | 000,467,200 | —- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 – C:\WINDOWS\dell\iastor\iastor.sys
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2002/12/31 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2002/12/31 08:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009/04/23 12:33:28 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/04/23 12:33:28 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/04/23 12:33:28 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Administrator\Desktop\Generic CADD.pif:SummaryInformation
< End of report >
Here is the extras text file:
OTL Extras logfile created on: 8/19/2010 12:54:38 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Administrator\Desktop\A1
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 4095 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 94.98 Gb Free Space | 31.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 74.52 Gb Total Space | 27.32 Gb Free Space | 36.66% Space Free | Partition Type: NTFS
Drive G: | 2.73 Gb Total Space | 2.72 Gb Free Space | 99.82% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
Drive I: | 7.45 Gb Total Space | 7.44 Gb Free Space | 99.94% Space Free | Partition Type: FAT32
Computer Name: DEN
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe File not found
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L File not found
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L File not found
Drive [find] – %SystemRoot%\Explorer.exe File not found
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"4369:TCP" = 4369:TCP:LocalSubNet:Enabled:enerGdot
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\SevenGens\EGDremote\EGDremote.exe" = C:\Program Files\SevenGens\EGDremote\EGDremote.exe:*:Enabled:EGDremote – ()
"C:\Program Files\NetworkView\NetworkView.exe" = C:\Program Files\NetworkView\NetworkView.exe:*:Enabled:NetworkView – (NetworkView Software)
"C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2411" = CanoScan LiDE 70
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{17C4A35A-2041-42C0-8D10-DEF55B47BE56}" = Adobe Premiere Elements 8.0 Templates
"{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
"{20207CCE-A8FA-44A7-AA3D-1E43EB307B27}" = Sony Sound Forge Audio Studio 9.0
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F5CFC1C-653B-4B22-9153-2BDDF2E03C0E}" = Seagate Manager Installer
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4685A344-6718-4923-AA9D-158A0A2E1CFB}" = SmartSound Quicktracks for Premiere Elements 8.0
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5C104E56-A441-429D-A609-D8A46EB92EA1}" = PCMark05
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{97E038E1-41AD-4C93-BCDC-6A2394AEE352}" = Vegas Movie Studio Platinum 9.0
"{9EDE7573-F2B0-4FAC-8928-A7E9381BCB91}" = ArcSoft MediaImpression for Kodak
"{A0E583D1-23F7-4C35-9620-B169D7715E4B}" = Adobe Premiere Elements 8.0
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5670-0000-900000000003}" = Korean Fonts Support For Adobe Reader 9
"{AFEA2EBC-E0CA-4A0D-BAB6-03B663B753AD}" = SolidWorks eDrawings 2010
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{CA72A82C-7DBC-4814-8CCB-E5BFAC59FAEF}" = ArcSoft MediaImpression for Kodak
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DDF9EE-C67F-368B-EB42-ECB44FD7556D}" = Adobe Photoshop.com Inspiration Browser
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E40CE517-0D42-4198-96B4-C8232B257EB5}" = Data Lifeguard Diagnostic for Windows
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{FC98FBE9-E931-494C-8717-497185371033}" = Nero 7 Ultra Edition
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
"Aide PDF to DXF Converter_is1" = Aide PDF to DXF Converter 9.5
"Any DWG to PDF Converter_is1" = Any DWG to PDF Converter 2010
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BitTorrent" = BitTorrent
"Brother 1440" = Brother 1440
"BROWNIE" = Brownie
"Canon CanoScan LiDE 70 User Registration" = Canon CanoScan LiDE 70 User Registration
"CanoScan Toolbox 5.0" = Canon CanoScan Toolbox 5.0
"Carbonite Setup Lite" = Carbonite Online Backup Setup
"Cool Edit 96" = Cool Edit 96
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"EnerGDot" = EnerGDot 1106
"EnerGDot Remote" = EnerGDot Remote 1.003
"HammerHead Rhythm Station" = HammerHead Rhythm Station
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Hot CPU Tester Lite_is1" = Hot CPU Tester Lite
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"InstallShield_{3F5CFC1C-653B-4B22-9153-2BDDF2E03C0E}" = Seagate Manager Installer
"InstallShield_{4685A344-6718-4923-AA9D-158A0A2E1CFB}" = SmartSound Quicktracks for Premiere Elements 8.0
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"InstallShield_{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NAV" = Norton AntiVirus
"NetworkView_is1" = NetworkView Version 1.4
"NSS" = Norton Security Scan
"PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.
1" = Adobe Photoshop.com Inspiration Browser
"PremElem80" = Adobe Premiere Elements 8.0
"PremElem80Templates" = Adobe Premiere Elements 8.0 Templates
"PROSet" = Intel® PRO Network Adapters and Drivers
"RarZilla Free Unrar" = RarZilla Free Unrar
"SpeedFan" = SpeedFan (remove only)
"ThumbsPlus 3.0f-S" = ThumbsPlus 3.0f-S
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WM Capture" = WM Capture
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Cadlibrary2009" = Cadlibrary2009
"GoToMeeting" = GoToMeeting 4.0.0.320
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/19/2010 9:37:01 AM | Computer Name = DEN | Source = Application Error | ID = 1000
Description = Faulting application divxupdate.exe, version 1.0.1.10, faulting module
msvcp80.dll, version 8.0.50727.4053, fault address 0x000100b5.
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >