This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help removing HTTPS Tidserv Request2

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This was posted 8/17/10 on Norton’s Internet Security Board (edited with recent knowledge)
I was told by them, I have Tidserev, and to come here for help.
I will be SO grateful if you can help. My business PC is down.

Embedded questions below.
“Bit torrent killed XP Pro explorer.exe”

My Bad! I used Bit Torrent to download a replacement for some broken old software and something ugly came with it. Tough lesson!

I left the PC running, went to bed, got up and the screen was blank with the desktop background and cursor. On reboot, Windows XP Pro boots, plays the welcome music, puts up my desktop background and the cursor..and that's it. Then, if the network is connected, every few minutes I get a Norton message saying a threat was found and fixed (not), then that Suspicious.Mystic was detected, only to have it repeat endlessly. Norton AV 2010 (I believe) Version 17.7.0.12 everything turned on, WIN XP Pro SP3 A Gateway Hyperthreaded 2.4GHz P4 loaded.

So I did some digging and explorer.exe is deleted from the c:\windows dir, and if I replace it, Norton immediately says it detected Suspicious.Mystic immediately takes it out. It seems that instead, svchost.exe may be run (not certain about that part).

I then discovered I could put explorer.exe on a thumb drive and run it from that using File Run from task manager. Yay, I think, I'll get the beast running and hook up with Symantec for a scan. Well guess what, it doesn’t work when the net is connected, it just reboots in a minute or 2 after some sort of attempted intrusion detection by Norton (fortunately, leaving the explorer.exe on the thumb drive).

Norton gives me that message about Suspicious. Mystic every time, and I now (since the bit torrent incident) get repeated hits from an attack from various Trojans, sometimes several in a minute now. Looking back at Norton history, seems like this has happened once in a while, for several days in the past, and I ignored it as all were "resolved", but the attacks are hundreds of times worse now…what a mess.

Pretty much same thing happens in safe mode. Hmmm Is Norton out to lunch?

Sometimes, it runs for several minutes with the net connected and I actually managed a Norton live update then ran a quick scan, exporting 17 resolved items (text file of Norton activity is available). Exported some older Norton history (also available if you want it). In fact, looking at the Norton text files, lots of stuff is detected as Suspicious.Mystic and blocked, deleted or quarantined, yet Norton virus scans didn't remove whatever is causing this.

The guys in the Norton forum universally think this is “HTTPS Tidserv Request2”.

I have a lot of business data on this PC (I know, I’m an idiot) including software that came with it I have no backup discs for , massive video files and a ton of CAD and Simulation data, and software I bought and downloaded over a couple years. I HAVE to revive this PC.

FIRST, before I start disinfection, I bought a Seagate Free Agent USB drive, and need advice before backing up.
1. Should I use the FreeAgent software to back up everything (way faster) or just get all the data files (will take a day or so, a zillion programs and directories to sift thru).
2. OR, can I copy everything, then do a search of the USB drive and delete all exe, dll, script, java files?
3. I have 3 drives, should I disinfect the PC with all 3 connected (as they were when the infection caught)
4. Curiosity…Since the downloaded software was never actually run, and the infection happened during the end of the download, how was the infection passed to my PC (I have a router with a firewall and Norton 2010 everything is enabled)?
5. What’s the chance Norton’s firewall actually prevented theft of data from my PC (this is actually pretty important here)?

Then I need help, bigtime! (I already know what an idiot I am for doing this!)
I am not comfortable with registry edits, but can follow detailed instructions. I have been around PCs since the 8080 but this stuff is scary!
I just ran OTL per instructions, one error on my part, I forgot to connect one of the SATA drives, is that OK? Should I reconnect and run or reconnect for disinfecting?

Here is th OTL output text file:

OTL logfile created on: 8/19/2010 12:54:38 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Administrator\Desktop\A1
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 4095 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 94.98 Gb Free Space | 31.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 74.52 Gb Total Space | 27.32 Gb Free Space | 36.66% Space Free | Partition Type: NTFS
Drive G: | 2.73 Gb Total Space | 2.72 Gb Free Space | 99.82% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
Drive I: | 7.45 Gb Total Space | 7.44 Gb Free Space | 99.94% Space Free | Partition Type: FAT32

Computer Name: DEN
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Desktop\A1\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (Seagate LLC)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - I:\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Nero\Nero 7\Core\nero.exe (Nero AG)
PRC - C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe (Nero AG)
PRC - C:\WINDOWS\system32\BRSS01A.EXE (brother Industries Ltd)
PRC - C:\WINDOWS\system32\BRSVC01A.EXE (brother Industries Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Administrator\Desktop\A1\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SolidWorks Licensing Service) – C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (AdobeActiveFileMonitor8.0) – C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (Brother XP spl Service) – C:\WINDOWS\system32\BRSVC01A.EXE (brother Industries Ltd)


========== Driver Services (SafeList) ==========

DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMNDIS.SYS File not found
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMIDS.SYS File not found
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMFW.SYS File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100817.008\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\VirusDefs\20100817.008\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\BASHDefs\20100719.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20100816.001\IDSXpx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1107000.00C\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\Ironx86.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1107000.00C\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\ccHPx86.sys (Symantec Corporation)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) QuickCam for Notebooks Deluxe(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (lvpopflt) – C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1107000.00C\SYMDS.SYS (Symantec Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (ArcCD) – C:\WINDOWS\System32\drivers\ArcCD.sys (ArcSoft Inc.)
DRV - (ArcUdfs) – C:\WINDOWS\System32\drivers\ArcUdfs.sys (ArcSoft Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (Nbf) – C:\WINDOWS\system32\drivers\NBF.SYS (Microsoft Corporation)
DRV - (PQNTDrv) – C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0

FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\IPSFFPlgn\ [2010/05/26 08:38:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/24 16:03:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/26 23:47:40 | 000,000,000 | —D | M]

[2009/11/12 10:58:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/08/16 11:48:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qltff2qb.default\extensions
[2010/06/24 10:06:36 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qltff2qb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/17 15:15:59 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/14 12:54:26 | 000,274,432 | —- | M] (Dassault Systèmes SolidWorks Corp.) – C:\Program Files\Mozilla Firefox\plugins\npEModelPlugin.dll

O1 HOSTS File: ([2002/12/31 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/23 16:43:28 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/04/23 16:43:28 | 000,000,000 | —- | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{6fa617fb-09bf-11df-8a21-0007e946bf6f}\Shell - "" = AutoRun
O33 - MountPoints2\{6fa617fb-09bf-11df-8a21-0007e946bf6f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6fa617fb-09bf-11df-8a21-0007e946bf6f}\Shell\AutoRun\command - "" = H:\MI.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (68130555115339776)

========== Files/Folders - Created Within 30 Days ==========

[2010/08/19 12:42:35 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Desktop\A1
[2010/08/19 09:23:42 | 000,000,000 | —D | C] – C:\src
[2010/08/17 20:11:38 | 001,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\Copy of zexplorer.exe
[2010/08/17 15:07:50 | 001,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\explorer.exe
[2010/08/17 00:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/08/17 00:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/08/17 00:26:27 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2010/08/16 10:37:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Windows Server
[2010/08/16 10:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\A0F2B4576AD8BCE58806D40B0DCDAEE3
[2010/08/15 12:35:50 | 000,000,000 | —D | C] – C:\EWB5
[2010/08/15 12:34:41 | 000,245,248 | —- | C] (Stirling Technologies, Inc.) – C:\WINDOWS\UNINST16.EXE
[2010/08/07 19:43:31 | 000,000,000 | —D | C] – C:\mikepida
[2010/08/06 11:46:48 | 000,000,000 | —D | C] – C:\New Folder (11)
[2010/08/06 09:45:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\test
[2010/07/28 19:09:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Ed T Rodriguez
[2010/07/28 00:29:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\IACT July
[2010/07/28 00:00:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\CREE
[2010/07/27 16:05:56 | 000,000,000 | —D | C] – C:\mold
[2010/07/27 10:39:54 | 000,000,000 | —D | C] – C:\New Folder (10)
[2010/07/26 13:25:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\EDrawings
[2010/07/26 13:23:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SolidWorks Shared
[2010/07/26 13:23:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\eDrawings2010
[2010/07/26 11:01:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\0710 Atlanta videos
[2010/07/23 10:50:18 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/19 11:31:29 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/19 11:31:13 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/19 11:31:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/19 10:39:07 | 008,126,464 | —- | M] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/08/19 10:39:07 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2010/08/19 10:04:41 | 000,139,776 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/19 09:53:02 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/18 17:54:16 | 000,000,490 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Administrator.job
[2010/08/18 14:27:20 | 000,346,132 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Droot share3.nri
[2010/08/18 13:25:25 | 000,242,910 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\droot share2.nri
[2010/08/18 12:41:48 | 000,676,740 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Droot share1.nru
[2010/08/18 11:57:22 | 000,676,740 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Dshare1.nru
[2010/08/17 13:50:29 | 000,000,507 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/17 13:50:29 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/17 13:50:29 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/08/16 10:26:29 | 000,021,443 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\solidworks 2005 tor.docx
[2010/08/16 08:10:13 | 000,014,306 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Website hits.xlsx
[2010/08/15 14:34:09 | 000,024,175 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\UNEMP 2010.xlsx
[2010/08/15 12:36:04 | 000,000,000 | —- | M] () – C:\WINDOWS\System\Win32s.ini
[2010/08/13 10:55:46 | 000,011,073 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\LED footcandles and color temperature.docx
[2010/08/13 09:18:00 | 000,010,751 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\LED contacts 081310.docx
[2010/08/13 08:18:28 | 000,297,256 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/13 00:28:04 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/13 00:27:05 | 000,488,244 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/13 00:27:05 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/13 00:27:05 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/02 17:03:31 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\YouSendIt.lnk
[2010/07/30 16:08:28 | 000,062,611 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\TestDocument.pdf
[2010/07/30 16:06:02 | 000,063,192 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Test Document.pdf
[2010/07/27 13:21:21 | 000,034,816 | —- | M] () – C:\resume 072710.doc
[2010/07/27 13:12:57 | 000,029,184 | —- | M] () – C:\general cover 072710.doc
[2010/07/27 02:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2010/07/26 23:47:41 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/07/26 14:47:14 | 000,035,569 | —- | M] () – C:\COPPER1.DXF
[2010/07/26 14:41:57 | 000,072,382 | —- | M] () – C:\PATTERN.DXF
[2010/07/26 14:01:22 | 000,052,342 | —- | M] () – C:\SLOTPLAT.DXF
[2010/07/26 13:30:57 | 000,015,588 | —- | M] () – C:\COPPER4.GCD
[2010/07/26 13:30:52 | 000,066,267 | —- | M] () – C:\COPPER4.DXF
[2010/07/26 13:23:37 | 000,000,000 | —- | M] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2010/07/26 13:23:23 | 000,001,902 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk
[2010/07/26 13:23:23 | 000,001,884 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SolidWorks eDrawings 2010.lnk
[2010/07/26 12:52:17 | 000,015,902 | —- | M] () – C:\COPPER3.BMP
[2010/07/26 12:46:29 | 000,038,528 | —- | M] () – C:\COPPER3.TIF
[2010/07/26 12:45:57 | 000,067,686 | —- | M] () – C:\COPPER3.DXF
[2010/07/26 12:45:42 | 000,015,888 | —- | M] () – C:\COPPER3.GCD
[2010/07/24 16:25:11 | 000,035,288 | —- | M] () – C:\COPPER.DXF
[2010/07/24 16:13:49 | 000,038,528 | —- | M] () – C:\COPPER.TIF
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/18 14:27:20 | 000,346,132 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Droot share3.nri
[2010/08/18 13:25:24 | 000,242,910 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\droot share2.nri
[2010/08/18 12:41:47 | 000,676,740 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Droot share1.nru
[2010/08/18 11:57:21 | 000,676,740 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Dshare1.nru
[2010/08/17 07:13:56 | 008,126,464 | —- | C] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/08/16 10:26:28 | 000,021,443 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\solidworks 2005 tor.docx
[2010/08/15 12:36:04 | 000,000,000 | —- | C] () – C:\WINDOWS\System\Win32s.ini
[2010/08/15 11:30:32 | 000,014,306 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Website hits.xlsx
[2010/08/13 16:12:21 | 000,024,175 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\UNEMP 2010.xlsx
[2010/08/13 10:50:04 | 000,011,073 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\LED footcandles and color temperature.docx
[2010/08/13 09:08:22 | 000,010,751 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\LED contacts 081310.docx
[2010/07/30 16:08:28 | 000,062,611 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\TestDocument.pdf
[2010/07/30 16:06:02 | 000,063,192 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Test Document.pdf
[2010/07/27 12:49:19 | 000,029,184 | —- | C] () – C:\general cover 072710.doc
[2010/07/27 12:42:42 | 000,034,816 | —- | C] () – C:\resume 072710.doc
[2010/07/26 14:47:14 | 000,035,569 | —- | C] () – C:\COPPER1.DXF
[2010/07/26 14:41:56 | 000,072,382 | —- | C] () – C:\PATTERN.DXF
[2010/07/26 13:57:45 | 000,052,342 | —- | C] () – C:\SLOTPLAT.DXF
[2010/07/26 13:30:57 | 000,015,588 | —- | C] () – C:\COPPER4.GCD
[2010/07/26 13:30:52 | 000,066,267 | —- | C] () – C:\COPPER4.DXF
[2010/07/26 13:23:37 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2010/07/26 13:23:23 | 000,001,902 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk
[2010/07/26 13:23:23 | 000,001,884 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SolidWorks eDrawings 2010.lnk
[2010/07/26 12:46:49 | 000,015,902 | —- | C] () – C:\COPPER3.BMP
[2010/07/26 12:46:26 | 000,038,528 | —- | C] () – C:\COPPER3.TIF
[2010/07/26 12:45:56 | 000,067,686 | —- | C] () – C:\COPPER3.DXF
[2010/07/26 10:40:09 | 000,015,888 | —- | C] () – C:\COPPER3.GCD
[2010/07/24 16:13:47 | 000,038,528 | —- | C] () – C:\COPPER.TIF
[2010/07/24 16:00:06 | 000,035,288 | —- | C] () – C:\COPPER.DXF
[2010/02/27 19:28:40 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/02/27 18:02:13 | 000,010,593 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2010/02/26 16:48:09 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/01/28 18:52:10 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/12/31 18:57:28 | 000,000,416 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/11/29 15:45:17 | 000,082,289 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/11/16 19:02:01 | 000,139,776 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/16 18:47:09 | 000,006,818 | —- | C] () – C:\WINDOWS\COOL.INI
[2009/11/16 13:55:48 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2009/11/11 19:44:45 | 000,000,000 | —- | C] () – C:\WINDOWS\Brohl144.ini
[2009/11/11 19:44:22 | 000,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2009/11/11 19:44:22 | 000,000,039 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2009/11/11 19:44:22 | 000,000,023 | —- | C] () – C:\WINDOWS\Brownie.ini
[2009/11/11 19:44:01 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\BRVPDNTA.DLL
[2009/11/11 19:44:00 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2009/11/11 19:44:00 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2009/11/11 19:44:00 | 000,011,568 | —- | C] () – C:\WINDOWS\HL-1440.INI
[2009/11/11 19:44:00 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2009/11/11 19:42:01 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_1440.ini
[2009/11/11 19:41:42 | 000,000,068 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2009/11/11 19:39:44 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2009/11/11 19:39:42 | 000,000,861 | —- | C] () – C:\WINDOWS\brwmark.ini
[2009/11/11 19:39:41 | 000,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/11/11 17:58:52 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\CNMVS5c.DLL
[2009/10/07 02:46:36 | 000,025,752 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 02:23:08 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2004/02/18 15:40:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[1996/12/04 01:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1996/12/04 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/03 15:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2010/08/16 10:36:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\A0F2B4576AD8BCE58806D40B0DCDAEE3
[2010/05/15 14:32:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AlpCAD Software
[2010/08/17 07:09:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\BitTorrent
[2009/12/31 19:12:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Canon
[2010/07/26 13:25:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\EDrawings
[2010/03/24 16:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ImgBurn
[2009/11/29 15:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Leadertech
[2010/02/23 17:18:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\No Company Name
[2010/02/22 16:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Publish Providers
[2009/12/31 18:57:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ScanSoft
[2010/02/22 18:20:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Sony
[2010/04/22 20:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Tific
[2010/06/16 11:45:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\YouSendIt
[2010/01/21 17:47:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2010/03/24 15:31:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2010/07/12 09:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/12/31 18:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/07/12 10:01:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2010/02/23 16:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/03/09 11:39:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2002/12/31 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2002/12/31 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010/01/22 11:53:49 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2002/12/31 08:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2002/12/31 08:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2002/12/31 08:00:00 | 000,467,200 | —- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 – C:\WINDOWS\dell\iastor\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2002/12/31 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2002/12/31 08:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/04/23 12:33:28 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/04/23 12:33:28 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/04/23 12:33:28 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Administrator\Desktop\Generic CADD.pif:SummaryInformation
< End of report >

Here is the extras text file:
OTL Extras logfile created on: 8/19/2010 12:54:38 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Administrator\Desktop\A1
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 4095 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 94.98 Gb Free Space | 31.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 74.52 Gb Total Space | 27.32 Gb Free Space | 36.66% Space Free | Partition Type: NTFS
Drive G: | 2.73 Gb Total Space | 2.72 Gb Free Space | 99.82% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
Drive I: | 7.45 Gb Total Space | 7.44 Gb Free Space | 99.94% Space Free | Partition Type: FAT32

Computer Name: DEN
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe File not found
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L File not found
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L File not found
Drive [find] – %SystemRoot%\Explorer.exe File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"4369:TCP" = 4369:TCP:LocalSubNet:Enabled:enerGdot

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\SevenGens\EGDremote\EGDremote.exe" = C:\Program Files\SevenGens\EGDremote\EGDremote.exe:*:Enabled:EGDremote – ()
"C:\Program Files\NetworkView\NetworkView.exe" = C:\Program Files\NetworkView\NetworkView.exe:*:Enabled:NetworkView – (NetworkView Software)
"C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2411" = CanoScan LiDE 70
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{17C4A35A-2041-42C0-8D10-DEF55B47BE56}" = Adobe Premiere Elements 8.0 Templates
"{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
"{20207CCE-A8FA-44A7-AA3D-1E43EB307B27}" = Sony Sound Forge Audio Studio 9.0
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F5CFC1C-653B-4B22-9153-2BDDF2E03C0E}" = Seagate Manager Installer
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4685A344-6718-4923-AA9D-158A0A2E1CFB}" = SmartSound Quicktracks for Premiere Elements 8.0
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5C104E56-A441-429D-A609-D8A46EB92EA1}" = PCMark05
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{97E038E1-41AD-4C93-BCDC-6A2394AEE352}" = Vegas Movie Studio Platinum 9.0
"{9EDE7573-F2B0-4FAC-8928-A7E9381BCB91}" = ArcSoft MediaImpression for Kodak
"{A0E583D1-23F7-4C35-9620-B169D7715E4B}" = Adobe Premiere Elements 8.0
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5670-0000-900000000003}" = Korean Fonts Support For Adobe Reader 9
"{AFEA2EBC-E0CA-4A0D-BAB6-03B663B753AD}" = SolidWorks eDrawings 2010
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{CA72A82C-7DBC-4814-8CCB-E5BFAC59FAEF}" = ArcSoft MediaImpression for Kodak
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DDF9EE-C67F-368B-EB42-ECB44FD7556D}" = Adobe Photoshop.com Inspiration Browser
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E40CE517-0D42-4198-96B4-C8232B257EB5}" = Data Lifeguard Diagnostic for Windows
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{FC98FBE9-E931-494C-8717-497185371033}" = Nero 7 Ultra Edition
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
"Aide PDF to DXF Converter_is1" = Aide PDF to DXF Converter 9.5
"Any DWG to PDF Converter_is1" = Any DWG to PDF Converter 2010
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BitTorrent" = BitTorrent
"Brother 1440" = Brother 1440
"BROWNIE" = Brownie
"Canon CanoScan LiDE 70 User Registration" = Canon CanoScan LiDE 70 User Registration
"CanoScan Toolbox 5.0" = Canon CanoScan Toolbox 5.0
"Carbonite Setup Lite" = Carbonite Online Backup Setup
"Cool Edit 96" = Cool Edit 96
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"EnerGDot" = EnerGDot 1106
"EnerGDot Remote" = EnerGDot Remote 1.003
"HammerHead Rhythm Station" = HammerHead Rhythm Station
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Hot CPU Tester Lite_is1" = Hot CPU Tester Lite
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"InstallShield_{3F5CFC1C-653B-4B22-9153-2BDDF2E03C0E}" = Seagate Manager Installer
"InstallShield_{4685A344-6718-4923-AA9D-158A0A2E1CFB}" = SmartSound Quicktracks for Premiere Elements 8.0
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"InstallShield_{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NAV" = Norton AntiVirus
"NetworkView_is1" = NetworkView Version 1.4
"NSS" = Norton Security Scan
"PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.
1" = Adobe Photoshop.com Inspiration Browser
"PremElem80" = Adobe Premiere Elements 8.0
"PremElem80Templates" = Adobe Premiere Elements 8.0 Templates
"PROSet" = Intel® PRO Network Adapters and Drivers
"RarZilla Free Unrar" = RarZilla Free Unrar
"SpeedFan" = SpeedFan (remove only)
"ThumbsPlus 3.0f-S" = ThumbsPlus 3.0f-S
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WM Capture" = WM Capture
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Cadlibrary2009" = Cadlibrary2009
"GoToMeeting" = GoToMeeting 4.0.0.320
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/19/2010 9:37:01 AM | Computer Name = DEN | Source = Application Error | ID = 1000
Description = Faulting application divxupdate.exe, version 1.0.1.10, faulting module
msvcp80.dll, version 8.0.50727.4053, fault address 0x000100b5.


========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.


NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
THANK YOU! I am here , printed your instructions and am proceeding. FYI latest Norton (updated around midnight) detects Trojan.Bamital!inf and backdoor.trojan repeatedly, but PC runs I will disable Norton. Will post results after scans.
I think, very bad news. Prior to last night, I was able to boot to a wallpaper image and run explorer.exe from a thumb drive to get my desktop. if I put it anywhere on C, the bug (or Norton) found it and deleted in immediately. Last night I managed to run Liveupdate, never shut off the PC, left the net connected for a half hour or so, saw repeated detections of Trojan Bamital!inf and backdoor.trojan, but the PC ran, still with explorer.exe on a flash disc. Putting explorer on the c drive, explorer was still removed but with a Bamital message now from Norton. Shut down for sleep. This am the PC will not boot in regular or safe mode, reboots repeatedly. F8 to safe stops at menu, anything I select reboots after several seconds. Maybe norton doing it? Net disconnected, same results. PC came with OS (XP Pro installed) and I do not have OS discs! I will attempt to find it from friends. I REALLY wish I didn't run Liveupdate….at least I could MAKE the PC run, albeit without net, or only for a few minutes with net connected. I will continue to try things to boot. Any ideas how to stop rebooting? I sure hope so…
your winlogon may have been deleted by the sounds of it. If you attempt to boot into safe mode, does the advanced menu screen actually appear or not? Are you able to choose "Last Known Good Configuration" ?
Yes advanced menu appears, like other options, last known good starts to boot xp….then reboots I have 2 other XP Pro PCs here, but alas, no system discs (I know, should have purchased them) Can I use one of them to create a bootable CD for THIS beast? Have never done that before. (Just a thought, doing NOTHING without your permission!) Thanks
Yes, that would be a possibility


alternatively, we can try this rescue CD

please do the following:

You will need a USB drive and a CD. (not absolutely necessary but format the USB before using it)

First do this:

Download GETxPUD.exe to the desktop of your clean computer
  • Run GETxPUD.exe
  • A new folder will appear on the desktop.
  • Open the GETxPUD folder and click on the get&burn.bat
  • The program will download xpud_0.9.2.iso, and upon finished will open BurnCDCC ready to burn the image.
  • Click on Start and follow the prompts to burn the image to a CD.


Insert your USB drive into the clean computer > we need to create and save a dummy file to it to enable the next file to run:

open notepad (type the word test) then save this file as vesamenu.c32
save as type: All Files (*.*)
save it to the USB


Now download the following file to the USB drive and run it:

NTBRHive.exe http://noahdfear.net/downloads/NTBRHive.exe

you should be presented with the following message:

USB drive ready to collect hive(s)


there will now be a file on the USB called hives.sh

you are now ready to boot the non bootable computer with the xPUD bootable CD.

Insert the CD into the CD drive and plug in the readied USB > make sure the nonbootable computer boots from the CD (boot menu is usually F9 or F12)


Once you have booted with the xPUD cd, choose your language, xPUD will then open a menu

select the "Files" on the left side of the menu by clicking on it.

It will open up an Explorer style directory tree,

expand the /mnt folder and locate the readied USB device.

In a common setup, the internal hard drive(s) and partitions will be identified as sda* and removable USB devices will be sdb*


Now do the following

when you open the USB tree (which is likely sdb1) verify that hives.sh is present - do not click off the sdb* key

make sure hives.sh is visible in the main window and only the sdb* key is selected,

now click Tool on the top menu bar, then select Open Terminal.

Terminal is the linux equivalent to a Windows command window, so a small black box will open.


In the terminal window type the following

bash hives.sh
then hit Enter

You be prompted to type the name of the hive to collect

type


software


(note: case sensitive > use lowercase)

then hit enter


the tool will now collect your software registry hive, (make sure your USB is large enough > some hives can be larger that 40MB)

(this can take a little while > please be patient)

When complete, press Enter to exit the script, then type exit and hit Enter to close the terminal window.

you may now remove the USB device and take it to the working computer,

the collected hive will be named ntbsoft on the usb device

open the USB on the clean computer and run the NTBRHive.exe again.

a command window will open - let it remain open while you run the following batch

Now do the following


open Notepad

  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as Query.bat
  • Change the Save as Type to All Files
  • and Save it on the desktop
  • Once saved, double click on the Query.bat file.
  • Post the resulting report.

@echo off
regedit /e peek1.txt "HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon"
type peek1.txt > look.txt
start notepad look.txt

leave the USB in place for now (just minimize it)

post the content of look.txt for me to see it.
When you say you need a USB drive, do you mean a flashdisk or a hard drive? (dont know size of files we're dealing with)

I have both, but the USB hard drive has important data on it, has not touched the infected PC, and 333Gig free
I cannot format it but am sure it is bug free
OK will do, have to go offline till ~8PM EDT Will post after I complete tasks If you're off, I'll be back tomorrow ~9am EDT thanks!
OK CatByte, Sorry it took a while! Here is your Look.txt: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon] "AutoRestartShell"=dword:00000001 "DefaultDomainName"="DEN" "DefaultUserName"="Administrator" "LegalNoticeCaption"="" "LegalNoticeText"="" "PowerdownAfterShutdown"="0" "ReportBootOk"="1" "Shell"="Explorer.exe" "ShutdownWithoutLogon"="0" "System"="" "Userinit"="C:\\WINDOWS\\system32\\Userinit.exe" "VmApplet"="rundll32 shell32,Control_RunDLL \"sysdm.cpl\"" "SfcQuota"=dword:ffffffff "allocatecdroms"="0" "allocatedasd"="0" "allocatefloppies"="0" "cachedlogonscount"="10" "forceunlocklogon"=dword:00000000 "passwordexpirywarning"=dword:0000000e "scremoveoption"="0" "AllowMultipleTSSessions"=dword:00000001 "UIHost"=hex(2):6c,00,6f,00,67,00,6f,00,6e,00,75,00,69,00,2e,00,65,00,78,00,65,\ 00,00,00 "LogonType"=dword:00000001 "Background"="0 0 0" "DebugServerCommand"="no" "SFCDisable"=dword:00000000 "WinStationsDisabled"="0" "HibernationPreviouslyEnabled"=dword:00000001 "ShowLogonOptions"=dword:00000000 "AltDefaultUserName"="Administrator" "AltDefaultDomainName"="DEN" "ChangePasswordUseKerberos"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions] [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}] @="Wireless" "ProcessGroupPolicy"="ProcessWIRELESSPolicy" "DllName"=hex(2):67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "NoUserPolicy"=dword:00000001 "NoGPOListChanges"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}] @="Folder Redirection" "ProcessGroupPolicyEx"="ProcessGroupPolicyEx" "DllName"=hex(2):66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "NoMachinePolicy"=dword:00000001 "NoSlowLink"=dword:00000001 "PerUserLocalSettings"=dword:00000001 "NoGPOListChanges"=dword:00000000 "NoBackgroundPolicy"=dword:00000000 "GenerateGroupPolicy"="GenerateGroupPolicy" "EventSources"=hex(7):28,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,00,52,00,65,\ 00,64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,2c,00,41,00,70,00,\ 70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,29,00,00,00,00,00 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}] @="Microsoft Disk Quota" "NoMachinePolicy"=dword:00000000 "NoUserPolicy"=dword:00000001 "NoSlowLink"=dword:00000001 "NoBackgroundPolicy"=dword:00000001 "NoGPOListChanges"=dword:00000001 "PerUserLocalSettings"=dword:00000000 "RequiresSuccessfulRegistry"=dword:00000001 "EnableAsynchronousProcessing"=dword:00000000 "DllName"=hex(2):64,00,73,00,6b,00,71,00,75,00,6f,00,74,00,61,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "ProcessGroupPolicy"="ProcessGroupPolicy" [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}] @="QoS Packet Scheduler" "ProcessGroupPolicy"="ProcessPSCHEDPolicy" "DllName"=hex(2):67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "NoUserPolicy"=dword:00000001 "NoGPOListChanges"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}] @="Scripts" "ProcessGroupPolicy"="ProcessScriptsGroupPolicy" "ProcessGroupPolicyEx"="ProcessScriptsGroupPolicyEx" "GenerateGroupPolicy"="GenerateScriptsGroupPolicy" "DllName"=hex(2):67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "NoSlowLink"=dword:00000001 "NoGPOListChanges"=dword:00000001 "NotifyLinkTransition"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}] @="Internet Explorer Zonemapping" "DllName"="C:\\WINDOWS\\system32\\iedkcs32.dll" "ProcessGroupPolicy"="ProcessGroupPolicyForZoneMap" "NoGPOListChanges"=dword:00000001 "RequiresSucessfulRegistry"=dword:00000001 "DisplayName"="@C:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051" "RequiresSuccessfulRegistry"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}] @="Internet Explorer User Accelerators" "DisplayName"="@C:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051" "DllName"="C:\\WINDOWS\\system32\\iedkcs32.dll" "NoGPOListChanges"=dword:00000001 "ProcessGroupPolicy"="ProcessGroupPolicyForActivities" "ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx" "RequiresSuccessfulRegistry"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] "ProcessGroupPolicy"="SceProcessSecurityPolicyGPO" "GenerateGroupPolicy"="SceGenerateGroupPolicy" "ExtensionRsopPlanningDebugLevel"=dword:00000001 "ProcessGroupPolicyEx"="SceProcessSecurityPolicyGPOEx" "ExtensionDebugLevel"=dword:00000001 "DllName"=hex(2):73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,\ 00,00 @="Security" "NoUserPolicy"=dword:00000001 "NoGPOListChanges"=dword:00000001 "EnableAsynchronousProcessing"=dword:00000001 "MaxNoGPOListChangesInterval"=dword:000003c0 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}] "ProcessGroupPolicyEx"="ProcessGroupPolicyEx" "GenerateGroupPolicy"="GenerateGroupPolicy" "ProcessGroupPolicy"="ProcessGroupPolicy" "DllName"="C:\\WINDOWS\\system32\\iedkcs32.dll" @="Internet Explorer Branding" "NoSlowLink"=dword:00000001 "NoBackgroundPolicy"=dword:00000000 "NoGPOListChanges"=dword:00000001 "NoMachinePolicy"=dword:00000001 "DisplayName"="@C:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3014" [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}] "ProcessGroupPolicy"="SceProcessEFSRecoveryGPO" "DllName"=hex(2):73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,\ 00,00 @="EFS recovery" "NoUserPolicy"=dword:00000001 "NoGPOListChanges"=dword:00000001 "RequiresSuccessfulRegistry"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}] @="802.3 Group Policy" "DisplayName"=hex(2):40,00,64,00,6f,00,74,00,33,00,67,00,70,00,63,00,6c,00,6e,\ 00,74,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,31,00,30,00,30,00,00,00 "ProcessGroupPolicyEx"="ProcessLANPolicyEx" "GenerateGroupPolicy"="GenerateLANPolicy" "DllName"=hex(2):64,00,6f,00,74,00,33,00,67,00,70,00,63,00,6c,00,6e,00,74,00,\ 2e,00,64,00,6c,00,6c,00,00,00 "NoUserPolicy"=dword:00000001 "NoGPOListChanges"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}] @="Microsoft Offline Files" "DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\ 00,73,00,63,00,75,00,69,00,2e,00,64,00,6c,00,6c,00,00,00 "EnableAsynchronousProcessing"=dword:00000000 "NoBackgroundPolicy"=dword:00000000 "NoGPOListChanges"=dword:00000000 "NoMachinePolicy"=dword:00000000 "NoSlowLink"=dword:00000000 "NoUserPolicy"=dword:00000001 "PerUserLocalSettings"=dword:00000000 "ProcessGroupPolicy"="ProcessGroupPolicy" "RequiresSuccessfulRegistry"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}] @="Software Installation" "DllName"=hex(2):61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "ProcessGroupPolicyEx"="ProcessGroupPolicyObjectsEx" "GenerateGroupPolicy"="GenerateGroupPolicy" "NoBackgroundPolicy"=dword:00000000 "RequiresSucessfulRegistry"=dword:00000000 "NoSlowLink"=dword:00000001 "PerUserLocalSettings"=dword:00000001 "EventSources"=hex(7):28,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\ 00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,6e,00,\ 74,00,2c,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,\ 00,29,00,00,00,28,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,00,6c,00,\ 6c,00,65,00,72,00,2c,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\ 00,6f,00,6e,00,29,00,00,00,00,00 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}] @="Internet Explorer Machine Accelerators" "DisplayName"="@C:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051" "DllName"="C:\\WINDOWS\\system32\\iedkcs32.dll" "NoGPOListChanges"=dword:00000001 "ProcessGroupPolicy"="ProcessGroupPolicyForActivities" "ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx" "RequiresSuccessfulRegistry"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}] @="IP Security" "ProcessGroupPolicy"="ProcessIPSECPolicy" "DllName"=hex(2):67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "NoUserPolicy"=dword:00000001 "NoGPOListChanges"=dword:00000000 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] "Asynchronous"=dword:00000001 "DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,\ 00,69,00,6d,00,73,00,6e,00,74,00,66,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "Startup"="WlDimsStartup" "Shutdown"="WlDimsShutdown" "Logon"="WlDimsLogon" "Logoff"="WlDimsLogoff" "StartShell"="WlDimsStartShell" "Lock"="WlDimsLock" "Unlock"="WlDimsUnlock" [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] @="" "DLLName"="igfxsrvc.dll" "Asynchronous"=dword:00000001 "Impersonate"=dword:00000001 "Unlock"="WinlogonUnlockEvent" [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] "Logon"="WLEventLogon" "Logoff"="WLEventLogoff" "Startup"="WLEventStartup" "Shutdown"="WLEventShutdown" "StartScreenSaver"="WLEventStartScreenSaver" "StopScreenSaver"="WLEventStopScreenSaver" "Lock"="WLEventLock" "Unlock"="WLEventUnlock" "StartShell"="WLEventStartShell" "PostShell"="WLEventPostShell" "Disconnect"="WLEventDisconnect" "Reconnect"="WLEventReconnect" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000000 "SafeMode"=dword:00000001 "MaxWait"=dword:ffffffff "DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Event"=dword:00000000 "InstallEvent"="1.9.0040.0" [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings] @="" "Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\ 00,00,14,9d,90,9a,53,4b,78,4d,9f,f8,5b,74,9d,90,95,93,04,00,00,00,04,00,00,\ 00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,63,5a,0d,3f,06,62,e9,f1,\ e7,f6,bf,b7,c2,2b,f2,af,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,2d,\ 06,9f,cf,5c,de,14,a7,1b,48,52,41,91,4d,06,71,b0,01,00,00,43,a8,f8,ff,61,74,\ 6c,24,46,13,90,c5,79,1d,15,52,b7,04,f3,49,6c,13,dc,31,33,39,7f,5e,b3,f4,ac,\ fd,b3,c1,56,60,12,17,fe,f7,89,1a,87,a6,bb,89,a8,be,de,26,0f,fa,7d,e4,35,d0,\ 03,d0,b7,c3,ed,ad,a7,75,5c,1d,48,6d,72,ba,cc,c9,cd,52,6f,26,7b,a4,e1,42,10,\ 05,40,2b,34,7d,48,75,0e,99,bf,dd,34,24,70,2f,e4,d2,70,23,a3,40,bc,5e,a0,13,\ 80,62,15,a1,fb,f6,ec,9e,92,c1,0b,cf,5f,2c,3e,e0,34,7f,cd,cc,81,20,5e,56,ec,\ b5,57,44,b4,54,a0,e0,a2,af,b5,a6,0a,fe,45,74,cd,57,4d,e0,ac,f9,0f,40,f1,7a,\ 95,63,bf,d9,08,a8,dc,35,a4,54,5c,85,04,f4,eb,64,90,8b,f3,ed,32,ab,07,20,13,\ ad,10,8b,ac,ed,d3,82,3e,5a,a2,34,a2,a8,89,0d,fd,19,a0,ae,6e,76,d9,ea,c3,47,\ 58,c5,2e,28,d0,d9,1d,68,76,52,ef,35,8c,31,e3,5f,e8,70,2e,60,c2,13,31,17,c9,\ c8,0c,8f,6a,52,06,54,02,60,fb,e6,aa,a4,b6,f4,06,5e,84,ae,d6,9f,11,b8,18,01,\ 9c,b7,00,9f,4e,30,e0,b0,ab,d7,66,6f,38,1b,c7,77,4d,7a,32,ec,10,bd,16,ba,0f,\ a8,07,5d,47,f3,51,26,35,81,b0,c1,48,82,28,66,36,a4,45,79,fc,af,de,3a,21,4f,\ 4c,89,ba,e7,22,e4,41,0f,df,71,4f,0f,cf,1a,ad,af,3c,a0,ef,d5,5e,6e,44,71,34,\ 43,81,6c,43,5b,bb,d0,58,9b,57,ca,19,57,96,06,f0,09,c6,a2,db,5a,f7,89,47,3b,\ 66,8a,af,03,b0,52,c2,d0,85,30,75,2d,61,86,19,96,5f,20,8c,47,8b,67,91,88,6a,\ a3,91,f6,26,2b,86,78,b7,1e,71,29,15,53,55,fb,6d,41,3a,b1,2a,16,25,72,dc,4e,\ c3,04,5d,f4,ac,c0,dc,3d,4e,75,06,e8,fa,53,2c,01,20,b6,59,72,6c,19,d3,e1,79,\ 2e,14,00,00,00,2d,93,1a,e5,68,a7,a4,86,07,bb,76,45,b3,d7,39,29,0d,25,d3,62 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts] [HKEY_LOCAL_MACHINE\ntbsoft\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList] "HelpAssistant"=dword:00000000 "TsInternetUser"=dword:00000000 "SQLAgentCmdExec"=dword:00000000 "NetShowServices"=dword:00000000 "IWAM_"=dword:00010000 "IUSR_"=dword:00010000 "VUSR_"=dword:00010000
OK

the userinit is correct in the registry hive so the actual file may be missing, type exit in the open command window to unload the hive.

Now we need to save another file to the USB to run and look for the files that may have been deleted by your AV

please do the following:

download http://noahdfear.net/downloads/driver.sh and save it to the USB

  • Remove the USB and insert it in the infected computer
  • (the computer should still be booted with xPUD - if it isn't reboot into xPUD)
  • Press File
  • Expand mnt
  • Click on the folder that represents your USB drive (sdb1)
  • Confirm that you see the driver.sh that you downloaded there
  • Press Tool at the top
  • Choose Open Terminal
  • Type bash driver.sh -f
  • Press Enter
  • You will be prompted to input a filename.
  • Type the following:

    userinit.exe

  • Press Enter
  • the script will search for this file.
  • After it has finished a report will be automatically saved to the USB drive as filefind.txt
  • locate this file and right click it > choose rename > rename it to userinit.txt

    now we will do the same for explorer.exe and winlogon.exe

  • go back to Tool > open terminal
  • Type bash driver.sh -f
  • Press Enter
  • You will be prompted to input a filename.
  • Type the following:

    explorer.exe

  • Press Enter
  • repeat the rename procedure > locate filefind.txt > right click it > rename > rename it explorer.txt
  • Do the same for winlogon.exe



Please note - all text entries are case sensitive
Copy and paste the userinit.txt, explorer.txt and winlogon.txt for my review

Please advise if anything is unclear or you encounter any issues

we need to rename filefind.txt each time as the report is overwritten each time we do a search,

once I have the reports of where these files are located and if they exist, we can put the files where they are supposed to be so you can boot normally.
OK I'm back
I know you're the pro–just some notes first:
I have a clean copy of explorer.exe on the flashdrive

As you may know Quads in the Norton Antivirus forum has a ton of info on how this bug works, predicting winlogon would be gone and I know explorer.exe is because norton removes it as soon as you put it in the c:\windows directory.

Before I updated with Liveupdate, I WAS able to get the desktop with explorer running from this same flashdisk, using program manager. No more….. New virus definitions ID the bug and cleans out those files.

Maybe all of you work together on some level? He says he has provided virus samples to Norton and is working with them on it.

You probably know all this, just trying to avoid you're having to figure out stuf someone else has.

Per your instructions:
userinit.txt:
Search results for userinit.exe

a93aee1928a9d7ce3e16d24ec7380f89 /mnt/sda1/WINDOWS/system32/userinit.exe
25.5K Apr 14 2008

a93aee1928a9d7ce3e16d24ec7380f89 /mnt/sda1/WINDOWS/ServicePackFiles/i386/userinit.exe
25.5K Apr 14 2008

39b1ffb03c2296323832acbae50d2aff /mnt/sda1/WINDOWS/$NtServicePackUninstall$/userinit.exe
24.0K Dec 31 2002


and explorer.txt:
Search results for explorer.exe

12896823fb95bfb3dc9b46bcaedc9923 /mnt/sdb1/explorer.exe
1009.5K Apr 13 2008

12896823fb95bfb3dc9b46bcaedc9923 /mnt/sda1/explorer.exe
1009.5K Apr 14 2008

12896823fb95bfb3dc9b46bcaedc9923 /mnt/sda1/WINDOWS/system/explorer.exe
1009.5K Apr 14 2008

12896823fb95bfb3dc9b46bcaedc9923 /mnt/sda1/WINDOWS/system32/dllcache/explorer.exe
1009.5K Apr 14 2008

12896823fb95bfb3dc9b46bcaedc9923 /mnt/sda1/WINDOWS/ServicePackFiles/i386/explorer.exe
1009.5K Apr 14 2008

a0732187050030ae399b241436565e64 /mnt/sda1/WINDOWS/$NtServicePackUninstall$/explorer.exe
1008.0K Dec 31 2002

And winlogon.txt
Search results for winlogon.exe

ed0ef0a136dec83df69f04118870003e /mnt/sda1/WINDOWS/system32/dllcache/winlogon.exe
496.0K Apr 14 2008

ed0ef0a136dec83df69f04118870003e /mnt/sda1/WINDOWS/ServicePackFiles/i386/winlogon.exe
496.0K Apr 14 2008

01c3346c241652f43aed8e2149881bfe /mnt/sda1/WINDOWS/$NtServicePackUninstall$/winlogon.exe
490.5K Dec 31 2002
Hi

Yes thanks I am aware the various AV companies are working on this - it is a new infection and there are many developments are being made, but I am seriously not a fan of a company that eats system files regardless if they are infected or not so a user cannot boot.

When we get this machine up and running, I suggest uninstalling your security programs immediately so that it will not eat the files again, then we will set about cleaning any remaining infection from the machine, then you can reinstall what security programs you wish. (I can recommend some if you wish)


we need to replace those files as they are not where they should be,

so please do the following:

Please download rep.sh from the following location and save it to the USB

http://noahdfear.net/downloads/beta/rep.sh


next - do the following:

open notepad on the clean machine and copy/paste the following into the open notepad:

/mnt/sda1/WINDOWS/system32/winlogon.exe::/mnt/sda1/WINDOWS/system32/dllcache/winlogon.exe::
/mnt/sda1/WINDOWS/explorer.exe::/mnt/sda1/WINDOWS/ServicePackFiles/i386/explorer.exe::
/mnt/sda1/WINDOWS/system32/userinit.exe::/mnt/sda1/WINDOWS/ServicePackFiles/i386/userinit.exe::


now save this as replace.txt , save as All files, and save it to the USB


now plug the USB back into the infected machine and open the sdb tree where rep.sh and the replace.txt resides.

Now on the menu bar go to Tool > Open Terminal

now type bash rep.sh -r

the script will replace the missing files.

Now go to Home > restart

remove the xPUD CD from the machine before it starts to reboot and allow the machine to reboot normally.

Please make sure you immediately disable the security programs so they do not delete those files again > they shouldn't actually be infected as we have replaced them with clean copies, but just incase the name is targeted.

Please advise when you are booted normally.

I then want you to run ComboFix on the machine:




Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI