This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Nukesploit Request

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got the url here from the Norton forums (nothing done yet). Here's the exported event from Norton Internet Security:

Severity: High
Activity: An intrusion attempt by SURKNIGHT-PC was blocked. Application path
Date & Time: 8/25/2010 11:46 AM
Status: Blocked
Recommended Action: No Action Required
Risk Name: HTTP Nukesploit Request
Attacking Computer: SURKNIGHT-PC (192.168.1.100, 49938)
Attacker URL: alphashow.ru:8080/jquery.jxx?v=5.3.4
Destination Address: 188.165.192.106, 8080
Source Address: 192.168.1.100 (192.168.1.100)
Traffic Description: TCP, Port 49938

TIA for any assistance.
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message to me on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


Scanning with GMER

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

Notes:
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



NEXT:



Please download MBRCheck.exe to your Desktop. Run the application.

If no infection is found, it will produce a report on the desktop. Post that report in your next reply.

If an infection is found, you will be presented with the following dialog:

Enter 'Y' and hit ENTER for more options, or 'N' to exit:


Type N and press Enter. A report will be produced on the desktop. Post that report in your next reply.



NEXT:




  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hello SweetTech. I ran GMER as instructed, but it didn't find anything and the log file was blank. Also, the only options that were available were Services, Registry, and Files - everything else was greyed out (yes, I ran GMER as administrator). Should I go on and run MBRCheck?
Here's the MBRCheck output: (Going to run OTL now) MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows Vista Ultimate Edition Windows Information: Service Pack 2 (build 6002), 64-bit Base Board Manufacturer: PEGATRON CORPORATION BIOS Manufacturer: Phoenix Technologies, LTD System Manufacturer: HP-Pavilion System Product Name: FK480AV-ABA a6660z Logical Drives Mask: 0x000003fc Kernel Drivers (total 155): 0x01E51000 \SystemRoot\system32\ntoskrnl.exe 0x01E0B000 \SystemRoot\system32\hal.dll 0x00609000 \SystemRoot\system32\kdcom.dll 0x00613000 \SystemRoot\system32\PSHED.dll 0x00627000 \SystemRoot\system32\CLFS.SYS 0x00684000 \SystemRoot\system32\CI.dll 0x0080C000 \SystemRoot\system32\drivers\Wdf01000.sys 0x008E6000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x008F4000 \SystemRoot\system32\drivers\acpi.sys 0x0094A000 \SystemRoot\system32\drivers\WMILIB.SYS 0x00953000 \SystemRoot\system32\drivers\msisadrv.sys 0x0095D000 \SystemRoot\system32\drivers\pci.sys 0x0098D000 \SystemRoot\System32\drivers\partmgr.sys 0x009A2000 \SystemRoot\system32\drivers\volmgr.sys 0x00736000 \SystemRoot\System32\drivers\volmgrx.sys 0x009B6000 \SystemRoot\system32\drivers\pciide.sys 0x009BD000 \SystemRoot\system32\drivers\PCIIDEX.SYS 0x009CD000 \SystemRoot\System32\drivers\mountmgr.sys 0x0079C000 \SystemRoot\system32\drivers\nvraid.sys 0x007BF000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x009E0000 \SystemRoot\system32\drivers\atapi.sys 0x00A0A000 \SystemRoot\system32\drivers\ataport.SYS 0x00A2E000 \SystemRoot\system32\drivers\nvstor64.sys 0x00A59000 \SystemRoot\system32\drivers\storport.sys 0x00AB6000 \SystemRoot\system32\drivers\fltmgr.sys 0x00AFD000 \SystemRoot\system32\drivers\fileinfo.sys 0x00B11000 \SystemRoot\system32\drivers\NISx64\1008000.029\SYMEFA64.SYS 0x00B78000 \SystemRoot\System32\Drivers\ksecdd.sys 0x00C0B000 \SystemRoot\system32\drivers\ndis.sys 0x00E0A000 \SystemRoot\system32\drivers\msrpc.sys 0x00E5A000 \SystemRoot\system32\drivers\NETIO.SYS 0x01009000 \SystemRoot\System32\drivers\tcpip.sys 0x0117F000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x01200000 \SystemRoot\System32\Drivers\Ntfs.sys 0x01380000 \SystemRoot\system32\drivers\volsnap.sys 0x013C4000 \SystemRoot\System32\Drivers\spldr.sys 0x013CC000 \SystemRoot\System32\Drivers\mup.sys 0x011AB000 \SystemRoot\System32\drivers\ecache.sys 0x011D7000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x013DE000 \SystemRoot\system32\drivers\disk.sys 0x013F2000 \SystemRoot\system32\drivers\crcdisk.sys 0x00F09000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x00F16000 \SystemRoot\system32\DRIVERS\amdk8.sys 0x00F2A000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x00F40000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x00F4C000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x00F5A000 \SystemRoot\system32\DRIVERS\usbohci.sys 0x00F65000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x00FAB000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x00FBC000 \SystemRoot\system32\DRIVERS\ohci1394.sys 0x00FCE000 \SystemRoot\system32\DRIVERS\1394BUS.SYS 0x0340B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x03602000 \SystemRoot\system32\DRIVERS\nvmfdx64.sys 0x0376F000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x03806000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys 0x04300000 \SystemRoot\system32\DRIVERS\nvBridge.kmd 0x04302000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x043E5000 \SystemRoot\System32\drivers\watchdog.sys 0x0378B000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x037C4000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x037D1000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x037F4000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x034F8000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x03529000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x03539000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x03557000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x04408000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0x044A2000 \SystemRoot\system32\DRIVERS\termdd.sys 0x044B5000 \SystemRoot\system32\DRIVERS\swenum.sys 0x044B7000 \SystemRoot\system32\DRIVERS\ks.sys 0x044EB000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x044F6000 \SystemRoot\system32\DRIVERS\umbus.sys 0x04506000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x0454E000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x04A0C000 \SystemRoot\system32\drivers\RTKVHD64.sys 0x04B74000 \SystemRoot\system32\drivers\portcls.sys 0x04BAF000 \SystemRoot\system32\drivers\drmk.sys 0x04BD2000 \SystemRoot\system32\drivers\ksthunk.sys 0x04BD8000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x04BE2000 \SystemRoot\System32\Drivers\Null.SYS 0x04BF5000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x04562000 \SystemRoot\System32\drivers\vga.sys 0x04570000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x04A00000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x04BEB000 \SystemRoot\system32\drivers\rdpencdd.sys 0x04595000 \SystemRoot\System32\Drivers\Msfs.SYS 0x045A0000 \SystemRoot\System32\Drivers\Npfs.SYS 0x045B1000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x045BA000 \SystemRoot\system32\DRIVERS\tdx.sys 0x0356F000 \SystemRoot\System32\Drivers\NISx64\1008000.029\SYMTDI.SYS 0x035BB000 \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 0x045D7000 \SystemRoot\System32\Drivers\NISx64\1008000.029\SYMNDISV.SYS 0x00FDE000 \SystemRoot\System32\Drivers\NISx64\1008000.029\SYMFW.SYS 0x00DCE000 \SystemRoot\system32\DRIVERS\smb.sys 0x04C0B000 \SystemRoot\system32\drivers\afd.sys 0x04C76000 \SystemRoot\System32\DRIVERS\netbt.sys 0x04CBA000 \SystemRoot\system32\DRIVERS\pacer.sys 0x04CD8000 \SystemRoot\system32\DRIVERS\SymIMv.sys 0x04CE3000 \SystemRoot\system32\DRIVERS\netbios.sys 0x04CF2000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x04D0D000 \SystemRoot\system32\drivers\NISx64\1008000.029\SRTSPX64.SYS 0x04D21000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x04D3D000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x04D3F000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x04D8C000 \SystemRoot\system32\DRIVERS\usbscan.sys 0x04D9C000 \SystemRoot\system32\drivers\nsiproxy.sys 0x04DA8000 \SystemRoot\system32\DRIVERS\usbprint.sys 0x04E0C000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100825.001\IDSvia64.sys 0x04E82000 \SystemRoot\system32\DRIVERS\dot4usb.sys 0x04E92000 \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys 0x04F08000 \SystemRoot\system32\DRIVERS\Dot4.sys 0x04F30000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0x04F48000 \SystemRoot\system32\DRIVERS\Dot4Prt.sys 0x04F52000 \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0x04F77000 \SystemRoot\system32\drivers\csc.sys 0x04DB3000 \SystemRoot\System32\Drivers\dfsc.sys 0x05007000 \SystemRoot\System32\Drivers\NISx64\1008000.029\ccHPx64.sys 0x0509A000 \SystemRoot\System32\Drivers\NISx64\1008000.029\BHDrvx64.sys 0x050F1000 \SystemRoot\System32\Drivers\crashdmp.sys 0x050FF000 \SystemRoot\System32\Drivers\dump_diskdump.sys 0x05109000 \SystemRoot\System32\Drivers\dump_nvstor64.sys 0x05134000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x05147000 \SystemRoot\system32\DRIVERS\netr7364.sys 0x00060000 \SystemRoot\System32\win32k.sys 0x051E7000 \SystemRoot\System32\drivers\Dxapi.sys 0x04FED000 \SystemRoot\system32\DRIVERS\monitor.sys 0x004C0000 \SystemRoot\System32\TSDDD.dll 0x006C0000 \SystemRoot\System32\cdd.dll 0x04DD0000 \SystemRoot\system32\drivers\luafv.sys 0x09400000 \SystemRoot\system32\drivers\spsys.sys 0x0949A000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x094AE000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x094E2000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x094ED000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x09505000 \SystemRoot\system32\drivers\HTTP.sys 0x095A8000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x095D1000 \SystemRoot\system32\DRIVERS\bowser.sys 0x00EB3000 \SystemRoot\System32\drivers\mpsdrv.sys 0x00ECD000 \SystemRoot\system32\drivers\mrxdav.sys 0x09A03000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x09A2C000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x09A75000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x09A94000 \SystemRoot\System32\DRIVERS\srv2.sys 0x09AC6000 \SystemRoot\System32\DRIVERS\srv.sys 0x0A00B000 \SystemRoot\system32\drivers\peauth.sys 0x0A0C1000 \SystemRoot\System32\Drivers\secdrv.SYS 0x0A0CC000 \SystemRoot\System32\drivers\tcpipreg.sys 0x0A0DC000 \SystemRoot\system32\DRIVERS\WUDFRd.sys 0x0A0FC000 \SystemRoot\system32\DRIVERS\WUDFPf.sys 0x0A112000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x0A12E000 \SystemRoot\system32\DRIVERS\ipnat.sys 0x0A15D000 \SystemRoot\System32\Drivers\NISx64\1008000.029\SRTSP64.SYS 0x0B404000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100826.002\EX64.SYS 0x0B5BE000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100826.002\ENG64.SYS 0x77620000 \Windows\System32\ntdll.dll Processes (total 70): 0 System Idle Process 4 System 524 C:\Windows\System32\smss.exe 592 csrss.exe 644 C:\Windows\System32\wininit.exe 668 csrss.exe 700 C:\Windows\System32\services.exe 712 C:\Windows\System32\lsass.exe 720 C:\Windows\System32\lsm.exe 856 C:\Windows\System32\svchost.exe 888 C:\Windows\System32\winlogon.exe 944 C:\Windows\System32\nvvsvc.exe 972 C:\Windows\System32\svchost.exe 548 C:\Windows\System32\svchost.exe 556 C:\Windows\System32\svchost.exe 580 C:\Windows\System32\svchost.exe 1064 C:\Windows\System32\audiodg.exe 1092 C:\Windows\System32\svchost.exe 1108 C:\Windows\System32\SLsvc.exe 1204 C:\Windows\System32\svchost.exe 1264 C:\Windows\System32\nvvsvc.exe 1392 C:\Windows\System32\svchost.exe 1608 C:\Windows\System32\spoolsv.exe 1632 C:\Windows\System32\svchost.exe 1856 C:\Windows\System32\agr64svc.exe 1868 C:\Windows\SysWOW64\ASTSRV.EXE 1892 C:\Windows\SysWOW64\svchost.exe 1912 C:\Windows\SysWOW64\svchost.exe 1944 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe 1328 C:\Windows\System32\svchost.exe 1496 C:\Windows\SysWOW64\nlssrv32.exe 1640 C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe 2056 C:\Windows\System32\svchost.exe 2068 C:\Windows\System32\svchost.exe 2096 C:\Windows\System32\svchost.exe 2128 C:\Windows\System32\svchost.exe 2160 C:\Windows\System32\SearchIndexer.exe 2760 C:\Windows\System32\dwm.exe 2792 C:\Windows\explorer.exe 2820 WUDFHost.exe 2960 C:\Windows\System32\taskeng.exe 2968 C:\Program Files\Windows Sidebar\sidebar.exe 2976 C:\Windows\ehome\ehtray.exe 3156 C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe 3164 C:\Windows\ehome\ehmsas.exe 3232 C:\hp\support\hpsysdrv.exe 3240 C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe 3248 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe 3336 C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe 3344 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 3352 C:\Windows\System32\taskeng.exe 3572 C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe 3688 C:\Program Files\Windows Media Player\wmpnscfg.exe 1196 C:\Program Files\Windows Sidebar\sidebar.exe 2716 C:\Windows\System32\wbem\unsecapp.exe 2828 WmiPrvSE.exe 3060 C:\Windows\System32\svchost.exe 1656 C:\Windows\System32\alg.exe 3736 C:\Program Files\Windows Media Player\wmpnetwk.exe 4144 dllhost.exe 4540 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe 2732 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe 3188 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe 4640 C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe 4600 C:\Program Files (x86)\Internet Explorer\ielowutil.exe 1244 C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe 3548 C:\Windows\splwow64.exe 2896 dllhost.exe 5080 dllhost.exe 2856 C:\Users\Surknight\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x000000ab`3f7c9800 (NTFS) PhysicalDrive0 Model Number: SAMSUNGHD753LJ, Rev: 1AA0 Size Device Name MBR Status ——————————————– 698 GB \\.\PhysicalDrive0 Hewlett-Packard MBR code detected SHA1: F362CE084BC77B454330005C1657154A64FB9456 Done!
Here's OTL.txt:

OTL logfile created on: 8/26/2010 1:35:38 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Surknight\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.99 Gb Total Space | 540.83 Gb Free Space | 78.95% Space Free | Partition Type: NTFS
Drive D: | 13.64 Gb Total Space | 1.86 Gb Free Space | 13.63% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SURKNIGHT-PC
Current User Name: Surknight
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Surknight\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\Windows\SysWOW64\ASTSRV.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Users\Surknight\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (nlsX86cc) – C:\Windows\SysNative\nlssrv32.exe File not found
SRV:64bit: - (ezSharedSvc) – C:\Windows\SysNative\ezsvc7.dll File not found
SRV:64bit: - (astcc) – C:\Windows\SysNative\ASTSRV.EXE File not found
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (nlsX86cc) – C:\Windows\SysWOW64\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (astcc) – C:\Windows\SysWOW64\ASTSRV.EXE (Nalpeiron Ltd.)
SRV - (Norton Internet Security) – C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
SRV - (ezSharedSvc) – C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (NwlnkFwd) – C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found
DRV:64bit: - (NwlnkFlt) – C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found
DRV:64bit: - (IpInIp) – C:\Windows\SysNative\DRIVERS\ipinip.sys File not found
DRV:64bit: - (ccHP) – C:\Windows\SysNative\Drivers\NISx64\1008000.029\ccHPx64.sys (Symantec Corporation)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\Drivers\NISx64\1008000.029\SRTSP64.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1008000.029\SYMEFA64.SYS (Symantec Corporation)
DRV:64bit: - (BHDrvx64) – C:\Windows\SysNative\Drivers\NISx64\1008000.029\BHDrvx64.sys (Symantec Corporation)
DRV:64bit: - (SYMTDI) – C:\Windows\SysNative\Drivers\NISx64\1008000.029\SYMTDI.SYS (Symantec Corporation)
DRV:64bit: - (SYMFW) – C:\Windows\SysNative\Drivers\NISx64\1008000.029\SYMFW.SYS (Symantec Corporation)
DRV:64bit: - (SYMNDISV) – C:\Windows\SysNative\Drivers\NISx64\1008000.029\SYMNDISV.SYS (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1008000.029\SRTSPX64.SYS (Symantec Corporation)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymIM) – C:\Windows\SysNative\DRIVERS\SymIMv.sys (Symantec Corporation)
DRV:64bit: - (netr7364) – C:\Windows\SysNative\DRIVERS\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\DRIVERS\agrsm64.sys (Agere Systems)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100826.002\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100826.002\ENG64.SYS (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100825.001\IDSviA64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.5.9

FF - HKLM\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/04/26 08:58:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/31 19:30:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/22 11:44:17 | 000,000,000 | —D | M]

[2010/07/31 19:31:46 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\Mozilla\Extensions
[2010/08/05 19:26:15 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\Mozilla\Firefox\Profiles\gp8kh4d7.default\extensions
[2010/07/31 19:53:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Surknight\AppData\Roaming\Mozilla\Firefox\Profiles\gp8kh4d7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/31 19:53:17 | 000,000,000 | —D | M] (SeoQuake) – C:\Users\Surknight\AppData\Roaming\Mozilla\Firefox\Profiles\gp8kh4d7.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2010/08/26 12:08:36 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/08/11 22:54:17 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2006/09/18 14:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DVDAgent] c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\SysWow64\jureg.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\SysWOW64\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 6.0; WOW64; Trident\4.0; File not found
O4 - Startup: C:\Users\Surknight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WKCALREM.LNK = C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: &ieSpell Options - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8:64bit: - Extra context menu item: Check &Spelling - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8:64bit: - Extra context menu item: Lookup on Merriam Webster - C:\Program Files (x86)\ieSpell\Merriam Webster.HTM ()
O8:64bit: - Extra context menu item: Lookup on Wikipedia - C:\Program Files (x86)\ieSpell\wikipedia.HTM ()
O8 - Extra context menu item: &ieSpell Options - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files (x86)\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files (x86)\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/66.12/uploader2.cab (UploadListView Class)
O16 - DPF: {44990B00-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlcm.cab (Symantec Configuration Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/pm/activex/eBay_E…l_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - Reg Error: Key error. File not found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\horizon.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\horizon.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
NetSvcs: ezSharedSvc - C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/08/26 13:30:16 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\Surknight\Desktop\OTL.exe
[2010/08/18 10:09:23 | 000,000,000 | —D | C] – C:\ProgramData\Viper
[2010/08/18 10:09:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kerigwa
[2010/08/11 22:55:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/08/11 22:54:15 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/08/11 22:54:15 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/08/11 22:54:15 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/08/11 21:20:39 | 000,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2010/08/11 21:20:38 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2010/08/11 21:19:58 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2010/08/11 21:19:56 | 004,697,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2010/08/11 21:19:40 | 002,335,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iertutil.dll
[2010/08/11 21:19:37 | 000,706,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2010/08/11 21:19:37 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2010/08/11 21:19:37 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010/08/11 21:19:37 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2010/08/11 21:19:37 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010/08/11 21:19:37 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2010/08/11 21:19:37 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2010/08/11 21:19:36 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2010/08/11 21:19:36 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2010/08/11 21:19:36 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2010/08/11 21:19:36 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/08/11 21:19:36 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010/08/11 21:19:36 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2010/08/11 21:19:36 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2010/08/11 21:19:36 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2010/08/11 21:19:36 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2010/08/11 21:19:36 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2010/08/11 21:19:36 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2010/08/11 21:19:36 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2010/08/11 21:19:36 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2010/08/11 21:19:35 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010/08/11 21:19:35 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010/08/07 10:49:42 | 000,000,000 | —D | C] – C:\Users\Surknight\Documents\Word Gigs
[2010/07/31 19:31:24 | 000,000,000 | —D | C] – C:\Users\Surknight\AppData\Roaming\Mozilla
[2010/07/31 19:31:24 | 000,000,000 | —D | C] – C:\Users\Surknight\AppData\Local\Mozilla
[2010/07/31 19:30:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/07/29 00:59:26 | 000,000,000 | —D | C] – C:\Users\Surknight\AppData\Roaming\OpenOffice.org
[2010/07/29 00:55:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\JRE
[2010/07/29 00:55:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\OpenOffice.org 3
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/26 13:36:57 | 003,407,872 | -HS- | M] () – C:\Users\Surknight\NTUSER.DAT
[2010/08/26 13:36:48 | 000,000,426 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{E3027D1E-448C-417D-BD63-13932104EF83}.job
[2010/08/26 13:30:24 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Surknight\Desktop\OTL.exe
[2010/08/26 13:19:21 | 000,080,384 | —- | M] () – C:\Users\Surknight\Desktop\MBRCheck.exe
[2010/08/26 12:23:49 | 000,293,376 | —- | M] () – C:\Users\Surknight\Desktop\gmer.exe
[2010/08/26 12:08:44 | 000,032,251 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/08/26 12:08:43 | 000,032,251 | —- | M] () – C:\ProgramData\nvModes.001
[2010/08/26 12:08:38 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/26 12:08:37 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/26 12:08:32 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/26 12:08:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/26 04:25:06 | 000,524,288 | -HS- | M] () – C:\Users\Surknight\NTUSER.DAT{f9b6d8e0-0d17-11de-9758-001644186b3b}.TMContainer00000000000000000001.regtrans-ms
[2010/08/26 04:25:06 | 000,065,536 | -HS- | M] () – C:\Users\Surknight\NTUSER.DAT{f9b6d8e0-0d17-11de-9758-001644186b3b}.TM.blf
[2010/08/26 04:24:57 | 003,687,291 | -H– | M] () – C:\Users\Surknight\AppData\Local\IconCache.db
[2010/08/25 21:09:06 | 000,030,208 | —- | M] () – C:\Users\Surknight\Documents\EBT.xlr
[2010/08/25 21:09:06 | 000,008,742 | —- | M] () – C:\Users\Surknight\AppData\Roaming\wklnhst.dat
[2010/08/25 21:08:30 | 000,069,632 | —- | M] () – C:\Users\Surknight\Documents\2010 Bill Payments.xlr
[2010/08/25 12:53:18 | 006,617,202 | —- | M] () – C:\Users\Surknight\Documents\Recent History.mcf
[2010/08/24 13:03:12 | 000,012,800 | —- | M] () – C:\Users\Public\Documents\2010 Sales and Use Tax - Mantis Moon.xlr
[2010/08/23 12:43:55 | 000,090,707 | —- | M] () – C:\Users\Public\Documents\Order 1173278-Bartels.pdf
[2010/08/21 00:20:20 | 000,022,229 | —- | M] () – C:\Users\Surknight\Documents\Word Gigs Article Draft.odt
[2010/08/20 22:59:26 | 000,008,800 | —- | M] () – C:\Users\Surknight\Documents\Elance Proposals.ods
[2010/08/13 17:01:59 | 000,000,114 | —- | M] () – C:\Windows\SysWow64\prsgrc.tgz
[2010/08/13 17:01:59 | 000,000,100 | —- | M] () – C:\Windows\SysWow64\prsgrc.dll
[2010/08/13 17:01:59 | 000,000,086 | —- | M] () – C:\Windows\SysWow64\ssprs.tgz
[2010/08/13 17:01:58 | 000,000,350 | —- | M] () – C:\Windows\SysWow64\i9fnz1v.tgz
[2010/08/13 17:01:58 | 000,000,336 | —- | M] () – C:\Windows\SysWow64\i9fnz1v.dll
[2010/08/12 10:16:13 | 000,326,168 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/08/06 09:33:22 | 000,000,350 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForSurknight.job
[2010/08/04 12:50:02 | 000,001,138 | —- | M] () – C:\Users\Surknight\Documents\Chris & Nick's Calendar.ics
[2010/08/03 22:34:04 | 000,087,553 | —- | M] () – C:\Users\Surknight\Desktop\Aveson teamwear Pg2.JPG
[2010/08/03 22:32:28 | 000,141,743 | —- | M] () – C:\Users\Surknight\Desktop\Aveson teamwear Pg1.JPG
[2010/07/31 19:30:12 | 000,001,780 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/07/29 11:39:02 | 000,080,720 | —- | M] () – C:\Users\Surknight\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/07/29 00:56:34 | 000,001,027 | —- | M] () – C:\Users\Public\Desktop\OpenOffice.org 3.2.lnk
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/26 13:19:20 | 000,080,384 | —- | C] () – C:\Users\Surknight\Desktop\MBRCheck.exe
[2010/08/25 12:52:58 | 006,617,202 | —- | C] () – C:\Users\Surknight\Documents\Recent History.mcf
[2010/08/24 13:03:12 | 000,012,800 | —- | C] () – C:\Users\Public\Documents\2010 Sales and Use Tax - Mantis Moon.xlr
[2010/08/23 12:43:55 | 000,090,707 | —- | C] () – C:\Users\Public\Documents\Order 1173278-Bartels.pdf
[2010/08/18 10:38:06 | 000,022,229 | —- | C] () – C:\Users\Surknight\Documents\Word Gigs Article Draft.odt
[2010/08/16 12:31:04 | 000,008,800 | —- | C] () – C:\Users\Surknight\Documents\Elance Proposals.ods
[2010/08/06 03:33:06 | 000,000,350 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForSurknight.job
[2010/08/03 22:34:02 | 000,087,553 | —- | C] () – C:\Users\Surknight\Desktop\Aveson teamwear Pg2.JPG
[2010/08/03 22:32:26 | 000,141,743 | —- | C] () – C:\Users\Surknight\Desktop\Aveson teamwear Pg1.JPG
[2010/07/31 19:30:12 | 000,001,780 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/07/29 00:56:34 | 000,001,027 | —- | C] () – C:\Users\Public\Desktop\OpenOffice.org 3.2.lnk
[2010/07/29 00:53:57 | 000,394,780 | —- | C] () – C:\Users\Surknight\AppData\Local\dd_vcredistMSI47A2.txt
[2010/07/29 00:53:56 | 000,011,254 | —- | C] () – C:\Users\Surknight\AppData\Local\dd_vcredistUI47A2.txt
[2010/07/11 13:48:48 | 000,023,888 | —- | C] () – C:\Users\Surknight\AppData\Roaming\UserTile.png
[2010/06/30 00:12:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2010/02/02 22:07:11 | 000,000,680 | —- | C] () – C:\Users\Surknight\AppData\Local\d3d9caps.dat
[2009/09/26 16:24:32 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/09/26 16:23:25 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/05/30 22:02:34 | 000,032,251 | —- | C] () – C:\ProgramData\nvModes.001
[2009/05/30 22:02:17 | 000,032,251 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/01/03 12:57:18 | 000,008,742 | —- | C] () – C:\Users\Surknight\AppData\Roaming\wklnhst.dat
[2008/12/17 22:54:32 | 000,008,192 | —- | C] () – C:\Users\Surknight\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/14 21:37:03 | 000,000,732 | —- | C] () – C:\Users\Surknight\AppData\Local\d3d9caps64.dat
[2008/12/06 16:39:47 | 000,005,801 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/12/06 16:15:41 | 000,327,680 | —- | C] () – C:\Windows\SysWow64\pythoncom25.dll
[2008/12/06 16:15:41 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\pywintypes25.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2008/01/20 19:49:10 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 19:48:00 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\pilqxhk.dll
[2008/01/20 19:48:00 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\grcauth2.dll
[2008/01/20 19:48:00 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\grcauth1.dll
[2008/01/20 19:48:00 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\clauth2.dll
[2008/01/20 19:48:00 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\clauth1.dll
[2008/01/20 19:48:00 | 000,000,336 | —- | C] () – C:\Windows\SysWow64\i9fnz1v.dll
[2008/01/20 19:48:00 | 000,000,100 | —- | C] () – C:\Windows\SysWow64\prsgrc.dll
[2008/01/20 19:48:00 | 000,000,072 | —- | C] () – C:\Windows\SysWow64\ssprs.dll
[2008/01/20 19:48:00 | 000,000,016 | -H– | C] () – C:\Windows\SysWow64\cbqwhir.dll

========== LOP Check ==========

[2010/07/23 16:36:31 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\CherryPickerLive
[2010/06/08 13:36:46 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\Image Zone Express
[2010/07/29 00:59:26 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\OpenOffice.org
[2010/07/11 13:48:48 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\PeerNetworking
[2009/02/09 09:47:27 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\PlayFirst
[2009/03/20 15:58:43 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\Printer Info Cache
[2009/02/08 22:30:09 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\Template
[2009/03/08 23:36:49 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\WildTangent
[2008/12/18 20:18:54 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\WinBatch
[2009/02/25 22:04:55 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\Windows Live Writer
[2009/08/29 02:25:36 | 000,000,000 | —D | M] – C:\Users\Surknight\AppData\Roaming\Wizards of the Coast
[2010/08/26 04:25:08 | 000,032,584 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/08/26 13:36:48 | 000,000,426 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{E3027D1E-448C-417D-BD63-13932104EF83}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/04/10 23:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/12/06 15:44:56 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2010/08/06 03:34:16 | 000,000,500 | —- | M] () – C:\FINIS_IT.TXT
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:44:20 | 000,855,040 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006/12/02 00:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2009/02/11 12:16:16 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\npbittorrent.dll
[2010/08/26 12:08:24 | 312,033,279 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:50:40 | 001,927,956 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:53:12 | 000,242,176 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 08:05:44 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:05:44 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:05:44 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/26 18:10:31 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 20:21:14 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/04/04 19:20:43 | 000,000,286 | -HS- | M] () – C:\Users\Surknight\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/08/26 12:23:49 | 000,293,376 | —- | M] () – C:\Users\Surknight\Desktop\gmer.exe
[2010/08/26 13:19:21 | 000,080,384 | —- | M] () – C:\Users\Surknight\Desktop\MBRCheck.exe
[2010/08/26 13:30:24 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Surknight\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2010/07/22 19:06:53 | 000,910,296 | —- | M] (Mozilla Corporation) MD5=BACCDA841C689D1CBA941F478E8ED24B – C:\Program Files (x86)\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2010/06/25 23:06:48 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D – C:\Program Files (x86)\Internet Explorer\iexplore.exe

< %systemroot%\ADDINS\*.* >
[2006/11/02 08:03:11 | 000,000,802 | —- | M] () – C:\Windows\addins\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >


==================================

Here's Extras.txt:

OTL Extras logfile created on: 8/26/2010 1:35:38 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Surknight\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.99 Gb Total Space | 540.83 Gb Free Space | 78.95% Space Free | Partition Type: NTFS
Drive D: | 13.64 Gb Total Space | 1.86 Gb Free Space | 13.63% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SURKNIGHT-PC
Current User Name: Surknight
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = C2 FE 8D 6A DC 5B C8 01 [binary data]
"VistaSp2" = B1 2E 05 CF 11 3F CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\BitTorrent\bittorrent.exe" = C:\Program Files (x86)\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found
"C:\Program Files (x86)\BitTorrent\bittorrent.exe" = C:\Program Files (x86)\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0F68837E-86B2-44C3-B160-11BBCBD1CB4B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{33CE2DFD-F18B-4B9C-86A7-70CA43D81ED5}" = rport=139 | protocol=6 | dir=out | app=system |
"{380A7DA5-62E0-40F2-8ADB-3941E25DABC0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3E44DDF6-5983-4DE1-88B3-50BEB4B5C116}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{4CB8BE0C-127D-432C-8B7E-C333E4F15A73}" = rport=445 | protocol=6 | dir=out | app=system |
"{4DE2FCAE-FEF2-4B7B-9467-03D86AFB09BB}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{681FC6BB-2EAE-460D-861F-9F44F584C996}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{781D8CF1-3BE3-459C-AE16-8C4B93937742}" = rport=137 | protocol=17 | dir=out | app=system |
"{80EB4E43-5C7D-4C0A-814A-04757CFCCDFB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{906B1589-8329-4719-845B-7B4A34825E45}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9BE486A5-BBA0-4737-8E6C-327AE99A286B}" = rport=138 | protocol=17 | dir=out | app=system |
"{A88F1D98-94AE-432F-9465-D5E0403CAFCC}" = lport=445 | protocol=6 | dir=in | app=system |
"{ABE978A0-C73B-4284-8AF0-FCB655317A9D}" = lport=138 | protocol=17 | dir=in | app=system |
"{AF130421-34A6-41F8-84D0-9109FC0E381F}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{C738DBBA-700B-40A7-B700-CBC81335753A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D230A395-9F1D-44B6-A8A6-3DBD4F9CBBF7}" = rport=2869 | protocol=6 | dir=out | app=system |
"{DDBDA4ED-5FA4-4D62-B190-A75D5AEE35E5}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E076D09C-502B-4971-97DB-3DDDE712670A}" = lport=139 | protocol=6 | dir=in | app=system |
"{EF84B74B-06C7-4F41-8490-EBAF2E38FC79}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F72C062D-9D05-46F5-9AAB-E4F2A1B80C38}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{13D15830-17A7-43AE-A463-9B8033937B76}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{16C2CFD8-EE01-4E82-9D80-FD1FECFFFBC5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{24010366-088D-4A90-B428-4852BD4D7920}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{462C498C-4FAA-4651-8CA7-0F495A09D2D1}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{5D81BD15-E88F-49A3-9197-4E153EF3A22B}" = dir=in | app=c:\program files (x86)\norton internet security\engine\16.8.0.41\ccsvchst.exe |
"{60210D44-59FE-45F3-8864-DF951BCDACBF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{64051074-7E3E-4677-9D9A-BAD500F8F45E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{683FBE01-D47B-43AD-8564-0D7B9D258085}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{6A4D854E-6023-4581-A19E-EB30088BA1CF}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{6D1FFED3-9926-43E0-9AD8-2A7EA5D70BA1}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{781A34C8-7BF7-4AFD-A494-0B7324FC23F6}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{83D2395B-8661-40DE-84B0-AB56DFC16B69}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{8F5A3E70-4E2E-4515-BA5F-F0D56B595FD9}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{950F9A81-AF60-4DFB-B445-1C83B888CDD5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{9EE69B7A-D2FC-4AF1-8F73-CD2CA7C61FB7}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{A9F6E3CC-9BE3-476B-A117-2AC627B826E7}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{B8B2962A-0ACA-4EBC-9E95-32A6E6E3C926}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{EC9852DE-2603-4D41-8E7C-4835B01B6C53}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{17E02F38-FF2D-4c3d-83DF-ECE2A1D20A5E}" = AIO_CDB_ToolboxIni64
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{78F697ED-EC97-4D8D-881D-838984EA9855}" = 64 Bit HP CIO Components Installer
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B1EF559-C401-4DC2-A456-F0C464F1C7E7}" = NetDeviceManager64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Agere Systems Soft Modem" = Agere Systems USB 2.0 Soft Modem
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
"PC-Doctor for Windows" = Hardware Diagnostic Tools

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{1FCC7185-DCF3-4478-86AD-C2F2D1116BE3}" = 7300
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 21
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32257980-61DF-4685-A72B-08683838233B}" = 7300_Help
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{377739AE-00D9-4E80-8ECB-4C8A7EFFE526}" = 7300Trb
"{39CB30DB-27F8-4dd4-A294-CB4AE3B584FD}" = Copy
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6B976ADF-8AE8-434E-B282-A06C7F624D2F}" = Python 2.5.2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{97ABD26A-3249-46CB-B2E2-F66E64B2E480}" = HP Demo
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.4
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AF7733C1-FB0B-4FED-9730-E0433AF7A2EF}" = Magic Online III
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B9AB88D8-3A09-4A4A-8993-0E2F6F9F294B}" = muvee autoProducer 6.1
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E1077A0C-0DF2-4A9E-AD83-D6ACDFA40890}" = Twitter Plugin for Windows Live Writer
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F41A9EE5-A6A8-5647-63D0-F0A5D744612A}" = CherryPicker
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Belarc Advisor" = Belarc Advisor 8.1
"CherryPickerLive" = CherryPicker
"ieSpell" = ieSpell
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Loki ActiveX Control" = Loki ActiveX Control
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"NIS" = Norton Internet Security
"sp41119" = sp41119
"sp44626" = sp44626
"SystemRequirementsLab" = System Requirements Lab
"VertusBlingIt" = Vertus Bling! It 1.0.2
"Viper" = Viper 1.5.00
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/26/2009 12:21:21 PM | Computer Name = Surknight-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/27/2009 12:29:32 PM | Computer Name = Surknight-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/27/2009 11:09:36 PM | Computer Name = Surknight-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/28/2009 11:14:32 AM | Computer Name = Surknight-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/28/2009 10:13:03 PM | Computer Name = Surknight-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/29/2009 12:31:46 PM | Computer Name = Surknight-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/30/2009 11:23:12 AM | Computer Name = Surknight-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/30/2009 1:22:05 PM | Computer Name = Surknight-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/31/2009 3:14:18 PM | Computer Name = Surknight-PC | Source = WinMgmt | ID = 10
Description =

Error - 11/1/2009 2:48:39 PM | Computer Name = Surknight-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 8/24/2010 3:04:14 PM | Computer Name = Surknight-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 8/25/2010 12:42:05 AM | Computer Name = Surknight-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 8/25/2010 12:44:16 AM | Computer Name = Surknight-PC | Source = ipnathlp | ID = 31004
Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This
may indicate that the system is low on virtual memory, or that the memory manager
has encountered an internal error.

Error - 8/25/2010 2:09:53 PM | Computer Name = Surknight-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 002354490499 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 8/25/2010 2:11:43 PM | Computer Name = Surknight-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 8/25/2010 11:50:56 PM | Computer Name = Surknight-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 002354490499 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 8/25/2010 11:52:47 PM | Computer Name = Surknight-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 8/26/2010 3:08:32 PM | Computer Name = Surknight-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 002354490499 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 8/26/2010 3:10:26 PM | Computer Name = Surknight-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 8/26/2010 4:21:28 PM | Computer Name = Surknight-PC | Source = nvstor64 | ID = 262149
Description = A parity error was detected on \Device\RaidPort0.


< End of report >
Hello,

Do you have your Windows disc?

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [hpqSRMon] File not found
    O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
    O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\SysWOW64\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 6.0; WOW64; Trident\4.0; File not found
    O4 - Startup: C:\Users\Surknight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WKCALREM.LNK = C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O18:64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - Reg Error: Key error. File not found
    [2008/01/20 19:48:00 | 000,000,016 | -H– | C] () – C:\Windows\SysWow64\cbqwhir.dll
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
Go ahead and run the OTL fix in my previous post and then run a new scan using these directions:


OTL Custom Scan

We need to run an OTL Custom Scan
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following bolded text into the [external image: Posted Image] textbox.


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Push Quick Scan
  • A report will open. Copy and Paste that report in your next reply.
OTL stopped responding in the middle of the fix and had to be closed (it had the [emptytemp] and [EMPTYFLASH] commands still to do). Should I rerun it?
No actually don't re-running it.

Do this instead of running the above OTL Custom Scan.

Open up OTL.exe

Click on None

Copy/Paste following into Custom Scans/Fixes:

%PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
%PROGRAMFILES%\Internet Explorer\iexplore.exe /md5

Click on Run Scan button.

Post the log it produces.
I tried to open OTL to do the procedure in your reply and this popped up in notepad: Files\Folders moved on Reboot… File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. File move failed. C:\Users\Surknight\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot. File move failed. C:\Users\Surknight\AppData\Local\Temp\VGX1D9D.tmp scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\SET10D3.tmp scheduled to be moved on reboot. File move failed. C:\Windows\temp\JET9951.tmp scheduled to be moved on reboot. Registry entries deleted on Reboot… 64bit-Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\symres\ scheduled to be deleted on reboot. Should I run the procedure in your last reply now?
Here it is:

OTL logfile created on: 8/26/2010 3:34:39 PM - Run 2
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Surknight\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 51.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.99 Gb Total Space | 542.60 Gb Free Space | 79.21% Space Free | Partition Type: NTFS
Drive D: | 13.64 Gb Total Space | 1.86 Gb Free Space | 13.63% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SURKNIGHT-PC
Current User Name: Surknight
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Custom Scans ==========


< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2010/07/22 19:06:53 | 000,910,296 | —- | M] (Mozilla Corporation) MD5=BACCDA841C689D1CBA941F478E8ED24B – C:\Program Files (x86)\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2010/06/25 23:06:48 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D – C:\Program Files (x86)\Internet Explorer\iexplore.exe
< End of report >
Hello,


VirusTotal File Scan
Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: C:\Program Files (x86)\Internet Explorer\iexplore.exe
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI