This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HTTP Nukesploit Request

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, ive had some problems with the computer running slow recently and today Norton 360 detected HTTP Nukesploit Request. I searched online for the term and came accross a thread on this forum, which seems to be the same as what I have. Not entirly sure what it is that I have, but it seems like its important to get it removed. I have downloaded OTL and run the scan as per instructions in the sticky in this forum and I have the logs ready to post. I have a print screen of the alert in Norton 360 too, which gives the details of the risk. All advice and help is much appreciated, KenMan.
Ok no problem! The first is the file called Extras.Txt


OTL Extras logfile created on: 26/08/2010 13:51:56 - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Kennedy\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,013.00 Mb Total Physical Memory | 444.00 Mb Available Physical Memory | 44.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 55.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.35 Gb Total Space | 5.35 Gb Free Space | 7.71% Space Free | Partition Type: NTFS
Drive D: | 5.18 Gb Total Space | 1.17 Gb Free Space | 22.54% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KENNEDY-PC
Current User Name: Kennedy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1AFCC713-F894-41CC-85E0-A820AA9D4AB6}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{86D39BBD-D605-4A01-87CC-96B7185E8542}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9D9731B8-99F6-471C-B25F-A4AD95C3D255}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{DCD7D9DF-4D84-41A6-9ADF-509F7CAF4EF3}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{394C277B-6AFD-4AD5-9C29-5E1DD8638381}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{400AFE63-6775-4B2B-B0EA-A062641C6A70}" = protocol=6 | dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{46036258-043E-40E9-BEC7-8269663E41F5}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{4CFC9A7C-CD04-45A0-B015-02C2080B0AD5}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{4E8261BB-B4E8-45C1-8FA3-5B0CAF64252F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5B86A13F-AC79-4225-935D-858558DE6907}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7C4722EE-B382-40D6-BC22-7073A2438E03}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{84E7E315-4936-46D7-B35F-35E21F438624}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{926CCC99-397E-4AF9-B8B6-5A64A2523D61}" = protocol=17 | dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{97A0C27F-0199-4EE5-8432-3B2BA88EA9EF}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{02F33FB0-F7D5-4C0A-B4AD-8CE5CE230BBE}" = HP Wireless Assistant
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23B59B9F-C360-11D7-875B-0090CC005647}" = PIF DESIGNER2.1
"{23B59ED4-C360-11D7-875B-0090CC005647}" = EPSON PRINT Image Framer Tool2.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 21
"{2CDCCE7E-55D5-40CC-AEA0-ABA54713501F}" = LUMIX Simple Viewer
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}" = Roxio MyDVD Basic v9
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.10 B9
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.0
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{65F5B7AF-3363-11D7-BB6B-00018021113F}" = EPSON PhotoQuicker3.5
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6E65247F-58F9-41CA-BE69-0316F7907170}" = Disc2Phone
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{80CA15EA-C0A5-7CAF-B9E9-B8B2A87EFE11}" = Orange menu application
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90CA15EA-C0A5-7CAF-B9E9-B8B2A87EFE11}" = Orange signup
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.5
"{AC76BA86-7AD7-1033-7B44-A81300000003}_814" = KB408682
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E4DDBA93-769B-49D8-BA33-8814E45ED0C1}" = HP Help and Support
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{ED4905E3-2B32-4DD8-BC14-7CAFD30E9ECD}" = HP User Guide 0048
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{F94234DB-FD06-42C3-B88D-6FC4DC9F988C}" = HP Easy Setup - Core
"{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}" = ASL_HS_Installer32
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_5045&SUBSYS_103C30B7" = Soft Data Fax Modem with SmartCP
"EPSON Printer and Utilities" = EPSON Printer Software
"ESPR200 Reference Guide" = ESPR200 Reference Guide
"ESPR200 Software Guide" = ESPR200 Software Guide
"FL Studio 9" = FL Studio 9
"Hardcore" = Hardcore
"HDMI" = Intel® Graphics Media Accelerator DriverUninstall\Hardcore
"IL Download Manager" = IL Download Manager
"LDC Driving Test 3-in-18.2" = LDC Driving Test 3-in-1
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"N360" = Norton 360
"Peggle" = Peggle (remove only)
"PoiZone" = PoiZone
"PROR" = Microsoft Office Professional 2007 Trial
"Sakura" = Sakura
"Sawer" = Sawer
"Skype_is1" = Skype 2.5
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Toxic Biohazard" = Toxic Biohazard
"VLC media player" = VideoLAN VLC media player 0.8.6f
"WinLiveSuite_Wave3" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 04/08/2010 07:36:21 | Computer Name = Kennedy-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 04/08/2010 07:36:24 | Computer Name = Kennedy-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 04/08/2010 07:36:25 | Computer Name = Kennedy-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 06/08/2010 16:05:08 | Computer Name = Kennedy-PC | Source = Google Update | ID = 20
Description =

Error - 14/08/2010 09:30:22 | Computer Name = Kennedy-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18928, time stamp
0x4bdfa327, faulting module mshtml.dll, version 8.0.6001.18928, time stamp 0x4bdfb76d,
exception code 0xc0000005, fault offset 0x00029d9f, process id 0x1320, application
start time 0x01cb3bb433a92b5a.

Error - 14/08/2010 10:17:23 | Computer Name = Kennedy-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.0.3725 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1398 Start Time: 01cb3bb9f066f3ea Termination Time: 7

Error - 15/08/2010 16:27:29 | Computer Name = Kennedy-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.0.3725 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1708 Start Time: 01cb3cb66a297834 Termination Time: 256

Error - 15/08/2010 16:43:08 | Computer Name = Kennedy-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.0.3725 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1560 Start Time: 01cb3cba080657f4 Termination Time: 6

Error - 15/08/2010 16:46:42 | Computer Name = Kennedy-PC | Source = Windows Search Service | ID = 3024
Description =

Error - 20/08/2010 08:40:25 | Computer Name = Kennedy-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18943, time stamp
0x4c25813d, faulting module mshtml.dll, version 8.0.6001.18943, time stamp 0x4c259878,
exception code 0xc0000005, fault offset 0x00029d9f, process id 0x1534, application
start time 0x01cb40640c931d04.

[ Media Center Events ]
Error - 24/09/2007 11:15:30 | Computer Name = Kennedy-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 16/04/2008 11:17:22 | Computer Name = Kennedy-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 17/04/2008 11:13:48 | Computer Name = Kennedy-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 22/05/2008 11:15:14 | Computer Name = Kennedy-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 24/05/2008 09:46:21 | Computer Name = Kennedy-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

[ System Events ]
Error - 23/08/2010 07:32:25 | Computer Name = Kennedy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 23/08/2010 07:49:42 | Computer Name = Kennedy-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 23/08/2010 07:50:11 | Computer Name = Kennedy-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 24/08/2010 12:09:32 | Computer Name = Kennedy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 25/08/2010 06:33:27 | Computer Name = Kennedy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 25/08/2010 06:36:06 | Computer Name = Kennedy-PC | Source = WinDefend | ID = 2004
Description = %%827 has encountered an error trying to load signatures and will
attempt reverting back to a known-good set of signatures. Signatures Attempted: %%824

Error
Code: 0x8050a001 Error description: The program can't find definition files that
help detect unwanted software. Check for updates to the definition files, and then
try again. For information on installing updates, see Help and Support. Signatures
loading: %%825 Loading signature version: 1.87.2231.0 Loading engine version: 1.1.6004.0

Error - 25/08/2010 10:24:44 | Computer Name = Kennedy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 25/08/2010 10:33:35 | Computer Name = Kennedy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 26/08/2010 06:57:51 | Computer Name = Kennedy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 26/08/2010 07:04:14 | Computer Name = Kennedy-PC | Source = Service Control Manager | ID = 7022
Description =


< End of report >


The other is called OTL.Txt


OTL logfile created on: 26/08/2010 13:51:56 - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Kennedy\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,013.00 Mb Total Physical Memory | 444.00 Mb Available Physical Memory | 44.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 55.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.35 Gb Total Space | 5.35 Gb Free Space | 7.71% Space Free | Partition Type: NTFS
Drive D: | 5.18 Gb Total Space | 1.17 Gb Free Space | 22.54% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KENNEDY-PC
Current User Name: Kennedy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Kennedy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Napster\napster.exe (Napster)
PRC - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\Kennedy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\asoehook.dll (Symantec Corporation)
MOD - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\microsoft.vc90.crt\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\microsoft.vc90.crt\msvcp90.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (N360) – C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AddFiltr) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)


========== Driver Services (SafeList) ==========

DRV - (UIUSys) – C:\Windows\System32\DRIVERS\UIUSYS.SYS File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (SymSMR130) – C:\Windows\System32\drivers\SymSMR130.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100825.040\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100825.040\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20100810.004\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20100825.001\IDSvix86.sys (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\N360\0402000.00C\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0402000.00C\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0402000.00C\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0402000.00C\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0402000.00C\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\Windows\system32\drivers\N360\0402000.00C\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0402000.00C\SYMDS.SYS (Symantec Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (zebrmdmc) Sony Ericsson mRouter Port (WDM) – C:\Windows\System32\drivers\zebrmdmc.sys (MCCI)
DRV - (zebrmdm) Sony Ericsson Port (WDM) – C:\Windows\System32\drivers\zebrmdm.sys (MCCI)
DRV - (zebrmdfl) – C:\Windows\System32\drivers\zebrmdfl.sys (MCCI Corporation)
DRV - (zebrbus) – C:\Windows\System32\drivers\zebrbus.sys (MCCI)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (ialm) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (HdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (HSFHWAZL) – C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (BCM43XV) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (eabfiltr) – C:\Windows\System32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…O&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…O&pf=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\ [2010/07/26 15:22:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\ [2010/07/24 18:29:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/21 22:02:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/21 22:02:56 | 000,000,000 | —D | M]

[2008/12/16 16:24:37 | 000,000,000 | —D | M] – C:\Users\Kennedy\AppData\Roaming\Mozilla\Extensions
[2010/08/18 19:48:28 | 000,000,000 | —D | M] – C:\Users\Kennedy\AppData\Roaming\Mozilla\Firefox\Profiles\j1fpwhha.default\extensions
[2009/07/14 12:23:53 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Kennedy\AppData\Roaming\Mozilla\Firefox\Profiles\j1fpwhha.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/26 12:31:09 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/14 10:25:17 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/26 12:31:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/03/31 23:47:26 | 000,324,976 | —- | M] (Symantec Corporation) – C:\Program Files\Mozilla Firefox\components\coFFPlgn.dll
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/09/17 15:11:48 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2009/09/17 15:11:48 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2009/09/17 15:11:48 | 000,000,759 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2009/09/17 15:11:48 | 000,000,831 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/03/01 23:33:29 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [EPSON Product Registration Reminder] C:\Windows\Temp\RegModule.exe File not found
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe (Napster)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks)
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/resources/…NPUplden-gb.cab (MSN Photo Upload Tool)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Kennedy\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Kennedy\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 15:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{40ac37a3-6bff-11dc-88f6-001b24020a99}\Shell - "" = AutoRun
O33 - MountPoints2\{40ac37a3-6bff-11dc-88f6-001b24020a99}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{a7f02805-edb9-11de-a993-001b24020a99}\Shell - "" = AutoRun
O33 - MountPoints2\{a7f02805-edb9-11de-a993-001b24020a99}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/08/26 13:50:48 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\Kennedy\Desktop\OTL.exe
[2010/08/26 13:18:55 | 000,063,536 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\SymSMR130.SYS
[2010/08/26 13:18:10 | 000,000,000 | —D | C] – C:\Users\Kennedy\AppData\Local\NPE
[2010/08/26 13:16:51 | 005,527,408 | —- | C] (Symantec Corporation) – C:\Users\Kennedy\Desktop\NPE.exe
[2010/08/26 12:31:04 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/08/26 12:31:04 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/08/26 12:31:04 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/08/14 15:19:52 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/08/14 15:19:52 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/08/14 15:19:51 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/08/14 15:19:51 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/08/14 15:19:51 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/08/14 15:19:51 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/08/14 15:19:50 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/08/14 15:19:50 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/08/14 15:19:50 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/08/14 15:19:50 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/08/14 15:19:50 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/08/14 15:19:50 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/08/14 15:19:50 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/08/14 15:19:49 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/08/14 15:19:49 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/08/14 15:19:40 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2010/08/14 15:19:17 | 002,037,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/08/14 15:19:07 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtutils.dll
[2010/08/14 15:18:52 | 003,600,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2010/08/14 15:18:50 | 003,548,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2010/08/01 21:27:36 | 000,000,000 | —D | C] – C:\Users\Kennedy\AppData\Local\CrashDumps

========== Files - Modified Within 30 Days ==========

[2010/08/26 13:52:12 | 003,932,160 | -HS- | M] () – C:\Users\Kennedy\ntuser.dat
[2010/08/26 13:50:57 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Kennedy\Desktop\OTL.exe
[2010/08/26 13:18:57 | 000,000,000 | —- | M] () – C:\Windows\System32\drivers\SymSMR130.dat
[2010/08/26 13:18:55 | 000,063,536 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SymSMR130.SYS
[2010/08/26 13:17:13 | 005,527,408 | —- | M] (Symantec Corporation) – C:\Users\Kennedy\Desktop\NPE.exe
[2010/08/26 13:05:09 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/26 12:00:37 | 000,000,422 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{FE4FD8A0-3B89-4584-BD65-192BC78BA3D6}.job
[2010/08/26 11:57:27 | 000,000,150 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2010/08/26 11:57:13 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/26 11:57:12 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/26 11:57:12 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/26 11:57:07 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/26 11:56:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/26 11:56:52 | 1061,236,736 | -HS- | M] () – C:\hiberfil.sys
[2010/08/25 17:44:52 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/08/25 17:44:26 | 000,524,288 | -HS- | M] () – C:\Users\Kennedy\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/08/25 17:44:26 | 000,065,536 | -HS- | M] () – C:\Users\Kennedy\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/08/23 15:07:22 | 002,379,656 | -H– | M] () – C:\Users\Kennedy\AppData\Local\IconCache.db
[2010/08/18 18:46:32 | 000,006,836 | —- | M] () – C:\Users\Kennedy\AppData\Roaming\wklnhst.dat
[2010/08/15 22:00:02 | 002,354,136 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/08/06 14:52:01 | 000,715,876 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/08/06 14:52:01 | 000,617,524 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/08/06 14:52:01 | 000,112,362 | —- | M] () – C:\Windows\System32\perfc009.dat

========== Files Created - No Company Name ==========

[2010/08/26 13:18:57 | 000,000,000 | —- | C] () – C:\Windows\System32\drivers\SymSMR130.dat
[2009/08/04 20:13:15 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/03/30 13:59:23 | 000,000,000 | —- | C] () – C:\Users\Kennedy\AppData\Local\FnF4.txt
[2007/09/09 18:34:06 | 000,000,025 | —- | C] () – C:\Windows\CDER200Euro.ini
[2007/08/06 14:17:37 | 000,026,112 | —- | C] () – C:\Users\Kennedy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/07/28 11:06:03 | 000,006,836 | —- | C] () – C:\Users\Kennedy\AppData\Roaming\wklnhst.dat
[2007/07/27 17:56:30 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2007/07/24 15:18:10 | 000,005,676 | —- | C] () – C:\Users\Kennedy\AppData\Local\d3d9caps.dat
[2007/07/24 15:02:18 | 000,000,000 | —- | C] () – C:\Users\Kennedy\AppData\Local\QSwitch.txt
[2007/07/24 15:02:18 | 000,000,000 | —- | C] () – C:\Users\Kennedy\AppData\Local\DSwitch.txt
[2007/07/24 15:02:18 | 000,000,000 | —- | C] () – C:\Users\Kennedy\AppData\Local\AtStart.txt
[2007/02/26 18:54:14 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1187.dll
[2006/11/29 08:32:42 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/06 12:02:10 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1114.dll
[2006/11/06 10:05:40 | 000,180,224 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/19 08:02:40 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/19 08:02:40 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/03/10 00:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2005/05/08 05:06:00 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll

========== LOP Check ==========

[2007/07/27 17:57:43 | 000,000,000 | —D | M] – C:\Users\Kennedy\AppData\Roaming\Panasonic
[2007/07/28 11:08:50 | 000,000,000 | —D | M] – C:\Users\Kennedy\AppData\Roaming\Template
[2010/07/24 17:41:06 | 000,000,000 | —D | M] – C:\Users\Kennedy\AppData\Roaming\Tific
[2010/08/25 17:45:01 | 000,032,552 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/08/26 12:00:37 | 000,000,422 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{FE4FD8A0-3B89-4584-BD65-192BC78BA3D6}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/08/26 11:56:52 | 1061,236,736 | -HS- | M] () – C:\hiberfil.sys
[2007/09/09 18:34:25 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2007/09/09 18:34:25 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/08/26 11:56:49 | 1377,107,968 | -HS- | M] () – C:\pagefile.sys
[2009/08/15 14:26:13 | 000,000,909 | —- | M] () – C:\updatedatfix.log

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/08/04 20:51:00 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/12/10 19:41:42 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 11:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/03 18:39:46 | 000,000,286 | -HS- | M] () – C:\Users\Kennedy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/07/24 17:43:51 | 000,137,568 | —- | M] (Symantec Corporation) – C:\Users\Kennedy\Desktop\buDump.exe
[2010/07/23 12:26:12 | 001,321,008 | —- | M] (Symantec Corporation) – C:\Users\Kennedy\Desktop\KB20100122121538EN.exe
[2010/03/02 00:12:57 | 082,952,744 | —- | M] (Symantec Corporation) – C:\Users\Kennedy\Desktop\N360S300EN.exe
[2010/07/24 17:51:09 | 000,921,512 | —- | M] (Symantec Corporation) – C:\Users\Kennedy\Desktop\Norton_Removal_Tool.exe
[2010/08/26 13:17:13 | 005,527,408 | —- | M] (Symantec Corporation) – C:\Users\Kennedy\Desktop\NPE.exe
[2010/08/26 13:50:57 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Kennedy\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-25 10:59:27
< End of report >


Thanks alot for the help!
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message to me on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [EPSON Product Registration Reminder] C:\Windows\Temp\RegModule.exe File not found
    O4 - HKCU..\Run: [AdobeBridge] File not found
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O33 - MountPoints2\{40ac37a3-6bff-11dc-88f6-001b24020a99}\Shell - "" = AutoRun
    O33 - MountPoints2\{40ac37a3-6bff-11dc-88f6-001b24020a99}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    O33 - MountPoints2\{a7f02805-edb9-11de-a993-001b24020a99}\Shell - "" = AutoRun
    O33 - MountPoints2\{a7f02805-edb9-11de-a993-001b24020a99}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
    O33 - MountPoints2\G\Shell - "" = AutoRun
    O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Scanning with GMER

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

Notes:
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



NEXT:



Please download MBRCheck.exe to your Desktop. Run the application.

If no infection is found, it will produce a report on the desktop. Post that report in your next reply.

If an infection is found, you will be presented with the following dialog:

Enter 'Y' and hit ENTER for more options, or 'N' to exit:


Type N and press Enter. A report will be produced on the desktop. Post that report in your next reply.
Ive just done OTL fix, here are the results. I will do the GMER scan next. Thanks again!


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\EPSON Product Registration Reminder deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\Windows\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\Windows\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{40ac37a3-6bff-11dc-88f6-001b24020a99}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40ac37a3-6bff-11dc-88f6-001b24020a99}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{40ac37a3-6bff-11dc-88f6-001b24020a99}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40ac37a3-6bff-11dc-88f6-001b24020a99}\ not found.
File F:\LaunchU3.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a7f02805-edb9-11de-a993-001b24020a99}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a7f02805-edb9-11de-a993-001b24020a99}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a7f02805-edb9-11de-a993-001b24020a99}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a7f02805-edb9-11de-a993-001b24020a99}\ not found.
File G:\LaunchU3.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found.
File G:\LaunchU3.exe not found.
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Could not flush the DNS Resolver Cache: Function failed during execution.
C:\Users\Kennedy\Desktop\cmd.bat deleted successfully.
C:\Users\Kennedy\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Kennedy
->Temp folder emptied: 70377181 bytes
->Temporary Internet Files folder emptied: 93030178 bytes
->Java cache emptied: 11322948 bytes
->FireFox cache emptied: 85966364 bytes
->Flash cache emptied: 405485 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1577752 bytes
RecycleBin emptied: 607542892 bytes

Total Files Cleaned = 830.00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Kennedy
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.10.0 log created on 08262010_153134

Files\Folders moved on Reboot…
C:\Users\Kennedy\AppData\Local\Temp\ehmsas.txt moved successfully.
File\Folder C:\Users\Kennedy\AppData\Local\Temp\~DF354C.tmp not found!
File\Folder C:\Users\Kennedy\AppData\Local\Temp\~DF3692.tmp not found!
File\Folder C:\Users\Kennedy\AppData\Local\Temp\~DF3703.tmp not found!
File\Folder C:\Users\Kennedy\AppData\Local\Temp\~DF3719.tmp not found!
File\Folder C:\Users\Kennedy\AppData\Local\Temp\~DF38A2.tmp not found!
File\Folder C:\Users\Kennedy\AppData\Local\Temp\~DF38B7.tmp not found!
C:\Users\Kennedy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T1WL5K4B\iframe[2].htm moved successfully.
C:\Users\Kennedy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KUF95Z10\index[3].htm moved successfully.
C:\Users\Kennedy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KUF95Z10\like[1].htm moved successfully.

Registry entries deleted on Reboot…
I just tried to do the GMER scan, and after a minute or so, windows came up and said the program stopped working and needs to be closed. So I did that and tried again. Part way through the scan, a black screen comes up with a blue box, and says something about a file causing windows to stop working, then it rebooted. I think the file was uwtafog.txt or something along those lines. Then a windows error recovery message came up so I said to start normally and it has done… Not sure weather to try scanning with GMER again…?
Try this instead:

Rootkit UnHooker (RkU)
Please download Rootkit Unhooker … Save it to your Desktop.
Note: The log can be very long, you may need to post it separately.
  • Double-click on RKUnhookerLE.exe to execute it.
    Vista - W7 users: Right click RKUnhookerLE.exe, choose "Run As Administrator" to execute it. If UAC prompts, please allow it.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth Code, Files and Code Hooks. Uncheck the rest. then Click OK. (See image below…)
    🖼Click to load external image (Posted Image)
    The scanning will toggle through the checked items "tabs" … it will take a while, so please be patient.
  • When the scanner is finished… click File, Save Report.
  • Save the file "Report.txt" to your Desktop… Press Close… then press Yes
  • Copy the entire contents of the Report.txt file in you're next reply.
Right ive tried the rootkit unhooker program, but for the last two hours it doesnt seem to have made any progress… Its just been "getting a list of files and directories (C:\)" so far. Not sure if its supposed to take that long or maybe its normal for this program? Is it worth Norton 360 doing a complete system scan? Cheers EDIT: Sorry, the last hour and a half - not two hours…
Ok the MBRCheck report said: MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows Vista Home Premium Edition Windows Information: Service Pack 2 (build 6002), 32-bit Base Board Manufacturer: Quanta BIOS Manufacturer: Hewlett-Packard System Manufacturer: Hewlett-Packard System Product Name: Presario V6000 (GF815EA#ABU) Logical Drives Mask: 0x0000001c Kernel Drivers (total 166): 0x81C14000 \SystemRoot\system32\ntkrnlpa.exe 0x81FCD000 \SystemRoot\system32\hal.dll 0x80605000 \SystemRoot\system32\kdcom.dll 0x8060C000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x8067C000 \SystemRoot\system32\PSHED.dll 0x8068D000 \SystemRoot\system32\BOOTVID.dll 0x80695000 \SystemRoot\system32\CLFS.SYS 0x806D6000 \SystemRoot\system32\CI.dll 0x8220E000 \SystemRoot\system32\drivers\Wdf01000.sys 0x8228A000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x82297000 \SystemRoot\system32\drivers\acpi.sys 0x822DD000 \SystemRoot\system32\drivers\WMILIB.SYS 0x822E6000 \SystemRoot\system32\drivers\msisadrv.sys 0x822EE000 \SystemRoot\system32\drivers\pci.sys 0x82315000 \SystemRoot\System32\drivers\partmgr.sys 0x82324000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x82327000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x82331000 \SystemRoot\system32\drivers\volmgr.sys 0x82340000 \SystemRoot\System32\drivers\volmgrx.sys 0x8238A000 \SystemRoot\system32\drivers\intelide.sys 0x82391000 \SystemRoot\system32\drivers\PCIIDEX.SYS 0x8239F000 \SystemRoot\System32\drivers\mountmgr.sys 0x823AF000 \SystemRoot\system32\drivers\atapi.sys 0x823B7000 \SystemRoot\system32\drivers\ataport.SYS 0x823D5000 \SystemRoot\system32\drivers\msahci.sys 0x807B6000 \SystemRoot\system32\drivers\fltmgr.sys 0x8280C000 \SystemRoot\system32\drivers\N360\0402000.00C\SYMDS.SYS 0x82862000 \SystemRoot\system32\drivers\fileinfo.sys 0x82872000 \SystemRoot\system32\drivers\N360\0402000.00C\SYMEFA.SYS 0x8289F000 \SystemRoot\System32\Drivers\PxHelp20.sys 0x828A8000 \SystemRoot\System32\Drivers\ksecdd.sys 0x82A07000 \SystemRoot\system32\drivers\ndis.sys 0x82B12000 \SystemRoot\system32\drivers\msrpc.sys 0x82B3D000 \SystemRoot\system32\drivers\NETIO.SYS 0x8620D000 \SystemRoot\System32\drivers\tcpip.sys 0x862F7000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x86408000 \SystemRoot\System32\Drivers\Ntfs.sys 0x86518000 \SystemRoot\system32\drivers\volsnap.sys 0x86551000 \SystemRoot\System32\Drivers\spldr.sys 0x86559000 \SystemRoot\System32\Drivers\mup.sys 0x86568000 \SystemRoot\System32\drivers\ecache.sys 0x8658F000 \SystemRoot\system32\drivers\disk.sys 0x865A0000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x865C1000 \SystemRoot\system32\drivers\crcdisk.sys 0x865EC000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x865F7000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x86312000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x86400000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x86321000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x8B207000 \SystemRoot\system32\DRIVERS\igdkmd32.sys 0x8632A000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x8B7DE000 \SystemRoot\System32\drivers\watchdog.sys 0x82919000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x8AE08000 \SystemRoot\system32\DRIVERS\NETw3v32.sys 0x8AFC9000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x82B78000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x8AFD4000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x8AFE3000 \SystemRoot\system32\DRIVERS\ohci1394.sys 0x8B7EA000 \SystemRoot\system32\DRIVERS\1394BUS.SYS 0x863CB000 \SystemRoot\system32\DRIVERS\sdbus.sys 0x863E5000 \SystemRoot\system32\DRIVERS\rimmptsk.sys 0x82BB6000 \SystemRoot\system32\DRIVERS\rimsptsk.sys 0x829A6000 \SystemRoot\system32\DRIVERS\rixdptsk.sys 0x82BCA000 \SystemRoot\system32\DRIVERS\e100b325.sys 0x8AFF3000 \SystemRoot\system32\DRIVERS\cpqbttn.sys 0x823DF000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x8AFF6000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x807E8000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x863F3000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x8B80A000 \SystemRoot\system32\DRIVERS\SynTP.sys 0x8B835000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x8B837000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x8B842000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x8B85A000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys 0x8B860000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x8B88F000 \SystemRoot\system32\DRIVERS\storport.sys 0x8B8D0000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8B8DB000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8B8F2000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8B8FD000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8B920000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8B92F000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8B943000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8B958000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8B968000 \SystemRoot\system32\DRIVERS\swenum.sys 0x8B96A000 \SystemRoot\system32\DRIVERS\ks.sys 0x8B994000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8B99E000 \SystemRoot\system32\DRIVERS\umbus.sys 0x8B9AB000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x8B9E0000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x8B9E9000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8BC00000 \SystemRoot\system32\drivers\CHDRT32.sys 0x8BC31000 \SystemRoot\system32\drivers\portcls.sys 0x8BC5E000 \SystemRoot\system32\drivers\drmk.sys 0x8BC83000 \SystemRoot\system32\DRIVERS\HSXHWAZL.sys 0x8BCC0000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys 0x8BE02000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys 0x8BEB6000 \SystemRoot\system32\drivers\modem.sys 0x8BEC3000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x8BECC000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x8BED4000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x8BEDD000 \SystemRoot\System32\Drivers\Null.SYS 0x8BEE4000 \SystemRoot\System32\Drivers\Beep.SYS 0x8BEEB000 \SystemRoot\System32\drivers\vga.sys 0x8BEF7000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8BF18000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8BF20000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8BF28000 \SystemRoot\System32\Drivers\Msfs.SYS 0x8BF33000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8BF41000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x8BF4A000 \SystemRoot\system32\DRIVERS\tdx.sys 0x8BF60000 \SystemRoot\System32\Drivers\N360\0402000.00C\SYMTDIV.SYS 0x8BFB9000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS 0x8BFDE000 \SystemRoot\system32\DRIVERS\smb.sys 0x8C808000 \SystemRoot\system32\drivers\afd.sys 0x8C850000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8C882000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8C898000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8C8A6000 \SystemRoot\system32\DRIVERS\eabfiltr.sys 0x8C8A8000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8C8BB000 \SystemRoot\system32\drivers\N360\0402000.00C\Ironx86.SYS 0x8C8DA000 \SystemRoot\system32\drivers\N360\0402000.00C\SRTSPX.SYS 0x8C8E4000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8C920000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8C92A000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20100825.001\IDSvix86.sys 0x8C982000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0x8C9E0000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0x8BDC3000 \SystemRoot\System32\Drivers\dfsc.sys 0x8CE0C000 \SystemRoot\system32\drivers\N360\0402000.00C\ccHPx86.sys 0x8CE8B000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20100810.004\BHDrvx86.sys 0x8CF37000 \SystemRoot\System32\Drivers\crashdmp.sys 0x8CF44000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x8CF4F000 \SystemRoot\System32\Drivers\dump_msahci.sys 0x98230000 \SystemRoot\System32\win32k.sys 0x8CF59000 \SystemRoot\System32\drivers\Dxapi.sys 0x8CF63000 \SystemRoot\system32\DRIVERS\monitor.sys 0x98450000 \SystemRoot\System32\TSDDD.dll 0x98470000 \SystemRoot\System32\cdd.dll 0x98480000 \SystemRoot\System32\ATMFD.DLL 0x8CF72000 \SystemRoot\system32\drivers\luafv.sys 0xAA80F000 \SystemRoot\system32\drivers\spsys.sys 0xAA8BF000 \SystemRoot\system32\DRIVERS\lltdio.sys 0xAA8CF000 \SystemRoot\system32\DRIVERS\nwifi.sys 0xAA8F9000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xAA903000 \SystemRoot\system32\DRIVERS\rspndr.sys 0xAA916000 \SystemRoot\system32\drivers\HTTP.sys 0xAA983000 \SystemRoot\System32\DRIVERS\srvnet.sys 0xAA9A0000 \SystemRoot\system32\DRIVERS\bowser.sys 0xAA9B9000 \SystemRoot\System32\drivers\mpsdrv.sys 0xAA9CE000 \SystemRoot\system32\drivers\mrxdav.sys 0x8CF95000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x8CFB4000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x8BDDA000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0xAC00D000 \SystemRoot\System32\DRIVERS\srv2.sys 0xAC034000 \SystemRoot\System32\DRIVERS\srv.sys 0xAC09A000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys 0xAC09E000 \SystemRoot\system32\drivers\peauth.sys 0xAC17C000 \SystemRoot\System32\Drivers\secdrv.SYS 0xAC186000 \SystemRoot\System32\drivers\tcpipreg.sys 0xAC192000 \SystemRoot\system32\DRIVERS\xaudio.sys 0xAC19A000 \SystemRoot\System32\Drivers\N360\0402000.00C\SRTSP.SYS 0xB2964000 \SystemRoot\system32\DRIVERS\cdfs.sys 0xB297A000 \SystemRoot\System32\Drivers\Normandy.SYS 0xB2800000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100826.002\NAVEX15.SYS 0xB294C000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100826.002\NAVENG.SYS 0x76EE0000 \Windows\System32\ntdll.dll Processes (total 72): 0 System Idle Process 4 System 440 C:\Windows\System32\smss.exe 572 csrss.exe 616 C:\Windows\System32\wininit.exe 624 csrss.exe 660 C:\Windows\System32\services.exe 712 C:\Windows\System32\winlogon.exe 740 C:\Windows\System32\lsass.exe 748 C:\Windows\System32\lsm.exe 880 C:\Windows\System32\svchost.exe 940 C:\Windows\System32\svchost.exe 980 C:\Windows\System32\svchost.exe 1076 C:\Windows\System32\svchost.exe 1140 C:\Windows\System32\svchost.exe 1152 C:\Windows\System32\svchost.exe 1256 C:\Windows\System32\audiodg.exe 1284 C:\Windows\System32\svchost.exe 1304 C:\Windows\System32\SLsvc.exe 1360 C:\Windows\System32\svchost.exe 1488 C:\Windows\System32\svchost.exe 1780 C:\Windows\System32\dwm.exe 1808 C:\Windows\explorer.exe 1864 C:\Windows\System32\spoolsv.exe 1892 C:\Windows\System32\svchost.exe 1944 C:\Windows\System32\taskeng.exe 1976 C:\Windows\System32\taskeng.exe 1376 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1456 C:\Program Files\Bonjour\mDNSResponder.exe 1480 C:\Windows\System32\svchost.exe 536 C:\Program Files\Common Files\LightScribe\LSSrvc.exe 1640 C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccsvchst.exe 2124 C:\Windows\System32\svchost.exe 2152 C:\Windows\System32\svchost.exe 2184 C:\Windows\System32\svchost.exe 2204 C:\Windows\System32\SearchIndexer.exe 2276 C:\Windows\System32\drivers\XAudio.exe 2296 C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe 2980 C:\Program Files\Windows Defender\MSASCui.exe 2988 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 2996 C:\Program Files\HP\QuickPlay\QPService.exe 3008 C:\Program Files\Napster\napster.exe 3016 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe 3036 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe 3056 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe 3080 C:\Windows\System32\igfxtray.exe 3132 C:\Windows\System32\hkcmd.exe 3148 C:\Windows\System32\igfxpers.exe 3228 dllhost.exe 3252 C:\Program Files\iTunes\iTunesHelper.exe 3260 C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe 3364 WmiPrvSE.exe 3416 C:\Program Files\HP\HP Software Update\hpwuschd2.exe 3424 C:\Program Files\Common Files\Java\Java Update\jusched.exe 3492 C:\Program Files\Windows Sidebar\sidebar.exe 3500 C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccsvchst.exe 3512 C:\Windows\ehome\ehtray.exe 3736 C:\Program Files\Windows Media Player\wmpnscfg.exe 3768 C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe 2756 C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE 3848 C:\Windows\ehome\ehmsas.exe 4068 C:\Program Files\Windows Sidebar\sidebar.exe 3412 C:\Program Files\iPod\bin\iPodService.exe 3952 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe 5132 RKUnhookerLE.EXE 5992 C:\Program Files\Internet Explorer\iexplore.exe 3340 C:\Program Files\Internet Explorer\iexplore.exe 488 C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe 6112 C:\Windows\System32\Macromed\Flash\FlashUtil10i_ActiveX.exe 5016 C:\Windows\System32\SearchProtocolHost.exe 5644 C:\Windows\System32\SearchFilterHost.exe 5548 C:\Users\Kennedy\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000011`565e3a00 (NTFS) PhysicalDrive0 Model Number: TOSHIBAMK8034GSX, Rev: AH301H Size Device Name MBR Status ——————————————– 74 GB \\.\PhysicalDrive0 Unknown MBR code SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
Please do the following:

Run MBRCheck again

When prompted, Enter 'Y' and hit ENTER for more options

When you see: "Enter your choice: Enter the physical disk number to dump (0-99, -1 to exit):"

Enter 0 to dump the MBR to the physical disk.

Name the dumped file as dump0.dat

Enter -1 to exit

A log file named "dump.dat" will be located in the same folder as MBRCheck was saved, please zip it up and attach in your next reply.
Running ComboFix
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hi SweetTech

Ive ran ComboFix and I have the report/log.

After it had finished though, I tried to open IE to post this and it wouldnt let me, saying "illegal operation attempted on a registry key that has been marked for deletion" and I got the same with firefox. Ive managed to get past it though by going through the windows help and support section online. Just wondering why that would happen or if it means anything….I havent tried and other programs yet.
Heres the ComboFix Log:

ComboFix 10-08-26.04 - Kennedy 27/08/2010 18:39:34.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.1013.333 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-07-27 to 2010-08-27 )))))))))))))))))))))))))))))))
.

2010-08-27 17:54 . 2010-08-27 17:54 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-08-26 14:31 . 2010-08-26 14:31 ——– d—–w- C:\_OTL
2010-08-26 12:18 . 2010-08-26 12:21 ——– d—–w- c:\users\Kennedy\AppData\Local\NPE
2010-08-14 14:20 . 2010-06-11 16:15 1248768 —-a-w- c:\windows\system32\msxml3.dll
2010-08-14 14:20 . 2010-06-18 15:04 302080 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-14 14:20 . 2010-06-18 15:04 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2010-08-14 14:18 . 2010-06-08 17:35 3600768 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-14 14:18 . 2010-06-08 17:35 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-08-14 14:18 . 2010-06-16 16:04 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-01 20:27 . 2010-08-26 14:57 ——– d—–w- c:\users\Kennedy\AppData\Local\CrashDumps

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-26 19:18 . 2006-12-19 05:45 12 —-a-w- c:\windows\bthservsdp.dat
2010-08-26 12:18 . 2010-03-01 23:17 ——– d—–w- c:\programdata\Norton
2010-08-26 11:33 . 2006-12-19 06:53 ——– d—–w- c:\program files\Common Files\Java
2010-08-26 11:30 . 2006-12-19 06:53 ——– d—–w- c:\program files\Java
2010-08-18 17:46 . 2007-07-28 10:06 6836 —-a-w- c:\users\Kennedy\AppData\Roaming\wklnhst.dat
2010-08-15 20:44 . 2008-08-23 13:29 ——– d—–w- c:\programdata\Microsoft Help
2010-08-15 20:28 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-08-14 13:33 . 2009-08-15 13:24 ——– d—–w- c:\users\Kennedy\AppData\Roaming\HpUpdate
2010-07-25 19:34 . 2006-12-19 06:17 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-07-24 17:27 . 2010-07-24 17:25 ——– d—–w- c:\program files\Symantec
2010-07-24 17:25 . 2010-07-24 17:27 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-07-24 17:25 . 2010-07-24 17:27 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-07-24 17:25 . 2010-07-24 17:27 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-07-24 17:24 . 2010-03-01 23:27 ——– d—–w- c:\program files\Norton 360
2010-07-24 17:23 . 2010-07-24 17:23 ——– d—–w- c:\program files\NortonInstaller
2010-07-24 16:41 . 2010-07-24 16:41 ——– d—–w- c:\users\Kennedy\AppData\Roaming\Tific
2010-07-22 22:43 . 2010-03-01 22:08 ——– d—–w- c:\programdata\FLEXnet
2010-07-22 22:43 . 2006-12-19 06:30 ——– d—–w- c:\program files\Microsoft Works
2010-07-22 22:43 . 2007-08-11 21:47 ——– d—–w- c:\program files\Disc2Phone
2010-07-22 22:43 . 2006-12-19 06:17 ——– d—–w- c:\program files\Common Files\SureThing Shared
2010-07-21 19:48 . 2010-07-21 19:48 ——– d—–w- c:\program files\Norton 360(357)
2010-07-21 19:38 . 2010-03-01 23:14 ——– d—–w- c:\programdata\NortonInstaller
2010-07-17 04:00 . 2010-05-14 09:25 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-26 06:05 . 2010-08-14 14:19 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-14 14:19 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-14 14:19 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-14 14:19 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-06-23 18:42 . 2010-06-23 18:42 501936 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb2C7E.tmp.exe
2010-06-21 13:41 . 2007-07-24 14:18 5676 —-a-w- c:\users\Kennedy\AppData\Local\d3d9caps.dat
2010-06-21 13:37 . 2010-08-14 14:19 2037760 —-a-w- c:\windows\system32\win32k.sys
2010-06-18 17:31 . 2010-08-14 14:19 36864 —-a-w- c:\windows\system32\rtutils.dll
2010-06-11 16:16 . 2010-08-14 14:19 274944 —-a-w- c:\windows\system32\schannel.dll
2009-03-31 22:47 . 2009-12-13 20:50 324976 —-a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2007-07-24 17:26 . 2007-07-24 17:26 22 –sha-w- c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-14 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-11-24 167936]
"NapsterShell"="c:\program files\Napster\napster.exe" [2006-09-06 323216]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 317152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 472800]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-02-26 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-02-26 151552]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-02-26 126976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-12-13 122880]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2007-7-27 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):af,18,be,84,41,15,ca,01

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 135664]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0402000.00C\SYMDS.SYS [2010-02-04 328752]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0402000.00C\SYMEFA.SYS [2010-04-22 173104]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20100810.004\BHDrvx86.sys [2010-08-10 692272]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0402000.00C\ccHPx86.sys [2010-02-26 501888]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20100826.001\IDSvix86.sys [2010-06-17 344112]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0402000.00C\Ironx86.SYS [2010-04-29 116784]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\N360\0402000.00C\SYMTDIV.SYS [2010-05-06 339504]
S2 N360;Norton 360;c:\program files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe [2010-02-26 126392]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-07-22 102448]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 21:48]

2010-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 21:48]

2010-08-27 c:\windows\Tasks\User_Feed_Synchronization-{FE4FD8A0-3B89-4584-BD65-192BC78BA3D6}.job
- c:\windows\system32\msfeedssync.exe [2010-08-14 04:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_GB&c;=71&bd;=PRESARIO&pf;=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Kennedy\AppData\Roaming\Mozilla\Firefox\Profiles\j1fpwhha.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-27 18:54
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Norton 360\Engine\4.2.0.12\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-08-27 19:03:22
ComboFix-quarantined-files.txt 2010-08-27 18:03

Pre-Run: 4,832,358,400 bytes free
Post-Run: 4,729,212,928 bytes free

- - End Of File - - 9F816E18BED3BC75C4C1986799848129

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI