ajsimo
Topic Starter
Last Night Symantec Endpoint Protection began alerting my with the message "[SID: 23363] HTTP Nukesploit P4ck Activity Detected." I followed the instructions on the Symantec Site which told me to disable system restore, Update VIrus Defs, and Run a Full Scan.
I completed this and the msg keeps popping up every couple minutes. I read the Instructions page for posting to this forum and ran the OTL Took with the instructions that were given.
OTL.TXT
OTL logfile created on: 8/30/2010 12:29:22 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Tony\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 52.47 Gb Free Space | 22.53% Space Free | Partition Type: NTFS
Drive D: | 6.70 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: VENTURE-B6C3A09
Current User Name: Tony
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Tony\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe (ScanSoft, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Tony\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\ScanSoft\OmniPageSE2.0\OpHookSE2.dll (ScanSoft, Inc.)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE (Microsoft Corporation)
SRV - (MSSQLServerADHelper100) – c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE (Microsoft Corporation)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (bgsvcgen) – C:\WINDOWS\System32\bgsvcgen.exe (B.H.A Corporation)
========== Driver Services (SafeList) ==========
DRV - (TCCrystalCpuInfo) – C:\DOCUME~1\Tony\LOCALS~1\Temp\TCCpuInfo.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100829.004\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100829.004\NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) – C:\WINDOWS\system32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SysPlant) – C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:\WINDOWS\system32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (COH_Mon) – C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (Teefer2) – C:\WINDOWS\system32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (RsFx0102) – C:\WINDOWS\system32\drivers\RsFx0102.sys (Microsoft Corporation)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (ADIDTSFiltService) – C:\WINDOWS\system32\drivers\adidts.sys (Analog Devices, Inc.)
DRV - (JRAID) – C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (ADIHdAudAddService) – C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (cdrbsdrv) – C:\WINDOWS\System32\drivers\cdrbsdrv.sys (B.H.A Corporation)
DRV - (JGOGO) – C:\WINDOWS\system32\DRIVERS\JGOGO.sys (JMicron )
DRV - (ATIAVAIW) – C:\WINDOWS\system32\drivers\atinavt2.sys (ATI Technologies Inc.)
DRV - (atinevxx) – C:\WINDOWS\system32\drivers\atinevxx.sys (ATI Technologies Inc.)
DRV - (MVDCODEC) – C:\WINDOWS\system32\drivers\atinmdxx.sys (ATI Technologies Inc.)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (msloop) – C:\WINDOWS\system32\drivers\loop.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?hl=en
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
O1 HOSTS File: ([2010/05/12 20:22:22 | 000,001,155 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts:
O1 - Hosts: 10.254.254.253 Xdrive
O1 - Hosts: 82.98.231.89 browser-security.microsoft.com
O1 - Hosts: 82.98.231.89 best-click-scanner.info
O1 - Hosts: 82.98.231.89 antivirus-xp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.infosecuritycenter.com
O1 - Hosts: 82.98.231.89 microsoft.softwaresecurityhelp.com
O1 - Hosts: 82.98.231.89 onlinenotifyq.net
O1 - Hosts: 82.98.231.89 antivirusxp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.browser-security-center.com
O1 - Hosts: 192.168.254.4 HP0016354EB76B
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [JMB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe (JMicron Technology Corp.)
O4 - HKLM..\Run: [OpwareSE2] C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Tony\Start Menu\Programs\Startup\sysrda32.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: doccentral.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: fnismls.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: getmedianow.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: rdesk.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: rexplorer.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: showingtime.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sitexdata.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: spellchecker.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: transactionpoint.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: trpoint.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virtualearth.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: xmlsweb.com ([]* in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos2.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} http://www.xdrive.com/downloads/std_install/setup.exe (InstallShield Setup Player 2K2)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1264368736984 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254 192.168.254.254
O18 - Protocol\Handler\cf - No CLSID value found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/27 23:17:35 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2006/09/17 16:56:02 | 000,335,872 | R— | M] (Monolith Productions, Inc.) - D:\AutoRun.exe – [ CDFS ]
O32 - AutoRun File - [2007/02/16 23:04:22 | 000,000,000 | R–D | M] - D:\autorun – [ CDFS ]
O32 - AutoRun File - [2006/12/04 14:08:34 | 000,000,070 | R— | M] () - D:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2006/12/07 17:41:55 | 000,002,144 | R— | M] () - D:\autorun.ini – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.
========== Files/Folders - Created Within 30 Days ==========
[2010/08/24 16:00:03 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2010/08/22 12:16:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Tony\My Documents\My Games
[2010/08/18 19:12:09 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/08/18 19:12:09 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/08/18 19:12:09 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/08/18 19:12:09 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2008/08/05 22:51:57 | 001,283,912 | —- | C] (Blizzard Entertainment) – C:\Program Files\WoW-2.3.0.7561-enUS-downloader.exe
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/30 12:17:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1006UA.job
[2010/08/30 12:15:10 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/30 12:13:59 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/08/30 12:13:42 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/30 12:13:37 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/30 12:13:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/30 12:07:53 | 007,077,888 | —- | M] () – C:\Documents and Settings\Tony\ntuser.dat
[2010/08/30 12:07:53 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Tony\ntuser.ini
[2010/08/30 01:52:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/30 01:40:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1007UA.job
[2010/08/30 00:34:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1003UA.job
[2010/08/30 00:34:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1003Core.job
[2010/08/29 23:40:26 | 000,000,004 | —- | M] () – C:\Documents and Settings\Tony\Application Data\avdrn.dat
[2010/08/29 21:40:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1007Core.job
[2010/08/29 17:55:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for Tony.job
[2010/08/29 16:17:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1006Core.job
[2010/08/28 17:35:00 | 000,000,476 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for Alicia.job
[2010/08/28 17:32:54 | 000,001,466 | —- | M] () – C:\Documents and Settings\Tony\Desktop\DivX Movies.lnk
[2010/08/28 17:32:39 | 000,000,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/08/22 14:27:06 | 000,000,023 | —- | M] () – C:\WINDOWS\BlendSettings.ini
[2010/08/20 19:42:48 | 000,204,800 | —- | M] () – C:\Documents and Settings\Tony\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/19 23:01:39 | 004,976,176 | -H– | M] () – C:\Documents and Settings\Tony\Local Settings\Application Data\IconCache.db
[2010/08/19 13:39:44 | 000,078,104 | —- | M] () – C:\Documents and Settings\Tony\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/08/18 19:29:14 | 000,302,032 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/18 19:27:48 | 000,000,813 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/18 19:27:48 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/08/18 19:27:48 | 000,000,274 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/12 03:33:13 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/12 03:20:16 | 000,626,356 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/12 03:20:16 | 000,530,384 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/12 03:20:16 | 000,103,360 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/04 11:34:23 | 011,685,888 | —- | M] () – C:\Documents and Settings\Tony\Desktop\Venture Services, LLC.QBW
[2010/08/02 18:30:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/02 16:05:26 | 000,011,399 | —- | M] () – C:\Documents and Settings\Tony\Desktop\content.pl
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/08/29 23:40:26 | 000,000,004 | —- | C] () – C:\Documents and Settings\Tony\Application Data\avdrn.dat
[2010/08/28 17:32:39 | 000,000,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/08/02 16:05:26 | 000,011,399 | —- | C] () – C:\Documents and Settings\Tony\Desktop\content.pl
[2010/05/24 16:29:48 | 000,038,502 | —- | C] () – C:\Documents and Settings\Tony\Application Data\Comma Separated Values (Windows).ADR
[2010/05/07 15:29:44 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/04/11 22:48:00 | 000,008,438 | -HS- | C] () – C:\Documents and Settings\Tony\Local Settings\Application Data\0CMR8yFmkXh
[2010/04/11 22:48:00 | 000,008,438 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\0CMR8yFmkXh
[2010/04/08 18:36:48 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/30 20:58:42 | 000,000,314 | —- | C] () – C:\WINDOWS\primopdf.ini
[2009/03/11 20:38:53 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/11 20:38:53 | 000,022,328 | —- | C] () – C:\Documents and Settings\Tony\Application Data\PnkBstrK.sys
[2008/04/17 22:58:39 | 000,278,984 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2008/04/17 22:58:39 | 000,025,416 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/02/27 20:40:14 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2007/12/27 20:15:14 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2007/12/17 21:10:40 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\Gif89.dll
[2007/10/28 19:17:20 | 000,000,008 | —- | C] () – C:\WINDOWS\ctrdmrd3.ini
[2007/09/27 11:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/07/20 19:10:44 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\ktdll.dll
[2007/07/09 23:23:53 | 000,394,240 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2007/07/09 23:23:52 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2007/07/09 09:58:26 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2007/07/09 09:58:26 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2007/07/09 09:58:26 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2007/05/15 00:25:45 | 000,000,000 | —- | C] () – C:\WINDOWS\Mavis Beacon Teaches Typing.INI
[2007/04/11 21:52:23 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2006/12/22 17:54:48 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/12/20 01:40:48 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2006/12/16 13:38:28 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/12/15 14:58:34 | 000,000,732 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2006/12/15 13:55:24 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/12/15 13:55:11 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2006/12/15 13:36:44 | 000,010,007 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/12/01 20:35:05 | 000,000,085 | —- | C] () – C:\WINDOWS\Prestopm.INI
[2006/11/10 14:00:46 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/10/14 22:33:23 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS6y.DLL
[2006/10/14 22:30:35 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2006/10/14 22:30:27 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2006/10/14 22:28:50 | 000,000,532 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2006/10/14 22:26:53 | 000,000,398 | —- | C] () – C:\WINDOWS\System32\CNCMP60.INI
[2006/10/14 21:06:10 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Tony.ini
[2006/09/14 00:47:53 | 000,204,800 | —- | C] () – C:\Documents and Settings\Tony\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/14 00:18:59 | 000,002,963 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/09/13 21:34:40 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/08/26 19:05:22 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2006/08/26 03:23:56 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2006/08/26 01:38:05 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2006/08/26 01:38:05 | 000,005,685 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2006/08/26 01:30:59 | 000,000,127 | —- | C] () – C:\Documents and Settings\Tony\Local Settings\Application Data\fusioncache.dat
[2006/08/26 00:39:41 | 000,021,933 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2006/08/26 00:39:23 | 000,023,885 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/08/26 00:39:20 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/08/26 00:39:16 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/08/26 00:35:44 | 000,063,730 | —- | C] () – C:\Program Files\viewsonicinstruct_xp.pdf
[2006/08/26 00:35:23 | 000,000,085 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2004/09/22 14:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2001/07/06 17:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2007/05/15 00:34:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund
[2009/07/07 18:56:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2008/11/27 23:26:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/08/20 17:50:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2006/10/21 19:03:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2006/10/14 22:28:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2010/05/09 09:44:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/27 19:30:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/05 15:21:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/04/02 18:04:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Any Video Converter
[2010/08/20 22:29:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\BitTorrent
[2007/05/15 00:26:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Tony\Application Data\Broderbund
[2006/12/01 20:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Canon
[2010/01/17 22:34:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\com.fox.dollhouse.VirtualEcho.8DB2FB41E3AF9617470F9C3E78FDAAA51EF66383.1
[2010/08/30 12:24:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\DNA
[2009/07/07 07:18:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\GARMIN
[2006/08/26 00:36:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Leadertech
[2007/07/10 09:57:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\MPEG Streamclip
[2006/10/14 22:30:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\NewSoft
[2010/04/07 13:12:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\OpenOffice.org
[2010/05/07 15:35:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Panasonic
[2010/04/21 11:25:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\PrimoPDF
[2006/10/14 22:28:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\ScanSoft
[2009/08/12 20:52:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Snapfish
[2008/12/08 00:05:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Windows Desktop Search
[2008/12/08 01:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Windows Search
[2007/12/27 20:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Xdrive
[2010/04/02 18:14:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Xilisoft Corporation
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/11/27 23:17:35 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2009/02/28 17:05:01 | 000,001,509 | —- | M] () – C:\BFUlogdeepdive.txt
[2006/08/28 19:21:15 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/08/18 19:27:48 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/07/04 23:15:03 | 000,000,000 | RHS- | M] () – C:\CONFIG.SYS
[2008/10/09 20:25:47 | 000,002,553 | —- | M] () – C:\Cucu_Video_log.txt
[2006/04/11 03:32:48 | 000,000,051 | —- | M] () – C:\delnis.bat
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006/08/26 00:21:58 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/03/08 13:43:05 | 000,018,819 | —- | M] () – C:\JavaRa.log
[2006/08/26 00:21:58 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/09/03 19:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\npbittorrent.dll
[2004/08/12 08:25:07 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/12/03 17:52:26 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/30 12:13:06 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/03/08 14:05:35 | 000,000,308 | —- | M] () – C:\TCleaner.txt
[2009/07/13 12:43:01 | 000,001,699 | —- | M] () – C:\trace3.txt
[2009/07/13 12:46:18 | 000,000,817 | —- | M] () – C:\trace4.txt
[2009/07/13 13:57:26 | 000,001,269 | —- | M] () – C:\tracert.txt
[2009/07/13 12:34:39 | 000,001,709 | —- | M] () – C:\tracert2.txt
[2010/05/07 15:40:29 | 000,000,026 | —- | M] () – C:\UpdaterforApp.ini
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2006/08/26 01:13:51 | 000,000,185 | —- | M] () – C:\wifi.log
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/08/26 00:21:40 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/06/14 15:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD6y.DLL
[2004/06/14 15:00:00 | 000,054,272 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP6y.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/10/14 23:41:46 | 000,072,192 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2007/05/24 22:59:50 | 000,184,400 | —- | M] (MacSourcery) – C:\WINDOWS\Pride and Prejudice-DVD.scr
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2002/09/11 09:26:52 | 000,063,730 | —- | M] () – C:\Program Files\viewsonicinstruct_xp.pdf
[2008/08/05 22:51:57 | 001,283,912 | —- | M] (Blizzard Entertainment) – C:\Program Files\WoW-2.3.0.7561-enUS-downloader.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2001/12/31 20:34:02 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2001/12/31 20:34:02 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2001/12/31 20:34:02 | 000,921,600 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/03 17:57:27 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/08/26 00:25:57 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Tony\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/08/26 00:25:57 | 000,000,079 | —- | M] () – C:\Documents and Settings\Tony\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2008/05/28 21:56:07 | 007,327,744 | —- | M] () – C:\Documents and Settings\Tony\Desktop\Complete Forms 905.exe
[2009/07/07 03:15:41 | 2060,596,375 | —- | M] () – C:\Documents and Settings\Tony\Desktop\Garmin_RMU_CNNANT2010C.exe
[2007/01/08 11:06:22 | 005,689,344 | —- | M] (Gabest) – C:\Documents and Settings\Tony\Desktop\mplayerc.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-26 06:39:12
< End of report >
I completed this and the msg keeps popping up every couple minutes. I read the Instructions page for posting to this forum and ran the OTL Took with the instructions that were given.
OTL.TXT
OTL logfile created on: 8/30/2010 12:29:22 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Tony\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 52.47 Gb Free Space | 22.53% Space Free | Partition Type: NTFS
Drive D: | 6.70 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: VENTURE-B6C3A09
Current User Name: Tony
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Tony\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe (ScanSoft, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Tony\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\ScanSoft\OmniPageSE2.0\OpHookSE2.dll (ScanSoft, Inc.)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE (Microsoft Corporation)
SRV - (MSSQLServerADHelper100) – c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE (Microsoft Corporation)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (bgsvcgen) – C:\WINDOWS\System32\bgsvcgen.exe (B.H.A Corporation)
========== Driver Services (SafeList) ==========
DRV - (TCCrystalCpuInfo) – C:\DOCUME~1\Tony\LOCALS~1\Temp\TCCpuInfo.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100829.004\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100829.004\NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) – C:\WINDOWS\system32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SysPlant) – C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:\WINDOWS\system32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (COH_Mon) – C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (Teefer2) – C:\WINDOWS\system32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (RsFx0102) – C:\WINDOWS\system32\drivers\RsFx0102.sys (Microsoft Corporation)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (ADIDTSFiltService) – C:\WINDOWS\system32\drivers\adidts.sys (Analog Devices, Inc.)
DRV - (JRAID) – C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (ADIHdAudAddService) – C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (cdrbsdrv) – C:\WINDOWS\System32\drivers\cdrbsdrv.sys (B.H.A Corporation)
DRV - (JGOGO) – C:\WINDOWS\system32\DRIVERS\JGOGO.sys (JMicron )
DRV - (ATIAVAIW) – C:\WINDOWS\system32\drivers\atinavt2.sys (ATI Technologies Inc.)
DRV - (atinevxx) – C:\WINDOWS\system32\drivers\atinevxx.sys (ATI Technologies Inc.)
DRV - (MVDCODEC) – C:\WINDOWS\system32\drivers\atinmdxx.sys (ATI Technologies Inc.)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (msloop) – C:\WINDOWS\system32\drivers\loop.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?hl=en
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
O1 HOSTS File: ([2010/05/12 20:22:22 | 000,001,155 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts:
O1 - Hosts: 10.254.254.253 Xdrive
O1 - Hosts: 82.98.231.89 browser-security.microsoft.com
O1 - Hosts: 82.98.231.89 best-click-scanner.info
O1 - Hosts: 82.98.231.89 antivirus-xp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.infosecuritycenter.com
O1 - Hosts: 82.98.231.89 microsoft.softwaresecurityhelp.com
O1 - Hosts: 82.98.231.89 onlinenotifyq.net
O1 - Hosts: 82.98.231.89 antivirusxp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.browser-security-center.com
O1 - Hosts: 192.168.254.4 HP0016354EB76B
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [JMB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe (JMicron Technology Corp.)
O4 - HKLM..\Run: [OpwareSE2] C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Tony\Start Menu\Programs\Startup\sysrda32.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: doccentral.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: fnismls.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: getmedianow.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: rdesk.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: rexplorer.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: showingtime.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sitexdata.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: spellchecker.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: transactionpoint.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: trpoint.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virtualearth.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: xmlsweb.com ([]* in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos2.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} http://www.xdrive.com/downloads/std_install/setup.exe (InstallShield Setup Player 2K2)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1264368736984 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254 192.168.254.254
O18 - Protocol\Handler\cf - No CLSID value found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/27 23:17:35 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2006/09/17 16:56:02 | 000,335,872 | R— | M] (Monolith Productions, Inc.) - D:\AutoRun.exe – [ CDFS ]
O32 - AutoRun File - [2007/02/16 23:04:22 | 000,000,000 | R–D | M] - D:\autorun – [ CDFS ]
O32 - AutoRun File - [2006/12/04 14:08:34 | 000,000,070 | R— | M] () - D:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2006/12/07 17:41:55 | 000,002,144 | R— | M] () - D:\autorun.ini – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.
========== Files/Folders - Created Within 30 Days ==========
[2010/08/24 16:00:03 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2010/08/22 12:16:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Tony\My Documents\My Games
[2010/08/18 19:12:09 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/08/18 19:12:09 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/08/18 19:12:09 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/08/18 19:12:09 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2008/08/05 22:51:57 | 001,283,912 | —- | C] (Blizzard Entertainment) – C:\Program Files\WoW-2.3.0.7561-enUS-downloader.exe
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/30 12:17:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1006UA.job
[2010/08/30 12:15:10 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/30 12:13:59 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/08/30 12:13:42 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/30 12:13:37 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/30 12:13:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/30 12:07:53 | 007,077,888 | —- | M] () – C:\Documents and Settings\Tony\ntuser.dat
[2010/08/30 12:07:53 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Tony\ntuser.ini
[2010/08/30 01:52:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/30 01:40:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1007UA.job
[2010/08/30 00:34:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1003UA.job
[2010/08/30 00:34:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1003Core.job
[2010/08/29 23:40:26 | 000,000,004 | —- | M] () – C:\Documents and Settings\Tony\Application Data\avdrn.dat
[2010/08/29 21:40:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1007Core.job
[2010/08/29 17:55:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for Tony.job
[2010/08/29 16:17:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1006Core.job
[2010/08/28 17:35:00 | 000,000,476 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for Alicia.job
[2010/08/28 17:32:54 | 000,001,466 | —- | M] () – C:\Documents and Settings\Tony\Desktop\DivX Movies.lnk
[2010/08/28 17:32:39 | 000,000,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/08/22 14:27:06 | 000,000,023 | —- | M] () – C:\WINDOWS\BlendSettings.ini
[2010/08/20 19:42:48 | 000,204,800 | —- | M] () – C:\Documents and Settings\Tony\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/19 23:01:39 | 004,976,176 | -H– | M] () – C:\Documents and Settings\Tony\Local Settings\Application Data\IconCache.db
[2010/08/19 13:39:44 | 000,078,104 | —- | M] () – C:\Documents and Settings\Tony\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/08/18 19:29:14 | 000,302,032 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/18 19:27:48 | 000,000,813 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/18 19:27:48 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/08/18 19:27:48 | 000,000,274 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/12 03:33:13 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/12 03:20:16 | 000,626,356 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/12 03:20:16 | 000,530,384 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/12 03:20:16 | 000,103,360 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/04 11:34:23 | 011,685,888 | —- | M] () – C:\Documents and Settings\Tony\Desktop\Venture Services, LLC.QBW
[2010/08/02 18:30:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/02 16:05:26 | 000,011,399 | —- | M] () – C:\Documents and Settings\Tony\Desktop\content.pl
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/08/29 23:40:26 | 000,000,004 | —- | C] () – C:\Documents and Settings\Tony\Application Data\avdrn.dat
[2010/08/28 17:32:39 | 000,000,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/08/02 16:05:26 | 000,011,399 | —- | C] () – C:\Documents and Settings\Tony\Desktop\content.pl
[2010/05/24 16:29:48 | 000,038,502 | —- | C] () – C:\Documents and Settings\Tony\Application Data\Comma Separated Values (Windows).ADR
[2010/05/07 15:29:44 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/04/11 22:48:00 | 000,008,438 | -HS- | C] () – C:\Documents and Settings\Tony\Local Settings\Application Data\0CMR8yFmkXh
[2010/04/11 22:48:00 | 000,008,438 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\0CMR8yFmkXh
[2010/04/08 18:36:48 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/30 20:58:42 | 000,000,314 | —- | C] () – C:\WINDOWS\primopdf.ini
[2009/03/11 20:38:53 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/11 20:38:53 | 000,022,328 | —- | C] () – C:\Documents and Settings\Tony\Application Data\PnkBstrK.sys
[2008/04/17 22:58:39 | 000,278,984 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2008/04/17 22:58:39 | 000,025,416 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/02/27 20:40:14 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2007/12/27 20:15:14 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2007/12/17 21:10:40 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\Gif89.dll
[2007/10/28 19:17:20 | 000,000,008 | —- | C] () – C:\WINDOWS\ctrdmrd3.ini
[2007/09/27 11:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/07/20 19:10:44 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\ktdll.dll
[2007/07/09 23:23:53 | 000,394,240 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2007/07/09 23:23:52 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2007/07/09 09:58:26 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2007/07/09 09:58:26 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2007/07/09 09:58:26 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2007/05/15 00:25:45 | 000,000,000 | —- | C] () – C:\WINDOWS\Mavis Beacon Teaches Typing.INI
[2007/04/11 21:52:23 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2006/12/22 17:54:48 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/12/20 01:40:48 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2006/12/16 13:38:28 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/12/15 14:58:34 | 000,000,732 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2006/12/15 13:55:24 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/12/15 13:55:11 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2006/12/15 13:36:44 | 000,010,007 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/12/01 20:35:05 | 000,000,085 | —- | C] () – C:\WINDOWS\Prestopm.INI
[2006/11/10 14:00:46 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/10/14 22:33:23 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS6y.DLL
[2006/10/14 22:30:35 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2006/10/14 22:30:27 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2006/10/14 22:28:50 | 000,000,532 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2006/10/14 22:26:53 | 000,000,398 | —- | C] () – C:\WINDOWS\System32\CNCMP60.INI
[2006/10/14 21:06:10 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Tony.ini
[2006/09/14 00:47:53 | 000,204,800 | —- | C] () – C:\Documents and Settings\Tony\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/14 00:18:59 | 000,002,963 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/09/13 21:34:40 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/08/26 19:05:22 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2006/08/26 03:23:56 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2006/08/26 01:38:05 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2006/08/26 01:38:05 | 000,005,685 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2006/08/26 01:30:59 | 000,000,127 | —- | C] () – C:\Documents and Settings\Tony\Local Settings\Application Data\fusioncache.dat
[2006/08/26 00:39:41 | 000,021,933 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2006/08/26 00:39:23 | 000,023,885 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/08/26 00:39:20 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/08/26 00:39:16 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/08/26 00:35:44 | 000,063,730 | —- | C] () – C:\Program Files\viewsonicinstruct_xp.pdf
[2006/08/26 00:35:23 | 000,000,085 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2004/09/22 14:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2001/07/06 17:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2007/05/15 00:34:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund
[2009/07/07 18:56:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2008/11/27 23:26:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/08/20 17:50:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2006/10/21 19:03:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2006/10/14 22:28:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2010/05/09 09:44:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/27 19:30:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/05 15:21:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/04/02 18:04:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Any Video Converter
[2010/08/20 22:29:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\BitTorrent
[2007/05/15 00:26:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Tony\Application Data\Broderbund
[2006/12/01 20:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Canon
[2010/01/17 22:34:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\com.fox.dollhouse.VirtualEcho.8DB2FB41E3AF9617470F9C3E78FDAAA51EF66383.1
[2010/08/30 12:24:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\DNA
[2009/07/07 07:18:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\GARMIN
[2006/08/26 00:36:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Leadertech
[2007/07/10 09:57:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\MPEG Streamclip
[2006/10/14 22:30:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\NewSoft
[2010/04/07 13:12:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\OpenOffice.org
[2010/05/07 15:35:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Panasonic
[2010/04/21 11:25:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\PrimoPDF
[2006/10/14 22:28:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\ScanSoft
[2009/08/12 20:52:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Snapfish
[2008/12/08 00:05:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Windows Desktop Search
[2008/12/08 01:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Windows Search
[2007/12/27 20:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Xdrive
[2010/04/02 18:14:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Xilisoft Corporation
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/11/27 23:17:35 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2009/02/28 17:05:01 | 000,001,509 | —- | M] () – C:\BFUlogdeepdive.txt
[2006/08/28 19:21:15 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/08/18 19:27:48 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/07/04 23:15:03 | 000,000,000 | RHS- | M] () – C:\CONFIG.SYS
[2008/10/09 20:25:47 | 000,002,553 | —- | M] () – C:\Cucu_Video_log.txt
[2006/04/11 03:32:48 | 000,000,051 | —- | M] () – C:\delnis.bat
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006/08/26 00:21:58 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/03/08 13:43:05 | 000,018,819 | —- | M] () – C:\JavaRa.log
[2006/08/26 00:21:58 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/09/03 19:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\npbittorrent.dll
[2004/08/12 08:25:07 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/12/03 17:52:26 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/30 12:13:06 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/03/08 14:05:35 | 000,000,308 | —- | M] () – C:\TCleaner.txt
[2009/07/13 12:43:01 | 000,001,699 | —- | M] () – C:\trace3.txt
[2009/07/13 12:46:18 | 000,000,817 | —- | M] () – C:\trace4.txt
[2009/07/13 13:57:26 | 000,001,269 | —- | M] () – C:\tracert.txt
[2009/07/13 12:34:39 | 000,001,709 | —- | M] () – C:\tracert2.txt
[2010/05/07 15:40:29 | 000,000,026 | —- | M] () – C:\UpdaterforApp.ini
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2006/08/26 01:13:51 | 000,000,185 | —- | M] () – C:\wifi.log
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/08/26 00:21:40 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/06/14 15:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD6y.DLL
[2004/06/14 15:00:00 | 000,054,272 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP6y.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/10/14 23:41:46 | 000,072,192 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2007/05/24 22:59:50 | 000,184,400 | —- | M] (MacSourcery) – C:\WINDOWS\Pride and Prejudice-DVD.scr
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2002/09/11 09:26:52 | 000,063,730 | —- | M] () – C:\Program Files\viewsonicinstruct_xp.pdf
[2008/08/05 22:51:57 | 001,283,912 | —- | M] (Blizzard Entertainment) – C:\Program Files\WoW-2.3.0.7561-enUS-downloader.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2001/12/31 20:34:02 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2001/12/31 20:34:02 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2001/12/31 20:34:02 | 000,921,600 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/03 17:57:27 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/08/26 00:25:57 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Tony\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/08/26 00:25:57 | 000,000,079 | —- | M] () – C:\Documents and Settings\Tony\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2008/05/28 21:56:07 | 007,327,744 | —- | M] () – C:\Documents and Settings\Tony\Desktop\Complete Forms 905.exe
[2009/07/07 03:15:41 | 2060,596,375 | —- | M] () – C:\Documents and Settings\Tony\Desktop\Garmin_RMU_CNNANT2010C.exe
[2007/01/08 11:06:22 | 005,689,344 | —- | M] (Gabest) – C:\Documents and Settings\Tony\Desktop\mplayerc.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-26 06:39:12
< End of report >