This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Nukesploit P4ck Activity

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Last Night Symantec Endpoint Protection began alerting my with the message "[SID: 23363] HTTP Nukesploit P4ck Activity Detected." I followed the instructions on the Symantec Site which told me to disable system restore, Update VIrus Defs, and Run a Full Scan.

I completed this and the msg keeps popping up every couple minutes. I read the Instructions page for posting to this forum and ran the OTL Took with the instructions that were given.

OTL.TXT


OTL logfile created on: 8/30/2010 12:29:22 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Tony\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 52.47 Gb Free Space | 22.53% Space Free | Partition Type: NTFS
Drive D: | 6.70 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VENTURE-B6C3A09
Current User Name: Tony
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Tony\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe (ScanSoft, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Tony\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\ScanSoft\OmniPageSE2.0\OpHookSE2.dll (ScanSoft, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE (Microsoft Corporation)
SRV - (MSSQLServerADHelper100) – c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE (Microsoft Corporation)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (bgsvcgen) – C:\WINDOWS\System32\bgsvcgen.exe (B.H.A Corporation)


========== Driver Services (SafeList) ==========

DRV - (TCCrystalCpuInfo) – C:\DOCUME~1\Tony\LOCALS~1\Temp\TCCpuInfo.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100829.004\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100829.004\NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) – C:\WINDOWS\system32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SysPlant) – C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:\WINDOWS\system32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (COH_Mon) – C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (Teefer2) – C:\WINDOWS\system32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (RsFx0102) – C:\WINDOWS\system32\drivers\RsFx0102.sys (Microsoft Corporation)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (ADIDTSFiltService) – C:\WINDOWS\system32\drivers\adidts.sys (Analog Devices, Inc.)
DRV - (JRAID) – C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (ADIHdAudAddService) – C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (cdrbsdrv) – C:\WINDOWS\System32\drivers\cdrbsdrv.sys (B.H.A Corporation)
DRV - (JGOGO) – C:\WINDOWS\system32\DRIVERS\JGOGO.sys (JMicron )
DRV - (ATIAVAIW) – C:\WINDOWS\system32\drivers\atinavt2.sys (ATI Technologies Inc.)
DRV - (atinevxx) – C:\WINDOWS\system32\drivers\atinevxx.sys (ATI Technologies Inc.)
DRV - (MVDCODEC) – C:\WINDOWS\system32\drivers\atinmdxx.sys (ATI Technologies Inc.)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (msloop) – C:\WINDOWS\system32\drivers\loop.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?hl=en
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



O1 HOSTS File: ([2010/05/12 20:22:22 | 000,001,155 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts:
O1 - Hosts: 10.254.254.253 Xdrive
O1 - Hosts: 82.98.231.89 browser-security.microsoft.com
O1 - Hosts: 82.98.231.89 best-click-scanner.info
O1 - Hosts: 82.98.231.89 antivirus-xp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.infosecuritycenter.com
O1 - Hosts: 82.98.231.89 microsoft.softwaresecurityhelp.com
O1 - Hosts: 82.98.231.89 onlinenotifyq.net
O1 - Hosts: 82.98.231.89 antivirusxp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.browser-security-center.com
O1 - Hosts: 192.168.254.4 HP0016354EB76B
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [JMB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe (JMicron Technology Corp.)
O4 - HKLM..\Run: [OpwareSE2] C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Tony\Start Menu\Programs\Startup\sysrda32.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: doccentral.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: fnismls.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: getmedianow.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: rdesk.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: rexplorer.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: showingtime.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sitexdata.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: spellchecker.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: transactionpoint.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: trpoint.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virtualearth.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: xmlsweb.com ([]* in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos2.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} http://www.xdrive.com/downloads/std_install/setup.exe (InstallShield Setup Player 2K2)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1264368736984 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254 192.168.254.254
O18 - Protocol\Handler\cf - No CLSID value found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/27 23:17:35 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2006/09/17 16:56:02 | 000,335,872 | R— | M] (Monolith Productions, Inc.) - D:\AutoRun.exe – [ CDFS ]
O32 - AutoRun File - [2007/02/16 23:04:22 | 000,000,000 | R–D | M] - D:\autorun – [ CDFS ]
O32 - AutoRun File - [2006/12/04 14:08:34 | 000,000,070 | R— | M] () - D:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2006/12/07 17:41:55 | 000,002,144 | R— | M] () - D:\autorun.ini – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2010/08/24 16:00:03 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2010/08/22 12:16:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Tony\My Documents\My Games
[2010/08/18 19:12:09 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/08/18 19:12:09 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/08/18 19:12:09 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/08/18 19:12:09 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2008/08/05 22:51:57 | 001,283,912 | —- | C] (Blizzard Entertainment) – C:\Program Files\WoW-2.3.0.7561-enUS-downloader.exe
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/30 12:17:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1006UA.job
[2010/08/30 12:15:10 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/30 12:13:59 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/08/30 12:13:42 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/30 12:13:37 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/30 12:13:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/30 12:07:53 | 007,077,888 | —- | M] () – C:\Documents and Settings\Tony\ntuser.dat
[2010/08/30 12:07:53 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Tony\ntuser.ini
[2010/08/30 01:52:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/30 01:40:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1007UA.job
[2010/08/30 00:34:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1003UA.job
[2010/08/30 00:34:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1003Core.job
[2010/08/29 23:40:26 | 000,000,004 | —- | M] () – C:\Documents and Settings\Tony\Application Data\avdrn.dat
[2010/08/29 21:40:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1007Core.job
[2010/08/29 17:55:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for Tony.job
[2010/08/29 16:17:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1788223648-682003330-1006Core.job
[2010/08/28 17:35:00 | 000,000,476 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for Alicia.job
[2010/08/28 17:32:54 | 000,001,466 | —- | M] () – C:\Documents and Settings\Tony\Desktop\DivX Movies.lnk
[2010/08/28 17:32:39 | 000,000,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/08/22 14:27:06 | 000,000,023 | —- | M] () – C:\WINDOWS\BlendSettings.ini
[2010/08/20 19:42:48 | 000,204,800 | —- | M] () – C:\Documents and Settings\Tony\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/19 23:01:39 | 004,976,176 | -H– | M] () – C:\Documents and Settings\Tony\Local Settings\Application Data\IconCache.db
[2010/08/19 13:39:44 | 000,078,104 | —- | M] () – C:\Documents and Settings\Tony\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/08/18 19:29:14 | 000,302,032 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/18 19:27:48 | 000,000,813 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/18 19:27:48 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/08/18 19:27:48 | 000,000,274 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/12 03:33:13 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/12 03:20:16 | 000,626,356 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/12 03:20:16 | 000,530,384 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/12 03:20:16 | 000,103,360 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/04 11:34:23 | 011,685,888 | —- | M] () – C:\Documents and Settings\Tony\Desktop\Venture Services, LLC.QBW
[2010/08/02 18:30:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/02 16:05:26 | 000,011,399 | —- | M] () – C:\Documents and Settings\Tony\Desktop\content.pl
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/29 23:40:26 | 000,000,004 | —- | C] () – C:\Documents and Settings\Tony\Application Data\avdrn.dat
[2010/08/28 17:32:39 | 000,000,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/08/02 16:05:26 | 000,011,399 | —- | C] () – C:\Documents and Settings\Tony\Desktop\content.pl
[2010/05/24 16:29:48 | 000,038,502 | —- | C] () – C:\Documents and Settings\Tony\Application Data\Comma Separated Values (Windows).ADR
[2010/05/07 15:29:44 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/04/11 22:48:00 | 000,008,438 | -HS- | C] () – C:\Documents and Settings\Tony\Local Settings\Application Data\0CMR8yFmkXh
[2010/04/11 22:48:00 | 000,008,438 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\0CMR8yFmkXh
[2010/04/08 18:36:48 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/30 20:58:42 | 000,000,314 | —- | C] () – C:\WINDOWS\primopdf.ini
[2009/03/11 20:38:53 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/11 20:38:53 | 000,022,328 | —- | C] () – C:\Documents and Settings\Tony\Application Data\PnkBstrK.sys
[2008/04/17 22:58:39 | 000,278,984 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2008/04/17 22:58:39 | 000,025,416 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/02/27 20:40:14 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2007/12/27 20:15:14 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2007/12/17 21:10:40 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\Gif89.dll
[2007/10/28 19:17:20 | 000,000,008 | —- | C] () – C:\WINDOWS\ctrdmrd3.ini
[2007/09/27 11:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/07/20 19:10:44 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\ktdll.dll
[2007/07/09 23:23:53 | 000,394,240 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2007/07/09 23:23:52 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2007/07/09 09:58:26 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2007/07/09 09:58:26 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2007/07/09 09:58:26 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2007/05/15 00:25:45 | 000,000,000 | —- | C] () – C:\WINDOWS\Mavis Beacon Teaches Typing.INI
[2007/04/11 21:52:23 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2006/12/22 17:54:48 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/12/20 01:40:48 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2006/12/16 13:38:28 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/12/15 14:58:34 | 000,000,732 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2006/12/15 13:55:24 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/12/15 13:55:11 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2006/12/15 13:36:44 | 000,010,007 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/12/01 20:35:05 | 000,000,085 | —- | C] () – C:\WINDOWS\Prestopm.INI
[2006/11/10 14:00:46 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/10/14 22:33:23 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS6y.DLL
[2006/10/14 22:30:35 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2006/10/14 22:30:27 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2006/10/14 22:28:50 | 000,000,532 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2006/10/14 22:26:53 | 000,000,398 | —- | C] () – C:\WINDOWS\System32\CNCMP60.INI
[2006/10/14 21:06:10 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Tony.ini
[2006/09/14 00:47:53 | 000,204,800 | —- | C] () – C:\Documents and Settings\Tony\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/14 00:18:59 | 000,002,963 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/09/13 21:34:40 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/08/26 19:05:22 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2006/08/26 03:23:56 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2006/08/26 01:38:05 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2006/08/26 01:38:05 | 000,005,685 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2006/08/26 01:30:59 | 000,000,127 | —- | C] () – C:\Documents and Settings\Tony\Local Settings\Application Data\fusioncache.dat
[2006/08/26 00:39:41 | 000,021,933 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2006/08/26 00:39:23 | 000,023,885 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/08/26 00:39:20 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/08/26 00:39:16 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/08/26 00:35:44 | 000,063,730 | —- | C] () – C:\Program Files\viewsonicinstruct_xp.pdf
[2006/08/26 00:35:23 | 000,000,085 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2004/09/22 14:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2001/07/06 17:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2007/05/15 00:34:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund
[2009/07/07 18:56:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2008/11/27 23:26:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/08/20 17:50:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2006/10/21 19:03:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2006/10/14 22:28:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2010/05/09 09:44:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/27 19:30:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/05 15:21:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/04/02 18:04:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Any Video Converter
[2010/08/20 22:29:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\BitTorrent
[2007/05/15 00:26:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Tony\Application Data\Broderbund
[2006/12/01 20:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Canon
[2010/01/17 22:34:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\com.fox.dollhouse.VirtualEcho.8DB2FB41E3AF9617470F9C3E78FDAAA51EF66383.1
[2010/08/30 12:24:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\DNA
[2009/07/07 07:18:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\GARMIN
[2006/08/26 00:36:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Leadertech
[2007/07/10 09:57:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\MPEG Streamclip
[2006/10/14 22:30:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\NewSoft
[2010/04/07 13:12:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\OpenOffice.org
[2010/05/07 15:35:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Panasonic
[2010/04/21 11:25:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\PrimoPDF
[2006/10/14 22:28:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\ScanSoft
[2009/08/12 20:52:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Snapfish
[2008/12/08 00:05:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Windows Desktop Search
[2008/12/08 01:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Windows Search
[2007/12/27 20:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Xdrive
[2010/04/02 18:14:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Tony\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/11/27 23:17:35 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2009/02/28 17:05:01 | 000,001,509 | —- | M] () – C:\BFUlogdeepdive.txt
[2006/08/28 19:21:15 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/08/18 19:27:48 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/07/04 23:15:03 | 000,000,000 | RHS- | M] () – C:\CONFIG.SYS
[2008/10/09 20:25:47 | 000,002,553 | —- | M] () – C:\Cucu_Video_log.txt
[2006/04/11 03:32:48 | 000,000,051 | —- | M] () – C:\delnis.bat
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006/08/26 00:21:58 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/03/08 13:43:05 | 000,018,819 | —- | M] () – C:\JavaRa.log
[2006/08/26 00:21:58 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/09/03 19:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\npbittorrent.dll
[2004/08/12 08:25:07 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/12/03 17:52:26 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/30 12:13:06 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/03/08 14:05:35 | 000,000,308 | —- | M] () – C:\TCleaner.txt
[2009/07/13 12:43:01 | 000,001,699 | —- | M] () – C:\trace3.txt
[2009/07/13 12:46:18 | 000,000,817 | —- | M] () – C:\trace4.txt
[2009/07/13 13:57:26 | 000,001,269 | —- | M] () – C:\tracert.txt
[2009/07/13 12:34:39 | 000,001,709 | —- | M] () – C:\tracert2.txt
[2010/05/07 15:40:29 | 000,000,026 | —- | M] () – C:\UpdaterforApp.ini
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2006/08/26 01:13:51 | 000,000,185 | —- | M] () – C:\wifi.log

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/08/26 00:21:40 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/06/14 15:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD6y.DLL
[2004/06/14 15:00:00 | 000,054,272 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP6y.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/10/14 23:41:46 | 000,072,192 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2007/05/24 22:59:50 | 000,184,400 | —- | M] (MacSourcery) – C:\WINDOWS\Pride and Prejudice-DVD.scr
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2002/09/11 09:26:52 | 000,063,730 | —- | M] () – C:\Program Files\viewsonicinstruct_xp.pdf
[2008/08/05 22:51:57 | 001,283,912 | —- | M] (Blizzard Entertainment) – C:\Program Files\WoW-2.3.0.7561-enUS-downloader.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2001/12/31 20:34:02 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2001/12/31 20:34:02 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2001/12/31 20:34:02 | 000,921,600 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/03 17:57:27 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/08/26 00:25:57 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Tony\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/08/26 00:25:57 | 000,000,079 | —- | M] () – C:\Documents and Settings\Tony\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2008/05/28 21:56:07 | 007,327,744 | —- | M] () – C:\Documents and Settings\Tony\Desktop\Complete Forms 905.exe
[2009/07/07 03:15:41 | 2060,596,375 | —- | M] () – C:\Documents and Settings\Tony\Desktop\Garmin_RMU_CNNANT2010C.exe
[2007/01/08 11:06:22 | 005,689,344 | —- | M] (Gabest) – C:\Documents and Settings\Tony\Desktop\mplayerc.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-26 06:39:12
< End of report >
EXTRAS.TXT


OTL Extras logfile created on: 8/30/2010 12:29:22 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Tony\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 52.47 Gb Free Space | 22.53% Space Free | Partition Type: NTFS
Drive D: | 6.70 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VENTURE-B6C3A09
Current User Name: Tony
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML.Tony] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader
"6112:TCP" = 6112:TCP:*:Enabled:Blizzard Downloader

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – File not found
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – File not found
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe – File not found
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk – File not found
"C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe:*:Disabled:PowerDVD – File not found
"C:\Program Files\EA SPORTS\Madden NFL 07\Updater.exe" = C:\Program Files\EA SPORTS\Madden NFL 07\Updater.exe:*:Enabled:Updater – File not found
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\QuickTime\QuickTimePlayer.exe" = C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player – (Apple Inc.)
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA – (BitTorrent, Inc.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer – (Microsoft Corporation)
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher – File not found
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Turbine\Dungeons and Dragons Online - Eberron Unlimited\dndclient.exe" = C:\Program Files\Turbine\Dungeons and Dragons Online - Eberron Unlimited\dndclient.exe:*:Enabled:dndclient – File not found
"C:\Documents and Settings\Tony\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Tony\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe" = C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:*:Enabled:SMC Service – (Symantec Corporation)
"C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE" = C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:*:Enabled:SNAC Service – (Symantec Corporation)
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email – (Symantec Corporation)
"C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe" = C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe:*:Enabled:TurbineMessageService – File not found
"C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe" = C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe:*:Enabled:TurbineNetworkService – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{083F79E4-6FE9-46FB-A6C6-4F8862742947}" = ATI HYDRAVISION
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 21
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2b02f822-a9b9-458c-80e5-3ea8c0de8471}" = QuickBooks Pro Edition 2004
"{2EFCC193-D915-4CCB-9201-31773A27BC06}" = Symantec Endpoint Protection
"{301CC8D1-FE75-41ED-9B11-41F006110950}" = Garmin City Navigator North America NT 2010.10 Update
"{325F7A83-E15A-4C18-B5FE-E03A38F690BD}" = ATI Catalyst Control Center
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JRAID
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3D654496-9C3D-4565-858C-3E551ECDA4E2}" = Virtual Cable Tester
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{497A1721-088F-41EF-8876-B43C9DA5528B}" = ArcSoft Software Suite
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{5721A8EA-A30F-4F66-9046-3F40C43AE1DC}" = Driver Detective
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = AsusUpdate
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{58E6A969-8215-4ABC-BD73-FCB25EA6F544}" = FormViewer
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{5C104E56-A441-429D-A609-D8A46EB92EA1}" = PCMark05
"{5DA6F06A-B389-407B-BF8C-1548767914D8}" = ATI Problem Report Wizard
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE 2.0
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{82CA0A0C-A3EC-4167-B694-909205B2EDEC}" = muvee Plugin 1.0
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_OUTLOOKSTD_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_OUTLOOKSTD_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_OUTLOOKSTD_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_OUTLOOKSTD_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_OUTLOOKSTD_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00E0-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2007
"{90120000-00E0-0000-0000-0000000FF1CE}_OUTLOOKSTD_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00E0-0000-0000-0000000FF1CE}_OUTLOOKSTD_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_OUTLOOKSTD_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow! Plus
"{9862B19F-4CAD-4EED-920F-2F378D84393F}" = ATI Parental Control & Encoder
"{9A9DBEBC-C800-4776-A970-D76D6AA405B1}" = PHOTOfunSTUDIO HD Edition
"{9D6D76A6-4328-49E8-97A7-531A74841DA5}" = Microsoft SQL Server 2008 Setup Support Files (English)
"{A1F2EF0E-1EE5-4F0B-8A31-EE875EBD3F01}" = Mavis Beacon Teaches Typing 15
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A7DEBAA4-B211-4D1A-A6B3-E52BFAAA1D0C}" = Garmin Communicator Plugin
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AC76BA86-7AD7-5464-3428-7E8A450000A7}" = Spelling Dictionaries For Adobe Reader Package
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B79FBFDD-8B0C-4B8E-B70E-499E39978281}" = Windows Vista Upgrade Advisor
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D8087907-E255-3A41-A46D-D0F798709C71}" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
"{D9D937B0-E842-4130-9588-B948E876904A}" = Microsoft SQL Server 2008 Native Client
"{E0783143-EAE2-4047-A8D6-E155523C594C}" = Garmin WebUpdater
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F1DC7648-8623-442F-92B7-E118DF61872E}" = Microsoft SQL Server 2008 RsFx Driver
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AviSynth" = AviSynth 2.5
"BZFlag2.0.10" = BZFlag 2.0.10 (remove only)
"CD Audio Reader Filter" = CD Audio Reader Filter (remove only)
"DirectVobSub" = DirectVobSub (remove only)
"DivX Setup.divx.com" = DivX Setup
"DScaler 5 Mpeg Decoders_is1" = DScaler 5 Mpeg Decoders
"DS-MP3 Source" = DS-MP3 Source 1.30
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"Google Updater" = Google Updater
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{58E6A969-8215-4ABC-BD73-FCB25EA6F544}" = FormViewer
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaJoin" = MediaJoin
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Visual C++ 2008 Express Edition with SP1 - ENU" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OpenSource Flash Video Splitter" = OpenSource Flash Video Splitter (remove only)
"OUTLOOKSTD" = Microsoft Office Outlook 2007
"Panda ActiveScan" = Panda ActiveScan
"Picasa 3" = Picasa 3
"Ping Plotter Freeware" = Ping Plotter Freeware
"PrimoPDF" = PrimoPDF – by Nitro PDF Software
"PunkBusterSvc" = PunkBuster Services
"RealMedia" = RealMedia (remove only)
"SHOUTcast Source" = SHOUTcast Source (remove only)
"Videora iPod Converter" = Videora iPod Converter 4.01
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"winpcap-nmap" = winpcap-nmap 3.1
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"YouTube Downloader App" = YouTube Downloader App 1.00

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
"Google Chrome" = Google Chrome
"Move Media Player" = Move Media Player
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/22/2010 2:54:21 PM | Computer Name = VENTURE-B6C3A09 | Source = Application Error | ID = 1000
Description = Faulting application oblivion.exe, version 1.1.0.511, faulting module
oblivion.exe, version 1.1.0.511, fault address 0x002d7899.

Error - 8/27/2010 7:20:02 PM | Computer Name = VENTURE-B6C3A09 | Source = Application Error | ID = 1000
Description = Faulting application mplayerc.exe, version 6.4.9.0, faulting module
xvid.ax, version 0.0.0.0, fault address 0x0003dd11.

Error - 8/30/2010 12:53:13 AM | Computer Name = VENTURE-B6C3A09 | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!CainAbel in File: c:\program files\cain\voip\rtp-20070424205325375.wav
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.

Error - 8/30/2010 12:53:27 AM | Computer Name = VENTURE-B6C3A09 | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Tracking Cookies in File: Unavailable by: Manual
scan. Action: Quarantine failed : Leave Alone failed. Action Description: The
file was deleted successfully.

Error - 8/30/2010 1:18:38 AM | Computer Name = VENTURE-B6C3A09 | Source = Symantec AntiVirus | ID = 16711731
Description = Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\4\40591084-2fc3a12c>>vmain.class by: Manual
scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully. Security Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\4\40591084-2fc3a12c>>vmain.class by: Manual
scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully. Security Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\4\40591084-2fc3a12c by: Manual scan. Action:
Quarantine succeeded. Action Description: The file was quarantined successfully.

Risk
Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application Data\Sun\Java\Deployment\cache\6.0\4\40591084-2fc3a12c
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.

Error - 8/30/2010 1:18:47 AM | Computer Name = VENTURE-B6C3A09 | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\4\40591084-2fc3a12c by: Manual scan. Action:
Quarantine succeeded. Action Description: The file was quarantined successfully.

Security
Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application Data\Sun\Java\Deployment\cache\6.0\51\22c3fb33-60baba94>>myf/y/AppletX.class
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\51\22c3fb33-60baba94>>myf/y/AppletX.class by:
Manual scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully.

Error - 8/30/2010 1:18:47 AM | Computer Name = VENTURE-B6C3A09 | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\51\22c3fb33-60baba94>>myf/y/AppletX.class by:
Manual scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully. Security Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\51\22c3fb33-60baba94>>myf/y/LoaderX.class by:
Manual scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully. Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\51\22c3fb33-60baba94>>myf/y/LoaderX.class by:
Manual scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully.

Error - 8/30/2010 1:18:47 AM | Computer Name = VENTURE-B6C3A09 | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\51\22c3fb33-60baba94>>myf/y/LoaderX.class by:
Manual scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully. Security Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\51\22c3fb33-60baba94>>myf/y/PayloadX.class by:
Manual scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully. Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\51\22c3fb33-60baba94>>myf/y/PayloadX.class by:
Manual scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully.

Error - 8/30/2010 1:18:51 AM | Computer Name = VENTURE-B6C3A09 | Source = Symantec AntiVirus | ID = 16711731
Description = Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\8\3f5641c8-6323454b>>vmain.class by: Manual
scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully. Security Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\8\3f5641c8-6323454b>>vmain.class by: Manual
scan. Action: Quarantine succeeded. Action Description: The file was quarantined
successfully. Security Risk Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application
Data\Sun\Java\Deployment\cache\6.0\8\3f5641c8-6323454b by: Manual scan. Action:
Quarantine succeeded. Action Description: The file was quarantined successfully.

Risk
Found!Trojan Horse in File: c:\Documents and Settings\Tony\Application Data\Sun\Java\Deployment\cache\6.0\8\3f5641c8-6323454b
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.

Error - 8/30/2010 2:01:40 AM | Computer Name = VENTURE-B6C3A09 | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.KillAV in File: c:\_OTListIt\MovedFiles\03072009_211225\Program
Files\Common\helper.dll by: Manual scan. Action: Quarantine succeeded. Action
Description: The file was quarantined successfully.

[ OSession Events ]
Error - 7/25/2009 8:44:00 PM | Computer Name = VENTURE-B6C3A09 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 28
seconds with 0 seconds of active time. This session ended with a crash.

Error - 8/15/2009 11:30:16 AM | Computer Name = VENTURE-B6C3A09 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 28
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 8/30/2010 2:29:19 AM | Computer Name = VENTURE-B6C3A09 | Source = Service Control Manager | ID = 7001
Description = The Bonjour Service service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 8/30/2010 2:29:19 AM | Computer Name = VENTURE-B6C3A09 | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 8/30/2010 2:29:19 AM | Computer Name = VENTURE-B6C3A09 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD AsIO eeCtrl Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SPBBCDrv SRTSP SRTSPX SYMTDI
Tcpip
WPS

Error - 8/30/2010 2:37:58 AM | Computer Name = VENTURE-B6C3A09 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 8/30/2010 2:50:10 AM | Computer Name = VENTURE-B6C3A09 | Source = Service Control Manager | ID = 7034
Description = The PnkBstrA service terminated unexpectedly. It has done this 1
time(s).

Error - 8/30/2010 1:09:35 PM | Computer Name = VENTURE-B6C3A09 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 8/30/2010 1:10:29 PM | Computer Name = VENTURE-B6C3A09 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AsIO eeCtrl Fips intelppm SPBBCDrv SRTSP SRTSPX SYMTDI

Error - 8/30/2010 1:12:11 PM | Computer Name = VENTURE-B6C3A09 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 8/30/2010 1:29:47 PM | Computer Name = VENTURE-B6C3A09 | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 8/30/2010 1:29:47 PM | Computer Name = VENTURE-B6C3A09 | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2


< End of report >
Hello,

My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message to me on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________

First things first, please go back and re-enable System Restore.


Do you have any idea what this file is doing here:

C:\WINDOWS\Pride and Prejudice-DVD.scr



OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    DRV - (TCCrystalCpuInfo) – C:\DOCUME~1\Tony\LOCALS~1\Temp\TCCpuInfo.sys File not found
    DRV - (catchme) – C:\ComboFix\catchme.sys File not found
    O4 - Startup: C:\Documents and Settings\Tony\Start Menu\Programs\Startup\sysrda32.exe ()
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
    O18 - Protocol\Handler\cf - No CLSID value found
    [2010/04/11 22:48:00 | 000,008,438 | -HS- | C] () – C:\Documents and Settings\Tony\Local Settings\Application Data\0CMR8yFmkXh
    [2010/04/11 22:48:00 | 000,008,438 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\0CMR8yFmkXh
    [2009/03/08 13:43:05 | 000,018,819 | —- | M] () – C:\JavaRa.log
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:



Kaspersky Online Scanner
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


NEXT:



Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.




Please make sure you include the requested logs above, as well as an update on how your computer is currently running in your next post.
Sweet Tech,

Thank you so much for the assistance! I ran OTL with your prescribed fixes and it required a reboot. I have copied the log below.

After the reboot, Google Chrome will no longer load and gives the following error:" The Application failed to initialize properly (0x0000022). Click OK to terminate the application."

Also, upon reboot, Symantec Endpoint Protection caught many more threats ,and more warning came up after: The Original Error is now gone, However we are not in the clear yet.

Here is an abbreviated log from SEP With the OTL log following:

Filename Risk Action Action Description Date and Time
________vload.class Downloader Cleaned by deletion The file was deleted successfully. 8/30/2010 0:18
vmain.class Trojan.Gen Quarantined The file was quarantined successfully. 8/30/2010 0:18
7adbb65d-2250e379 Multiple Risks Quarantined The file was quarantined successfully. 8/30/2010 0:18
JavaUpdateApplication.class Downloader Cleaned by deletion The file was deleted successfully. 8/30/2010 0:18
JavaUpdateManager.class Downloader Cleaned by deletion The file was deleted successfully. 8/30/2010 0:18
2c9ba28b-14c273bb Downloader Log only The file was left unchanged. 8/30/2010 0:18
vmain.class Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
7bb99554-4d6911a2 Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
vmain.class Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
40591084-2fc3a12c Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
myf/y/AppletX.class Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
myf/y/LoaderX.class Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
myf/y/PayloadX.class Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
22c3fb33-60baba94 Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
AppletX.class Downloader Cleaned by deletion The file was deleted successfully. 8/30/2010 0:18
947f9b6-1c0f62a5 Downloader Log only The file was left unchanged. 8/30/2010 0:18
________vload.class Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
vmain.class Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
3f5641c8-6323454b Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 0:18
helper.dll Trojan.KillAV Quarantined The file was quarantined successfully. 8/30/2010 1:01
rtp-20070424205325375.wav CainAbel Quarantined The file was quarantined successfully. 8/29/2010 23:53
redbook.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
secdrv.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
usbaudio.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
TDPIPE.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
RDPWD.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
usbaapl.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
nwlnkflt.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
yk51x86.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
ndisip.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
TDTCP.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
PCIDump.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
entech.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
i2omgmt.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
PDCOMP.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
mpe.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
splitter.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
ParVdm.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
wudfrd.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
fjhdyfhsn.bat Trojan Horse Quarantined The file was quarantined successfully. 8/30/2010 14:43
swmidi.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
4103387408.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
Unavailable Tracking Cookies Deleted The file was deleted successfully. 8/29/2010 23:53
Modem.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
PDFRAME.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
ccdecode.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
mspclock.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
Cdaudio.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
srtspl.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
nwlnkfwd.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
atmarpc.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
i8042prt.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
ipfltdrv.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
usbscan.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
mstee.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
serscan.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
usbstor.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
wudfpf.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
Parport.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
coh_mon.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
slip.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
WDICA.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
irenum.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
drmkaud.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
npf.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
PDRFRAME.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
ipinip.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
usbprint.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
adidts.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
mskssrv.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
atinevxx.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
Changer.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
Sfloppy.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
ip6fw.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
wstcodec.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
mspqm.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
atinmdxx.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
loop.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
nabtsfec.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
PDRELI.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
imapi.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
streamip.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
lbrtfdc.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
dmusic.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43
aec.sys Hacktool.Rootkit Cleaned The file was repaired successfully. 8/30/2010 14:43

OTL Log

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Service TCCrystalCpuInfo stopped successfully!
Service TCCrystalCpuInfo deleted successfully!
File C:\DOCUME~1\Tony\LOCALS~1\Temp\TCCpuInfo.sys File not found not found.
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\ComboFix\catchme.sys File not found not found.
File move failed. C:\Documents and Settings\Tony\Start Menu\Programs\Startup\sysrda32.exe scheduled to be moved on reboot.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
File oft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab not found.
Starting removal of ActiveX control Microsoft XML Parser for Java
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\cf\ deleted successfully.
File Protocol\Handler\cf - No CLSID value found not found.
C:\Documents and Settings\Tony\Local Settings\Application Data\0CMR8yFmkXh moved successfully.
C:\Documents and Settings\All Users\Application Data\0CMR8yFmkXh moved successfully.
C:\JavaRa.log moved successfully.
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Tony\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Tony\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point (0)

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 688784 bytes
->Temporary Internet Files folder emptied: 1599643 bytes
->Flash cache emptied: 83 bytes

User: Administrator.VENTURE-B6C3A09
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 38766 bytes
->Flash cache emptied: 2919 bytes

User: Alicia
->Temp folder emptied: 107256813 bytes
->Temporary Internet Files folder emptied: 849277791 bytes
->Java cache emptied: 62059507 bytes
->Google Chrome cache emptied: 177605263 bytes
->Apple Safari cache emptied: 10455040 bytes
->Flash cache emptied: 66177 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 2919 bytes

User: HelpAssistant
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 83 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49554 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 805380 bytes

User: Test
->Temp folder emptied: 361462 bytes
->Temporary Internet Files folder emptied: 4039336 bytes
->Java cache emptied: 13652318 bytes
->Google Chrome cache emptied: 9753310 bytes
->Flash cache emptied: 898 bytes

User: Tony
->Temp folder emptied: 26646994 bytes
->Temporary Internet Files folder emptied: 35892262 bytes
->Java cache emptied: 47724834 bytes
->Google Chrome cache emptied: 13045965 bytes
->Apple Safari cache emptied: 54494208 bytes
->Flash cache emptied: 2541303 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2162283 bytes
%systemroot%\System32 .tmp files removed: 5670913 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2443088991 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 88338550 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 32768 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 3,774.00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: Administrator.VENTURE-B6C3A09
->Flash cache emptied: 0 bytes

User: Alicia
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: HelpAssistant
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

User: Test
->Flash cache emptied: 0 bytes

User: Tony
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.11.0 log created on 08302010_143332

Files\Folders moved on Reboot…
C:\Documents and Settings\Tony\Start Menu\Programs\Startup\sysrda32.exe moved successfully.

Registry entries deleted on Reboot…
hmm.. Okay.

Please hold off on the rest of my instructions.

I'm seeing something in your latest logs.

Do the following:

HAMeb_Check Scan

Download and run HAMeb_check.exe

Post the contents of the resulting log.
Hi Again,

I am now getting a notification of HTTP Infostealer Snifula.B Activity detected.

I ran Malwarebytes before I saw you Instructions. I ran HAMeb Check Scan as well. Here are both logs:

C:\Documents and Settings\Tony\Desktop\HAMeb_check.exe
Tue 08/31/2010 at 0:14:10.71

Account active No
Local Group Memberships

~~ Checking profile list ~~

S-1-5-21-1844237615-1788223648-682003330-1000
%SystemDrive%\Documents and Settings\HelpAssistant

~~ Checking for HelpAssistant directories ~~

HelpAssistant

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK

~~ Checking for termsrv32.dll ~~

termsrv32.dll was not found


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\GloballyOpenPorts\List]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


~~ EOF ~~


Malwarebytes

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4510

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

8/30/2010 3:27:40 PM
mbam-log-2010-08-30 (15-27-40).txt

Scan type: Quick scan
Objects scanned: 179527
Time elapsed: 6 minute(s), 17 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
C:\WINDOWS\system32\wuaucldt.exe (Trojan.Agent.Gen) -> Unloaded process successfully.

Memory Modules Infected:
C:\WINDOWS\utcprc.dll (Trojan.Hiloti) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wuaucldt (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cfumerebevami (Trojan.Hiloti) -> Delete on reboot.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\wuaucldt.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
C:\WINDOWS\utcprc.dll (Trojan.Hiloti) -> Delete on reboot.
C:\WINDOWS\system32\config\SystemProfile\wuaucldt.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Tony\Application Data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully.
Hello,

Please do the following:

Open notepad by going to START > RUN and type notepad.exe in the box that appears. In the window that pops up please copy and paste the following:

@echo off
echo Please wait
net stop RDSessMgr >nul 2>&1
net stop TermService >nul 2>&1
net user HelpAssistant /active:no >nul 2>&1
net localgroup Administrators HelpAssistant /delete >nul 2>&1
attrib -s -h -r %systemdrive%\docume~\HelpAssistant\* /s /d
del /s/q %systemdrive%\docume~\HelpAssistant\*.* >nul 2>&1
rmdir /s/q %systemdrive%\docume~\HelpAssistant >nul 2>&1
if exist %systemroot%\system32\termsrv32.dll del /q %systemroot%\system32\termsrv32.dll >nul 2>&1
mbr.exe -f
reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1844237615-1788223648-682003330-1000" /f
reg add HKLM\SYSTEM\CurrentControlSet\Services\TermService\Parameters /v ServiceDll /t REG_EXPAND_SZ /d ^%systemroot^%\System32\termsrv.dll /f
exit
cls

In Notepad click on the "File" menu > Save As… Under "File name" type fix.bat and Change "Save as type" to All Files, save it to a place you will remember.

[external image: Posted Image]

Double click on fix.bat


Re-Run HAMeb_Check Scan and post the log for me.
Good Morning,

Thank you so much for all of your help!!

I ran Kaspersky last night. When I awoke this morning I ran the batch file and HAmeb. Here are log files:

C:\Documents and Settings\Tony\Desktop\HAMeb_check.exe
Tue 08/31/2010 at 7:28:48.82

Account active No
Local Group Memberships

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking for HelpAssistant directories ~~

HelpAssistant

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK

~~ Checking for termsrv32.dll ~~

termsrv32.dll was not found


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ \System32\termsrv.dll

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\GloballyOpenPorts\List]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


~~ EOF ~~

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, August 31, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Monday, August 30, 2010 23:52:57
Records in database: 4169051
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Objects scanned: 99587
Threats found: 4
Infected objects found: 67
Suspicious objects found: 0
Scan duration: 02:07:06


File name / Threat / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40000.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40001.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40002.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40003.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40004.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40005.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40006.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40007.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40008.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40009.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000A.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000B.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000C.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000D.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000E.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000F.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40010.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40011.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40012.VBN Infected: Trojan.BAT.Agent.vf 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40013.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40014.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40015.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40016.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40017.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40018.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40019.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001A.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001B.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001C.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001D.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001E.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001F.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40020.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40021.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40022.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40023.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40024.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40025.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40026.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40027.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40028.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40029.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002A.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002B.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002C.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002D.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002E.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002F.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40030.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40031.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40032.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40033.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40034.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40035.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40036.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40037.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40038.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40039.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4003A.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4003B.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4003C.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4003D.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4003E.VBN Infected: Rootkit.Win32.Agent.biiu 1
C:\Documents and Settings\Tony\.housecall6.6\Quarantine\jar_cache6701.tmp.bac_a04076 Infected: Trojan.Java.ClassLoader.ap 3
C:\_OTL\MovedFiles\08302010_143332\C_Documents and Settings\Tony\Start Menu\Programs\Startup\sysrda32.exe Infected: Trojan.Win32.Agent.ezyw 1

Selected area has been scanned.
Hello,

Have you ever used remote assistance on your computer?

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40000.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40001.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40002.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40003.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40004.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40005.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40006.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40007.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40008.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40009.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000A.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000B.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000C.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000D.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000E.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4000F.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40010.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40011.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40012.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40013.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40014.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40015.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40016.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40017.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40018.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40019.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001A.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001B.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001C.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001D.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001E.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4001F.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40020.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40021.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40022.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40023.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40024.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40025.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40026.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40027.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40028.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40029.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002A.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002B.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002C.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002D.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002E.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4002F.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40030.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40031.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40032.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40033.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40034.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40035.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40036.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40037.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40038.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C40039.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4003A.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4003B.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4003C.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4003D.VBN
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\09C4003E.VBN
    C:\Documents and Settings\Tony\.housecall6.6\Quarantine\jar_cache6701.tmp.bac_a04076
    
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
I need to leave my home here in about 20 minutes and will be gone most of the day. I forgot to mention that I am not getting any more symptoms at the moment. Google Chrome still doesn't work. Thanks! I will check again before I leave and start any processes you ask. Thank you, Tony
Hi, I saw your previous post. I ran OTL with the designated fixes, however, when the system rebooted, it is very challenged: 1. It came up with your hardware has significantly changed and you must run windows activation within 3 days? —I said later 2. The theme was similar to classic menu but it was not set to that, also no sound card found, iexplore wouldn't work so I am now posting from my laptop. 3. Nothing was running in the systray. Including SEP Any Ideas?
hmm… That doesn't seem right. Go ahead and reboot your computer and see if everything is back to normal, or if your still experiencing issues with it.
I rebooted and received the same messages and the same scenario. I have to go now but I will check back when I return. Also, yes I did use Remote Assistance at one point.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI