This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC slow & just shuts down, Webpages dont show correct

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Machine is slow and sometimes just shuts down in the middle of work. It gives a windows error every login. Would not allow download of HJT or malwarebytes. The Symantec never finishes its scan. Just closes in the middle of scan. Cannot get a full webpage of most sites in either IE7 or Firefox. Very frustrating. Thanks in advance for your help.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:12:31 PM, on 9/12/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17080)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.maritadonohueteam.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.realtytools.com
O15 - Trusted Zone: http://*.toolkitcma.com
O15 - Trusted Zone: http://*.toolkitcma2.com
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.thelistingwidget.com/includes/u…geUploader5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1230856684750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1230917110406
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} (Image Uploader Control) - http://www.thelistingwidget.com/includes/u…geUploader6.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://dev.publicrecords.trendmls.com/Reso…er/fileopen.cab
O16 - DPF: {F375116A-793C-11D2-BFE1-444553540001} (First American Res MapActiveX Control) - http://realist2.firstamres.com/mapviewer/mapviewer.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

–
End of file - 8901 bytes
Hi NlightN, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Open hijackthis, do a system scan only and checkmark this line, if present

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.

Reboot your computer.

Next

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please post back with the OTL.txt and Extra.txt in your next reply .

Thanks
HJT gave parameter error, so I re-istalled and fixed the F2 line
No more errors on startup.

OTL logfile created on: 9/13/2010 5:17:13 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = D:\HaveDisk
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 568.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.61 Gb Total Space | 3.87 Gb Free Space | 20.81% Space Free | Partition Type: NTFS
Drive D: | 18.65 Gb Total Space | 5.54 Gb Free Space | 29.71% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DONOHUE
Current User Name: Marita
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - D:\HaveDisk\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardian.exe (LogMeIn, Inc.)
PRC - C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - D:\HaveDisk\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (TuneUp.ProgramStatisticsSvc) – C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)
SRV - (TuneUp.Defrag) – C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100912.005\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100912.005\NAVENG.SYS (Symantec Corporation)
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (WpsHelper) – C:\WINDOWS\system32\drivers\WpsHelper.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SysPlant) – C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:\WINDOWS\system32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (COH_Mon) – C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (Teefer2) – C:\WINDOWS\system32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.maritadonohueteam.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://www.topproducer8i.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0


FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/03 08:49:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/18 12:59:48 | 000,000,000 | —D | M]

[2009/01/05 10:06:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\Mozilla\Extensions
[2010/09/10 11:12:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\Mozilla\Firefox\Profiles\jm98hrkh.default\extensions
[2009/09/15 13:50:21 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Marita\Application Data\Mozilla\Firefox\Profiles\jm98hrkh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/01/05 10:06:17 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/27 11:33:58 | 000,184,320 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npxsciter.dll

O1 HOSTS File: ([2009/01/03 01:16:07 | 000,290,793 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10016 more lines…
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: realtytools.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: toolkitcma.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: toolkitcma2.com ([]http in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://www.thelistingwidget.com/includes/u…geUploader5.cab (Image Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1230856684750 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1230917110406 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} http://www.thelistingwidget.com/includes/u…geUploader6.cab (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} http://dev.publicrecords.trendmls.com/Reso…er/fileopen.cab (FoInstaller Class)
O16 - DPF: {F375116A-793C-11D2-BFE1-444553540001} http://realist2.firstamres.com/mapviewer/mapviewer.cab (First American Res MapActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.22.5.10 10.21.1.69 10.22.5.19
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\Marita\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Marita\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/01 13:17:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\CSvidcap.dll (TechSmith Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/13 09:39:41 | 000,000,000 | —D | C] – D:\My Documents\Referrals
[2010/09/13 09:19:16 | 000,000,000 | —D | C] – D:\My Documents\Marita's Personal Pics
[2010/09/12 16:21:06 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/09/12 16:09:08 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/09/08 02:45:03 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 D:\My Documents\*.tmp files -> D:\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/13 17:11:32 | 000,000,488 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/09/13 17:11:29 | 000,000,181 | —- | M] () – C:\WINDOWS\hpbafd.ini
[2010/09/13 16:55:59 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/13 16:55:50 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/13 16:54:57 | 009,175,040 | -H– | M] () – C:\Documents and Settings\Marita\NTUSER.DAT
[2010/09/13 16:54:57 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Marita\ntuser.ini
[2010/09/13 16:53:50 | 000,002,449 | —- | M] () – C:\Documents and Settings\Marita\Desktop\HiJackThis.lnk
[2010/09/12 16:10:06 | 000,000,709 | —- | M] () – C:\WINDOWS\win.ini
[2010/09/12 16:10:06 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/09/12 16:10:06 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/09/12 15:32:48 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/03 09:42:16 | 000,022,016 | —- | M] () – D:\My Documents\Envelope.doc
[2010/09/03 09:32:44 | 000,124,928 | —- | M] () – D:\My Documents\ANNIVERSARIE1.doc
[2010/09/02 10:24:42 | 000,000,256 | —- | M] () – C:\WINDOWS\System32\pool.bin
[2010/09/01 12:45:09 | 000,526,384 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/01 12:45:09 | 000,446,932 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/01 12:45:09 | 000,072,748 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/31 10:52:02 | 000,002,443 | —- | M] () – C:\Documents and Settings\Marita\Desktop\Microsoft Office Publisher 2003.lnk
[2010/08/26 10:11:14 | 010,340,864 | —- | M] () – D:\My Documents\Inquirer Article Aug 25.pub
[2010/08/26 10:00:07 | 000,005,632 | —- | M] () – C:\Documents and Settings\Marita\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/26 09:59:28 | 000,798,701 | —- | M] () – D:\My Documents\Inquirer article Aug 25.jpg
[2010/08/24 08:53:02 | 000,021,504 | —- | M] () – D:\My Documents\Closings.doc
[2010/08/19 14:22:21 | 000,002,549 | —- | M] () – C:\Documents and Settings\Marita\.powerupdate.user.properties
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 D:\My Documents\*.tmp files -> D:\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/12 16:21:07 | 000,002,449 | —- | C] () – C:\Documents and Settings\Marita\Desktop\HiJackThis.lnk
[2010/08/26 10:11:12 | 010,340,864 | —- | C] () – D:\My Documents\Inquirer Article Aug 25.pub
[2010/08/26 09:56:43 | 000,798,701 | —- | C] () – D:\My Documents\Inquirer article Aug 25.jpg
[2010/03/25 11:21:39 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2009/11/07 21:02:17 | 000,027,294 | —- | C] () – C:\Documents and Settings\Marita\Application Data\Comma Separated Values (Windows).ADR
[2009/10/07 10:59:04 | 000,005,632 | —- | C] () – C:\Documents and Settings\Marita\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2009/08/03 10:08:43 | 000,000,000 | —- | C] () – C:\WINDOWS\webica.ini
[2009/06/18 11:33:33 | 000,000,094 | —- | C] () – C:\WINDOWS\family.ini
[2009/01/27 13:13:26 | 000,000,129 | —- | C] () – C:\Documents and Settings\Marita\Local Settings\Application Data\fusioncache.dat
[2009/01/04 12:03:51 | 000,000,181 | —- | C] () – C:\WINDOWS\hpbafd.ini
[2009/01/02 23:20:16 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2009/01/02 09:53:14 | 000,000,000 | —- | C] () – C:\WINDOWS\oodcnt.INI
[2009/01/01 23:28:21 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/01/01 19:16:55 | 000,000,092 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2009/01/01 19:16:54 | 000,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2009/01/01 19:16:51 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[2009/01/01 19:16:50 | 000,028,672 | —- | C] () – C:\WINDOWS\CMIRmDriver.dll
[2009/01/01 18:21:04 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/09/06 00:30:42 | 000,190,976 | —- | C] () – C:\WINDOWS\System32\WgaLogon.dll
[2008/03/20 19:06:36 | 001,481,728 | —- | C] () – C:\WINDOWS\System32\LegitCheckControl.dll
[2006/10/27 09:26:56 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2004/04/09 04:15:50 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2010/01/12 14:52:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FileOpen
[2009/01/03 19:15:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/01/05 10:14:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MySpell
[2009/01/03 13:04:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2009/12/18 20:46:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009/01/04 01:21:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/12/18 20:46:03 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/06/18 13:52:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\Blackberry Desktop
[2009/01/02 09:53:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/03/15 08:43:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\CVS
[2010/03/25 09:04:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\Facebook
[2009/10/14 10:44:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\FileOpen
[2009/11/07 20:43:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\Funambol
[2009/06/18 11:33:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\HotSync
[2009/08/03 10:09:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\ICAClient
[2009/01/02 18:15:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\Leadertech
[2009/06/16 16:01:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\Research In Motion
[2010/08/30 10:04:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\ToolkitCMA
[2009/12/18 20:47:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\TuneUp Software
[2009/01/04 11:38:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\Xerox
[2010/09/13 17:11:32 | 000,000,488 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/01/03 19:15:36 | 000,001,024 | —- | M] () – C:\.rnd
[2009/05/19 09:21:43 | 000,001,945 | —- | M] () – C:\additdiag.txt
[2009/10/06 13:35:42 | 000,852,882 | —- | M] () – C:\AssessorMap_42045_630_1.tif
[2009/01/01 13:17:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/09/12 16:10:06 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/01/01 13:17:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/01/01 13:17:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/01 13:17:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/01/01 14:36:50 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/13 16:55:44 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2009/12/30 09:24:41 | 000,000,000 | —- | M] () – C:\t1n4.1
[2009/01/05 12:02:36 | 000,470,744 | —- | M] () – C:\tkwebsetup.exe

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/01/01 13:16:58 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2010/06/09 09:14:03 | 000,053,632 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/12/08 22:42:48 | 000,049,480 | —- | M] (Symantec Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\FwsVpn.dll
[2008/12/08 22:43:32 | 000,107,848 | —- | M] (Symantec Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\SymVPN.dll
[2008/12/08 22:43:34 | 000,357,704 | —- | M] (Symantec Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\sysfer.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/01/01 07:54:05 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/01 07:54:05 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/01 07:54:05 | 000,888,832 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/14 06:42:10 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/14 06:42:12 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/14 06:42:12 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 – C:\WINDOWS\system32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-12 20:49:44
< End of report >


OTL Extras logfile created on: 9/13/2010 5:17:13 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = D:\HaveDisk
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 568.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.61 Gb Total Space | 3.87 Gb Free Space | 20.81% Space Free | Partition Type: NTFS
Drive D: | 18.65 Gb Total Space | 5.54 Gb Free Space | 29.71% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DONOHUE
Current User Name: Marita
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"4899:TCP" = 4899:TCP:*:Enabled:tcp4899

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe" = C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:*:Enabled:SMC Service – (Symantec Corporation)
"C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE" = C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:*:Enabled:SNAC Service – (Symantec Corporation)
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email – (Symantec Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3BAB4914-9CC1-4CC2-A3DA-56EF62DFD373}" = Symantec Endpoint Protection
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}" = Apple Mobile Device Support
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{58E6A969-8215-4ABC-BD73-FCB25EA6F544}" = FormViewer
"{59991D18-A988-45AB-B1BF-5ADE6E64CD3F}" = SnagIt 9
"{5D95AD35-368F-47D5-B63A-A082DDF00119}" = Microsoft Digital Image Suite 2006 Editor
"{691F4068-81BF-49E3-B32E-FE3E16400119}" = Microsoft Digital Image Suite 2006 Library
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7F831576-6246-42C7-B523-55B3F96509CC}" = LogMeIn
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow! Deluxe
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B28759B8-5FC6-4F56-9C6C-6EDAD36455A9}" = Roxio Media Manager
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE5E3F15-320A-4865-97D3-F07227C5BB2F}" = BlackBerry Desktop Software 4.5
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"AgentMetrics" = AgentMetrics
"BlackBerry_{CE5E3F15-320A-4865-97D3-F07227C5BB2F}" = BlackBerry Desktop Software 4.5
"Camtasia Studio 3" = Camtasia Studio 3
"C-Media Audio" = C-Media 3D Audio
"C-Media Audio Driver" = C-Media WDM Audio Driver
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"doPDF 6 printer_is1" = doPDF 6.1 printer
"Hard Disk Sentinel_is1" = Hard Disk Sentinel PRO
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{58E6A969-8215-4ABC-BD73-FCB25EA6F544}" = FormViewer
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Ahead Nero 6 Demo
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PictureItSuite_v11" = Microsoft Digital Image Suite 2006
"Resize Pictures Plus_is1" = Resize Pictures Plus 2.1
"Simplify Printing Client v3" = Simplify Printing Client v3
"Top Producer Editor_is1" = Top Producer Editor
"ViewpointMediaPlayer" = Viewpoint Media Player
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xerox_Support_Centre" = Xerox Support Centre

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"GoToMeeting" = GoToMeeting 4.0.0.320
"ToolkitCMA" = ToolkitCMA

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/13/2010 12:00:57 PM | Computer Name = DONOHUE | Source = Application Hang | ID = 1002
Description = Hanging application MSPUB.EXE, version 11.0.8324.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/13/2010 12:09:18 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/13/2010 12:32:27 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/13/2010 1:31:15 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/13/2010 1:50:17 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/13/2010 2:15:05 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/13/2010 2:33:08 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/13/2010 3:23:21 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/13/2010 3:41:43 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/13/2010 4:44:56 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

[ System Events ]
Error - 9/13/2010 3:30:45 PM | Computer Name = DONOHUE | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk0\D.

Error - 9/13/2010 3:31:28 PM | Computer Name = DONOHUE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher
9 service to connect.

Error - 9/13/2010 3:36:49 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 00083201, parameter2 0000000a, parameter3
00000000, parameter4 f74d8e5e.

Error - 9/13/2010 3:36:55 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 1000000a, parameter1 3b01000d, parameter2 00000006, parameter3
00000001, parameter4 804d9122.

Error - 9/13/2010 3:37:00 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 1000000a, parameter1 00000177, parameter2 00000007, parameter3
00000001, parameter4 806d68bb.

Error - 9/13/2010 4:34:45 PM | Computer Name = DONOHUE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher
9 service to connect.

Error - 9/13/2010 4:50:09 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 00083201, parameter2 0000000a, parameter3
00000000, parameter4 f74d8e5e.

Error - 9/13/2010 4:50:16 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 1000000a, parameter1 3b01000d, parameter2 00000006, parameter3
00000001, parameter4 804d9122.

Error - 9/13/2010 4:50:19 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 10000050, parameter1 e23f0000, parameter2 00000000, parameter3
ee486cf5, parameter4 00000001.

Error - 9/13/2010 4:56:44 PM | Computer Name = DONOHUE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher
9 service to connect.


< End of report >


Thanks for your help
N
Hi NlightN,

Is this a program you used before and have sincw uninstalled?
O&O Defrag


You can uninstall this program via add/remove programs if you want to. You probably got it when you updated Adobe. It just uses up resources.

McAfee Security Scan Plus



Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now


Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

:Files
C:\WINDOWS\system32\sdra64.exe
:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL log in you next reply.



Let's have a deeper look.

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Saffe Mode

Please post back with
  • OTL fix log
  • GMER log
What problems are you still experiencing?

Thanks
Yes O&O defrag was removed when Tuneup utilies was installed because it has a scheduled defrag module.

Removed McAfee Security Scan

Updated JAVA

The machine disconnected me during the OTL fix. I've been doing this by Logmein since I am away on vacation. Luckily somebody local I contacted by phone could tell me whats going on.

Reports are below. The machine still gives errors on startup and auto-reboots ramdomly. This is my second attempt tp post because it rebooted in the middle of my reply.

All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\sdra64.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users
->Flash cache emptied: 35 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 98438 bytes

User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Marita
->Temp folder emptied: 30047423 bytes
->Temporary Internet Files folder emptied: 119420690 bytes
->Java cache emptied: 127859621 bytes
->FireFox cache emptied: 37740545 bytes
->Flash cache emptied: 2016652 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2342507 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 357782755 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 77466740 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 32902 bytes
RecycleBin emptied: 124928 bytes

Total Files Cleaned = 720.00 mb


OTL by OldTimer - Version 3.2.12.0 log created on 09142010_124233

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…



GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-14 15:46:58
Windows 5.1.2600 Service Pack 3
Running: r4dlyom6.exe; Driver: C:\DOCUME~1\Marita\LOCALS~1\Temp\fxldapod.sys


—- System - GMER 1.0.15 —-

SSDT 864E0D90 ZwAlertResumeThread
SSDT 864E0E68 ZwAlertThread
SSDT 865CF0D8 ZwAllocateVirtualMemory
SSDT 864F7D80 ZwConnectPort
SSDT 865B6370 ZwCreateMutant
SSDT 864D87D0 ZwCreateThread
SSDT 85F6A768 ZwFreeVirtualMemory
SSDT 864D93C8 ZwImpersonateAnonymousToken
SSDT 864DF510 ZwImpersonateThread
SSDT 864C3670 ZwMapViewOfSection
SSDT 864D8E90 ZwOpenEvent
SSDT 864E3528 ZwOpenProcessToken
SSDT 8664C288 ZwOpenThreadToken
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwProtectVirtualMemory [0xEEF776B0]
SSDT 864F65F8 ZwResumeThread
SSDT 864E2490 ZwSetContextThread
SSDT 864F7AA8 ZwSetInformationProcess
SSDT 864B17B8 ZwSetInformationThread
SSDT 864D74A8 ZwSuspendProcess
SSDT 864E1608 ZwSuspendThread
SSDT 864F7DD8 ZwTerminateProcess
SSDT 864E16E0 ZwTerminateThread
SSDT 864E2568 ZwUnmapViewOfSection
SSDT 85EAC8B8 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

Device \Driver\Tcpip \Device\Ip wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\Udp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\RawIp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)

AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\IPMULTICAST wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG11.00.00.01WORKSTATION 633A6C5ACB31B8869B2CEEDF5763333C74573A38B9ABE85D104BD0CA65CD4304840283EC052D5F8B
3CCDAC274600F0D3A151BD006792FB9A1A0CAA5B9E1560DB53730DE8D1853151E09F2F21159CD8F1A
60356578350980B1836E6D5626B4AE54154518B96A9FE0128E0D74C65EFE2517146971E8E08F89CE4
DEF0FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC
74CFEBC9E127BECC74CA6A0AC4980AC7933A6A0AC4980AC79335D575E7D6A3B9808FEBC9E127BECC7
4CE94845DD087F8953CFCFAEF994F593336F9E04E21F9AAFDA46E71371C7822A38A1897B2312325A9
EE72169D33A13322A79F1EFC39644D4719D95E6F29637C27E83065D48449714A84CEA9F885B8C43AE
B0C545A16FC508AAA5E05640A4D2BED025177E3C72D3E87FF5E4CB4DFDF430220CCF0694FE3C8A5FF
79B8E763622D81B62CBD0C17301AB442179CAA82BD2887B4BF719899F3B457AF24A9C079864F1DC5B
E6AE6FA22C582D4CC8DD77ED9F7CC4ED5B48C22E4A417BB728763798CE8EACF0DD522F60558803BCA
72BE8D7C9E11B39C9C1D10DE32FF32EA1F1A2098854AF4CDDDE4211F200A17A9B3C017D323432B649
1923A1F6610EFE574AB5C1AD912457C157B81B6CA27CD261FC9777300F50B310C471D467CD8219212
0329CCE345A421FA37AEAA0F797D3684057628D37CFC08C1D4D1

—- EOF - GMER 1.0.15 —-


Thanks for your help
Hi NlightN,

The machine still gives errors on startup

Please elaborate on the errors received at startup. If there are any codes or messages please post them in there entirety.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O34 - HKLM BootExecute: (OODBS) - File not found

:Commands
[reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Next
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Standard Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt . No Extra.txt this time.

Please post back with
  • OTL fix log
  • OTL.txt
Thanks
Error on startup = " Windows has recovered from a serious error 📎20100914_error_msg.png Send the msg and link states to check for virus, malware, & updates. Been there done that. Thats why I am here for advice. NOW, It keeps rebooting on the OTL fix and scan and no report. I'm going to cut my vacation short to sit in front of the machine tomorrow. Get this stuff done. Any other suggestions? Thanks for your help !! N
OK I am now in front of the computer and ran the fix. Unfortunately no log from the fix before or after the reboot. The scan is as below per your request.

OTL logfile created on: 9/15/2010 5:43:00 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = D:\HaveDisk
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 570.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.61 Gb Total Space | 3.59 Gb Free Space | 19.29% Space Free | Partition Type: NTFS
Drive D: | 18.65 Gb Total Space | 5.64 Gb Free Space | 30.24% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DONOHUE
Current User Name: Marita
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/09/13 16:31:44 | 000,576,000 | —- | M] (OldTimer Tools) – D:\HaveDisk\OTL.exe
PRC - [2010/06/09 09:14:18 | 000,116,104 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2010/06/09 09:14:01 | 000,378,248 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2009/12/18 20:47:28 | 000,604,488 | —- | M] (TuneUp Software) – C:\WINDOWS\system32\TUProgSt.exe
PRC - [2008/12/08 23:01:54 | 002,440,120 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
PRC - [2008/12/08 22:42:34 | 001,443,144 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
PRC - [2008/12/08 22:42:32 | 001,795,400 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
PRC - [2008/08/14 15:45:52 | 000,115,560 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2008/08/14 15:45:28 | 000,108,392 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2008/07/24 19:46:10 | 000,063,048 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2008/07/24 19:46:10 | 000,063,040 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2008/04/14 06:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010/09/13 16:31:44 | 000,576,000 | —- | M] (OldTimer Tools) – D:\HaveDisk\OTL.exe
MOD - [2008/04/14 06:40:22 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\WINDOWS\System32\hidserv.dll – (HidServ)
SRV - [2010/06/09 09:14:18 | 000,116,104 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files\LogMeIn\x86\RaMaint.exe – (LMIMaint)
SRV - [2009/12/18 20:47:28 | 000,604,488 | —- | M] (TuneUp Software) [Auto | Running] – C:\WINDOWS\system32\TUProgSt.exe – (TuneUp.ProgramStatisticsSvc)
SRV - [2009/12/18 20:47:25 | 000,361,288 | —- | M] (TuneUp Software) [On_Demand | Stopped] – C:\WINDOWS\system32\TuneUpDefragService.exe – (TuneUp.Defrag)
SRV - [2009/07/15 12:48:20 | 000,029,000 | —- | M] (TuneUp Software) [Auto | Running] – C:\WINDOWS\system32\uxtuneup.dll – (UxTuneUp)
SRV - [2009/01/02 16:02:45 | 000,654,848 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/12/08 23:01:54 | 002,440,120 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe – (Symantec AntiVirus)
SRV - [2008/12/08 22:42:32 | 001,795,400 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe – (SmcService)
SRV - [2008/12/08 22:01:28 | 000,320,840 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE – (SNAC)
SRV - [2008/08/14 15:45:28 | 000,108,392 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccSetMgr)
SRV - [2008/08/14 15:45:28 | 000,108,392 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccEvtMgr)
SRV - [2008/07/24 19:46:10 | 000,063,040 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files\LogMeIn\x86\LogMeIn.exe – (LogMeIn)
SRV - [2008/06/30 17:36:35 | 003,093,872 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE – (LiveUpdate)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\DRIVERS\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2010/07/13 04:00:00 | 001,362,608 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100914.052\NAVEX15.SYS – (NAVEX15)
DRV - [2010/07/13 04:00:00 | 000,085,424 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100914.052\NAVENG.SYS – (NAVENG)
DRV - [2010/06/09 09:14:04 | 000,083,360 | —- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] – C:\WINDOWS\System32\LMIRfsClientNP.dll – (LMIRfsClientNP)
DRV - [2010/06/02 19:59:06 | 000,161,920 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WpsHelper.sys – (WpsHelper)
DRV - [2010/05/27 04:00:00 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2010/05/27 04:00:00 | 000,102,448 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2009/01/01 17:50:53 | 000,123,952 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2008/12/08 22:45:28 | 000,092,488 | —- | M] (Symantec Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys – (SysPlant)
DRV - [2008/12/08 22:43:46 | 000,042,312 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\WPSDRVnt.sys – (WPS)
DRV - [2008/11/18 19:17:08 | 000,023,888 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\COH_Mon.sys – (COH_Mon)
DRV - [2008/10/14 12:24:18 | 000,049,536 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Teefer2.sys – (Teefer2)
DRV - [2008/10/13 13:31:46 | 000,319,664 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\srtspl.sys – (SRTSPL)
DRV - [2008/10/13 13:31:46 | 000,279,600 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\WINDOWS\system32\drivers\srtsp.sys – (SRTSP)
DRV - [2008/10/13 13:31:46 | 000,043,824 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\srtspx.sys – (SRTSPX)
DRV - [2008/08/21 12:13:56 | 000,191,536 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI)
DRV - [2008/08/21 12:13:56 | 000,027,696 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV)
DRV - [2008/07/24 19:46:12 | 000,012,856 | —- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] – C:\Program Files\LogMeIn\x86\rainfo.sys – (LMIInfo)
DRV - [2008/07/24 19:46:10 | 000,047,640 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV - [2008/06/16 17:53:14 | 000,420,400 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys – (SPBBCDrv)
DRV - [2007/12/04 18:10:30 | 000,016,640 | R— | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\PalmUSBD.sys – (PalmUSBD)
DRV - [2004/08/03 18:29:28 | 000,701,440 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2004/03/10 02:04:00 | 000,100,597 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\dla\tfsnudfa.sys – (tfsnudfa)
DRV - [2004/03/10 02:04:00 | 000,098,580 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\dla\tfsnudf.sys – (tfsnudf)
DRV - [2004/03/10 02:04:00 | 000,085,204 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\dla\tfsnifs.sys – (tfsnifs)
DRV - [2004/03/10 02:04:00 | 000,034,837 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\dla\tfsncofs.sys – (tfsncofs)
DRV - [2004/03/10 02:04:00 | 000,025,685 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\dla\tfsnboio.sys – (tfsnboio)
DRV - [2004/03/10 02:04:00 | 000,014,229 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\dla\tfsnopio.sys – (tfsnopio)
DRV - [2004/03/10 02:04:00 | 000,006,357 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\dla\tfsnpool.sys – (tfsnpool)
DRV - [2004/03/10 02:04:00 | 000,004,117 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\dla\tfsndrct.sys – (tfsndrct)
DRV - [2004/03/10 02:04:00 | 000,002,233 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\dla\tfsndres.sys – (tfsndres)
DRV - [2004/02/19 04:21:00 | 000,086,064 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\drvmcdb.sys – (drvmcdb)
DRV - [2003/11/13 12:47:40 | 000,005,621 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\sscdbhk5.sys – (sscdbhk5)
DRV - [2003/11/13 12:47:28 | 000,023,219 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\ssrtln.sys – (ssrtln)
DRV - [2003/11/13 03:56:00 | 000,040,448 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\drvnddm.sys – (drvnddm)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.maritadonohueteam.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://www.topproducer8i.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0


FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/03 08:49:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/18 12:59:48 | 000,000,000 | —D | M]

[2009/01/05 10:06:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\Mozilla\Extensions
[2010/09/10 11:12:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Marita\Application Data\Mozilla\Firefox\Profiles\jm98hrkh.default\extensions
[2009/09/15 13:50:21 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Marita\Application Data\Mozilla\Firefox\Profiles\jm98hrkh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/01/05 10:06:17 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/27 11:33:58 | 000,184,320 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npxsciter.dll

O1 HOSTS File: ([2009/01/03 01:16:07 | 000,290,793 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10016 more lines…
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll (TechSmith Corporation)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: realtytools.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: toolkitcma.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: toolkitcma2.com ([]http in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://www.thelistingwidget.com/includes/u…geUploader5.cab (Image Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1230856684750 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1230917110406 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} http://www.thelistingwidget.com/includes/u…geUploader6.cab (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} http://dev.publicrecords.trendmls.com/Reso…er/fileopen.cab (FoInstaller Class)
O16 - DPF: {F375116A-793C-11D2-BFE1-444553540001} http://realist2.firstamres.com/mapviewer/mapviewer.cab (First American Res MapActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.22.5.10 10.21.1.69 10.22.5.19
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\Marita\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Marita\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/01 13:17:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/09/14 12:33:21 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/09/13 09:39:41 | 000,000,000 | —D | C] – D:\My Documents\Referrals
[2010/09/13 09:19:16 | 000,000,000 | —D | C] – D:\My Documents\Marita's Personal Pics
[2010/09/12 16:21:06 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/09/12 16:09:08 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/09/08 02:45:03 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[1 D:\My Documents\*.tmp files -> D:\My Documents\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/15 17:40:07 | 000,000,488 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/09/15 17:39:14 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/15 17:39:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/15 17:38:07 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Marita\ntuser.ini
[2010/09/15 17:38:06 | 009,175,040 | -H– | M] () – C:\Documents and Settings\Marita\NTUSER.DAT
[2010/09/15 14:39:55 | 000,002,549 | —- | M] () – C:\Documents and Settings\Marita\.powerupdate.user.properties
[2010/09/15 12:53:17 | 000,000,181 | —- | M] () – C:\WINDOWS\hpbafd.ini
[2010/09/15 10:06:25 | 000,047,616 | —- | M] () – D:\My Documents\Filing Spine.pub
[2010/09/14 13:35:51 | 000,293,376 | —- | M] () – C:\Documents and Settings\Marita\Desktop\r4dlyom6.exe
[2010/09/13 16:53:50 | 000,002,449 | —- | M] () – C:\Documents and Settings\Marita\Desktop\HiJackThis.lnk
[2010/09/12 16:10:06 | 000,000,709 | —- | M] () – C:\WINDOWS\win.ini
[2010/09/12 16:10:06 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/09/12 16:10:06 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/09/12 15:32:48 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/03 09:42:16 | 000,022,016 | —- | M] () – D:\My Documents\Envelope.doc
[2010/09/03 09:32:44 | 000,124,928 | —- | M] () – D:\My Documents\ANNIVERSARIE1.doc
[2010/09/02 10:24:42 | 000,000,256 | —- | M] () – C:\WINDOWS\System32\pool.bin
[2010/09/01 12:45:09 | 000,526,384 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/01 12:45:09 | 000,446,932 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/01 12:45:09 | 000,072,748 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/31 10:52:02 | 000,002,443 | —- | M] () – C:\Documents and Settings\Marita\Desktop\Microsoft Office Publisher 2003.lnk
[2010/08/26 10:11:14 | 010,340,864 | —- | M] () – D:\My Documents\Inquirer Article Aug 25.pub
[2010/08/26 10:00:07 | 000,005,632 | —- | M] () – C:\Documents and Settings\Marita\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/26 09:59:28 | 000,798,701 | —- | M] () – D:\My Documents\Inquirer article Aug 25.jpg
[2010/08/24 08:53:02 | 000,021,504 | —- | M] () – D:\My Documents\Closings.doc
[1 D:\My Documents\*.tmp files -> D:\My Documents\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/14 13:35:42 | 000,293,376 | —- | C] () – C:\Documents and Settings\Marita\Desktop\r4dlyom6.exe
[2010/09/12 16:21:07 | 000,002,449 | —- | C] () – C:\Documents and Settings\Marita\Desktop\HiJackThis.lnk
[2010/08/26 10:11:12 | 010,340,864 | —- | C] () – D:\My Documents\Inquirer Article Aug 25.pub
[2010/08/26 09:56:43 | 000,798,701 | —- | C] () – D:\My Documents\Inquirer article Aug 25.jpg
[2010/03/25 11:21:39 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2009/11/07 21:02:17 | 000,027,294 | —- | C] () – C:\Documents and Settings\Marita\Application Data\Comma Separated Values (Windows).ADR
[2009/10/07 10:59:04 | 000,005,632 | —- | C] () – C:\Documents and Settings\Marita\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2009/08/03 10:08:43 | 000,000,000 | —- | C] () – C:\WINDOWS\webica.ini
[2009/06/18 11:33:33 | 000,000,094 | —- | C] () – C:\WINDOWS\family.ini
[2009/01/27 13:13:26 | 000,000,129 | —- | C] () – C:\Documents and Settings\Marita\Local Settings\Application Data\fusioncache.dat
[2009/01/04 12:03:51 | 000,000,181 | —- | C] () – C:\WINDOWS\hpbafd.ini
[2009/01/02 23:20:16 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2009/01/02 09:53:14 | 000,000,000 | —- | C] () – C:\WINDOWS\oodcnt.INI
[2009/01/01 23:28:21 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/01/01 19:16:55 | 000,000,092 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2009/01/01 19:16:54 | 000,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2009/01/01 19:16:51 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[2009/01/01 19:16:50 | 000,028,672 | —- | C] () – C:\WINDOWS\CMIRmDriver.dll
[2009/01/01 18:21:04 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/09/06 00:30:42 | 000,190,976 | —- | C] () – C:\WINDOWS\System32\WgaLogon.dll
[2008/03/20 19:06:36 | 001,481,728 | —- | C] () – C:\WINDOWS\System32\LegitCheckControl.dll
[2006/10/27 09:26:56 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2004/04/09 04:15:50 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
< End of report >


Also gave me extras

OTL Extras logfile created on: 9/15/2010 5:43:00 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = D:\HaveDisk
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 570.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.61 Gb Total Space | 3.59 Gb Free Space | 19.29% Space Free | Partition Type: NTFS
Drive D: | 18.65 Gb Total Space | 5.64 Gb Free Space | 30.24% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DONOHUE
Current User Name: Marita
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"4899:TCP" = 4899:TCP:*:Enabled:tcp4899

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe" = C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:*:Enabled:SMC Service – (Symantec Corporation)
"C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE" = C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:*:Enabled:SNAC Service – (Symantec Corporation)
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email – (Symantec Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3BAB4914-9CC1-4CC2-A3DA-56EF62DFD373}" = Symantec Endpoint Protection
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}" = Apple Mobile Device Support
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{58E6A969-8215-4ABC-BD73-FCB25EA6F544}" = FormViewer
"{59991D18-A988-45AB-B1BF-5ADE6E64CD3F}" = SnagIt 9
"{5D95AD35-368F-47D5-B63A-A082DDF00119}" = Microsoft Digital Image Suite 2006 Editor
"{691F4068-81BF-49E3-B32E-FE3E16400119}" = Microsoft Digital Image Suite 2006 Library
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7F831576-6246-42C7-B523-55B3F96509CC}" = LogMeIn
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow! Deluxe
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B28759B8-5FC6-4F56-9C6C-6EDAD36455A9}" = Roxio Media Manager
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE5E3F15-320A-4865-97D3-F07227C5BB2F}" = BlackBerry Desktop Software 4.5
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"AgentMetrics" = AgentMetrics
"BlackBerry_{CE5E3F15-320A-4865-97D3-F07227C5BB2F}" = BlackBerry Desktop Software 4.5
"Camtasia Studio 3" = Camtasia Studio 3
"C-Media Audio" = C-Media 3D Audio
"C-Media Audio Driver" = C-Media WDM Audio Driver
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"doPDF 6 printer_is1" = doPDF 6.1 printer
"Hard Disk Sentinel_is1" = Hard Disk Sentinel PRO
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{58E6A969-8215-4ABC-BD73-FCB25EA6F544}" = FormViewer
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Ahead Nero 6 Demo
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PictureItSuite_v11" = Microsoft Digital Image Suite 2006
"Resize Pictures Plus_is1" = Resize Pictures Plus 2.1
"Simplify Printing Client v3" = Simplify Printing Client v3
"Top Producer Editor_is1" = Top Producer Editor
"ViewpointMediaPlayer" = Viewpoint Media Player
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xerox_Support_Centre" = Xerox Support Centre

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"GoToMeeting" = GoToMeeting 4.0.0.320
"ToolkitCMA" = ToolkitCMA

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/15/2010 10:55:52 AM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/15/2010 11:26:53 AM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/15/2010 12:26:22 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/15/2010 1:07:02 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/15/2010 1:55:53 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/15/2010 2:09:41 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/15/2010 3:08:52 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/15/2010 4:08:48 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/15/2010 5:08:48 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 9/15/2010 5:27:42 PM | Computer Name = DONOHUE | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

[ System Events ]
Error - 9/15/2010 1:46:28 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 1000000a, parameter1 ffff5df1, parameter2 00000006, parameter3
00000001, parameter4 804d9122.

Error - 9/15/2010 1:59:18 PM | Computer Name = DONOHUE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher
9 service to connect.

Error - 9/15/2010 2:00:55 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 00000000, parameter2 00000007, parameter3
00000000, parameter4 00000000.

Error - 9/15/2010 2:00:57 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 1000000a, parameter1 ffff5df1, parameter2 00000006, parameter3
00000001, parameter4 804d9122.

Error - 9/15/2010 2:00:59 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 1000007f, parameter1 00000008, parameter2 80042000, parameter3
00000000, parameter4 00000000.

Error - 9/15/2010 5:17:33 PM | Computer Name = DONOHUE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher
9 service to connect.

Error - 9/15/2010 5:30:42 PM | Computer Name = DONOHUE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher
9 service to connect.

Error - 9/15/2010 5:31:50 PM | Computer Name = DONOHUE | Source = Print | ID = 54
Description = Document JasperReports - MedianPrice was corrupted and has been deleted.
The associated driver is: Xerox Phaser 8560DN PS.

Error - 9/15/2010 5:33:27 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 00000000, parameter2 00000007, parameter3
00000000, parameter4 00000000.

Error - 9/15/2010 5:35:38 PM | Computer Name = DONOHUE | Source = System Error | ID = 1003
Description = Error code 1000000a, parameter1 ffff5df1, parameter2 00000006, parameter3
00000001, parameter4 804d9122.

[ TuneUp Events ]
Error - 9/11/2010 6:53:40 PM | Computer Name = DONOHUE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-09-11 18:53:40', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2768',0)


< End of report >

Looking in the minidump I see
0x000000D1 (0xE8458BF3,0x00000005,0x00000000,0xF7777D1C)

FÐ;Eü}
‹Eü¯Eøt0ÐëEƒ}üuVVèÓi …
*** atapi.sys - Address F7777D1C base at F7772000, DateStamp 4802539d

the "atapi.sys" is the Parrellel driver isn't it?

which seems to indicate driver for the reboot problem. No drivers have been updated on this machine. There are 3 hardware driver updates available per Windows update.
AG Neovo (LCD Monitor)
VIA Tech Ethernet
Xerox Phaser 8560DN PS

I dont these would be a problem. Have not installed. Just checking things out.
Thanks for your help
Hi NlightN,

The OTL fix log can be found at C:\_OTL\MovedFiles It will have a file name consisting of numbers that reflect the date and time stamp the fix was ran. It will be something similar to 14092010_111009.log . Please copy and paste the contents into your next reply.

Atapi.sys is a disk controller.

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.


NEXT


Please download Rootkit Unhooker and save it on your desktop.
  • Disable your security programs
  • Double click RKUnhookerLE.exe to run it
  • Click the Report tab, then click Scan
  • Check Drivers and Stealth Code,
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • Copy the entire contents of the report and paste it in your next reply.
Note - You may get this warning, it is ok, just ignore it:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"



Next

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the None button near the top.
  • In the window under Custom Scans/Fixes copy and paste the following


    atapi.sys /md5

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window. OTL.Txt. It will be short this time.



Please post back with
  • OTL fix log
  • MBRCheck log
  • RKUnhooker log
  • OTL.txt
  • Make and model of your computer
Any other symptoms such as redirects, random audio, etc?

Thanks
Machine is running very very slow

========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:OODBS deleted successfully.
========== COMMANDS ==========

OTL by OldTimer - Version 3.2.12.0 log created on 09152010_173738


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0040000d

Kernel Drivers (total 144):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EE000 \WINDOWS\system32\hal.dll
0xF7D2F000 \WINDOWS\system32\KDCOM.DLL
0xF7C3F000 \WINDOWS\system32\BOOTVID.dll
0xF77E0000 ACPI.sys
0xF7D31000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF77CF000 pci.sys
0xF782F000 isapnp.sys
0xF7D33000 viaide.sys
0xF7AAF000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF783F000 MountMgr.sys
0xF77B0000 ftdisk.sys
0xF7D35000 dmload.sys
0xF778A000 dmio.sys
0xF7AB7000 PartMgr.sys
0xF784F000 VolSnap.sys
0xF7772000 atapi.sys
0xF785F000 viamraid.sys
0xF775A000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF786F000 disk.sys
0xF787F000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF773A000 fltmgr.sys
0xF7728000 sr.sys
0xF7713000 drvmcdb.sys
0xF788F000 PxHelp20.sys
0xF76FC000 KSecDD.sys
0xF766F000 Ntfs.sys
0xF7642000 NDIS.sys
0xF789F000 uagp35.sys
0xF7628000 Mup.sys
0xF7A7F000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF7519000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
0xF7505000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF7A8F000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF7D7B000 \SystemRoot\system32\drivers\sscdbhk5.sys
0xF7A9F000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF78CF000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF74E2000 \SystemRoot\system32\DRIVERS\ks.sys
0xF7D0F000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xF7B5F000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF74BE000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF7B67000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF7B6F000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF74AA000 \SystemRoot\system32\DRIVERS\parport.sys
0xF78DF000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF7B77000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF7B7F000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF78EF000 \SystemRoot\system32\DRIVERS\serial.sys
0xF7D1B000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF735C000 \SystemRoot\system32\drivers\cmuda.sys
0xF7338000 \SystemRoot\system32\drivers\portcls.sys
0xF78FF000 \SystemRoot\system32\drivers\drmk.sys
0xF790F000 \SystemRoot\system32\DRIVERS\fetnd5bv.sys
0xF7F74000 \SystemRoot\system32\DRIVERS\lmimirr.sys
0xF7F77000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF7D7D000 \SystemRoot\System32\Drivers\RootMdm.sys
0xF7B87000 \SystemRoot\System32\Drivers\Modem.SYS
0xF791F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF7D27000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF7321000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF792F000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF793F000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF7B8F000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF70E6000 \SystemRoot\system32\DRIVERS\psched.sys
0xF794F000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7B97000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF7B9F000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF7BA7000 \SystemRoot\system32\DRIVERS\RimSerial.sys
0xF6776000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF799F000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF6718000 \SystemRoot\system32\DRIVERS\teefer2.sys
0xF7D7F000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF66BA000 \SystemRoot\system32\DRIVERS\update.sys
0xF75E8000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF79AF000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF7A2F000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7D81000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF7BB7000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xEE548000 \SystemRoot\System32\Drivers\SRTSP.SYS
0xEE3FC000 \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100915.039\NAVEX15.SYS
0xEE3D7000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
0xEE3C3000 \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100915.039\NAVENG.SYS
0xF72A1000 \SystemRoot\System32\Drivers\SRTSPX.SYS
0xF7D8D000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7ECE000 \SystemRoot\System32\Drivers\Null.SYS
0xF7D97000 \SystemRoot\System32\Drivers\Beep.SYS
0xF7BDF000 \SystemRoot\system32\drivers\ssrtln.sys
0xF7BE7000 \SystemRoot\System32\drivers\vga.sys
0xF7D9B000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7D9D000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF7BEF000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF7BFF000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF676A000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xEE390000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xEE337000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF7A4F000 \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys
0xF797F000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xEE309000 \SystemRoot\System32\Drivers\SYMTDI.SYS
0xEE2E1000 \SystemRoot\system32\DRIVERS\netbt.sys
0xEE2BF000 \SystemRoot\System32\drivers\afd.sys
0xF72C1000 \SystemRoot\system32\DRIVERS\netbios.sys
0xEE256000 \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
0xEE22B000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xEE1BB000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF2652000 \SystemRoot\System32\Drivers\Fips.SYS
0xEE135000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0xEE118000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
0xF72F1000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xEE100000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7DDF000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xF7D23000 \SystemRoot\System32\drivers\Dxapi.sys
0xF7AE7000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7EA5000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF048000 \SystemRoot\System32\ati2cqag.dll
0xBF080000 \SystemRoot\System32\ati3d1ag.dll
0xF72D1000 \SystemRoot\system32\drivers\drvnddm.sys
0xF7E96000 \SystemRoot\system32\dla\tfsndres.sys
0xEDFAB000 \SystemRoot\system32\dla\tfsnifs.sys
0xF66B2000 \SystemRoot\system32\dla\tfsnopio.sys
0xF7D51000 \SystemRoot\system32\dla\tfsnpool.sys
0xF7B17000 \SystemRoot\system32\dla\tfsnboio.sys
0xF7A3F000 \SystemRoot\system32\dla\tfsncofs.sys
0xF7F3B000 \SystemRoot\system32\dla\tfsndrct.sys
0xEDEF2000 \SystemRoot\system32\dla\tfsnudf.sys
0xEDED9000 \SystemRoot\system32\dla\tfsnudfa.sys
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xEDEB9000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xEDA15000 \SystemRoot\system32\drivers\wdmaud.sys
0xEDBD9000 \SystemRoot\system32\drivers\sysaudio.sys
0xED82A000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF7D43000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xF7D77000 \??\C:\Program Files\LogMeIn\x86\RaInfo.sys
0xED66C000 \SystemRoot\system32\DRIVERS\srv.sys
0xF7AF7000 \SystemRoot\System32\Drivers\SYMREDRV.SYS
0xED5E4000 \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
0xECFC3000 \SystemRoot\System32\Drivers\HTTP.sys
0xED1E4000 \??\C:\WINDOWS\system32\Drivers\COH_Mon.sys
0xBF155000 \SystemRoot\System32\lmimirr.dll
0xBF15A000 \SystemRoot\System32\lmimirr2.dll
0xECAE9000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 40):
0 System Idle Process
4 System
924 C:\WINDOWS\system32\smss.exe
1620 csrss.exe
1980 C:\WINDOWS\system32\winlogon.exe
184 C:\WINDOWS\system32\services.exe
208 C:\WINDOWS\system32\lsass.exe
692 C:\WINDOWS\system32\svchost.exe
800 svchost.exe
988 C:\WINDOWS\system32\svchost.exe
1208 C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
1372 svchost.exe
1552 svchost.exe
1804 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
940 C:\WINDOWS\system32\spoolsv.exe
568 C:\WINDOWS\explorer.exe
1352 svchost.exe
1560 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
1584 C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
300 C:\Program Files\Messenger\msmsgs.exe
588 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
608 C:\Program Files\LogMeIn\x86\LMIGuardian.exe
1228 C:\Program Files\Bonjour\mDNSResponder.exe
1516 C:\Program Files\Java\jre6\bin\jqs.exe
552 C:\Program Files\LogMeIn\x86\ramaint.exe
1608 C:\Program Files\LogMeIn\x86\LogMeIn.exe
1680 C:\Program Files\LogMeIn\x86\LMIGuardian.exe
1360 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
2508 C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
2684 C:\WINDOWS\system32\svchost.exe
2776 C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
2800 C:\WINDOWS\system32\TUProgSt.exe
3604 C:\WINDOWS\system32\wuauclt.exe
2680 C:\Program Files\LogMeIn\x86\LogMeIn.exe
3816 C:\Program Files\LogMeIn\x86\LMIGuardian.exe
2760 C:\Program Files\Internet Explorer\iexplore.exe
3296 C:\WINDOWS\system32\notepad.exe
3628 C:\WINDOWS\system32\notepad.exe
304 C:\WINDOWS\system32\wscntfy.exe
3676 C:\Documents and Settings\Marita\Desktop\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: –> \\.\PhysicalDrive0 at offset 0x00000004`a7587a00 (NTFS)

PhysicalDrive0 Model Number: WDCWD400JB-00ENA0, Rev: 05.03E05

Size Device Name MBR Status
——————————————–
37 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Done!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows XP
Version 5.1.2600 (Service Pack 3)
Number of processors #1
==============================================
>Drivers
==============================================
0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2189952 bytes (Microsoft Corporation, NT Kernel & System)
0x804D7000 PnpManager 2189952 bytes
0x804D7000 RAW 2189952 bytes
0x804D7000 WMIxWDM 2189952 bytes
0xBF800000 Win32k 1855488 bytes
0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0xF735C000 C:\WINDOWS\system32\drivers\cmuda.sys 1368064 bytes (C-Media Inc, C-Media Audio WDM Driver)
0xEE3FC000 C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100915.039\NAVEX15.SYS 1359872 bytes (Symantec Corporation, AV Engine)
0xBF080000 C:\WINDOWS\System32\ati3d1ag.dll 872448 bytes (ATI Technologies Inc. , ati3d1ag.dll)
0xF7519000 C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 815104 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver)
0xF766F000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)
0xEE1BB000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0xEE256000 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 430080 bytes (Symantec Corporation, SPBBC Driver)
0xEE135000 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 385024 bytes (Symantec Corporation, Symantec Eraser Control Driver)
0xF66BA000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver)
0xEE337000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver)
0xED66C000 C:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver)
0xEE548000 C:\WINDOWS\System32\Drivers\SRTSP.SYS 303104 bytes (Symantec Corporation, Symantec AutoProtect)
0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0xECFC3000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)
0xBF048000 C:\WINDOWS\System32\ati2cqag.dll 229376 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module)
0xBF012000 C:\WINDOWS\System32\ati2dvag.dll 221184 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver)
0xF6718000 C:\WINDOWS\system32\DRIVERS\teefer2.sys 221184 bytes (Symantec Corporation, Symantec CMC Firewall Teefer2)
0xF6776000 C:\WINDOWS\system32\DRIVERS\rdpdr.sys 196608 bytes (Microsoft Corporation, Microsoft RDP Device redirector)
0xF77E0000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)
0xEE309000 C:\WINDOWS\System32\Drivers\SYMTDI.SYS 188416 bytes (Symantec Corporation, Network Dispatch Driver)
0xED82A000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0xF7642000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)
0xECAE9000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)
0xEE22B000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0xEE2E1000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)
0xF778A000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver)
0xEE3D7000 C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 151552 bytes (Symantec Corporation, Symantec Event Library)
0xF7338000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0xF74BE000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0xF74E2000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)
0xEE2BF000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x806EE000 ACPI_HAL 131840 bytes
0x806EE000 C:\WINDOWS\system32\hal.dll 131840 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0xF773A000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0xF77B0000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)
0xEE118000 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 118784 bytes (Symantec Corporation, Symantec Eraser Utility Driver)
0xF7628000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0xEDEF2000 C:\WINDOWS\system32\dla\tfsnudf.sys 102400 bytes (Sonic Solutions, Drive Letter Access Component)
0xEDED9000 C:\WINDOWS\system32\dla\tfsnudfa.sys 102400 bytes (Sonic Solutions, Drive Letter Access Component)
0xF7772000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)
0xEE100000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes
0xF775A000 C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver)
0xF76FC000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0xF7321000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0xF7713000 drvmcdb.sys 86016 bytes (Sonic Solutions, Device Driver)
0xEDFAB000 C:\WINDOWS\system32\dla\tfsnifs.sys 86016 bytes (Sonic Solutions, Drive Letter Access Component)
0xEDA15000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)
0xEE3C3000 C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100915.039\NAVENG.SYS 81920 bytes (Symantec Corporation, AV Engine)
0xF74AA000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver)
0xF7505000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)
0xEE390000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)
0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)
0xF7728000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)
0xF77CF000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0xF70E6000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)
0xF72F1000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)
0xF7A9F000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xF78EF000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver)
0xF78FF000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0xF78CF000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver)
0xEDBD9000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)
0xF7A2F000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)
0xF785F000 viamraid.sys 61440 bytes (VIA Technologies inc,.ltd, VIA RAID DRIVER FOR WIN 2000/XP/2003IA32)
0xF7A4F000 C:\WINDOWS\system32\drivers\wpsdrvnt.sys 57344 bytes (Symantec Corporation, Symantec CMC Firewall WPS)
0xF787F000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)
0xF78DF000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver)
0xF791F000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xF784F000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0xF793F000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0xF790F000 C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys 45056 bytes (VIA Technologies, Inc. , NDIS 5.0 miniport driver)
0xF2652000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver)
0xF7A8F000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)
0xF783F000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)
0xF792F000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0xF789F000 uagp35.sys 45056 bytes (Microsoft Corporation, MS AGPv3.5 Filter)
0xF72D1000 C:\WINDOWS\system32\drivers\drvnddm.sys 40960 bytes (Sonic Solutions, Device Driver Manager)
0xF782F000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver)
0xED5E4000 C:\WINDOWS\system32\drivers\LMIRfsDriver.sys 40960 bytes (LogMeIn, Inc., LogMeIn Rfs Drivemap Driver)
0xF79AF000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)
0xF72A1000 C:\WINDOWS\System32\Drivers\SRTSPX.SYS 40960 bytes (Symantec Corporation, Symantec AutoProtect)
0xF799F000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)
0xED1E4000 C:\WINDOWS\system32\Drivers\COH_Mon.sys 36864 bytes (Symantec Corporation, Confidence Online v6.1 WDM driver (6,1,4,10))
0xF786F000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)
0xF7A7F000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver)
0xF794F000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)
0xF72C1000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)
0xECB64000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0xF788F000 PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0xF7A3F000 C:\WINDOWS\system32\dla\tfsncofs.sys 36864 bytes (Sonic Solutions, Drive Letter Access Component)
0xF797F000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0xF7B87000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver)
0xF7BFF000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)
0xF7B67000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0xF7B6F000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver)
0xF7AAF000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0xF7BA7000 C:\WINDOWS\system32\DRIVERS\RimSerial.sys 28672 bytes (Research in Motion Ltd, RIM Virtual Serial Driver)
0xF7B17000 C:\WINDOWS\system32\dla\tfsnboio.sys 28672 bytes (Sonic Solutions, Drive Letter Access Component)
0xF7B77000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)
0xF7B7F000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)
0xF7BDF000 C:\WINDOWS\system32\drivers\ssrtln.sys 24576 bytes (Sonic Solutions, Shared Driver Component)
0xF7AF7000 C:\WINDOWS\System32\Drivers\SYMREDRV.SYS 24576 bytes (Symantec Corporation, Redirector Filter Driver)
0xF7B5F000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0xF7BE7000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0xF7BB7000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver)
0xBF155000 C:\WINDOWS\System32\lmimirr.dll 20480 bytes (LogMeIn, Inc., LogMeIn Mirror Driver)
0xF7BEF000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)
0xF7AB7000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)
0xF7B97000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)
0xF7B9F000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)
0xF7B8F000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)
0xF7AE7000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)
0xF75E8000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)
0xEDEB9000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)
0xF7D1B000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator)
0xF66B2000 C:\WINDOWS\system32\dla\tfsnopio.sys 16384 bytes (Sonic Solutions, Drive Letter Access Component)
0xF7C3F000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)
0xF7D23000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)
0xF7D0F000 C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys 12288 bytes (GEAR Software Inc., CD DVD Filter)
0xF7D27000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0xF676A000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0xF7D97000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)
0xF7D35000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver)
0xF7DDF000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes
0xF7D8D000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)
0xF7D2F000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0xBF15A000 C:\WINDOWS\System32\lmimirr2.dll 8192 bytes (LogMeIn, Inc., LogMeIn Video Helper)
0xF7D9B000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)
0xF7D43000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver)
0xF7D77000 C:\Program Files\LogMeIn\x86\RaInfo.sys 8192 bytes (LogMeIn, Inc., RemotelyAnywhere Kernel Information Provider)
0xF7D9D000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)
0xF7D7D000 C:\WINDOWS\System32\Drivers\RootMdm.sys 8192 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver)
0xF7D7B000 C:\WINDOWS\system32\drivers\sscdbhk5.sys 8192 bytes (Sonic Solutions, Shared Driver Component)
0xF7D7F000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0xF7D51000 C:\WINDOWS\system32\dla\tfsnpool.sys 8192 bytes (Sonic Solutions, Drive Letter Access Component)
0xF7D81000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0xF7D33000 viaide.sys 8192 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
0xF7D31000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0xF7F77000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)
0xF7EA5000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)
0xF7F74000 C:\WINDOWS\system32\DRIVERS\lmimirr.sys 4096 bytes (LogMeIn, Inc., LogMeIn Mirror Miniport Driver)
0xF7ECE000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)
0xF7F3B000 C:\WINDOWS\system32\dla\tfsndrct.sys 4096 bytes (Sonic Solutions, Drive Letter Access Component)
0xF7E96000 C:\WINDOWS\system32\dla\tfsndres.sys 4096 bytes (Sonic Solutions, Drive Letter Access Component)
==============================================
>Stealth
==============================================


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

OTL logfile created on: 9/16/2010 2:47:35 PM - Run 2
OTL by OldTimer - Version 3.2.12.0 Folder = D:\HaveDisk
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 483.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.61 Gb Total Space | 3.12 Gb Free Space | 16.74% Space Free | Partition Type: NTFS
Drive D: | 18.65 Gb Total Space | 5.63 Gb Free Space | 30.17% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive W: | 82.93 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DONOHUE
Current User Name: Marita
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Custom Scans ==========


< atapi.sys /md5 >
< End of report >


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Machine is a black box
ASUS P4V8X-MX
2.26 GHz intel CPU
1GB Ram (2x512)
Radeon 7000 AGP card 32MB?
40GB HD


Thanks for your help
Hi Nlightn,


The cutom scan failed to show any instance of atpi.sys. Let's try it this way.

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the None button near the top.
  • In the window under Custom Scans/Fixes copy and paste the following

    /md5start
    atapi.sys
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window. OTL.Txt.
Now I cant get past BSOD in normal or safe mode. log does not indicate file these latest times. 0x0000000A (0x000001F7, 0x00000005, 0x00000001, ox806D68BB) next BSOD 0x000000D1 (0x67E4D794, 0x0000001B, 0x00000000, 0x67E4D794) in safe mode it shows 0x000000000 all across Goofy computers. I was thinking that perhaps it would be best to the fresh install, but now I'm thinking there is a hardware problem. memtest86 shows memory good. Ran for about 8hrs. I cant even get to run the above OTL code. Any ideas, questions, concerns, or requests, letshear them. I'm stumped on this one. THX for all your guidance oldman960
Hi Nlightn,

It does seem like a hardware or driver issue.

0x0000000A (0x000001F7, 0x00000005, 0x00000001, ox806D68BB) usually will include a file name at the end. Strange

in safe mode it shows 0x000000000 all across

This includes the first set of numbers?

Have you installed any new hardware recently?

Do you have an XP CD?
Yes in safe mode it is all 0x000000000 Which I've never seen ever. I do have a XP disk and gonna ply with this a bit more for education. Swapping the machine out Tuesday with another. Gotta keep the girls happy and productive. The MBoard here is not that old. I'm wondering if its a bad CPU. My diagnostics card shows all is good Power supply shows all good. Today, had to reset CMOS to boot. Any ideas is appreciated. THX for the input N

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI