This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HTTP Fragus Toolkit Request 1

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello WTT
High,An intrusion attempt by BJM-PC was blocked.,Blocked,No Action Required,HTTP Fragus Toolkit Request 1,"BJM-PC (192.168.2.2, 50496)",strgdfdsg.co.cc/ar/show.php?key=9b562fa34ce9c8505cbeab290c0c9f46&u=kavabanga,"195.189.226.193, 80",192.168.2.2 (192.168.2.2),"TCP, Port 50496",

OTL
OTL logfile created on: 12/8/2010 9:55:52 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\BJMS\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 64.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.54 Gb Total Space | 83.29 Gb Free Space | 60.55% Space Free | Partition Type: NTFS
Drive D: | 11.51 Gb Total Space | 2.03 Gb Free Space | 17.60% Space Free | Partition Type: NTFS

Computer Name: BJM-PC | User Name: BJMS | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\BJMS\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
PRC - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\BJMS\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\asOEHook.dll (Symantec Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c
2\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c
2\msvcp90.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) – C:\WINDOWS\System32\FntCache.dll (Microsoft Corporation)
SRV - (SgtSch2Svc) – C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Seagate)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Symantec RemoteAssist) – C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Com4Qlb) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)


========== Driver Services (SafeList) ==========

DRV - (SymIMMP) – C:\Windows\System32\DRIVERS\SymIM.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101123.003\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101208.001\IDSvix86.sys (Symantec Corporation)
DRV - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101208.002\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101208.002\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\NIS\1201000.025\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\NIS\1201000.025\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\NIS\1201000.025\SRTSPX.SYS (Symantec Corporation)
DRV - (SymIM) – C:\WINDOWS\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\system32\drivers\NIS\1201000.025\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\NIS\1201000.025\Ironx86.SYS (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\NIS\1201000.025\SYMDS.SYS (Symantec Corporation)
DRV - (PSI) – C:\WINDOWS\System32\drivers\psi_mf.sys (Secunia)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (tdrpman174) Acronis Try&Decide and Restore Points filter (build 174) – C:\Windows\system32\DRIVERS\tdrpm174.sys (Acronis)
DRV - (timounter) – C:\Windows\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\System32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman380) Acronis Snapshots Manager (Build 380) – C:\Windows\system32\DRIVERS\snman380.sys (Acronis)
DRV - (RTSTOR) – C:\WINDOWS\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (iaStor) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (RTL8023xp) – C:\WINDOWS\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (CnxtHdAudService) – C:\WINDOWS\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (igfx) – C:\WINDOWS\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (tapvpn) – C:\WINDOWS\System32\drivers\tapvpn.sys (The OpenVPN Project)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) – C:\WINDOWS\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (rcmirror) – C:\WINDOWS\System32\drivers\rcmirror.sys (Windows ® Codename Longhorn DDK provider)
DRV - (HSF_DPV) – C:\WINDOWS\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\WINDOWS\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvm60x32.sys (NVIDIA Corporation)
DRV - (BCM43XV) – C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (speedfan) – C:\Windows\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (HBtnKey) – C:\WINDOWS\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (giveio) – C:\Windows\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://news.yahoo.com/page/sitemap
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Norton Safe Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://refdesk.com/"
FF - prefs.js..extensions.enabledItems: [removed]:0.78.2
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.7
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {c33c5b47-69c8-45a4-a5e0-af85bbe628dd}:[removed]
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.48.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:5.1
FF - prefs.js..extensions.enabledItems: {6614d11d-d21d-b211-ae23-815234e1ebb5}:1.0.21

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2010/10/02 11:54:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2010/10/02 11:50:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/28 00:29:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 00:29:42 | 000,000,000 | —D | M]

[2009/12/14 14:42:33 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Mozilla\Extensions
[2009/12/14 14:42:33 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/12/04 16:21:31 | 000,000,000 | R–D | M] – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions
[2010/04/26 16:52:21 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/25 15:25:58 | 000,000,000 | —D | M] (Dr.Web anti-virus link checker) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}
[2010/11/25 22:45:17 | 000,000,000 | —D | M] (NoScript) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/09/09 13:23:27 | 000,000,000 | —D | M] (WOT) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/01/14 10:41:22 | 000,000,000 | —D | M] (Interclue) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}
[2010/11/03 18:31:04 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/07/30 10:46:27 | 000,000,000 | —D | M] (No name found) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010/11/18 17:16:30 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\[removed]
[2009/01/10 13:36:37 | 000,001,908 | —- | M] () – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\searchplugins\aboutcom.xml
[2010/11/27 14:48:28 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/10/13 11:23:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 03:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/04/04 09:33:45 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

O1 HOSTS File: ([2010/06/09 21:57:32 | 000,000,027 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: secunia.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: secunia.com ([]https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\CompaqTrace.jpg
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\CompaqTrace.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/22 10:35:03 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 09:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{f1449dbe-e81b-11de-b75e-001b38f93826}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/12/08 09:46:27 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\BJMS\Desktop\HiJackThis.exe
[2010/12/08 09:46:01 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\BJMS\Desktop\OTL.exe
[2010/11/28 14:00:58 | 001,746,864 | —- | C] (Codejock Software) – C:\Windows\System32\Codejock.CommandBars.Unicode.v11.2.0.ocx
[2010/11/28 14:00:58 | 000,665,600 | —- | C] (Alientools Software) – C:\Windows\System32\pdfgenx.ocx
[2010/11/28 14:00:58 | 000,518,064 | —- | C] (Codejock Software) – C:\Windows\System32\Codejock.SkinFramework.Unicode.v11.2.0.ocx
[2010/11/28 14:00:58 | 000,000,000 | —D | C] – C:\Program Files\PDFArea
[2010/11/26 10:25:33 | 000,107,368 | R— | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/11/26 10:24:58 | 000,000,000 | —D | C] – C:\Program Files\Norton Bootable Recovery Tool Wizard
[2010/11/26 10:24:58 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\NBRTWizard
[2010/11/26 10:24:58 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\NBRTWizard\0301000.00B
[2010/11/17 13:42:14 | 000,000,000 | —D | C] – C:\Users\BJMS\My Documents\Global Health
[2010/11/15 17:11:31 | 000,000,000 | —D | C] – C:\Users\BJMS\My Documents\APWU
[2010/11/09 15:56:33 | 000,000,000 | —D | C] – C:\Users\BJMS\My Documents\GEHA

========== Files - Modified Within 30 Days ==========

[2010/12/08 09:47:31 | 000,359,929 | —- | M] () – C:\Users\BJMS\Desktop\dds.scr
[2010/12/08 09:46:28 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\BJMS\Desktop\HiJackThis.exe
[2010/12/08 09:46:01 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\BJMS\Desktop\OTL.exe
[2010/12/08 09:02:44 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/07 17:22:05 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/07 17:22:05 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/06 10:53:32 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/06 10:53:32 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/06 10:48:21 | 3210,756,096 | -HS- | M] () – C:\hiberfil.sys
[2010/12/05 10:00:07 | 000,000,356 | —- | M] () – C:\Windows\tasks\GlaryUpdate.job
[2010/12/03 21:37:34 | 000,006,794 | —- | M] () – C:\Windows\Sandboxie.ini
[2010/11/30 16:07:20 | 000,016,968 | —- | M] () – C:\Windows\System32\drivers\hitmanpro35.sys
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/27 18:10:59 | 000,000,036 | —- | M] () – C:\Users\BJMS\AppData\Local\housecall.guid.cache
[2010/11/27 14:35:12 | 000,001,854 | —- | M] () – C:\Users\BJMS\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2010/11/27 14:15:41 | 000,000,797 | —- | M] () – C:\Users\BJMS\Desktop\Glary Utilities.lnk
[2010/11/25 13:59:32 | 000,000,804 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/11/17 10:10:44 | 000,001,047 | —- | M] () – C:\Users\BJMS\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2010/11/14 14:41:25 | 001,368,511 | R— | M] () – C:\Users\BJMS\My Documents\Aetna Health Fund OK.PDF
[2010/11/13 16:08:51 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/11/13 16:08:51 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/12 14:05:21 | 000,086,076 | R— | M] () – C:\Users\BJMS\My Documents\BofI Fees Terms Effect 12102010.pdf

========== Files Created - No Company Name ==========

[2010/12/08 09:47:31 | 000,359,929 | —- | C] () – C:\Users\BJMS\Desktop\dds.scr
[2010/11/27 18:10:59 | 000,000,036 | —- | C] () – C:\Users\BJMS\AppData\Local\housecall.guid.cache
[2010/11/27 14:16:51 | 000,000,356 | —- | C] () – C:\Windows\tasks\GlaryUpdate.job
[2010/11/26 10:24:58 | 000,000,172 | —- | C] () – C:\Windows\System32\drivers\NBRTWizard\0301000.00B\isolate.ini
[2010/11/17 10:10:44 | 000,001,047 | —- | C] () – C:\Users\BJMS\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2010/11/14 14:41:25 | 001,368,511 | R— | C] () – C:\Users\BJMS\My Documents\Aetna Health Fund OK.PDF
[2010/11/13 16:08:51 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2010/11/13 16:08:51 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2010/11/12 14:05:21 | 000,086,076 | R— | C] () – C:\Users\BJMS\My Documents\BofI Fees Terms Effect 12102010.pdf
[2010/02/15 11:27:26 | 000,016,968 | —- | C] () – C:\Windows\System32\drivers\hitmanpro35.sys
[2009/11/21 07:53:35 | 000,027,893 | —- | C] () – C:\Users\BJMS\AppData\Roaming\UserTile.png
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/05/30 14:00:43 | 000,006,794 | —- | C] () – C:\Windows\Sandboxie.ini
[2009/05/29 13:18:50 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/27 16:27:36 | 000,000,680 | —- | C] () – C:\Users\BJMS\AppData\Local\d3d9caps.dat
[2009/01/31 12:34:59 | 000,000,064 | —- | C] () – C:\Windows\wininit.ini
[2008/10/05 12:47:50 | 000,005,012 | —- | C] () – C:\Users\BJMS\AppData\Roaming\wklnhst.dat
[2008/07/03 23:33:16 | 000,006,144 | —- | C] () – C:\Users\BJMS\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/04 20:44:34 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/03/11 22:10:44 | 000,155,648 | —- | C] () – C:\Windows\System32\igfxtvcx.dll
[2008/02/22 10:49:17 | 000,004,154 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/02/11 18:55:18 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1437.dll
[2008/01/25 15:25:08 | 000,011,264 | —- | C] () – C:\Windows\System32\rcmirror.dll
[2007/08/20 06:34:08 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1318.dll
[2007/08/20 06:25:00 | 000,910,720 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[1996/04/03 13:33:26 | 000,005,248 | —- | C] () – C:\Windows\System32\giveio.sys

========== LOP Check ==========

[2009/12/16 10:57:38 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\cspa
[2009/06/28 12:06:07 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Foxit
[2010/01/08 12:14:57 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Foxit Software
[2009/03/09 14:33:42 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\GlarySoft
[2010/08/09 15:22:47 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\KC Softwares
[2008/07/14 19:54:07 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\MiniDm
[2010/08/20 13:25:28 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\MozBackup
[2010/08/18 07:38:26 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\OpenOffice.org
[2010/08/21 14:39:15 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Process Hacker
[2009/11/25 15:54:14 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Seagate
[2009/03/04 18:11:52 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\SignupShield
[2009/06/26 16:27:20 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Template
[2009/11/29 01:44:35 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Tific
[2009/12/14 14:42:30 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\TomTom
[2009/06/29 10:27:11 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\WinBatch
[2010/12/05 10:00:07 | 000,000,356 | —- | M] () – C:\WINDOWS\Tasks\GlaryUpdate.job
[2010/12/06 10:47:09 | 000,032,614 | —- | M] () – C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/02/22 10:35:03 | 000,000,074 | —- | M] () – C:\autoexec.bat
[2009/04/10 22:36:38 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/12/06 10:48:21 | 3210,756,096 | -HS- | M] () – C:\hiberfil.sys
[2009/10/10 11:31:58 | 000,000,108 | —- | M] () – C:\index.ini
[2010/11/13 16:08:51 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/02/22 10:11:46 | 000,000,383 | -H– | M] () – C:\IPH.PH
[2010/08/20 12:59:57 | 000,000,000 | —- | M] () – C:\JavaRa.log
[2010/11/13 16:08:51 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/12/06 10:48:15 | 3524,546,560 | -HS- | M] () – C:\pagefile.sys
[2009/07/27 12:53:50 | 000,000,665 | —- | M] () – C:\updatedatfix.log

< %systemroot%\Fonts\*.com >
[2008/07/20 12:27:48 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2008/07/20 12:27:48 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2008/07/20 12:27:48 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/05/29 13:27:23 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 03:46:03 | 000,070,144 | —- | M] (CANON INC.) – C:\WINDOWS\System32\spool\prtprocs\w32x86\CNBPP3.DLL
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\System32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2006/11/02 06:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 21:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 20:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 21:14:18 | 016,846,848 | —- | M] () – C:\WINDOWS\System32\config\COMPONENTS.SAV
[2008/01/20 21:14:08 | 000,106,496 | —- | M] () – C:\WINDOWS\System32\config\DEFAULT.SAV
[2008/01/20 21:14:18 | 000,020,480 | —- | M] () – C:\WINDOWS\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\WINDOWS\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/04/30 07:34:33 | 000,000,221 | -HS- | M] () – C:\Users\BJMS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/12/08 09:46:28 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\BJMS\Desktop\HiJackThis.exe
[2010/12/08 09:46:01 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\BJMS\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-03 18:03:58

========== Alternate Data Streams ==========

@Alternate Data Stream - 379 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1CA73D29

< End of report >

Extras
OTL Extras logfile created on: 12/8/2010 9:55:52 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\BJMS\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 64.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.54 Gb Total Space | 83.29 Gb Free Space | 60.55% Space Free | Partition Type: NTFS
Drive D: | 11.51 Gb Total Space | 2.03 Gb Free Space | 17.60% Space Free | Partition Type: NTFS

Computer Name: BJM-PC | User Name: BJMS | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [hitmanpro] – "C:\Program Files\Hitman Pro 3.5\HitmanPro35.exe" "%1\"
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-937870164-965859634-2082662236-1000]
"EnableNotificationsRef" = 3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-937870164-965859634-2082662236-1004]
"EnableNotificationsRef" = 8

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03510A4F-F70C-41A5-BCBC-ACE4311F5B29}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{70BBC0E6-A428-4B94-AED1-03C6FC39BEF7}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{7A238C26-4591-411D-ABB7-F73ACEAAF4D7}" = protocol=17 | dir=in | app=c:\users\bjm\appdata\local\temp\wzse0.tmp\symnrt.exe |
"{7AC37F4F-38B2-467D-9B36-5928C8AE0322}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{9D3EAB25-7FE2-4059-99AD-705B409E0582}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{B1DD21E3-600D-4A50-BFC1-46449F6C36B9}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{B908ADA1-3BC1-4B64-8EB4-3BEFA1EC4D00}" = protocol=6 | dir=in | app=c:\users\bjm\appdata\local\temp\wzse0.tmp\symnrt.exe |
"{E8474A6C-2929-473E-BC70-2CAF59DF1323}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"TCP Query User{4DCC0EB7-D8A4-4233-8F4D-3A812303AF97}C:\windows\lmi8710.tmp\lmi_rescue.exe" = protocol=6 | dir=in | app=c:\windows\lmi8710.tmp\lmi_rescue.exe |
"TCP Query User{B1BF550D-F6BC-4109-B9B6-C5D9EEF34A04}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{3426B1F4-EB0A-4C16-8030-5A37648A619A}C:\windows\lmi8710.tmp\lmi_rescue.exe" = protocol=17 | dir=in | app=c:\windows\lmi8710.tmp\lmi_rescue.exe |
"UDP Query User{67E96E6A-1A55-478A-A630-5C3B6D5887A1}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0CE5F45E-F6CC-4638-B0DD-BB7F6EF56713}" = HP Deskjet D1500 Printer Driver Software 10.0 Rel .3
"{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}" = HP Driver Diagnostics
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{20C53FA2-4307-4671-A93F-9463B29DFCF1}" = Symantec Technical Support Web Controls
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{25771101-7948-4591-ABF3-B1ECE7A7F45F}" = HP Update
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 22
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{305468A6-DE2D-43ba-A168-2F45A97A89DA}" = DJ_SF_03_D1500_Software_Min
"{326957C7-83FD-4550-A59A-849B7B4297DE}" = Microsoft Easy Assist v2
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 B2
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{38436888-9EAA-4cec-A56F-65B73D9D423C}" = D1500
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.6
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5AC2D321-11E2-47E7-A1CA-61A34C2057AB}" = WOT for Internet Explorer
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{82C113AD-486F-4bd5-A2EA-2383AF57D084}" = D1500_Help
"{85833A03-476B-43B3-B61C-5EB946DBF6E4}" = HP User Guides 0092
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8B8240B3-891D-4965-AA51-8799622D44FF}" = DJ_SF_03_D1500_ProductContext
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DF6EC22-733E-4EDC-AC88-54CAD4BF4E7B}" = BlackArmor Backup
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Touch Pad Driver
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AE46ABD3-D625-467F-B5A7-8D3FFF077F0D}" = Realtek 8139 and 8139C+ Ethernet Network Card Driver for Windows Vista
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B1421599-A42D-47ef-B512-B9B0317BD599}" = DJ_SF_03_D1500_Software
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D85376A5-8F53-43EB-9777-41E2A193FC5F}" = GEAR ISO Burn
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Belarc Advisor" = Belarc Advisor 8.1
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Defraggler" = Defraggler
"ESET Online Scanner" = ESET Online Scanner v3
"FileHippo.com" = FileHippo.com Update Checker
"Foxit Reader" = Foxit Reader
"Glary Utilities_is1" = Glary Utilities Pro 2.30.0.1066
"HDMI" = Intel® Graphics Media Accelerator Driver
"HitmanPro35" = Hitman Pro 3.5
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"Image to PDF Converter Free_is1" = Image to PDF Converter Free 3.0
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"KC Softwares SUMo_is1" = KC Softwares SUMo
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MozBackup" = MozBackup 1.4.10
"Mozilla Firefox (3.6.12)" = Mozilla Firefox (3.6.12)
"NBRTWizard" = Norton Bootable Recovery Tool Wizard
"NirSoft BlueScreenView" = NirSoft BlueScreenView
"NIS" = Norton Internet Security
"Recuva" = Recuva
"Revo Uninstaller" = Revo Uninstaller 1.90
"Sandboxie" = Sandboxie 3.50
"Secunia PSI" = Secunia PSI
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.4
"TomTom HOME" = TomTom HOME 2.7.6.2056
"TVWiz" = Intel® TV Wizard

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
It looks like you were attacked when visiting a website. Norton did it's job and blocked the attack. Your OTL log doesn't show any obvious signs of malware, but to be on the safe side let's run a couple of scans and just be sure nothing turns up.

If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates. Allow it to check for and apply any updates.
  • Select the Scanner tab, and Perform Quick Scan
  • [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the log in your next reply.
Hello patndoris
Nice to meet you….
Brief comment re > GMER ~~ While scanning activity was obvious. When activity stopped I was expecting a notice ~ End / Complete.

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-09 18:33:50
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 Hitachi_ rev.BBCO
Running: gmer.exe; Driver: C:\Users\BJMS\AppData\Local\Temp\uwldqpow.sys


—- System - GMER 1.0.15 —-

SSDT 87135EF0 ZwAlertResumeThread
SSDT 87135FD0 ZwAlertThread
SSDT 86E1F080 ZwAllocateVirtualMemory
SSDT 86D3E228 ZwAlpcConnectPort
SSDT 87135698 ZwAssignProcessToJobObject
SSDT 87135C40 ZwCreateMutant
SSDT 87423E18 ZwCreateSymbolicLinkObject
SSDT 873EFF50 ZwCreateThread
SSDT 87135778 ZwDebugActiveProcess
SSDT 86E1F250 ZwDuplicateObject
SSDT 8738D210 ZwFreeVirtualMemory
SSDT 87135D30 ZwImpersonateAnonymousToken
SSDT 87135E10 ZwImpersonateThread
SSDT 86CE8080 ZwLoadDriver
SSDT 8738D110 ZwMapViewOfSection
SSDT 87135B60 ZwOpenEvent
SSDT 873EFDF8 ZwOpenProcess
SSDT 86E1F170 ZwOpenProcessToken
SSDT 871359A0 ZwOpenSection
SSDT 86E1F320 ZwOpenThread
SSDT 871355A8 ZwProtectVirtualMemory
SSDT 86EE1B98 ZwResumeThread
SSDT 86EE1E38 ZwSetContextThread
SSDT 86EE1F18 ZwSetInformationProcess
SSDT 87135858 ZwSetSystemInformation
SSDT 87135A80 ZwSuspendProcess
SSDT 86EE1C78 ZwSuspendThread
SSDT 873BEDB0 ZwTerminateProcess
SSDT 86EE1D58 ZwTerminateThread
SSDT 8738D030 ZwUnmapViewOfSection
SSDT 8738D300 ZwWriteVirtualMemory
SSDT 87423F08 ZwCreateThreadEx

Code BD7ECBFC ZwTraceEvent
Code BD7ECBFB NtTraceEvent

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!NtTraceEvent 81C46376 2 Bytes JMP BD7ECC00
.text ntkrnlpa.exe!NtTraceEvent + 3 81C46379 2 Bytes [BA, 3B]
.text ntkrnlpa.exe!KeSetEvent + 11D 81CC7880 8 Bytes [F0, 5E, 13, 87, D0, 5F, 13, …]
.text ntkrnlpa.exe!KeSetEvent + 131 81CC7894 4 Bytes [80, F0, E1, 86]
.text ntkrnlpa.exe!KeSetEvent + 13D 81CC78A0 4 Bytes [28, E2, D3, 86]
.text ntkrnlpa.exe!KeSetEvent + 191 81CC78F4 4 Bytes JMP 9523117A
.text ntkrnlpa.exe!KeSetEvent + 1F5 81CC7958 4 Bytes [40, 5C, 13, 87]
.text …
PAGE ntkrnlpa.exe!NtRequestPort + 2 81E26F08 5 Bytes JMP BD7ECCA0
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 2 81E584DD 5 Bytes JMP BD7ECDE0
PAGE ntkrnlpa.exe!NtRequestWaitReplyPort + 2 81E5EAB2 5 Bytes JMP BD7ECD40

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Tcp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 tdrpm174.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 snman380.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 tdrpm174.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 snman380.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\tdx \Device\Udp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\RawIp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)

—- EOF - GMER 1.0.15 —-
——————————————————————————————————-

Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Database version: 5283

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

12/9/2010 6:43:03 PM
mbam-log-2010-12-09 (18-43-03).txt

Scan type: Quick scan
Objects scanned: 151532
Time elapsed: 3 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
————————————————————————————————–
Thanks for helping me !
bjm_
Your logs appear to be malware free and you do not appear to be experiencing any malware related problems. You probably just happened upon a bad website. Your machine looks well protected and it appears you keep programs like Java and Adobe up to date which is a good. Please do the following now:

If you ran DeFogger

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.


Now to remove most of the tools that we have used in fixing your machine:
  • Run OTL.exe
  • This time, click on the CleanUp button.

If you notice any remaining tools or files you can delete them by right clicking and choosing delete.



Here are a few other tips for the future to help you continue keeping your machine malware free.

Check your Windows Updates
In Vista, you can go to Control Panel / Windows Update. You should check occasionally to ensure that all your updates, including optional ones, have been installed.

Use and Update your Norton AntiVirus & Firewall
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.



Make your Internet Explorer more secure
This can be done by following these simple instructions:

1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.

1. Change the Download signed ActiveX controls to Prompt
2. Change theDownload unsigned ActiveX controls to Disable
3. Change the Initialise and script ActiveX controls not marked as safe to Disable
4. Change the Installation of desktop items to Prompt
5. Change the Launching programs and files in an IFRAME to Prompt
6. Change the Navigate sub-frames across different domains to Prompt
7. When all these settings have been made, click on the OK button.
8. If it prompts you as to whether or not you want to save the settings, press the Yes button.

Next press the Apply button and then the OK to exit the Internet Properties page.


Update and Runl Malwarebytes Anti-Malware
Scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with SuperAntiSpyware.

Update and Run SUPERAntiSpyware Home Edition (free edition)
You should also scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with Malwarebytes.

Perform an online virus scan
Every so often, also perform an online virus scan.
AntiVirus scanners use databases which are not identical, and one may find malware that another does not.

Some online scanners:
TrendMicro HouseCall: http://uk.trendmicro-europe.com/consumer/h…call_launch.php
Panda ActiveScan: http://www.pandasoftware.com/products/activescan.htm
Kaspersky Online Scanner (using Internet Explorer): http://www.kaspersky.com/virusscanner
BitDefender: http://www.bitdefender.com/scan8/

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

Update all these programs regularly
Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.


Good luck & Happy surfing!
Hello pantdoris Maybe, a few questions I am curious as to why OTL instructions do not include … tic > Scan All Users Why only active user ? I am curious who / how to contact WTT if my Topic has not been answered….or, if I need my Topic reopened….or if I need WTT Help about or beyond my Topic. I am curious as to why I had a choice of Tools to initially run. OTL, Hijack, DDS Why not OTL and DDS. ( HijackThis may be easily abused ) Would we have proceeded differently had I run DDS or HijackThis instead of OTL. Thanks ….waiting for your reply
I will do my best to answer the questions you have.

I am curious as to why OTL instructions do not include … tic > Scan All Users
Why only active user ?

When you are logged in as administrator or run it with Admin rights on the machine, OTL scans all the necessary files for all users.

I am curious who / how to contact WTT if my Topic has not been answered….or, if I need my Topic reopened….or if I need WTT Help about or beyond my Topic.

If a topic has not been answered within 3 days you can follow the instructions found here. If you were the topic starter, and need a topic reopened, please contact a staff member with the address of the thread. If you need additional help beyond what was provided in the answer to your topic, you can certainly let the person assisting you know by posting in the topic (as you have done here). I'm quite sure if the person can help they will, or perhaps will give you instructions on where you might find more assistance if they are unable to do answer your additional questions.

I am curious as to why I had a choice of Tools to initially run. OTL, Hijack, DDS

There are many tools that can be used to find where malware may be hiding. HijackThis is not the preferred tool these days, because it simply does not look in all the necessary locations malware can hide. However, infections may block users from downloading new tools. If a user already has HijackThis and/or is more comfortable in running it - it certainly still provides a starting point for evaluating a system. As for OTL and DDS, it's really a matter of preference. In some cases, with tricky malware, we might even run both, as each tool looks in slightly different places. There is no single solution when it comes to malware. (As a person researching the logs, I personally prefer looking at an OTL log.)

Why not OTL and DDS. ( HijackThis may be easily abused )

Again, HijackThis is still offered as an option because if the user has it and cannot download any other tool, it may be a place to start. It certainly still can perform some fixes and still has merit in some situations. But I will reiterate it is not the tool of choice for most situations.

Would we have proceeded differently had I run DDS or HijackThis instead of OTL.

If you had provided a HijackThis log, I would have reviewed it completely to see if there were initial information to be found. I would have informed you that it is not the tool of choice as it has not had consistent development and updates, and would have requested and OTL log from you. If you had posted a DDS log, I would have reviewed it just as I would an OTL log. The direction would have been the same regardless of which log you posted. The log itself does not determine the action - the information contained in the log determines the next steps.




The one thing we do try to do is to keep this particular forum dedicated to malware removal. If a poster has questions, or if their particular problem is not related to malware), we may direct them to post in another of our forums where they will receive better assistance with the matter at hand.

:) You had quite a lot of questions there! I hope I've answered them all for you. Feel free to browse around the forums and take a look all we offer here at WTT. Feel free to stop in the Meet and Greet Forum and introduce yourself. You can also find some of the basic site questions/information in the Site Orientation and FAQ forum if you need additional information.
Yes, Thanks for your additional attention
Umm, I have two Admin Accounts. Vista default Admin and user created Admin.
re > When you are logged in as administrator or run it with Admin rights on the machine, OTL scans all the necessary files for all users.

I only see >> C:\Users\BJMS\Desktop\OTL.exe (OldTimer Tools)
My default Admin is BJM and user created Admin is BJMS
So, OTL scanned all necessary files at BJM and BJMS

I scanned OTL. My untrained eyes finds no >>> C:\Users\BJM\ only >>> C:\Users\BJMS\
OTL scanned all necessary files at BJM and BJMS ?

So, next time (if there is a next time) and I clic Scan All Users ~ No harm No foul ?

So, why is there a tic box Scan All Users. For XP where the user account structure was different.

Sorry, to pick at this one scab

C:\Users\BJMS\Desktop\OTL.exe (OldTimer Tools)

This is the location from which OTL is running. It is merely an indication that this executable file is running from your desktop. It does not indicate where it is scanning.

If you look at the following sections you will clearly see that /BJM areas were scanned. You can also see that the installed programas are for all users, as well as those listed for currently logged in user.

========== Vista Active Application Exception List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
========== HKEY_CURRENT_USER Uninstall List ==========


You should ALWAYS follow the directions for running tools exactly as they are given. Not doing so puts you at risk for causing additional complications on your machine.


If you are interested in learning more about OTL and in helping others with malware removal, you may want to consider applying for training her in the forums :)
Hello patndoris
From my post Dec 9 2010, 07:06 PM
Hello patndoris
Nice to meet you….
Brief comment re > GMER ~~ While scanning activity was obvious. When activity stopped I was expecting a notice ~ End / Complete.
——————————————————————————————
I ran OTL Scan again with Scan All Users
Two commnets
1) This time I saw "Scan Complete"
2) This time LOP Check renders C:\Users\BJM\ & C:\Users\BJMS\ ~~~~ Compare LOP Check with 12/08 OTL

Both Scans 12/08 & Today run from Admin account ~ Run As Admin

OTL logfile created on: 12/11/2010 5:01:54 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\BJMS\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 68.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.54 Gb Total Space | 85.66 Gb Free Space | 62.28% Space Free | Partition Type: NTFS
Drive D: | 11.51 Gb Total Space | 2.03 Gb Free Space | 17.60% Space Free | Partition Type: NTFS

Computer Name: BJM-PC | User Name: BJMS | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\BJMS\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
PRC - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\BJMS\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\asOEHook.dll (Symantec Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c
2\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c
2\msvcp90.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) – C:\WINDOWS\System32\FntCache.dll (Microsoft Corporation)
SRV - (SgtSch2Svc) – C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Seagate)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Symantec RemoteAssist) – C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Com4Qlb) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)


========== Driver Services (SafeList) ==========

DRV - (SymIMMP) – C:\Windows\System32\DRIVERS\SymIM.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101211.006\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101211.006\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101123.003\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101210.001\IDSvix86.sys (Symantec Corporation)
DRV - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\NIS\1201000.025\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\NIS\1201000.025\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\NIS\1201000.025\SRTSPX.SYS (Symantec Corporation)
DRV - (SymIM) – C:\WINDOWS\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\system32\drivers\NIS\1201000.025\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\NIS\1201000.025\Ironx86.SYS (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\NIS\1201000.025\SYMDS.SYS (Symantec Corporation)
DRV - (PSI) – C:\WINDOWS\System32\drivers\psi_mf.sys (Secunia)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (tdrpman174) Acronis Try&Decide and Restore Points filter (build 174) – C:\Windows\system32\DRIVERS\tdrpm174.sys (Acronis)
DRV - (timounter) – C:\Windows\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\System32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman380) Acronis Snapshots Manager (Build 380) – C:\Windows\system32\DRIVERS\snman380.sys (Acronis)
DRV - (RTSTOR) – C:\WINDOWS\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (iaStor) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (RTL8023xp) – C:\WINDOWS\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (CnxtHdAudService) – C:\WINDOWS\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (igfx) – C:\WINDOWS\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (tapvpn) – C:\WINDOWS\System32\drivers\tapvpn.sys (The OpenVPN Project)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) – C:\WINDOWS\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (rcmirror) – C:\WINDOWS\System32\drivers\rcmirror.sys (Windows ® Codename Longhorn DDK provider)
DRV - (HSF_DPV) – C:\WINDOWS\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\WINDOWS\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvm60x32.sys (NVIDIA Corporation)
DRV - (BCM43XV) – C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (speedfan) – C:\Windows\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (HBtnKey) – C:\WINDOWS\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (giveio) – C:\Windows\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-21-937870164-965859634-2082662236-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
IE - HKU\S-1-5-21-937870164-965859634-2082662236-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://news.yahoo.com/page/sitemap
IE - HKU\S-1-5-21-937870164-965859634-2082662236-1004\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-937870164-965859634-2082662236-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Norton Safe Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://refdesk.com/"
FF - prefs.js..extensions.enabledItems: [removed]:0.78.2
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.7
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {c33c5b47-69c8-45a4-a5e0-af85bbe628dd}:[removed]
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.2
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.48.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:5.1
FF - prefs.js..extensions.enabledItems: {6614d11d-d21d-b211-ae23-815234e1ebb5}:1.0.21

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2010/10/02 11:54:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2010/10/02 11:50:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/09 19:15:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/09 19:15:24 | 000,000,000 | —D | M]

[2009/12/14 14:42:33 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Mozilla\Extensions
[2009/12/14 14:42:33 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/12/11 14:24:51 | 000,000,000 | R–D | M] – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions
[2010/04/26 16:52:21 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/25 15:25:58 | 000,000,000 | —D | M] (Dr.Web anti-virus link checker) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}
[2010/11/25 22:45:17 | 000,000,000 | —D | M] (NoScript) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/09/09 13:23:27 | 000,000,000 | —D | M] (WOT) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/01/14 10:41:22 | 000,000,000 | —D | M] (Interclue) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}
[2010/12/09 18:44:31 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/07/30 10:46:27 | 000,000,000 | —D | M] (No name found) – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010/11/18 17:16:30 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\extensions\[removed]
[2009/01/10 13:36:37 | 000,001,908 | —- | M] () – C:\Users\BJMS\AppData\Roaming\Mozilla\Firefox\Profiles\8hmdv0vd.default\searchplugins\aboutcom.xml
[2010/11/27 14:48:28 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/10/13 11:23:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 03:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/04/04 09:33:45 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

O1 HOSTS File: ([2010/06/09 21:57:32 | 000,000,027 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-937870164-965859634-2082662236-1004\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-937870164-965859634-2082662236-1004\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-937870164-965859634-2082662236-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-937870164-965859634-2082662236-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-937870164-965859634-2082662236-1004\..Trusted Domains: secunia.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-937870164-965859634-2082662236-1004\..Trusted Domains: secunia.com ([]https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\CompaqTrace.jpg
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\CompaqTrace.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/22 10:35:03 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 09:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{f1449dbe-e81b-11de-b75e-001b38f93826}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/12/11 16:56:18 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\BJMS\Desktop\OTL.exe
[2010/12/09 00:19:33 | 000,000,000 | —D | C] – C:\Users\BJMS\Desktop\WTT
[2010/11/28 14:00:58 | 001,746,864 | —- | C] (Codejock Software) – C:\Windows\System32\Codejock.CommandBars.Unicode.v11.2.0.ocx
[2010/11/28 14:00:58 | 000,665,600 | —- | C] (Alientools Software) – C:\Windows\System32\pdfgenx.ocx
[2010/11/28 14:00:58 | 000,518,064 | —- | C] (Codejock Software) – C:\Windows\System32\Codejock.SkinFramework.Unicode.v11.2.0.ocx
[2010/11/28 14:00:58 | 000,000,000 | —D | C] – C:\Program Files\PDFArea
[2010/11/26 10:25:33 | 000,107,368 | R— | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/11/26 10:24:58 | 000,000,000 | —D | C] – C:\Program Files\Norton Bootable Recovery Tool Wizard
[2010/11/26 10:24:58 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\NBRTWizard
[2010/11/26 10:24:58 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\NBRTWizard\0301000.00B
[2010/11/17 13:42:14 | 000,000,000 | —D | C] – C:\Users\BJMS\My Documents\Global Health
[2010/11/15 17:11:31 | 000,000,000 | —D | C] – C:\Users\BJMS\My Documents\APWU

========== Files - Modified Within 30 Days ==========

[2010/12/11 16:56:19 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\BJMS\Desktop\OTL.exe
[2010/12/11 16:14:06 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/11 16:14:06 | 000,003,344 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/11 14:14:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/11 07:39:02 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/11 07:39:02 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/11 07:34:29 | 000,323,944 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/11 07:33:34 | 3210,756,096 | -HS- | M] () – C:\hiberfil.sys
[2010/12/05 10:00:07 | 000,000,356 | —- | M] () – C:\Windows\tasks\GlaryUpdate.job
[2010/12/03 21:37:34 | 000,006,794 | —- | M] () – C:\Windows\Sandboxie.ini
[2010/11/30 16:07:20 | 000,016,968 | —- | M] () – C:\Windows\System32\drivers\hitmanpro35.sys
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/27 18:10:59 | 000,000,036 | —- | M] () – C:\Users\BJMS\AppData\Local\housecall.guid.cache
[2010/11/27 14:35:12 | 000,001,854 | —- | M] () – C:\Users\BJMS\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2010/11/27 14:15:41 | 000,000,797 | —- | M] () – C:\Users\BJMS\Desktop\Glary Utilities.lnk
[2010/11/25 13:59:32 | 000,000,804 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/11/17 10:10:44 | 000,001,047 | —- | M] () – C:\Users\BJMS\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2010/11/14 14:41:25 | 001,368,511 | R— | M] () – C:\Users\BJMS\My Documents\Aetna Health Fund OK.PDF
[2010/11/13 16:08:51 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/11/13 16:08:51 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/12 14:05:21 | 000,086,076 | R— | M] () – C:\Users\BJMS\My Documents\BofI Fees Terms Effect 12102010.pdf

========== Files Created - No Company Name ==========

[2010/11/27 18:10:59 | 000,000,036 | —- | C] () – C:\Users\BJMS\AppData\Local\housecall.guid.cache
[2010/11/27 14:16:51 | 000,000,356 | —- | C] () – C:\Windows\tasks\GlaryUpdate.job
[2010/11/26 10:24:58 | 000,000,172 | —- | C] () – C:\Windows\System32\drivers\NBRTWizard\0301000.00B\isolate.ini
[2010/11/17 10:10:44 | 000,001,047 | —- | C] () – C:\Users\BJMS\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2010/11/14 14:41:25 | 001,368,511 | R— | C] () – C:\Users\BJMS\My Documents\Aetna Health Fund OK.PDF
[2010/11/13 16:08:51 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2010/11/13 16:08:51 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2010/11/12 14:05:21 | 000,086,076 | R— | C] () – C:\Users\BJMS\My Documents\BofI Fees Terms Effect 12102010.pdf
[2010/02/15 11:27:26 | 000,016,968 | —- | C] () – C:\Windows\System32\drivers\hitmanpro35.sys
[2009/11/21 07:53:35 | 000,027,893 | —- | C] () – C:\Users\BJMS\AppData\Roaming\UserTile.png
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/05/30 14:00:43 | 000,006,794 | —- | C] () – C:\Windows\Sandboxie.ini
[2009/05/29 13:18:50 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/27 16:27:36 | 000,000,680 | —- | C] () – C:\Users\BJMS\AppData\Local\d3d9caps.dat
[2009/01/31 12:34:59 | 000,000,064 | —- | C] () – C:\Windows\wininit.ini
[2008/10/05 12:47:50 | 000,005,012 | —- | C] () – C:\Users\BJMS\AppData\Roaming\wklnhst.dat
[2008/07/03 23:33:16 | 000,006,144 | —- | C] () – C:\Users\BJMS\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/04 20:44:34 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/03/11 22:10:44 | 000,155,648 | —- | C] () – C:\Windows\System32\igfxtvcx.dll
[2008/02/22 10:49:17 | 000,004,154 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/02/11 18:55:18 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1437.dll
[2008/01/25 15:25:08 | 000,011,264 | —- | C] () – C:\Windows\System32\rcmirror.dll
[2007/08/20 06:34:08 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1318.dll
[2007/08/20 06:25:00 | 000,910,720 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[1996/04/03 13:33:26 | 000,005,248 | —- | C] () – C:\Windows\System32\giveio.sys

========== LOP Check ==========

[2009/10/02 10:30:51 | 000,000,000 | —D | M] – C:\Users\BJM\AppData\Roaming\cspa
[2008/05/26 12:01:14 | 000,000,000 | —D | M] – C:\Users\BJM\AppData\Roaming\GlarySoft
[2010/04/10 11:16:10 | 000,000,000 | —D | M] – C:\Users\BJM\AppData\Roaming\KC Softwares
[2009/03/06 09:29:20 | 000,000,000 | —D | M] – C:\Users\BJM\AppData\Roaming\MiniDm
[2010/11/08 16:28:59 | 000,000,000 | —D | M] – C:\Users\BJM\AppData\Roaming\OpenOffice.org
[2009/11/27 13:24:00 | 000,000,000 | —D | M] – C:\Users\BJM\AppData\Roaming\Seagate
[2009/06/25 09:57:26 | 000,000,000 | —D | M] – C:\Users\BJM\AppData\Roaming\SignupShield
[2008/08/31 13:23:28 | 000,000,000 | —D | M] – C:\Users\BJM\AppData\Roaming\Template
[2009/11/27 17:08:29 | 000,000,000 | —D | M] – C:\Users\BJM\AppData\Roaming\Tific
[2009/12/15 06:38:33 | 000,000,000 | —D | M] – C:\Users\BJM\AppData\Roaming\TomTom
[2009/12/16 10:57:38 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\cspa
[2009/06/28 12:06:07 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Foxit
[2010/01/08 12:14:57 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Foxit Software
[2009/03/09 14:33:42 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\GlarySoft
[2010/08/09 15:22:47 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\KC Softwares
[2008/07/14 19:54:07 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\MiniDm
[2010/08/20 13:25:28 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\MozBackup
[2010/08/18 07:38:26 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\OpenOffice.org
[2010/08/21 14:39:15 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Process Hacker
[2009/11/25 15:54:14 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Seagate
[2009/03/04 18:11:52 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\SignupShield
[2009/06/26 16:27:20 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Template
[2009/11/29 01:44:35 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\Tific
[2009/12/14 14:42:30 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\TomTom
[2009/06/29 10:27:11 | 000,000,000 | —D | M] – C:\Users\BJMS\AppData\Roaming\WinBatch
[2010/12/05 10:00:07 | 000,000,356 | —- | M] () – C:\WINDOWS\Tasks\GlaryUpdate.job
[2010/12/11 07:32:19 | 000,032,614 | —- | M] () – C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/02/22 10:35:03 | 000,000,074 | —- | M] () – C:\autoexec.bat
[2009/04/10 22:36:38 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/12/11 07:33:34 | 3210,756,096 | -HS- | M] () – C:\hiberfil.sys
[2009/10/10 11:31:58 | 000,000,108 | —- | M] () – C:\index.ini
[2010/11/13 16:08:51 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/02/22 10:11:46 | 000,000,383 | -H– | M] () – C:\IPH.PH
[2010/08/20 12:59:57 | 000,000,000 | —- | M] () – C:\JavaRa.log
[2010/11/13 16:08:51 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/12/11 07:33:26 | 3524,546,560 | -HS- | M] () – C:\pagefile.sys
[2009/07/27 12:53:50 | 000,000,665 | —- | M] () – C:\updatedatfix.log

< %systemroot%\Fonts\*.com >
[2008/07/20 12:27:48 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2008/07/20 12:27:48 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2008/07/20 12:27:48 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/05/29 13:27:23 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 03:46:03 | 000,070,144 | —- | M] (CANON INC.) – C:\WINDOWS\System32\spool\prtprocs\w32x86\CNBPP3.DLL
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\System32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2006/11/02 06:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 21:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 20:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 21:14:18 | 016,846,848 | —- | M] () – C:\WINDOWS\System32\config\COMPONENTS.SAV
[2008/01/20 21:14:08 | 000,106,496 | —- | M] () – C:\WINDOWS\System32\config\DEFAULT.SAV
[2008/01/20 21:14:18 | 000,020,480 | —- | M] () – C:\WINDOWS\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\WINDOWS\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/04/30 07:34:33 | 000,000,221 | -HS- | M] () – C:\Users\BJMS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/12/11 16:56:19 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\BJMS\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-10 22:52:41

========== Alternate Data Streams ==========

@Alternate Data Stream - 379 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1CA73D29

< End of report >
——————————————————————————————–
OTL Extras logfile created on: 12/11/2010 5:01:54 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\BJMS\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 68.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.54 Gb Total Space | 85.66 Gb Free Space | 62.28% Space Free | Partition Type: NTFS
Drive D: | 11.51 Gb Total Space | 2.03 Gb Free Space | 17.60% Space Free | Partition Type: NTFS

Computer Name: BJM-PC | User Name: BJMS | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-937870164-965859634-2082662236-1004\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [hitmanpro] – "C:\Program Files\Hitman Pro 3.5\HitmanPro35.exe" "%1\"
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-937870164-965859634-2082662236-1000]
"EnableNotificationsRef" = 3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-937870164-965859634-2082662236-1004]
"EnableNotificationsRef" = 8

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03510A4F-F70C-41A5-BCBC-ACE4311F5B29}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{70BBC0E6-A428-4B94-AED1-03C6FC39BEF7}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{7A238C26-4591-411D-ABB7-F73ACEAAF4D7}" = protocol=17 | dir=in | app=c:\users\bjm\appdata\local\temp\wzse0.tmp\symnrt.exe |
"{7AC37F4F-38B2-467D-9B36-5928C8AE0322}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{9D3EAB25-7FE2-4059-99AD-705B409E0582}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{B1DD21E3-600D-4A50-BFC1-46449F6C36B9}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{B908ADA1-3BC1-4B64-8EB4-3BEFA1EC4D00}" = protocol=6 | dir=in | app=c:\users\bjm\appdata\local\temp\wzse0.tmp\symnrt.exe |
"{E8474A6C-2929-473E-BC70-2CAF59DF1323}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"TCP Query User{4DCC0EB7-D8A4-4233-8F4D-3A812303AF97}C:\windows\lmi8710.tmp\lmi_rescue.exe" = protocol=6 | dir=in | app=c:\windows\lmi8710.tmp\lmi_rescue.exe |
"TCP Query User{B1BF550D-F6BC-4109-B9B6-C5D9EEF34A04}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{3426B1F4-EB0A-4C16-8030-5A37648A619A}C:\windows\lmi8710.tmp\lmi_rescue.exe" = protocol=17 | dir=in | app=c:\windows\lmi8710.tmp\lmi_rescue.exe |
"UDP Query User{67E96E6A-1A55-478A-A630-5C3B6D5887A1}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0CE5F45E-F6CC-4638-B0DD-BB7F6EF56713}" = HP Deskjet D1500 Printer Driver Software 10.0 Rel .3
"{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}" = HP Driver Diagnostics
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{20C53FA2-4307-4671-A93F-9463B29DFCF1}" = Symantec Technical Support Web Controls
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{25771101-7948-4591-ABF3-B1ECE7A7F45F}" = HP Update
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 22
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{305468A6-DE2D-43ba-A168-2F45A97A89DA}" = DJ_SF_03_D1500_Software_Min
"{326957C7-83FD-4550-A59A-849B7B4297DE}" = Microsoft Easy Assist v2
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 B2
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{38436888-9EAA-4cec-A56F-65B73D9D423C}" = D1500
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.6
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5AC2D321-11E2-47E7-A1CA-61A34C2057AB}" = WOT for Internet Explorer
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{82C113AD-486F-4bd5-A2EA-2383AF57D084}" = D1500_Help
"{85833A03-476B-43B3-B61C-5EB946DBF6E4}" = HP User Guides 0092
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8B8240B3-891D-4965-AA51-8799622D44FF}" = DJ_SF_03_D1500_ProductContext
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DF6EC22-733E-4EDC-AC88-54CAD4BF4E7B}" = BlackArmor Backup
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Touch Pad Driver
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AE46ABD3-D625-467F-B5A7-8D3FFF077F0D}" = Realtek 8139 and 8139C+ Ethernet Network Card Driver for Windows Vista
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B1421599-A42D-47ef-B512-B9B0317BD599}" = DJ_SF_03_D1500_Software
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D85376A5-8F53-43EB-9777-41E2A193FC5F}" = GEAR ISO Burn
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Belarc Advisor" = Belarc Advisor 8.1
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Defraggler" = Defraggler
"ESET Online Scanner" = ESET Online Scanner v3
"FileHippo.com" = FileHippo.com Update Checker
"Foxit Reader" = Foxit Reader
"Glary Utilities_is1" = Glary Utilities Pro 2.30.0.1066
"HDMI" = Intel® Graphics Media Accelerator Driver
"HitmanPro35" = Hitman Pro 3.5
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"Image to PDF Converter Free_is1" = Image to PDF Converter Free 3.0
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"KC Softwares SUMo_is1" = KC Softwares SUMo
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MozBackup" = MozBackup 1.4.10
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"NBRTWizard" = Norton Bootable Recovery Tool Wizard
"NirSoft BlueScreenView" = NirSoft BlueScreenView
"NIS" = Norton Internet Security
"Recuva" = Recuva
"Revo Uninstaller" = Revo Uninstaller 1.90
"Sandboxie" = Sandboxie 3.50
"Secunia PSI" = Secunia PSI
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.4
"TomTom HOME" = TomTom HOME 2.7.6.2056
"TVWiz" = Intel® TV Wizard

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-937870164-965859634-2082662236-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hi, I just wanted to thank you for using the WhattheTech forum for your malware concerns. I think that Patndoris answered your questions and concerns fairly well. When you have more than one user on your system, whatever user infects your computer it infects the operating system, not just for that user but for all users, your system will be infected period, When you use OTL to Scan All Users the program just checks in the other user accounts for modified files or newly created files , as an example, documents and pictures and files of that sort. When scans are run they should be run from the main users account which you did and no infections where found. It looks like you did have an Intrusian attempt on your system but Norton blocked it and no malware was installed. This topic will be closed, if you have any malware concerns in the future please just start a new topic and one of our able staff can help you. Thanks again for using WhattheTech.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI