This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Another Win7 PING issue [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please assist with removal of whatever is spawning ping.

Have tried several legit antiviris, malware, spyware tools with no effect.

Appreciate yor help.

OTL Log


OTL logfile created on: 12/13/2011 9:46:26 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\rberry\Desktop
Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.65% Memory free
3.98 Gb Paging File | 2.49 Gb Available in Paging File | 62.53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.79 Gb Total Space | 6.60 Gb Free Space | 11.83% Space Free | Partition Type: NTFS

Computer Name: WMDBALAP7 | User Name: RBERRY | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\rberry\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10t_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\rpcnet.exe (Absolute Software Corp.)
PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe (Motorola)
PRC - C:\Program Files\UltraMon\UltraMonUiAcc.exe (Realtime Soft Ltd)
PRC - C:\Program Files\UltraMon\UltraMonTaskbar.exe (Realtime Soft Ltd)
PRC - C:\Program Files\UltraMon\UltraMon.exe (Realtime Soft Ltd)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe (Altiris, Inc.)
PRC - C:\Program Files\Altiris\Altiris Agent\AeXAgentUIHost.exe (Altiris, Inc.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\Altiris\Dagent\dagent.exe (Altiris, Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\PING.EXE (Microsoft Corporation)
PRC - C:\Windows\Temp\PQ8910.EXE (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\PccNTMon.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Windows\System32\DWRCST.EXE (DameWare Development)
PRC - C:\Windows\System32\DWRCS.EXE (DameWare Development LLC)
PRC - C:\Program Files\HHVcdV6Sys\VC6SecS.exe (H+H Software GmbH)


========== Modules (No Company Name) ==========

MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.DLL ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()


========== Win32 Services (SafeList) ==========

SRV - (SPService) – File not found
SRV - (Altiris Deployment Agent) – File not found
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (Rpcnet) Remote Procedure Call (RPC) – C:\Windows\System32\rpcnet.exe (Absolute Software Corp.)
SRV - (MotoConnect Service) – C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AeXNSClient) – C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe (Altiris, Inc.)
SRV - (dsNcService) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (tmlisten) – C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe (Trend Micro Inc.)
SRV - (ntrtscan) – C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe (Trend Micro Inc.)
SRV - (TmProxy) – C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe (Trend Micro Inc.)
SRV - (DWMRCS) – C:\Windows\System32\DWRCS.EXE (DameWare Development LLC)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (VC6SecS) – C:\Program Files\HHVcdV6Sys\VC6SecS.exe (H+H Software GmbH)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (TmFilter) – C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys (Trend Micro Inc.)
DRV - (TmPreFilter) – C:\Program Files\Trend Micro\OfficeScan Client\tmpreflt.sys (Trend Micro Inc.)
DRV - (VSApiNt) – C:\Program Files\Trend Micro\OfficeScan Client\vsapiNT.sys (Trend Micro Inc.)
DRV - (motport) – C:\Windows\System32\drivers\motport.sys (Motorola)
DRV - (motmodem) – C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (dsNcAdpt) – C:\Windows\System32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (netw5v32) Intel® – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (motccgp) – C:\Windows\System32\drivers\motccgp.sys (Motorola)
DRV - (tmcomm) – C:\Windows\System32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\Windows\System32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (motccgpfl) – C:\Windows\System32\drivers\motccgpfl.sys (Motorola)
DRV - (UltraMonUtility) – C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys (Realtime Soft Ltd)
DRV - (MotoSwitchService) – C:\Windows\System32\drivers\motswch.sys (Motorola)
DRV - (kwndis) – C:\Windows\System32\drivers\kwndis.sys (www.codemachine.com)
DRV - (kwkpcusb) – C:\Windows\System32\drivers\kwusbnt.sys (Kyocera Wireless Corporation)
DRV - (obvious) – C:\Windows\System32\drivers\obvious.sys (H+H Software GmbH)
DRV - (pelusblf) – C:\Windows\System32\drivers\pelusblf.sys (Primax Electronics Ltd.)
DRV - (pelmouse) – C:\Windows\System32\drivers\PELMOUSE.SYS (Primax Electronics Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 6D 62 9D 28 B4 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\rberry\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\rberry\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\rberry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\rberry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)



Hosts file not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [AeXAgentLogon] C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe (Altiris, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DameWare MRC Agent] C:\Windows\System32\DWRCST.EXE (DameWare Development)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [OfficeScanNT Monitor] C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 2007\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office 2007\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: wakemed.org ([]http in Trusted sites)
O16 - DPF: {74233DB3-F72F-44EA-94DC-258A624037E6} https://access.wakemed.org/aspnet_client/Al…org+VSFlex8.CAB (ComponentOne FlexGrid 8.0 (UNICODE Light))
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D576AB8D-02C7-4588-98AC-5C2533A4481B} http://helpdesk/aspnet_client/Altiris_AppW…verControls.CAB (AppWeaverControls.DTPicker)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://access.wakemed.org/dana-cached/sc/J…SetupClient.cab (JuniperSetupClientControl Class)
O16 - DPF: {FDF527BA-DDDA-11D3-AA82-006094EB09CB} https://access.wakemed.org/aspnet_client/Al…eXClipboard.CAB (Altiris Clipboard Helper)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wakemed.org
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0293DAE9-A90F-4D03-A755-3F4BE84BBD4D}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1DE5898B-08D7-463A-8FDE-E6672564D7C2}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{6dd05467-7995-11df-96f0-002713681c00}\Shell - "" = AutoRun
O33 - MountPoints2\{6dd05467-7995-11df-96f0-002713681c00}\Shell\AutoRun\command - "" = E:\setup.exe -a
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/13 09:44:04 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\rberry\Desktop\OTL.exe
[2011/12/09 23:59:40 | 000,000,000 | —D | C] – C:\Users\rberry\AppData\Roaming\SUPERAntiSpyware.com
[2011/12/09 23:59:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/12/09 23:59:10 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/12/09 23:59:10 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/12/09 23:56:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/12/09 23:56:10 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/12/09 23:56:10 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/12/09 16:38:58 | 000,000,000 | —D | C] – C:\Users\rberry\AppData\Roaming\Malwarebytes
[2011/12/09 16:38:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/09 16:38:52 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/12/09 16:38:49 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/12/09 16:38:49 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/12/09 08:29:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/09 08:28:29 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/09 08:28:25 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/11/26 08:32:25 | 000,000,000 | —D | C] – C:\Users\rberry\AppData\Roaming\Mozilla
[2011/11/15 08:39:15 | 002,332,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/11/15 08:35:29 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/11/15 08:35:28 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/11/15 08:35:27 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/11/15 08:35:26 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/11/15 08:35:26 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/11/15 08:35:26 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/11/15 08:35:25 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/11/15 08:35:25 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/11/15 08:35:24 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/11/15 08:35:24 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/11/15 08:35:23 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/11/15 08:35:23 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/11/15 08:25:22 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2011/11/15 08:25:22 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2011/11/15 08:25:22 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2011/11/15 08:25:22 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/11/15 08:25:22 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/11/15 08:25:22 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2011/11/15 08:25:22 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2011/11/15 08:25:22 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2011/11/15 08:25:21 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2011/11/15 08:25:21 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/11/15 08:25:21 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2011/11/15 08:25:21 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2011/11/15 08:25:21 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2011/11/15 08:25:21 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2011/11/15 08:25:20 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2011/11/15 08:25:20 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2011/11/15 08:25:20 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2011/11/15 08:25:20 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/11/15 08:25:19 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/13 09:44:13 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\rberry\Desktop\OTL.exe
[2011/12/13 09:21:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1467574211-1640638566-184960113-2715UA.job
[2011/12/13 09:01:40 | 000,012,288 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/13 09:01:40 | 000,012,288 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/13 08:48:36 | 000,017,408 | —- | M] () – C:\Windows\System32\rpcnetp.exe
[2011/12/13 08:48:34 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\System32\rpcnet.dll
[2011/12/13 08:48:24 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/13 08:48:22 | 1603,084,288 | -HS- | M] () – C:\hiberfil.sys
[2011/12/13 08:31:42 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1467574211-1640638566-184960113-2715Core.job
[2011/12/12 15:36:46 | 212,918,798 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/12/09 23:59:19 | 000,001,961 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/12/09 23:56:24 | 000,001,216 | —- | M] () – C:\Users\rberry\Desktop\Spybot - Search & Destroy.lnk
[2011/12/09 17:35:21 | 000,017,408 | —- | M] () – C:\Windows\System32\rpcnetp.dll
[2011/12/09 16:19:43 | 000,012,952 | -HS- | M] () – C:\Users\rberry\AppData\Local\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/12/09 16:19:43 | 000,012,952 | -HS- | M] () – C:\ProgramData\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/12/09 16:05:08 | 000,000,000 | —- | M] () – C:\ProgramData\m57vYyUd4.dat
[2011/12/09 16:05:08 | 000,000,000 | —- | M] () – C:\ProgramData\Ky1Kh.exe
[2011/12/09 16:05:08 | 000,000,000 | —- | M] () – C:\Windows\System32\Ky1Kh.com
[2011/12/09 09:05:15 | 000,013,728 | —- | M] () – C:\Windows\cfgall.ini
[2011/12/09 08:29:57 | 000,001,753 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/12/09 08:19:35 | 000,012,610 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2011/12/06 05:38:02 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2011/12/04 05:49:53 | 000,002,042 | -H– | M] () – C:\Users\rberry\Documents\Default.rdp
[2011/12/03 18:44:24 | 000,011,020 | -HS- | M] () – C:\Users\rberry\AppData\Local\m2bd12w3tu8ghw
[2011/12/03 18:44:24 | 000,011,020 | -HS- | M] () – C:\ProgramData\m2bd12w3tu8ghw
[2011/11/15 09:58:14 | 000,409,752 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/15 08:03:27 | 000,615,360 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/11/15 08:03:27 | 000,103,702 | —- | M] () – C:\Windows\System32\perfc009.dat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/09 23:59:19 | 000,001,961 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/12/09 23:56:24 | 000,001,216 | —- | C] () – C:\Users\rberry\Desktop\Spybot - Search & Destroy.lnk
[2011/12/09 16:05:08 | 000,000,000 | —- | C] () – C:\ProgramData\m57vYyUd4.dat
[2011/12/09 16:05:08 | 000,000,000 | —- | C] () – C:\ProgramData\Ky1Kh.exe
[2011/12/09 16:05:08 | 000,000,000 | —- | C] () – C:\Windows\System32\Ky1Kh.com
[2011/12/09 15:42:51 | 000,012,952 | -HS- | C] () – C:\Users\rberry\AppData\Local\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/12/09 15:42:51 | 000,012,952 | -HS- | C] () – C:\ProgramData\kwqvso5e2fii2ncv7fvy0w413s8v
[2011/12/09 08:29:57 | 000,001,753 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/12/03 18:20:48 | 000,011,020 | -HS- | C] () – C:\Users\rberry\AppData\Local\m2bd12w3tu8ghw
[2011/12/03 18:20:48 | 000,011,020 | -HS- | C] () – C:\ProgramData\m2bd12w3tu8ghw
[2010/12/27 14:38:21 | 000,049,152 | —- | C] () – C:\Windows\System32\vc6upd.dll
[2010/12/11 16:00:14 | 000,024,576 | —- | C] () – C:\Windows\System32\FSRremoC.DLL
[2010/12/11 16:00:14 | 000,020,480 | —- | C] () – C:\Windows\System32\FSRremoS.EXE
[2010/06/11 21:44:10 | 000,004,608 | —- | C] () – C:\Users\rberry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/25 10:04:51 | 000,008,762 | —- | C] () – C:\Windows\System32\DWRCS.INI
[2010/05/25 08:55:25 | 000,017,408 | —- | C] () – C:\Windows\System32\rpcnetp.dll
[2010/05/25 08:54:48 | 000,017,408 | —- | C] () – C:\Windows\System32\rpcnetp.exe
[2010/04/15 16:24:57 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2010/04/15 16:24:57 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2010/04/15 16:24:57 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2010/04/15 16:24:57 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2010/04/15 16:24:57 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2010/04/15 16:24:57 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2010/04/15 15:38:32 | 000,013,728 | —- | C] () – C:\Windows\cfgall.ini
[2010/04/06 22:09:37 | 000,000,000 | —- | C] () – C:\Users\rberry\AppData\Roaming\chrtmp
[2010/04/01 23:11:22 | 000,000,017 | —- | C] () – C:\Users\rberry\AppData\Local\resmon.resmoncfg
[2010/03/31 12:00:24 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/03/14 13:14:44 | 000,000,600 | —- | C] () – C:\Users\rberry\AppData\Local\PUTTY.RND
[2010/02/22 14:30:11 | 000,012,610 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/07/13 23:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 23:33:53 | 000,409,752 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 21:05:48 | 000,615,360 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 21:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 21:05:48 | 000,103,702 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 21:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 21:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 21:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 19:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 18:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/13 18:37:50 | 000,000,000 | —- | C] () – C:\Windows\System32\neth.dll
[2009/07/13 18:15:58 | 000,015,872 | —- | C] () – C:\Windows\System32\kernelceip.dll
[2009/07/13 18:15:05 | 000,668,160 | —- | C] () – C:\Windows\System32\autochk.exe
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2010/07/28 10:46:58 | 000,000,000 | —D | M] – C:\Users\rberry\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/05/17 21:07:43 | 000,000,000 | —D | M] – C:\Users\rberry\AppData\Roaming\FileZilla
[2010/02/22 21:05:27 | 000,000,000 | —D | M] – C:\Users\rberry\AppData\Roaming\Juniper Networks
[2010/05/05 13:38:36 | 000,000,000 | —D | M] – C:\Users\rberry\AppData\Roaming\Opera
[2010/12/04 12:46:05 | 000,000,000 | —D | M] – C:\Users\rberry\AppData\Roaming\SanDisk
[2011/12/09 20:16:07 | 000,000,000 | —D | M] – C:\Users\rberry\AppData\Roaming\uTorrent
[2010/03/24 10:02:29 | 000,000,000 | —D | M] – C:\Users\rberry\AppData\Roaming\visionapp
[2011/12/09 20:16:21 | 000,017,916 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 16:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 16:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/12/13 08:48:22 | 1603,084,288 | -HS- | M] () – C:\hiberfil.sys
[2010/12/11 15:53:19 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/12/11 15:53:19 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/04/15 16:24:42 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2010/04/15 16:24:41 | 000,005,120 | -HS- | M] () – C:\ntuser.dat.LOG1
[2010/04/15 16:24:41 | 000,000,000 | -HS- | M] () – C:\ntuser.dat.LOG2
[2010/04/15 16:24:42 | 000,065,536 | -HS- | M] () – C:\ntuser.dat{bc1646dd-48d3-11df-ad39-002713681c00}.TM.blf
[2010/04/15 16:24:42 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{bc1646dd-48d3-11df-ad39-002713681c00}.TMContainer00000000000000000001.regtrans-ms
[2010/04/15 16:24:42 | 000,524,288 | -HS- | M] () – C:\ntuser.dat{bc1646dd-48d3-11df-ad39-002713681c00}.TMContainer00000000000000000002.regtrans-ms
[2011/12/13 08:48:22 | 2137,448,448 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/13 23:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/06/22 17:58:20 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2009/07/13 20:15:26 | 000,090,624 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPWN7.DLL
[2009/07/13 20:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 18:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\mdippr.dll
[2009/07/13 20:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/02/14 01:52:34 | 000,240,128 | —- | M] (Realtime Soft Ltd) – C:\Windows\UltraMon.scr
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2011/12/09 16:05:08 | 000,000,000 | —- | M] () – C:\Windows\system32\config\systemprofile\Ky1Kh.exe

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/02/22 20:33:02 | 000,000,221 | -HS- | M] () – C:\Users\rberry\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/12/13 09:44:13 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\rberry\Desktop\OTL.exe
[2010/03/14 12:57:52 | 000,454,656 | —- | M] (Simon Tatham) – C:\Users\rberry\Desktop\putty.exe

< %PROGRAMFILES%\Common Files\*.* >
[2005/11/15 14:32:22 | 000,003,638 | R— | M] () – C:\Program Files\Common Files\Altiris_Icon.ico

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoUpdate" = 1

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-03-18 21:15:25

< >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB23867$] -> Error: Cannot create file handle -> Unknown point type

< End of report >
OTL Extras (pasted)
==============

OTL Extras logfile created on: 12/13/2011 9:46:26 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\rberry\Desktop
Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.65% Memory free
3.98 Gb Paging File | 2.49 Gb Available in Paging File | 62.53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.79 Gb Total Space | 6.60 Gb Free Space | 11.83% Space Free | Partition Type: NTFS

Computer Name: WMDBALAP7 | User Name: RBERRY | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office 2007\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office 2007\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1EBEC42C-5E3F-4077-933B-411E33A0C3A4}" = Motorola Driver Installation 4.6.0
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 24
"{2851123E-5786-41BE-A3F1-A9B21E499EEB}" = Altiris Task Synchronization Agent
"{3127F76D-5335-4AC7-BD1E-2F5247A23C24}" = iTunes
"{479F8C12-576B-4A58-AB78-4B70F7012AA8}" = DIRECTV2PC Playback Advisor
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5CF6EEE9-86B1-3DB6-A07C-8F6C079C39BA}" = Google Talk Plugin
"{6C8D5E56-CA12-42B2-9075-044B4C7067A9}" = Altiris Deployment Agent
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B6A2114-C7EE-449B-807F-98AA99435CF7}" = visionapp Remote Desktop 2010
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{89CBFF00-A9F2-41F5-A188-9EF43517001B}" = Virtual CD v6
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90260409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Web Components
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{A08AEEC6-79E2-4090-917F-5A1C8B0BF071}" = Merge PACS AS Workstation V6 MR4
"{A0A1EB01-A6FD-423A-8480-364055A7C961}" = Altiris Software Delivery Solution Agent
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4654A72-087B-49B5-BDCA-E4894400C524}" = MotoConnect
"{B49673F8-7AB6-4A14-8213-C8A7BE370010}" = UltraMon
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C3}" = WinZip 15.5
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E7C97E98-4C2D-BEAF-5D2F-CC45A2F95D90}" = Acrobat.com
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ComandoDeinstKey" = Commando
"FastStone Capture" = FastStone Capture 6.7
"FileZilla Client" = FileZilla Client 3.3.1
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallShield_{479F8C12-576B-4A58-AB78-4B70F7012AA8}" = DIRECTV2PC Playback Advisor
"Juniper Network Connect 6.5.0" = Juniper Networks Network Connect 6.5.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"MouseSuite98" = Mouse Suite
"OfficeScanNT" = Trend Micro OfficeScan Client
"Opera 11.01.1190" = Opera 11.01
"Picasa 3" = Picasa 3
"Power Management Driver" = ThinkPad Power Management Driver
"PROPLUS" = Microsoft Office Professional Plus 2007
"TightVNC_is1" = TightVNC 1.3.10
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.5
"WakeMed-AMICAS" = WakeMed Amicas Phoenix Viewer 6.0.4.74736

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Acrobat Connect Add-in" = Adobe Acrobat Connect Add-in
"Juniper_Setup_Client" = Juniper Networks Setup Client
"Juniper_Term_Services" = Juniper Terminal Services Client
"Sansa Updater" = Sansa Updater

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/27/2011 1:39:27 AM | Computer Name = wmDBALap7.wakemed.org | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\system32\conhost.exe".
Dependent
Assembly Microsoft.Windows.SystemCompatible,processorArchitecture="x86",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.7600.16816"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 10/27/2011 1:44:31 AM | Computer Name = wmDBALap7.wakemed.org | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\system32\conhost.exe".
Dependent
Assembly Microsoft.Windows.SystemCompatible,processorArchitecture="x86",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.7600.16816"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 10/27/2011 1:49:15 AM | Computer Name = wmDBALap7.wakemed.org | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 10/27/2011 1:49:15 AM | Computer Name = wmDBALap7.wakemed.org | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 998

Error - 10/27/2011 1:49:15 AM | Computer Name = wmDBALap7.wakemed.org | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 998

Error - 10/27/2011 1:49:16 AM | Computer Name = wmDBALap7.wakemed.org | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 10/27/2011 1:49:16 AM | Computer Name = wmDBALap7.wakemed.org | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2371

Error - 10/27/2011 1:49:16 AM | Computer Name = wmDBALap7.wakemed.org | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2371

Error - 10/27/2011 1:49:17 AM | Computer Name = wmDBALap7.wakemed.org | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 10/27/2011 1:49:17 AM | Computer Name = wmDBALap7.wakemed.org | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3370

[ System Events ]
Error - 4/4/2011 9:52:19 PM | Computer Name = wmDBALap7.wakemed.org | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume C:.

Error - 4/4/2011 9:52:24 PM | Computer Name = wmDBALap7.wakemed.org | Source = Service Control Manager | ID = 7023
Description = The Windows Search service terminated with the following error: %%1392

Error - 4/4/2011 9:52:24 PM | Computer Name = wmDBALap7.wakemed.org | Source = Service Control Manager | ID = 7031
Description = The Windows Search service terminated unexpectedly. It has done this
2 time(s). The following corrective action will be taken in 30000 milliseconds:
Restart the service.

Error - 4/4/2011 9:52:28 PM | Computer Name = wmDBALap7.wakemed.org | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.

Error - 4/4/2011 9:52:28 PM | Computer Name = wmDBALap7.wakemed.org | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.

Error - 4/4/2011 9:52:38 PM | Computer Name = wmDBALap7.wakemed.org | Source = Service Control Manager | ID = 7023
Description = The Windows Search service terminated with the following error: %%1392

Error - 4/4/2011 9:52:38 PM | Computer Name = wmDBALap7.wakemed.org | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
3 time(s).

Error - 4/4/2011 9:52:55 PM | Computer Name = wmDBALap7.wakemed.org | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Search service to connect.

Error - 4/4/2011 9:52:55 PM | Computer Name = wmDBALap7.wakemed.org | Source = Service Control Manager | ID = 7000
Description = The Windows Search service failed to start due to the following error:
%%1053

Error - 4/4/2011 9:53:07 PM | Computer Name = wmDBALap7.wakemed.org | Source = Microsoft-Windows-Kernel-General | ID = 5
Description =


< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right-click and Run as Administrator GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI