Hey,
Ok, I ran HiJackThis and removed the file that you specified. I then ran OTMoveIt and it found many file to be removed. It could not remove them and had to be run at startup. After that, I ran JavaRa and removed all of the previous updates and then installed JRE 6 build 10. Finally, I ran RSIT. The logs are attached below.
Thanks,
-Nick
OTMoveIt-
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3bfb1073-a923-11dc-99d7-806d6172696f}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9188eda1-af65-11dc-99e8-001d097cba8b}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9188eda2-af65-11dc-99e8-001d097cba8b}\\ deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\HOMECO~1\LOCALS~1\Temp\Perflib_Perfdata_430.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\HOMECO~1\LOCALS~1\Temp\Perflib_Perfdata_b4.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\HOMECO~1\LOCALS~1\Temp\~DF9B0F.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\HOMECO~1\LOCALS~1\Temp\~DF9B67.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS028FC485-D61E-44A9-A340-5F9AD1F752E5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS02FCF12E-7C76-4246-848A-3BCB0A7FA648.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS03DE9D15-5A0F-4505-8850-A5838DB8E7D0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0BEF1822-2FC5-4500-9080-C6AB913C914A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0CC4C113-7CFD-44F1-81CD-5740BE5A4593.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0DC170D1-BF84-4D5F-BC48-D2765AD5B757.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0FA27A59-7967-47C7-B9DF-A58020D05B10.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS11CF7BD1-B47D-4F7B-9080-0AA1BCDF77ED.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS13681308-6078-4129-8468-825721712AA0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS14154BFE-1202-49C8-9439-7E57AFAD4AA5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1797AF52-058A-48D2-AFD2-1BC1CC62EF6E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1921598F-4DA0-4743-A95F-9CC1D6AFF874.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1A48BEA4-A5B9-48A1-9457-5EF4535B1B34.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1AA4202A-0BC7-4BB4-A60A-1A275BF5E7F6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS21A6874A-558A-4F3F-B87D-7708437F23E7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS232C1E80-C7C4-4AD7-8269-54D866F07E64.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS23560119-7CB7-47A0-A446-5F2667A9DB0C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS23AF3CEF-F727-43EA-86CE-0C498BA1265E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS27FCE5AC-6497-4F0F-B827-4DBC7E652B33.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS29AD6221-82D2-4931-91FA-76C7954C53C6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS29F45CAA-DDCE-475A-9E9D-9550E79443F7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2AE641A1-EB93-4369-81B9-D27F8E7A73B1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2B2872D2-6293-45A4-9286-5C9DFCAD0ED5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2C48534F-CA4F-4192-BC6D-F27EB7FC3064.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2F675561-B7AE-4AB2-9478-43E12F93B1A1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS337F8A85-A9DE-44D3-ADD0-0D102E52C697.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS353E3172-F6A0-4C04-B336-B4DD1F52132E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS35D62FC9-C88A-40A4-8A8B-867F988DE7AF.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS38741CAA-8298-4478-9B2C-A76B05AE7B17.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS390D27DA-F03B-4B7E-A2AF-98C93C6C5CF6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS3A18EE4F-98B0-40B5-B25E-325FFC26730A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS3D5FF8C8-3947-4C85-8676-C6384ABAC693.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS3F2D72FD-2A10-403D-9DB3-448AA8811BCA.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS44528331-A862-458C-82D8-4525A1187802.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS455BF752-32AF-41D5-94F4-49087E09A7CE.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS484FA549-863F-41BF-A520-A62C85845A33.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS48D84420-55F7-469F-BE89-57412416568F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4AD1D91D-5DEF-4292-A7E8-3DCD9950361E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4FFBC434-94A4-485A-88F9-D99EDE451589.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS54AA927B-8460-4E84-888B-DC38E5D958DC.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS57434C2C-37D8-426A-9859-401B547A6774.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5A01D6F2-407A-4934-9225-E80458E786FF.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5A9B8CC4-73F3-4C3C-A4D2-DA79BB413325.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5AA49785-57C1-4403-8B7B-688DA1B07DBD.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5F8FF64E-1E3A-47B1-A54C-AA4252C20814.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS630556E4-03CA-4A07-ABCA-06DF3424E481.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS655D7DDD-651E-4C96-9A64-8CC800D397D2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS67176596-50EC-45F1-8CD9-4A45BD50F530.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS692CB3BA-9EE3-4F54-BF7E-04B8ABE797EB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS69F26B13-18E7-41CD-9F6E-DEF4E49E6DCC.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6C25069E-1DD3-4AEA-A417-452B138D762F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6C7A83E7-30F0-4A05-8AF7-8B00930A2F3E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6D549239-1418-4C01-859A-25B26B0D7286.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7744E06B-D3F7-4233-90E1-C3A1291EB4E3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7B522403-09AA-48B8-9980-CEF593655CBF.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7DAD949C-ECAB-495F-91A0-5891DE158077.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7F0F6DD4-D506-486D-837D-550504255EAA.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8067AEDF-4C84-41A9-9971-7F459CDA114F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS80FBF9A5-196B-4617-B7A2-3F68281DC20F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8419D231-0BA9-469C-81BA-633BB559E57F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8469FB1D-1530-417A-9E88-7906CF792F46.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS85B606D0-7B2B-47BB-8F50-9CC8965EA9D3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8922F7F0-690C-45EC-8953-2AAFD02C593B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8A2931EA-1028-4EAB-985D-C66749CB6CE1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8C7F8705-00FE-4398-8A5F-C3E6F114081C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8FF1EC85-4E23-404D-9F18-3EC207979E2D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS936095A0-9E3F-4C49-B84A-706BC2D3B1CB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9AABF238-00D0-48CE-AB76-71366D5D47EF.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9B1D070A-20A6-4B41-A94B-00109C325182.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9E157ED3-13A9-43F0-8344-487DB71ACA03.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA0773B58-560C-4590-94F2-95338E9CB7B7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA0ADA013-11B1-424A-A9D8-78293BCD09D3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA2E847D2-29C9-477F-B38F-5C336C3B9E08.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA6EFB9BB-DA3B-4D77-B0FC-36458FA34872.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAF9B21AF-08BB-4DAB-AA93-3630A8262057.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB57975D3-474F-4CA8-9FDE-8E9A84157A0D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB5B90266-F004-4103-8424-19D8978958BF.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBC5B7F30-E6E4-4903-805E-B1236D2CD245.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBCC00841-60EC-49D2-830F-71173B9F8CE6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBE7EC0B8-F268-4A39-9794-D10C33E15EF9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBF212037-FD76-4475-B6B9-C059268E38B5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSC9635931-DD59-4B77-85D8-559AE4F45BC5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSCCD62B5B-B29B-4EF8-9475-DE0AD79D5220.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSCD8C9624-E50E-46E2-8F43-CD6008D07EE0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSCE84C86E-5E6F-40DD-983C-94A98B529E5E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD13298E2-A1EB-4C13-84A8-80767EB7A226.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD2EA4BC2-A81B-493B-8327-FB2011B555CE.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD64CBF00-78D4-4A24-B057-19D8F13B3BA9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDB364A2B-961B-4057-8217-56826FB8C597.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDB73E2EA-53C2-4982-96AB-B0403B9880FD.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE1CD5EB2-F543-425A-8FEE-488D2A0B74B7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE7974130-F785-4988-AD59-ADB2DD3517D4.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEA624B41-2EB5-491B-B9E5-145ED55406AD.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEE4C1F69-F535-476A-8907-C33F67F9AF9A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEE815BA0-8130-4BBD-8E5C-D2CEB5BFFFEC.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEEF7CD0E-39DA-4D55-811C-D04004752461.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF257A235-C879-49C2-8F82-D37835DDA34B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF2AD2579-0E81-41BD-9FBB-59875574994E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF91797B7-8315-42EF-92A7-E37D89F580D1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSFC1E10BA-5BAF-41ED-8AC9-EB96FDE7FCCE.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSFE44D43B-B6F2-4DC1-AB70-7343A202B792.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSFF2AC87F-799C-47F3-980E-33AF73CE4BD2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSFF87540A-F556-4719-B6D3-43A9263CA0E7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSFF953C67-73C8-4719-8605-F446FFFD3BB2.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11082008_184402
Files moved on Reboot...
File C:\DOCUME~1\HOMECO~1\LOCALS~1\Temp\Perflib_Perfdata_430.dat not found!
File C:\DOCUME~1\HOMECO~1\LOCALS~1\Temp\Perflib_Perfdata_b4.dat not found!
File C:\DOCUME~1\HOMECO~1\LOCALS~1\Temp\~DF9B0F.tmp not found!
File C:\DOCUME~1\HOMECO~1\LOCALS~1\Temp\~DF9B67.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\wrstemp\SSMS028FC485-D61E-44A9-A340-5F9AD1F752E5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS02FCF12E-7C76-4246-848A-3BCB0A7FA648.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS03DE9D15-5A0F-4505-8850-A5838DB8E7D0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0BEF1822-2FC5-4500-9080-C6AB913C914A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0CC4C113-7CFD-44F1-81CD-5740BE5A4593.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0DC170D1-BF84-4D5F-BC48-D2765AD5B757.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0FA27A59-7967-47C7-B9DF-A58020D05B10.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS11CF7BD1-B47D-4F7B-9080-0AA1BCDF77ED.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS13681308-6078-4129-8468-825721712AA0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS14154BFE-1202-49C8-9439-7E57AFAD4AA5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1797AF52-058A-48D2-AFD2-1BC1CC62EF6E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1921598F-4DA0-4743-A95F-9CC1D6AFF874.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1A48BEA4-A5B9-48A1-9457-5EF4535B1B34.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1AA4202A-0BC7-4BB4-A60A-1A275BF5E7F6.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS21A6874A-558A-4F3F-B87D-7708437F23E7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS232C1E80-C7C4-4AD7-8269-54D866F07E64.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS23560119-7CB7-47A0-A446-5F2667A9DB0C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS23AF3CEF-F727-43EA-86CE-0C498BA1265E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS27FCE5AC-6497-4F0F-B827-4DBC7E652B33.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS29AD6221-82D2-4931-91FA-76C7954C53C6.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS29F45CAA-DDCE-475A-9E9D-9550E79443F7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2AE641A1-EB93-4369-81B9-D27F8E7A73B1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2B2872D2-6293-45A4-9286-5C9DFCAD0ED5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2C48534F-CA4F-4192-BC6D-F27EB7FC3064.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2F675561-B7AE-4AB2-9478-43E12F93B1A1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS337F8A85-A9DE-44D3-ADD0-0D102E52C697.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS353E3172-F6A0-4C04-B336-B4DD1F52132E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS35D62FC9-C88A-40A4-8A8B-867F988DE7AF.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS38741CAA-8298-4478-9B2C-A76B05AE7B17.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS390D27DA-F03B-4B7E-A2AF-98C93C6C5CF6.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS3A18EE4F-98B0-40B5-B25E-325FFC26730A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS3D5FF8C8-3947-4C85-8676-C6384ABAC693.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS3F2D72FD-2A10-403D-9DB3-448AA8811BCA.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS44528331-A862-458C-82D8-4525A1187802.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS455BF752-32AF-41D5-94F4-49087E09A7CE.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS484FA549-863F-41BF-A520-A62C85845A33.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS48D84420-55F7-469F-BE89-57412416568F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4AD1D91D-5DEF-4292-A7E8-3DCD9950361E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4FFBC434-94A4-485A-88F9-D99EDE451589.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS54AA927B-8460-4E84-888B-DC38E5D958DC.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS57434C2C-37D8-426A-9859-401B547A6774.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5A01D6F2-407A-4934-9225-E80458E786FF.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5A9B8CC4-73F3-4C3C-A4D2-DA79BB413325.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5AA49785-57C1-4403-8B7B-688DA1B07DBD.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5F8FF64E-1E3A-47B1-A54C-AA4252C20814.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS630556E4-03CA-4A07-ABCA-06DF3424E481.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS655D7DDD-651E-4C96-9A64-8CC800D397D2.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS67176596-50EC-45F1-8CD9-4A45BD50F530.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS692CB3BA-9EE3-4F54-BF7E-04B8ABE797EB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS69F26B13-18E7-41CD-9F6E-DEF4E49E6DCC.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6C25069E-1DD3-4AEA-A417-452B138D762F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6C7A83E7-30F0-4A05-8AF7-8B00930A2F3E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6D549239-1418-4C01-859A-25B26B0D7286.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7744E06B-D3F7-4233-90E1-C3A1291EB4E3.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7B522403-09AA-48B8-9980-CEF593655CBF.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7DAD949C-ECAB-495F-91A0-5891DE158077.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7F0F6DD4-D506-486D-837D-550504255EAA.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8067AEDF-4C84-41A9-9971-7F459CDA114F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS80FBF9A5-196B-4617-B7A2-3F68281DC20F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8419D231-0BA9-469C-81BA-633BB559E57F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8469FB1D-1530-417A-9E88-7906CF792F46.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS85B606D0-7B2B-47BB-8F50-9CC8965EA9D3.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8922F7F0-690C-45EC-8953-2AAFD02C593B.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8A2931EA-1028-4EAB-985D-C66749CB6CE1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8C7F8705-00FE-4398-8A5F-C3E6F114081C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8FF1EC85-4E23-404D-9F18-3EC207979E2D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS936095A0-9E3F-4C49-B84A-706BC2D3B1CB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9AABF238-00D0-48CE-AB76-71366D5D47EF.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9B1D070A-20A6-4B41-A94B-00109C325182.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9E157ED3-13A9-43F0-8344-487DB71ACA03.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA0773B58-560C-4590-94F2-95338E9CB7B7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA0ADA013-11B1-424A-A9D8-78293BCD09D3.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA2E847D2-29C9-477F-B38F-5C336C3B9E08.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA6EFB9BB-DA3B-4D77-B0FC-36458FA34872.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSAF9B21AF-08BB-4DAB-AA93-3630A8262057.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB57975D3-474F-4CA8-9FDE-8E9A84157A0D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB5B90266-F004-4103-8424-19D8978958BF.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBC5B7F30-E6E4-4903-805E-B1236D2CD245.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBCC00841-60EC-49D2-830F-71173B9F8CE6.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBE7EC0B8-F268-4A39-9794-D10C33E15EF9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBF212037-FD76-4475-B6B9-C059268E38B5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSC9635931-DD59-4B77-85D8-559AE4F45BC5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSCCD62B5B-B29B-4EF8-9475-DE0AD79D5220.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSCD8C9624-E50E-46E2-8F43-CD6008D07EE0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSCE84C86E-5E6F-40DD-983C-94A98B529E5E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD13298E2-A1EB-4C13-84A8-80767EB7A226.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD2EA4BC2-A81B-493B-8327-FB2011B555CE.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD64CBF00-78D4-4A24-B057-19D8F13B3BA9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSDB364A2B-961B-4057-8217-56826FB8C597.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSDB73E2EA-53C2-4982-96AB-B0403B9880FD.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE1CD5EB2-F543-425A-8FEE-488D2A0B74B7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE7974130-F785-4988-AD59-ADB2DD3517D4.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEA624B41-2EB5-491B-B9E5-145ED55406AD.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEE4C1F69-F535-476A-8907-C33F67F9AF9A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEE815BA0-8130-4BBD-8E5C-D2CEB5BFFFEC.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEEF7CD0E-39DA-4D55-811C-D04004752461.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSF257A235-C879-49C2-8F82-D37835DDA34B.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSF2AD2579-0E81-41BD-9FBB-59875574994E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSF91797B7-8315-42EF-92A7-E37D89F580D1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSFC1E10BA-5BAF-41ED-8AC9-EB96FDE7FCCE.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSFE44D43B-B6F2-4DC1-AB70-7343A202B792.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSFF2AC87F-799C-47F3-980E-33AF73CE4BD2.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSFF87540A-F556-4719-B6D3-43A9263CA0E7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSFF953C67-73C8-4719-8605-F446FFFD3BB2.tmp not found!
RSIT -
Logfile of random's system information tool 1.04 (written by random/random)
Run by Home Computer at 2008-11-08 19:14:38
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 191 GB (81%) free of 235 GB
Total RAM: 1022 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:14:50 PM, on 11/8/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navstub.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\dlcqcoms.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\notepad.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\Home Computer\Desktop\G2G\RSIT.exe
C:\Documents and Settings\Home Computer\Desktop\G2G\Home Computer.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3071207
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] "C:\WINDOWS\KHALMNPR.EXE"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [DLCQCATS] "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [AllSeeingEye] "C:\Program Files\Fortego Security\All-Seeing Eye\ase.exe" -auto
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell....iler/SysPro.CABO16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://a1540.g.akama...ex/qtplugin.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://photo.walgree...eensActivia.cabO16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) -
http://www.blackberr...re/AxLoader.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: dlcq_device - - C:\WINDOWS\system32\dlcqcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
--
End of file - 11645 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Home Computer.job
C:\WINDOWS\tasks\wrSpySweeper_L7747FFD549244D3A9E328E76911804ED.job
C:\WINDOWS\tasks\wrSpySweeper_LA6F6A8870C1C4590B515357C40FA7566.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}]
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-11 96936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-08 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-11-08 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{90222687-F593-4738-B738-FBEE9C7B26DF} - Show Norton Toolbar - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll [2007-01-11 607888]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe [2006-09-25 90112]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-07-16 16132608]
"ISUSPM Startup"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-11 218032]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-09-11 86960]
"PDVDDXSrv"=C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [2006-10-20 118784]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2008-02-29 76304]
"FaxCenterServer"=C:\Program Files\Dell PC Fax\fm3032.exe [2007-06-29 312560]
"dlcqmon.exe"=C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe [2007-06-29 292080]
"MemoryCardManager"=C:\Program Files\Dell Photo AIO Printer 966\memcard.exe [2007-06-29 304368]
"dscactivate"=C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [2007-10-09 16384]
"DellSupportCenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-08-13 206064]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-09-10 289576]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2007-01-09 115816]
"osCheck"=C:\Program Files\Norton Internet Security\osCheck.exe [2007-01-13 771704]
"Symantec PIF AlertEng"=C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
"DLCQCATS"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll [2006-10-15 106496]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-11-08 136600]
"SpySweeper"=C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-10-12 6272888]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2006-09-11 218032]
"AllSeeingEye"=C:\Program Files\Fortego Security\All-Seeing Eye\ase.exe -auto []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-08-13 206064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [2007-10-09 16384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-09-10 289576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe [2006-08-17 1116920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2007-03-26 228088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Home Computer^Start Menu^Programs^Startup^RollerCoaster Tycoon 3 Registration.lnk]
C:\Documents and Settings\Home Computer\Local Settings\Temp\{C9485106-2CD8-445A-9ED7-FBA414231614}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe /remind /language=ENU /PRNM=RollerCoaster Tycoon 3/PRMP=RCT3/SKUN=PCXX/GTYP=STRY []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
Photo Loader supervisory.lnk - C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Documents and Settings\Home Computer\Start Menu\Programs\Startup
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll [2008-05-02 72208]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WebrootSpySweeperService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WRConsumerService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableStatusMessages"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NofolderOptions"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\WINDOWS\system32\dlcqcoms.exe"="C:\WINDOWS\system32\dlcqcoms.exe:*:Enabled:Dell Communications System"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3bfb1073-a923-11dc-99d7-806d6172696f}]
shell\AutoRun\command - D:\CDSTART.EXE
======File associations======
.exe - open - "%1" %*"
.bat - edit - %SystemRoot%\System32\NOTEPAD.EXE %1"
.ini - open - %SystemRoot%\System32\NOTEPAD.EXE %1"
======List of files/folders created in the last 1 months======
2008-11-08 19:10:43 ----A---- C:\WINDOWS\system32\javaws.exe
2008-11-08 19:10:43 ----A---- C:\WINDOWS\system32\javaw.exe
2008-11-08 19:10:43 ----A---- C:\WINDOWS\system32\java.exe
2008-11-08 19:10:43 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-11-08 18:44:02 ----D---- C:\_OTMoveIt
2008-11-07 21:43:26 ----A---- C:\WINDOWS\ntbtlog.txt
2008-11-06 18:04:24 ----D---- C:\Program Files\Norton Internet Security
2008-11-06 18:02:58 ----A---- C:\WINDOWS\system32\S32EVNT1.DLL
2008-11-06 18:01:35 ----D---- C:\Program Files\Symantec
2008-11-06 18:01:32 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2008-10-31 23:15:46 ----D---- C:\rsit
2008-10-31 22:59:04 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-10-31 12:05:36 ----D---- C:\WINDOWS\Prefetch
2008-10-31 12:02:49 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2008-10-31 12:02:35 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-10-31 12:02:18 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-10-31 12:02:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-10-31 12:01:48 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-10-31 12:01:31 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-10-31 12:01:16 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-10-31 12:01:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-10-31 12:00:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-10-31 12:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-31 12:00:15 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-10-31 11:59:58 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-10-31 11:59:44 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-10-31 11:59:30 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-10-31 11:59:14 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-10-31 11:59:00 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-10-31 11:54:25 ----D---- C:\WINDOWS\system32\scripting
2008-10-31 11:54:23 ----D---- C:\WINDOWS\l2schemas
2008-10-31 11:54:22 ----D---- C:\WINDOWS\system32\en
2008-10-31 11:54:21 ----D---- C:\WINDOWS\system32\bits
2008-10-31 11:49:18 ----D---- C:\WINDOWS\ServicePackFiles
2008-10-31 11:45:27 ----D---- C:\WINDOWS\network diagnostic
2008-10-31 11:39:52 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-10-31 11:32:03 ----D---- C:\WINDOWS\EHome
2008-10-30 18:22:59 ----D---- C:\WINDOWS\ERDNT
2008-10-30 18:22:21 ----D---- C:\Program Files\ERUNT
2008-10-30 11:37:22 ----D---- C:\WINDOWS\system32\ime
2008-10-23 22:05:15 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2008-10-15 22:31:50 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-15 22:31:42 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-10-15 22:31:33 ----HDC---- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-15 22:30:51 ----HDC---- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-15 22:30:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$
2008-10-13 19:28:33 ----D---- C:\Documents and Settings\Home Computer\Application Data\Malwarebytes
2008-10-13 19:28:29 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-13 19:28:29 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-13 19:27:46 ----D---- C:\Program Files\Common Files\Download Manager
2008-10-13 19:13:57 ----D---- C:\Documents and Settings\Home Computer\Application Data\Help
======List of files/folders modified in the last 1 months======
2008-11-08 19:14:40 ----D---- C:\WINDOWS\Temp
2008-11-08 19:11:01 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-11-08 19:10:57 ----D---- C:\WINDOWS\system32\CatRoot2
2008-11-08 19:10:55 ----SHD---- C:\WINDOWS\Installer
2008-11-08 19:10:54 ----SHD---- C:\Config.Msi
2008-11-08 19:10:43 ----D---- C:\WINDOWS\system32
2008-11-08 19:07:23 ----D---- C:\Program Files\Java
2008-11-08 19:00:15 ----D---- C:\WINDOWS
2008-11-08 18:52:41 ----D---- C:\MDT
2008-11-08 18:47:02 ----A---- C:\WINDOWS\ModemLog_Standar