Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Help Tidserv Activity 2 has got me [Solved]


  • This topic is locked This topic is locked

#1
DKullman

DKullman

    Member

  • Member
  • PipPip
  • 14 posts
My computer is part of a network with a roaming profile that logs into my server. The computers resources have become consumed and I am constantly (but not always) redirected and the system has become very unstable. Norton endpoint was my first line of defense and it spotted the virus and alerted me to it. Because it said that it had quarantined the virus I was comfortable with deleting them and rebooting after which endpoint was rendered useless. I also noticed that after reboot my IE privacy setting and been reset to accept all cookies. I uninstalled and then reinstalled Norton endpoint. I ran Symantec’s other suggested scans that found nothing. Malwarebytes quarantined three and then one more after a subsequent scan. Endpoint is now giving me this warning: System Infected: Tidserv Activity 2." I also get a warning that says: System Infected: Tidserv Activity." Not sure what to do now as nothing seems to be able to find this.

I did read a previous post: http://www.geekstogo...ity-2-detected/

Seems very similar but I want to be sure before I go any further. I installed and ran OTL as described in this tutorial post: http://www.geekstogo...ldtimer-listit/

Here are the logs and some screen shots of what I’m seeing. There is an OTL txt log and an OTL Extras log.

Your help is greatly appreciated! Darrel

Screen Shot 1.JPG
Screen Shot 2.JPG
Screen Shot 3.JPG

OTL logfile created on: 1/5/2012 8:10:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\DKullman\Desktop\Virus Removal Software\Old Timer
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.22 Gb Total Physical Memory | 2.28 Gb Available Physical Memory | 71.00% Memory free
7.88 Gb Paging File | 7.08 Gb Available in Paging File | 89.87% Paging File free
Paging file location(s): C:\pagefile.sys 4939 8200 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 18.12 Gb Free Space | 24.33% Space Free | Partition Type: NTFS
Drive F: | 5.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 973.17 Mb Total Space | 909.52 Mb Free Space | 93.46% Space Free | Partition Type: FAT

Computer Name: WORKSTATION3NEW | User Name: DKullman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\DKullman\Desktop\Virus Removal Software\Old Timer\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\Program Files\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Citrix\GoToMyPC\g2tray.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2pre.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2comm.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\ACT\Act for Windows\Sage.ACT.Integration.exe (Sage Software, Inc)
PRC - C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe (Sage Software, Inc.)
PRC - C:\Program Files\ACT\Act for Windows\Act.Server.Host.exe (Microsoft)
PRC - C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
PRC - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (arvato digital services llc)
PRC - C:\Program Files\Jungle Disk Workgroup\JungleDiskWorkgroup.exe (Jungle Disk, Inc.)
PRC - C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Voltage Security\VSAgent.exe ()
PRC - C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe (SentriLock LLC)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe (American Power Conversion Corporation)
PRC - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Intuit\QuickBooks 2011\QBMAPILibrary.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\QBCompressor.DLL ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\mbpopup.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\boost_regex-vc90-mt-p-1_33.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\boost_serialization-vc90-mt-p-1_33.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\BackupLib.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\17902fdb0e0d3bc8b49bce693415fe7e\System.WorkflowServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\9ec7da53380a754b4ad97709df0dd7e7\System.ServiceModel.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\24331b719aa25ac2b21099e32232840c\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\29a2030900e91074446e9fadce2c8670\Microsoft.Practices.Unity.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\32a4fb229b569f461c061e8c78d49799\Microsoft.Practices.Unity.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\8e74526b90a406073e352590a0f5375d\Microsoft.Practices.ObjectBuilder2.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Interop.ADChronopher\5390dfe3f708253c14a48936a2e3434a\Interop.ADChronopher.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Genghis\829150d02bc643f86aa25986d1dbdf2e\Genghis.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\474a341340f687bcbd7777f2820a8c7a\SMDiagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\ceadaf3b3d017c7a1ef10a06f8009f6f\System.ServiceModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\d14065ede44df8e9b5d6b60c5ddccc69\System.IdentityModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6303e256d2ac0843c3e4c24172c90544\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.UI.SyncSetup\05c61258fc4f51d5a30d9b340f7a49e4\Act.UI.SyncSetup.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Windows.#\3f830ad41839685ecb7458588b43023a\Act.Shared.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Win32\b268962e1d5451ddac8d7ec57015bfb8\Act.Shared.Win32.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Images\020dbb59d9623c2a189948999b7f080b\Act.Shared.Images.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Config\878d8197a79ac647b06dadecdaa1c25b\Act.Shared.Config.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Sync.Co#\94058bcd82f4f3bf07e57ae8ab06b44f\Act.Outlook.Sync.Common.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Service#\41933ae1a35d5e327ffe6e4bebfbe203\Act.Outlook.Service.Shared.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Service#\d5553a03158fc068ef0dbe6d5c304eec\Act.Outlook.Service.Interfaces.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Service#\47f5ffdc2f3fd4e442e04ba6fd73dbf0\Act.Outlook.Service.Desktop.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Service#\bfb1f546392cfe620495e583ea620f10\Act.Outlook.Service.AppCommon.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Integra#\c81ea0fd5abfbd5a1e18bec3d9cb1931\Act.Outlook.Integration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Framework\7cf101c871265a51b7aac1818d8a54ad\Act.Framework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\d507b9e0e50e453793ee5e01c07a5485\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_51a2442a\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_746f0387\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_a7bc458b\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_f24bf17b\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_502c4886\system.dll ()
MOD - c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Shared.Sync\14.0.572.0__ebf6b2ff4d0a08aa\Act.Shared.Sync.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Shared.Utilities\14.0.572.0__ebf6b2ff4d0a08aa\Act.Shared.Utilities.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Shared.Diagnostics\14.0.572.0__ebf6b2ff4d0a08aa\Act.Shared.Diagnostics.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Win.Integration\14.0.572.0__ebf6b2ff4d0a08aa\Act.Outlook.Win.Integration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.Interfaces\14.0.572.0__ebf6b2ff4d0a08aa\Act.Outlook.Service.Interfaces.dll ()
MOD - C:\Program Files\Jungle Disk Workgroup\monitor_images.dll ()
MOD - C:\Program Files\Voltage Security\Voltage SecureMail\VSHookZFRShim.dll ()
MOD - C:\Program Files\Voltage Security\Voltage SecureFile\VSFShellHookShim.dll ()
MOD - C:\Program Files\Common Files\Voltage Security\VSLog_com.dll ()
MOD - C:\Program Files\Common Files\Voltage Security\VSCOM2.dll ()
MOD - C:\Program Files\Common Files\Voltage Security\VSAgent.exe ()
MOD - C:\Program Files\Common Files\Voltage Security\VSzlib1.dll ()
MOD - C:\Program Files\Common Files\Voltage Security\vslibxml2.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\zlib1.dll ()
MOD - C:\WINDOWS\system32\custmon2k.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) -- File not found
SRV - (QBCFMonitorService) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (GoToMyPC) -- C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (Sage ACT! Scheduler) -- C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe (Sage Software, Inc.)
SRV - (ActService) -- C:\Program Files\ACT\Act for Windows\Act.Server.Host.exe (Microsoft)
SRV - (QBVSS) -- C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
SRV - (PSI_SVC_2) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (arvato digital services llc)
SRV - (JungleDiskWorkgroupService) -- C:\Program Files\Jungle Disk Workgroup\JungleDiskWorkgroup.exe (Jungle Disk, Inc.)
SRV - (Symantec AntiVirus) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (QBFCService) -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (APC UPS Service) -- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)


========== Driver Services (SafeList) ==========

DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20120104.017\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20120104.017\NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) -- C:\WINDOWS\system32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (AnyDVD) -- C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (cbfs3) -- C:\WINDOWS\system32\drivers\cbfs3.sys (EldoS Corporation)
DRV - (RsFx0150) -- C:\WINDOWS\system32\drivers\RsFx0150.sys (Microsoft Corporation)
DRV - (WPS) -- C:\WINDOWS\system32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) -- C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (COH_Mon) -- C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (Teefer2) -- C:\WINDOWS\system32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (SCR3xx USB Smart Card Reader) -- C:\WINDOWS\system32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (atiide) -- C:\WINDOWS\system32\DRIVERS\atiide.sys (ATI Technologies Inc.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (SenFiltService) -- C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061121
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061121

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061121
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.co...html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co...html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@voltage.com/MozillaTokenHandler;version=1: C:\Program Files\Common Files\Voltage Security\npvsth.dll (Voltage Security)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/13 14:56:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/03/14 11:31:31 | 000,000,000 | ---D | M]

[2010/01/08 09:07:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009/06/13 12:34:06 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/10/25 20:56:33 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/12/28 09:43:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2009/10/11 04:17:27 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2006/10/26 20:12:16 | 000,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL

Hosts file not found
O2 - BHO: (Virtual Storage Mount Notification) - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile) - {D5233FCD-D258-4903-89B8-FB1568E7413D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Act! Preloader] C:\Program Files\ACT\Act for Windows\ActSage.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [Act.Outlook.Service] C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [ATT-SST_McciTrayApp] "C:\Program Files\ATT-SST\McciTrayApp.exe" File not found
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DVDLauncher] C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NWEReboot] File not found
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [Synchronization Manager] C:\WINDOWS\System32\mobsync.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" File not found
O4 - HKCU..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk = C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Jungle Disk Workgroup.lnk = C:\Program Files\Jungle Disk Workgroup\JungleDiskWorkgroup.exe (Jungle Disk, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk = C:\Program Files\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sage ACT! Integration.lnk = C:\Program Files\ACT\Act for Windows\Sage.ACT.Integration.exe (Sage Software, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SentriLockCardUtility.lnk = C:\WINDOWS\Installer\{03792636-ED5B-4CD3-A93B-19BC2C18F8F8}\Icon037926361.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Voltage Encryption Manager.lnk = C:\Program Files\Common Files\Voltage Security\VSManager2.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\System32\nwprovau.dll File not found
O15 - HKCU\..Trusted Domains: motive.com ([pattta.att] https in Trusted sites)
O15 - HKCU\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell....iler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} http://www.alternati.../00/alttiff.cab (AlternaTIFF ActiveX)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1261981436673 (MUWebControl Class)
O16 - DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F127} http://www.swiftview...stall_green.exe (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.micros...ntent/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = arroyoview.local
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files\Intuit\QuickBooks 2011\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-vs-authtoken {1F17617E-C296-4C16-89E3-E22C6C454645} - C:\Program Files\Common Files\Voltage Security\VSTokenHandler.dll ()
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) -C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) -C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") -C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - (%SystemRoot%\System32\dimsntfy.dll) - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\GoToMyPC: DllName - (C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll) - C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (WgaLogon.dll) - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {3F5D957F-979C-4733-9EAE-93791A8E2131} - C:\Program Files\Voltage Security\Voltage SecureFile\VSFShellHookShim.dll ()
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {8E18BB3C-EF56-4294-8DFF-FED6F11ACDBE} - C:\Program Files\Voltage Security\Voltage SecureMail\VSHookZFRShim.dll ()
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) -C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) -C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) -C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) -C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) -C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) -C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) -C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) -C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) -C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 15:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/05/11 14:13:39 | 000,000,279 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{d6a0a481-9079-11db-8e73-00188b7844ab}\Shell - "" = AutoRun
O33 - MountPoints2\{d6a0a481-9079-11db-8e73-00188b7844ab}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d6a0a481-9079-11db-8e73-00188b7844ab}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- [2006/04/18 14:33:36 | 000,950,272 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/05 19:59:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\DKullman\Desktop\Virus Removal Software
[2012/01/05 19:58:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\DKullman\Desktop\Tidserv Virus
[2012/01/04 22:41:12 | 000,167,936 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\wpshelper.sys
[2012/01/04 22:39:15 | 000,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2012/01/04 22:39:14 | 000,124,976 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/01/04 22:38:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Symantec Endpoint Protection
[2012/01/04 22:38:31 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2012/01/04 10:20:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\DKullman\Local Settings\Application Data\NPE
[2012/01/04 10:20:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2012/01/04 09:05:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\DKullman\Desktop\Virus Removal Tools
[2012/01/04 02:26:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2012/01/04 00:47:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/04 00:47:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/10/03 20:24:37 | 002,124,656 | ---- | C] (Sage Software ) -- C:\Documents and Settings\DKullman\Application Data\ACT2012HotFix_SS.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/05 20:00:16 | 000,000,428 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Backup.job
[2012/01/05 09:52:45 | 000,002,827 | ---- | M] () -- C:\WINDOWS\winpoint.ini
[2012/01/05 09:47:32 | 000,002,361 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SentriLockCardUtility.lnk
[2012/01/05 09:46:56 | 000,002,335 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2012/01/05 09:45:39 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/05 09:40:03 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/05 09:39:38 | 3453,980,672 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/05 09:33:10 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/04 22:39:35 | 000,124,976 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/01/04 22:39:35 | 000,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2012/01/04 22:39:35 | 000,007,456 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/01/04 22:39:35 | 000,000,806 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/01/04 17:34:29 | 000,000,610 | ---- | M] () -- C:\Documents and Settings\DKullman\Desktop\ACT!.lnk
[2012/01/04 11:44:27 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2012/01/04 10:59:39 | 006,975,770 | ---- | M] () -- C:\Documents and Settings\DKullman\Application Data\SMRBackup210.dat
[2012/01/02 19:22:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/12/31 22:40:09 | 000,000,477 | ---- | M] () -- C:\Documents and Settings\DKullman\Desktop\Shortcut to c$ on Home Office Computer (kullman-server).lnk
[2011/12/31 22:39:41 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011/12/31 22:39:40 | 000,008,192 | ---- | M] () -- C:\Documents and Settings\DKullman\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/31 22:39:11 | 000,000,477 | ---- | M] () -- C:\Documents and Settings\DKullman\Desktop\Shortcut to e$ on Home Office Computer (kullman-server).lnk
[2011/12/31 18:51:42 | 000,000,125 | ---- | M] () -- C:\Documents and Settings\DKullman\default.pls
[2011/12/31 13:05:47 | 000,000,796 | ---- | M] () -- C:\Documents and Settings\DKullman\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/31 12:48:07 | 000,000,090 | ---- | M] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2011/12/23 16:35:01 | 000,286,904 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/23 15:15:32 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/12/16 13:47:16 | 000,000,015 | ---- | M] () -- C:\WINDOWS\DatabaseID
[2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/04 22:39:14 | 000,007,456 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/01/04 22:39:14 | 000,000,806 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/01/04 16:29:31 | 006,975,770 | ---- | C] () -- C:\Documents and Settings\DKullman\Application Data\SMRBackup210.dat
[2012/01/04 11:23:24 | 3453,980,672 | -HS- | C] () -- C:\hiberfil.sys
[2012/01/04 01:19:37 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/12/31 13:05:47 | 000,000,796 | ---- | C] () -- C:\Documents and Settings\DKullman\Desktop\Malwarebytes Anti-Malware.lnk
[2011/08/17 21:42:44 | 000,266,327 | ---- | C] () -- C:\WINDOWS\System32\ADErrorHandling.dll
[2011/01/08 13:11:34 | 000,051,984 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/07 23:11:36 | 000,000,090 | ---- | C] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2010/01/25 10:58:06 | 000,462,848 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
[2010/01/07 21:24:36 | 000,000,038 | ---- | C] () -- C:\WINDOWS\camcodec100.ini
[2010/01/07 21:20:56 | 000,695,578 | ---- | C] () -- C:\WINDOWS\System32\unins000.exe
[2010/01/07 21:20:56 | 000,001,082 | ---- | C] () -- C:\WINDOWS\System32\unins000.dat
[2010/01/07 11:19:48 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010/01/07 11:19:46 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\DKullman\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/20 09:07:11 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2009/10/24 13:13:34 | 000,000,040 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/05/18 19:27:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/16 13:59:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PNTINFO.INI
[2008/05/16 11:26:18 | 000,021,504 | ---- | C] () -- C:\WINDOWS\jestertb.dll
[2008/02/06 12:26:34 | 000,000,115 | ---- | C] () -- C:\Documents and Settings\DKullman\Application Data\sview.ini
[2008/02/06 12:25:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\srfvdo.dat
[2008/01/29 16:34:40 | 000,000,287 | ---- | C] () -- C:\WINDOWS\DESI.INI
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/09/12 12:53:38 | 000,000,232 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2007/08/24 10:50:24 | 000,010,875 | ---- | C] () -- C:\WINDOWS\ESOA.INI
[2007/08/24 10:50:24 | 000,000,053 | ---- | C] () -- C:\WINDOWS\PRSRVDLL.INI
[2007/08/02 16:48:04 | 000,000,079 | ---- | C] () -- C:\WINDOWS\Syn252.ini
[2007/07/02 12:47:10 | 000,000,165 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2007/03/19 12:02:50 | 000,000,058 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\mchguid.ini
[2007/02/12 14:12:02 | 000,001,759 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/07 14:45:47 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\custmon2k.dll
[2007/02/07 14:45:47 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\uninstpw.exe
[2007/02/07 11:40:01 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\DKullman\Local Settings\Application Data\fusioncache.dat
[2006/12/08 10:14:49 | 000,000,056 | ---- | C] () -- C:\WINDOWS\tiger.ini
[2006/12/07 13:55:31 | 000,000,058 | ---- | C] () -- C:\WINDOWS\mchguid.ini
[2006/12/07 13:42:22 | 000,002,827 | ---- | C] () -- C:\WINDOWS\winpoint.ini
[2006/12/05 16:53:11 | 000,192,590 | ---- | C] () -- C:\WINDOWS\System32\ActExt.dll
[2006/12/05 16:53:11 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ActAB32.dll
[2006/12/05 12:44:26 | 000,000,243 | ---- | C] () -- C:\WINDOWS\ActiveAct.INI
[2006/12/05 11:59:20 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\EmailShared.dll
[2006/12/04 14:28:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2006/11/20 22:54:55 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/11/20 22:49:34 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/11/20 22:18:40 | 000,129,112 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/11/20 22:18:27 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe
[2006/11/20 22:17:40 | 000,000,389 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/11 15:24:19 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/11 15:19:30 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/11 15:12:14 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 15:11:31 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 15:07:24 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/11 15:06:43 | 000,286,904 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 15:00:30 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/11 15:00:28 | 000,532,574 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/11 15:00:28 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/11 15:00:28 | 000,104,782 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/11 15:00:28 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/11 15:00:27 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/11 15:00:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/11 15:00:24 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/11 15:00:19 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/11 15:00:19 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/11 15:00:12 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/11 15:00:04 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin

========== LOP Check ==========

[2011/10/03 20:42:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACT
[2010/08/26 17:13:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CitrixLogs
[2011/01/07 23:11:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2011/04/07 22:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JungleDisk
[2011/06/24 10:40:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/01/07 23:12:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nuance
[2011/10/03 20:41:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sage Software, Inc
[2010/05/25 20:32:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SentriLock
[2009/10/24 13:13:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2011/01/08 13:04:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2011/09/30 08:22:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/02/07 14:45:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\24U
[2011/10/03 20:51:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\ACT
[2009/10/23 12:38:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\Calyx Software
[2009/04/26 09:05:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\FileMaker
[2011/10/03 20:48:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\IsolatedStorage
[2007/02/07 14:46:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\net.dacons.mail.it
[2008/11/18 15:11:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\OfficeUpdate12
[2010/05/25 20:35:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\SentriLock
[2012/01/05 14:44:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\Voltage
[2010/07/28 08:49:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\webex
[2009/12/29 16:53:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\Windows Desktop Search
[2010/01/07 14:11:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\Windows Search
[2012/01/02 19:22:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2012/01/05 20:00:16 | 000,000,428 | ---- | M] () -- C:\WINDOWS\Tasks\SyncBack Backup.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C41CE1F6

< End of report >

OTL Extras logfile created on: 1/5/2012 8:10:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\DKullman\Desktop\Virus Removal Software\Old Timer
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.22 Gb Total Physical Memory | 2.28 Gb Available Physical Memory | 71.00% Memory free
7.88 Gb Paging File | 7.08 Gb Available in Paging File | 89.87% Paging File free
Paging file location(s): C:\pagefile.sys 4939 8200 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 18.12 Gb Free Space | 24.33% Space Free | Partition Type: NTFS
Drive F: | 5.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 973.17 Mb Total Space | 909.52 Mb Free Space | 93.46% Space Free | Partition Type: FAT

Computer Name: WORKSTATION3NEW | User Name: DKullman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Credit Money Machine Net\Credit Money Machine Net.exe" = C:\Program Files\Credit Money Machine Net\Credit Money Machine Net.exe:*:Enabled:FileMaker Pro Runtime -- (FileMaker, Inc.)
"\\SERVERAD\Installs\Credit Money Machine Net\Credit Money Machine Net.exe" = \\SERVERAD\Installs\Credit Money Machine Net\Credit Money Machine Net.exe:*:Enabled:FileMaker Pro Runtime
"C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe" = C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:*:Enabled:SMC Service -- (Symantec Corporation)
"C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE" = C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:*:Enabled:SNAC Service -- (Symantec Corporation)
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email -- (Symantec Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Intuit\QuickBooks 2011\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks 2011\QBDBMgrN.exe:*:Enabled:QuickBooks 2011 Data Manager -- (Intuit, Inc.)
"C:\Program Files\ACT\Act for Windows\ActSage.exe" = C:\Program Files\ACT\Act for Windows\ActSage.exe:*:Enabled:ActSage -- (Sage Software, Inc.)
"C:\Program Files\ACT\Act for Windows\ActEmail.exe" = C:\Program Files\ACT\Act for Windows\ActEmail.exe:*:Enabled:ActEmail -- (Sage Software, Inc)
"C:\Program Files\ACT\Act for Windows\Act14.exe" = C:\Program Files\ACT\Act for Windows\Act14.exe:*:Enabled:Act14 -- (Sage Software, Inc.)
"C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" = C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe:*:Enabled:PsiService_2 -- (arvato digital services llc)
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" = C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe:*:Enabled:sqlbrowser -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\ACT\ActUpdt.exe" = C:\Program Files\ACT\ActUpdt.exe:*:Enabled:ACT! Update -- (Interact Commerce Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03792636-ED5B-4CD3-A93B-19BC2C18F8F8}" = Sentrilock Card Utility
"{0A48F047-5D01-463F-A732-DE75D224034B}" = Point
"{11E0AC7D-6822-4F67-865F-EE1C13D28C38}" = QuickBooks Pro 2011
"{13D3698D-70EA-46DD-A303-7B0346D75ADA}" = Point 7.3
"{14374622-0900-4056-BA06-C87C900AF9E6}" = QuickBooks Pro 2005
"{1D70AABC-CB59-4700-A708-EA56D1CA07B0}" = QuickBooks
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 26
"{2EFCC193-D915-4CCB-9201-31773A27BC06}" = Symantec Endpoint Protection
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{357F75A5-CADA-42E3-8B16-3F3EDD431141}" = Point
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{47BE41E6-2F0F-4D17-9C2D-3850FFD9D405}" = Microsoft SQL Server VSS Writer
"{4837C529-BBBB-47E3-95FC-70C69C003120}" = Jungle Disk Workgroup
"{4AB6A079-178B-4144-B21F-4D1AE71666A2}" = Microsoft SQL Server 2008 R2 Native Client
"{4C9D82EB-9001-4E59-8F64-0BEEE5F4A30A}" = SQL Server 2008 R2 Database Engine Shared
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = SQL Server 2008 R2 Database Engine Services
"{58F4D4FD-1814-4068-B316-C28FC776C6DD}" = GoToMyPC
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}" = APC PowerChute Personal Edition
"{5B7D68A3-C39B-4BC5-BDF1-22085290C43C}" = Point 6.1
"{5FE545A1-D215-4216-9189-E7B39C9D1CC1}" = Quicken 2011
"{612B9183-67A9-4B44-9877-2F059E35B86A}" = Broadcom 440x 10/100 Integrated Controller
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD OD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{72DE3C67-FB48-450E-8BEA-4EB1B3B5355D}" = Microsoft SQL Server 2008 R2 Setup (English)
"{7C8EAD2B-A954-4F73-AAFC-C3EC60D49ADA}" = Microsoft SQL Server 2008 R2 RsFx Driver
"{7D3A6B8F-45C1-4814-967E-6D84BBB868CD}" = ATI Catalyst Control Center
"{896D642C-7125-44F0-AC49-A23ABF82209C}" = CDBurnerXP Pro 3
"{89B44DBB-9F91-4541-839F-67024172CCF0}" = Sage ACT! Premium 2012
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{8DDB7719-21CF-4449-BECE-3B2A1C416B6A}" = Point 7.4 SP5
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_OUTLOOKSTD_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_OUTLOOKSTD_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_OUTLOOKSTD_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_OUTLOOKSTD_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_OUTLOOKSTD_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00E0-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2007
"{90120000-00E0-0000-0000-0000000FF1CE}_OUTLOOKSTD_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00E0-0000-0000-0000000FF1CE}_OUTLOOKSTD_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_OUTLOOKSTD_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91490409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Primary Interop Assemblies
"{93998800-1608-403F-9A51-420A77D23C25}" = Sql Server Customer Experience Improvement Program
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9733A34B-4241-4C75-9A17-35A4E8766BB0}" = Voltage Encryption 4.1.3
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = SQL Server 2008 R2 Database Engine Services
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{BF9BF038-FE03-429D-9B26-2FA0FD756052}" = Microsoft SQL Server Browser
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CAA73495-D542-4BD2-B2F2-886C316868C7}" = Calyx LoanBridge 5.3
"{CACEA8C8-3D38-4F51-953D-1E6FC3346FEF}" = SQL Server 2008 R2 Common Files
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3A80508-CD83-4CA3-8671-914A1BC78B61}" = Microsoft Sync Framework 2.0 Provider Services (x86) ENU
"{D441BD04-E548-4F8E-97A4-1B66135BAAA8}" = Microsoft SQL Server 2008 Setup Support Files
"{D6C35F0E-D09D-4177-BAEE-4D412D749A96}" = Point
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{F021CC0C-21C3-4038-AA4A-6E3CBC669CE8}" = SQL Server 2008 R2 Database Engine Shared
"{F2E0640D-BEB8-4E14-8C97-71D5C7A29844}" = Point
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F398D45A-300F-486B-BC4E-6E2066F6DA10}" = Point 7.4 SP6
"{F3CA9611-CD42-4562-ADAB-A554CF8E17F1}" = Microsoft WSE 2.0 SP3 Runtime
"{F751F153-0D23-4ED5-85D5-BAE46893D1F9}" = Point
"{F90D6825-8F1F-4E3A-9E42-A9C8A9DD1033}" = Nero 7 Ultra Edition
"{FC835376-FF3B-4CAA-83E0-2148B3FB7C98}" = SQL Server 2008 R2 Common Files
"{FF63121D-91C6-42CC-B341-F1AA729728E7}" = Microsoft Sync Framework 2.0 Core Components (x86) ENU
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"ABCPDFwriter" = ABCPDFwriter
"ACT!" = ACT!
"ActiveTouchMeetingClient" = WebEx
"Adobe Acrobat 7.0 Professional" = Adobe Acrobat 7.1.0 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AnyDVD" = AnyDVD
"ATI Display Driver" = ATI Display Driver
"C4B4D7F5499921DF57A4F6B55E59E0F50C2FE298" = Windows Driver Package - SCM Microsystems Inc. (SCR3xx USB Smart Card Reader) SmartCardReader (11/07/2006 4.35.00.01)
"CamStudio" = CamStudio
"CamStudio Lossless Codec_is1" = CamStudio Lossless Codec v1.4
"Credit Money Machine Net_is1" = Credit Money Machine Net
"CustomPrint" = CustomPrint
"DVD Shrink_is1" = DVD Shrink 3.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{89B44DBB-9F91-4541-839F-67024172CCF0}" = Sage ACT! Premium 2012
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 R2
"Microsoft SQL Server 2008 R2" = Microsoft SQL Server 2008 R2
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Microsoft Visual Studio 2005 Tools for Office Runtime
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OUTLOOKSTD" = Microsoft Office Outlook 2007
"SnagIt5" = SnagIt 5
"SyncBack_is1" = SyncBack
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"2c777a09c05bdfb6" = Point
"2f8d25aeed0b3ae4" = Sage Download Manager
"f031ef6ac137efc5" = Dell Driver Download Manager
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Point" = Point

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/5/2012 1:38:09 PM | Computer Name = WORKSTATION3NEW | Source = Userenv | ID = 1053
Description = Windows cannot determine the user or computer name. (The RPC protocol
sequence is not supported. ). Group Policy processing aborted.

Error - 1/5/2012 1:41:06 PM | Computer Name = WORKSTATION3NEW | Source = JungleDiskWorkgroupService | ID = 2
Description = Jungle Disk Workgroup has not been configured.

Error - 1/5/2012 1:43:26 PM | Computer Name = WORKSTATION3NEW | Source = Sage ACT! Scheduler | ID = 0
Description = Service cannot be started. System.Exception: Unable to start scheduler
service. ScheduledItems count is less than or equal to 0. at Act.Scheduler.SchedulerService.OnStart(String[]
args) at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 1/5/2012 1:45:09 PM | Computer Name = WORKSTATION3NEW | Source = Userenv | ID = 1053
Description = Windows cannot determine the user or computer name. (The RPC protocol
sequence is not supported. ). Group Policy processing aborted.

Error - 1/5/2012 1:45:11 PM | Computer Name = WORKSTATION3NEW | Source = Userenv | ID = 1053
Description = Windows cannot determine the user or computer name. (The RPC protocol
sequence is not supported. ). Group Policy processing aborted.

Error - 1/5/2012 1:53:59 PM | Computer Name = WORKSTATION3NEW | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 1/5/2012 1:53:59 PM | Computer Name = WORKSTATION3NEW | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 1/5/2012 1:53:59 PM | Computer Name = WORKSTATION3NEW | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 1/5/2012 9:40:06 PM | Computer Name = WORKSTATION3NEW | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 1/6/2012 12:03:44 AM | Computer Name = WORKSTATION3NEW | Source = SescLU | ID = 13
Description =

[ OSession Events ]
Error - 5/28/2010 11:43:31 PM | Computer Name = WORKSTATION3NEW | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 27347
seconds with 240 seconds of active time. This session ended with a crash.

Error - 7/9/2010 3:36:57 AM | Computer Name = WORKSTATION3NEW | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1007652
seconds with 2880 seconds of active time. This session ended with a crash.

Error - 8/28/2010 6:31:35 AM | Computer Name = WORKSTATION3NEW | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 109316
seconds with 360 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 1/5/2012 3:01:14 PM | Computer Name = WORKSTATION3NEW | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 1/5/2012 3:02:45 PM | Computer Name = WORKSTATION3NEW | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 1/5/2012 3:04:16 PM | Computer Name = WORKSTATION3NEW | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 1/5/2012 3:05:46 PM | Computer Name = WORKSTATION3NEW | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 1/5/2012 3:07:17 PM | Computer Name = WORKSTATION3NEW | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 1/5/2012 3:08:48 PM | Computer Name = WORKSTATION3NEW | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 1/5/2012 3:10:18 PM | Computer Name = WORKSTATION3NEW | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 1/5/2012 4:34:55 PM | Computer Name = WORKSTATION3NEW | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 1/5/2012 5:46:00 PM | Computer Name = WORKSTATION3NEW | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain ARROYOVIEW due to the
following: %%1311. Make sure that the computer is connected to the network and try
again.
If the problem persists, please contact your domain administrator.

Error - 1/5/2012 10:46:00 PM | Computer Name = WORKSTATION3NEW | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain ARROYOVIEW due to the
following: %%1311. Make sure that the computer is connected to the network and try
again.
If the problem persists, please contact your domain administrator.


< End of report >
  • 0

Advertisements


#2
Crag_Hack

Crag_Hack

    Trusted Helper

  • Malware Removal
  • 1,839 posts
Hello and welcome to the Geeks to Go Virus, Spyware & Malware Removal forum. My name is Josh and I will be helping you remove your infection. I am only human not superman - I can make errors but will do my best to help you as best I can so we can solve your problems. Some of the following instructions to begin the malware removal process can be hard to follow - let me know if you have any questions. Please read all of my responses through at least once before attempting to follow the procedures described. I would recommend printing them out, if you can, as you can check off each step as you complete it. Also please do not attempt any disinfection procedures without my instruction as things can go wrong that way. One more thing - please refrain from using your computer until it is disinfected unless you absolutely have to - when you are using it the current malware infection could propagate further infections - forcing us to do a second or even third round of disinfection after the first. I will get back to you soon with disinfection instructions.
  • 0

#3
DKullman

DKullman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hi Josh,

Thanks for the reply. I am using another computer to communicate with you and have disconnected the infected computer from the network entirely. I appreciate your willingness to help and look forward to working with you. Darrel
  • 0

#4
Crag_Hack

Crag_Hack

    Trusted Helper

  • Malware Removal
  • 1,839 posts
Hello DKullman. There are several suspicious files on your machine that might or might not be malware. We will scan them to verify. Let me know if you have any trouble following these instructions. Please do the following:

  • Go to this site
  • Click the browse button at the top of the page
  • Navigate to this file C:\WINDOWS\System32\custmon2k.dll and click the open button
  • Click the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button
  • Once the Scan is completed, click on the "Copy to Clipboard" button at the bottom of the page. This will copy the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Now repeat the above instructions but for the file C:\WINDOWS\setpwr32.exe this time.

We will now run a neat little utility to scan for some infections very prevalent these days.

  • Download aswMBR.exe ( 1870KB ) to your desktop.
  • Double click the aswMBR.exe to run it
  • It will ask you if you want to download the latest Avast! virus definitions, answer yes (it will be around 50 MB)
    Posted Image
  • Click the Scan button to start scan
    Posted Image
  • On completion of the scan click Save log, save it to your desktop and post in your next reply

That's it for now!
  • 0

#5
Crag_Hack

Crag_Hack

    Trusted Helper

  • Malware Removal
  • 1,839 posts
Forgot to mention you will have to reconnect your computer to the Internet temporarily to follow these steps.
  • 0

#6
DKullman

DKullman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hi Josh,

OK, first thing I did was open my IE8 browser. It started at my Google homepage. I typed http://virscan.org in the address bar and was redirected to this website:

Redirected webpage 01-10-2012 pt1.JPG

I then opened a new tab and was able to get to http://virscan.org. Here is the log from the C:\WINDOWS\System32\custmon2k.dll scan:

Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\DKullman>VirSCAN.org Scanned Report :
'VirSCAN.org' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Scanned time : 2012/01/10 23:54:58 (PST)
'Scanned' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Scanner results: Scanners did not find malwar
e!
'Scanner' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>File Name : custmon2k.dll
'File' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>File Size : 90112 byte
'File' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>File Type : PE32 executable for MS Windo
ws (DLL) (GUI) Intel 80386 32-bi
'File' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>MD5 : afaabcb753c057df2751d082abd5
27bc
'MD5' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>SHA1 : 1318e4c94b4dfb3046587d5ae869
436ebab960ca
'SHA1' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Online report : http://r.virscan.org/4a18648
313166f9d2886e66b0e0ae272
'Online' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>
C:\Documents and Settings\DKullman>Scanner Engine Ver Sig Ver
Sig Date Time Scan result
'Scanner' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>a-squared 5.1.0.4 20120111120227
2012-01-11 0.30 -
'a-squared' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>AhnLab V3 2012.01.11.00 2012.01.11
2012-01-11 2.89 -
'AhnLab' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>AntiVir 8.2.8.22 7.11.20.228
2012-01-11 0.25 -
'AntiVir' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Antiy 2.0.18 20120111.15666
815 2012-01-11 0.02 -
'Antiy' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Arcavir 2011 201201101418
2012-01-10 3.42 -
'Arcavir' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Authentium 5.1.1 201201110147
2012-01-11 1.44 -
'Authentium' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>AVAST! 4.7.4 120110-1
2012-01-10 0.01 -
'AVAST!' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>AVG 10.0.1405 2090/4135
2012-01-10 0.08 -
'AVG' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>BitDefender 7.90123.7945748 7.40549
2012-01-11 4.07 -
'BitDefender' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>ClamAV 0.97.1 14291
2012-01-11 0.04 -
'ClamAV' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Comodo 5.1 11236
2012-01-10 2.13 -
'Comodo' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>CP Secure 1.3.0.5 2012.01.11
2012-01-11 0.07 -
'CP' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Dr.Web 7.0.0.11250 2012.01.11
2012-01-11 11.25 -
'Dr.Web' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>F-Prot 4.6.2.117 20120111
2012-01-11 0.77 -
'F-Prot' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>F-Secure 7.02.73807 2012.01.10.04
2012-01-10 3.49 -
'F-Secure' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Fortinet 4.2.257 15.82
2012-01-10 0.11 -
'Fortinet' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>GData 22.3432 20120111
2012-01-11 4.75 -
'GData' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>ViRobot 20120110 2012.01.10
2012-01-10 0.37 -
'ViRobot' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Ikarus T3.1.32.20.0 2012.01.11.802
02 2012-01-11 5.02 -
'Ikarus' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>JiangMin 13.0.900 2011.11.26
2011-11-26 2.09 -
'JiangMin' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Kaspersky 5.5.10 2012.01.11
2012-01-11 0.19 -
'Kaspersky' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>KingSoft 2009.2.5.15 2012.1.11.9
2012-01-11 1.18 -
'KingSoft' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>McAfee 5400.1158 6585
2012-01-10 10.80 -
'McAfee' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Microsoft 1.7903 2012.01.10
2012-01-10 3.62 -
'Microsoft' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>NOD32 3.0.21 6777
2012-01-08 0.02 -
'NOD32' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Panda 9.05.01 2012.01.10
2012-01-10 2.43 -
'Panda' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Trend Micro 9.500-1005 8.702.02
2012-01-10 0.04 -
'Trend' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Quick Heal 11.00 2012.01.10
2012-01-10 1.00 -
'Quick' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Rising 20.0 23.92.02.01
2012-01-11 2.29 -
'Rising' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Sophos 3.27.0 4.73
2012-01-11 4.50 -
'Sophos' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Sunbelt 3.9.2525.2 11380
2012-01-10 0.78 -
'Sunbelt' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>Symantec 1.3.0.24 20120110.002
2012-01-10 0.07 -
'Symantec' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>nProtect 20120109.01 11897583
2012-01-09 1.26 -
'nProtect' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>The Hacker 6.7.0.1 v00375
2012-01-10 0.52 -
'The' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>VBA32 3.12.16.4 20120110.0721
2012-01-10 6.05 -
'VBA32' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>VirusBuster 5.4.0.10 14.1.160.0/737
45152012-01-11 0.02 -
'VirusBuster' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\DKullman>

Here is the log for the C:\WINDOWS\setpwr32.exe scan:

VirSCAN.org Scanned Report :
Scanned time : 2012/01/11 00:10:06 (PST)
Scanner results: 6% Scanner(s) (2/36) found malware!
File Name : setpwr32.exe
File Size : 77824 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : f83d2ea22cbac284c56d5ac4122ab5a3
SHA1 : 04fb6453fd1bd50428a2dff82cfa0408b79233b3
Online report : http://r.virscan.org...80c4dd6ef96216e

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.1.0.4 20120111120227 2012-01-11 1.46 -
AhnLab V3 2012.01.11.00 2012.01.11 2012-01-11 8.26 -
AntiVir 8.2.8.22 7.11.20.228 2012-01-11 0.31 -
Antiy 2.0.18 20120111.15666815 2012-01-11 0.02 -
Arcavir 2011 201201101418 2012-01-10 3.55 Trojan.Diple.Oho
Authentium 5.1.1 201201110147 2012-01-11 1.66 -
AVAST! 4.7.4 120110-1 2012-01-10 0.01 -
AVG 10.0.1405 2090/4135 2012-01-10 0.12 -
BitDefender 7.90123.7945748 7.40549 2012-01-11 4.29 -
ClamAV 0.97.1 14291 2012-01-11 0.03 -
Comodo 5.1 11236 2012-01-10 2.56 -
CP Secure 1.3.0.5 2012.01.11 2012-01-11 0.06 -
Dr.Web 7.0.0.11250 2012.01.11 2012-01-11 11.80 -
F-Prot 4.6.2.117 20120111 2012-01-11 0.92 -
F-Secure 7.02.73807 2012.01.10.04 2012-01-10 0.31 -
Fortinet 4.2.257 15.82 2012-01-10 0.16 -
GData 22.3432 20120111 2012-01-11 10.28 -
ViRobot 20120110 2012.01.10 2012-01-10 0.42 -
Ikarus T3.1.32.20.0 2012.01.11.80202 2012-01-11 5.74 -
JiangMin 13.0.900 2011.11.26 2011-11-26 1.97 -
Kaspersky 5.5.10 2012.01.11 2012-01-11 0.19 -
KingSoft 2009.2.5.15 2012.1.11.9 2012-01-11 0.98 -
McAfee 5400.1158 6585 2012-01-10 11.11 -
Microsoft 1.7903 2012.01.10 2012-01-10 18.81 -
NOD32 3.0.21 6777 2012-01-08 0.02 -
Panda 9.05.01 2012.01.10 2012-01-10 4.31 -
Trend Micro 9.500-1005 8.702.02 2012-01-10 0.22 -
Quick Heal 11.00 2012.01.10 2012-01-10 10.82 -
Rising 20.0 23.92.02.01 2012-01-11 0.76 -
Sophos 3.27.0 4.73 2012-01-11 4.70 -
Sunbelt 3.9.2525.2 11380 2012-01-10 0.97 -
Symantec 1.3.0.24 20120110.002 2012-01-10 1.66 -
nProtect 20120109.01 11897583 2012-01-09 13.94 -
The Hacker 6.7.0.1 v00375 2012-01-10 0.72 -
VBA32 3.12.16.4 20120110.0721 2012-01-10 4.93 Trojan.Diple.oho
VirusBuster 5.4.0.10 14.1.160.0/73745152012-01-11 0.01 -

I then downloaded and ran aswMBR.exe. The version is a little newer than the screenshot you sent me. I let it default to “Quickscan”. I was still connected to the internet during the scan with Symantec Endpoint running. The following screenshots show the sequence of events:

aswMBR Scan Log Part 1 01-10-2012 pt2.JPG
aswMBR Scan Log Part 2 01-10-2012 pt3.JPG
Endpoint Auto Protect 01-10-2012 pt4.JPG
Endpoint Auto Protect 01-10-2012 pt5.JPG
Endpoint Auto Protect 01-10-2012 pt6.JPG
Endpoint Auto Protect 01-10-2012 pt7.JPG
Endpoint Auto Protect 01-10-2012 pt8.JPG

I disconnected from the internet and have not rebooted the system. Here is the aswMBR.exe log:

aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-10 20:27:22
-----------------------------
20:27:22.125 OS Version: Windows 5.1.2600 Service Pack 3
20:27:22.125 Number of processors: 2 586 0x409
20:27:22.125 ComputerName: WORKSTATION3NEW UserName: dkullman
20:27:27.750 Initialize success
20:33:03.705 AVAST engine defs: 12011001
20:37:20.149 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3
20:37:20.149 Disk 0 Vendor: WDC_WD800JD-75MSA3 10.01E04 Size: 76293MB BusType: 3
20:37:20.165 Disk 0 MBR read successfully
20:37:20.165 Disk 0 MBR scan
20:37:20.399 Disk 0 Windows XP default MBR code
20:37:20.430 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
20:37:20.571 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76245 MB offset 80325
20:37:20.711 Disk 0 scanning sectors +156232125
20:37:20.883 Disk 0 scanning C:\WINDOWS\system32\drivers
20:37:37.956 File: C:\WINDOWS\system32\drivers\netbt.sys **INFECTED** Win32:Aluroot-B [Rtk]
20:37:48.327 Disk 0 trace - called modules:
20:37:48.358 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a89cea0]<<
20:37:48.358 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8afbfab8]
20:37:48.358 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> [0x8af06a28]
20:37:48.358 \Driver\00002102[0x8aee5f10] -> IRP_MJ_CREATE -> 0x8a89cea0
20:37:49.124 AVAST engine scan C:\WINDOWS
20:38:27.397 AVAST engine scan C:\WINDOWS\system32
20:41:28.954 AVAST engine scan C:\WINDOWS\system32\drivers
20:41:46.608 File: C:\WINDOWS\system32\drivers\netbt.sys **INFECTED** Win32:Aluroot-B [Rtk]
20:42:01.168 AVAST engine scan C:\Documents and Settings\DKullman
20:54:00.353 AVAST engine scan C:\Documents and Settings\All Users
21:01:14.563 Scan finished successfully
23:06:16.553 Disk 0 MBR has been saved successfully to "G:\Logs\MBR.dat"
23:06:16.585 The log file has been saved successfully to "G:\Logs\aswMBR Scan Log 01-10-2012.txt"

Here is the Symantec Endpoint Log:

Risk Filename Original Location Status Date
Trojan.Gen.2 unp227078300.tmp C:\Documents and Settings\DKullman\Local Settings\Temp\_avast4_\ Infected 1/10/2012 20:49
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:48
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:49
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:49
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:49
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:49
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:49
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:49
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:49
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:49
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:49
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:50
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:50
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:50
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:50
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:50
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:50
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:50
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:50
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:50
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:50
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:51
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:51
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:51
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:51
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:51
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:51
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:51
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:51
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:51
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:52
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:52
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:52
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:52
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:52
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:52
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:52
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:52
Trojan.Gen netbt.sys C:\WINDOWS\system32\drivers\ Infected 1/10/2012 21:52

Thanks Josh, Let me know what’s next. Darrel
  • 0

#7
Crag_Hack

Crag_Hack

    Trusted Helper

  • Malware Removal
  • 1,839 posts
Please refrain from restarting the system while I consult a colleague. Will almost certainly reply to you tomorrow.
  • 0

#8
DKullman

DKullman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
I have been disconnected from the internet since after the last scan, but the system has mysteriously re-booted itself. Do you want me to re-run the scans? Thanks Josh !

Edited by DKullman, 12 January 2012 - 10:28 AM.

  • 0

#9
Crag_Hack

Crag_Hack

    Trusted Helper

  • Malware Removal
  • 1,839 posts
Hello DKullman. The next step depends on whether or not you have Internet access on your infected computer now that netbt.sys might have been deleted. If you do still have Internet access on your computer (just browse to google or something simple to determine that) follow the instructions below. If not follow the instructions after the dividing line.

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now



----------------------------------------------------------------------------------------------



INSTRUCTIONS IF NO INTERNET ACCESS

Download the tools needed to a flash drive or other removable media, and transfer them to the infected computer.

Download ComboFix from one of the following locations:
Link 1
Link 2

With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before doing any malware removal.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Go here

Download the file & save it as it's originally named.

Transfer all files you just downloaded, to the desktop of the infected computer.

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

Posted Image

  • Drag the setup package onto ComboFix.exe and drop it.
  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.

    Posted Image
  • At the next prompt, click 'Yes' to run the full ComboFix scan.

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
  • 0

#10
DKullman

DKullman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hi Josh,

Downloaded ComboFix and Windows Recovery Console to a flash drive and then transferred to infected computer as instructed. I do not know if the infected computer is able to connect to the internet as I chose to install via option 2 and leave the computer disconnected from the net. I hope that is OK? I am a little paranoid at this point. I ran ComboFix and it seemed to run just fine rebooting the system a couple of times. Have not tried to re-connect to the internet yet. Will await instruction from you. Anyway, here are a couple of screenshots of what I saw and the ComboFix Logs:

ComboFix Run pt1 01-12-2012.JPG
ComboFix Run pt2 01-12-2012.JPG

ComboFix 12-01-12.04 - dkullman 01/12/2012 19:12:49.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3294.2477 [GMT -8:00]
Running from: c:\documents and settings\DKullman\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\DKullman\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: Symantec Endpoint Protection *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *Disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\ckelley\Application Data\24U
c:\documents and settings\DKullman\Application Data\24U
c:\documents and settings\DKullman\g2mdlhlpx.exe
c:\windows\$NtUninstallKB19512$
c:\windows\$NtUninstallKB19512$\2131243824\@
c:\windows\$NtUninstallKB19512$\2131243824\bckfg.tmp
c:\windows\$NtUninstallKB19512$\2131243824\cfg.ini
c:\windows\$NtUninstallKB19512$\2131243824\Desktop.ini
c:\windows\$NtUninstallKB19512$\2131243824\keywords
c:\windows\$NtUninstallKB19512$\2131243824\kwrd.dll
c:\windows\$NtUninstallKB19512$\2131243824\L\iahonoel
c:\windows\$NtUninstallKB19512$\2131243824\lsflt7.ver
c:\windows\$NtUninstallKB19512$\2131243824\U\00000001.@
c:\windows\$NtUninstallKB19512$\2131243824\U\00000002.@
c:\windows\$NtUninstallKB19512$\2131243824\U\00000004.@
c:\windows\$NtUninstallKB19512$\2131243824\U\80000000.@
c:\windows\$NtUninstallKB19512$\2131243824\U\80000004.@
c:\windows\$NtUninstallKB19512$\2131243824\U\80000032.@
c:\windows\$NtUninstallKB19512$\923185231
c:\windows\Downloaded Installations\BMP
c:\windows\Downloaded Installations\BMP\{3795247B-A089-4568-AAF7-E47D9285A9E9}\1033.MST
c:\windows\Downloaded Installations\BMP\{3795247B-A089-4568-AAF7-E47D9285A9E9}\BACS.msi
c:\windows\Downloaded Installations\BMP\{44C774BE-1389-4E84-B5DE-54D9FB4A2253}\1033.MST
c:\windows\Downloaded Installations\BMP\{44C774BE-1389-4E84-B5DE-54D9FB4A2253}\BACS.msi
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_FAD
.
.
((((((((((((((((((((((((( Files Created from 2011-12-13 to 2012-01-13 )))))))))))))))))))))))))))))))
.
.
2012-01-05 06:41 . 2011-07-09 00:44 167936 ----a-w- c:\windows\system32\drivers\wpshelper.sys
2012-01-05 06:39 . 2012-01-05 06:39 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2012-01-05 06:39 . 2012-01-05 06:39 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-01-05 06:38 . 2012-01-05 06:39 -------- d-----w- c:\program files\Symantec
2012-01-04 18:20 . 2012-01-04 19:44 -------- d-----w- c:\documents and settings\DKullman\Local Settings\Application Data\NPE
2012-01-04 18:20 . 2012-01-04 18:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2012-01-04 08:47 . 2012-01-04 08:47 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-10 23:24 . 2010-01-02 23:01 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-23 13:25 . 2004-08-11 23:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20 . 2004-08-11 23:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-11 23:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-11 23:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-11 23:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-08-11 23:00 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-11 23:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-08-11 23:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-04 04:59 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2004-08-11 23:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-15 21:14 . 2011-09-06 16:16 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay]
@="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}"
[HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}]
2010-06-10 06:16 155416 ----a-w- c:\windows\system32\CbFsMntNtf3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\JungleDiskWorkgroup1_Complete]
@="{78061A12-1E91-4446-8B65-8ED2FF328D4A}"
[HKEY_CLASSES_ROOT\CLSID\{78061A12-1E91-4446-8B65-8ED2FF328D4A}]
2010-09-24 19:12 818176 ----a-w- c:\program files\Jungle Disk Workgroup\monitor_shellext.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\JungleDiskWorkgroup2_InProgress]
@="{700AD13D-E86F-41C9-9A8F-39B4C438806F}"
[HKEY_CLASSES_ROOT\CLSID\{700AD13D-E86F-41C9-9A8F-39B4C438806F}]
2010-09-24 19:12 818176 ----a-w- c:\program files\Jungle Disk Workgroup\monitor_shellext.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\JungleDiskWorkgroup3_Conflicted]
@="{48C7A606-0F84-4DC8-8AFD-A157BDF18A08}"
[HKEY_CLASSES_ROOT\CLSID\{48C7A606-0F84-4DC8-8AFD-A157BDF18A08}]
2010-09-24 19:12 818176 ----a-w- c:\program files\Jungle Disk Workgroup\monitor_shellext.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SecureOfficeIconOverlay]
@="{419B6A44-1B3E-4AB2-A14D-5D1B95C57BA5}"
[HKEY_CLASSES_ROOT\CLSID\{419B6A44-1B3E-4AB2-A14D-5D1B95C57BA5}]
2009-06-19 00:49 287376 ----a-w- c:\program files\Voltage Security\Voltage SecureFile\SecureOfficeIconOverlay.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2010-07-27 4455360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2008-01-22 152872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-06-23 53248]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2011-09-30 2215768]
"Act.Outlook.Service"="c:\program files\ACT\Act for Windows\Act.Outlook.Service.exe" [2011-08-18 28672]
"Act! Preloader"="c:\program files\ACT\Act for Windows\ActSage.exe" [2011-08-18 337224]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-09 115560]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2010-1-21 25214]
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2007-2-6 221247]
Intuit Data Protect.lnk - c:\program files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe [2011-11-9 5923672]
Jungle Disk Workgroup.lnk - c:\program files\Jungle Disk Workgroup\JungleDiskWorkgroup.exe [2010-9-24 7204864]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2011-11-9 1156968]
QuickBooks_Standard_21.lnk - c:\program files\Intuit\QuickBooks 2011\QBW32.EXE [2011-11-9 1178984]
Sage ACT! Integration.lnk - c:\program files\ACT\Act for Windows\Sage.ACT.Integration.exe [2011-8-17 96768]
SentriLockCardUtility.lnk - c:\windows\Installer\{03792636-ED5B-4CD3-A93B-19BC2C18F8F8}\Icon037926361.exe [2010-5-25 84480]
Voltage Encryption Manager.lnk - c:\program files\Common Files\Voltage Security\VSManager2.exe [2009-6-18 1118864]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{8E18BB3C-EF56-4294-8DFF-FED6F11ACDBE}"= "c:\program files\Voltage Security\Voltage SecureMail\VSHookZFRShim.dll" [2009-06-19 152208]
"{3F5D957F-979C-4733-9EAE-93791A8E2131}"= "c:\program files\Voltage Security\Voltage SecureFile\VSFShellHookShim.dll" [2009-06-19 111248]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToMyPC]
2011-08-22 12:39 15216 ----a-w- c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ACT\\ActUpdt.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [11/20/2006 10:18 PM 3456]
R1 cbfs3;cbfs3;c:\windows\system32\drivers\cbfs3.sys [10/5/2010 11:47 AM 267208]
R2 ActService;ACT! Service Host;c:\program files\ACT\Act for Windows\Act.Server.Host.exe [8/17/2011 10:10 PM 18432]
R2 JungleDiskWorkgroupService;JungleDiskWorkgroupService;c:\program files\Jungle Disk Workgroup\JungleDiskWorkgroup.exe [9/24/2010 11:14 AM 7204864]
R2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe [5/5/2010 9:40 PM 42884448]
R2 QBVSS;QBIDPService;c:\program files\Common Files\Intuit\DataProtect\QBIDPService.exe [6/30/2011 12:25 PM 1248256]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/4/2012 10:56 PM 106104]
S2 Sage ACT! Scheduler;Sage ACT! Scheduler;c:\program files\ACT\Act for Windows\Act.Scheduler.exe [8/17/2011 10:18 PM 81920]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [7/14/2009 12:51 PM 23888]
S3 SCR3xx USB Smart Card Reader;SCR3xx USB Smart Card Reader;c:\windows\system32\drivers\SCR3XX2K.sys [5/25/2010 8:33 PM 47488]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [5/5/2010 9:41 PM 44896]
S4 RsFx0150;RsFx0150 Driver;c:\windows\system32\drivers\RsFx0150.sys [4/3/2010 10:02 AM 240608]
S4 SQLAgent$ACT7;SQL Server Agent (ACT7);c:\program files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\SQLAGENT.EXE [5/5/2010 9:40 PM 367456]
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-13 c:\windows\Tasks\SyncBack Backup.job
- c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2007-02-07 23:16]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061121
uInternet Settings,ProxyOverride = <local>
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: motive.com\pattta.att
Trusted Zone: motive.com\patttbc.att
Filter: application/x-vs-authtoken - {1F17617E-C296-4C16-89E3-E22C6C454645} - c:\program files\Common Files\Voltage Security\VSTokenHandler.dll
DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F127} - hxxp://www.swiftview.com/product/public/svinstall_green.exe
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
HKLM-Run-NWEReboot - (no file)
HKLM-Run-ATT-SST_McciTrayApp - c:\program files\ATT-SST\McciTrayApp.exe
HKU-Default-RunOnce-AutoLaunch - c:\program files\Lavasoft\Ad-Aware\AutoLaunch.exe
Notify-NavLogon - (no file)
SafeBoot-Symantec Antvirus
AddRemove-Point - c:\winpoint\Uninstal.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-12 20:53
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"="a"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(908)
c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
c:\windows\system32\CbFsNetRdr3.dll
.
- - - - - - - > 'explorer.exe'(5212)
c:\windows\system32\WININET.dll
c:\program files\SlySoft\AnyDVD\ADvdDiscHlp.dll
c:\windows\system32\CbFsMntNtf3.dll
c:\program files\Jungle Disk Workgroup\monitor_shellext.dll
c:\program files\Voltage Security\Voltage SecureFile\SecureOfficeIconOverlay.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\CbFsNetRdr3.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\windows\System32\SCardSvr.exe
c:\program files\APC\APC PowerChute Personal Edition\mainserv.exe
c:\program files\Citrix\GoToMyPC\g2svc.exe
c:\program files\Citrix\GoToMyPC\g2comm.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Citrix\GoToMyPC\g2pre.exe
c:\program files\Citrix\GoToMyPC\g2tray.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\IoctlSvc.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\program files\APC\APC PowerChute Personal Edition\apcsystray.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\SentrilockCardUtility\SentriLockCardUtility.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Common Files\Voltage Security\VSAgent.exe
c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\QBMsgMgr.exe
.
**************************************************************************
.
Completion time: 2012-01-12 21:08:55 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-13 05:08
.
Pre-Run: 22,253,363,200 bytes free
Post-Run: 24,827,035,648 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 3FD9B71A558C27B47B042E0872992817

Thanks Josh, Let me know what's next. Darrel
  • 0

Advertisements


#11
Crag_Hack

Crag_Hack

    Trusted Helper

  • Malware Removal
  • 1,839 posts
Hi DKullman, it looks like Combofix confronted your infection. Now is time to see if it conquered it. Reenable your antivirus and firewall now and after every Combofix run to be safe. Please reconnect your computer to the Internet and test it out (you can just do some simple web browsing). If it doesn't work restart and then try again. If it still doesn't work follow these instructions (please refrain from screenshots during the combofix run - I fear it may interfere with the scan - if you get any just take note of what they say and then post in your next reply):

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
  • 0

#12
Crag_Hack

Crag_Hack

    Trusted Helper

  • Malware Removal
  • 1,839 posts
If the Internet does work again please use your computer a little bit and let me know if you are still experiencing any malware infection symptoms. If not we can proceed to final disinfection procedures. Yay! :)
  • 0

#13
DKullman

DKullman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hey Josh,

I have re-enabled Endpoint AV. I have internet access and can browse. My privacy settings where re-set to accept all cookies. I have re-set my privacy setting to medium high. My opening home tabs had been re-set to Google only. I had three other home pages set up before. I only browsed to CNBC’s home page and then Google and Yahoo’s home page before I noticed these setting were re-set that way. Opened word, and excel. Everything seems to be running very fast again. Let me know what’s next.

Thank you, Darrel

PS Now Windows want's to install a ton of security updates.

Edited by DKullman, 15 January 2012 - 12:03 AM.

  • 0

#14
Crag_Hack

Crag_Hack

    Trusted Helper

  • Malware Removal
  • 1,839 posts
Hi DKullman, we have one last little bit of malware to get rid of and then two scans to run to clean up remainders from the infection. Also one scan to make sure a system file is happy.

First please do the following to zap the last of the malware:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    
    @Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C41CE1F6
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Then post the produced log (it will be in C:\_OTL\MovedFiles with a filename beginning with the date)
  • Open OTL again and click the Quick Scan button. Post the log it produces as in your next reply as well. Make sure you grab the contents of this log before running the system file scan below as the system file scan will overwrite this log file.

Now for the system file scan:

  • Double click on the OTL icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the None button.
  • Paste this into the 'Custom Scans/Fixes' section:
    /md5start
    netbt.sys
    /md5stop
  • Click the Run Scan button. The scan wont take long.
  • When the scan completes, it will open a notepad window - OTL.Txt.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it in your topic

The following instructions are for running a scan using ESET anti-virus via an online implementation and a scan with Malwarebytes' Anti-Malware (they are free). These scans will find any remaining infections that aren't already cleaned.

Posted Image Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

Posted Image Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java :
Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Scroll to the middle of the page where it says Java SE 6 Update 30. Click the download button below where it says JRE
  • Click to accept the license agreement
  • Click the download link to the right of where it says Windows x86 Offline
  • Once downloaded install

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the options Scan unwanted applications and Enable Anti-Stealth technology (both under Advanced settings) are checked
  • Click Start (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

We're almost done. Hooray!
  • 0

#15
DKullman

DKullman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hey Josh,

OK I did everything. ESET quarantined some things and I didn’t know if you wanted me to delete them yet. Please let me know. Here are all the logs:

All processes killed
========== OTL ==========
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:C41CE1F6 .
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: ckelley
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78991 bytes
->Java cache emptied: 354840 bytes
->Flash cache emptied: 12804 bytes

User: Darrel Kullman
->Temp folder emptied: 16744689 bytes
->Temporary Internet Files folder emptied: 249924781 bytes
->Java cache emptied: 250848 bytes
->Flash cache emptied: 2844 bytes

User: Default User
->Temp folder emptied: 16384 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: DKullman
->Temp folder emptied: 1024 bytes
->Temporary Internet Files folder emptied: 165948801 bytes
->Java cache emptied: 4555 bytes
->Flash cache emptied: 821737 bytes

User: Dkullm~1

User: DRobinson
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78991 bytes
->Java cache emptied: 2393534 bytes
->Flash cache emptied: 1538831 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 5964 bytes
->Flash cache emptied: 34526 bytes

User: test
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 439 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 418.00 mb

Restore point Set: OTL Restore Point (0)

OTL by OldTimer - Version 3.2.31.0 log created on 01162012_093625

Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\DKullman\Local Settings\Temp\~DF4F1.tmp not found!
File\Folder C:\Documents and Settings\DKullman\Local Settings\Temp\~DF88DA.tmp not found!
File\Folder C:\Documents and Settings\DKullman\Local Settings\Temporary Internet Files\Content.Word\~WRF0005.tmp not found!
File\Folder C:\Documents and Settings\DKullman\Local Settings\Temporary Internet Files\Content.Word\~WRS0004.tmp not found!

Registry entries deleted on Reboot...


OTL Second Scan:


OTL logfile created on: 1/16/2012 10:11:05 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\DKullman\Desktop\Virus Removal Software\Old Timer
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.22 Gb Total Physical Memory | 2.33 Gb Available Physical Memory | 72.42% Memory free
7.88 Gb Paging File | 7.14 Gb Available in Paging File | 90.52% Paging File free
Paging file location(s): C:\pagefile.sys 4939 8200 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 23.31 Gb Free Space | 31.31% Space Free | Partition Type: NTFS
Drive F: | 5.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 973.17 Mb Total Space | 871.55 Mb Free Space | 89.56% Space Free | Partition Type: FAT

Computer Name: WORKSTATION3NEW | User Name: dkullman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\DKullman\Desktop\Virus Removal Software\Old Timer\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\Program Files\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Citrix\GoToMyPC\g2tray.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2pre.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2comm.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\ACT\Act for Windows\Sage.ACT.Integration.exe (Sage Software, Inc)
PRC - C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe (Sage Software, Inc.)
PRC - C:\Program Files\ACT\Act for Windows\Act.Server.Host.exe (Microsoft)
PRC - C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
PRC - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (arvato digital services llc)
PRC - C:\Program Files\Jungle Disk Workgroup\JungleDiskWorkgroup.exe (Jungle Disk, Inc.)
PRC - C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Voltage Security\VSManager2.exe ()
PRC - C:\Program Files\Common Files\Voltage Security\VSAgent.exe ()
PRC - C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe (SentriLock LLC)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe (American Power Conversion Corporation)
PRC - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Intuit\QuickBooks 2011\QBMAPILibrary.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\QBCompressor.DLL ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\mbpopup.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\boost_regex-vc90-mt-p-1_33.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\boost_serialization-vc90-mt-p-1_33.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\BackupLib.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\17902fdb0e0d3bc8b49bce693415fe7e\System.WorkflowServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\9ec7da53380a754b4ad97709df0dd7e7\System.ServiceModel.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\24331b719aa25ac2b21099e32232840c\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\29a2030900e91074446e9fadce2c8670\Microsoft.Practices.Unity.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\32a4fb229b569f461c061e8c78d49799\Microsoft.Practices.Unity.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\8e74526b90a406073e352590a0f5375d\Microsoft.Practices.ObjectBuilder2.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Interop.ADChronopher\5390dfe3f708253c14a48936a2e3434a\Interop.ADChronopher.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Genghis\829150d02bc643f86aa25986d1dbdf2e\Genghis.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\474a341340f687bcbd7777f2820a8c7a\SMDiagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\ceadaf3b3d017c7a1ef10a06f8009f6f\System.ServiceModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\d14065ede44df8e9b5d6b60c5ddccc69\System.IdentityModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6303e256d2ac0843c3e4c24172c90544\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.UI.SyncSetup\05c61258fc4f51d5a30d9b340f7a49e4\Act.UI.SyncSetup.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Windows.#\3f830ad41839685ecb7458588b43023a\Act.Shared.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Win32\b268962e1d5451ddac8d7ec57015bfb8\Act.Shared.Win32.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Images\020dbb59d9623c2a189948999b7f080b\Act.Shared.Images.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Config\878d8197a79ac647b06dadecdaa1c25b\Act.Shared.Config.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Sync.Co#\94058bcd82f4f3bf07e57ae8ab06b44f\Act.Outlook.Sync.Common.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Service#\41933ae1a35d5e327ffe6e4bebfbe203\Act.Outlook.Service.Shared.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Service#\d5553a03158fc068ef0dbe6d5c304eec\Act.Outlook.Service.Interfaces.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Service#\47f5ffdc2f3fd4e442e04ba6fd73dbf0\Act.Outlook.Service.Desktop.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Service#\bfb1f546392cfe620495e583ea620f10\Act.Outlook.Service.AppCommon.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Outlook.Integra#\c81ea0fd5abfbd5a1e18bec3d9cb1931\Act.Outlook.Integration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Framework\7cf101c871265a51b7aac1818d8a54ad\Act.Framework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\d507b9e0e50e453793ee5e01c07a5485\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_51a2442a\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_746f0387\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_a7bc458b\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_f24bf17b\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_502c4886\system.dll ()
MOD - c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Shared.Sync\14.0.572.0__ebf6b2ff4d0a08aa\Act.Shared.Sync.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Shared.Utilities\14.0.572.0__ebf6b2ff4d0a08aa\Act.Shared.Utilities.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Shared.Diagnostics\14.0.572.0__ebf6b2ff4d0a08aa\Act.Shared.Diagnostics.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Win.Integration\14.0.572.0__ebf6b2ff4d0a08aa\Act.Outlook.Win.Integration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.Interfaces\14.0.572.0__ebf6b2ff4d0a08aa\Act.Outlook.Service.Interfaces.dll ()
MOD - C:\Program Files\Jungle Disk Workgroup\monitor_images.dll ()
MOD - C:\Program Files\Voltage Security\Voltage SecureMail\VSHookZFRShim.dll ()
MOD - C:\Program Files\Voltage Security\Voltage SecureFile\VSFShellHookShim.dll ()
MOD - C:\Program Files\Common Files\Voltage Security\VSLog_com.dll ()
MOD - C:\Program Files\Common Files\Voltage Security\VSCOM2.dll ()
MOD - C:\Program Files\Common Files\Voltage Security\VSManager2.exe ()
MOD - C:\Program Files\Common Files\Voltage Security\VSAgent.exe ()
MOD - C:\Program Files\Common Files\Voltage Security\VSzlib1.dll ()
MOD - C:\Program Files\Common Files\Voltage Security\vslibxml2.dll ()
MOD - c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2011\zlib1.dll ()
MOD - C:\WINDOWS\system32\custmon2k.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) -- File not found
SRV - (QBCFMonitorService) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (GoToMyPC) -- C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (Sage ACT! Scheduler) -- C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe (Sage Software, Inc.)
SRV - (ActService) -- C:\Program Files\ACT\Act for Windows\Act.Server.Host.exe (Microsoft)
SRV - (QBVSS) -- C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
SRV - (PSI_SVC_2) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (arvato digital services llc)
SRV - (JungleDiskWorkgroupService) -- C:\Program Files\Jungle Disk Workgroup\JungleDiskWorkgroup.exe (Jungle Disk, Inc.)
SRV - (Symantec AntiVirus) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (QBFCService) -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (APC UPS Service) -- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)


========== Driver Services (SafeList) ==========

DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20120115.009\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20120115.009\NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) -- C:\WINDOWS\system32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (AnyDVD) -- C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (cbfs3) -- C:\WINDOWS\system32\drivers\cbfs3.sys (EldoS Corporation)
DRV - (RsFx0150) -- C:\WINDOWS\system32\drivers\RsFx0150.sys (Microsoft Corporation)
DRV - (WPS) -- C:\WINDOWS\system32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) -- C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (COH_Mon) -- C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (Teefer2) -- C:\WINDOWS\system32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (SCR3xx USB Smart Card Reader) -- C:\WINDOWS\system32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (atiide) -- C:\WINDOWS\system32\DRIVERS\atiide.sys (ATI Technologies Inc.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (SenFiltService) -- C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061121
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061121


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061121
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061121
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@voltage.com/MozillaTokenHandler;version=1: C:\Program Files\Common Files\Voltage Security\npvsth.dll (Voltage Security)


[2010/01/08 09:07:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2012/01/16 09:36:30 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Virtual Storage Mount Notification) - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Act! Preloader] C:\Program Files\ACT\Act for Windows\ActSage.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [Act.Outlook.Service] C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKU\.DEFAULT..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-18..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
O4 - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk = C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Jungle Disk Workgroup.lnk = C:\Program Files\Jungle Disk Workgroup\JungleDiskWorkgroup.exe (Jungle Disk, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk = C:\Program Files\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sage ACT! Integration.lnk = C:\Program Files\ACT\Act for Windows\Sage.ACT.Integration.exe (Sage Software, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SentriLockCardUtility.lnk = C:\WINDOWS\Installer\{03792636-ED5B-4CD3-A93B-19BC2C18F8F8}\Icon037926361.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Voltage Encryption Manager.lnk = C:\Program Files\Common Files\Voltage Security\VSManager2.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109\..Trusted Domains: motive.com ([pattta.att] https in Trusted sites)
O15 - HKU\S-1-5-21-2682579246-2760933382-2103505420-1109\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell....iler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} http://www.alternati.../00/alttiff.cab (AlternaTIFF ActiveX)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1261981436673 (MUWebControl Class)
O16 - DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F127} http://www.swiftview...stall_green.exe (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.micros...ntent/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = arroyoview.local
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files\Intuit\QuickBooks 2011\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Filter\application/x-vs-authtoken {1F17617E-C296-4C16-89E3-E22C6C454645} - C:\Program Files\Common Files\Voltage Security\VSTokenHandler.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToMyPC: DllName - (C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll) - C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {3F5D957F-979C-4733-9EAE-93791A8E2131} - C:\Program Files\Voltage Security\Voltage SecureFile\VSFShellHookShim.dll ()
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {8E18BB3C-EF56-4294-8DFF-FED6F11ACDBE} - C:\Program Files\Voltage Security\Voltage SecureMail\VSHookZFRShim.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 15:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/05/11 14:13:39 | 000,000,279 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/16 09:41:30 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/01/16 09:36:25 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/01/12 18:55:08 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/01/12 18:51:44 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/01/12 18:51:44 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/01/12 18:51:44 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/01/12 18:51:44 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/01/12 18:46:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/01/12 18:46:44 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/12 18:34:00 | 004,381,975 | R--- | C] (Swearware) -- C:\Documents and Settings\DKullman\Desktop\ComboFix.exe
[2012/01/05 19:59:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\DKullman\Desktop\Virus Removal Software
[2012/01/05 19:58:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\DKullman\Desktop\Tidserv Virus
[2012/01/04 22:41:12 | 000,167,936 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\wpshelper.sys
[2012/01/04 22:39:15 | 000,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2012/01/04 22:39:14 | 000,124,976 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/01/04 22:38:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Symantec Endpoint Protection
[2012/01/04 22:38:31 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2012/01/04 10:20:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\DKullman\Local Settings\Application Data\NPE
[2012/01/04 10:20:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2012/01/04 09:05:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\DKullman\Desktop\Virus Removal Tools
[2012/01/04 02:26:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2012/01/04 00:47:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/04 00:47:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/10/03 20:24:37 | 002,124,656 | ---- | C] (Sage Software ) -- C:\Documents and Settings\DKullman\Application Data\ACT2012HotFix_SS.exe

========== Files - Modified Within 30 Days ==========

[2012/01/16 09:50:48 | 000,002,361 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SentriLockCardUtility.lnk
[2012/01/16 09:50:33 | 000,002,335 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2012/01/16 09:49:36 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/16 09:46:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/16 09:46:34 | 3453,980,672 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/16 09:36:30 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2012/01/15 20:00:01 | 000,000,428 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Backup.job
[2012/01/12 18:55:12 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/01/12 18:50:37 | 000,000,364 | ---- | M] () -- C:\Documents and Settings\DKullman\Desktop\Shortcut to ComboFix.exe (2).lnk
[2012/01/12 18:33:58 | 004,381,975 | R--- | M] (Swearware) -- C:\Documents and Settings\DKullman\Desktop\ComboFix.exe
[2012/01/11 00:36:16 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/05 09:52:45 | 000,002,827 | ---- | M] () -- C:\WINDOWS\winpoint.ini
[2012/01/04 22:39:35 | 000,124,976 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/01/04 22:39:35 | 000,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2012/01/04 22:39:35 | 000,007,456 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/01/04 22:39:35 | 000,000,806 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/01/04 17:34:29 | 000,000,610 | ---- | M] () -- C:\Documents and Settings\DKullman\Desktop\ACT!.lnk
[2012/01/04 11:44:27 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2012/01/04 10:59:39 | 006,975,770 | ---- | M] () -- C:\Documents and Settings\DKullman\Application Data\SMRBackup210.dat
[2011/12/31 22:40:09 | 000,000,477 | ---- | M] () -- C:\Documents and Settings\DKullman\Desktop\Shortcut to c$ on Home Office Computer (kullman-server).lnk
[2011/12/31 22:39:41 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011/12/31 22:39:40 | 000,008,192 | ---- | M] () -- C:\Documents and Settings\DKullman\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/31 22:39:11 | 000,000,477 | ---- | M] () -- C:\Documents and Settings\DKullman\Desktop\Shortcut to e$ on Home Office Computer (kullman-server).lnk
[2011/12/31 18:51:42 | 000,000,125 | ---- | M] () -- C:\Documents and Settings\DKullman\default.pls
[2011/12/31 13:05:47 | 000,000,796 | ---- | M] () -- C:\Documents and Settings\DKullman\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/31 12:48:07 | 000,000,090 | ---- | M] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2011/12/23 16:35:01 | 000,286,904 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/23 15:15:32 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK

========== Files Created - No Company Name ==========

[2012/01/12 18:55:12 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2012/01/12 18:55:09 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/01/12 18:51:44 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/01/12 18:51:44 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/01/12 18:51:44 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/01/12 18:51:44 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/01/12 18:51:44 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/01/12 18:50:37 | 000,000,364 | ---- | C] () -- C:\Documents and Settings\DKullman\Desktop\Shortcut to ComboFix.exe (2).lnk
[2012/01/04 22:39:14 | 000,007,456 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/01/04 22:39:14 | 000,000,806 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/01/04 16:29:31 | 006,975,770 | ---- | C] () -- C:\Documents and Settings\DKullman\Application Data\SMRBackup210.dat
[2012/01/04 11:23:24 | 3453,980,672 | -HS- | C] () -- C:\hiberfil.sys
[2012/01/04 01:19:37 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/12/31 13:05:47 | 000,000,796 | ---- | C] () -- C:\Documents and Settings\DKullman\Desktop\Malwarebytes Anti-Malware.lnk
[2011/08/17 21:42:44 | 000,266,327 | ---- | C] () -- C:\WINDOWS\System32\ADErrorHandling.dll
[2011/01/08 13:11:34 | 000,051,984 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/07 23:11:36 | 000,000,090 | ---- | C] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2010/01/25 10:58:06 | 000,462,848 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
[2010/01/07 21:24:36 | 000,000,038 | ---- | C] () -- C:\WINDOWS\camcodec100.ini
[2010/01/07 21:20:56 | 000,695,578 | ---- | C] () -- C:\WINDOWS\System32\unins000.exe
[2010/01/07 21:20:56 | 000,001,082 | ---- | C] () -- C:\WINDOWS\System32\unins000.dat
[2010/01/07 11:19:48 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010/01/07 11:19:46 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\DKullman\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/20 09:07:11 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2009/10/24 13:13:34 | 000,000,040 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/05/18 19:27:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/16 13:59:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PNTINFO.INI
[2008/05/16 11:26:18 | 000,021,504 | ---- | C] () -- C:\WINDOWS\jestertb.dll
[2008/02/06 12:26:34 | 000,000,115 | ---- | C] () -- C:\Documents and Settings\DKullman\Application Data\sview.ini
[2008/02/06 12:25:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\srfvdo.dat
[2008/01/29 16:34:40 | 000,000,287 | ---- | C] () -- C:\WINDOWS\DESI.INI
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/09/12 12:53:38 | 000,000,232 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2007/08/24 10:50:24 | 000,010,875 | ---- | C] () -- C:\WINDOWS\ESOA.INI
[2007/08/24 10:50:24 | 000,000,053 | ---- | C] () -- C:\WINDOWS\PRSRVDLL.INI
[2007/08/02 16:48:04 | 000,000,079 | ---- | C] () -- C:\WINDOWS\Syn252.ini
[2007/07/02 12:47:10 | 000,000,165 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2007/03/19 12:02:50 | 000,000,058 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\mchguid.ini
[2007/02/12 14:12:02 | 000,001,759 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/07 14:45:47 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\custmon2k.dll
[2007/02/07 14:45:47 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\uninstpw.exe
[2007/02/07 11:40:01 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\DKullman\Local Settings\Application Data\fusioncache.dat
[2006/12/08 10:14:49 | 000,000,056 | ---- | C] () -- C:\WINDOWS\tiger.ini
[2006/12/07 13:55:31 | 000,000,058 | ---- | C] () -- C:\WINDOWS\mchguid.ini
[2006/12/07 13:42:22 | 000,002,827 | ---- | C] () -- C:\WINDOWS\winpoint.ini
[2006/12/05 16:53:11 | 000,192,590 | ---- | C] () -- C:\WINDOWS\System32\ActExt.dll
[2006/12/05 16:53:11 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ActAB32.dll
[2006/12/05 12:44:26 | 000,000,243 | ---- | C] () -- C:\WINDOWS\ActiveAct.INI
[2006/12/05 11:59:20 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\EmailShared.dll
[2006/12/04 14:28:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2006/11/20 22:54:55 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/11/20 22:49:34 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/11/20 22:18:40 | 000,129,112 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/11/20 22:18:27 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe
[2006/11/20 22:17:40 | 000,000,389 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/11 15:24:19 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/11 15:19:30 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/11 15:12:14 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 15:11:31 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 15:07:24 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/11 15:06:43 | 000,286,904 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 15:00:30 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/11 15:00:28 | 000,532,574 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/11 15:00:28 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/11 15:00:28 | 000,104,782 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/11 15:00:28 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/11 15:00:27 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/11 15:00:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/11 15:00:24 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/11 15:00:19 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/11 15:00:19 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/11 15:00:12 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/11 15:00:04 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin

========== LOP Check ==========

[2011/10/03 20:42:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACT
[2010/08/26 17:13:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CitrixLogs
[2011/01/07 23:11:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2011/04/07 22:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JungleDisk
[2011/06/24 10:40:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/01/07 23:12:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nuance
[2011/10/03 20:41:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sage Software, Inc
[2010/05/25 20:32:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SentriLock
[2009/10/24 13:13:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2011/01/08 13:04:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2007/02/06 16:10:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ckelley\Application Data\Interact Commerce
[2007/02/09 10:43:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ckelley\Application Data\net.dacons.mail.it
[2007/10/16 16:47:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ckelley\Application Data\OfficeUpdate12
[2006/12/05 12:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Darrel Kullman\Application Data\Interact Commerce
[2011/10/03 20:51:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\ACT
[2009/10/23 12:38:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\Calyx Software
[2009/04/26 09:05:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\FileMaker
[2011/10/03 20:48:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\IsolatedStorage
[2007/02/07 14:46:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\net.dacons.mail.it
[2008/11/18 15:11:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\OfficeUpdate12
[2010/05/25 20:35:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\SentriLock
[2012/01/16 08:22:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\Voltage
[2010/07/28 08:49:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\webex
[2009/12/29 16:53:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\Windows Desktop Search
[2010/01/07 14:11:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DKullman\Application Data\Windows Search
[2007/02/06 15:06:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DRobinson\Application Data\Interact Commerce
[2008/11/18 14:38:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DRobinson\Application Data\OfficeUpdate12
[2008/03/06 10:54:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DRobinson\Application Data\PDS
[2012/01/15 20:00:01 | 000,000,428 | ---- | M] () -- C:\WINDOWS\Tasks\SyncBack Backup.job

========== Purity Check ==========



< End of report >


OTL Third Scan:


OTL logfile created on: 1/16/2012 10:24:38 AM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\DKullman\Desktop\Virus Removal Software\Old Timer
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.22 Gb Total Physical Memory | 2.29 Gb Available Physical Memory | 71.22% Memory free
7.88 Gb Paging File | 7.09 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 4939 8200 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 23.31 Gb Free Space | 31.31% Space Free | Partition Type: NTFS
Drive F: | 5.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 973.17 Mb Total Space | 871.45 Mb Free Space | 89.55% Space Free | Partition Type: FAT

Computer Name: WORKSTATION3NEW | User Name: dkullman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========



< MD5 for: NETBT.SYS >
[2004/08/04 03:00:00 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B -- C:\i386\netbt.sys
[2004/08/04 03:00:00 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B -- C:\WINDOWS\$NtServicePackUninstall$\netbt.sys
[2008/04/13 11:21:00 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D -- C:\WINDOWS\ServicePackFiles\i386\netbt.sys
[2008/04/13 11:21:00 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D -- C:\WINDOWS\system32\dllcache\netbt.sys
[2008/04/13 11:21:00 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D -- C:\WINDOWS\system32\drivers\netbt.sys

< End of report >


Malwarebytes Scan:


Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.16.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
dkullman :: WORKSTATION3NEW [administrator]

1/16/2012 11:09:22 AM
mbam-log-2012-01-16 (11-09-22).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 263803
Time elapsed: 8 minute(s), 7 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


ESET Scan:


ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=d75d8a71f9cbd94ea1543aa362195baa
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-16 09:31:27
# local_time=2012-01-16 01:31:27 (-0800, Pacific Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=113032
# found=10
# cleaned=10
# scan_time=5490
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000024.sys a variant of Win32/Rootkit.Kryptik.HA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000051.sys a variant of Win32/Rootkit.Kryptik.HA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000408.sys a variant of Win32/Rootkit.Kryptik.HA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000486.sys a variant of Win32/Rootkit.Kryptik.HA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP2\A0000504.sys a variant of Win32/Rootkit.Kryptik.HA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0000536.sys a variant of Win32/Rootkit.Kryptik.HA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0000568.sys a variant of Win32/Rootkit.Kryptik.HA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0000670.sys a variant of Win32/Rootkit.Kryptik.HA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP6\A0000777.sys a variant of Win32/Rootkit.Kryptik.HA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP8\A0000857.sys a variant of Win32/Rootkit.Kryptik.HA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

That's it let me know what's next, Thank you so much !! Darrel
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP