I installed Firefox and had to log off of the user to change a setting under the admin account and when I logged back on the the user account Firefox was gone. I tried changing a display setting for her screen saver and it just changes itself back to the original.
I tried to do a system restore but there is no restore point to load from. I am pretty stumpped and if I could get another brain to think about this and throw me some ideas that would be great!
P.S. I forgot to mention that we run Symantec Antivirus Corporate Edition on all machines. I've had this virus before and other viruses similar to this and the virus always seems to stop the Realtime Protection associated with Symantec and puts a yellow exlamation point over the shield.
EDIT: Here is my OTL Log:
OTL logfile created on: 6/15/2010 10:50:12 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\apay\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 649.00 Mb Available Physical Memory | 63.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.61 Gb Total Space | 4.86 Gb Free Space | 26.08% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive M: | 276.51 Gb Total Space | 102.67 Gb Free Space | 37.13% Space Free | Partition Type: NTFS
Drive O: | 256.91 Gb Total Space | 175.09 Gb Free Space | 68.15% Space Free | Partition Type: NTFS
Computer Name: TWFINAP12
Current User Name: apay
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/06/15 10:50:10 | 000,572,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\apay\Desktop\OTL.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2003/05/21 01:22:36 | 000,032,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
PRC - [2003/05/21 01:21:18 | 000,090,112 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe
========== Modules (SafeList) ==========
MOD - [2010/06/15 10:50:10 | 000,572,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\apay\Desktop\OTL.exe
MOD - [2006/08/25 11:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 06:00:00 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2009/01/07 18:21:00 | 000,026,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\system32\spupdsvc.exe -- (spupdsvc)
SRV - [2003/05/21 01:27:46 | 000,610,304 | ---- | M] (Symantec Corporation) [Auto | Stopped] -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe -- (Norton AntiVirus Server)
SRV - [2003/05/21 01:22:36 | 000,032,768 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe -- (DefWatch)
========== Driver Services (SafeList) ==========
DRV - [2010/01/12 22:23:55 | 001,323,568 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100105.019\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/01/12 22:23:54 | 000,084,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100105.019\NAVENG.SYS -- (NAVENG)
DRV - [2008/04/16 04:07:48 | 000,385,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2007/08/09 11:38:07 | 000,073,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent)
DRV - [2003/05/02 21:08:22 | 000,030,208 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navapel.sys -- (NAVAPEL)
DRV - [2003/05/02 21:08:18 | 000,224,256 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navap.sys -- (NAVAP)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:80
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://en-us.start.m...en-US:official"
FF - prefs.js..network.proxy.backup.ftp: "127.0.0.1"
FF - prefs.js..network.proxy.backup.ftp_port: 80
FF - prefs.js..network.proxy.backup.gopher: "127.0.0.1"
FF - prefs.js..network.proxy.backup.gopher_port: 80
FF - prefs.js..network.proxy.backup.socks: "127.0.0.1"
FF - prefs.js..network.proxy.backup.socks_port: 80
FF - prefs.js..network.proxy.backup.ssl: "127.0.0.1"
FF - prefs.js..network.proxy.backup.ssl_port: 80
FF - prefs.js..network.proxy.ftp: "127.0.0.1"
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.gopher: "127.0.0.1"
FF - prefs.js..network.proxy.gopher_port: 80
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "127.0.0.1"
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.ssl: "127.0.0.1"
FF - prefs.js..network.proxy.ssl_port: 80
FF - prefs.js..network.proxy.type: 1
[2007/08/11 16:55:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\apay\Application Data\Mozilla\Firefox\Profiles\6jkx8nwx.default\extensions
[2006/01/02 11:15:46 | 001,312,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\RunOnce: [NoIE4StubProcessing] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft....k/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1186663274265 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1186663268796 (MUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.0.129 66.0.214.14 207.230.75.34
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = twest.lan
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\apay\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\apay\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/07/27 13:22:11 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/06/15 10:50:08 | 000,572,416 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\apay\Desktop\OTL.exe
[2010/06/15 10:43:31 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/06/15 10:43:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010/06/15 10:40:51 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\zh-TW
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\zh-HK
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\tr-TR
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\sv-SE
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\pt-BR
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\nl-NL
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\nb-NO
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ko-KR
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\it-IT
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\he-IL
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\fr-FR
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\fi-FI
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\es-ES
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\el-GR
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\de-DE
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\da-DK
[2010/06/15 10:36:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ar-SA
[2010/06/15 10:34:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[46 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[32 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/06/15 10:50:10 | 000,572,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\apay\Desktop\OTL.exe
[2010/06/15 10:48:08 | 000,000,573 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/15 10:44:15 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/06/15 10:43:08 | 000,000,873 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2010/06/15 10:36:27 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2010/06/15 10:32:44 | 000,001,016 | RHS- | M] () -- C:\Documents and Settings\apay\ntuser.pol
[2010/06/15 10:31:55 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/06/15 10:31:38 | 004,718,592 | -H-- | M] () -- C:\Documents and Settings\apay\NTUSER.DAT
[2010/06/15 10:31:38 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\apay\ntuser.ini
[2010/06/15 10:31:29 | 003,579,728 | -H-- | M] () -- C:\Documents and Settings\apay\Local Settings\Application Data\IconCache.db
[2010/06/15 10:16:19 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/06/15 10:16:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/06/15 08:25:38 | 000,063,592 | ---- | M] () -- C:\Documents and Settings\apay\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/08 10:16:35 | 000,113,664 | ---- | M] () -- C:\Documents and Settings\apay\Desktop\DEPARTMENT REQUEST.xls
[2010/05/28 16:45:24 | 000,057,856 | ---- | M] () -- C:\Documents and Settings\apay\My Documents\OFFICE SUPPLY.doc
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[46 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[32 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/06/15 10:43:08 | 000,000,873 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2010/06/15 10:36:27 | 000,000,236 | ---- | C] () -- C:\WINDOWS\tasks\OGALogon.job
[2010/05/28 16:45:23 | 000,057,856 | ---- | C] () -- C:\Documents and Settings\apay\My Documents\OFFICE SUPPLY.doc
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2007/08/09 11:51:17 | 000,051,712 | ---- | C] () -- C:\WINDOWS\System32\ngprtserv.dll
[2007/08/09 11:51:17 | 000,000,575 | ---- | C] () -- C:\WINDOWS\Setupwizard.ini
[2007/08/09 08:47:01 | 000,000,556 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/08/04 06:00:00 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 06:00:00 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 06:00:00 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 06:00:00 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 06:00:00 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
[2003/05/21 01:19:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
< End of report >
Mark
Edited by MarMah, 15 June 2010 - 08:53 AM.