also @ TechSpot: Next iPad rumored to be 33% lighter and thinner thanks to new touchscreen tech

Slender Man virus

Discussion in 'Virus and Malware Removal' started by daveed12vas, Dec 16, 2012.

Post New Reply
  1. Broni Malware Annihilator Posts: 39,324   +175

    If this is Desktop shortcut try to create new one.

    As for Norton you may need to reinstall it.

    Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    Next...

    • Double click on adwcleaner.exe to run the tool.
    • Click on Uninstall.
    • Confirm with yes.

    =============================

    Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
  2. daveed12vas Newcomer, in training Posts: 31

    # AdwCleaner v2.101 - Logfile created 12/17/2012 at 00:07:17
    # Updated 16/12/2012 by Xplode
    # Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
    # User : Administrator - GX620
    # Boot Mode : Normal
    # Running from : C:\Documents and Settings\Administrator\My Documents\Downloads\adwcleaner.exe
    # Option [Delete]


    ***** [Services] *****


    ***** [Files / Folders] *****

    File Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ga180uks.default\searchplugins\safesearch.xml
    Folder Deleted : C:\Documents and Settings\Administrator\Application Data\DefaultTab

    ***** [Registry] *****

    Key Deleted : HKCU\Software\AppDataLow\Software\DefaultTab
    Key Deleted : HKCU\Software\Default Tab
    Key Deleted : HKCU\Software\DefaultTab
    Key Deleted : HKLM\Software\Default Tab
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DefaultTab

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v8.0.6001.18702

    [OK] Registry is clean.

    -\\ Mozilla Firefox v17.0.1 (en-US)

    Profile name : default
    File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ga180uks.default\prefs.js

    [OK] File is clean.

    *************************

    AdwCleaner[R1].txt - [1387 octets] - [17/12/2012 00:06:49]
    AdwCleaner[S1].txt - [1332 octets] - [17/12/2012 00:07:17]

    ########## EOF - C:\AdwCleaner[S1].txt - [1392 octets] ##########
  3. daveed12vas Newcomer, in training Posts: 31

    OTL logfile created on: 12/17/2012 12:13:01 AM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.50 Gb Total Physical Memory | 2.93 Gb Available Physical Memory | 83.79% Memory free
    4.09 Gb Paging File | 3.71 Gb Available in Paging File | 90.61% Paging File free
    Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 74.50 Gb Total Space | 53.71 Gb Free Space | 72.09% Space Free | Partition Type: NTFS

    Computer Name: GX620 | User Name: Administrator | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/12/17 00:05:20 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
    PRC - [2012/10/10 20:29:13 | 000,143,928 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Management\Engine\3.2.0.19\ccsvchst.exe
    PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
    PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
    PRC - [2012/06/15 20:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\6.4.0.9\ccsvchst.exe
    PRC - [2008/11/09 14:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


    ========== Modules (No Company Name) ==========


    ========== Services (SafeList) ==========

    SRV - [2012/12/12 11:32:26 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/12/01 12:07:23 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2012/10/10 20:29:13 | 000,143,928 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Management\Engine\3.2.0.19\ccSvcHst.exe -- (MCLIENT)
    SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
    SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
    SRV - [2012/06/15 20:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton 360\Engine\6.4.0.9\ccSvcHst.exe -- (N360)
    SRV - [2008/11/09 14:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys -- (catchme)
    DRV - [2012/10/23 17:34:24 | 000,995,488 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\BASHDefs\20121130.005\BHDrvx86.sys -- (BHDrvx86)
    DRV - [2012/10/03 19:19:14 | 000,134,304 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\MCLIENT\0302000.013\ccsetx86.sys -- (ccSet_MCLIENT)
    DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
    DRV - [2012/09/14 09:26:00 | 001,601,184 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20121216.007\NAVEX15.SYS -- (NAVEX15)
    DRV - [2012/09/14 09:26:00 | 000,092,704 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20121216.007\NAVENG.SYS -- (NAVENG)
    DRV - [2012/09/06 03:54:30 | 000,373,728 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\IPSDefs\20121214.001\IDSXpx86.sys -- (IDSxpx86)
    DRV - [2012/08/09 06:48:37 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
    DRV - [2012/08/09 06:48:37 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
    DRV - [2012/07/05 20:17:57 | 000,574,112 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\srtsp.sys -- (SRTSP)
    DRV - [2012/07/05 20:17:57 | 000,032,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\srtspx.sys -- (SRTSPX)
    DRV - [2012/07/04 00:54:32 | 007,874,560 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
    DRV - [2012/07/01 17:56:17 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
    DRV - [2012/06/06 22:43:43 | 000,132,768 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\ccsetx86.sys -- (ccSet_N360)
    DRV - [2012/05/21 19:37:12 | 000,924,320 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\symefa.sys -- (SymEFA)
    DRV - [2012/05/14 00:12:12 | 000,103,040 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService)
    DRV - [2012/03/29 00:28:38 | 000,388,216 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\symtdi.sys -- (SYMTDI)
    DRV - [2012/03/29 00:28:25 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\symds.sys -- (SymDS)
    DRV - [2012/03/29 00:06:25 | 000,149,624 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\ironx86.sys -- (SymIRON)
    DRV - [2010/04/27 17:57:28 | 000,066,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
    DRV - [2010/04/27 17:57:28 | 000,015,048 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
    DRV - [2010/04/27 17:57:22 | 000,022,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
    DRV - [2010/04/27 15:01:26 | 000,037,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
    DRV - [2005/03/17 15:30:10 | 000,132,608 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
    DRV - [2004/09/17 08:02:54 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\..\SearchScopes,DefaultScope =
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}


    IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-21-790525478-796845957-725345543-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    IE - HKU\S-1-5-21-790525478-796845957-725345543-500\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-21-790525478-796845957-725345543-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKU\S-1-5-21-790525478-796845957-725345543-500\..\SearchScopes\{271AB670-473B-4EDC-8036-15E5194F33A9}: "URL" = http://search.yahoo.com/search?p={s...ype=W3i_DS,136,0_0,Search,20121251,6901,0,8,0
    IE - HKU\S-1-5-21-790525478-796845957-725345543-500\..\SearchScopes\{988AA950-1F62-48B2-A8DA-EFE0B23C8875}: "URL" = http://www.mysearchresults.com/search?&c=2650&t=03&q={searchTerms}
    IE - HKU\S-1-5-21-790525478-796845957-725345543-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
    FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
    FF - prefs.js..extensions.enabledAddons: %7BBBDA0591-3099-440a-AA10-41764D9DB4DB%7D:11.1.1.5%20-%203
    FF - prefs.js..extensions.enabledAddons: artur.dubovoy%40gmail.com:3.8.1
    FF - prefs.js..extensions.enabledAddons: %7B2D3F3651-74B9-4795-BDEC-6DA2F431CB62%7D:2012.5.8.4
    FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
    FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
    FF - user.js - File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\IPSFFPlgn\ [2012/07/01 17:59:49 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\coFFPlgn\ [2012/12/17 00:09:39 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/01 12:07:23 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/12/01 12:07:16 | 000,000,000 | ---D | M]

    [2010/04/07 16:35:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
    [2012/12/16 15:56:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ga180uks.default\extensions
    [2012/12/16 15:56:25 | 000,234,972 | ---- | M] () (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ga180uks.default\extensions\artur.dubovoy@gmail.com.xpi
    [2012/12/01 12:07:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2012/12/17 00:09:39 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\COFFPLGN
    [2012/07/01 17:59:49 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\IPSFFPLGN
    [2011/07/04 08:31:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
    [2012/12/01 12:07:23 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2012/08/29 09:25:25 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
    [2012/10/12 17:01:44 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

    O1 HOSTS File: ([2012/12/16 19:40:44 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
    O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.4.0.9\ips\ipsbho.dll (Symantec Corporation)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
    O3 - HKU\S-1-5-21-790525478-796845957-725345543-500\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - No CLSID value found.
    O3 - HKU\S-1-5-21-790525478-796845957-725345543-500\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - No CLSID value found.
    O3 - HKU\S-1-5-21-790525478-796845957-725345543-500\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-790525478-796845957-725345543-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-790525478-796845957-725345543-500\Software\Policies\Microsoft\Internet Explorer\Recovery present
    O7 - HKU\S-1-5-21-790525478-796845957-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-21-790525478-796845957-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-21-790525478-796845957-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1340484126046 (WUWebControl Class)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1350846574421 (MUWebControl Class)
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.217.0.5 24.217.201.67 24.247.15.53
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2225B3BB-99B4-43AD-B80C-7B7402075F2B}: DhcpNameServer = 24.217.0.5 24.217.201.67 24.247.15.53
    O18 - Protocol\Handler\mhtml - No CLSID value found
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
    O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2010/04/07 16:13:33 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/12/16 19:31:14 | 005,011,996 | R--- | C] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
    [2012/12/16 17:38:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\RK_Quarantine
    [2012/12/16 09:58:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Optimizer Pro
    [2012/12/16 09:58:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Yahoo!
    [2012/12/16 09:45:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\Slender v0.9.7
    [2012/12/16 09:28:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
    [2012/12/16 09:28:23 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
    [2012/12/14 10:29:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\NPE
    [2012/12/09 17:03:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\LightScribe Direct Disc Labeling
    [2012/12/09 17:03:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LightScribe
    [2012/12/09 15:51:23 | 000,000,000 | ---D | C] -- C:\HOME2
    [2012/12/01 12:07:13 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/12/17 00:09:05 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2012/12/17 00:08:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2012/12/16 23:32:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
    [2012/12/16 23:21:57 | 000,004,625 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2012/12/16 23:21:50 | 000,432,838 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2012/12/16 23:21:50 | 000,067,794 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2012/12/16 22:51:08 | 005,011,996 | R--- | M] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
    [2012/12/16 19:40:44 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2012/12/16 18:26:15 | 000,000,438 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{7F981BCB-ABC9-4C36-9EBA-E7880CC42B20}.job
    [2012/12/16 18:07:36 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\MBR.dat
    [2012/12/16 14:21:44 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2012/12/16 13:43:53 | 000,106,484 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559867574_7095613_n.jpg
    [2012/12/16 13:43:34 | 000,075,678 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559862574_6188948_n.jpg
    [2012/12/16 13:43:19 | 000,080,971 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559857574_334677_n.jpg
    [2012/12/16 13:14:25 | 000,059,706 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\261_1062181270983_8081_n.jpg
    [2012/12/16 10:53:14 | 000,085,576 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\198723_246654008692257_3722898_n.jpg
    [2012/12/16 10:34:55 | 000,100,854 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\527968_10151082408668579_1144189974_n.jpg
    [2012/12/16 10:05:56 | 000,111,328 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\575143_10151496327190174_908941605_n.jpg
    [2012/12/16 09:43:43 | 065,812,970 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Slender_v0_9_7.zip
    [2012/12/16 02:03:35 | 000,044,575 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\253_20287805827_5281_n.jpg
    [2012/12/16 01:54:28 | 000,154,897 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\556064_10150917674280828_1381619199_n.jpg
    [2012/12/16 01:43:07 | 000,039,697 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\581594_185262564942140_1908392838_n.jpg
    [2012/12/16 01:36:03 | 000,071,971 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\23472_10150157315130478_2968909_n.jpg
    [2012/12/16 01:35:47 | 000,089,247 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\23472_10150157311865478_7692424_n.jpg
    [2012/12/16 01:03:23 | 000,058,984 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\3180_1149796901319_769025_n.jpg
    [2012/12/16 01:03:18 | 000,060,869 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\3180_1149796941320_5306665_n.jpg
    [2012/12/15 23:42:09 | 000,071,459 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\248781_2144181005483_5042624_n.jpg
    [2012/12/15 23:41:12 | 000,094,800 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\267583_2249405116020_2639995_n.jpg
    [2012/12/15 23:21:45 | 000,085,011 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\396614_1820614511340_316881020_n.jpg
    [2012/12/15 23:10:23 | 000,084,725 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\206767_10150154363369039_6466081_n.jpg
    [2012/12/15 23:10:02 | 000,103,964 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\215679_10150154363429039_2434430_n.jpg
    [2012/12/15 23:02:44 | 000,053,307 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\9021_126017333602_4267830_n.jpg
    [2012/12/12 11:32:24 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
    [2012/12/12 11:32:24 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
    [2012/12/11 21:48:40 | 000,064,808 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\560781_210920942374896_1376037402_n.jpg
    [2012/12/10 22:01:05 | 000,053,036 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\205769_110753989007984_1569016_n.jpg
    [2012/12/10 21:44:31 | 000,038,682 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\269811_104812279614250_4588483_n.jpg
    [2012/12/09 20:59:05 | 014,117,417 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 4.mp3
    [2012/12/09 20:58:58 | 014,457,374 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 3.mp3
    [2012/12/09 20:58:50 | 014,501,103 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 2.mp3
    [2012/12/09 20:58:38 | 015,049,699 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 1.mp3
    [2012/12/09 17:03:49 | 000,001,774 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\LightScribe.lnk
    [2012/12/09 16:43:35 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
    [2012/12/09 15:02:25 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/12/09 14:38:47 | 000,115,768 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2012/12/02 12:25:44 | 163,910,310 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\BF3_Premium_Bonus_Art_EN_v2.pdf
    [2012/11/30 12:35:48 | 000,100,383 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ovw001-checklist.pdf
    [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/12/16 18:07:36 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\MBR.dat
    [2012/12/16 13:43:53 | 000,106,484 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559867574_7095613_n.jpg
    [2012/12/16 13:43:34 | 000,075,678 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559862574_6188948_n.jpg
    [2012/12/16 13:43:19 | 000,080,971 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559857574_334677_n.jpg
    [2012/12/16 13:14:24 | 000,059,706 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\261_1062181270983_8081_n.jpg
    [2012/12/16 10:53:13 | 000,085,576 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\198723_246654008692257_3722898_n.jpg
    [2012/12/16 10:34:55 | 000,100,854 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\527968_10151082408668579_1144189974_n.jpg
    [2012/12/16 10:05:55 | 000,111,328 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\575143_10151496327190174_908941605_n.jpg
    [2012/12/16 09:43:43 | 065,812,970 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Slender_v0_9_7.zip
    [2012/12/16 02:03:35 | 000,044,575 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\253_20287805827_5281_n.jpg
    [2012/12/16 01:54:28 | 000,154,897 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\556064_10150917674280828_1381619199_n.jpg
    [2012/12/16 01:43:07 | 000,039,697 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\581594_185262564942140_1908392838_n.jpg
    [2012/12/16 01:36:03 | 000,071,971 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\23472_10150157315130478_2968909_n.jpg
    [2012/12/16 01:35:47 | 000,089,247 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\23472_10150157311865478_7692424_n.jpg
    [2012/12/16 01:03:23 | 000,058,984 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\3180_1149796901319_769025_n.jpg
    [2012/12/16 01:03:18 | 000,060,869 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\3180_1149796941320_5306665_n.jpg
    [2012/12/15 23:42:08 | 000,071,459 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\248781_2144181005483_5042624_n.jpg
    [2012/12/15 23:41:11 | 000,094,800 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\267583_2249405116020_2639995_n.jpg
    [2012/12/15 23:21:45 | 000,085,011 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\396614_1820614511340_316881020_n.jpg
    [2012/12/15 23:10:23 | 000,084,725 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\206767_10150154363369039_6466081_n.jpg
    [2012/12/15 23:10:02 | 000,103,964 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\215679_10150154363429039_2434430_n.jpg
    [2012/12/15 23:02:43 | 000,053,307 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\9021_126017333602_4267830_n.jpg
    [2012/12/11 21:48:40 | 000,064,808 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\560781_210920942374896_1376037402_n.jpg
    [2012/12/10 22:01:04 | 000,053,036 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\205769_110753989007984_1569016_n.jpg
    [2012/12/10 21:44:30 | 000,038,682 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\269811_104812279614250_4588483_n.jpg
    [2012/12/09 20:58:57 | 014,117,417 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 4.mp3
    [2012/12/09 20:58:50 | 014,457,374 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 3.mp3
    [2012/12/09 20:58:39 | 014,501,103 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 2.mp3
    [2012/12/09 20:58:30 | 015,049,699 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 1.mp3
    [2012/12/09 17:03:49 | 000,001,774 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\LightScribe.lnk
    [2012/12/02 12:24:04 | 163,910,310 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\BF3_Premium_Bonus_Art_EN_v2.pdf
    [2012/11/30 12:35:44 | 000,100,383 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\ovw001-checklist.pdf
    [2012/03/14 16:30:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
    [2012/02/06 17:34:59 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2012/02/06 17:34:59 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2012/02/06 17:34:59 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2012/02/06 17:34:59 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2012/02/06 17:34:59 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2012/02/01 17:35:55 | 000,199,307 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\census.cache
    [2012/02/01 17:35:52 | 000,165,959 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ars.cache
    [2012/02/01 17:27:17 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\housecall.guid.cache
    [2011/08/03 18:48:56 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2011/07/13 20:42:30 | 000,140,024 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
    [2011/07/13 20:42:29 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\PnkBstrK.sys
    [2011/07/13 20:41:51 | 000,280,768 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
    [2011/07/13 20:41:49 | 002,434,856 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_bc2.exe
    [2011/07/13 20:41:49 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
    [2011/07/07 22:37:28 | 000,053,760 | ---- | C] () -- C:\WINDOWS\System32\OVDecode.dll
    [2011/06/19 09:53:07 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
    [2011/06/19 09:53:07 | 000,618,823 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
    [2011/06/19 09:53:07 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
    [2011/06/17 16:27:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin

    ========== ZeroAccess Check ==========

    [2011/06/17 16:24:56 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 18:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 06:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
    "" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/13 18:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    < End of report >
  4. daveed12vas Newcomer, in training Posts: 31

    OTL Extras logfile created on: 12/17/2012 12:13:01 AM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.50 Gb Total Physical Memory | 2.93 Gb Available Physical Memory | 83.79% Memory free
    4.09 Gb Paging File | 3.71 Gb Available in Paging File | 90.61% Paging File free
    Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 74.50 Gb Total Space | 53.71 Gb Free Space | 72.09% Space Free | Partition Type: NTFS

    Computer Name: GX620 | User Name: Administrator | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

    [HKEY_USERS\S-1-5-21-790525478-796845957-725345543-500\SOFTWARE\Classes\<extension>]
    .html [@ = htmlfile] -- Reg Error: Key error. File not found

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    exefile [open] -- "%1" %*
    htmlfile [edit] -- Reg Error: Key error.
    InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 1
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 0
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22008

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 -- (Microsoft Corporation)
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 -- (Microsoft Corporation)
    "C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe" = C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe:LocalSubNet:Enabled:HP Device Setup -- (Hewlett-Packard Co.)
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)
    "C:\WINDOWS\system32\PnkBstrA.exe" = C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:pnkBstrA -- ()
    "C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:pnkBstrB -- ()


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0807E67B-DACB-1739-A87E-3046FF40BA23}" = CCC Help Chinese Traditional
    "{0DF310E3-6C01-99DC-296F-1D021BA36C2D}" = CCC Help English
    "{1E8E87B5-4531-CEE3-4791-6AD9E72076EC}" = CCC Help Danish
    "{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java(TM) 6 Update 26
    "{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9
    "{27596347-C945-B113-EF47-169D471CEB05}" = CCC Help Turkish
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{3666DE18-A4CC-4E1E-8165-0D78758C2209}" = CCC Help Russian
    "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
    "{479826D5-FE36-711F-8BE3-AB7B44440F66}" = ccc-utility
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{5033F411-4848-49D6-BAC2-DAA06AFA0AFC}" = HP Deskjet 2050 J510 series Basic Device Software
    "{532669C6-3139-E755-B3B8-95F184EB27EB}" = CCC Help German
    "{577F4DD2-ED68-690F-6328-8A8CAC8FCA75}" = CCC Help Polish
    "{637A3EC2-4299-67B2-E0D2-C25572F4D37A}" = CCC Help Thai
    "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
    "{6F2954FB-3F0F-B384-3E6F-5D0CAAF80A77}" = ATI AVIVO Codecs
    "{702F39B4-05FB-22F4-8426-E5FFFA330FF3}" = CCC Help Chinese Standard
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{73FB391E-E800-CC82-D9BA-EF9CB8A939F3}" = CCC Help French
    "{747E2E56-A68B-15C6-BB77-31BFE0C031EF}" = CCC Help Spanish
    "{7A37A44B-968E-6CA3-278C-878D4D08B226}" = CCC Help Czech
    "{7A3DF2E2-CF13-44FB-A93E-F71D5381DB3F}" = HP Deskjet 2050 J510 series Help
    "{7C0FB04E-5A40-C63D-CC1B-B6C1B60FDDA3}" = CCC Help Japanese
    "{7D94796D-007E-45DE-CEAD-8E616D78E95B}" = CCC Help Dutch
    "{7E7C98D1-4F44-21D4-C351-25E2367027F3}" = Catalyst Control Center
    "{87A91A66-1566-714D-E1BE-1F3B040E65D5}" = CCC Help Swedish
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver
    "{90538B62-F392-4DE1-B886-7B48123866E9}" = LightScribe System Software
    "{92F63D17-2A32-7184-B8D7-905E0E1BC2A9}" = CCC Help Hungarian
    "{95CEF602-B837-0C37-F5E6-49C8F3196998}" = CCC Help Greek
    "{97E1A4DE-82AB-0448-0AEA-77DC1DD9A492}" = Catalyst Control Center Localization All
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9DFD861E-2692-873F-BA2C-E4788648D966}" = CCC Help Italian
    "{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
    "{B50676DC-AAE9-20DF-01A5-DABCDECD6DFC}" = Catalyst Control Center Graphics Previews Common
    "{B7F54262-AB66-44B3-88BF-9FC69941B643}" = Broadcom Gigabit Integrated Controller
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D6346B4B-FDD6-C406-06FE-0CF77F561E78}" = AMD Catalyst Install Manager
    "{D9C7FB0D-B233-1B2E-E9DC-543911F6D94A}" = Catalyst Control Center InstallProxy
    "{DD9F821E-7B8D-210F-A4AE-47C60870DEBE}" = CCC Help Norwegian
    "{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
    "{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
    "{E6F42010-AA5A-B862-9620-8CBD23ACDED4}" = CCC Help Portuguese
    "{EAAE7669-947C-26DD-563D-863B63FFC1EA}" = CCC Help Finnish
    "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
    "{F296A4CD-54A2-1EEE-CE14-8F88A1D97083}" = CCC Help Korean
    "{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "CCleaner" = CCleaner
    "CDisplay_is1" = CDisplay 1.8
    "DVD Shrink_is1" = DVD Shrink 3.2
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie7" = Windows Internet Explorer 7
    "ie8" = Windows Internet Explorer 8
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
    "MCLIENT" = Norton Management
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Mozilla Firefox 17.0.1 (x86 en-US)" = Mozilla Firefox 17.0.1 (x86 en-US)
    "MozillaMaintenanceService" = Mozilla Maintenance Service
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "N360" = Norton 360
    "Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "PunkBusterSvc" = PunkBuster Services
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
    "Yahoo! Software Update" = Yahoo! Software Update

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-790525478-796845957-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "f031ef6ac137efc5" = Dell Driver Download Manager

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 8/20/2012 10:46:02 AM | Computer Name = GX620 | Source = Application Error | ID = 1001
    Description = Fault bucket -1216698070.

    Error - 8/23/2012 11:24:47 AM | Computer Name = GX620 | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: The server name or address could not be resolved

    Error - 9/8/2012 3:55:56 PM | Computer Name = GX620 | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: The server name or address could not be resolved

    Error - 9/9/2012 3:33:16 PM | Computer Name = GX620 | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: The server name or address could not be resolved

    Error - 9/9/2012 3:33:23 PM | Computer Name = GX620 | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: The server name or address could not be resolved

    Error - 9/10/2012 3:04:47 PM | Computer Name = GX620 | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: The server name or address could not be resolved

    Error - 10/2/2012 11:30:22 AM | Computer Name = GX620 | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: The server name or address could not be resolved

    Error - 10/10/2012 11:43:46 AM | Computer Name = GX620 | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: The server name or address could not be resolved

    Error - 12/1/2012 1:34:15 PM | Computer Name = GX620 | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: The server name or address could not be resolved

    Error - 12/1/2012 9:23:18 PM | Computer Name = GX620 | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: The server name or address could not be resolved

    [ System Events ]
    Error - 12/1/2012 9:23:14 PM | Computer Name = GX620 | Source = Dhcp | ID = 1002
    Description = The IP address lease 192.168.100.2 for the Network Card with network
    address 0013727340F4 has been denied by the DHCP server 192.168.100.1 (The DHCP
    Server sent a DHCPNACK message).

    Error - 12/6/2012 11:20:51 AM | Computer Name = GX620 | Source = Dhcp | ID = 1000
    Description = Your computer has lost the lease to its IP address 192.168.100.2 on
    the Network Card with network address 0013727340F4.

    Error - 12/8/2012 10:20:38 PM | Computer Name = GX620 | Source = W32Time | ID = 39452689
    Description = Time Provider NtpClient: An error occurred during DNS lookup of the
    manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
    again in 15 minutes. The error was: A socket operation was attempted to an unreachable
    host. (0x80072751)

    Error - 12/8/2012 10:20:38 PM | Computer Name = GX620 | Source = W32Time | ID = 39452701
    Description = The time provider NtpClient is configured to acquire time from one
    or more time sources, however none of the sources are currently accessible. No attempt
    to contact a source will be made for 14 minutes. NtpClient has no source of accurate
    time.

    Error - 12/8/2012 10:20:55 PM | Computer Name = GX620 | Source = Dhcp | ID = 1002
    Description = The IP address lease 192.168.100.2 for the Network Card with network
    address 0013727340F4 has been denied by the DHCP server 192.168.100.1 (The DHCP
    Server sent a DHCPNACK message).

    Error - 12/10/2012 1:26:03 AM | Computer Name = GX620 | Source = Dhcp | ID = 1002
    Description = The IP address lease 71.85.230.56 for the Network Card with network
    address 0013727340F4 has been denied by the DHCP server 192.168.100.1 (The DHCP
    Server sent a DHCPNACK message).

    Error - 12/10/2012 1:26:15 AM | Computer Name = GX620 | Source = Dhcp | ID = 1002
    Description = The IP address lease 192.168.100.2 for the Network Card with network
    address 0013727340F4 has been denied by the DHCP server 192.168.100.1 (The DHCP
    Server sent a DHCPNACK message).

    Error - 12/14/2012 12:05:26 PM | Computer Name = GX620 | Source = Dhcp | ID = 1002
    Description = The IP address lease 192.168.100.2 for the Network Card with network
    address 0013727340F4 has been denied by the DHCP server 192.168.100.1 (The DHCP
    Server sent a DHCPNACK message).

    Error - 12/16/2012 5:32:39 PM | Computer Name = GX620 | Source = Dhcp | ID = 1002
    Description = The IP address lease 71.85.225.232 for the Network Card with network
    address 0013727340F4 has been denied by the DHCP server 192.168.100.1 (The DHCP
    Server sent a DHCPNACK message).

    Error - 12/16/2012 7:38:41 PM | Computer Name = GX620 | Source = Service Control Manager | ID = 7034
    Description = The DefaultTabUpdate service terminated unexpectedly. It has done
    this 1 time(s).


    < End of report >
  5. Broni Malware Annihilator Posts: 39,324   +175

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
      O3 - HKU\S-1-5-21-790525478-796845957-725345543-500\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - No CLSID value found.
      O3 - HKU\S-1-5-21-790525478-796845957-725345543-500\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - No CLSID value found.
      O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      
      :Commands
      [purity]
      [emptytemp]
      [emptyjava]
      [emptyflash]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.

    ==============================

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

    2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    3. Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    4. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
  6. daveed12vas Newcomer, in training Posts: 31

    All processes killed
    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
    Registry value HKEY_USERS\S-1-5-21-790525478-796845957-725345543-500\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01E04581-4EEE-11D0-BFE9-00AA005B4383}\ not found.
    Registry value HKEY_USERS\S-1-5-21-790525478-796845957-725345543-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01E04581-4EEE-11D0-BFE9-00AA005B4383}\ not found.
    Starting removal of ActiveX control {7530BFB8-7293-4D34-9923-61A11451AFC5}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 2174916 bytes
    ->Flash cache emptied: 492 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 20297 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 2.00 mb


    [EMPTYJAVA]

    User: Administrator
    ->Java cache emptied: 0 bytes

    User: All Users

    User: Default User

    User: LocalService

    User: NetworkService

    Total Java Files Cleaned = 0.00 mb


    [EMPTYFLASH]

    User: Administrator
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: LocalService

    User: NetworkService

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 12172012_192755

    Files\Folders moved on Reboot...
    File\Folder C:\WINDOWS\temp\Perflib_Perfdata_49c.dat not found!

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     
  7. daveed12vas Newcomer, in training Posts: 31

    Results of screen317's Security Check version 0.99.56
    Windows XP Service Pack 3 x86
    Internet Explorer 7 Out of date!
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Disabled!
    Norton 360
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Malwarebytes Anti-Malware version 1.65.1.1000
    CCleaner
    Java(TM) 6 Update 26
    Java 7 Update 9
    Adobe Flash Player 11.5.502.135
    Adobe Reader 10.1.4 Adobe Reader out of Date!
    Mozilla Firefox (17.0.1)
    ````````Process Check: objlist.exe by Laurent````````
    Norton ccSvcHst.exe
    Malwarebytes' Anti-Malware mbamscheduler.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C:: 2%
    ````````````````````End of Log``````````````````````
  8. daveed12vas Newcomer, in training Posts: 31

    The link for FSS only takes to a download of other products like 'Reimage'
  9. daveed12vas Newcomer, in training Posts: 31

    ESET online scanner found no threats.
  10. Broni Malware Annihilator Posts: 39,324   +175

    No. C'mmon...
    Uploaded it for you here: http://www.filedropper.com/tfc

    =========================

    Update Adobe Reader

    You can download it from http://www.adobe.com/products/acrobat/readstep2.html
    After installing the latest Adobe Reader, uninstall all previous versions (if present).
    Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

    Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
    It's a much smaller file to download and uses a lot less resources than Adobe Reader.
    Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage.

    ========================

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [emptyjava]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Check if your browser plugins are up to date.
    Firefox - https://www.mozilla.org/en-US/plugincheck/
    other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

    6. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    7. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    8. Run Temporary File Cleaner (TFC) weekly.

    9. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    10. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    11. (Windows XP only) Run defrag at your convenience.

    12. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    13. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

    14. Please, let me know, how your computer is doing.
  11. daveed12vas Newcomer, in training Posts: 31

    Adobe Reader does not install, I only get an error message. I still can not use internet explorer without my PC freezing, I still can not use a double mouse click to open any programs, and Norton360 still stalls and stops running when I try to run scans.
  12. Broni Malware Annihilator Posts: 39,324   +175

    Go here: http://support.microsoft.com/kb/923737 and run "FixIt" procedure.
    Make sure you follow ALL steps listed there.
    See how IE works afterwards.

    As I said before reinstall Norton and see how it goes.

    We'll go from there.
  13. daveed12vas Newcomer, in training Posts: 31

    You said to get FSS from the link above, but the link takes me to a download of TFC.
    I have uninstalled & then reinstalled Norton360, but Norton stills stalls out after 2000-2900 files scanned.
    I have uninstalled my Internet Explorer, but the new download will not Install and stalls out like norton360, or it will open and then quickly snap closed.
    And still programs will not open with a left mouse click. (Example: left click mouse on Start button, move mouse pointer up to All Programs, move mouse pointer up to Mozilla and a left mouse click will no longer open Mozilla; or any other program either. Start Menu closes.)
  14. daveed12vas Newcomer, in training Posts: 31

    I can not run Windows Updates. I think because of the bad Internet Explorer virus or registry errors or what ever.
  15. daveed12vas Newcomer, in training Posts: 31

    The Fixit download will not run. I get an error message: ! The Windows Installer program could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support for personal assistance.
  16. daveed12vas Newcomer, in training Posts: 31

    I followed the instructions on how to reset internet explorer settings by myself. Doing this did not fix the problems on my PC.
  17. daveed12vas Newcomer, in training Posts: 31

    I have -I guess- successfully uninstalled Internet Explorer 8 for XP. However, my new IE8 download will not install, and will not download Windows Updates. The install program just runs endlessly. I tried to run the new install many, many times. One time I let the installation run for over 12 hours... nothing installed. I could only force a reboot of my PC by pressing & holding the power button.
  18. daveed12vas Newcomer, in training Posts: 31

    A friend said to run Malwarebytes in Safe Mode. Here is the log file of that scan. It took only an hour.


    Malwarebytes Anti-Malware 1.65.1.1000
    www.malwarebytes.org

    Database version: v2012.12.16.08

    Windows XP Service Pack 3 x86 NTFS (Safe Mode)
    Internet Explorer 7.0.5730.13
    Administrator :: GX620 [administrator]

    12/18/2012 12:47:14 PM
    mbam-log-2012-12-18 (12-47-14).txt

    Scan type: Full scan (C:\|D:\|E:\|)
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 227858
    Time elapsed: 58 minute(s), 28 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
  19. Broni Malware Annihilator Posts: 39,324   +175

    Download Windows Repair (all in one) from this site

    Install the program then run it.

    Go to Step 2 and allow it to run CheckDisk by clicking on Do It button:

    [IMG]



    Once that is done then go to Step 3 and allow it to run System File Check by clicking on Do It button:

    [IMG]


    Go to Step 4 and under "System Restore" click on Create button:

    [IMG]


    Go to Start Repairs tab and click Start button.

    [IMG]


    Please ensure that ONLY items seen in the image below are ticked as indicated (they're all checked by default):

    IMPORTANT! In addition checkmark also:
    - Repair icons
    - Repair .lnk (Shortcuts) File Association

    [IMG]

    Click on box next to the Restart System when Finished. Then click on Start.
  20. daveed12vas Newcomer, in training Posts: 31

    Sorry, but I can not run the Windows Repair (All in One). I only get an error message: 'could not create uninstall shortcut: C:/Documents and settings/ all users/ start menu/ programs/ tweaking.com/ windows repair (all in one)/ uninstall tweaking.com - windows repair (all in one).ink'