Thank you for your reply and guidance, PP! See my logs posted below. I look forward to your next reply! Thanks again!
***OTViewIt.Txt:****************************************************************
*****************
********************************************************************************
***************
OTViewIt logfile created on: 10/17/2008 6:25:20 PM - Run 3
OTViewIt by OldTimer - Version 1.0.15.0 Folder = C:\Documents and Settings\kman\Desktop\Rootkit Removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.99 Mb Total Physical Memory | 471.41 Mb Available Physical Memory | 46.08% Memory free
3.40 Gb Paging File | 3.02 Gb Available in Paging File | 88.75% Paging File free
Paging file location(s): C:\pagefile.sys 2560 2560;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.17 Gb Total Space | 76.99 Gb Free Space | 82.63% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 69.86 Gb Total Space | 35.06 Gb Free Space | 50.19% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive R: | 69.86 Gb Total Space | 27.81 Gb Free Space | 39.81% Space Free | Partition Type: NTFS
Drive Z: | 69.86 Gb Total Space | 35.06 Gb Free Space | 50.19% Space Free | Partition Type: NTFS
Computer Name: DELL-P4
Current User Name: kman
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ========== [2006/11/03 19:19:58 | 00,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
[2005/12/21 12:33:30 | 00,186,016 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
[2005/12/21 12:33:40 | 00,177,824 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
[2005/10/19 18:39:34 | 00,214,672 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
[2005/03/30 22:48:22 | 00,992,864 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
[2006/05/26 22:51:32 | 00,020,208 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe
[2006/10/26 13:40:34 | 00,335,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
[2006/10/22 13:22:00 | 00,159,810 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
[2006/05/26 22:51:42 | 01,764,592 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe
[2005/01/28 14:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe
[2008/04/14 05:42:42 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
[2005/12/21 12:33:28 | 00,048,800 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[2006/11/03 19:20:12 | 00,866,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
[2002/03/19 18:30:00 | 00,045,632 | ---- | M] () -- C:\WINDOWS\system32\TaskSwitch.exe
[2008/04/14 05:42:34 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
[2001/11/20 05:51:28 | 00,356,352 | ---- | M] () -- C:\Program Files\Belkin Mouse 1.0\Mouse32A.exe
[2006/05/26 22:51:52 | 00,085,744 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\VPTray.exe
[2008/04/14 05:42:38 | 00,135,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\taskmgr.exe
[2008/04/14 05:42:34 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
[2008/10/17 18:06:27 | 00,421,888 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kman\Desktop\Rootkit Removal\OTViewIt.exe
[2008/04/14 05:42:30 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
[2008/04/14 05:42:30 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
========== (O23) Win32 Services ========== [2007/04/13 03:20:52 | 00,033,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2005/12/21 12:33:30 | 00,186,016 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [Auto | Running])
[2005/12/21 12:33:38 | 00,083,616 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc [On_Demand | Stopped])
[2005/12/21 12:33:40 | 00,177,824 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running])
[2007/04/13 03:21:18 | 00,068,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2006/05/26 22:51:32 | 00,020,208 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running])
[2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2005/10/13 14:09:08 | 00,069,632 | ---- | M] (Macromedia) -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service [On_Demand | Stopped])
[2006/10/26 13:40:34 | 00,335,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe -- (MDM [Auto | Running])
[2006/04/14 11:03:04 | 00,203,552 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe -- (MsDtsServer [Disabled | Stopped])
[2006/02/14 03:50:58 | 00,092,880 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe -- (msftesql [Disabled | Stopped])
[2005/10/14 05:51:45 | 28,768,528 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\MSSQL.4\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS [Disabled | Stopped])
[2006/04/14 11:07:20 | 28,933,976 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQLSERVER [Disabled | Stopped])
[2006/04/14 10:55:46 | 14,623,008 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe -- (MSSQLServerOLAPService [Disabled | Stopped])
[2006/10/26 13:45:00 | 02,799,808 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon80 [Disabled | Stopped])
[2006/10/22 13:22:00 | 00,159,810 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
[2006/10/26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
[2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2006/04/14 10:59:42 | 00,014,624 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe -- (ReportServer [Disabled | Stopped])
[2006/05/26 22:51:44 | 00,169,200 | ---- | M] (symantec) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam [On_Demand | Stopped])
[2005/10/19 18:39:34 | 00,214,672 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [Auto | Running])
[2005/03/30 22:48:22 | 00,992,864 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc [Auto | Running])
[2006/04/14 11:05:58 | 00,240,416 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser [Disabled | Stopped])
[2006/04/14 11:06:10 | 00,319,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE -- (SQLSERVERAGENT [On_Demand | Stopped])
[2006/04/14 11:04:54 | 00,087,840 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter [On_Demand | Stopped])
[2006/05/26 22:51:42 | 01,764,592 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus [Auto | Running])
[2005/01/28 14:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running])
[2006/11/03 19:19:58 | 00,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend [Auto | Running])
========== Driver Services ========== [2008/10/08 02:27:58 | 00,000,220 | -HS- | M] () -- C:\WINDOWS\System32\drivers\02658.DAT -- (02658 [Boot | Stopped])
[2008/10/08 02:27:58 | 00,000,220 | -HS- | M] () -- C:\WINDOWS\System32\drivers\99959.DAT -- (99959 [System | Stopped])
[2008/10/08 02:27:58 | 00,000,220 | -HS- | M] () -- C:\WINDOWS\System32\drivers\9ce5A.DAT -- (9ce5A [Auto | Stopped])
[2002/04/01 11:15:00 | 00,004,816 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (aeaudio [On_Demand | Running])
[2006/12/26 23:33:37 | 00,021,035 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP [Auto | Running])
[2004/12/13 16:14:00 | 00,039,904 | ---- | M] (Adaptec, Inc.) -- C:\WINDOWS\System32\drivers\cercsr6.sys -- (cercsr6 [Boot | Stopped])
[2002/11/12 11:02:20 | 00,099,840 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\e1000325.sys -- (E1000 [On_Demand | Running])
[2008/09/21 01:00:00 | 00,371,248 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl [System | Running])
[2008/10/10 01:00:00 | 00,099,376 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv [On_Demand | Running])
[2004/02/10 10:17:06 | 00,681,469 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\ialmnt5.sys -- (ialm [On_Demand | Stopped])
[2008/04/14 00:09:50 | 00,014,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\kbdhid.sys -- (kbdhid [System | Running])
[2008/10/10 01:00:00 | 00,089,104 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081015.003\NAVENG.SYS -- (NAVENG [On_Demand | Running])
[2008/10/10 01:00:00 | 00,873,552 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081015.003\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
[2004/08/04 05:00:00 | 00,098,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\NBF.SYS -- (Nbf [Auto | Running])
[2006/10/22 13:22:00 | 03,994,624 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Running])
[2004/08/04 05:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2006/03/27 18:53:28 | 00,167,808 | ---- | M] (NETGEAR Inc.) -- C:\WINDOWS\system32\drivers\wg111v2.sys -- (RTLWUSB [On_Demand | Stopped])
[2005/12/19 23:41:56 | 00,337,592 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT [System | Running])
[2005/12/19 23:41:58 | 00,054,968 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL [System | Running])
[2008/04/13 22:09:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2002/12/19 18:48:48 | 00,539,008 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])
[2001/08/17 13:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
[2005/03/30 22:48:20 | 00,372,832 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv [System | Running])
[2005/09/17 01:20:06 | 00,108,168 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
[2005/10/19 18:38:58 | 00,024,720 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symredrv.sys -- (SYMREDRV [On_Demand | Running])
[2005/10/19 18:39:04 | 00,195,728 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symtdi.sys -- (SYMTDI [System | Running])
[2008/06/20 06:08:27 | 00,225,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6 [System | Running])
[2008/04/14 00:26:02 | 00,012,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\tunmp.sys -- (tunmp [On_Demand | Running])
[2005/07/26 11:13:42 | 00,057,648 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\z520bus.sys -- (z520bus [On_Demand | Stopped])
[2005/07/26 11:15:16 | 00,008,336 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\z520mdfl.sys -- (z520mdfl [On_Demand | Stopped])
[2005/07/26 11:15:22 | 00,093,488 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\z520mdm.sys -- (z520mdm [On_Demand | Stopped])
[2005/07/26 11:16:44 | 00,084,928 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\z520mgmt.sys -- (z520mgmt [On_Demand | Stopped])
[2005/07/26 11:18:02 | 00,082,864 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\z520obex.sys -- (z520obex [On_Demand | Stopped])
========== (R ) Internet Explorer ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=
"Default_Search_URL"=
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://hsremove.com/done.htm
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=
"Start Page"=http://www.yahoo.com/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=
"Start Page"=http://www.yahoo.com/
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ========== HOSTS File = (250769 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.1001-search.info
127.0.0.1 1001-search.info
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.123topsearch.com
127.0.0.1 123topsearch.com
127.0.0.1 www.132.com
127.0.0.1 132.com
127.0.0.1 www.136136.net
127.0.0.1 136136.net
8742 more lines...
========== (O2) BHO's ========== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{00C6482D-C502-44C8-8409-FCE54AD9C208} (HKLM) -- c:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll (TechSmith Corporation)
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
{AE7CD045-E861-484f-8273-0445EE161910} (HKLM) -- C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
========== (O3) Toolbars ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) -- C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}" (HKLM) -- c:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll (TechSmith Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) -- C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) -- C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) -- C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) -- C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
========== (O4) Run Keys ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
"CoolSwitch"=C:\WINDOWS\system32\taskswitch.exe ()
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
"LWBMOUSE"=C:\Program Files\Belkin Mouse 1.0\MOUSE32A.EXE ()
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"NvMediaCenter"=RunDLL32.exe NvMCTray.dll,NvTaskbarInit (NVIDIA Corporation)
"nwiz"=nwiz.exe /install ()
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
"vptray"=C:\PROGRA~1\SYMANT~1\\vptray.exe (Symantec Corporation)
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)
========== (O4) RunOnceEx Keys ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
"Flags"= File not found
"Title"=UnHackMe Rootkit Check File not found
========== (O4) Startup Folders ========== [2003/10/14 02:11:40 | 00,110,592 | ---- | M] (Adobe Systems, Inc.) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.LNK = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
========== (O6 & O7) Current Version Policies ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoRecentDocsMenu"=01 00 00 00 [binary data]
"ClearRecentDocsOnExit"= [binary data]
"NoRecentDocsHistory"= [binary data]
"NoSharedDocuments"=01 00 00 00 [binary data]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"NoDispBackgroundPage"=0
"NoDispScrSavPage"=0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoRecentDocsMenu"=01 00 00 00 [binary data]
"ClearRecentDocsOnExit"= [binary data]
"NoRecentDocsHistory"= [binary data]
"NoSharedDocuments"=01 00 00 00 [binary data]
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"NoDispBackgroundPage"=0
"NoDispScrSavPage"=0
========== (O8) IE Context Menu Extensions ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MI69DF~1\Office12\EXCEL.EXE File not found
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MI69DF~1\Office12\EXCEL.EXE File not found
========== (O9) IE Extensions ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.6.0\bin\npjpi160.dll [2007/01/04 04:30:26 | 00,132,744 | ---- | M] (Sun Microsystems, Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2007/04/19 15:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 15:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 15:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.microsoft.com/controls/find...=%s&mime=%sPluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
41 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
texashealth.org: https in Trusted sites
texashealth.org\cag2: https in My Computer
turbotax.com: https in Trusted sites
40 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
40 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
40 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
texashealth.org: https in Trusted sites
texashealth.org\cag2: https in My Computer
turbotax.com: https in Trusted sites
40 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}:
http://www.apple.com/qtactivex/qtplugin.cab -- QuickTime Object
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}:
http://download.microsoft.com/download/e/7.../OGAControl.cab -- Office Genuine Advantage Validation Tool
{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}:
http://download.microsoft.com/download/a/f...tualEarth3D.cab -- Reg Error: Key does not exist or could not be opened.
{1239CC52-59EF-4DFA-8C61-90FFA846DF7E}:
http://www.musicnotes.com/download/mnviewer.cab -- Musicnotes Viewer
{17492023-C23A-453E-A040-C7C580BBF700}:
http://download.microsoft.com/download/5/B...heckControl.cab -- Windows Genuine Advantage Validation Tool
{238F6F83-B8B4-11CF-8771-00A024541EE3}:
https://cag.texashealth.org/CitrixSessionIn...AWEB/icaweb.cab -- Citrix ICA Client
{31435657-9980-0010-8000-00AA00389B71}:
http://download.microsoft.com/download/e/2...78f/wvc1dmo.cab -- Reg Error: Key does not exist or could not be opened.
{406B5949-7190-4245-91A9-30A17DE16AD0}:
http://photo.walgreens.com/WalgreensActivia.cab -- Snapfish Activia
{6414512B-B978-451D-A0D8-FCFDF33E833C}:
http://update.microsoft.com/microsoftupdat...b?1199325768359 -- WUWebControl Class
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}:
http://update.microsoft.com/microsoftupdat...b?1199325426171 -- MUWebControl Class
{74C861A1-D548-4916-BC8A-FDE92EDFF62C}:
http://mediaplayer.walmart.com/installer/install.cab -- Reg Error: Key does not exist or could not be opened.
{85BA505F-FD01-4A91-836C-F7D502E89C9A}:
http://www.evite.com/html/imageUpload/ImageUploader4.cab -- Image Uploader Control
{8AD9C840-044E-11D1-B3E9-00805F499D93}:
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0
{C7DB51B4-BCF7-4923-8874-7F1A0DC92277}:
http://office.microsoft.com/officeupdate/content/opuc4.cab -- Office Update Installation Engine
{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0
{D27CDB6E-AE6D-11CF-96B8-444553540000}:
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab -- Shockwave Flash Object
{EB387D2F-E27B-4D36-979E-847D1036C65D}:
http://h30155.www3.hp.com/ediags/hpfix/sj/.../qdiagh.cab?326 -- QDiagHUpdateObj Class
========== (O17) DNS Name Servers ========== {0DFC80AD-6794-4553-9689-F3EDE8EACCF3} (Servers: | Description: NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter)
{F17FAE5F-C7BC-448D-A6E8-39AECA994915} (Servers: | Description: Intel® PRO/1000 MT Network Connection)
========== (O20) Winlogon Notify Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
igfxcui: "DllName" = igfxsrvc.dll -- C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
NavLogon: "DllName" = C:\WINDOWS\system32\NavLogon.dll -- C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
========== Shell Execute Hooks ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
========== Safeboot Options ========== "AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Files/Folders - Created Within 30 Days ========== [2008/10/17 02:22:44 | 00,019,968 | ---- | C] () -- C:\Documents and Settings\kman\Desktop\Lisa.doc
[2008/10/17 00:29:00 | 00,303,921 | ---- | C] () -- C:\Documents and Settings\kman\Desktop\SnowDay16Oct08.JPG
[2008/10/16 20:41:06 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2008/10/16 20:39:50 | 00,010,485 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2008/10/12 07:00:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2008/10/11 10:25:02 | 00,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2008/10/11 10:22:00 | 00,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2008/10/10 00:03:49 | 00,001,787 | ---- | C] () -- C:\Documents and Settings\kman\Desktop\HijackThis.lnk
[2008/10/10 00:03:48 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2008/10/08 02:27:58 | 00,000,220 | -HS- | C] () -- C:\WINDOWS\System32\drivers\9ce5A.DAT
[2008/10/08 02:27:58 | 00,000,220 | -HS- | C] () -- C:\WINDOWS\System32\drivers\99959.DAT
[2008/10/08 02:27:58 | 00,000,220 | -HS- | C] () -- C:\WINDOWS\System32\drivers\02658.DAT
[2008/10/05 21:25:22 | 00,004,096 | -HS- | C] () -- C:\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Thumbs.db:encryptable
[2008/10/02 11:56:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\kman\Application Data\ZoomBrowser EX
[2008/10/02 11:53:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\kman\Application Data\CameraWindowDC
[2008/10/02 11:53:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\kman\Application Data\CANON INC
[2008/10/02 10:49:23 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2008/10/02 10:49:23 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2008/10/02 10:48:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/09/24 23:11:59 | 00,004,608 | -HS- | C] () -- C:\WINDOWS\System32\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\System32\Thumbs.db:encryptable
[2008/09/24 22:47:14 | 00,000,000 | ---D | C] -- C:\!KillBox
[2008/09/24 22:38:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\kman\Desktop\Rootkit Removal
[2008/09/24 19:27:10 | 00,014,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\kbdhid.sys
[2008/09/24 19:26:42 | 00,010,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidusb.sys
[2008/09/22 20:43:28 | 00,002,184 | ---- | C] () -- C:\WINDOWS\System32\wpa.dbl
[2008/09/22 19:41:44 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\zzz
[2008/09/22 19:32:13 | 00,003,109 | ---- | C] () -- C:\Documents and Settings\kman\Desktop\rootkit.csv
[2008/09/22 17:39:01 | 00,000,002 | RHS- | C] () -- C:\WINDOWS\winstart.bat
[2008/09/22 17:38:34 | 00,000,000 | ---D | C] -- E:\Documents and Settings\kman\My Documents\RegRun2
[2008/09/22 17:38:28 | 00,000,000 | ---D | C] -- C:\Program Files\UnHackMe
[2008/09/21 01:44:34 | 00,001,689 | ---- | C] () -- C:\Documents and Settings\kman\Desktop\Symantec AntiVirus.lnk
[2008/09/20 23:30:11 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Common
========== Files - Modified Within 30 Days ========== [2008/10/17 08:40:43 | 00,015,360 | -HS- | M] () -- C:\Documents and Settings\kman\Desktop\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\kman\Desktop\Thumbs.db:encryptable
[2008/10/17 03:00:11 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2008/10/17 02:27:21 | 00,000,272 | ---- | M] () -- C:\WINDOWS\tasks\defrag.job
[2008/10/17 02:22:45 | 00,019,968 | ---- | M] () -- C:\Documents and Settings\kman\Desktop\Lisa.doc
[2008/10/17 00:29:00 | 00,303,921 | ---- | M] () -- C:\Documents and Settings\kman\Desktop\SnowDay16Oct08.JPG
[2008/10/16 21:02:27 | 00,731,740 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2008/10/16 21:02:27 | 00,586,022 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2008/10/16 21:02:27 | 00,131,432 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2008/10/16 20:59:14 | 00,010,485 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2008/10/16 20:28:57 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/10/16 20:28:36 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008/10/16 08:02:03 | 00,078,336 | ---- | M] () -- C:\Documents and Settings\kman\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/15 00:49:09 | 00,010,752 | -HS- | M] () -- C:\WINDOWS\Thumbs.db
[2008/10/15 00:49:09 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2008/10/12 07:02:06 | 00,000,224 | ---- | M] () -- C:\WINDOWS\tasks\CleanUp.job
[2008/10/12 06:00:03 | 00,000,222 | ---- | M] () -- C:\WINDOWS\tasks\chkdsk.job
[2008/10/10 00:03:49 | 00,001,787 | ---- | M] () -- C:\Documents and Settings\kman\Desktop\HijackThis.lnk
[2008/10/08 02:27:58 | 00,000,220 | -HS- | M] () -- C:\WINDOWS\System32\drivers\9ce5A.DAT
[2008/10/08 02:27:58 | 00,000,220 | -HS- | M] () -- C:\WINDOWS\System32\drivers\99959.DAT
[2008/10/08 02:27:58 | 00,000,220 | -HS- | M] () -- C:\WINDOWS\System32\drivers\02658.DAT
[2008/10/07 22:10:07 | 00,002,184 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008/10/05 21:25:23 | 00,004,096 | -HS- | M] () -- C:\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Thumbs.db:encryptable
[2008/10/02 10:49:23 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2008/10/02 10:49:23 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2008/09/24 23:11:59 | 00,004,608 | -HS- | M] () -- C:\WINDOWS\System32\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\System32\Thumbs.db:encryptable
[2008/09/22 19:45:49 | 00,003,109 | ---- | M] () -- C:\Documents and Settings\kman\Desktop\rootkit.csv
[2008/09/22 17:39:01 | 00,001,688 | ---- | M] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2008/09/22 17:39:01 | 00,000,002 | RHS- | M] () -- C:\WINDOWS\winstart.bat
< End of report >
***Extras.Txt:******************************************************************
*********************
********************************************************************************
*******************
OTViewIt Extras logfile created on: 10/17/2008 6:25:20 PM - Run 3
OTViewIt by OldTimer - Version 1.0.15.0 Folder = C:\Documents and Settings\kman\Desktop\Rootkit Removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.99 Mb Total Physical Memory | 471.41 Mb Available Physical Memory | 46.08% Memory free
3.40 Gb Paging File | 3.02 Gb Available in Paging File | 88.75% Paging File free
Paging file location(s): C:\pagefile.sys 2560 2560;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.17 Gb Total Space | 76.99 Gb Free Space | 82.63% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 69.86 Gb Total Space | 35.06 Gb Free Space | 50.19% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive R: | 69.86 Gb Total Space | 27.81 Gb Free Space | 39.81% Space Free | Partition Type: NTFS
Drive Z: | 69.86 Gb Total Space | 35.06 Gb Free Space | 50.19% Space Free | Partition Type: NTFS
Computer Name: DELL-P4
Current User Name: kman
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== File Associations ==========[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.scr [@ = scrfile] -- "%1" /s
========== Security Center Settings ==========[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=1
"DoNotAllowExceptions"=0
"DisableNotifications"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\IcmpSettings]
========== Authorized Applications List ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/14 05:42:36 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008/04/14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/14 05:42:36 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008/06/23 04:20:52 | 00,625,664 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer
File not found -- C:\Program Files\Pando Networks\Pando\pando.exe:*:Disabled:pando
[2008/04/14 05:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
[2008/04/14 05:42:22 | 00,769,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice
File not found -- C:\Program Files\TurboTax\Home & Business 2006\32bit\ttax.exe:LocalSubNet:Disabled:TurboTax
File not found -- C:\Program Files\TurboTax\Home & Business 2006\32bit\updatemgr.exe:LocalSubNet:Disabled:TurboTax Update Manager
[2008/04/14 00:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
File not found -- C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player
========== (O10) Winsock2 Catalogs ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000004 [PNRP Cloud Namespace Provider] -- C:\WINDOWS\system32\pnrpnsp.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000005 [PNRP Name Namespace Provider] -- C:\WINDOWS\system32\pnrpnsp.dll (Microsoft Corporation)
========== (O18) Protocol Handlers ==========[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2006/10/26 19:49:48 | 01,011,488 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2006/10/26 19:49:48 | 01,011,488 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2006/10/26 19:49:48 | 01,011,488 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2006/10/26 13:45:02 | 00,873,216 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (ms-help:{314111c7-a502-11d2-bbca-00c04f8ec294} (HKLM) [HxProtocol Class])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2000/04/19 19:47:36 | 00,520,117 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (ms-itss:{0A9007C0-4076-11D3-8789-0000F8105754} (HKLM) [Microsoft Infotech Storage Protocol for IE 4.0])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/03/14 14:10:22 | 07,255,384 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/05/10 14:45:34 | 08,069,464 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler])
========== (O18) Protocol Filters ==========[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2006/10/26 21:41:48 | 00,044,344 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL text/xml:{807563E5-5146-11D5-A672-00B0D022E945} (HKLM) [Microsoft Office InfoPath XML Mime Filter]
========== HKEY_LOCAL_MACHINE Uninstall List ==========[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}"=Macromedia Dreamweaver MX 2004
"{0B43A744-B1B8-4089-9BD1-9D41C7EC0AA3}"=Microsoft SQL Server 2005 Books Online (English)
"{10CE1EA2-12E9-11D3-825E-00C04F6843FE}"=Microsoft Office Sounds
"{1389C6A4-4965-4AEC-9175-08B54A10FA48}"=Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
"{1DB2FBA5-D57A-42A7-8E87-5B3EEBED8283}"=Wal-Mart Music Downloads Store
"{2243F21A-E132-44F7-BA13-024D0845C815}"=Microsoft SQL Server 2005 Backward compatibility
"{2373A92B-1C1C-4E71-B494-5CA97F96AA19}"=Microsoft SQL Server 2005
"{23959E96-A80F-4172-A655-210E9BB7BFBE}"=MSDN Library for Visual Studio 2005
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}"=Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{2F353D44-73BB-4971-B31D-F7642E9E9531}"=Macromedia Flash MX 2004
"{3248F0A8-6813-11D6-A77B-00B0D0160000}"=Java SE Runtime Environment 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{3686E7AE-19F9-470B-8D8C-02AE68A7B11B}"=Sony Ericsson PC Suite
"{3BDB182E-8371-46BD-AC39-C14A91D5EEF8}"=Microsoft SQL Server 2005 Reporting Services
"{437AB8E0-FB69-4222-B280-A64F3DE22591}"=Microsoft Visual Studio 2005 Professional Edition - ENU
"{44D4AF75-6870-41F5-9181-662EA05507E1}"=Microsoft Document Explorer 2005
"{46B63F23-2B4A-4525-A827-688026BE5E40}"=Symantec AntiVirus
"{50A0893D-47D8-48E0-A7E8-44BCD7E4422E}"=Microsoft SQL Server Native Client
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}"=Microsoft SQL Server Setup Support Files (English)
"{625386A4-B6B6-4911-A6E8-23189C3F2D15}"=Microsoft .NET Compact Framework 2.0
"{63A5DC0D-1EDD-4D69-8F31-87FAEB1F7084}"=Microsoft SQL Server 2005 Notification Services
"{6855CCDD-BDF9-48E4-B80A-80DFB96FE36C}"=CmdHere Powertoy For Windows XP
"{68A35043-C55A-4237-88C9-37EE1C63ED71}"=Microsoft Visual J# 2.0 Redistributable Package
"{6C531060-84FB-4F96-8F33-29DF020632EB}"=Microsoft .NET Compact Framework 1.0 SP3 Developer
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"=Microsoft .NET Framework 2.0
"{78B75C6D-E53C-424C-BF83-4B63BD4A6682}"=Microsoft Device Emulator version 1.0 - ENU
"{7F231232-C309-4401-964A-2A002B6E1ED9}"=Microsoft Baseline Security Analyzer 2.0.1
"{8DB2C22D-A23A-4C0E-9A56-7D10440B9B40}"=Microsoft Office Outlook 2003 Calendar Views Add-in
"{90032DD0-ABEE-4424-AC1E-B076BDD4E350}"=Microsoft SQL Server 2005 Tools
"{90120000-0010-0409-0000-0000000FF1CE}"=Microsoft Software Update for Web Folders (English) 12
"{90120000-001F-0409-0000-0000000FF1CE}"=Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}"=Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}"=Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}"=Microsoft Office Proofing (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}"=Microsoft Office Visio MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}"=Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}"=Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90A40409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office 2003 Web Components
"{91110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003
"{91120000-0051-0000-0000-0000000FF1CE}"=Microsoft Office Visio Professional 2007
"{91170409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office FrontPage 2003
"{939740B5-0064-4779-854A-8C1086181C05}"=Macromedia FreeHand MXa
"{95120000-0038-0409-0000-0000000FF1CE}"=Time Zone Data Update Tool for Microsoft Office Outlook
"{97AB9822-39D9-11D6-BBC2-0000CB591583}"=A.F.5 Rename your files 1.1
"{982DB00A-9C4E-436B-8707-18E113BAA44C}"=Microsoft SQL Server 2005 Analysis Services
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}"=Google SketchUp 6
"{A06275F4-324B-4E85-95E6-87B2CD729401}"=Windows Defender
"{A188FCCF-E929-494D-B1F1-4313E02ACD52}"=SQLXML4
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}"=Macromedia Extension Manager
"{A7050037-F0EA-4BAB-BCD5-FC05507D6147}"=Alt-Tab Task Switcher Powertoy for Windows XP
"{AC76BA86-1033-0000-7760-000000000001}"=Adobe Acrobat 6.0 Professional
"{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}"=Google SketchUp 6
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1"=Spybot - Search & Destroy
"{B510A987-487E-4C66-9F4F-D386AC275715}"=TextPad 4.7
"{C0D2F614-5CE5-4DCB-8678-E5C9AF7044F8}"=Microsoft SQL Server VSS Writer
"{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}"=QuickTime
"{C25EF637-BE7A-4761-9B45-9069989C319F}"=Microsoft Visual Studio 2005 Premier Partner Edition - ENU
"{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}"=ClearType Tuning Control Panel Applet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{D52ECEBC-9B20-41A5-81C4-A62DE2367419}"=Adobe Creative Suite
"{DA0BF7AB-88EB-4675-8FA1-531EAD938821}"=SnagIt 8
"{E0A41F96-7231-4AE8-A654-EEB34F935462}"=Microsoft SQL Server 2005 Integration Services
"{E583ED6F-BD99-4066-A420-C815BF692B69}"=Macromedia Fireworks MX 2004
"{E9459BCF-0982-498B-ABA7-26C34323493F}"=Citrix Presentation Server Client - Web Only
"{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}"=Microsoft Plus! for Windows XP
"{F0A37341-D692-11D4-A984-009027EC0A9C}"=SoundMAX
"Ad-Aware SE Personal"=Ad-Aware SE Personal
"Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player Plugin
"Adobe SVG Viewer"=Adobe SVG Viewer 3.0
"AsfTools 3.1"=AsfTools 3.1 (remove only)
"AVBrosPageCurl"=AV Bros. Page Curl 1.2 (Remove Only)
"Belkin Mouse Belkin Mouse"=Belkin Mouse 1.0
"CCleaner"=CCleaner (remove only)
"Citrix ICA Web Client"=Citrix Presentation Server Web Client for Win32
"Eye Candy 4000"=Eye Candy 4000
"Free Mp3 Wma Converter_is1"=Free Mp3 Wma Converter V 1.5.3
"HijackThis"=HijackThis 2.0.2
"HP Deskjet 3840 Series_Driver"=HP Deskjet 3840 Series
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"InstallShield_{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}"=QuickTime
"LiveUpdate"=LiveUpdate 2.6 (Symantec Corporation)
"MetaFrame Presentation Server Web Client for Win32"=MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0"=Microsoft .NET Framework 2.0
"Microsoft Document Explorer 2005"=Microsoft Document Explorer 2005
"Microsoft SQL Server 2005"=Microsoft SQL Server 2005
"Microsoft Visual J# 2.0 Redistributable Package"=Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual Studio 2005 Professional Edition - ENU"=Microsoft Visual Studio 2005 Professional Edition - ENU
"Mozilla Firefox (2.0.0.12)"=Mozilla Firefox (2.0.0.12)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"MSDN Library for Visual Studio 2005"=MSDN Library for Visual Studio 2005
"NeroMultiInstaller!UninstallKey"=Nero Suite
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers"=NVIDIA Drivers
"OnlineBible"=Online Bible 10.00.02
"Photon"=Professor Franklin
"PROSet"=Intel® PRO Ethernet Adapter and Software
"RealPlayer 6.0"=RealPlayer
"Spybot - Search & Destroy_is1"=Spybot - Search & Destroy 1.5.2.20
"ST6UNST #1"=NoClone
"Tweak UI 2.10"=Tweak UI
"TweakNow RegCleaner Standard_is1"=TweakNow RegCleaner Standard
"VISPROR"=Microsoft Office Visio Professional 2007
"WIC"=Windows Imaging Component
"Windows Media Format Runtime"=Windows Media Format Runtime
"Windows Media Player"=Windows Media Player 10
"Windows XP Service Pack"=Windows XP Service Pack 3
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting"=GoToMeeting/GoToWebinar 3.0.0.198
"OnlineBible"=Online Bible 10.00.02
========== HKEY_USERS Uninstall List ==========[HKEY_USERS\S-1-5-21-1085031214-448539723-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting"=GoToMeeting/GoToWebinar 3.0.0.198
"OnlineBible"=Online Bible 10.00.02
========== Last 10 Event Log Errors ==========[ Application Events ]
Error - 10/16/2008 9:32:05 PM | Computer Name = DELL-P4 | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\PROGRA~1\SYMANT~1\vptray.exe
Event
Info: Open Process Action Taken: Blocked Actor Process: C:\WINDOWS\system32\rundll32.exe
(PID 3052) Time: Thursday, October 16, 2008 8:32:05 PM
Error - 10/16/2008 9:32:05 PM | Computer Name = DELL-P4 | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Common Files\Symantec
Shared\ccApp.exe Event Info: Open Process Action Taken: Blocked Actor Process:
C:\WINDOWS\system32\rundll32.exe (PID 3052) Time: Thursday, October 16, 2008 8:32:05
PM
Error - 10/16/2008 9:32:05 PM | Computer Name = DELL-P4 | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Common Files\Symantec
Shared\ccApp.exe Event Info: Open Process Action Taken: Blocked Actor Process:
C:\WINDOWS\system32\rundll32.exe (PID 3052) Time: Thursday, October 16, 2008 8:32:05
PM
Error - 10/16/2008 9:32:06 PM | Computer Name = DELL-P4 | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\Rtvscan.exe Event Info: Open Process Action Taken: Blocked Actor Process:
C:\WINDOWS\system32\rundll32.exe (PID 3052) Time: Thursday, October 16, 2008
8:32:06 PM
Error - 10/16/2008 9:32:06 PM | Computer Name = DELL-P4 | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\Rtvscan.exe Event Info: Open Process Action Taken: Blocked Actor Process:
C:\WINDOWS\system32\rundll32.exe (PID 3052) Time: Thursday, October 16, 2008
8:32:06 PM
Error - 10/16/2008 9:32:06 PM | Computer Name = DELL-P4 | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\DoScan.exe Event Info: Open Process Action Taken: Blocked Actor Process:
C:\WINDOWS\system32\rundll32.exe (PID 3052) Time: Thursday, October 16, 2008
8:32:06 PM
Error - 10/16/2008 9:32:06 PM | Computer Name = DELL-P4 | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\PROGRA~1\SYMANT~1\vptray.exe
Event
Info: Open Process Action Taken: Blocked Actor Process: C:\WINDOWS\system32\rundll32.exe
(PID 3052) Time: Thursday, October 16, 2008 8:32:06 PM
Error - 10/16/2008 9:32:06 PM | Computer Name = DELL-P4 | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\PROGRA~1\SYMANT~1\vptray.exe
Event
Info: Open Process Action Taken: Blocked Actor Process: C:\WINDOWS\system32\rundll32.exe
(PID 3052) Time: Thursday, October 16, 2008 8:32:06 PM
Error - 10/16/2008 9:32:07 PM | Computer Name = DELL-P4 | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Common Files\Symantec
Shared\ccApp.exe Event Info: Open Process Action Taken: Blocked Actor Process:
C:\WINDOWS\system32\rundll32.exe (PID 3052) Time: Thursday, October 16, 2008 8:32:07
PM
Error - 10/16/2008 9:32:07 PM | Computer Name = DELL-P4 | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Common Files\Symantec
Shared\ccApp.exe Event Info: Open Process Action Taken: Blocked Actor Process:
C:\WINDOWS\system32\rundll32.exe (PID 3052) Time: Thursday, October 16, 2008 8:32:07
PM
[ System Events ]
Error - 10/14/2008 8:37:22 AM | Computer Name = DELL-P4 | Source = Service Control Manager | ID = 7000
Description = The 9ce5A service failed to start due to the following error: %%2
Error - 10/14/2008 8:37:22 AM | Computer Name = DELL-P4 | Source = Service Control Manager | ID = 7000
Description = The ASPI32 service failed to start due to the following error: %%2
Error - 10/14/2008 8:37:29 AM | Computer Name = DELL-P4 | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 10/15/2008 11:37:39 PM | Computer Name = DELL-P4 | Source = Service Control Manager | ID = 7000
Description = The 9ce5A service failed to start due to the following error: %%2
Error - 10/15/2008 11:37:39 PM | Computer Name = DELL-P4 | Source = Service Control Manager | ID = 7000
Description = The ASPI32 service failed to start due to the following error: %%2
Error - 10/15/2008 11:37:39 PM | Computer Name = DELL-P4 | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 10/15/2008 11:40:42 PM | Computer Name = DELL-P4 | Source = DCOM | ID = 10010
Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
with DCOM within the required timeout.
Error - 10/16/2008 9:29:21 PM | Computer Name = DELL-P4 | Source = Service Control Manager | ID = 7000
Description = The 9ce5A service failed to start due to the following error: %%2
Error - 10/16/2008 9:29:21 PM | Computer Name = DELL-P4 | Source = Service Control Manager | ID = 7000
Description = The ASPI32 service failed to start due to the following error: %%2
Error - 10/16/2008 9:32:25 PM | Computer Name = DELL-P4 | Source = DCOM | ID = 10010
Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
with DCOM within the required timeout.
< End of report >
***gmer.txt:********************************************************************
**************
********************************************************************************
*************
GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2008-10-17 23:18:58
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
SSDT 86587618 ZwConnectPort
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xF5207DC0]
SSDT 864AD360 ZwDuplicateObject
SSDT 865C2308 ZwOpenProcess
SSDT 865C2230 ZwOpenThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xF5208020]
---- Kernel code sections - GMER 1.0.14 ----
.text ntoskrnl.exe!_abnormal_termination + C8 804E2724 2 Bytes [ 18, 76 ]
.text ntoskrnl.exe!_abnormal_termination + CB 804E2727 1 Byte [ 86 ]
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
---- EOF - GMER 1.0.14 ----