This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Vundo!grb Removal?

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi beachbriant,

Please do the following:


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


NEXT

Locate OTListIt2 on your desktop (I had you download it previously)
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Make sure under Extra Registry the Use SafeList is checked.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of both these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

In your next response I need

  • MBAM log
  • Fresh OTListItlog log


Pleas also advise how your computer is running now
PC seems to be running fine, but each scan finds more trojans….

******mbam-log output follows*******

Malwarebytes' Anti-Malware 1.34
Database version: 1799
Windows 5.1.2600 Service Pack 3

2/24/2009 5:44:43 PM
mbam-log-2009-02-24 (17-44-43).txt

Scan type: Full Scan (C:\|)
Objects scanned: 210252
Time elapsed: 2 hour(s), 14 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d528dc7d-3f68-42e3-8105-5611ffd81e6f} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d528dc7d-3f68-42e3-8105-5611ffd81e6f} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{263bea5d-83ca-4197-95c1-6192454c115d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{263bea5d-83ca-4197-95c1-6192454c115d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vasobupizu (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINNT\system32\zqrtba.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.


*******OTListIt.txt*********
OTListIt logfile created on: 2/24/2009 5:56:01 PM - Run 10
OTListIt2 by OldTimer - Version 2.0.0.18 Folder = C:\Documents and Settings\briant\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.20 Mb Total Physical Memory | 405.26 Mb Available Physical Memory | 39.92% Memory free
1.64 Gb Paging File | 1.20 Gb Available in Paging File | 73.18% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 13.30 Gb Free Space | 35.69% Space Free | Partition Type: NTFS
Drive D: | 702.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive W: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS
Drive X: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS
Drive Y: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS
Drive Z: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS

Computer Name: bcantrell2
Current User Name: briant
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe (Hewlett-Packard Company)
PRC - C:\PROGRAM FILES\DRU\bin\DRUService.exe (AT&T)
PRC - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe (Hummingbird Ltd.)
PRC - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe (Hummingbird Ltd.)
PRC - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\hjavaw.exe (Hummingbird Ltd.)
PRC - c:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Java\jre1.5.0_13\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - c:\Program Files\Network Associates\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\AT&T Global Network Client\netcfgsvr.exe (AT&T)
PRC - C:\WINNT\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINNT\system32\pstartSr.exe ()
PRC - C:\WINNT\system32\snmpdm.exe ()
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\Program Files\compapps\swstore\ssservice.exe ()
PRC - C:\Program Files\Doctor Install\DrInstalSvc.exe (AT&T)
PRC - C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe ()
PRC - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe (Intel)
PRC - C:\WINNT\System32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\WINNT\system32\CCM\CcmExec.exe (Microsoft Corporation)
PRC - C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe (1E Ltd.)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Cpqdmi.exe (Compaq Computer Corporation)
PRC - C:\WINNT\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_gui.exe ()
PRC - C:\WINNT\System32\igfxtray.exe (Intel Corporation)
PRC - C:\WINNT\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Chkadmin.exe (Hewlett-Packard Company)
PRC - C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe (Compaq Computer Corporation)
PRC - C:\Program Files\Network Associates\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - c:\Program Files\Network Associates\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Program Files\Doctor Install\InstallMgr.exe (AT&T)
PRC - C:\WINNT\system32\carpserv.exe (Conexant Systems)
PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
PRC - C:\WINNT\Logi_MwX.Exe (Logitech Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
PRC - C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe (Check Point Software Tech Ltd)
PRC - C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE (HP Company)
PRC - C:\Compaq\EAKDRV\EAUSBKBD.EXE (Compaq)
PRC - C:\WINNT\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Compaq\Easy Access Button Support\BttnServ.exe (Compaq Computer Corporation)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe (Microsoft Corporation)
PRC - C:\Program Files\Linksys\Bluetooth Utility\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Linksys\Bluetooth Utility\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Documents and Settings\briant\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (btwdins [Auto | Running]) – C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe (Broadcom Corporation.)
SRV - (CcmExec [Auto | Running]) – C:\WINNT\system32\CCM\CcmExec.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CPQALERT [Auto | Running]) – C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe (Hewlett-Packard Company)
SRV - (cpqdmi [Auto | Running]) – C:\Program Files\Compaq\Compaq Management Agents\Cpqdmi.exe (Compaq Computer Corporation)
SRV - (DRUAgent [Auto | Running]) – C:\PROGRAM FILES\DRU\bin\DRUService.exe (AT&T)
SRV - (ExtranetAccess [On_Demand | Stopped]) – C:\Program Files\Nortel Networks\Extranet_serv.exe (Nortel Networks NA, Inc.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINNT\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (HCLInetd [Auto | Running]) – C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe (Hummingbird Ltd.)
SRV - (helpsvc [Auto | Running]) – C:\WINNT\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – c:\WINNT\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (Jconfigd [Auto | Running]) – C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe (Hummingbird Ltd.)
SRV - (McAfeeFramework [Auto | Running]) – c:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (McShield [Auto | Running]) – C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
SRV - (McTaskManager [Auto | Running]) – C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (MDM [Auto | Running]) – c:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (netcfgsvr [Auto | Running]) – C:\Program Files\AT&T Global Network Client\netcfgsvr.exe (AT&T)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – c:\WINNT\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (OracleOraHome90ClientCache [On_Demand | Stopped]) – C:\oracle\ora90\BIN\ONRSD.EXE ()
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pointsec_start [Auto | Running]) – C:\WINNT\system32\pstartSr.exe ()
SRV - (rcmdsvc [On_Demand | Stopped]) – File not found
SRV - (SMSWUagent [Auto | Running]) – C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe (1E Ltd.)
SRV - (snmpdm [Auto | Running]) – C:\WINNT\system32\snmpdm.exe ()
SRV - (SoundMAX Agent Service (default) [Auto | Running]) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (ssserviceWinService [Auto | Running]) – C:\Program Files\compapps\swstore\ssservice.exe ()
SRV - (Svc_DrInstal [Auto | Running]) – C:\Program Files\Doctor Install\DrInstalSvc.exe (AT&T)
SRV - (TRCTARGET [Auto | Running]) – C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe ()
SRV - (WIN32SL [Auto | Running]) – C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe (Intel)
SRV - (WMDM PMSP Service [Auto | Running]) – C:\WINNT\System32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Running]) – C:\WINNT\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (agnfilt [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\agnfilt.sys (AT&T)
DRV - (agnwifi [Auto | Running]) – C:\WINNT\system32\DRIVERS\agnwifi.sys (AT&T)
DRV - (avpnnic [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\avpnnic.sys (AT&T)
DRV - (b57w2k [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (btaudio [On_Demand | Running]) – C:\WINNT\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTDriver [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTSERIAL [Auto | Running]) – C:\WINNT\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTSLBCSP [Auto | Running]) – C:\WINNT\system32\drivers\btslbcsp.sys (Broadcom Corporation.)
DRV - (BTWDNDIS [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Running]) – C:\WINNT\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BVRPMPR5 [On_Demand | Stopped]) – C:\WINNT\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (ClntMgmt [System | Running]) – C:\WINNT\System32\Drivers\ClntMgmt.sys (Hewlett-Packard)
DRV - (eaps2kbd [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\eaps2kbd.sys (Compaq Computer Corp.)
DRV - (EAWDMFD [System | Running]) – C:\WINNT\system32\drivers\EAWDMFD.sys (Compaq Computer Corporation)
DRV - (gmer [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\gmer.sys (GMER)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\HSF_DP.sys (Conexant Systems)
DRV - (ialm [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (IPSECEXT [Auto | Stopped]) – C:\WINNT\System32\DRIVERS\ipsecw2k.sys (Nortel Networks)
DRV - (IPSECSHM [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ipsecw2k.sys (Nortel Networks)
DRV - (L8042Kbd [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\L8042Kbd.sys (Logitech Inc.)
DRV - (L8042mou [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\L8042mou.Sys (Logitech Inc.)
DRV - (L8042pr2 [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\L8042pr2.Sys (Logitech, Inc.)
DRV - (LMouFlt2 [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\LMouFlt2.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\LMouKE.Sys (Logitech Inc.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINNT\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mfeapfk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfeavfk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [System | Running]) – C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys (McAfee, Inc.)
DRV - (mfetdik [System | Running]) – C:\WINNT\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINNT\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (Point32 [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\point32.sys (Microsoft Corporation)
DRV - (prepdrvr [On_Demand | Running]) – C:\WINNT\system32\CCM\prepdrv.sys (Microsoft Corporation)
DRV - (prot_2k [Boot | Running]) – C:\WINNT\System32\drivers\prot_2k.sys (Check Point Software Tech Ltd)
DRV - (Ptilink [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINNT\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (scsiscan [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\scsiscan.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SMPLSCSI [Boot | Stopped]) – C:\WINNT\System32\SMPLSCSI.INF ()
DRV - (smwdm [On_Demand | Running]) – C:\WINNT\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (snmpdm_ [System | Running]) – C:\WINNT\system32\snmpdm_.sys (Guidance Software Inc.)
DRV - (StreamDispatcher [Auto | Running]) – C:\WINNT\System32\DRIVERS\strmdisp.sys (Conexant Systems)
DRV - (winachsf [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Running]) – C:\WINNT\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running]) – C:\WINNT\system32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = http://www.microsoft.com/isapi/redir.dll?P…mp;Ar=ie5update
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com//
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

O1 HOSTS File: (27 bytes) - C:\WINNT\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (CitiUSBrowserHelper Class) - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINNT\system32\BhoCitUS.dll (Orbiscom Ltd. All rights reserved.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent (Microsoft Corporation)
O4 - HKLM..\Run: [CARPService] carpserv.exe (Conexant Systems)
O4 - HKLM..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe (Compaq Computer Corporation)
O4 - HKLM..\Run: [Doctor Install] C:\Program Files\Doctor Install\InstallMgr.exe (AT&T)
O4 - HKLM..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE (Logitech Inc.)
O4 - HKLM..\Run: [Logitech Utility] Logi_MwX.Exe (Logitech Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] "c:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey (McAfee, Inc.)
O4 - HKLM..\Run: [Pointsec Tray] C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe (Check Point Software Tech Ltd)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE (McAfee, Inc.)
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [start dr install service] c:\winnt\startsrv /service=svc_drinstal (Microsoft Corporation)
O4 - HKCU..\Run: [NetSP - restore settings on power failure] "C:\Program Files\AT&T Global Network Client\NetSP.exe" -show (AT&T)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AT&T Global Network Client Monitor.lnk = C:\WINNT\Installer\{FC0FC4BA-17D0-493C-AFF4-1FDF92657457}\NetGM_1B536450052A4C0BA1B8FC31F1D473F7.exe (Macrovision Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk = C:\Program Files\Linksys\Bluetooth Utility\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: UseDefaultTile = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = Warning Notice:
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = This system is restricted solely to AT&T authorized users for legitimate business purposes only. The actual or attempted unauthorized access, use, or modification of this system is strictly prohibited by AT&T. Unauthorized users are subject to Company disciplinary proceedings and/or criminal and civil penalties under state, federal, or other applicable domestic and foreign laws. The use of this system may be monitored and recorded for administrative and security reasons. Anyone,", accessing this system exp
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: consentpromptbehavioruser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Back = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Forward = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Stop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Refresh = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Home = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Search = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_History = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Favorites = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Media = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Folders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Fullscreen = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Tools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_MailNews = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Size = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Print = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Edit = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Discussions = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Cut = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Copy = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Paste = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Encoding = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_PrintPreview = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnforceShellExtensionSecurity = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetConnectDisconnect = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie_ctx.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_13\bin\npjpi150_13.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm ()
O9 - Extra Button: Knowledge Gateway - {D666CFDA-F583-889A-323D-9F8FAF7144C3} - C:\Program Files\knowledgegateway\launch.htm ()
O9 - Extra 'Tools' menuitem : Knowledge Gateway - {D666CFDA-F583-889A-323D-9F8FAF7144C3} - C:\Program Files\knowledgegateway\launch.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] - C:\WINNT\system32\wshbth.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ameritech.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: att.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: atttest.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: attws.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: bellsouth.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: bls.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: cingular.net ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: cingularlab.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: cingularnext.net ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: pacbell.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: sbc.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: sbcdo.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: sbcld.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: sbctest.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: snet.com ([]* in Local intranet)
O16 - DPF: {08288600-E9D9-11D1-9C84-006008319186} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vantfind.cab (VanTFind.VanTFindCtrl)
O16 - DPF: {14924309-C4D4-11D1-85ED-006097794610} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkCst.cab (StkCstUserControl.StkCstMaster)
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} http://lmc.sbc.com/courses/aicc/download/a…yer/awswaxf.cab (Macromedia Authorware Web Player Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1C8B8F66-60FA-11D1-8B99-0020AFF5AA3B} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\icccdf4.cab (ucCommonDataField.ucCmnDataField)
O16 - DPF: {201CF4B6-C42D-11D1-A0EC-006008936BDD} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmStk.cab (ItemStUC.ItemStocking)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3D82A12A-C1FA-11D0-9B21-0080C79EFE90} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vanfind.cab (VanFind.VanFindCtrl)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {4117ECE7-C7FE-11D1-9844-0060089F7AEB} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkLkp.cab (StkLkpUC.StockLookup)
O16 - DPF: {413D6754-BFD4-47FE-9346-319559290BFA} https://www.webpcfos.com/webpcfos/websabre/HTEweb_new.cab (HTECtrl Class)
O16 - DPF: {4E192D78-E515-11D1-B89E-0020AFF695A0} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmMst.cab (ItmMastUC.ItemMaster)
O16 - DPF: {51BB7DFD-A6F5-4FAC-B8C9-E71CF84D082C} http://pdsnsm1/Altiris/NS/NSCap/Bin/Win32/…isNSConsole.cab (AeXNSConsoleContextHelp Class)
O16 - DPF: {60046ED9-8E77-11D0-9B21-0080C79EFE90} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vangrid.cab (VanGrid.VanGridCtrl)
O16 - DPF: {603607C4-BE6F-11D1-983A-0060089F7AEB} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCarrier.cab (CarrierUserControl.CarrierMaster)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1235086621796 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1235086609093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9345E91A-BF88-11D1-8AFE-00A02470741B} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVendCt.cab (VendorContUC.VendorCont)
O16 - DPF: {97EEFD1A-C41D-11D1-A0EC-006008936BDD} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCusLbl.cab (CustLabelsUsrCtrl.CustomLabels)
O16 - DPF: {9E85612B-D0A6-11D1-89BF-0060089F7A3E} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\SHIPVIEW.cab (ShipComp.ShipmentViewer)
O16 - DPF: {AA64AF34-C45D-11D1-85ED-006097794610} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVirDm.cab (VirDomUC.VirDomainMaster)
O16 - DPF: {ABDE29F2-6F9C-11D1-9B21-0080C79EFE90} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\VanLiteral.CAB (VanLiteral.CodeSet)
O16 - DPF: {B86D4018-C597-11D1-9843-0060089F7AEB} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucUOM.cab (UOMUserControl.UOMMaster)
O16 - DPF: {B86D4502-C597-11D1-9843-0060089F7AEB} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmCat.cab (ItemCat.ItmCatUC)
O16 - DPF: {B8958DE0-BAC9-101C-933E-0000C005958C} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\edt32x20.ocx (FarPoint DateTime Control)
O16 - DPF: {BE033B8C-722E-11D1-9B21-0080C79EFE90} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\VanMessage.CAB (VanMessage.Message)
O16 - DPF: {BE77224A-C41F-11D1-85ED-006097794610} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkDt.cab (StkDtUserControl.StkDtMaster)
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_12)
O16 - DPF: {CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_13)
O16 - DPF: {D7553B82-8EEC-11D4-AAE3-005056A35A1F} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\UPLOADCOMPONENT.cab (ATTCustomComponents.UploadComponent)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://advancedmeetings.webex.com/client/v…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {EB0CF3B4-C33B-11D1-A0EC-006008936BDD} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkSt.cab (StkStUC.StockStatusMaint)
O16 - DPF: {EB52CF7B-3917-11CE-80FB-0000C0C14E92} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\sscala32.cab (SSDateCombo Control)
O16 - DPF: {EBF47667-BF3F-11D1-983D-0060089F7AEB} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCarCont.cab (CarrConUserControl.CarrierContactMaster)
O16 - DPF: {ED738376-C44A-11D1-A0EC-006008936BDD} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucBusDom.cab (BDUsrCtrl.BusinessDomain)
O16 - DPF: {F29BE3C6-BE82-11D1-91FE-0020AFF5AA68} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCurr.cab (CurrencyUserControl.CurrencyMaster)
O16 - DPF: {F39FD815-E9C3-11D1-9C83-006008319186} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vantree.cab (VanTree.VanTreeCtrl)
O16 - DPF: {F74887C8-C44B-11D1-85ED-006097794610} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVend.cab (VendorUserControl.VendorMaster)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{5652F885-570C-4CD6-BC0A-7689B37B68CF}\\Domain = ugd.att.com
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\smscrd {FA3F5003-93D4-11D2-8E48-00A0C98BD8C3} - c:\smsadmin\bin\i386\sms_mcrd.dll (Microsoft Corporation)
O18 - Protocol\Handler\widimg {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINNT\system32\btxppanel.dll (Broadcom Corporation.)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (pssogina.dll) - C:\WINNT\system32\pssogina.dll (Check Point Software Tech Ltd)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINNT\system32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINNT\System32\*.tmp files]
[3 C:\WINNT\*.tmp files]
[2009/02/24 15:22:21 | 00,000,000 | —D | C] – C:\Documents and Settings\briant\Application Data\Malwarebytes
[2009/02/24 15:21:55 | 00,001,797 | —- | C] () – C:\WINNT\sho1100w.mif
[2009/02/24 15:19:35 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2009/02/24 15:19:35 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/24 15:19:32 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbamswissarmy.sys
[2009/02/24 15:19:31 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/24 15:19:30 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/24 15:17:47 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\briant\Desktop\mbam-setup.exe
[2009/02/24 09:01:33 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/02/23 18:10:39 | 12,658,160 | —- | C] (Doctor Web, Ltd.) – C:\Documents and Settings\briant\Desktop\drweb-cureit.exe
[2009/02/23 09:20:28 | 00,000,250 | —- | C] () – C:\WINNT\gmer.ini
[2009/02/23 09:20:27 | 00,884,736 | —- | C] () – C:\WINNT\gmer.dll
[2009/02/23 09:20:27 | 00,811,008 | —- | C] () – C:\WINNT\gmer.exe
[2009/02/23 09:20:27 | 00,085,969 | —- | C] (GMER) – C:\WINNT\System32\drivers\gmer.sys
[2009/02/23 09:20:27 | 00,000,080 | —- | C] () – C:\WINNT\gmer_uninstall.cmd
[2009/02/23 09:18:18 | 00,747,873 | —- | C] () – C:\Documents and Settings\briant\Desktop\gmer.zip
[2009/02/20 19:40:02 | 21,244,872 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\MRT.exe
[2009/02/20 19:32:09 | 00,000,000 | —D | C] – C:\WINNT\System32\XPSViewer
[2009/02/20 19:32:04 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/02/20 19:31:51 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/02/20 19:31:12 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\xpssvcs.dll
[2009/02/20 19:31:12 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\xpssvcs.dll
[2009/02/20 19:31:12 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\printfilterpipelinesvc.exe
[2009/02/20 19:31:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\xpsshhdr.dll
[2009/02/20 19:31:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\xpsshhdr.dll
[2009/02/20 19:31:12 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\prntvpt.dll
[2009/02/20 19:31:12 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\filterpipelineprintproc.dll
[2009/02/20 19:31:11 | 00,000,000 | —D | C] – C:\16f8fd295b7a9f92269924876cb964
[2009/02/20 18:31:41 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\msadce.dll
[2009/02/20 17:55:32 | 00,000,000 | —D | C] – C:\WINNT\Prefetch
[2009/02/20 17:31:44 | 00,000,000 | —D | C] – C:\WINNT\System32\en-us
[2009/02/20 17:31:43 | 00,000,000 | —D | C] – C:\WINNT\System32\scripting
[2009/02/20 17:31:41 | 00,000,000 | —D | C] – C:\WINNT\l2schemas
[2009/02/20 17:31:40 | 00,000,000 | —D | C] – C:\WINNT\System32\en
[2009/02/20 17:31:40 | 00,000,000 | —D | C] – C:\Program Files\msn
[2009/02/20 17:25:31 | 00,000,000 | —D | C] – C:\WINNT\network diagnostic
[2009/02/20 17:23:41 | 00,001,374 | —- | C] () – C:\WINNT\imsins.BAK
[2009/02/20 17:08:51 | 00,121,856 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\xmllite.dll
[2009/02/20 17:08:49 | 00,276,992 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\wmphoto.dll
[2009/02/20 17:08:47 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\wlanapi.dll
[2009/02/20 17:08:45 | 00,712,704 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\windowscodecs.dll
[2009/02/20 17:08:45 | 00,346,112 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\windowscodecsext.dll
[2009/02/20 17:08:37 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\tsgqec.dll
[2009/02/20 17:08:37 | 00,050,688 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\tspkg.dll
[2009/02/20 17:08:23 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\drivers\sffp_mmc.sys
[2009/02/20 17:08:22 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\setupn.exe
[2009/02/20 17:08:19 | 00,290,304 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\rhttpaa.dll
[2009/02/20 17:08:18 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\rasqec.dll
[2009/02/20 17:08:16 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\qutil.dll
[2009/02/20 17:08:15 | 00,291,328 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\qagentrt.dll
[2009/02/20 17:08:15 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\qagent.dll
[2009/02/20 17:08:15 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\qcliprov.dll
[2009/02/20 17:08:14 | 00,412,160 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\photometadatahandler.dll
[2009/02/20 17:08:10 | 00,144,384 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\onex.dll
[2009/02/20 17:08:00 | 00,193,024 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\napmontr.dll
[2009/02/20 17:08:00 | 00,176,640 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\napstat.exe
[2009/02/20 17:08:00 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\napipsec.dll
[2009/02/20 17:07:59 | 01,306,624 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\msxml6.dll
[2009/02/20 17:07:59 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\msxml6r.dll
[2009/02/20 17:07:59 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\msxml6r.dll
[2009/02/20 17:07:57 | 00,155,136 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\mssha.dll
[2009/02/20 17:07:57 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\msshavmsg.dll
[2009/02/20 17:07:39 | 00,397,312 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\mmcex.dll
[2009/02/20 17:07:39 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\microsoft.managementconsole.dll
[2009/02/20 17:07:39 | 00,106,496 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\mmcfxcommon.dll
[2009/02/20 17:07:39 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\mmcperf.exe
[2009/02/20 17:07:25 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\kmsvc.dll
[2009/02/20 17:07:25 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\l2gpstore.dll
[2009/02/20 17:07:24 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\kbdpash.dll
[2009/02/20 17:07:24 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\kbdnepr.dll
[2009/02/20 17:07:24 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\kbdiultn.dll
[2009/02/20 17:07:24 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\kbdbhc.dll
[2009/02/20 17:07:22 | 00,102,912 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\dpcdll.dll
[2009/02/20 17:07:22 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\pidgen.dll
[2009/02/20 17:07:12 | 00,000,974 | —- | C] () – C:\WINNT\System32\pid.inf
[2009/02/20 17:06:57 | 00,184,832 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eapp3hst.dll
[2009/02/20 17:06:57 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eapphost.dll
[2009/02/20 17:06:57 | 00,126,976 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eappcfg.dll
[2009/02/20 17:06:57 | 00,094,208 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eappgnui.dll
[2009/02/20 17:06:57 | 00,059,392 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eapqec.dll
[2009/02/20 17:06:57 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eappprxy.dll
[2009/02/20 17:06:57 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eapsvc.dll
[2009/02/20 17:06:57 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eapolqec.dll
[2009/02/20 17:06:54 | 00,650,752 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3ui.dll
[2009/02/20 17:06:54 | 00,132,096 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3svc.dll
[2009/02/20 17:06:54 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3cfg.dll
[2009/02/20 17:06:54 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3msm.dll
[2009/02/20 17:06:54 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3gpclnt.dll
[2009/02/20 17:06:54 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3api.dll
[2009/02/20 17:06:54 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3dlg.dll
[2009/02/20 17:06:53 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dimsroam.dll
[2009/02/20 17:06:53 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dimsntfy.dll
[2009/02/20 17:06:52 | 00,048,640 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dhcpqec.dll
[2009/02/20 17:06:49 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\credssp.dll
[2009/02/20 17:06:45 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\bitsprx4.dll
[2009/02/20 17:06:44 | 00,233,472 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\azroles.dll
[2009/02/20 17:06:36 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\aaclient.dll
[2009/02/20 16:32:50 | 00,023,576 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\wuapi.dll.mui
[2009/02/20 15:43:33 | 00,212,480 | —- | C] (SteelWerX) – C:\WINNT\SWXCACLS.exe
[2009/02/20 15:43:33 | 00,161,792 | —- | C] (SteelWerX) – C:\WINNT\SWREG.exe
[2009/02/20 15:43:33 | 00,136,704 | —- | C] (SteelWerX) – C:\WINNT\SWSC.exe
[2009/02/20 15:43:33 | 00,098,816 | —- | C] () – C:\WINNT\sed.exe
[2009/02/20 15:43:33 | 00,089,504 | —- | C] (Smallfrogs Studio) – C:\WINNT\fdsv.exe
[2009/02/20 15:43:33 | 00,080,412 | —- | C] () – C:\WINNT\grep.exe
[2009/02/20 15:43:33 | 00,068,096 | —- | C] () – C:\WINNT\zip.exe
[2009/02/20 15:43:33 | 00,049,152 | —- | C] () – C:\WINNT\VFIND.exe
[2009/02/20 15:43:33 | 00,029,696 | —- | C] (NirSoft) – C:\WINNT\NIRCMD.exe
[2009/02/20 15:43:25 | 00,000,000 | —D | C] – C:\Qoobox
[2009/02/19 22:12:34 | 00,001,734 | —- | C] () – C:\Documents and Settings\briant\Desktop\HijackThis.lnk
[2009/02/19 22:12:34 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/19 21:54:21 | 00,001,744 | -H– | C] () – C:\WINNT\System32\nuwoboza
[2009/02/19 21:53:07 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/19 15:16:28 | 00,494,592 | —- | C] (OldTimer Tools) – C:\Documents and Settings\briant\Desktop\OTListIt2.exe
[2009/02/19 15:01:55 | 00,000,000 | —D | C] – C:\WINNT\ERDNT
[2009/02/17 14:55:51 | 00,136,979 | —- | C] () – C:\Documents and Settings\briant\Desktop\door_guy0001.JPG
[2009/02/02 14:44:36 | 00,226,015 | —- | C] () – C:\Documents and Settings\briant\Desktop\coolant_receipt0001.PDF
[2009/01/30 20:36:24 | 00,331,497 | —- | C] () – C:\Documents and Settings\briant\Desktop\Mad Minute0001.PDF
[2009/01/28 23:52:15 | 00,222,730 | —- | C] () – C:\Documents and Settings\briant\My Documents\Gulf Coast Roundup.jpg
[2009/01/28 17:58:35 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/01/27 20:18:07 | 00,025,088 | —- | C] () – C:\Documents and Settings\briant\My Documents\noel math.doc

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINNT\System32\*.tmp files]
[3 C:\WINNT\*.tmp files]
[2009/02/24 15:21:55 | 00,001,797 | —- | M] () – C:\WINNT\sho1100w.mif
[2009/02/24 15:19:35 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/24 15:17:53 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\briant\Desktop\mbam-setup.exe
[2009/02/23 23:04:38 | 00,002,279 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AT&T Global Network Client Monitor.lnk
[2009/02/23 23:04:31 | 00,000,466 | —- | M] () – C:\WINNT\SMSCFG.ini
[2009/02/23 23:03:25 | 00,002,206 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2009/02/23 23:02:58 | 00,000,006 | -H– | M] () – C:\WINNT\tasks\SA.DAT
[2009/02/23 23:02:55 | 00,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2009/02/23 23:02:54 | 10,645,79072 | -HS- | M] () – C:\hiberfil.sys
[2009/02/23 22:59:29 | 00,000,012 | —- | M] () – C:\WINNT\bthservsdp.dat
[2009/02/23 18:22:23 | 00,000,000 | —- | M] () – C:\WINNT\MEMORY.DMP
[2009/02/23 18:11:19 | 12,658,160 | —- | M] (Doctor Web, Ltd.) – C:\Documents and Settings\briant\Desktop\drweb-cureit.exe
[2009/02/23 09:20:28 | 00,000,250 | —- | M] () – C:\WINNT\gmer.ini
[2009/02/23 09:20:27 | 00,884,736 | —- | M] () – C:\WINNT\gmer.dll
[2009/02/23 09:20:27 | 00,085,969 | —- | M] (GMER) – C:\WINNT\System32\drivers\gmer.sys
[2009/02/23 09:20:27 | 00,000,080 | —- | M] () – C:\WINNT\gmer_uninstall.cmd
[2009/02/23 09:18:18 | 00,747,873 | —- | M] () – C:\Documents and Settings\briant\Desktop\gmer.zip
[2009/02/23 09:15:08 | 00,000,227 | —- | M] () – C:\WINNT\system.ini
[2009/02/20 23:40:42 | 00,447,422 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2009/02/20 23:40:42 | 00,073,356 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2009/02/20 23:40:41 | 00,527,896 | —- | M] () – C:\WINNT\System32\PerfStringBackup.INI
[2009/02/20 22:05:48 | 00,000,863 | —- | M] () – C:\WINNT\win.ini
[2009/02/20 21:54:43 | 00,216,856 | —- | M] () – C:\WINNT\System32\FNTCACHE.DAT
[2009/02/20 19:39:17 | 00,000,085 | —- | M] () – C:\WINNT\vbaddin.ini
[2009/02/20 19:24:12 | 00,001,374 | —- | M] () – C:\WINNT\imsins.BAK
[2009/02/20 17:58:22 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\briant\My Documents\desktop.ini
[2009/02/20 17:25:01 | 00,250,048 | RHS- | M] () – C:\ntldr
[2009/02/20 15:51:22 | 00,000,027 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2009/02/19 22:12:34 | 00,001,734 | —- | M] () – C:\Documents and Settings\briant\Desktop\HijackThis.lnk
[2009/02/19 22:02:48 | 00,001,744 | -H– | M] () – C:\WINNT\System32\nuwoboza
[2009/02/19 15:16:28 | 00,494,592 | —- | M] (OldTimer Tools) – C:\Documents and Settings\briant\Desktop\OTListIt2.exe
[2009/02/17 14:55:51 | 00,136,979 | —- | M] () – C:\Documents and Settings\briant\Desktop\door_guy0001.JPG
[2009/02/11 20:56:18 | 21,244,872 | —- | M] (Microsoft Corporation) – C:\WINNT\System32\MRT.exe
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2009/02/02 14:44:37 | 00,226,015 | —- | M] () – C:\Documents and Settings\briant\Desktop\coolant_receipt0001.PDF
[2009/01/30 20:36:25 | 00,331,497 | —- | M] () – C:\Documents and Settings\briant\Desktop\Mad Minute0001.PDF
[2009/01/28 23:52:17 | 00,222,730 | —- | M] () – C:\Documents and Settings\briant\My Documents\Gulf Coast Roundup.jpg
[2009/01/27 20:29:25 | 00,025,088 | —- | M] () – C:\Documents and Settings\briant\My Documents\noel math.doc

========== LOP Check ==========

[2009/02/24 15:19:31 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/02/26 08:15:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1E
[2008/09/17 23:00:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/01/08 17:18:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AGNS
[2008/09/17 23:04:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/09/30 16:02:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2004/10/01 14:55:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hummingbird
[2008/06/09 13:31:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IBM
[2007/07/20 14:35:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogiShrd
[2009/02/24 15:19:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/08/27 18:47:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2008/01/17 09:49:22 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/04/18 10:44:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NETg
[2007/08/27 18:46:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Network Associates
[2006/10/31 22:14:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panasonic
[2008/07/28 07:37:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pointsec
[2004/11/04 11:01:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2007/01/18 14:57:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2005/10/06 11:26:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/02/24 15:22:21 | 00,000,000 | RH-D | M] – C:\Documents and Settings\briant\Application Data
[2009/02/24 15:21:57 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Adobe
[2008/10/05 22:34:27 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Apple Computer
[2009/02/17 14:55:14 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Canon
[2004/09/29 10:51:31 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Identities
[2004/11/05 12:56:42 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\j2 Global
[2004/11/01 12:25:30 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Jabber Messenger
[2005/01/22 10:10:09 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Macromedia
[2009/02/24 15:22:21 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Malwarebytes
[2009/02/20 16:29:41 | 00,000,000 | –SD | M] – C:\Documents and Settings\briant\Application Data\Microsoft
[2008/09/17 22:50:06 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Mozilla
[2008/08/06 22:31:48 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Real
[2006/10/31 21:45:57 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Roxio
[2005/01/31 21:44:33 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\Sun
[2008/07/16 10:03:43 | 00,000,000 | —D | M] – C:\Documents and Settings\briant\Application Data\TextPad
[2001/08/23 03:00:00 | 00,000,065 | RH– | M] () – C:\WINNT\Tasks\desktop.ini
[2005/04/01 21:38:44 | 00,000,292 | —- | M] () – C:\WINNT\Tasks\IM.job
[2009/02/23 23:02:58 | 00,000,006 | -H– | M] () – C:\WINNT\Tasks\SA.DAT
[2006/01/30 15:21:52 | 00,000,226 | —- | M] () – C:\WINNT\Tasks\weftp.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 0 bytes -> C:\WINNT\Thumbs.db:encryptable
< End of report >


*******Extras.txt**********
OTListIt Extras logfile created on: 2/24/2009 5:56:04 PM - Run 10
OTListIt2 by OldTimer - Version 2.0.0.18 Folder = C:\Documents and Settings\briant\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.20 Mb Total Physical Memory | 405.26 Mb Available Physical Memory | 39.92% Memory free
1.64 Gb Paging File | 1.20 Gb Available in Paging File | 73.18% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 13.30 Gb Free Space | 35.69% Space Free | Partition Type: NTFS
Drive D: | 702.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive W: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS
Drive X: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS
Drive Y: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS
Drive Z: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS

Computer Name: bcantrell2
Current User Name: briant
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"FirewallDisableNotify" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® (Microsoft Corporation)
C:\Program Files\WSFTP\ws_ftp32.exe:*:Enabled:ws_ftp32 ()
C:\WINNT\system32\ftp.exe:*:Enabled:File Transfer Program (Microsoft Corporation)
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE:*:Enabled:Microsoft Office Word (Microsoft Corporation)
C:\WINNT\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console (Microsoft Corporation)
C:\Program Files\AT&T Global Network Client\NetClient.exe:10.0.0.0/255.0.0.0,32.70.1.0/255.255.255.0,130.1.0.0/255.255.0.0,130.2.0.0/255.254.0.0,135.0.0.0/255.0.0.0,192.20.0.0/255.255.0.0,192.128.0.0/255.255.0.0,192.151.83.0/255.255.255.0,192.205.0.0/255.255.0.0,192.206.169.0/255.255.255.0,204.159.0.0/255.255.0.0,206.121.250.0/255.255.255.0,206.121.253.0/255.255.255.0:Enabled:AT&T Global Network Client (AT&T)
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service (McAfee, Inc.)
C:\Program Files\Q Team-Link Messenger\j2re1.4.2_01\bin\java.exe:*:Enabled:java File not found
C:\WINNT\system32\jview.exe:*:Enabled:Microsoft® VM Command Line Interpreter (Microsoft Corporation)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype File not found
C:\Documents and Settings\bcantrell\Application Data\SBC\Q Team Link Messenger\Runtime\QTeamLinkMessenger.exe:*:Enabled:QTeamLinkMessenger ()
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service (McAfee, Inc.)
C:\Program Files\AT&T Global Network Client\NetClient.exe:10.0.0.0/255.0.0.0,32.70.1.0/255.255.255.0,130.1.0.0/255.255.0.0,130.2.0.0/255.254.0.0,135.0.0.0/255.0.0.0,192.20.0.0/255.255.0.0,192.128.0.0/255.255.0.0,192.151.83.0/255.255.255.0,192.205.0.0/255.255.0.0,192.206.169.0/255.255.255.0,204.159.0.0/255.255.0.0,206.121.250.0/255.255.255.0,206.121.253.0/255.255.255.0:Enabled:AT&T Global Network Client (AT&T)
C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe:*:Enabled:SMSWakeUp Agent (1E Ltd.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02F6993D-B763-4F40-8F93-2A9CD97586E3}" = Microsoft IntelliType Pro 6.3
"{0672DC0C-B90E-4466-BF6F-BC0DAC456777}" = AttachmentOptions
"{0B8B1AD0-FBB9-4F71-B9D7-7733B0A3EAC6}" = Windows Installer Service 3.1
"{0E4BC542-9CFD-4E97-B586-9F1E5516E7B9}" = Microsoft IntelliPoint 6.1
"{109AB81D-9732-40B3-9C1F-113A86CE6F93}" = Canon MP Navigator 1.0
"{18A5DFF2-8A95-49F3-873F-743CB5549F3D}" = Canon ScanGear Starter
"{1F695CFF-C3A2-4A06-8D40-2FC93BC4208A}" = BMC Remedy User 7.0
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2ED57E6C-7276-4430-86DE-49D2007303B6}" = BMC Remedy Administrator 7.0
"{31B33270-24D7-4307-84F2-A3288636B83A}" = Pointsec PC
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150120}" = J2SE Runtime Environment 5.0 Update 12
"{3248F0A8-6813-11D6-A77B-00B0D0150130}" = J2SE Runtime Environment 5.0 Update 13
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35C03C04-3F1F-42C2-A989-A757EE691F65}" = McAfee VirusScan Enterprise
"{370761F2-CF96-46EF-AC6D-3D0461A8A1DC}" = P2R 2.0
"{3B9EDAA4-A3FC-4049-B84F-650E21B8D95E}" = Remedy Encryption 6.3
"{3DA89EB8-DC3E-4210-90FB-E72DBC53EC76}" = Insider Portal 1.0
"{3DC0A1F2-038F-11D6-B897-00902799B4B8}" = AT&T Doctor Install
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = Linksys Bluetooth Utility 2.0
"{3FF3DD04-F386-46B0-97FC-B86238B65487}" = Canon MP Drivers 6.0
"{437B532F-EB2B-40A2-8585-DEFA15F92C76}" = Remedy User 6.3
"{48D1D5F4-8E6D-49BE-8933-DBA006E1277B}" = Secure Shell 5.8
"{4A39A27F-005B-407E-8CF5-F4D8065658E4}" = SMS Advanced Client
"{52D2A865-C336-4EB2-9617-8DB8B0A7B21C}" = AOTS IGWL Extension 3
"{53BCF0AA-1895-4791-800C-EBBB59E80825}" = x.hlp WebGuide_eng
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.79.1
"{5AE151DE-2E50-4711-B80F-88641B657D65}" = Emanate 6.0 y
"{5B567679-F825-47D4-9F68-47E51BD4C14A}" = AT&T Software Store Service 1.0.0x
"{5B769987-D4EC-4AE0-BC47-68D0EAD13107}" = AOTS IGWL Extension 2.2X
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{67367DB3-1C6E-443F-8840-0E8CBE579443}" = Shockwave 11.0.0.429 and Flash [removed] Players
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69CD2FEF-8302-4E56-8D74-C06E9ADD9826}" = Q Team-Link Messenger 3.0 x
"{7228CB73-80E9-48D3-A7FD-C2A242686AB3}" = Microsoft Office Live Meeting 2005
"{763848C8-2B92-4E52-9030-5A3C120E466D}" = Tivoli Remote Control 5.1
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{78CA0313-4A1E-4DD2-9BED-CE0F44BFD4E3}" = VeriSign Desktop Update 7.1
"{7CEF4888-F872-46D9-B2A1-0D8723525D40}" = Microsoft Office Live Meeting Add-in Pack
"{83880EAF-1524-44C2-9E43-539F925DC698}" = AT&T Before You Call
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8E6ACF46-2409-411C-B920-A734B6DAF3FD}" = SBC Assess 1.0.0y
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90510409-6D54-11D4-BEE3-00C04F990354}" = Microsoft Visio Professional 2002 [English]
"{930439A1-B49E-4A54-A499-31BDC1A91DE5}" = Shockwave Player
"{93539D60-1817-11D1-9504-00805F26A89C}" = Easy Access Button Support
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9886C963-FB48-4C58-8E75-64816F220D1D}" = Password Safe 1.7.1
"{9B0F88A7-7994-473A-B27B-6F2F16D1C1A2}" = Knowledge Gateway
"{9FF7DAE0-1030-43C5-AE2E-D2815D206E85}" = SMSWakeUp50 Agent
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A6738F33-5C7D-4120-A030-B58BA0D5EE3C}" = tSpace Internet Shortcut 1.1
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B510A987-487E-4C66-9F4F-D386AC275715}" = TextPad 4.7
"{B74681B8-CCE9-4681-BADF-CFEE340227A3}" = Altiris Patch Management Agent
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom NetXtreme Ethernet Controller
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1E26EED-CC8B-4371-9CC7-AD8A5814B4B2}" = IE5 Registration
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE573341-2049-4FBA-9473-C2B5DA82E8E8}" = Hummingbird Exceed V7.0
"{E0DD6DD6-C916-4038-BFF1-47B83C156152}" = Microsoft Office File Format Converter 1.0
"{EEE3579E-0272-4098-923F-16883639AF3B}" = Pharos Blueprint Cleanup 1.0
"{EF964A78-078C-11D1-B7A7-0000C0134CE6}" = AT&T Extranet Access Client
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{FC0FC4BA-17D0-493C-AFF4-1FDF92657457}" = AT&T Global Network Client Managed VPN Edition
"ACDSee" = ACDSee
"ActiveTouchMeetingClient" = Meeting Service Player
"Adobe AIR" = Adobe AIR
"Adobe Photoshop 6.0" = Adobe Photoshop 6.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Adobe SVG Viewer" = Adobe SVG Viewer
"Asterisk Key" = Asterisk Key
"BeforeUCall" = AT&T Before You Call
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F00&SUBSYS_200414F1" = SoftK56 Data Fax Voice Speakerphone CARP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Defraggler" = Defraggler (remove only)
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"F-Secure SSH Client" = F-Secure SSH Client
"HijackThis" = HijackThis 2.0.2
"HP Photo Imaging Software" = HP Photo Imaging Software
"HP Photo Printing Software" = HP Photo Printing Software
"InstallShield_{0B8B1AD0-FBB9-4F71-B9D7-7733B0A3EAC6}" = Windows Installer Service 3.1
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom NetXtreme Ethernet Controller
"IntMgmt" = Insight Management Agent
"IrfanView" = IrfanView (remove only)
"jEdit_is1" = jEdit 4.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Anti-Spyware Enterprise Module" = McAfee AntiSpyware Enterprise Module
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2000" = Microsoft SQL Server 2000
"Mozilla Firefox (3.0.6)" = Mozilla Firefox (3.0.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"Netscape (7.1)" = Netscape (7.1)
"RealPlayer 6.0" = RealPlayer
"ServicePass" = AT&T ServicePass Verification Utility
"Terminal Server Client" = Terminal Services Client
"TextPad" = TextPad
"Visual Studio 6.0 Professional Edition" = Microsoft Visual Studio 6.0 Professional Edition
"WebPost" = Microsoft Web Publishing Wizard 1.53
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/24/2009 11:48:17 AM | Computer Name = bcantrell2 | Source = Userenv | ID = 1096
Description = Windows cannot access the registry policy file, C:\WINNT\System32\GroupPolicy\User\registry.pol.
(Access is denied. ).

Error - 2/24/2009 1:18:19 PM | Computer Name = bcantrell2 | Source = Userenv | ID = 1043
Description = Windows cannot access the registry information at C:\WINNT\System32\GroupPolicy\User\registry.pol.
(Access is denied. ).

Error - 2/24/2009 1:18:19 PM | Computer Name = bcantrell2 | Source = Userenv | ID = 1096
Description = Windows cannot access the registry policy file, C:\WINNT\System32\GroupPolicy\User\registry.pol.
(Access is denied. ).

Error - 2/24/2009 2:50:22 PM | Computer Name = bcantrell2 | Source = Userenv | ID = 1043
Description = Windows cannot access the registry information at C:\WINNT\System32\GroupPolicy\User\registry.pol.
(Access is denied. ).

Error - 2/24/2009 2:50:22 PM | Computer Name = bcantrell2 | Source = Userenv | ID = 1096
Description = Windows cannot access the registry policy file, C:\WINNT\System32\GroupPolicy\User\registry.pol.
(Access is denied. ).

Error - 2/24/2009 4:02:59 PM | Computer Name = bcantrell2 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 2/24/2009 4:33:25 PM | Computer Name = bcantrell2 | Source = Userenv | ID = 1043
Description = Windows cannot access the registry information at C:\WINNT\System32\GroupPolicy\User\registry.pol.
(Access is denied. ).

Error - 2/24/2009 4:33:25 PM | Computer Name = bcantrell2 | Source = Userenv | ID = 1096
Description = Windows cannot access the registry policy file, C:\WINNT\System32\GroupPolicy\User\registry.pol.
(Access is denied. ).

Error - 2/24/2009 6:15:27 PM | Computer Name = bcantrell2 | Source = Userenv | ID = 1043
Description = Windows cannot access the registry information at C:\WINNT\System32\GroupPolicy\User\registry.pol.
(Access is denied. ).

Error - 2/24/2009 6:15:27 PM | Computer Name = bcantrell2 | Source = Userenv | ID = 1096
Description = Windows cannot access the registry policy file, C:\WINNT\System32\GroupPolicy\User\registry.pol.
(Access is denied. ).

[ Pointsec Events ]
Error - 8/25/2008 12:13:29 AM | Computer Name = bcantrell2 | Source = prot_srv | ID = 462754
Description =

Error - 8/26/2008 12:10:26 AM | Computer Name = bcantrell2 | Source = prot_srv | ID = 462754
Description =

Error - 8/27/2008 12:07:38 AM | Computer Name = bcantrell2 | Source = prot_srv | ID = 462754
Description =

Error - 8/28/2008 12:04:14 AM | Computer Name = bcantrell2 | Source = prot_srv | ID = 462754
Description =

Error - 8/29/2008 12:31:40 AM | Computer Name = bcantrell2 | Source = prot_srv | ID = 462754
Description =

Error - 8/30/2008 12:27:04 AM | Computer Name = bcantrell2 | Source = prot_srv | ID = 462754
Description =

Error - 8/31/2008 12:20:45 AM | Computer Name = bcantrell2 | Source = prot_srv | ID = 462754
Description =

Error - 9/2/2008 12:02:41 AM | Computer Name = bcantrell2 | Source = prot_srv | ID = 462754
Description =

Error - 9/3/2008 12:29:11 AM | Computer Name = bcantrell2 | Source = prot_srv | ID = 462754
Description =

Error - 9/4/2008 12:25:18 AM | Computer Name = bcantrell2 | Source = prot_srv | ID = 462754
Description =

[ System Events ]
Error - 2/24/2009 12:03:54 AM | Computer Name = bcantrell2 | Source = Service Control Manager | ID = 7000
Description = The ASPI32 service failed to start due to the following error: %%2

Error - 2/24/2009 12:03:54 AM | Computer Name = bcantrell2 | Source = Service Control Manager | ID = 7000
Description = The ONSIO service failed to start due to the following error: %%2

Error - 2/24/2009 12:03:54 AM | Computer Name = bcantrell2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
CCDevice i8042prt SMPLSCSI

Error - 2/24/2009 12:18:30 AM | Computer Name = bcantrell2 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.

Error - 2/24/2009 12:48:32 AM | Computer Name = bcantrell2 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 59 minutes. NtpClient has no source of accurate
time.

Error - 2/24/2009 1:48:36 AM | Computer Name = bcantrell2 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 119 minutes. NtpClient has no source of accurate
time.

Error - 2/24/2009 3:48:43 AM | Computer Name = bcantrell2 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 239 minutes. NtpClient has no source of accurate
time.

Error - 2/24/2009 7:48:56 AM | Computer Name = bcantrell2 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 479 minutes. NtpClient has no source of accurate
time.

Error - 2/24/2009 10:03:11 AM | Computer Name = bcantrell2 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain ISO due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.

Error - 2/24/2009 3:49:15 PM | Computer Name = bcantrell2 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 959 minutes. NtpClient has no source of accurate
time.


< End of report >


Thank you again!!
Hi beachbriant,

Please do this:

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTLI
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
[1 C:\*.tmp files]
[1 C:\WINNT\System32\*.tmp files]
[3 C:\WINNT\*.tmp files]
[2009/02/20 15:43:33 | 00,098,816 | —- | C] () – C:\WINNT\sed.exe
[2009/02/20 15:43:33 | 00,089,504 | —- | C] (Smallfrogs Studio) – C:\WINNT\fdsv.exe
[2009/02/20 15:43:33 | 00,080,412 | —- | C] () – C:\WINNT\grep.exe
[2009/02/20 15:43:33 | 00,068,096 | —- | C] () – C:\WINNT\zip.exe
[2009/02/20 15:43:33 | 00,049,152 | —- | C] () – C:\WINNT\VFIND.exe
[2009/02/20 15:43:33 | 00,029,696 | —- | C] (NirSoft) – C:\WINNT\NIRCMD.exe
[2009/02/20 15:43:25 | 00,000,000 | —D | C] – C:\Qoobox
[2009/02/19 21:54:21 | 00,001,744 | -H– | C] () – C:\WINNT\System32\nuwoboza

:Services

:Reg

:Files

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then, in your next reply, post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )


Next

Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop

Copy all the text contained inside the code box below to your Clipboard by highlighting it and pressing (Ctrl+C): (do not copy the word 'code')

Files to delete:
%systemroot%\System32\nuwoboza

Folders to delete:
%systemroot%\system32\nuwoboza

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

Now, start The Avenger program by clicking on its icon on your desktop.
  • Click in the window labeled Input Script Here and paste the text copied to the clipboard into it by pressing (Ctrl+V).
  • Click the Execute button
  • Answer "Yes" twice when prompted.
The Avenger will automatically do the following:
  • It will Restart your computer.
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

In your next reply please include
  • OTlistIt2 log
  • Avenger log
  • Fresh HJT Log
Also please advise how your computer is running now
PC seems to be running fine.
I still can't enable AutoUpdate.

Requested logs are below:

OTListIt Log


OTListIt logfile created on: 2/25/2009 2:52:47 PM - Run 13
OTListIt2 by OldTimer - Version 2.0.0.18 Folder = C:\Documents and Settings\briant\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.20 Mb Total Physical Memory | 539.70 Mb Available Physical Memory | 53.16% Memory free
1.64 Gb Paging File | 1.28 Gb Available in Paging File | 78.14% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 14.64 Gb Free Space | 39.28% Space Free | Partition Type: NTFS
Drive D: | 702.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive W: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS
Drive X: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS
Drive Y: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS
Drive Z: | 111.79 Gb Total Space | 51.45 Gb Free Space | 46.03% Space Free | Partition Type: NTFS

Computer Name: bcantrell2
Current User Name: briant
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe (Hewlett-Packard Company)
PRC - C:\PROGRAM FILES\DRU\bin\DRUService.exe (AT&T)
PRC - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe (Hummingbird Ltd.)
PRC - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe (Hummingbird Ltd.)
PRC - c:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\hjavaw.exe (Hummingbird Ltd.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Java\jre1.5.0_13\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\AT&T Global Network Client\netcfgsvr.exe (AT&T)
PRC - C:\WINNT\system32\pstartSr.exe ()
PRC - C:\WINNT\system32\snmpdm.exe ()
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - c:\Program Files\Network Associates\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\WINNT\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\compapps\swstore\ssservice.exe ()
PRC - C:\Program Files\Doctor Install\DrInstalSvc.exe (AT&T)
PRC - C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe ()
PRC - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe (Intel)
PRC - C:\WINNT\System32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\WINNT\system32\CCM\CcmExec.exe (Microsoft Corporation)
PRC - C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe (1E Ltd.)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Cpqdmi.exe (Compaq Computer Corporation)
PRC - C:\WINNT\System32\igfxtray.exe (Intel Corporation)
PRC - C:\WINNT\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Chkadmin.exe (Hewlett-Packard Company)
PRC - C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe (Compaq Computer Corporation)
PRC - C:\Program Files\Network Associates\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\Doctor Install\InstallMgr.exe (AT&T)
PRC - c:\Program Files\Network Associates\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\WINNT\system32\carpserv.exe (Conexant Systems)
PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
PRC - C:\WINNT\Logi_MwX.Exe (Logitech Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
PRC - C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE ()
PRC - C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe (Check Point Software Tech Ltd)
PRC - C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE (HP Company)
PRC - C:\Compaq\EAKDRV\EAUSBKBD.EXE (Compaq)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - C:\WINNT\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_gui.exe ()
PRC - C:\WINNT\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Compaq\Easy Access Button Support\BttnServ.exe (Compaq Computer Corporation)
PRC - c:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe (Microsoft Corporation)
PRC - C:\Program Files\Linksys\Bluetooth Utility\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Linksys\Bluetooth Utility\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\WINNT\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\briant\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (btwdins [Auto | Running]) – C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe (Broadcom Corporation.)
SRV - (CcmExec [Auto | Running]) – C:\WINNT\system32\CCM\CcmExec.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CPQALERT [Auto | Running]) – C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe (Hewlett-Packard Company)
SRV - (cpqdmi [Auto | Running]) – C:\Program Files\Compaq\Compaq Management Agents\Cpqdmi.exe (Compaq Computer Corporation)
SRV - (DRUAgent [Auto | Running]) – C:\PROGRAM FILES\DRU\bin\DRUService.exe (AT&T)
SRV - (ExtranetAccess [On_Demand | Stopped]) – C:\Program Files\Nortel Networks\Extranet_serv.exe (Nortel Networks NA, Inc.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINNT\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (HCLInetd [Auto | Running]) – C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe (Hummingbird Ltd.)
SRV - (helpsvc [Auto | Running]) – C:\WINNT\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – c:\WINNT\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (Jconfigd [Auto | Running]) – C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe (Hummingbird Ltd.)
SRV - (McAfeeFramework [Auto | Running]) – c:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (McShield [Auto | Running]) – C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
SRV - (McTaskManager [Auto | Running]) – C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (MDM [Auto | Running]) – c:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (netcfgsvr [Auto | Running]) – C:\Program Files\AT&T Global Network Client\netcfgsvr.exe (AT&T)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – c:\WINNT\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (OracleOraHome90ClientCache [On_Demand | Stopped]) – C:\oracle\ora90\BIN\ONRSD.EXE ()
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pointsec_start [Auto | Running]) – C:\WINNT\system32\pstartSr.exe ()
SRV - (rcmdsvc [On_Demand | Stopped]) – File not found
SRV - (SMSWUagent [Auto | Running]) – C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe (1E Ltd.)
SRV - (snmpdm [Auto | Running]) – C:\WINNT\system32\snmpdm.exe ()
SRV - (SoundMAX Agent Service (default) [Auto | Running]) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (ssserviceWinService [Auto | Running]) – C:\Program Files\compapps\swstore\ssservice.exe ()
SRV - (Svc_DrInstal [Auto | Running]) – C:\Program Files\Doctor Install\DrInstalSvc.exe (AT&T)
SRV - (TRCTARGET [Auto | Running]) – C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe ()
SRV - (WIN32SL [Auto | Running]) – C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe (Intel)
SRV - (WMDM PMSP Service [Auto | Running]) – C:\WINNT\System32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Running]) – C:\WINNT\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (agnfilt [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\agnfilt.sys (AT&T)
DRV - (agnwifi [Auto | Running]) – C:\WINNT\system32\DRIVERS\agnwifi.sys (AT&T)
DRV - (avpnnic [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\avpnnic.sys (AT&T)
DRV - (b57w2k [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (btaudio [On_Demand | Running]) – C:\WINNT\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTDriver [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTSERIAL [Auto | Running]) – C:\WINNT\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTSLBCSP [Auto | Running]) – C:\WINNT\system32\drivers\btslbcsp.sys (Broadcom Corporation.)
DRV - (BTWDNDIS [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Running]) – C:\WINNT\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BVRPMPR5 [On_Demand | Stopped]) – C:\WINNT\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (ClntMgmt [System | Running]) – C:\WINNT\System32\Drivers\ClntMgmt.sys (Hewlett-Packard)
DRV - (eaps2kbd [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\eaps2kbd.sys (Compaq Computer Corp.)
DRV - (EAWDMFD [System | Running]) – C:\WINNT\system32\drivers\EAWDMFD.sys (Compaq Computer Corporation)
DRV - (gmer [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\gmer.sys (GMER)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\HSF_DP.sys (Conexant Systems)
DRV - (ialm [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (IPSECEXT [Auto | Stopped]) – C:\WINNT\System32\DRIVERS\ipsecw2k.sys (Nortel Networks)
DRV - (IPSECSHM [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ipsecw2k.sys (Nortel Networks)
DRV - (L8042Kbd [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\L8042Kbd.sys (Logitech Inc.)
DRV - (L8042mou [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\L8042mou.Sys (Logitech Inc.)
DRV - (L8042pr2 [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\L8042pr2.Sys (Logitech, Inc.)
DRV - (LMouFlt2 [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\LMouFlt2.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\LMouKE.Sys (Logitech Inc.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINNT\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mfeapfk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfeavfk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [System | Running]) – C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys (McAfee, Inc.)
DRV - (mfetdik [System | Running]) – C:\WINNT\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINNT\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (Point32 [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\point32.sys (Microsoft Corporation)
DRV - (prepdrvr [On_Demand | Running]) – C:\WINNT\system32\CCM\prepdrv.sys (Microsoft Corporation)
DRV - (prot_2k [Boot | Running]) – C:\WINNT\System32\drivers\prot_2k.sys (Check Point Software Tech Ltd)
DRV - (Ptilink [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINNT\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (scsiscan [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\scsiscan.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SMPLSCSI [Boot | Stopped]) – C:\WINNT\System32\SMPLSCSI.INF ()
DRV - (smwdm [On_Demand | Running]) – C:\WINNT\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (snmpdm_ [System | Running]) – C:\WINNT\system32\snmpdm_.sys (Guidance Software Inc.)
DRV - (StreamDispatcher [Auto | Running]) – C:\WINNT\System32\DRIVERS\strmdisp.sys (Conexant Systems)
DRV - (winachsf [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Running]) – C:\WINNT\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running]) – C:\WINNT\system32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = http://www.microsoft.com/isapi/redir.dll?P…mp;Ar=ie5update
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com//
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

O1 HOSTS File: (27 bytes) - C:\WINNT\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (CitiUSBrowserHelper Class) - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINNT\system32\BhoCitUS.dll (Orbiscom Ltd. All rights reserved.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent (Microsoft Corporation)
O4 - HKLM..\Run: [CARPService] carpserv.exe (Conexant Systems)
O4 - HKLM..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe (Compaq Computer Corporation)
O4 - HKLM..\Run: [Doctor Install] C:\Program Files\Doctor Install\InstallMgr.exe (AT&T)
O4 - HKLM..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE (Logitech Inc.)
O4 - HKLM..\Run: [Logitech Utility] Logi_MwX.Exe (Logitech Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] "c:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey (McAfee, Inc.)
O4 - HKLM..\Run: [Pointsec Tray] C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe (Check Point Software Tech Ltd)
O4 - HKLM..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE (McAfee, Inc.)
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKCU..\Run: [NetSP - restore settings on power failure] "C:\Program Files\AT&T Global Network Client\NetSP.exe" -show (AT&T)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AT&T Global Network Client Monitor.lnk = C:\WINNT\Installer\{FC0FC4BA-17D0-493C-AFF4-1FDF92657457}\NetGM_1B536450052A4C0BA1B8FC31F1D473F7.exe (Macrovision Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk = C:\Program Files\Linksys\Bluetooth Utility\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: UseDefaultTile = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = Warning Notice:
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = This system is restricted solely to AT&T authorized users for legitimate business purposes only. The actual or attempted unauthorized access, use, or modification of this system is strictly prohibited by AT&T. Unauthorized users are subject to Company disciplinary proceedings and/or criminal and civil penalties under state, federal, or other applicable domestic and foreign laws. The use of this system may be monitored and recorded for administrative and security reasons. Anyone,", accessing this system exp
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: consentpromptbehavioruser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Back = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Forward = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Stop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Refresh = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Home = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Search = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_History = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Favorites = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Media = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Folders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Fullscreen = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Tools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_MailNews = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Size = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Print = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Edit = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Discussions = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Cut = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Copy = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Paste = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Encoding = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_PrintPreview = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnforceShellExtensionSecurity = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetConnectDisconnect = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie_ctx.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_13\bin\npjpi150_13.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm ()
O9 - Extra Button: Knowledge Gateway - {D666CFDA-F583-889A-323D-9F8FAF7144C3} - C:\Program Files\knowledgegateway\launch.htm ()
O9 - Extra 'Tools' menuitem : Knowledge Gateway - {D666CFDA-F583-889A-323D-9F8FAF7144C3} - C:\Program Files\knowledgegateway\launch.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] - C:\WINNT\system32\wshbth.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ameritech.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: att.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: atttest.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: attws.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: bellsouth.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: bls.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: cingular.net ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: cingularlab.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: cingularnext.net ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: pacbell.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: sbc.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: sbcdo.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: sbcld.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: sbctest.com ([]* in Local intranet)
O15 - HKCU\..Trusted Sites: snet.com ([]* in Local intranet)
O16 - DPF: {08288600-E9D9-11D1-9C84-006008319186} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vantfind.cab (VanTFind.VanTFindCtrl)
O16 - DPF: {14924309-C4D4-11D1-85ED-006097794610} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkCst.cab (StkCstUserControl.StkCstMaster)
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} http://lmc.sbc.com/courses/aicc/download/a…yer/awswaxf.cab (Macromedia Authorware Web Player Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1C8B8F66-60FA-11D1-8B99-0020AFF5AA3B} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\icccdf4.cab (ucCommonDataField.ucCmnDataField)
O16 - DPF: {201CF4B6-C42D-11D1-A0EC-006008936BDD} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmStk.cab (ItemStUC.ItemStocking)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3D82A12A-C1FA-11D0-9B21-0080C79EFE90} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vanfind.cab (VanFind.VanFindCtrl)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {4117ECE7-C7FE-11D1-9844-0060089F7AEB} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkLkp.cab (StkLkpUC.StockLookup)
O16 - DPF: {413D6754-BFD4-47FE-9346-319559290BFA} https://www.webpcfos.com/webpcfos/websabre/HTEweb_new.cab (HTECtrl Class)
O16 - DPF: {4E192D78-E515-11D1-B89E-0020AFF695A0} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmMst.cab (ItmMastUC.ItemMaster)
O16 - DPF: {51BB7DFD-A6F5-4FAC-B8C9-E71CF84D082C} http://pdsnsm1/Altiris/NS/NSCap/Bin/Win32/…isNSConsole.cab (AeXNSConsoleContextHelp Class)
O16 - DPF: {60046ED9-8E77-11D0-9B21-0080C79EFE90} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vangrid.cab (VanGrid.VanGridCtrl)
O16 - DPF: {603607C4-BE6F-11D1-983A-0060089F7AEB} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCarrier.cab (CarrierUserControl.CarrierMaster)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1235086621796 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1235086609093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9345E91A-BF88-11D1-8AFE-00A02470741B} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVendCt.cab (VendorContUC.VendorCont)
O16 - DPF: {97EEFD1A-C41D-11D1-A0EC-006008936BDD} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCusLbl.cab (CustLabelsUsrCtrl.CustomLabels)
O16 - DPF: {9E85612B-D0A6-11D1-89BF-0060089F7A3E} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\SHIPVIEW.cab (ShipComp.ShipmentViewer)
O16 - DPF: {AA64AF34-C45D-11D1-85ED-006097794610} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVirDm.cab (VirDomUC.VirDomainMaster)
O16 - DPF: {ABDE29F2-6F9C-11D1-9B21-0080C79EFE90} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\VanLiteral.CAB (VanLiteral.CodeSet)
O16 - DPF: {B86D4018-C597-11D1-9843-0060089F7AEB} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucUOM.cab (UOMUserControl.UOMMaster)
O16 - DPF: {B86D4502-C597-11D1-9843-0060089F7AEB} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmCat.cab (ItemCat.ItmCatUC)
O16 - DPF: {B8958DE0-BAC9-101C-933E-0000C005958C} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\edt32x20.ocx (FarPoint DateTime Control)
O16 - DPF: {BE033B8C-722E-11D1-9B21-0080C79EFE90} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\VanMessage.CAB (VanMessage.Message)
O16 - DPF: {BE77224A-C41F-11D1-85ED-006097794610} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkDt.cab (StkDtUserControl.StkDtMaster)
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_12)
O16 - DPF: {CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_13)
O16 - DPF: {D7553B82-8EEC-11D4-AAE3-005056A35A1F} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\UPLOADCOMPONENT.cab (ATTCustomComponents.UploadComponent)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://advancedmeetings.webex.com/client/v…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {EB0CF3B4-C33B-11D1-A0EC-006008936BDD} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkSt.cab (StkStUC.StockStatusMaint)
O16 - DPF: {EB52CF7B-3917-11CE-80FB-0000C0C14E92} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\sscala32.cab (SSDateCombo Control)
O16 - DPF: {EBF47667-BF3F-11D1-983D-0060089F7AEB} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCarCont.cab (CarrConUserControl.CarrierContactMaster)
O16 - DPF: {ED738376-C44A-11D1-A0EC-006008936BDD} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucBusDom.cab (BDUsrCtrl.BusinessDomain)
O16 - DPF: {F29BE3C6-BE82-11D1-91FE-0020AFF5AA68} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCurr.cab (CurrencyUserControl.CurrencyMaster)
O16 - DPF: {F39FD815-E9C3-11D1-9C83-006008319186} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vantree.cab (VanTree.VanTreeCtrl)
O16 - DPF: {F74887C8-C44B-11D1-85ED-006097794610} file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVend.cab (VendorUserControl.VendorMaster)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{5652F885-570C-4CD6-BC0A-7689B37B68CF}\\Domain = ugd.att.com
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\smscrd {FA3F5003-93D4-11D2-8E48-00A0C98BD8C3} - c:\smsadmin\bin\i386\sms_mcrd.dll (Microsoft Corporation)
O18 - Protocol\Handler\widimg {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINNT\system32\btxppanel.dll (Broadcom Corporation.)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (pssogina.dll) - C:\WINNT\system32\pssogina.dll (Check Point Software Tech Ltd)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINNT\system32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINNT\System32\*.tmp files]
[3 C:\WINNT\*.tmp files]
[2009/02/25 14:53:34 | 00,724,952 | —- | C] () – C:\Documents and Settings\briant\Desktop\avenger.zip
[2009/02/25 14:47:17 | 02,681,302 | -H– | C] () – C:\Documents and Settings\briant\Local Settings\Application Data\IconCache.db
[2009/02/25 14:16:13 | 00,000,000 | —D | C] – C:\Documents and Settings\briant\Application Data\WinPatrol
[2009/02/25 14:15:58 | 00,000,000 | —D | C] – C:\Program Files\BillP Studios
[2009/02/24 15:22:21 | 00,000,000 | —D | C] – C:\Documents and Settings\briant\Application Data\Malwarebytes
[2009/02/24 15:21:55 | 00,001,797 | —- | C] () – C:\WINNT\sho1100w.mif
[2009/02/24 15:19:35 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2009/02/24 15:19:35 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/24 15:19:32 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbamswissarmy.sys
[2009/02/24 15:19:31 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/24 15:19:30 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/24 15:17:47 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\briant\Desktop\mbam-setup.exe
[2009/02/24 09:01:33 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/02/23 18:10:39 | 12,658,160 | —- | C] (Doctor Web, Ltd.) – C:\Documents and Settings\briant\Desktop\drweb-cureit.exe
[2009/02/23 09:20:28 | 00,000,250 | —- | C] () – C:\WINNT\gmer.ini
[2009/02/23 09:20:27 | 00,884,736 | —- | C] () – C:\WINNT\gmer.dll
[2009/02/23 09:20:27 | 00,811,008 | —- | C] () – C:\WINNT\gmer.exe
[2009/02/23 09:20:27 | 00,085,969 | —- | C] (GMER) – C:\WINNT\System32\drivers\gmer.sys
[2009/02/23 09:20:27 | 00,000,080 | —- | C] () – C:\WINNT\gmer_uninstall.cmd
[2009/02/23 09:18:18 | 00,747,873 | —- | C] () – C:\Documents and Settings\briant\Desktop\gmer.zip
[2009/02/20 19:40:02 | 21,244,872 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\MRT.exe
[2009/02/20 19:32:09 | 00,000,000 | —D | C] – C:\WINNT\System32\XPSViewer
[2009/02/20 19:32:04 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/02/20 19:31:51 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/02/20 19:31:12 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\xpssvcs.dll
[2009/02/20 19:31:12 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\xpssvcs.dll
[2009/02/20 19:31:12 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\printfilterpipelinesvc.exe
[2009/02/20 19:31:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\xpsshhdr.dll
[2009/02/20 19:31:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\xpsshhdr.dll
[2009/02/20 19:31:12 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\prntvpt.dll
[2009/02/20 19:31:12 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\filterpipelineprintproc.dll
[2009/02/20 19:31:11 | 00,000,000 | —D | C] – C:\16f8fd295b7a9f92269924876cb964
[2009/02/20 18:31:41 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\msadce.dll
[2009/02/20 17:55:32 | 00,000,000 | —D | C] – C:\WINNT\Prefetch
[2009/02/20 17:31:44 | 00,000,000 | —D | C] – C:\WINNT\System32\en-us
[2009/02/20 17:31:43 | 00,000,000 | —D | C] – C:\WINNT\System32\scripting
[2009/02/20 17:31:41 | 00,000,000 | —D | C] – C:\WINNT\l2schemas
[2009/02/20 17:31:40 | 00,000,000 | —D | C] – C:\WINNT\System32\en
[2009/02/20 17:31:40 | 00,000,000 | —D | C] – C:\Program Files\msn
[2009/02/20 17:25:31 | 00,000,000 | —D | C] – C:\WINNT\network diagnostic
[2009/02/20 17:23:41 | 00,001,374 | —- | C] () – C:\WINNT\imsins.BAK
[2009/02/20 17:08:51 | 00,121,856 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\xmllite.dll
[2009/02/20 17:08:49 | 00,276,992 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\wmphoto.dll
[2009/02/20 17:08:47 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\wlanapi.dll
[2009/02/20 17:08:45 | 00,712,704 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\windowscodecs.dll
[2009/02/20 17:08:45 | 00,346,112 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\windowscodecsext.dll
[2009/02/20 17:08:37 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\tsgqec.dll
[2009/02/20 17:08:37 | 00,050,688 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\tspkg.dll
[2009/02/20 17:08:23 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\drivers\sffp_mmc.sys
[2009/02/20 17:08:22 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\setupn.exe
[2009/02/20 17:08:19 | 00,290,304 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\rhttpaa.dll
[2009/02/20 17:08:18 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\rasqec.dll
[2009/02/20 17:08:16 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\qutil.dll
[2009/02/20 17:08:15 | 00,291,328 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\qagentrt.dll
[2009/02/20 17:08:15 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\qagent.dll
[2009/02/20 17:08:15 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\qcliprov.dll
[2009/02/20 17:08:14 | 00,412,160 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\photometadatahandler.dll
[2009/02/20 17:08:10 | 00,144,384 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\onex.dll
[2009/02/20 17:08:00 | 00,193,024 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\napmontr.dll
[2009/02/20 17:08:00 | 00,176,640 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\napstat.exe
[2009/02/20 17:08:00 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\napipsec.dll
[2009/02/20 17:07:59 | 01,306,624 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\msxml6.dll
[2009/02/20 17:07:59 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\msxml6r.dll
[2009/02/20 17:07:59 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\msxml6r.dll
[2009/02/20 17:07:57 | 00,155,136 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\mssha.dll
[2009/02/20 17:07:57 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\msshavmsg.dll
[2009/02/20 17:07:39 | 00,397,312 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\mmcex.dll
[2009/02/20 17:07:39 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\microsoft.managementconsole.dll
[2009/02/20 17:07:39 | 00,106,496 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\mmcfxcommon.dll
[2009/02/20 17:07:39 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\mmcperf.exe
[2009/02/20 17:07:25 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\kmsvc.dll
[2009/02/20 17:07:25 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\l2gpstore.dll
[2009/02/20 17:07:24 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\kbdpash.dll
[2009/02/20 17:07:24 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\kbdnepr.dll
[2009/02/20 17:07:24 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\kbdiultn.dll
[2009/02/20 17:07:24 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\kbdbhc.dll
[2009/02/20 17:07:22 | 00,102,912 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\dpcdll.dll
[2009/02/20 17:07:22 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\pidgen.dll
[2009/02/20 17:07:12 | 00,000,974 | —- | C] () – C:\WINNT\System32\pid.inf
[2009/02/20 17:06:57 | 00,184,832 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eapp3hst.dll
[2009/02/20 17:06:57 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eapphost.dll
[2009/02/20 17:06:57 | 00,126,976 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eappcfg.dll
[2009/02/20 17:06:57 | 00,094,208 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eappgnui.dll
[2009/02/20 17:06:57 | 00,059,392 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eapqec.dll
[2009/02/20 17:06:57 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eappprxy.dll
[2009/02/20 17:06:57 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eapsvc.dll
[2009/02/20 17:06:57 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\eapolqec.dll
[2009/02/20 17:06:54 | 00,650,752 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3ui.dll
[2009/02/20 17:06:54 | 00,132,096 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3svc.dll
[2009/02/20 17:06:54 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3cfg.dll
[2009/02/20 17:06:54 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3msm.dll
[2009/02/20 17:06:54 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3gpclnt.dll
[2009/02/20 17:06:54 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3api.dll
[2009/02/20 17:06:54 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dot3dlg.dll
[2009/02/20 17:06:53 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dimsroam.dll
[2009/02/20 17:06:53 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dimsntfy.dll
[2009/02/20 17:06:52 | 00,048,640 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dhcpqec.dll
[2009/02/20 17:06:49 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\credssp.dll
[2009/02/20 17:06:45 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\bitsprx4.dll
[2009/02/20 17:06:44 | 00,233,472 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\azroles.dll
[2009/02/20 17:06:36 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\aaclient.dll
[2009/02/20 16:32:50 | 00,023,576 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\wuapi.dll.mui
[2009/02/20 15:43:33 | 00,212,480 | —- | C] (SteelWerX) – C:\WINNT\SWXCACLS.exe
[2009/02/20 15:43:33 | 00,161,792 | —- | C] (SteelWerX) – C:\WINNT\SWREG.exe
[2009/02/20 15:43:33 | 00,136,704 | —- | C] (SteelWerX) – C:\WINNT\SWSC.exe
[2009/02/20 15:43:25 | 00,000,000 | —D | C] – C:\Qoobox
[2009/02/19 22:12:34 | 00,001,734 | —- | C] () – C:\Documents and Settings\briant\Desktop\HijackThis.lnk
[2009/02/19 22:12:34 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/19 21:53:07 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/19 15:16:28 | 00,494,592 | —- | C] (OldTimer Tools) – C:\Documents and Settings\briant\Desktop\OTListIt2.exe
[2009/02/19 15:01:55 | 00,000,000 | —D | C] – C:\WINNT\ERDNT
[2009/02/17 14:55:51 | 00,136,979 | —- | C] () – C:\Documents and Settings\briant\Desktop\door_guy0001.JPG
[2009/02/02 14:44:36 | 00,226,015 | —- | C] () – C:\Documents and Settings\briant\Desktop\coolant_receipt0001.PDF
[2009/01/30 20:36:24 | 00,331,497 | —- | C] () – C:\Documents and Settings\briant\Desktop\Mad Minute0001.PDF
[2009/01/28 23:52:15 | 00,222,730 | —- | C] () – C:\Documents and Settings\briant\My Documents\Gulf Coast Roundup.jpg
[2009/01/28 17:58:35 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/01/27 20:18:07 | 00,025,088 | —- | C] () – C:\Documents and Settings\briant\My Documents\noel math.doc

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINNT\System32\*.tmp files]
[3 C:\WINNT\*.tmp files]
[2009/02/25 14:53:39 | 00,724,952 | —- | M] () – C:\Documents and Settings\briant\Desktop\avenger.zip
[2009/02/25 14:50:48 | 00,000,466 | —- | M] () – C:\WINNT\SMSCFG.ini
[2009/02/25 14:50:14 | 00,002,206 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2009/02/25 14:50:10 | 00,002,279 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AT&T Global Network Client Monitor.lnk
[2009/02/25 14:49:01 | 00,000,006 | -H– | M] () – C:\WINNT\tasks\SA.DAT
[2009/02/25 14:48:58 | 00,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2009/02/25 14:48:57 | 10,645,79072 | -HS- | M] () – C:\hiberfil.sys
[2009/02/25 14:47:26 | 00,000,012 | —- | M] () – C:\WINNT\bthservsdp.dat
[2009/02/25 14:47:17 | 02,681,302 | -H– | M] () – C:\Documents and Settings\briant\Local Settings\Application Data\IconCache.db
[2009/02/24 15:21:55 | 00,001,797 | —- | M] () – C:\WINNT\sho1100w.mif
[2009/02/24 15:19:35 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/24 15:17:53 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\briant\Desktop\mbam-setup.exe
[2009/02/23 18:22:23 | 00,000,000 | —- | M] () – C:\WINNT\MEMORY.DMP
[2009/02/23 18:11:19 | 12,658,160 | —- | M] (Doctor Web, Ltd.) – C:\Documents and Settings\briant\Desktop\drweb-cureit.exe
[2009/02/23 09:20:28 | 00,000,250 | —- | M] () – C:\WINNT\gmer.ini
[2009/02/23 09:20:27 | 00,884,736 | —- | M] () – C:\WINNT\gmer.dll
[2009/02/23 09:20:27 | 00,085,969 | —- | M] (GMER) – C:\WINNT\System32\drivers\gmer.sys
[2009/02/23 09:20:27 | 00,000,080 | —- | M] () – C:\WINNT\gmer_uninstall.cmd
[2009/02/23 09:18:18 | 00,747,873 | —- | M] () – C:\Documents and Settings\briant\Desktop\gmer.zip
[2009/02/23 09:15:08 | 00,000,227 | —- | M] () – C:\WINNT\system.ini
[2009/02/20 23:40:42 | 00,447,422 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2009/02/20 23:40:42 | 00,073,356 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2009/02/20 23:40:41 | 00,527,896 | —- | M] () – C:\WINNT\System32\PerfStringBackup.INI
[2009/02/20 22:05:48 | 00,000,863 | —- | M] () – C:\WINNT\win.ini
[2009/02/20 21:54:43 | 00,216,856 | —- | M] () – C:\WINNT\System32\FNTCACHE.DAT
[2009/02/20 19:39:55 | 00,001,374 | —- | M] () – C:\WINNT\imsins.BAK
[2009/02/20 19:39:17 | 00,000,085 | —- | M] () – C:\WINNT\vbaddin.ini
[2009/02/20 17:58:22 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\briant\My Documents\desktop.ini
[2009/02/20 17:25:01 | 00,250,048 | RHS- | M] () – C:\ntldr
[2009/02/20 15:51:22 | 00,000,027 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2009/02/19 22:12:34 | 00,001,734 | —- | M] () – C:\Documents and Settings\briant\Desktop\HijackThis.lnk
[2009/02/19 15:16:28 | 00,494,592 | —- | M] (OldTimer Tools) – C:\Documents and Settings\briant\Desktop\OTListIt2.exe
[2009/02/17 14:55:51 | 00,136,979 | —- | M] () – C:\Documents and Settings\briant\Desktop\door_guy0001.JPG
[2009/02/11 20:56:18 | 21,244,872 | —- | M] (Microsoft Corporation) – C:\WINNT\System32\MRT.exe
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2009/02/02 14:44:37 | 00,226,015 | —- | M] () – C:\Documents and Settings\briant\Desktop\coolant_receipt0001.PDF
[2009/01/30 20:36:25 | 00,331,497 | —- | M] () – C:\Documents and Settings\briant\Desktop\Mad Minute0001.PDF
[2009/01/28 23:52:17 | 00,222,730 | —- | M] () – C:\Documents and Settings\briant\My Documents\Gulf Coast Roundup.jpg
[2009/01/27 20:29:25 | 00,025,088 | —- | M] () – C:\Documents and Settings\briant\My Documents\noel math.doc

========== Alternate Data Streams ==========

@Alternate Data Stream - 0 bytes -> C:\WINNT\Thumbs.db:encryptable
< End of report >



Avenger Log

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "C:\WINNT\System32\nuwoboza" not found!
Deletion of file "C:\WINNT\System32\nuwoboza" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: folder "C:\WINNT\system32\nuwoboza" not found!
Deletion of folder "C:\WINNT\system32\nuwoboza" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Completed script processing.

*******************

Finished! Terminate.


HJT Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:18:56 PM, on 2/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRAM FILES\DRU\bin\DRUService.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\hjavaw.exe
c:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\Java\jre1.5.0_13\bin\javaw.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
C:\WINNT\system32\pstartSr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\snmpdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\compapps\swstore\ssservice.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Doctor Install\DrInstalSvc.exe
C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\system32\CCM\CcmExec.exe
C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
C:\Program Files\Doctor Install\InstallMgr.exe
C:\WINNT\system32\carpserv.exe
c:\Program Files\Network Associates\Common Framework\McTray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINNT\Logi_MwX.Exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\WINNT\system32\rundll32.exe
C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\WINNT\system32\msiexec.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
c:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Linksys\Bluetooth Utility\BTTray.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_gui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Linksys\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINNT\system32\BhoCitUS.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "c:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Doctor Install] C:\Program Files\Doctor Install\InstallMgr.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Pointsec Tray] C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetSP - restore settings on power failure] "C:\Program Files\AT&T Global Network Client\NetSP.exe" -show
O4 - S-1-5-18 Startup: ropu.bat (User 'SYSTEM')
O4 - .DEFAULT Startup: ropu.bat (User 'Default user')
O4 - .DEFAULT User Startup: ropu.bat (User 'Default user')
O4 - Global Startup: AT&T Global Network Client Monitor.lnk = ?
O4 - Global Startup: BTTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm
O9 - Extra button: Knowledge Gateway - {D666CFDA-F583-889A-323D-9F8FAF7144C3} - C:\Program Files\knowledgegateway\launch.htm
O9 - Extra 'Tools' menuitem: Knowledge Gateway - {D666CFDA-F583-889A-323D-9F8FAF7144C3} - C:\Program Files\knowledgegateway\launch.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {08288600-E9D9-11D1-9C84-006008319186} (VanTFind.VanTFindCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vantfind.cab
O16 - DPF: {14924309-C4D4-11D1-85ED-006097794610} (StkCstUserControl.StkCstMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkCst.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://lmc.sbc.com/courses/aicc/download/a…yer/awswaxf.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C8B8F66-60FA-11D1-8B99-0020AFF5AA3B} (ucCommonDataField.ucCmnDataField) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\icccdf4.cab
O16 - DPF: {201CF4B6-C42D-11D1-A0EC-006008936BDD} (ItemStUC.ItemStocking) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmStk.cab
O16 - DPF: {3D82A12A-C1FA-11D0-9B21-0080C79EFE90} (VanFind.VanFindCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vanfind.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4117ECE7-C7FE-11D1-9844-0060089F7AEB} (StkLkpUC.StockLookup) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkLkp.cab
O16 - DPF: {413D6754-BFD4-47FE-9346-319559290BFA} (HTECtrl Class) - https://www.webpcfos.com/webpcfos/websabre/HTEweb_new.cab
O16 - DPF: {4E192D78-E515-11D1-B89E-0020AFF695A0} (ItmMastUC.ItemMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmMst.cab
O16 - DPF: {51BB7DFD-A6F5-4FAC-B8C9-E71CF84D082C} (AeXNSConsoleContextHelp Class) - http://pdsnsm1/Altiris/NS/NSCap/Bin/Win32/…isNSConsole.cab
O16 - DPF: {60046ED9-8E77-11D0-9B21-0080C79EFE90} (VanGrid.VanGridCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vangrid.cab
O16 - DPF: {603607C4-BE6F-11D1-983A-0060089F7AEB} (CarrierUserControl.CarrierMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCarrier.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1235086621796
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1235086609093
O16 - DPF: {9345E91A-BF88-11D1-8AFE-00A02470741B} (VendorContUC.VendorCont) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVendCt.cab
O16 - DPF: {97EEFD1A-C41D-11D1-A0EC-006008936BDD} (CustLabelsUsrCtrl.CustomLabels) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCusLbl.cab
O16 - DPF: {9E85612B-D0A6-11D1-89BF-0060089F7A3E} (ShipComp.ShipmentViewer) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\SHIPVIEW.cab
O16 - DPF: {AA64AF34-C45D-11D1-85ED-006097794610} (VirDomUC.VirDomainMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVirDm.cab
O16 - DPF: {ABDE29F2-6F9C-11D1-9B21-0080C79EFE90} (VanLiteral.CodeSet) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\VanLiteral.CAB
O16 - DPF: {B86D4018-C597-11D1-9843-0060089F7AEB} (UOMUserControl.UOMMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucUOM.cab
O16 - DPF: {B86D4502-C597-11D1-9843-0060089F7AEB} (ItemCat.ItmCatUC) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmCat.cab
O16 - DPF: {B8958DE0-BAC9-101C-933E-0000C005958C} (FarPoint DateTime Control) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\edt32x20.ocx
O16 - DPF: {BE033B8C-722E-11D1-9B21-0080C79EFE90} (VanMessage.Message) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\VanMessage.CAB
O16 - DPF: {BE77224A-C41F-11D1-85ED-006097794610} (StkDtUserControl.StkDtMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkDt.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {D7553B82-8EEC-11D4-AAE3-005056A35A1F} (ATTCustomComponents.UploadComponent) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\UPLOADCOMPONENT.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://advancedmeetings.webex.com/client/v…bex/ieatgpc.cab
O16 - DPF: {EB0CF3B4-C33B-11D1-A0EC-006008936BDD} (StkStUC.StockStatusMaint) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkSt.cab
O16 - DPF: {EB52CF7B-3917-11CE-80FB-0000C0C14E92} (SSDateCombo Control) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\sscala32.cab
O16 - DPF: {EBF47667-BF3F-11D1-983D-0060089F7AEB} (CarrConUserControl.CarrierContactMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCarCont.cab
O16 - DPF: {ED738376-C44A-11D1-A0EC-006008936BDD} (BDUsrCtrl.BusinessDomain) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucBusDom.cab
O16 - DPF: {F29BE3C6-BE82-11D1-91FE-0020AFF5AA68} (CurrencyUserControl.CurrencyMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCurr.cab
O16 - DPF: {F39FD815-E9C3-11D1-9C83-006008319186} (VanTree.VanTreeCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vantree.cab
O16 - DPF: {F74887C8-C44B-11D1-85ED-006097794610} (VendorUserControl.VendorMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVend.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\Software\..\Telephony: DomainName = ugd.att.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{5652F885-570C-4CD6-BC0A-7689B37B68CF}: Domain = ugd.att.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ugd.att.com,ems.att.com,ims.att.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = ugd.att.com,ems.att.com,ims.att.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ugd.att.com,ems.att.com,ims.att.com
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe
O23 - Service: Insight Local Alerter (CPQALERT) - Hewlett-Packard Company - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: DRUAgent - AT&T - C:\PROGRAM FILES\DRU\bin\DRUService.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Ltd. - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
O23 - Service: Hummingbird Jconfig Daemon (Jconfigd) - Hummingbird Ltd. - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - c:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Network Configuration Service (netcfgsvr) - AT&T - C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
O23 - Service: OracleOraHome90ClientCache - Unknown owner - C:\oracle\ora90\BIN\ONRSD.EXE
O23 - Service: Pointsec Service Start (Pointsec_start) - Unknown owner - C:\WINNT\system32\pstartSr.exe
O23 - Service: Remote Command Service (rcmdsvc) - Unknown owner - \\BCANTRELL2\c$\temp\rcmdsvc.exe (file missing)
O23 - Service: SMSWUagent - 1E Ltd. - C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe
O23 - Service: snmpdm - Unknown owner - C:\WINNT\system32\snmpdm.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: AT&T Software Store (ssserviceWinService) - Unknown owner - C:\Program Files\compapps\swstore\ssservice.exe
O23 - Service: Doctor Install (Svc_DrInstal) - AT&T - C:\Program Files\Doctor Install\DrInstalSvc.exe
O23 - Service: IBM Tivoli Remote Control - Target (TRCTARGET) - Unknown owner - C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe

–
End of file - 15678 bytes
Hi beachbriant

Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.


NEXT
- After the Kaspersky scan has completed.

Please check with ATT to see if the disabling of the AutoUpdate feature is a policy that they have set on your computer as there doesn't appear to be any other reason why it doesn't work.

If it isn't an AT&T policy then try this

  • Download WUFix.exe to your desktop.
  • Double-Click WUFix.exe to run fix.
  • You will see a window open and commands processing. When the window closes the fix will have completed.
  • Restart the computer.
This fix will clear the proxy cache, places Windows Update sites in the Trusted Zone, places Windows Update sites in the exception list of IE Popup Blocker, starts all dependent services, registers required DLLS, empties the Windows Update temporary folder (with backup), renames the catroot2 folder, retains update history and Event log, and deletes BITS pending download queue.

Once done, go back to the Windows Update Website (You must use the Microsoft Internet Explorer to do this).


Let me know either way.

In your next response I need


  • Kaspersky log
  • Fresh HJT log
  • Update re ATT policy for auto updating
.
Thanks CatByte!

PC is running good. I believe you have walked me through successfully cleaning up all of the problems! Thank you very much!

Kaspersky Log
——————————————————————————–

KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, February 26, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, February 25, 2009 22:29:55
Records in database: 1844758
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
W:\
X:\
Y:\
Z:\

Scan statistics:
Files scanned: 139553
Threat name: 1
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 05:12:19


File name / Threat name / Threats count
Z:\1-Software\VNC\UltraVNC-100-RC18-Setup.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1
Z:\1-Software\VNC\UltraVNC-100-RC18-Setup.zip Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1

The selected area was scanned.


HTJ.log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:14:42 AM, on 2/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRAM FILES\DRU\bin\DRUService.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
c:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\hjavaw.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\Java\jre1.5.0_13\bin\javaw.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
C:\WINNT\system32\pstartSr.exe
C:\WINNT\system32\snmpdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\compapps\swstore\ssservice.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Doctor Install\DrInstalSvc.exe
C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\WINNT\Explorer.EXE
C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_gui.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
c:\Program Files\Network Associates\Common Framework\McTray.exe
C:\Program Files\Doctor Install\InstallMgr.exe
C:\WINNT\system32\carpserv.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINNT\Logi_MwX.Exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\WINNT\system32\rundll32.exe
C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\WINNT\system32\ctfmon.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
c:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Linksys\Bluetooth Utility\BTTray.exe
C:\PROGRA~1\Linksys\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINNT\system32\BhoCitUS.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "c:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Doctor Install] C:\Program Files\Doctor Install\InstallMgr.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Pointsec Tray] C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetSP - restore settings on power failure] "C:\Program Files\AT&T Global Network Client\NetSP.exe" -show
O4 - S-1-5-18 Startup: ropu.bat (User 'SYSTEM')
O4 - .DEFAULT Startup: ropu.bat (User 'Default user')
O4 - .DEFAULT User Startup: ropu.bat (User 'Default user')
O4 - Global Startup: AT&T Global Network Client Monitor.lnk = ?
O4 - Global Startup: BTTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm
O9 - Extra button: Knowledge Gateway - {D666CFDA-F583-889A-323D-9F8FAF7144C3} - C:\Program Files\knowledgegateway\launch.htm
O9 - Extra 'Tools' menuitem: Knowledge Gateway - {D666CFDA-F583-889A-323D-9F8FAF7144C3} - C:\Program Files\knowledgegateway\launch.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {08288600-E9D9-11D1-9C84-006008319186} (VanTFind.VanTFindCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vantfind.cab
O16 - DPF: {14924309-C4D4-11D1-85ED-006097794610} (StkCstUserControl.StkCstMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkCst.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://lmc.sbc.com/courses/aicc/download/a…yer/awswaxf.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C8B8F66-60FA-11D1-8B99-0020AFF5AA3B} (ucCommonDataField.ucCmnDataField) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\icccdf4.cab
O16 - DPF: {201CF4B6-C42D-11D1-A0EC-006008936BDD} (ItemStUC.ItemStocking) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmStk.cab
O16 - DPF: {3D82A12A-C1FA-11D0-9B21-0080C79EFE90} (VanFind.VanFindCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vanfind.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4117ECE7-C7FE-11D1-9844-0060089F7AEB} (StkLkpUC.StockLookup) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkLkp.cab
O16 - DPF: {413D6754-BFD4-47FE-9346-319559290BFA} (HTECtrl Class) - https://www.webpcfos.com/webpcfos/websabre/HTEweb_new.cab
O16 - DPF: {4E192D78-E515-11D1-B89E-0020AFF695A0} (ItmMastUC.ItemMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmMst.cab
O16 - DPF: {51BB7DFD-A6F5-4FAC-B8C9-E71CF84D082C} (AeXNSConsoleContextHelp Class) - http://pdsnsm1/Altiris/NS/NSCap/Bin/Win32/…isNSConsole.cab
O16 - DPF: {60046ED9-8E77-11D0-9B21-0080C79EFE90} (VanGrid.VanGridCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vangrid.cab
O16 - DPF: {603607C4-BE6F-11D1-983A-0060089F7AEB} (CarrierUserControl.CarrierMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCarrier.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1235086621796
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1235086609093
O16 - DPF: {9345E91A-BF88-11D1-8AFE-00A02470741B} (VendorContUC.VendorCont) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVendCt.cab
O16 - DPF: {97EEFD1A-C41D-11D1-A0EC-006008936BDD} (CustLabelsUsrCtrl.CustomLabels) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCusLbl.cab
O16 - DPF: {9E85612B-D0A6-11D1-89BF-0060089F7A3E} (ShipComp.ShipmentViewer) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\SHIPVIEW.cab
O16 - DPF: {AA64AF34-C45D-11D1-85ED-006097794610} (VirDomUC.VirDomainMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVirDm.cab
O16 - DPF: {ABDE29F2-6F9C-11D1-9B21-0080C79EFE90} (VanLiteral.CodeSet) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\VanLiteral.CAB
O16 - DPF: {B86D4018-C597-11D1-9843-0060089F7AEB} (UOMUserControl.UOMMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucUOM.cab
O16 - DPF: {B86D4502-C597-11D1-9843-0060089F7AEB} (ItemCat.ItmCatUC) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmCat.cab
O16 - DPF: {B8958DE0-BAC9-101C-933E-0000C005958C} (FarPoint DateTime Control) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\edt32x20.ocx
O16 - DPF: {BE033B8C-722E-11D1-9B21-0080C79EFE90} (VanMessage.Message) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\VanMessage.CAB
O16 - DPF: {BE77224A-C41F-11D1-85ED-006097794610} (StkDtUserControl.StkDtMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkDt.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {D7553B82-8EEC-11D4-AAE3-005056A35A1F} (ATTCustomComponents.UploadComponent) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\UPLOADCOMPONENT.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://advancedmeetings.webex.com/client/v…bex/ieatgpc.cab
O16 - DPF: {EB0CF3B4-C33B-11D1-A0EC-006008936BDD} (StkStUC.StockStatusMaint) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkSt.cab
O16 - DPF: {EB52CF7B-3917-11CE-80FB-0000C0C14E92} (SSDateCombo Control) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\sscala32.cab
O16 - DPF: {EBF47667-BF3F-11D1-983D-0060089F7AEB} (CarrConUserControl.CarrierContactMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCarCont.cab
O16 - DPF: {ED738376-C44A-11D1-A0EC-006008936BDD} (BDUsrCtrl.BusinessDomain) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucBusDom.cab
O16 - DPF: {F29BE3C6-BE82-11D1-91FE-0020AFF5AA68} (CurrencyUserControl.CurrencyMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCurr.cab
O16 - DPF: {F39FD815-E9C3-11D1-9C83-006008319186} (VanTree.VanTreeCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vantree.cab
O16 - DPF: {F74887C8-C44B-11D1-85ED-006097794610} (VendorUserControl.VendorMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVend.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\Software\..\Telephony: DomainName = ugd.att.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{5652F885-570C-4CD6-BC0A-7689B37B68CF}: Domain = ugd.att.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ugd.att.com,ems.att.com,ims.att.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = ugd.att.com,ems.att.com,ims.att.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ugd.att.com,ems.att.com,ims.att.com
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe
O23 - Service: Insight Local Alerter (CPQALERT) - Hewlett-Packard Company - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: DRUAgent - AT&T - C:\PROGRAM FILES\DRU\bin\DRUService.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Ltd. - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
O23 - Service: Hummingbird Jconfig Daemon (Jconfigd) - Hummingbird Ltd. - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - c:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Network Configuration Service (netcfgsvr) - AT&T - C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
O23 - Service: OracleOraHome90ClientCache - Unknown owner - C:\oracle\ora90\BIN\ONRSD.EXE
O23 - Service: Pointsec Service Start (Pointsec_start) - Unknown owner - C:\WINNT\system32\pstartSr.exe
O23 - Service: Remote Command Service (rcmdsvc) - Unknown owner - \\BCANTRELL2\c$\temp\rcmdsvc.exe (file missing)
O23 - Service: SMSWUagent - 1E Ltd. - C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe
O23 - Service: snmpdm - Unknown owner - C:\WINNT\system32\snmpdm.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: AT&T Software Store (ssserviceWinService) - Unknown owner - C:\Program Files\compapps\swstore\ssservice.exe
O23 - Service: Doctor Install (Svc_DrInstal) - AT&T - C:\Program Files\Doctor Install\DrInstalSvc.exe
O23 - Service: IBM Tivoli Remote Control - Target (TRCTARGET) - Unknown owner - C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe

–
End of file - 15585 bytes


AutoUpdate:

In the past, ATT has deployed code that disables the AutoUpdate feature of windows so that they can control the push of Windows patches to user's PCs. This was not done to my company provided PC that I use daily, however, they must have pushed this to this PC in the past. Good catch! For someone in training, you did an awesome job!! You thought of the real source of this issue AND stepped me through a lot to clean up the various instances of this pesky virus. Thank you and Senior Class for your thorough assistance!
Thanks CatByte!

PC is running good. I believe you have walked me through successfully cleaning up all of the problems! Thank you very much!

Kaspersky Log
——————————————————————————–

KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, February 26, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, February 25, 2009 22:29:55
Records in database: 1844758
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
W:\
X:\
Y:\
Z:\

Scan statistics:
Files scanned: 139553
Threat name: 1
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 05:12:19


File name / Threat name / Threats count
Z:\1-Software\VNC\UltraVNC-100-RC18-Setup.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1
Z:\1-Software\VNC\UltraVNC-100-RC18-Setup.zip Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1

The selected area was scanned.


HTJ.log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:14:42 AM, on 2/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRAM FILES\DRU\bin\DRUService.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
c:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\hjavaw.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\Java\jre1.5.0_13\bin\javaw.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
C:\WINNT\system32\pstartSr.exe
C:\WINNT\system32\snmpdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\compapps\swstore\ssservice.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Doctor Install\DrInstalSvc.exe
C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\WINNT\Explorer.EXE
C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_gui.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
c:\Program Files\Network Associates\Common Framework\McTray.exe
C:\Program Files\Doctor Install\InstallMgr.exe
C:\WINNT\system32\carpserv.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINNT\Logi_MwX.Exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\WINNT\system32\rundll32.exe
C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\WINNT\system32\ctfmon.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
c:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Linksys\Bluetooth Utility\BTTray.exe
C:\PROGRA~1\Linksys\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINNT\system32\BhoCitUS.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "c:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Doctor Install] C:\Program Files\Doctor Install\InstallMgr.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Pointsec Tray] C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetSP - restore settings on power failure] "C:\Program Files\AT&T Global Network Client\NetSP.exe" -show
O4 - S-1-5-18 Startup: ropu.bat (User 'SYSTEM')
O4 - .DEFAULT Startup: ropu.bat (User 'Default user')
O4 - .DEFAULT User Startup: ropu.bat (User 'Default user')
O4 - Global Startup: AT&T Global Network Client Monitor.lnk = ?
O4 - Global Startup: BTTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_13\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm
O9 - Extra button: Knowledge Gateway - {D666CFDA-F583-889A-323D-9F8FAF7144C3} - C:\Program Files\knowledgegateway\launch.htm
O9 - Extra 'Tools' menuitem: Knowledge Gateway - {D666CFDA-F583-889A-323D-9F8FAF7144C3} - C:\Program Files\knowledgegateway\launch.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {08288600-E9D9-11D1-9C84-006008319186} (VanTFind.VanTFindCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vantfind.cab
O16 - DPF: {14924309-C4D4-11D1-85ED-006097794610} (StkCstUserControl.StkCstMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkCst.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://lmc.sbc.com/courses/aicc/download/a…yer/awswaxf.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C8B8F66-60FA-11D1-8B99-0020AFF5AA3B} (ucCommonDataField.ucCmnDataField) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\icccdf4.cab
O16 - DPF: {201CF4B6-C42D-11D1-A0EC-006008936BDD} (ItemStUC.ItemStocking) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmStk.cab
O16 - DPF: {3D82A12A-C1FA-11D0-9B21-0080C79EFE90} (VanFind.VanFindCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vanfind.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4117ECE7-C7FE-11D1-9844-0060089F7AEB} (StkLkpUC.StockLookup) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkLkp.cab
O16 - DPF: {413D6754-BFD4-47FE-9346-319559290BFA} (HTECtrl Class) - https://www.webpcfos.com/webpcfos/websabre/HTEweb_new.cab
O16 - DPF: {4E192D78-E515-11D1-B89E-0020AFF695A0} (ItmMastUC.ItemMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmMst.cab
O16 - DPF: {51BB7DFD-A6F5-4FAC-B8C9-E71CF84D082C} (AeXNSConsoleContextHelp Class) - http://pdsnsm1/Altiris/NS/NSCap/Bin/Win32/…isNSConsole.cab
O16 - DPF: {60046ED9-8E77-11D0-9B21-0080C79EFE90} (VanGrid.VanGridCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vangrid.cab
O16 - DPF: {603607C4-BE6F-11D1-983A-0060089F7AEB} (CarrierUserControl.CarrierMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCarrier.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1235086621796
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1235086609093
O16 - DPF: {9345E91A-BF88-11D1-8AFE-00A02470741B} (VendorContUC.VendorCont) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVendCt.cab
O16 - DPF: {97EEFD1A-C41D-11D1-A0EC-006008936BDD} (CustLabelsUsrCtrl.CustomLabels) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCusLbl.cab
O16 - DPF: {9E85612B-D0A6-11D1-89BF-0060089F7A3E} (ShipComp.ShipmentViewer) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\SHIPVIEW.cab
O16 - DPF: {AA64AF34-C45D-11D1-85ED-006097794610} (VirDomUC.VirDomainMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVirDm.cab
O16 - DPF: {ABDE29F2-6F9C-11D1-9B21-0080C79EFE90} (VanLiteral.CodeSet) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\VanLiteral.CAB
O16 - DPF: {B86D4018-C597-11D1-9843-0060089F7AEB} (UOMUserControl.UOMMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucUOM.cab
O16 - DPF: {B86D4502-C597-11D1-9843-0060089F7AEB} (ItemCat.ItmCatUC) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucItmCat.cab
O16 - DPF: {B8958DE0-BAC9-101C-933E-0000C005958C} (FarPoint DateTime Control) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\edt32x20.ocx
O16 - DPF: {BE033B8C-722E-11D1-9B21-0080C79EFE90} (VanMessage.Message) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\VanMessage.CAB
O16 - DPF: {BE77224A-C41F-11D1-85ED-006097794610} (StkDtUserControl.StkDtMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkDt.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {D7553B82-8EEC-11D4-AAE3-005056A35A1F} (ATTCustomComponents.UploadComponent) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\UPLOADCOMPONENT.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://advancedmeetings.webex.com/client/v…bex/ieatgpc.cab
O16 - DPF: {EB0CF3B4-C33B-11D1-A0EC-006008936BDD} (StkStUC.StockStatusMaint) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucStkSt.cab
O16 - DPF: {EB52CF7B-3917-11CE-80FB-0000C0C14E92} (SSDateCombo Control) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\sscala32.cab
O16 - DPF: {EBF47667-BF3F-11D1-983D-0060089F7AEB} (CarrConUserControl.CarrierContactMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCarCont.cab
O16 - DPF: {ED738376-C44A-11D1-A0EC-006008936BDD} (BDUsrCtrl.BusinessDomain) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucBusDom.cab
O16 - DPF: {F29BE3C6-BE82-11D1-91FE-0020AFF5AA68} (CurrencyUserControl.CurrencyMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucCurr.cab
O16 - DPF: {F39FD815-E9C3-11D1-9C83-006008319186} (VanTree.VanTreeCtrl) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\vantree.cab
O16 - DPF: {F74887C8-C44B-11D1-85ED-006097794610} (VendorUserControl.VendorMaster) - file://C:\DOCUME~1\BCANTR~1\LOCALS~1\Temp\ucVend.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\Software\..\Telephony: DomainName = ugd.att.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{5652F885-570C-4CD6-BC0A-7689B37B68CF}: Domain = ugd.att.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ugd.att.com,ems.att.com,ims.att.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = ugd.att.com,ems.att.com,ims.att.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ugd.att.com,ems.att.com,ims.att.com
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe
O23 - Service: Insight Local Alerter (CPQALERT) - Hewlett-Packard Company - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: DRUAgent - AT&T - C:\PROGRAM FILES\DRU\bin\DRUService.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Ltd. - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
O23 - Service: Hummingbird Jconfig Daemon (Jconfigd) - Hummingbird Ltd. - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - c:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Network Configuration Service (netcfgsvr) - AT&T - C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
O23 - Service: OracleOraHome90ClientCache - Unknown owner - C:\oracle\ora90\BIN\ONRSD.EXE
O23 - Service: Pointsec Service Start (Pointsec_start) - Unknown owner - C:\WINNT\system32\pstartSr.exe
O23 - Service: Remote Command Service (rcmdsvc) - Unknown owner - \\BCANTRELL2\c$\temp\rcmdsvc.exe (file missing)
O23 - Service: SMSWUagent - 1E Ltd. - C:\Program Files\1E\SMSWakeUp50\SMSWUagent.exe
O23 - Service: snmpdm - Unknown owner - C:\WINNT\system32\snmpdm.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: AT&T Software Store (ssserviceWinService) - Unknown owner - C:\Program Files\compapps\swstore\ssservice.exe
O23 - Service: Doctor Install (Svc_DrInstal) - AT&T - C:\Program Files\Doctor Install\DrInstalSvc.exe
O23 - Service: IBM Tivoli Remote Control - Target (TRCTARGET) - Unknown owner - C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe

–
End of file - 15585 bytes


AutoUpdate:

In the past, ATT has deployed code that disables the AutoUpdate feature of windows so that they can control the push of Windows patches to user's PCs. This was not done to my company provided PC that I use daily, however, they must have pushed this to this PC in the past. Good catch! For someone in training, you did an awesome job!! You thought of the real source of this issue AND stepped me through a lot to clean up the various instances of this pesky virus. Thank you and Senior Class for your thorough assistance!
Hello beachbriant

Good news - your logs look clean :thumbup:

Now we have some clean up to do.

Your Java is outdated and is vulnerable to exploits

Please do this:


Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer. (Version 6 update 12)

NEXT
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
[external image: Posted Image]



>>>>NEXT<<<<< (Don't miss this step)

Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • For use with Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.
  • Please read the guide by Rorschach112 on how to prevent malware and about safe computing here

Thank you for your patience, and performing all of the procedures requested


(I have passed on your thanks to the very talented and charismatic Essexboy, who assisted me with your case)
Thank you and Essexboy for all of the assistance! I performed the steps below and have also installed the recommendations you provided. Hopefully this will help keep me from getting in this jam again! You all provide a great service and I have nothing but accolades for the assistance!! Thank You, Briant
I couldn't determine if you wanted me to add the info on the second PC to this thread or start a new one. If need a new one, just leave me that message.

This PC is running Windows 2000, has a 600 MHz processor and 384MB Ram.
I installed some of the recommendations you identified above and ran the Kapersky virus scan on it last night and nothing was found.

I had been unable to get it to take Windows updates, but read somewhere to allow SYSTEM full access to the C drive, stop AutoUpdate, rename the Software Distribution folder, start Auto Update, and I did connect and have 45 patches from Microsoft to install. After the installation and reboot, for some reason, I can't connect to Auto Update anymore…. This is more an FYI, since I don't think you all deal with those issues, unless you do… :thumbup:

Following is the HJT log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:46:47 AM, on 2/27/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\CTsvcCDA.EXE
C:\WINNT\System32\svchost.exe
d:\Program Files\ahead\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\opt\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINNT\system32\mgabg.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\ImageMate CompactFlash USB\SandIcon.Exe
C:\WINNT\system32\PDesk\PDesk.exe
C:\WINNT\system32\UMonit2k.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
D:\Program Files\ahead\InCD\InCD.exe
D:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
D:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaul…rch/search.html
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CitiUSBrowserHelper Class - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINNT\system32\BhoCitUS.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb02.exe
O4 - HKLM\..\Run: [SandIcon] C:\ImageMate CompactFlash USB\SandIcon.Exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINNT\system32\UMonit2k.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] d:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WinPatrol] D:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [Creative Detector] d:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [MPlayer2_FixUp] C:\WINNT\inf\unregmp2.exe /Fixups (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: Boxtop - file://C:\Program Files\BoxTopsShoppingReminder\System\Temp\boxtopgmills_script0.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Boxtop - {629C5DAA-BABC-4d44-983D-97AFF415621C} - file://C:\Program Files\BoxTopsShoppingReminder\System\Temp\boxtopgmills_script0.htm (HKCU)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .TIF: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin7.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - https://www.acss.att.com/CFIDE/classes/CFJava.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - https://www01.webpcfos.com/webpcfos/Citrix/wficat.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {4DEE438E-5A3F-463C-8944-006534BA52F2} - http://www.topmoxie.com/external/builds/bo…inder_moxie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1235685745988
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://sc.communities.msn.com/controls/chat/msnchat42.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297B} - http://www.net2phone.com/software/commcent…Center7675a.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tri…uginstaller.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ugd.att.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ugd.att.com
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTsvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - d:\Program Files\ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\opt\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\system32\mgabg.exe
O23 - Service: MSADC - Unknown owner - C:\WINNT\System32\msadc.exe (file missing)
O23 - Service: OracleOraHome90ClientCache - Unknown owner - C:\oracle\ora90\BIN\ONRSD.EXE
O23 - Service: Remotely Possible/32 (RP32Service) - Unknown owner - C:\PROGRA~1\Avalan\REMOTE~1\rp32serv.exe
O23 - Service: Doctor Install (Svc_DrInstal) - Unknown owner - C:\Program Files\Doctor Install\DrInstalSvc.exe (file missing)

–
End of file - 8620 bytes

Thanks Again!
I don't see anything too terrible there. There are some unwanted programs that can be removed though.

please do this:

Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your reply.

Once I get the uninstall list I will be back in time with further instructions:

CB
uninstall list

ACDSee
Adobe Flash Player ActiveX
Adobe Photoshop 6.0
Adobe Reader 7.0.9
Adobe Shockwave Player 11
ArcSoft VideoImpression 1.5
AT&T Global Network Dialer
AT&T Net Client
BUM
CCleaner (remove only)
Creative Mass Storage Drivers
Creative MediaSource
Creative System Information
Creative Zen Nano Plus
Defraggler (remove only)
FUJIFILM CAMERA DIGITAL Q1 Driver
HiFi WAV Splitter Joiner 3.00
HijackThis 2.0.2
ImageMate CompactFlash USB (SDDR-31) Ver. 5.05
InterActual Player
Internet Explorer Q903235
Java™ 6 Update 12
JumpStart Typing
Kid's Typing Skills
Malwarebytes' Anti-Malware
Matrox Graphics Software (remove only)
McAfee VirusScan Enterprise
Microsoft DirectX Transform optional components
Microsoft Office 2000 Premium
Microsoft Office Professional Edition 2003
Microtek ScanWizard
Mozilla Firefox (1.0PR)
MP3 Rocket
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
My Search Bar
Nero Suite
Panasonic DVC USB Driver
Pinball Panic
PYRO WebCam
Quick Movie Magic 1.0E
QuickTime
QuickTime 3.0
QuickTime for Windows (32-bit)
RealPlayer
Remotely Possible/32 4.0
RollerCoaster Tycoon Deluxe
Security Update for DirectX 9 (KB951698)
Security Update for Windows 2000 (KB941569)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 6.4 (KB954600)
Security Update for Windows Media Player 9 (KB936782)
Shockwave
SpywareBlaster 4.1
SpywareGuard v2.2
Typing Quick & Easy
Wav Combiner version 1.11
WeatherBug
Winamp
Windows 2000 Hotfix - KB918118
Windows 2000 Hotfix - KB920213
Windows 2000 Hotfix - KB922760
Windows 2000 Hotfix - KB923810
Windows 2000 Hotfix - KB923980
Windows 2000 Hotfix - KB924270
Windows 2000 Hotfix - KB924667
Windows 2000 Hotfix - KB925902
Windows 2000 Hotfix - KB926122
Windows 2000 Hotfix - KB926247
Windows 2000 Hotfix - KB926436
Windows 2000 Hotfix - KB927891
Windows 2000 Hotfix - KB928843
Windows 2000 Hotfix - KB930178
Windows 2000 Hotfix - KB931784
Windows 2000 Hotfix - KB933729
Windows 2000 Hotfix - KB935839
Windows 2000 Hotfix - KB935840
Windows 2000 Hotfix - KB937894
Windows 2000 Hotfix - KB938464
Windows 2000 Hotfix - KB938827
Windows 2000 Hotfix - KB943055
Windows 2000 Hotfix - KB943485
Windows 2000 Hotfix - KB944338
Windows 2000 Hotfix - KB945553
Windows 2000 Hotfix - KB950749
Windows 2000 Hotfix - KB950760
Windows 2000 Hotfix - KB950974
Windows 2000 Hotfix - KB951066
Windows 2000 Hotfix - KB951748
Windows 2000 Hotfix - KB952954
Windows 2000 Hotfix - KB954211
Windows 2000 Hotfix - KB955069
Windows 2000 Hotfix - KB956802
Windows 2000 Hotfix - KB957097
Windows 2000 Hotfix - KB958215
Windows 2000 Hotfix - KB958644
Windows 2000 Hotfix - KB958687
Windows 2000 Hotfix - KB960714
Windows 2000 Hotfix - KB960715
Windows 2000 Hotfix - KB967715
Windows Genuine Advantage v1.3.0254.0
Windows Media Encoder 7.1
Windows Media Player system update (9 Series)
WinPatrol 2008
WinZip

Hi beachbriant

Please go to Start>ControlPanel>Add/remove Programs
from the populated list of programs - select the following programs (If they are still there) and choose REMOVE
  • My Search Bar
  • WeatherBug
  • Bargain Buddy
  • TopMoxie


While you are in Add/Remove Programs, take a good look over your installed programs list - if there is anything there that you no longer use - uninstall it.

(If you are unsure what a certain program is or what it does - leave it alone, post back here and I will let you know)

NEXT

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O8 - Extra context menu item: Boxtop - file://C:\Program Files\BoxTopsShoppingReminder\System\Temp\boxtopgmills_script0.htm
O9 - Extra button: Boxtop - {629C5DAA-BABC-4d44-983D-97AFF415621C} - file://C:\Program Files\BoxTopsShoppingReminder\System\Temp\boxtopgmills_script0.htm (HKCU)
O16 - DPF: {4DEE438E-5A3F-463C-8944-006534BA52F2} - http://www.topmoxie.com/external/builds/bo…inder_moxie.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297B} - http://www.net2phone.com/software/commcent…Center7675a.cab G
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tri…uginstaller.cab
O18 - Filter hijack: text/html - (no CLSID) - (no file)


  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

NEXT

Lets try the Automated Windows Update Fix

  • Download WUFix.exe to your desktop.
  • Double-Click WUFix.exe to run fix.
  • You will see a window open and commands processing. When the window closes the fix will have completed.
  • Restart the computer.
This fix will clear the proxy cache, places Windows Update sites in the Trusted Zone, places Windows Update sites in the exception list of IE Popup Blocker, starts all dependent services, registers required DLLS, empties the Windows Update temporary folder (with backup), renames the catroot2 folder, retains update history and Event log, and deletes BITS pending download queue.
Once done, you should be able to access the Windows Update Website (You must use the Microsoft Internet Explorer to do this).

NEXT

Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

NEXT

Open the MalwareBytesAntiMalware program you have on this machine. Have it search for updates, then run the program.

Have it remove anything it finds


Note: McAffee is heavy on resources - if the subscriptions are up to date, then leave it be. If the subscription has expired and you are looking for a recommendation for a free antivirus that's a little lighter on resources yet works as effectively, let me know.

In your next response please post:

  • MBAM Log
  • Fresh HJT log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI