This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Possible Backdoor Infections, Trojans, Spyware

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've run my copy of PC Tools Spyware Doctor and it found dozens of backdoor infections, spyware, and trojans. It says that it has removed them, but the problems persist and the infections show up on repeated scans.

My computer is sluggish and certain programs (Paint Shop Pro, audio editing software, Real Player) act as if I've only just installed them, asking me – each time I open them – to register and associate file extensions.

Any help would be greatly appreciated.

Here is my Hijack This log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:06:12 PM, on 2/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\SYSTEM\atiptaxx.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Road Runner\Medic\RRMedic.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ATIPTA] C:\WINDOWS\SYSTEM\atiptaxx.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [U.S. Robotics Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Medic.lnk = C:\Program Files\Road Runner\Medic\RRMedic.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\PROGRAM FILES\ATI MULTIMEDIA\TV\EXPLBAR.DLL
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: RollingStone Radio - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://cs7.chat.sc5.yahoo.com/v43/yacscom.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093307014465
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123668607366
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} (TSCCInstall Class) - http://www.techsmith.com/codec/tsccinst.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C9BF44F-A941-4770-A9DE-E72E558E23A9}: NameServer = 192.168.0.1,4.2.2.2
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: U.S. Robotics Wireless LAN Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 12273 bytes
Hi boogie76, welcome to the forum.

Please be advised, as I'm still in training, all my replies will have to be approved by a teacher or expert before I can post them. This may cause some delays, but I will do my best to keep them as short as possible.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
I will post back soon with additional instructions.


Thanks
Hi Boogie76

Please go to Kaspersky website and perform an online antivirus scan.

Your antivirus program should be disabled during the online scan. This is usually done from it's system tray icon. Please remember to re-enable it after the scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Desktop is a good place.
  • Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply along with a new HijackThis log.
Thanks
OK, here is my Kaspersky Scanner log:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, February 24, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, February 24, 2009 16:30:35
Records in database: 1839529
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\

Scan statistics:
Files scanned: 149658
Threat name: 46
Infected objects: 209
Suspicious objects: 1
Duration of the scan: 06:39:16


File name / Threat name / Threats count
C:\WINDOWS\SYSTEM32\AST.exe Infected: Trojan-Downloader.Win32.VB.ah 1
C:\WINDOWS\gsi.exe Infected: not-a-virus:AdWare.Win32.HelpExpress 2
C:\Program Files\Microsoft AntiSpyware\Quarantine\1EDC722B-B21F-4452-9D80-865B1D\8D1D1603-DCFD-499D-BCF9-79545A Infected: Trojan-Downloader.Win32.VB.ah 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6C6418C1.exe Infected: Trojan-Downloader.Win32.Agent.ac 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6C6E16B6.exe Infected: not-a-virus:AdWare.Win32.DelphinMediaViewer.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6C853C9D.exe Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6C886699.exe Infected: not-a-virus:AdWare.Win32.DelphinMediaViewer.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6C92648F.exe Infected: not-a-virus:AdWare.Win32.DelphinMediaViewer.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6ABC5738.exe Infected: not-a-virus:AdWare.Win32.DelphinMediaViewer.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3757139E.zip Infected: Trojan.Java.ClassLoader.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3757139E.zip Infected: Exploit.Java.ByteVerify 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3757139E.zip Infected: Trojan.Java.ClassLoader.Dummy.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3757139E.zip Infected: Trojan-Downloader.Java.OpenConnection.v 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3757139E.cla Infected: Trojan.Java.ClassLoader.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5E556D7F.cla Infected: Trojan.Java.Femad 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\375A3D9A.cla Infected: Trojan.Java.ClassLoader.Dummy.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\375E6797.cla Infected: Exploit.Java.ByteVerify 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\69E5297E.cla Infected: Trojan.Java.Femad 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\015B5AAD.dll Infected: not-a-virus:AdWare.Win32.BiSpy.t 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79477D19.cab Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2F030316.cab Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\794A2715.cab Infected: Trojan-Downloader.Win32.Stubby.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\794A2715 Infected: Trojan.Win32.Agent.ay 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74CB6116 Infected: not-a-virus:AdWare.Win32.DelphinMediaViewer.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4BE42C9E Infected: not-a-virus:AdWare.Win32.DelphinMediaViewer.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\794A2715.exe Infected: not-a-virus:AdWare.Win32.FlashEnhancer.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\794A2715.exe Infected: not-a-virus:AdWare.Win32.Broadcap.b 3
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FE865CB.dll Infected: not-a-virus:AdWare.Win32.BlazeFind.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\794E5112.cab Infected: not-a-virus:AdWare.Win32.WebRebates.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\794E5112.cab Infected: not-a-virus:AdWare.Win32.WebRebates.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\794E5112.cab Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A933F15.cab Infected: not-a-virus:AdWare.Win32.WebRebates.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A933F15.cab Infected: not-a-virus:AdWare.Win32.WebRebates.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A933F15.cab Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\794E5112.exe Infected: not-a-virus:AdWare.Win32.WebRebates.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\794E5112.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\794E5112.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A933F15.exe Infected: not-a-virus:AdWare.Win32.WebRebates.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A933F15.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A933F15.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\742F3BF5.exe Infected: not-a-virus:AdWare.Win32.WebRebates.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\742F3BF5.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\742F3BF5.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\62991B36.exe Infected: not-a-virus:AdWare.Win32.WebRebates.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\62991B36.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\62991B36.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79517B0E.exe Infected: not-a-virus:AdWare.Win32.WebRebates.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79517B0E.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79517B0E.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\005B1D14.exe Infected: not-a-virus:AdWare.Win32.WebRebates.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\005B1D14.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\005B1D14.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79517B0E.cab Infected: not-a-virus:AdWare.Win32.BiSpy.t 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79517B0E.cab Infected: not-a-virus:AdWare.Win32.BiSpy.q 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\005B1D14.cab Infected: not-a-virus:AdWare.Win32.BiSpy.t 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\005B1D14.cab Infected: not-a-virus:AdWare.Win32.BiSpy.q 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7954250B.dll Infected: not-a-virus:AdWare.Win32.DelphinMediaViewer.f 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7954250B.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\46237B13.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\44C45AA2.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7AEA0457.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\396D3585.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00E56AC3.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\685E205B.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7EA946E1.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79574F07.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0BEC5913.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6D0E69F9.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\071378E8.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79ED1D81.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\43896595.zip Infected: Trojan.Java.ClassLoader.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\43896595.zip Infected: Exploit.Java.ByteVerify 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\43896595.zip Infected: Trojan.Java.ClassLoader.Dummy.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\43896595.zip Infected: Trojan-Downloader.Java.OpenConnection.v 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\438C0F91.cla Infected: Trojan.Java.ClassLoader.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4393638A.cla Infected: Trojan.Java.ClassLoader.Dummy.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3D1160A8.cla Infected: Exploit.Java.ByteVerify 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\78614392.cla Infected: Trojan.Java.ClassLoader.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\47A54EE9.cla Infected: Trojan.Java.ClassLoader.Dummy.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\71564952.cla Infected: Exploit.Java.ByteVerify 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31F97BCA.zip Infected: Exploit.Java.ByteVerify 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31F97BCA.zip Infected: Trojan.Java.ClassLoader.Dummy.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31F97BCA.zip Infected: Trojan-Downloader.Java.OpenStream.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77EA5B86.zip Infected: Trojan.Java.ClassLoader.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77EA5B86.zip Infected: Exploit.Java.ByteVerify 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77EA5B86.zip Infected: Trojan.Java.ClassLoader.Dummy.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77EA5B86.zip Infected: Trojan-Downloader.Java.OpenConnection.v 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3AAF096D.zip Infected: Trojan.Java.ClassLoader.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3AAF096D.zip Infected: Exploit.Java.ByteVerify 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3AAF096D.zip Infected: Trojan.Java.ClassLoader.Dummy.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3AAF096D.zip Infected: Trojan-Downloader.Java.OpenConnection.v 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31F97BCA.cla Infected: Trojan.Java.ClassLoader.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\32004FC3.cla Infected: Trojan.Java.ClassLoader.Dummy.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\320379BF.cla Infected: Exploit.Java.ByteVerify 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\78F7410F.zip Infected: Exploit.Java.ByteVerify 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\78F7410F.zip Infected: Trojan.Java.ClassLoader.Dummy.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\78F7410F.zip Infected: Trojan-Downloader.Java.OpenStream.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0ADF65D7.zip Infected: Trojan.Java.ClassLoader.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0ADF65D7.zip Infected: Exploit.Java.ByteVerify 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0ADF65D7.zip Infected: Trojan.Java.ClassLoader.Dummy.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0ADF65D7.zip Infected: Trojan-Downloader.Java.OpenConnection.v 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\33C72957.zip Infected: Exploit.Java.ByteVerify 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\33C72957.zip Infected: Trojan-Downloader.Java.OpenConnection.aa 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FFB61B6.exe Infected: Trojan-Downloader.Win32.Stubby.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6C706B36.cab Infected: Trojan-Downloader.Win32.Stubby.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\300235AF.exe Infected: Trojan-Downloader.Win32.Stubby.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7F4C29EC.cab Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\25913B44.cab Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2EB80B63.cab Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\123B2159.cab Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A80473D.cab Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7F5627E1.cab Infected: Trojan-Downloader.Win32.Stubby.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\64C81EEA.exe Infected: not-a-virus:AdWare.Win32.Broadcap.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4FD47415.exe Infected: not-a-virus:AdWare.Win32.Broadcap.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77B7318C.bak Infected: not-a-virus:AdWare.Win32.FlashTrack.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77BA5B88.cfg Infected: not-a-virus:AdWare.Win32.FlashTrack.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77BA5B88.exe Infected: not-a-virus:AdWare.Win32.Broadcap.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77BA5B88.dll Infected: not-a-virus:AdWare.Win32.FlashTrack.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00473B80.exe Infected: not-a-virus:AdWare.Win32.Broadcap.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\004D0F78.exe Infected: not-a-virus:AdWare.Win32.BlazeFind.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\004D0F78.dll Infected: not-a-virus:AdWare.Win32.BlazeFind.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00503975.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00546371.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00570D6E.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\005A376A.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\005D6166.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00610B63.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00675F5C.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\006B0958.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\006E3354.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0074074D.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0078314A.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\007B5B46.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4AFD1332.exe Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4C047A99.cab Infected: Trojan-Downloader.Win32.Agent.ae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0C3C09E5.php Infected: Exploit.HTML.Mht 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0B6C29E2.exe Infected: not-a-virus:AdWare.Win32.FlashTrack.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0B6C29E2.exe Infected: not-a-virus:AdWare.Win32.Broadcap.b 3
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0B737DDB.exe Infected: not-a-virus:AdWare.Win32.FlashTrack.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0B737DDB.exe Infected: not-a-virus:AdWare.Win32.Broadcap.b 3
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E6E5491.dll Infected: not-a-virus:AdWare.Win32.Altnet.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2B656EE1.dll Infected: not-a-virus:AdWare.Win32.Altnet.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\417553D6.dll Infected: not-a-virus:AdWare.Win32.Altnet.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E717E8D.dll Infected: not-a-virus:AdWare.Win32.Altnet.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\712D4CE0.dll Infected: not-a-virus:AdWare.Win32.Altnet.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\69BF632C.dll Infected: not-a-virus:AdWare.Win32.Altnet.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E717E8D.exe Infected: Trojan-Downloader.Win32.RVP.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E717E8D.exe Infected: Trojan.Win32.Small.an 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E74288A.exe Infected: Trojan-Downloader.Win32.Adroar 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\36F52ADF.exe Infected: Trojan-Downloader.Win32.Stubby.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\120A7283.exe Infected: Trojan-Downloader.Win32.Stubby.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\331E1F67.exe Infected: not-a-virus:AdWare.Win32.Comet.r 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\13AF0122.exe Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E785286.dll Infected: not-a-virus:AdWare.Win32.BiSpy.t 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7CBE08DF.dll Infected: not-a-virus:AdWare.Win32.BiSpy.t 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E922269.exe Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2AFF78D9.exe Infected: not-a-virus:AdWare.Win32.BetterInternet 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E9C205F.exe Infected: not-a-virus:AdWare.Win32.WebRebates.g 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E9C205F.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E9C205F.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E9F4A5B.exe Infected: not-a-virus:AdWare.Win32.WebRebates.g 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E9F4A5B.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E9F4A5B.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\422070D6.exe Infected: not-a-virus:AdWare.Win32.WebRebates.g 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\422070D6.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\422070D6.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1DD339EB.exe Infected: not-a-virus:AdWare.Win32.WebRebates.g 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1DD339EB.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1DD339EB.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\512C0AC0.exe Infected: not-a-virus:AdWare.Win32.WebRebates.g 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\512C0AC0.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\512C0AC0.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0EA27457.exe Infected: not-a-virus:AdWare.Win32.WebRebates.g 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0EA27457.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0EA27457.exe Infected: not-a-virus:AdWare.Win32.WebRebates.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\07E84ED6.exe Infected: Trojan-Downloader.Win32.Keenval 3
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\461E4941.exe Infected: not-a-virus:AdWare.Win32.HelpExpress 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6C616EC5.exe Infected: Trojan-Downloader.Win32.Adroar 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2E7F2390.cab Infected: not-a-virus:AdWare.Win32.Altnet.l 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2E7F2390.cab Infected: not-a-virus:AdWare.Win32.Altnet.b 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7F6C5614.cab Infected: not-a-virus:AdWare.Win32.BiSpy.m 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7F6C5614.cab Infected: not-a-virus:AdWare.Win32.BiSpy.q 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6E32339B.def Infected: not-a-virus:AdWare.Win32.180Solutions.am 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4B882FF7.def Infected: not-a-virus:AdWare.Win32.180Solutions.as 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1D6C59E9.exe Infected: not-a-virus:AdWare.Win32.Broadcap.a 2
C:\Documents and Settings\Donald Gibson\Application Data\Identities\{A2345120-E118-11D5-B81E-90AA38356F46}\Microsoft\Outlook Expr\Inbox.dbx Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Documents and Settings\Donald Gibson\Application Data\Identities\{A2345120-E118-11D5-B81E-90AA38356F46}\Microsoft\Outlook Expr\Inbox.dbx Infected: Email-Worm.Win32.NetSky.q 1
D:\programs\CWS.exe Infected: not-a-virus:AdWare.Win32.Gator.1050 1
G:\Writing\concert tickets, cheap, summer tour, bob dylan, live music.jpg Infected: Trojan-Downloader.JS.Psyme.alw 1

The selected area was scanned.



And here is my latest HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:49:35 PM, on 2/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\SYSTEM\atiptaxx.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Road Runner\Medic\RRMedic.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Microsoft Works\MSWorks.exe
C:\Program Files\Jasc Software Inc\Paint Shop Pro 7\psp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ATIPTA] C:\WINDOWS\SYSTEM\atiptaxx.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [U.S. Robotics Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Medic.lnk = C:\Program Files\Road Runner\Medic\RRMedic.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\PROGRAM FILES\ATI MULTIMEDIA\TV\EXPLBAR.DLL
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: RollingStone Radio - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://cs7.chat.sc5.yahoo.com/v43/yacscom.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093307014465
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123668607366
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} (TSCCInstall Class) - http://www.techsmith.com/codec/tsccinst.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C9BF44F-A941-4770-A9DE-E72E558E23A9}: NameServer = 192.168.0.1,4.2.2.2
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: U.S. Robotics Wireless LAN Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 12707 bytes
Hi boogie76,

There are 2 infected emails in your Outlook Express Inbox. These will have to be deleted from within Outlook Express. I can't tell you which one they are. Please clean out all unnecessary items from the Inbox in all accounts and empty the Deleted Items folders.


Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE
    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    G:\Writing\concert tickets, cheap, summer tour, bob dylan, live music.jpg
    D:\programs\CWS.exe
    C:\WINDOWS\SYSTEM32\AST.exe 
    C:\WINDOWS\gsi.exe
    
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Next, Download OTListIt2 to your desktop.
  • Double click on OTList2.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Next, Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.
Please include in your next reply, the OTMoveIt3 log, the OTListIt logs and the Rooter log.

No need for a Hijackthis log this time.
I deleted all the emails in my Outlook inbox, which was essentially filled with spam as I don't use the program for anything (I use Hotmail for my email account). Given that I don't use Outlook Express, is there a way to prevent any/all emails from going to my Outlook inbox? Can I delete Outlook Express and have it not create problems with my Microsoft OS?

________________________________________________________________________________
______________________________________________

Here is my OTMovieIt3 log:

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
G:\Writing\concert tickets, cheap, summer tour, bob dylan, live music.jpg moved successfully.
D:\programs\CWS.exe moved successfully.
C:\WINDOWS\SYSTEM32\AST.exe moved successfully.
C:\WINDOWS\gsi.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\DONALD~1\LOCALS~1\Temp\Perflib_Perfdata_5d0.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\DONALD~1\LOCALS~1\Temp\~DF8FD9.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\DONALD~1\LOCALS~1\Temp\~DF90B6.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\DONALD~1\LOCALS~1\Temp\etilqs_OmdXIzI5jeTSBbdre7P4 scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FLQ9THKL\controlCARHQSU5.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6ad0.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\XUL.mfl scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02252009_151945

Files moved on Reboot…
File C:\DOCUME~1\DONALD~1\LOCALS~1\Temp\Perflib_Perfdata_5d0.dat not found!
File C:\DOCUME~1\DONALD~1\LOCALS~1\Temp\~DF8FD9.tmp not found!
File C:\DOCUME~1\DONALD~1\LOCALS~1\Temp\~DF90B6.tmp not found!
File C:\DOCUME~1\DONALD~1\LOCALS~1\Temp\etilqs_OmdXIzI5jeTSBbdre7P4 not found!
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FLQ9THKL\controlCARHQSU5.htm moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_6ad0.dat moved successfully.
C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\XUL.mfl moved successfully.
C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\Mozilla\Firefox\Profiles\o84yixy9.default\urlclassifier3.sqlite moved successfully.


Here is my OTListIt2 log:

OTListIt logfile created on: 2/25/2009 3:42:45 PM - Run
OTListIt2 by OldTimer - Version 2.0.2.0 Folder = C:\Documents and Settings\Donald Gibson\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: enu | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 66.53% Memory free
2.11 Gb Paging File | 1.55 Gb Available in Paging File | 73.45% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 2.28 Gb Free Space | 6.12% Space Free | Partition Type: FAT32
Drive D: | 19.10 Gb Total Space | 8.44 Gb Free Space | 44.18% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Unable to calculate disk information.
Drive G: | 152.66 Gb Total Space | 0.85 Gb Free Space | 0.56% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: K9V7L1
Current User Name: Donald Gibson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe ()
PRC - C:\WINDOWS\System32\WLTRYSVC.EXE ()
PRC - C:\WINDOWS\System32\bcmwltry.exe (U.S. Robotics Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
PRC - C:\WINDOWS\Mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
PRC - C:\WINDOWS\SYSTEM\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\WLTRAY.exe (U.S. Robotics Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
PRC - C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
PRC - C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools)
PRC - C:\Program Files\ThreatFire\TFService.exe (PC Tools)
PRC - C:\Program Files\Road Runner\Medic\RRMedic.exe ()
PRC - C:\Program Files\Webshots\Webshots.scr (Webshots.com)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\BroadJump\CorrectConnect Engine\CCD.exe ()
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Donald Gibson\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\System32\Ati2evxx.exe ()
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\SYSTEM32\ati2sgag.exe ()
SRV - (CCALib8 [Auto | Running]) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CLTNetCnService [Auto | Stopped]) – File not found
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PACSPTISVR [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (sdAuxService [Auto | Running]) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (sdCoreService [Auto | Running]) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (SPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (Symantec Core LC [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (ThreatFire [Auto | Running]) – C:\Program Files\ThreatFire\TFService.exe (PC Tools)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Stopped]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (wltrysvc [Auto | Running]) – C:\WINDOWS\System32\WLTRYSVC.EXE ()
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (61883 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\61883.sys (Microsoft Corporation)
DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (ALIEHCD [Auto | Stopped]) – C:\WINDOWS\System32\Drivers\ALIEHCI.sys (ALi Corporation)
DRV - (AliIde [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (aliroothub [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\AliRtHub.sys (ALi Corporation)
DRV - (AN983 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\AN983.sys (ADMtek Incorporated.)
DRV - (aslm75 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\aslm75.sys ()
DRV - (Aspi32 [Auto | Running]) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Avc [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\avc.sys (Microsoft Corporation)
DRV - (BANTExt [System | Running]) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (BCM43XX [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (Cdr4_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cdrbsdrv [System | Running]) – C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (cmpci [On_Demand | Running]) – C:\WINDOWS\system32\drivers\cmaudio.sys (C-Media Inc)
DRV - (ctac32k [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctljystk [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (ctprxy2k [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (emu10k [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (emu10k1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emupia [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (epstw2k [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\epstw2k.sys (Microsoft Corporation)
DRV - (FWAuth [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\FWAuthDriver.sys (PC Tools)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ha10kx2k [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (IKFileSec [Boot | Stopped]) – C:\WINDOWS\system32\drivers\ikfilesec.sys (PCTools Research Pty Ltd.)
DRV - (IKSysFlt [System | Running]) – C:\WINDOWS\system32\drivers\iksysflt.sys (PCTools Research Pty Ltd.)
DRV - (IKSysSec [System | Running]) – C:\WINDOWS\system32\drivers\iksyssec.sys (PCTools Research Pty Ltd.)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MCSTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (MSDV [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\msdv.sys (Microsoft Corporation)
DRV - (MxlW2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (ossrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PCASp50 [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (pctfw2 [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\pctfw2.sys (PC Tools)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (PfModNT [Auto | Running]) – C:\WINDOWS\System32\PfModNT.sys (Creative Technology Ltd.)
DRV - (Point32 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\point32.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (SbcpHid [Auto | Running]) – C:\WINDOWS\system32\Drivers\SbcpHid.sys ()
DRV - (scsiscan [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\scsiscan.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SFilter [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\pctfw.sys (PC Tools)
DRV - (sfman [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (Stltrk2k [Auto | Running]) – C:\WINDOWS\System32\drivers\Stltrk2k.sys (SCM Microsystems Inc.)
DRV - (TfFsMon [Boot | Running]) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon [On_Demand | Running]) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfSysMon [Boot | Running]) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (USBCM [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Sacm2A.sys ( )

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = http://www.microsoft.com/isapi/redir.dll?P…mp;Ar=ie5update
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - presf.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://by106fd.bay106.hotmail.msn.com/cgi-bin/hmhome?fti=yes&curmbox;=00000000%2d0000%2d0000%2d0000%2d000000000001&a;=347567ae1de0cb81dfaf16aa7298ca0e"
FF - prefs.js..extensions.enabledItems: {cb84136f-9c44-433a-9048-c5cd9df1dc16}:1.0.34
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed] -> %ProgramFiles%\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2009/02/24 12:14:38 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2005/01/21 15:31:32 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2005/01/21 15:31:30 00,000,000 | —D | M]
FF - C:\Documents and Settings\Donald Gibson\Application Data\mozilla\Extensions [2008/07/16 00:27:30 00,000,000 | —D | M]
FF - C:\Documents and Settings\Donald Gibson\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/07/16 00:27:30 00,000,000 | —D | M]
FF - C:\Documents and Settings\Donald Gibson\Application Data\mozilla\Firefox\Profiles\o84yixy9.default\extensions [2005/01/21 15:32:00 00,000,000 | —D | M]
FF - C:\Documents and Settings\Donald Gibson\Application Data\mozilla\Firefox\Profiles\o84yixy9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/01/09 01:56:54 00,000,000 | —D | M]
FF - C:\Documents and Settings\Donald Gibson\Application Data\mozilla\Firefox\Profiles\o84yixy9.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696} [2008/08/20 16:06:14 00,000,000 | —D | M]
FF - C:\Documents and Settings\Donald Gibson\Application Data\mozilla\Firefox\Profiles\o84yixy9.default\extensions\{cb84136f-9c44-433a-9048-c5cd9df1dc16} [2008/12/01 22:19:10 00,000,000 | —D | M]
FF - C:\Documents and Settings\Donald Gibson\Application Data\mozilla\Firefox\Profiles\o84yixy9.default\extensions\[removed] [2009/02/08 19:09:18 00,000,000 | —D | M]
FF - C:\Documents and Settings\Donald Gibson\Application Data\mozilla\Firefox\Profiles\o84yixy9.default\extensions\TEMP [2005/09/11 21:57:34 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions [2005/01/21 15:32:42 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2005/01/21 15:32:42 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [2007/06/04 03:23:00 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [2008/06/19 06:04:04 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [2008/10/02 05:15:54 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2009/02/24 12:15:14 00,000,000 | —D | M]

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s (PC Tools)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [ATIPTA] C:\WINDOWS\SYSTEM\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [C-Media Mixer] Mixer.exe /startup (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe (America Online, Inc.)
O4 - HKLM..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe" (PC Tools)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" ()
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r (VERITAS Software, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
O4 - HKLM..\Run: [U.S. Robotics Wireless Manager UI] C:\WINDOWS\system32\WLTRAY (U.S. Robotics Corporation)
O4 - HKLM..\Run: [WINDVDPatch] CTHELPER.EXE (Creative Technology Ltd)
O4 - HKCU..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe" (ATI Technologies Inc.)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Medic.lnk = C:\Program Files\Road Runner\Medic\RRMedic.exe ()
O4 - Startup: C:\Documents and Settings\Donald Gibson\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\Launcher.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O8 - Extra context menu item: &Windows; Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\PROGRAM FILES\ATI MULTIMEDIA\TV\EXPLBAR.DLL (ATI Technologies Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: RollingStone Radio - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKLM\..Trusted Domains: 5 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O16 - DPF: {00000032-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msnaudio.CAB (Reg Error: Key error.)
O16 - DPF: {00000075-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxacm.CAB (Reg Error: Key error.)
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} http://download.microsoft.com/download/0/5…b?1093307516960 (MSSecurityAdvisor Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://cs7.chat.sc5.yahoo.com/v43/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {31564D57-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmvax.cab (Reg Error: Key error.)
O16 - DPF: {32564D57-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv8ax.cab (Reg Error: Key error.)
O16 - DPF: {32564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv8dmo.cab (Reg Error: Key error.)
O16 - DPF: {3334504D-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/mpeg4ax.cab (Reg Error: Key error.)
O16 - DPF: {33363249-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/i263_32.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} http://www.webshots.com/samplers/WSDownloader.ocx (WSDownloader Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.com/v5co…b?1093307014465 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1123668607366 (MUWebControl Class)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab (HouseCall Control)
O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} http://www.techsmith.com/codec/tsccinst.cab (TSCCInstall Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…7598.7634143519 (Reg Error: Key error.)
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} http://community.webshots.com/html/WSPhotoUploader.CAB (Webshots Photo Uploader)
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_01)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} http://windowsupdate.microsoft.com/R1024/V…en/actsetup.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Internet Explorer Classes for Java file://C:\WINDOWS\SYSTEM\iejava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{4C9BF44F-A941-4770-A9DE-E72E558E23A9}\\NameServer = 192.168.0.1,4.2.2.2
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\ole db\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\ole db\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\ole db\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ FAT32 ]
O32 - Autorun File - C:\AUTOEXEC.001 () - [ FAT32 ]
O32 - Autorun File - D:\AUTOEXEC.BAT () - [ FAT32 ]

========== Files/Folders - Created Within 30 Days ==========

[2066/11/26 14:12:24 | 00,079,947 | —- | C] () – C:\WINDOWS\fw20.vxd
[2009/02/25 15:38:23 | 00,497,152 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Donald Gibson\Desktop\OTListIt2.exe
[2009/02/25 15:19:45 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/02/25 15:18:45 | 00,348,160 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Donald Gibson\Desktop\OTMoveIt3.exe
[2009/02/16 22:58:22 | 00,025,088 | —- | C] () – C:\Documents and Settings\Donald Gibson\My Documents\25ThingsAboutme.doc
[2009/02/15 21:20:06 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/02/15 20:55:08 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/02/15 20:54:49 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/02/15 20:47:52 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/02/15 20:47:45 | 00,000,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/02/15 20:47:16 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/02/15 20:47:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/02/14 01:12:17 | 00,000,000 | —D | C] – C:\Program Files\GIMP-2.0
[2009/02/12 00:36:05 | 00,049,086 | —- | C] () – C:\Documents and Settings\Donald Gibson\My Documents\cc_20090212_003602.reg
[2009/02/11 17:02:03 | 00,186,439 | —- | C] () – C:\Documents and Settings\Donald Gibson\My Documents\Radio_City2bb.jpg
[2009/02/08 19:09:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Donald Gibson\Application Data\Move Networks
[2009/02/05 23:33:28 | 00,002,572 | —- | C] () – C:\Documents and Settings\Donald Gibson\My Documents\notebook.rtf
[2009/02/03 03:26:42 | 00,000,000 | —D | C] – C:\Documents and Settings\Donald Gibson\Application Data\Jasc
[2009/02/02 03:03:27 | 00,005,459 | —- | C] () – C:\Documents and Settings\Donald Gibson\My Documents\25_things.rtf
[2009/01/29 13:27:22 | 00,000,627 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PrinterShare Console.lnk
[2009/01/29 13:27:19 | 00,000,000 | —D | C] – C:\Program Files\PrinterShare

========== Files - Modified Within 30 Days ==========

[2009/02/25 15:38:26 | 00,497,152 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Donald Gibson\Desktop\OTListIt2.exe
[2009/02/25 15:33:06 | 00,000,256 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2009/02/25 15:32:46 | 00,487,426 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/25 15:32:46 | 00,411,702 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/25 15:32:46 | 00,067,584 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/25 15:30:32 | 00,013,366 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/25 15:28:36 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/25 15:28:18 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/25 15:28:12 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/25 15:28:06 | 16,101,29408 | -HS- | M] () – C:\hiberfil.sys
[2009/02/25 15:18:48 | 00,348,160 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Donald Gibson\Desktop\OTMoveIt3.exe
[2009/02/25 03:26:30 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/02/25 01:49:30 | 00,191,488 | —- | M] () – C:\Documents and Settings\Donald Gibson\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/24 08:19:26 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/02/24 05:26:34 | 00,038,208 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\TfSysMon.sys
[2009/02/24 05:26:32 | 00,033,088 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\TfNetMon.sys
[2009/02/24 05:26:30 | 00,051,520 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\TfFsMon.sys
[2009/02/24 05:26:30 | 00,012,608 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\TfKbMon.sys
[2009/02/23 20:54:20 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/02/16 22:58:24 | 00,025,088 | —- | M] () – C:\Documents and Settings\Donald Gibson\My Documents\25ThingsAboutme.doc
[2009/02/15 20:54:38 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/02/15 20:54:24 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/02/15 20:47:46 | 00,000,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/02/15 14:49:42 | 00,005,459 | —- | M] () – C:\Documents and Settings\Donald Gibson\My Documents\25_things.rtf
[2009/02/15 12:41:20 | 00,019,456 | —- | M] () – C:\Documents and Settings\Donald Gibson\Desktop\New Microsoft Word Document.doc
[2009/02/12 22:30:52 | 00,013,381 | —- | M] () – C:\Documents and Settings\Donald Gibson\My Documents\pspbrwse.jbf
[2009/02/12 00:36:16 | 00,049,086 | —- | M] () – C:\Documents and Settings\Donald Gibson\My Documents\cc_20090212_003602.reg
[2009/02/11 17:02:04 | 00,186,439 | —- | M] () – C:\Documents and Settings\Donald Gibson\My Documents\Radio_City2bb.jpg
[2009/02/11 14:25:02 | 00,002,666 | —- | M] () – C:\Documents and Settings\Donald Gibson\Desktop\Microsoft Works Calendar.lnk
[2009/02/06 00:23:52 | 00,002,572 | —- | M] () – C:\Documents and Settings\Donald Gibson\My Documents\notebook.rtf
[2009/02/05 15:05:04 | 00,007,257 | —- | M] () – C:\Documents and Settings\Donald Gibson\My Documents\long_survey.rtf
[2009/02/03 05:09:54 | 00,000,586 | —- | M] () – C:\Documents and Settings\Donald Gibson\Start Menu\Programs\Startup\Webshots.lnk
[2009/01/29 13:27:24 | 00,000,627 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PrinterShare Console.lnk

========== LOP Check ==========

[2003/02/08 19:05:04 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/02/15 20:47:54 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2003/07/22 18:40:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/05/11 00:47:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2006/05/11 00:42:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2007/12/12 13:31:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2003/11/02 19:08:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2003/02/08 19:13:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI MMC
[2008/08/10 03:43:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2003/12/15 21:59:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/08/31 03:23:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/02/15 20:47:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2007/08/02 22:01:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/12/07 11:09:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2003/02/08 19:04:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/03/26 15:47:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2005/05/31 03:03:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2007/02/13 20:32:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/10/02 03:54:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2005/12/27 21:00:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2003/11/02 19:08:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/10/29 23:07:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2004/10/22 02:28:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony Corporation
[2004/06/15 02:13:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2003/12/16 20:32:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2003/12/16 20:32:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2003/02/16 02:06:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2004/11/10 00:01:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2007/08/02 20:50:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/08/14 00:56:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2004/02/13 14:54:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/08/08 20:20:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2006/11/19 18:28:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2008/06/20 20:33:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2005/12/26 20:07:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2005/09/12 08:54:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2008/12/27 09:12:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2003/02/08 19:05:04 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Donald Gibson\Application Data
[2006/05/11 00:52:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\acccore
[2003/07/22 18:45:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Adobe
[2003/07/22 18:45:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\AdobeUM
[2007/11/01 04:16:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Amazon
[2003/11/02 19:30:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Apple Computer
[2003/12/16 20:54:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Arcsoft
[2008/08/10 03:43:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Azureus
[2007/08/30 01:22:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Canon
[2003/02/13 16:30:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Corel
[2004/01/10 02:51:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\CyberLink
[2005/11/02 19:00:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Digital Album Organizer
[2006/12/14 21:59:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\DivX
[2004/06/04 03:44:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\dvdcss
[2007/07/18 21:31:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Forte
[2008/08/22 00:41:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\FrostWire
[2005/11/25 20:21:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\FUJIFILM
[2007/01/07 19:02:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Google
[2003/04/25 22:07:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Help
[2003/02/08 19:13:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Identities
[2009/02/03 03:26:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Jasc
[2004/06/04 03:43:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Kontiki
[2003/12/15 22:07:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Leadertech
[2004/05/06 03:51:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Lycos
[2003/07/23 21:25:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Macromedia
[2008/12/07 11:10:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Malwarebytes
[2003/02/08 19:04:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Microsoft
[2003/02/08 19:13:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Microsoft Web Folders
[2009/02/08 19:09:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Move Networks
[2008/07/29 01:37:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Moyea
[2005/01/21 15:31:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Mozilla
[2005/05/31 03:03:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\MSN6
[2004/06/13 21:27:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\MSNInstaller
[2007/01/29 22:43:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\MySpace
[2004/04/28 23:13:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\NetMedia Providers
[2005/07/18 13:34:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\OurPictures
[2008/10/02 03:54:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\PC Tools
[2008/12/01 22:45:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\PCToolsFirewallPlus
[2004/04/28 22:19:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Publish Providers
[2003/02/08 19:13:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Real
[2004/11/06 19:03:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Roxio
[2003/03/02 20:23:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Roxio.old
[2004/04/08 23:23:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\roxio1.old
[2004/09/13 18:32:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Roxio2.old
[2004/04/28 23:13:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\SBF
[2003/12/16 20:32:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\ScanSoft
[2004/08/05 20:42:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Secretmaker
[2004/04/28 22:18:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Sony
[2004/10/22 02:32:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Sony Corporation
[2005/02/11 18:04:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Sun
[2004/11/10 00:02:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Symantec
[2007/08/02 20:29:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Uniblue
[2003/12/15 21:49:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\VERITAS
[2007/11/25 21:19:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Viewpoint
[2007/07/04 18:32:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Webshots
[2009/01/19 22:44:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\WinRAR
[2007/01/08 04:20:58 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Donald Gibson\Application Data\yahoo!
[2003/08/16 02:24:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Donald Gibson\Application Data\Yahoo! Messenger
[2001/12/21 20:16:46 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/25 15:28:18 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/02/25 15:33:06 | 00,000,256 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2008/07/23 02:15:46 | 00,000,316 | -H– | M] () – C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IType_exe.job
[2008/07/23 02:15:46 | 00,000,306 | -H– | M] () – C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
[2009/02/24 08:19:26 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/02/23 20:54:20 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========

< End of report >
Here is my Extras log:


OTListIt Extras logfile created on: 2/25/2009 3:42:45 PM - Run
OTListIt2 by OldTimer - Version 2.0.2.0 Folder = C:\Documents and Settings\Donald Gibson\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: enu | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 66.53% Memory free
2.11 Gb Paging File | 1.55 Gb Available in Paging File | 73.45% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 2.28 Gb Free Space | 6.12% Space Free | Partition Type: FAT32
Drive D: | 19.10 Gb Total Space | 8.44 Gb Free Space | 44.18% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Unable to calculate disk information.
Drive G: | 152.66 Gb Total Space | 0.85 Gb Free Space | 0.56% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: K9V7L1
Current User Name: Donald Gibson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server (Yahoo! Inc.)
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (America Online, Inc.)
C:\Program Files\Common Files\AOL\1147322816\ee\aolsoftware.exe:*:Enabled:AOL Services (America Online, Inc.)
C:\Program Files\Common Files\AOL\1147322816\ee\aim6.exe:*:Enabled:AIM (America Online, Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM ()
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\burst\core-new1.1.3\btdownloadheadless.exe:*:Enabled:burst! download engine ()
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)
C:\Program Files\PrinterShare\paConsole.exe:*:Enabled:PrinterAnywhere Console (PrinterAnywhere)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00170409-78E1-11D2-B60F-006097C998E7}" = Microsoft Word 2000 SR-1
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{06E73C0B-7DE7-4F41-860B-587033B75BD9}" = iPod Updater 2004-11-15
"{07295ABF-1245-415A-BE06-863271753443}" = ShowBiz
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = VERITAS RecordNow DX Update Manager
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0DB93918-2A77-11D3-805A-00C04FA329AA}" = Word in Works Suite add-in
"{0E4BC542-9CFD-4E97-B586-9F1E5516E7B9}" = Microsoft IntelliPoint 6.1
"{15D6D50A-DF65-11D6-B49C-0020183A6529}" = green label Greetings Cards
"{1632F7CB-FB7D-402E-BC20-CAA1CC01EEDA}" = Tiff Viewer
"{181EAEE6-AAE5-485B-8BAC-0FB564626781}" = Brava! Reader 2.5
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{3222543C-A4AB-4A5A-B777-64687182C1B2}" = FMV V5.93
"{3248F0A8-6813-11D6-A77B-00B0D0150010}" = J2SE Runtime Environment 5.0 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{399C08C4-4E92-4A3B-B7E9-3ED8BC4BA8E5}" = PrinterShare
"{3E2D9049-CB69-11D2-94EC-00A0C90683DA}" = VBA (2720)
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = HydraVision
"{3FCAADB8-EB1B-11D6-AB2D-0090271A23A2}" = Sound Blaster Live!
"{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"{44734179-8A79-4DEE-BB08-73037F065543}" = Apple Mobile Device Support
"{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{56364334-9530-11D2-BFFC-00C04FA329AA}" = Microsoft Works 2000
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = MyDVD
"{6249C22D-E6A8-407B-BA8B-40298848ED94}" = OmniPage SE
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6882B3A9-AB98-4ABA-A623-2979FBEA5F9F}_is1" = Moyea FLV Player version 1.5.2.7
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E26544D-9092-4A37-983E-8B5C70E1DBA9}" = U.S. Robotics iBand
"{6F1974D6-4249-43B6-88B0-9A9B8A33956C}" = OpenMG Secure Module 4.0.00
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{71D6CE84-B7DC-4166-8E0D-56C1C37BFB5A}" = SonicStage 2.2.00
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{77F97940-6D4B-11D4-AA4A-00C0580802FD}" = USB SmartMedia Reader
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{80FD852F-5AAC-4129-B931-06AAFFA43138}" = iTunes
"{8855FF30-19CE-4CB1-A654-87B38369CCE1}" = VERITAS RecordNow DX
"{8A62A068-3FD6-495A-9F66-26FE94F32EC9}" = Rhapsody Player Engine
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8E1DCD15-C9F1-49CE-807B-198C8241EB6B}" = ALi USB2.0 Driver
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PUBLISHERR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PUBLISHERR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PUBLISHERR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PUBLISHERR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PUBLISHERR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PUBLISHERR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90840409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel Viewer 2003
"{91120000-0019-0000-0000-0000000FF1CE}" = Microsoft Office Publisher 2007
"{91120000-0019-0000-0000-0000000FF1CE}_PUBLISHERR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{99D34763-7E45-4FE5-8424-28DBC3A5F0BF}" = GUIDE PLUS+™ for Windows® System - ATI
"{9DA00558-6566-484C-87BC-1650BCF60446}" = ATI DVD Decoder
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}" = Windows Live Sign-in Assistant
"{B093990A-AAF2-44AC-9216-14BB7A2189B6}" = ImageMixer VCD2 LE for FinePix
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource
"{B6ACFF51-248A-4290-B50B-E50C81F25B97}" = iPod for Windows 2005-02-22
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon Camera WIA Driver
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{C73A3AB4-99A4-45E5-B77F-09A3065E0D6A}" = Microsoft IntelliType Pro 6.1
"{C8C45573-C729-46D9-AAF5-3A09E0277B3D}" = Raptor Audio 1.6
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D5A145FC-D00C-4F1A-9119-EB4D9D659750}" = Windows Live Toolbar
"{D680C913-5955-469D-9D88-C1940F7506D6}" = RAW FILE CONVERTER LE
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"{DAF8B012-D559-4B8D-95C0-D98E1172E5C3}" = My Wal-Mart Digital Photo Center
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E957696E-6D13-4B92-AF02-2073D7D522B4}" = ATI Multimedia Center [removed]
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F9D3B5A4-F292-4EF8-BAB5-B1C4FD62736D}" = Access Password Retrieval Lite
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AdobeESD" = Adobe Download Manager 1.2 (Remove Only)
"All ATI Software" = ATI - Software Uninstall Utility
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AnswerWorks" = AnswerWorks Runtime
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"ASUS Probe V2.12.09" = ASUS Probe V2.12.09
"ATI Display Driver" = ATI Display Driver
"Audacity_is1" = Audacity 1.2.2
"audcle" = Plus! MP3 Audio Converter LE
"AudioHQ" = Creative AudioHQ
"Belarc Advisor 2.0" = Belarc Advisor 7.2
"BroadJump Client Foundation" = BroadJump Client Foundation
"BroadJump CorrectConnect Engine" = BroadJump CorrectConnect Engine
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"CCleaner" = CCleaner (remove only)
"CDex" = CDex extraction audio
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative Restore Defaults" = Creative Restore Defaults
"Creative Surround Mixer 2" = Creative Surround Mixer
"CSCLIB" = Canon Camera Support Core Library
"dBpowerAMP Mp4 & AAC Decode Codec" = dBpowerAMP Mp4 & AAC Decode Codec
"dBpowerAMP Music Converter" = dBpowerAMP Music Converter
"dBpowerAMP Shorten Codec" = dBpowerAMP Shorten Codec
"dBpowerAMP WMA V9 Codec" = dBpowerAMP WMA V9 Codec
"Defraggler" = Defraggler (remove only)
"DFX for Windows Media Player" = DFX for Windows Media Player
"Diagnostics2" = Creative Diagnostics
"Direct WAV MP3 Splitter_is1" = Direct WAV MP3 Splitter 2.4
"DivX Content Uploader" = DivX Content Uploader
"DPP" = Canon Utilities Digital Photo Professional 3.4
"drmtool.inf" = Personal License Update Wizard for Windows Media Player
"EOS Utility" = Canon Utilities EOS Utility
"Forte Agent" = Forté Agent
"HijackThis" = HijackThis 2.0.2
"HP DeskJet 895C Series" = HP DeskJet 895C Series (Remove only)
"HP Scanning Software" = HP PrecisionScan and Utilities
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{06E73C0B-7DE7-4F41-860B-587033B75BD9}" = iPod Updater 2004-11-15
"InstallShield_{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"InstallShield_{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"InstallShield_{6F1974D6-4249-43B6-88B0-9A9B8A33956C}" = OpenMG Secure Module 4.0.00
"InstallShield_{9DA00558-6566-484C-87BC-1650BCF60446}" = ATI DVD Decoder
"InstallShield_{B6ACFF51-248A-4290-B50B-E50C81F25B97}" = iPod for Windows 2005-02-22
"InstallShield_{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon EOS 5D WIA Driver
"InstallShield_{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"InterActual Player" = InterActual Player
"IPIX ActiveX Viewer" = iPIX ActiveX Viewer
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Medic" = Medic
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"mmmusic" = Movie Maker Background Music Files
"mmsounds" = Movie Maker Sound Effects
"mmtitle" = Movie Maker Title Images
"Morpheus 1.9" = Morpheus 1.9
"Mozilla Firefox (3.0.6)" = Mozilla Firefox (3.0.6)
"mplibwiz.inf" = Media Library Management Wizard
"mpxlswiz.inf" = Windows Media Player Playlist Import to Excel Wizard
"mpxptray.inf" = Windows Media Player Tray Control
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyCamera" = Canon Utilities MyCamera
"MySpaceIM" = MySpaceIM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OpenMG HotFix4.0-04-06-21-01" = OpenMG Limited Patch 4.0-04-08-02-01
"Original Data Security Tools" = Canon Utilities Original Data Security Tools
"PC Tools Firewall Plus" = PC Tools Firewall Plus 4.0
"PCFriendly" = PCFriendly
"PCI Audio Driver" = PCI Audio Driver
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"Plaxo" = Plaxo Toolbar for Windows
"Play MPE Player" = Play MPE Player
"PUBLISHERR" = Microsoft Office Publisher 2007 Trial
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer
"Registry Mechanic_is1" = Registry Mechanic 6.0
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Riva FLV Player_is1" = Riva FLV Player
"Rock and Roll JEOPARDY!" = Rock and Roll JEOPARDY! (remove only)
"Shockwave" = Shockwave
"Shutterfly Plugin" = Shutterfly Plugin
"Spyware Doctor" = Spyware Doctor 6.0
"TradersLittleHelper_is1" = Trader's Little Helper 1.0.0 Beta 1
"U.S. Robotics Wireless MAXg Adapter" = U.S. Robotics Wireless MAXg Adapter
"wa2wmp" = Windows Media Player Skin Importer
"Webshots Desktop_is1" = Webshots Desktop
"Webshots Toolbar" = Webshots Toolbar
"WebSTAR DPC2100 Uninstall" = Scientific-Atlanta WebSTAR 2000 series Cable Modem
"WFTK" = Canon Utilities WFT-E1/E2/E3 Utility
"Windows" = Windows XP Uninstall
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows SR 2.0" = Windows SR 2.0
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMBK2" = Windows Media Bonus Pack for Windows XP
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2kSetup" = Microsoft Works 2000 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XviD_is1" = XviD MPEG-4 Video Codec
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Customizations" = Yahoo! extras
"Yahoo! Internet Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Toolbar" = Yahoo! Toolbar
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"burst" = burst! v3.1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/23/2009 4:39:42 PM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

Error - 2/23/2009 7:55:09 PM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

Error - 2/24/2009 3:18:30 AM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

Error - 2/24/2009 1:08:35 PM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

Error - 2/25/2009 2:32:02 AM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

Error - 2/25/2009 2:41:50 AM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module divxdec.ax, version 6.3.0.63, fault address 0x0005c2c0.

Error - 2/25/2009 2:44:52 AM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module divxdec.ax, version 6.3.0.63, fault address 0x0005c2c0.

Error - 2/25/2009 2:45:56 AM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module divxdec.ax, version 6.3.0.63, fault address 0x0005c2c0.

Error - 2/25/2009 12:12:35 PM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application psp.exe, version 7.0.0.0, faulting module psp.exe,
version 7.0.0.0, fault address 0x00257930.

Error - 2/25/2009 4:18:32 PM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

[ Application Events ]
Error - 2/23/2009 4:39:42 PM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

Error - 2/23/2009 7:55:09 PM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

Error - 2/24/2009 3:18:30 AM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

Error - 2/24/2009 1:08:35 PM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

Error - 2/25/2009 2:32:02 AM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

Error - 2/25/2009 2:41:50 AM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module divxdec.ax, version 6.3.0.63, fault address 0x0005c2c0.

Error - 2/25/2009 2:44:52 AM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module divxdec.ax, version 6.3.0.63, fault address 0x0005c2c0.

Error - 2/25/2009 2:45:56 AM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module divxdec.ax, version 6.3.0.63, fault address 0x0005c2c0.

Error - 2/25/2009 12:12:35 PM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application psp.exe, version 7.0.0.0, faulting module psp.exe,
version 7.0.0.0, fault address 0x00257930.

Error - 2/25/2009 4:18:32 PM | Computer Name = K9V7L1 | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 7.6.1.9, faulting module
itunes.exe, version 7.6.1.9, fault address 0x000f9d15.

[ System Events ]
Error - 2/25/2009 5:02:13 AM | Computer Name = K9V7L1 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 2/25/2009 5:04:05 AM | Computer Name = K9V7L1 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 2/25/2009 5:04:19 AM | Computer Name = K9V7L1 | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom1, has a bad block.

Error - 2/25/2009 5:04:53 AM | Computer Name = K9V7L1 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 2/25/2009 5:12:26 AM | Computer Name = K9V7L1 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 2/25/2009 4:28:18 PM | Computer Name = K9V7L1 | Source = NIC1394 | ID = 5002
Description = 1394 Net Adapter : Has determined that the adapter is not functioning
properly.

Error - 2/25/2009 4:28:44 PM | Computer Name = K9V7L1 | Source = Service Control Manager | ID = 7000
Description = The ALi PCI to USB Enhanced Host Controller service failed to start
due to the following error: %%1058

Error - 2/25/2009 4:29:23 PM | Computer Name = K9V7L1 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
IKFileSec

Error - 2/25/2009 4:35:27 PM | Computer Name = K9V7L1 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.2 for the Network Card with network
address 00C049F706F3 has been denied by the DHCP server 192.168.2.1 (The DHCP Server
sent a DHCPNACK message).

Error - 2/25/2009 4:36:45 PM | Computer Name = K9V7L1 | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{C99B0DE1-3084-498B-AB10-BB96F749DC1B}
because another computer on the network has the same name. The server could not
start.


< End of report >


And here is my Rooter log:


Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon™ Processor )
BIOS : Award Medallion BIOS v6.0
USER : Donald Gibson ( Administrator )
BOOT : Normal boot

Antivirus : Spyware Doctor with AntiVirus (Activated)


A:\ (USB)
C:\ (Local Disk) - FAT32 - Total:37 Go (Free:2 Go)
D:\ (Local Disk) - FAT32 - Total:19 Go (Free:8 Go)
E:\ (CD or DVD)
F:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
G:\ (Local Disk) - NTFS - Total:152 Go (Free:0 Go)

Wed 02/25/2009|15:47

———————-\\ Search..

No infections found !


1 - "C:\Rooter$\Rooter_1.txt" - Wed 02/25/2009|15:50

———————-\\ Scan completed at 15:50
Hi boogie76,

How's the computer? Please describe the symptoms you are having.

For Outlook Express, the easiest way is to remove the identity.
http://www.comcast.com/customers/faq/FaqDetails.ashx?Id=2669

note: if there is only one identity in Outlook Express, you will first need to create a new one, just don't configure it to recieve mail.
http://email.about.com/od/outlookexpresstips/qt/et082704.htm


You have several old vulnerable versions on your computer. You may want to copy and paste the instructions for this tool into a notepad and save to your desktop for reference as your browser should be closed.

Please download JavaRa to your desktop and unzip it to its own folder. Close your browser.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
The current version is Java™ 6 Update 12


Next we'll take care of the Norton remnants. Go to add/remove programs and uninstall, if present

Symantec KB-DocID:2003093015493306

Next, Download the Norton Removal Tool from HERE and save it to your desktop.

Next Double click on Norton_Removal_Tool.exe to run the tool.

Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.



Next,
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE
    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\Program Files\Common Files\Symantec Shared
    C:\Documents and Settings\Donald Gibson\Application Data\Symantec
    C:\WINDOWS\fw20.vxd
    
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back with OTMOVEIT3 log, MBAM log and a new HJT log.

Thanks
Yes, I apologize for the delay. I'm at a bit of a loss here, as my computer was working OK for several hours but it's reverted to the original problem (programs asking me to register, asking to associate file extensions as if it's the 1st time I've run them). I've gotten as far in your instructions as the Malwarebytes scan, but when I try to run quick scan, but it says "There were no items selected to scan. Please check the selections tab and make the proper adjustments." I don't know which tabs to select.
a side note: I don't quite understand why, if I have (official, paid for and registered) anti-virus software running in real-time on my PC, the biggest problems only are found after my computer is infected. Aren't these programs supposed to prevent such infections from doing damage in the first place?
Hi Boogie76,

Try this.

Open MBAM
  • put the dot beside Perform full scan
  • Click Scan
  • a window will come up, in that window, make sure all of your hard drives are selected
  • click Start Scan
Let us know if you can now do a scan.

Thanks
I was able to perform a full scan with Malwarebytes (it took over 40 hours) and I've included the log below.

My programs are still acting goofy, asking me to register (as if they're new products) and resetting all of my file extension preferences. Whatever you instructed me to do in the beginning stages of this endeavor seemed to fix those problems. I don't want to repeat any functions without your directive, though.

This is my Malwarebytes log:

Malwarebytes' Anti-Malware 1.33
Database version: 1654
Windows 5.1.2600 Service Pack 2

3/3/2009 6:32:32 PM
mbam-log-2009-03-03 (18-32-32).txt

Scan type: Full Scan (C:\|D:\|G:\|)
Objects scanned: 186258
Time elapsed: 38 hour(s), 29 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


And here is a current HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:48:23 PM, on 3/3/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\SYSTEM\atiptaxx.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Road Runner\Medic\RRMedic.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\QuickTime\QuickTimePlayer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ATIPTA] C:\WINDOWS\SYSTEM\atiptaxx.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [U.S. Robotics Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Medic.lnk = C:\Program Files\Road Runner\Medic\RRMedic.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\PROGRAM FILES\ATI MULTIMEDIA\TV\EXPLBAR.DLL
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: RollingStone Radio - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://cs7.chat.sc5.yahoo.com/v43/yacscom.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093307014465
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123668607366
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} (TSCCInstall Class) - http://www.techsmith.com/codec/tsccinst.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C9BF44F-A941-4770-A9DE-E72E558E23A9}: NameServer = 192.168.0.1,4.2.2.2
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: U.S. Robotics Wireless LAN Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 12436 bytes
Hi Boogie76,

Give this a shot.



Please download RBFA to your desktop
  • Double click the program to run it. It will only take a few seconds to run.
  • You will be prompted to press any key at the end to close it
  • Once it is finished, it will remove itself. If not, delete it yourself
Hi Boogie76,

Sorry, for some reason all the post isn't there. Here's what it should have been.


Give this a shot.



Please download RBFA to your desktop
  • Double click the program to run it. It will only take a few seconds to run.
  • You will be prompted to press any key at the end to close it
  • Once it is finished, it will remove itself. If not, delete it yourself

Does your computer/programs seem any better?

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI