This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Checkup for computer nothing bad known

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi matthewp

Clearly there were/still are items on your computer that were not showing up in the HJT log.

So we need to dig a little deeper into your system, make sure we find it all…..

FIRST


Please download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, (also found at %systemdrive%\Rooter.txt)
  • Please post that log into your next reply


NEXT
  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.



In your next response I would like
  • Rooter Log
  • OTListIt log

Please advise any other issues you may be having with your computer
here are all the logs Microsoft Windows XP Home Edition (5.1.2600) Service Pack 2 A:\ [Removable] (Total:0 Mo/Free:0 Mo) C:\ [Fixed] - NTFS - (Total:186475 Mo/Free:2075 Mo) D:\ [Fixed] - FAT32 - (Total:4288 Mo/Free:629 Mo) E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) G:\ [Removable] (Total:0 Mo/Free:0 Mo) H:\ [Removable] (Total:0 Mo/Free:0 Mo) I:\ [Removable] (Total:0 Mo/Free:0 Mo) J:\ [Removable] (Total:0 Mo/Free:0 Mo) K:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) Sat 03/07/2009|19:25 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\Explorer.EXE –Locked– vsmon.exe ———- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe ———- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe ———- C:\Program Files\Alwil Software\Avast4\ashServ.exe ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\nvsvc32.exe ———- C:\WINDOWS\system32\oodag.exe ———- C:\Program Files\CyberLink\Shared Files\RichVideo.exe ———- C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe ———- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\Program Files\Windows Media Player\WMPNetwk.exe ———- C:\WINDOWS\System32\alg.exe ———- C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe ———- C:\WINDOWS\StartupMonitor.exe –Locked– zlclient.exe ———- C:\WINDOWS\system32\ctfmon.exe ———- C:\Program Files\Java\jre6\bin\jqs.exe ———- C:\WINDOWS\system32\wuauclt.exe ———- C:\Program Files\Internet Explorer\iexplore.exe ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! ———————-\\ Cracks & Keygens.. C:\DOCUME~1\Owner\Application Data\Azureus\torrents\Crack_Nikon_Capture_NX.zip.3534675.TPB[1].torrent C:\DOCUME~1\Owner\Desktop\adobe-master-cs3-keygen\adobe-master-cs3-keygen.exe C:\DOCUME~1\Owner\Desktop\adobe-master-cs3-keygen\Torrent downloaded from Demonoid.com.txt C:\DOCUME~1\Owner\Desktop\iworkCrack\Torrent downloaded from Demonoid.com.txt C:\DOCUME~1\Owner\Desktop\WiFi crack without virtual machine\Torrent downloaded from Demonoid.com.txt C:\DOCUME~1\Owner\Desktop\WiFi crack without virtual machine\WiFi cracking files.zip C:\DOCUME~1\Owner\Desktop\WiFi crack without virtual machine\WiFi cracking files\wifi crck info.txt C:\DOCUME~1\Owner\Desktop\WiFi crack without virtual machine\WiFi cracking files\The Unarchiver.app\Contents\Resources\exe.icns C:\DOCUME~1\Owner\Desktop\WiFi crack without virtual machine\WiFi cracking files\The Unarchiver.app\Contents\Resources\rar.icns C:\DOCUME~1\Owner\Desktop\WiFi crack without virtual machine\WiFi cracking files\The Unarchiver.app\Contents\Resources\zip.icns C:\DOCUME~1\Owner\Desktop\WiFi crack without virtual machine\WiFi cracking files\__MACOSX\The Unarchiver.app\Contents\Resources\._exe.icns C:\DOCUME~1\Owner\Desktop\WiFi crack without virtual machine\WiFi cracking files\__MACOSX\The Unarchiver.app\Contents\Resources\._rar.icns C:\DOCUME~1\Owner\Desktop\WiFi crack without virtual machine\WiFi cracking files\__MACOSX\The Unarchiver.app\Contents\Resources\._zip.icns C:\DOCUME~1\Owner\My Documents\azerus stuff\-=mininova[1].org=- Alcohol.120.v1.9.5.3823.Retail.FULLY.Cracked.READ.NFO-BLiZZARD_TeamExtream.rar.torrent C:\DOCUME~1\Owner\My Documents\azerus stuff\Nero7 Premium Orginal Keygen[1].rar +[mininova.org]+.torrent C:\DOCUME~1\Owner\My Documents\azerus stuff\O&O[1].Defrag.Professional.Edition.v8.0.1398.Incl.Keygen.rar [mininova.org].torrent C:\DOCUME~1\Owner\My Documents\Computer programs varius\Crack Nikon Capture NX.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\O&O Defrag v8.5.1788 Professional [Keygen].rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\Adobe Photoshop Pro CS2 v9.0 Full + Keygen\Setup.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\Adobe Photoshop Pro CS2 v9.0 Full + Keygen\Setup.exe.manifest C:\DOCUME~1\Owner\My Documents\Computer programs varius\Adobe Photoshop Pro CS2 v9.0 Full + Keygen\Torrent downloaded from Demonoid.com.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\Adobe Photoshop Pro CS2 v9.0 Full + Keygen\Adobe DNG Converter\Adobe DNG Converter.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\Adobe Photoshop Pro CS2 v9.0 Full + Keygen\Adobe® Photoshop® CS2\instmsia.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\Adobe Photoshop Pro CS2 v9.0 Full + Keygen\Adobe® Photoshop® CS2\instmsiw.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\Adobe Photoshop Pro CS2 v9.0 Full + Keygen\Adobe® Photoshop® CS2\setup.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\Adobe Photoshop Pro CS2 v9.0 Full + Keygen\Goodies\Custom File Info Panels\Sample File Info Panels\CustomPanel_allWidgets.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\Adobe Photoshop Pro CS2 v9.0 Full + Keygen\Goodies\Custom File Info Panels\Sample File Info Panels\Description.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\Alien.Skin.Eye.Candy.v5.1.Nature.Retail.for.Adobe.Photoshop.Incl.KeyGen-SCOTCH\s-ec21na.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\Alien.Skin.Eye.Candy.v5.1.Nature.Retail.for.Adobe.Photoshop.Incl.KeyGen-SCOTCH\s-ec21nb.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\Cyberlink PowerDVD Deluxe + Keygen\Cyberlink PowerDVD Deluxe v6.0.0.2023.rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\Cyberlink PowerDVD Deluxe + Keygen\Skins\chrome.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\Cyberlink PowerDVD Deluxe + Keygen\Skins\Class.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\Cyberlink PowerDVD Deluxe + Keygen\Skins\pioneer.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\Tracked_by_Demonoid_com.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\vrlwe88a.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\vrlwe88b.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\vrlwe88c.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\vrlwe88d.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\vrlwe88a\ooodfrgp.rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\O&O Defrag v8.5.1788 Professional [Keygen].rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\O&O.Defrag.Professional.Edition.v8.0.1398.Incl.Keygen.rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\ProShow Gold v2.5.1635 KeyGen.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\ADOBE CREATIVE SUITE 2 + KEYGEN\Torrent downloaded from Demonoid.com.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Adobe Photoshop CS2 ISO + Keygen\Important!.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Adobe Photoshop CS2 ISO + Keygen\keygen\instructions.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Adobe Photoshop CS2 ISO + Keygen\keygen\keygen.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\adobe stuff\Adobe.GoLive.CS-Keygen\agl7kg.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\adobe stuff\Adobe.GoLive.CS-Keygen\keygen.rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\adobe stuff\Adobe.Illustrator.CS.v11.Keygen\ssai11.keygen.rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\adobe stuff\Adobe.InDesign.CS-Keygen\aid3kg.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\adobe stuff\Adobe.InDesign.CS-Keygen\keygen.rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\adobe stuff\Adobe.PhotoShop.CS.Keygen\keygen.rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\adobe stuff\Adobe.PhotoShop.CS.Keygen\directions\install.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\adobe stuff\Adobe.Version.Cue.CS-Keygen\avc1kg.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\adobe stuff\Adobe.Version.Cue.CS-Keygen\keygen.rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Nero 7 Premium 7.2.3.2b Keygen ONLY\Torrent downloaded from Demonoid.com.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Nero 7 Premium 7.2.3.2b Keygen ONLY\Nero 7 Premium 7.2.3.2b\Keygen\read.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Nero 7 Premium 7.2.3.2b Keygen ONLY\Nero 7 Premium 7.2.3.2b\Keygen\Serials.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Nikon Capture v4.4.0\Nikon[1].Capture.4.4_CRK-FFF\Crack.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\O&O Software\Keygen\Keygen.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\O&O.Defrag.Professional.Edition.v8.0.1398.Incl.Keygen\keygen.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\O&O.Defrag.Professional.Edition.v8.0.1398.Incl.Keygen\O&O Defrag 8 ProfessionalEn 8.0.1398.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\Tracked_by_Demonoid_com.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\vrlwe88a.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\vrlwe88b.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\vrlwe88c.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\vrlwe88d.zip C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\OO.Defrag.Professional.Edition.v8.5.1788.WinALL.Incl.Keygen-ViRiLiTY\vrlwe88a\ooodfrgp.rar C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\SmartDraw 7 Suite Edition\Keygen.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\SuperCleaner 2.9\SuperCleaner 2.9\keygen.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Webroot SpySweeper v4.5.9.709 with keygen and updater151\spysweeper.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Webroot SpySweeper v4.5.9.709 with keygen and updater151\sspsetup1_768375.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Webroot SpySweeper v4.5.9.709 with keygen and updater151\keygen\keygen.exe C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Webroot SpySweeper v4.5.9.709 with keygen and updater151\keygen\_README.txt C:\DOCUME~1\Owner\My Documents\Computer programs varius\software programs\Webroot SpySweeper v4.5.9.709 with keygen and updater151\updater1.51\Spy Sweeper Updater 1.5.1.exe C:\DOCUME~1\Owner\Start Menu\Programs\Ultimate ZIP Cracker Trial C:\DOCUME~1\Owner\Start Menu\Programs\Ultimate ZIP Cracker Trial\Ultimate ZIP Cracker release notes.html C:\DOCUME~1\Owner\Start Menu\Programs\Ultimate ZIP Cracker Trial\Ultimate ZIP Cracker.lnk 1 - "C:\Rooter$\Rooter_1.txt" - Sat 03/07/2009|19:25 ———————-\\ Scan completed at 19:25
OTListIt logfile created on: 3/7/2009 7:27:46 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.30 Mb Total Physical Memory | 232.51 Mb Available Physical Memory | 45.47% Memory free
1.22 Gb Paging File | 0.88 Gb Available in Paging File | 71.98% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.10 Gb Total Space | 110.03 Gb Free Space | 60.42% Space Free | Partition Type: NTFS
Drive D: | 4.19 Gb Total Space | 0.61 Gb Free Space | 14.68% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-AT5QGAAC3Z
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\system32\oodag.exe (O&O Software GmbH)
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe ()
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (Rocket Division Software)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\WINDOWS\StartupMonitor.exe ()
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Documents and Settings\Owner\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPodService [On_Demand | Stopped]) – File not found
SRV - (NBService [On_Demand | Stopped]) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (O&O Defrag [Auto | Running]) – C:\WINDOWS\system32\oodag.exe (O&O Software GmbH)
SRV - (OOCleverCacheAgent [On_Demand | Stopped]) – C:\Program Files\OO Software\CleverCache\ooccag.exe (O&O Software GmbH)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (ScsiAccess [Auto | Running]) – C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe ()
SRV - (StarWindService [Auto | Running]) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (Rocket Division Software)
SRV - (vsmon [Auto | Running]) – C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)

========== Driver Services (SafeList) ==========

DRV - (61883 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\61883.sys (Microsoft Corporation)
DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (Afc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (ALCXSENS [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AmdK8 [System | Running]) – C:\WINDOWS\System32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (Avc [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\avc.sys (Microsoft Corporation)
DRV - (BANTExt [System | Running]) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (CoachUsb [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CoachUsb.sys (FotoNation Inc.)
DRV - (CoachVc [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CoachVc.sys (FotoNation Inc.)
DRV - (dtscsi [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\dtscsi.sys (DT Soft Ltd.)
DRV - (fasttx2k [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (Gmer [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\gmer.sys (GMER)
DRV - (ialm [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (Agere Systems)
DRV - (LVUSBSta [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\lvusbsta.sys ()
DRV - (MSDV [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\msdv.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NVENET [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\NVENET.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (OODrvled [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\OODrvled.sys (O&O Software GmbH)
DRV - (Pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (PID_08A0 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\LV302AV.SYS ()
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (SCDEmu [System | Running]) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (SiSkp [System | Running]) – C:\WINDOWS\System32\DRIVERS\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (srescan [Boot | Running]) – C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD)
DRV - (SunkFilt [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\sunkfilt.sys (Alcor Micro Corp.)
DRV - (vaxscsi [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\vaxscsi.sys ()
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (viagfx [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\vtmini.sys (Copyright © VIA/S3 Graphics, Inc.)
DRV - (vsdatant [System | Running]) – C:\WINDOWS\System32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www6.comcast.net/a/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed] -> %ProgramFiles%\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2009/03/05 16:52:58 00,000,000 | —D | M]

O1 HOSTS File: (683976 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtcc1.acecounter.com
O1 - Hosts: 127.0.0.1 gtp1.acecounter.com #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 acestats.com
O1 - Hosts: 127.0.0.1 www.acestats.com
O1 - Hosts: 18174 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [Run StartupMonitor] StartupMonitor.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108719
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 26 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02AA9E0F-B4EB-4BE9-A769-FD09543FEEC2} http://webcamnow.com/fs5/voice/voice-installer.cab (UniInstaller Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/pcpitstop/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/0/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab (Citrix ICA Client)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1138930436531 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1139019844687 (MUWebControl Class)
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} http://cam7-uccs.asa.utk.edu/activex/AMC.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://cam2.asa.utk.edu/activex/AxisCamControl.cab (Reg Error: Key error.)
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 2.1)
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} http://www.mpix.com/Customer/Uploading/act…geUploader3.cab (Aurigma Image Uploader 3.5 Control)
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab (FujifilmUploader Class)
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} http://www.trendmicro.com/spyware-scan/as4web.cab (Reg Error: Key error.)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://160.36.60.7:9009/activex/AMC.cab (Reg Error: Key error.)
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} http://liveca12.custhelp.com/7530-b327h/rnl/java/RntX.cab (Live Collaboration)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll (PCPitstop Exam)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\WRNotifier: DllName - WRLogonNTF.dll - File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - C:\AutoFX [2006/02/21 08:12:51 00,000,000 | —D | M] - [ NTFS ]
O32 - Autorun File - D:\AUTOEXEC.BAT () - [ FAT32 ]
O32 - Autorun File - D:\Autorun.inf () - [ FAT32 ]
O33 - MountPoints2\{a6f9267a-dcee-11dd-b519-000ea693435d}\Shell - "" = AutoRun
O33 - MountPoints2\{a6f9267a-dcee-11dd-b519-000ea693435d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a6f9267a-dcee-11dd-b519-000ea693435d}\Shell\AutoRun\command - "" = L:\LaunchU3.exe – File not found
O33 - MountPoints2\{bf7337aa-9448-11da-9b5d-806d6172696f}\Shell\AutoRun\command - "" = D:\Info.exe – [2002/09/10 21:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/03/07 19:25:56 | 00,497,664 | —- | C] (OldTimer Tools) – C:\DOCUME~1\Owner\Desktop\OTListIt2.exe
[2009/03/07 19:24:45 | 00,267,612 | —- | C] () – C:\DOCUME~1\Owner\Desktop\Rooter.exe
[2009/03/07 19:24:00 | 00,000,000 | —D | C] – C:\Rooter$
[2009/03/05 16:44:25 | 00,000,000 | —D | C] – C:\DOCUME~1\Owner\Desktop\JavaRa
[2009/03/05 16:43:28 | 00,069,512 | —- | C] () – C:\DOCUME~1\Owner\Desktop\JavaRa.zip
[2009/03/04 23:21:08 | 00,002,723 | —- | C] () – C:\DOCUME~1\Owner\Desktop\mbam-log
[2009/03/04 22:19:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/03/04 22:19:09 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/04 22:19:09 | 00,000,707 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/04 22:19:06 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/04 22:19:05 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/04 22:19:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/04 02:24:11 | 00,001,745 | —- | C] () – C:\DOCUME~1\Owner\Desktop\HijackThis.lnk

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/03/07 19:25:56 | 00,497,664 | —- | M] (OldTimer Tools) – C:\DOCUME~1\Owner\Desktop\OTListIt2.exe
[2009/03/07 19:24:45 | 00,267,612 | —- | M] () – C:\DOCUME~1\Owner\Desktop\Rooter.exe
[2009/03/06 20:00:00 | 00,000,414 | —- | M] () – C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (YOUR-AT5QGAAC3Z-Owner).job
[2009/03/05 21:13:11 | 01,033,216 | —- | M] () – C:\DOCUME~1\Owner\My Documents\archive2.pst
[2009/03/05 21:13:10 | 00,271,360 | —- | M] () – C:\DOCUME~1\Owner\My Documents\archive2
[2009/03/05 16:43:29 | 00,069,512 | —- | M] () – C:\DOCUME~1\Owner\Desktop\JavaRa.zip
[2009/03/04 23:21:08 | 00,002,723 | —- | M] () – C:\DOCUME~1\Owner\Desktop\mbam-log
[2009/03/04 22:19:09 | 00,000,707 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/04 02:24:12 | 00,001,745 | —- | M] () – C:\DOCUME~1\Owner\Desktop\HijackThis.lnk
[2009/03/04 02:22:30 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/04 02:21:55 | 00,348,371 | —- | M] () – C:\WINDOWS\System32\vsconfig.xml
[2009/03/04 02:21:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/04 02:21:03 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/04 02:20:52 | 00,194,388 | —- | M] () – C:\WINDOWS\System32\OODBS.lor
[2009/02/25 16:03:27 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/02/16 17:26:45 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/02/12 06:01:49 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

========== LOP Check ==========

[2009/03/04 22:19:05 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2006/05/08 20:28:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/02/06 19:21:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2006/12/29 18:47:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2006/12/29 18:38:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2006/12/29 18:38:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2006/02/03 09:04:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2006/02/11 11:59:32 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2006/10/07 14:35:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Command Line Utility
[2006/02/22 21:02:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2006/05/21 22:27:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2007/10/20 19:33:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/04/14 07:41:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gtek
[2004/01/20 21:41:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2007/08/03 18:19:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2007/12/18 07:38:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2008/01/27 22:51:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/08/23 20:54:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macromedia
[2007/09/06 10:45:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/03/04 22:19:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/01/10 15:35:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2006/10/21 09:31:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2006/09/18 10:04:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
[2007/02/15 23:05:31 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2004/01/20 23:05:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2008/12/25 01:01:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2006/07/30 10:34:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2007/09/19 07:43:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2008/01/15 13:26:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2006/02/03 08:57:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2006/03/19 19:27:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2004/01/20 20:21:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2006/02/14 17:14:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/02/28 22:47:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2008/03/21 20:57:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2006/02/26 17:29:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2006/02/11 11:58:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2007/09/25 09:30:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2006/02/02 19:21:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2006/04/17 12:07:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/04/05 16:13:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/05/21 22:27:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2006/12/29 18:38:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/02/02 20:37:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/03/04 22:19:13 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2009/01/04 22:06:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\.ABC
[2008/04/28 10:56:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Adobe
[2008/07/07 09:09:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeUM
[2006/08/16 17:08:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ahead
[2008/05/16 21:26:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Alien Skin
[2006/02/03 09:00:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apple Computer
[2008/12/25 01:20:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ArcSoft
[2008/07/12 23:51:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
[2007/04/22 22:36:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Camera Bits, Inc
[2006/04/26 12:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Camfrog
[2009/03/04 13:54:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Canon
[2007/08/03 18:20:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Corel Photo Album
[2007/02/28 08:29:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CyberLink
[2006/07/14 13:10:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FrostWire
[2006/08/11 08:18:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Google
[2008/04/14 07:41:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GTek
[2007/03/16 22:38:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\gtopala
[2006/03/04 20:55:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Help
[2006/02/03 20:27:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HP
[2007/10/05 11:04:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ICAClient
[2004/01/20 20:16:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Identities
[2006/02/17 15:53:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IDMComp
[2006/02/18 11:10:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2006/02/12 12:31:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2007/12/18 07:38:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\iolo
[2007/11/18 21:36:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lavasoft
[2006/02/02 22:15:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2007/03/03 01:25:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LimeWire
[2008/08/23 21:00:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Macromedia
[2009/03/04 22:19:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2006/02/09 08:50:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\McAfee.com Personal Firewall
[2007/02/21 20:25:44 | 00,000,000 | –SD | M] – C:\Documents and Settings\Owner\Application Data\Microsoft
[2006/10/25 08:27:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2008/04/30 12:45:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2006/05/21 22:29:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nikon
[2007/09/19 08:13:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OfficeUpdate12
[2006/12/07 09:11:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PC Tools
[2006/11/02 13:49:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\RCP 4
[2008/04/30 12:49:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Real
[2006/12/02 14:49:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Roxio
[2004/01/20 23:29:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2006/02/11 11:58:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ScanSoft
[2006/06/18 15:37:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SmartDraw
[2008/01/01 09:20:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2006/02/02 22:18:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sonic
[2008/08/23 21:06:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SSH
[2004/01/20 20:54:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sun
[2007/09/28 08:07:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2004/01/21 04:48:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Symantec
[2006/02/02 20:56:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2006/02/07 13:56:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Trend Micro
[2009/01/07 14:11:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2007/11/12 09:21:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Walgreens
[2002/08/29 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/06 20:00:00 | 00,000,414 | —- | M] () – C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (YOUR-AT5QGAAC3Z-Owner).job
[2009/03/04 02:21:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FC460D15
@Alternate Data Stream - 0 bytes -> C:\DOCUME~1\Owner\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\DOCUME~1\Owner\Desktop\Thumbs.db:encryptable
< End of report >
OTListIt Extras logfile created on: 3/7/2009 7:27:46 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.30 Mb Total Physical Memory | 232.51 Mb Available Physical Memory | 45.47% Memory free
1.22 Gb Paging File | 0.88 Gb Available in Paging File | 71.98% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.10 Gb Total Space | 110.03 Gb Free Space | 60.42% Space Free | Partition Type: NTFS
Drive D: | 4.19 Gb Total Space | 0.61 Gb Free Space | 14.68% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-AT5QGAAC3Z
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.js [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\FlashFXP\flashfxp.exe:*:Enabled:FlashFXP v3 (IniCom Networks, Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe:*:Enabled:BackWeb-137903 ()
C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk (Google)
C:\Program Files\FlashFXP\flashfxp.exe:*:Enabled:FlashFXP v3 (IniCom Networks, Inc.)
C:\Program Files\RNmail\rn.exe:*:Enabled:Email plugin for all Windows email clients which enables email tracking, certified email, self-destructing email, and numerous other features. File not found
C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus (Azureus Inc)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader File not found
C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player File not found
C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC (mIRC Co. Ltd.)
C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console (Microsoft Corporation)
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0496D9E9-224B-4AFA-8F37-23B98D52F1EB}" = Logitech QuickCam
"{0861E87B-24D7-4E7C-B11B-54F86E5C5199}" = hpg8200
"{092eeeee-9fdd-4895-a568-0818c96beb6c}" = AiO_Scan
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{14B4E017-ACDF-4DB0-9D94-8988F5F0145A}" = hpg4600
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{15B9DC72-73F9-4d99-9E28-848D66DA8D99}" = HP Photo & Imaging 3.5 - HP Devices
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F7473D9-6C0B-4F5A-8FA4-AB8AD78CBE54}" = DocProc
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{20CF99FC-2CE7-4AA4-966E-A4B11C0662B4}" = hpg3970
"{21DDC579-834B-4C14-8122-853994FA2214}" = NikonCapture
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{257EC58E-03FD-472B-A9B6-93F23A3C4CB0}" = Scan
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 12
"{29B39FB2-5ADF-4F94-BC82-13942871DD0D}" = CameraDrivers
"{29B50D30-EAFC-4cea-9F76-3A0E3729E9B0}" = SkinsHP1
"{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp
"{2FA6BA68-FDF6-4bd9-81EE-079855E89989}_is1" = DART CD-Recorder 4
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3580211E-3BB7-42C0-ADC3-9A8C1EFFF2CB}" = ArcSoft Media Card Companion
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{415B8A4E-0EA2-4C69-975C-EEE07B837FD7}" = Unload
"{45B6180B-DCAB-4093-8EE8-6164457517F0}" = Photosmart 140,240,7200,7600,7700,7900 Series
"{47813E93-F2A0-484A-838E-47EC1B28D190}" = Adobe Stock Photos 1.0
"{48242276-DB89-42e8-9678-BD4280D7B99A}" = Copy
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{53480150-81CB-4A86-B378-86B6F08AF80B}" = O&O DriveLED
"{53480370-6CA2-47EC-BC05-02B4B9271C31}" = O&O Defrag Professional Edition
"{53480390-0EC4-429E-BBEE-78E19EEB03BD}" = O&O CleverCache
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{54266945-8A11-424D-B20F-4F747A714FBA}" = DV TS
"{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"{54e854d5-d5d4-452d-9c75-b39f5625b5fb}" = Readme
"{57C7C46A-D35D-492d-A328-4F8C9B5B4B52}" = PrintScreen
"{60758250-C8CF-47EB-8CB6-E0C3B84D8207}" = PSShortcutsP
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{692854CC-97EF-4307-B787-8C6787B91033}" = Nero 7 Demo
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{723C033E-63EA-4227-BAB2-0AA8693C16EB}" = Director
"{73006B34-9743-4A39-AC37-38EDFCEB6DCE}" = Adobe Product/Adobe Studio Update 10/2001
"{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{76EFAC4F-1712-401F-B2AE-590B170C9BCE}" = StartupMonitor
"{76F0FEBD-6C17-4D57-BDCD-88004E3929B2}" = Ultimate ZIP Cracker Trial version
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE 2.0
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Pro
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{81DD5688-695A-4c1d-AE7D-368BF857725A}" = TrayApp
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" =
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90E00409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Outlook 2003
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{93F599DF-519B-4706-A3F1-9530DF2590B4}" = ArcSoft PhotoImpression 5
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD Player
"{9B03C535-3AEA-4ef2-B326-0A01A2207034}" = CreativeProjects
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{AC76BA86-7AD7-1033-7B44-000000000001}" = Adobe Reader 6.0
"{AD17BC8E-4A5D-4E59-8640-10DF36E9EB75}" = hpg5530
"{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
"{BA4DF4C3-196E-4128-969A-00996B5A46F8}" = Canon MP500
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{bb6cac2a-1fa0-471a-bc3c-ade699c39f3c}" = Fax
"{BC339BFD-F550-471a-8D26-4D08126C62F7}" = SkinsHP2
"{BC467935-A9A5-4D0F-BD89-94F36CDF0524}" = Adobe Stock Photos 1.0
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{c330461f-c4a9-4fc7-af5d-c158e0b56aa7}" = AiOSoftware
"{C6C44651-7C66-4b11-92E8-17565D3D22DD}" = HP Image Zone Plus 3.5
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBE3E0AF-73BB-4c21-8B96-B09E003EDE7F}" = QuickProjects
"{CE378F36-E404-4244-A33F-F50A2A6D31BD}" = Microsoft Color Control Panel Applet for Windows XP
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = HP Organize
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow! 1.0
"{DE1A361F-31DC-4AC5-ABBA-2323BC505880}" = LexarMedia ImageRescue Software
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E5BD1F9C-8BBA-410E-837D-94D523269F8F}" = ArcSoft MediaConverter
"{E6CF5B58-E775-46C0-BFF2-F39A0014FE4A}" = muvee autoProducer 4.1
"{E8BFBD0A-8002-4dc9-869C-E495FA9DCE7A}" = PhotoGallery
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{ec7d7a6a-31cb-4810-826f-74171bef44f1}" = AIOMinimal
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{ED869D8B-6C7E-44C7-9F2F-BD5436849C61}" = hpg2436
"{EF9967D8-1999-4260-ACC2-86901AA36650}" = Multimedia Card Reader
"{F247869D-3643-4A9F-821B-3534145928E3}" = HPIZ350
"{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}" = HP PSC & OfficeJet 3.0
"{F419D20A-7719-4639-8E30-C073A040D878}" = HP Deskjet Preloaded Printer Drivers
"{FBBF532A-47AC-457d-AC06-0D3163D8911E}" = WebReg
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FEDA56C4-82F3-46DD-8B50-FC592BBE1C0D}" = hp deskjet 5100
"{FF102450-55AA-4AE1-ACE4-E271E2470C83}" = hpmdtab
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"ABC" = ABC (remove only)
"Adobe Acrobat 7.0 Professional" = Adobe Acrobat 7.0.9 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player
"avast!" = avast! Antivirus
"Azureus" = Azureus
"BackWeb-137903 Uninstaller" = Updates from HP
"Belarc Advisor 2.0" = Belarc Advisor 7.2
"Citrix ICA Web Client" = MetaFrame Presentation Server Web Client for Win32
"CleanUp!" = CleanUp!
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"DreamSuite" = Uninstall DreamSuite
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"FlashFXP v3.2.0 (Build 1080) Scene Edition" = FlashFXP v3.2.0 (Build 1080) Scene Edition
"HijackThis" = HijackThis 2.0.2
"HP Instant Support" = HP Instant Support
"HP Photo & Imaging" = HP Image Zone 3.5
"HPTOOLKIT" = Toolkit View(HP)
"ID-Blaster Plus_is1" = ID-Blaster Plus v2.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"InstallShield_{EF9967D8-1999-4260-ACC2-86901AA36650}" = Multimedia Card Reader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"mIRC" = mIRC
"MP Navigator 2.0" = Canon MP Navigator 2.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Mystical" = Uninstall Mystical
"MysticalTTC" = Uninstall MysticalTTC
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Display Driver" = NVIDIA Display Driver
"NVIDIA Ethernet Driver" = NVIDIA Ethernet Driver
"NVIDIA GART Driver" = NVIDIA GART Driver
"Photo Mechanic" = Photo Mechanic
"Photo Watermark Professional_is1" = Photo Watermark Professional
"Photodex Presenter" = Photodex Presenter
"PhotoGraphic Edges" = PhotoGraphic Edges
"Picasa2" = Picasa 2
"PicasaNet" = Hello (remove only)
"PictureProject In Touch Downloader" = PictureProject In Touch Downloader 1.0
"PowerISO" = PowerISO
"ProShow Gold" = ProShow Gold
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"QcDrv" = Logitech® Camera Driver
"Quicken WillMaker Plus 2006" = Quicken WillMaker Plus 2006
"QuickGamma_is1" = QuickGamma 2.0.0.3
"QuickMonitorProfile_is1" = QuickMonitorProfile 2.0.0.1
"ReaConverter 4.0 Pro_is1" = ReaConverter 4.0 Pro
"Registrar Registry Manager (Lite Edition)_is1" = Registrar Registry Manager 4.04
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SpywareBlaster_is1" = SpywareBlaster 4.0
"SuperCleaner" = SuperCleaner
"Tweak UI 2.10" = Tweak UI
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR archiver
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoneAlarm" = ZoneAlarm

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 4/5/2008 4:58:58 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C0000005.

Error - 4/5/2008 5:18:12 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C0000005.

Error - 4/5/2008 5:27:16 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C0000005.

Error - 4/14/2008 8:03:02 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = avast! | ID = 33554522
Description = Error in aswChestS: chest s_NewFile Error 112.

Error - 4/14/2008 8:03:02 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = avast! | ID = 33554522
Description = Error in aswChestC: chestAddFile Error 112.

Error - 4/14/2008 8:03:14 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = avast! | ID = 33554522
Description = Error in aswChestS: chest s_NewFile Error 112.

Error - 4/14/2008 8:03:14 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = avast! | ID = 33554522
Description = Error in aswChestC: chestAddFile Error 112.

[ Application Events ]
Error - 7/25/2008 7:54:41 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Hang | ID = 1002
Description = Hanging application Mr QuestionMan.exe, version 0.8.0.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/31/2008 12:14:47 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16674, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/2/2008 12:38:18 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 6.0.0.2023, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/2/2008 12:38:36 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 6.0.0.2023, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/2/2008 12:38:39 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 6.0.0.2023, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/2/2008 4:13:57 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 6.0.0.2023, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/7/2008 1:03:51 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8125.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/15/2008 7:00:23 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 6.0.0.2023, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/25/2008 12:47:59 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x4ec6730c.

Error - 2/23/2009 5:57:18 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 3/6/2009 7:05:03 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070663: Update for Microsoft Office Outlook 2003 (KB953432).

Error - 3/7/2009 7:00:39 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070663: Update for Outlook 2003 (KB943649).

Error - 3/7/2009 7:00:39 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070663: Security Update for Microsoft Office 2003 (KB921598).

Error - 3/7/2009 7:00:56 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070663: Office 2003 Service Pack 3 (SP3).

Error - 3/7/2009 7:00:56 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070663: Security Update for Office 2003 (KB945185).

Error - 3/7/2009 7:00:56 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070663: Update for Microsoft Office Outlook 2003 Junk Email Filter
(KB959614).

Error - 3/7/2009 7:00:56 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070663: Security Update for Microsoft Office Outlook 2003 (KB945432).

Error - 3/7/2009 7:01:48 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070663: Security Update for Microsoft Office 2003 (KB953404).

Error - 3/7/2009 7:01:48 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070663: Security Update for Office 2003 (KB954478).

Error - 3/7/2009 7:01:48 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070663: Update for Microsoft Office Outlook 2003 (KB953432).


< End of report >
Hi matthewp,

You have a lot of cracked software obtained by p2p programs on this machine.

We are finding that this is the main cause of infections we are seeing these days. Anything downloaded from them cannot be trusted to be clean, even if the file appears to be what it claims to be, it can have malware embedded in it.

There are numerous extremely nasty infections being spread through p2p downloading that will wipe out your entire Operating System.
One such infection is virut - read about this virus HERE

Just to be safe, I would like to run an extra scan to check for this virus.

References for the risk of p2p programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm

NEXT

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (no name) - - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
    
    :Services
    :Reg
    :Files
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )


NEXT


Please download Dr.Web CureIt to the desktop:
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.


NEXT

Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply please include
  • Dr.Web log
  • Kaspersky log
  • Fresh HJT log
========== OTLISTIT ========== Process explorer.exe killed successfully! Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DFEEE8.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DFF00B.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_da8.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_e4.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\ZLT06a7a.TMP scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.3.5 log created on 03072009_232043 Files moved on Reboot… C:\Documents and Settings\Owner\Local Settings\Temp\~DFEEE8.tmp moved successfully. C:\Documents and Settings\Owner\Local Settings\Temp\~DFF00B.tmp moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_da8.dat not found! C:\WINDOWS\temp\Perflib_Perfdata_e4.dat moved successfully. File C:\WINDOWS\temp\ZLT06a7a.TMP not found! Registry entries deleted on Reboot…
Hi matthewp, would you mind running the Dr.Web and Kaspersky scans from my previous post as well and posting the results Thanks
here are two of the three other logs you asked for. I have to re-run Kaspersky since it failed after 41%. takes about 10 hours to run KS from start to finish.
HJT;

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:44:52 PM, on 3/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www6.comcast.net/a/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.comcast.net/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O16 - DPF: {02AA9E0F-B4EB-4BE9-A769-FD09543FEEC2} (UniInstaller Class) - http://webcamnow.com/fs5/voice/voice-installer.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1138930436531
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139019844687
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - http://cam7-uccs.asa.utk.edu/activex/AMC.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - http://cam2.asa.utk.edu/activex/AxisCamControl.cab
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.mpix.com/Customer/Uploading/act…geUploader3.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://160.36.60.7:9009/activex/AMC.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca12.custhelp.com/7530-b327h/rnl/java/RntX.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O17 - HKLM\System\CS2\Services\Tcpip\..\{28F0851D-E99D-4FDB-8DCF-6C5BE0B10B97}: NameServer = 68.87.68.162,68.87.74.162
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: O&O CleverCache Agent (OOCleverCacheAgent) - O&O Software GmbH - C:\Program Files\OO Software\CleverCache\ooccag.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 10503 bytes

drweb:
ocpinst.exe\data529;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.3\ocpinst.exe;Probably BACKDOOR.Trojan;;
ocpinst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.3;Archive contains infected objects;Moved.;
mirc.chm\ctcp_events.htm;C:\Program Files\mIRC\mirc.chm;IRC.Generic.32;;
mirc.chm;C:\Program Files\mIRC;Container contains infected objects;Moved.;
EarthLink Setup.msi/stream001\uninstll.exe;C:\Program Files\Online Services\Earthlink\EarthLink Setup.exe/Windows\access\EarthLink Setup.msi/stream001;Probably STPAGE.Trojan;;
stream001;C:\Program Files\Online Services\Earthlink\EarthLink Setup.exe/Windows\access;Archive contains infected objects;;
\Windows\access\EarthLink Setup.msi;C:\Program Files\Online Services\Earthlink\EarthLink Setup.exe/Windows\access;Archive contains infected objects;;
EarthLink Setup.exe;C:\Program Files\Online Services\Earthlink;Archive contains infected objects;Moved.;
rr.exe;C:\Program Files\Registrar Registry Manager;Probably WIN.WORM.Virus;Moved.;
A0092187.exe\data529;C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP297\A0092187.exe;Probably BACKDOOR.Trojan;;
A0092187.exe;C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP297;Archive contains infected objects;Moved.;
EarthLink Setup.msi/stream001\uninstll.exe;C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP297\A0092188.exe/Windows\access\EarthLink Setup.m;Probably STPAGE.Trojan;;
stream001;C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP297\A0092188.exe/Windows\access;Archive contains infected objects;;
\Windows\access\EarthLink Setup.msi;C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP297\A0092188.exe/Windows\access;Archive contains infected objects;;
A0092188.exe;C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP297;Archive contains infected objects;Moved.;

[*]Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )


NEXT



In your next reply please include

  • Dr.Web log
  • Kaspersky log
  • Fresh HJT log


Hate to have thrown you off but it did appear as if you wanted the first log and then the other three. Hard to know from some of it. Directions for Dr. web were not so easy to follow. There were some other things I had to do to get done what you requested. Perhaps it is a newer version. Do not know and not important but was not the easy instructions that are normally in here that are very point by point hard to screw up. I am used to some of these programs from previous years and was able to figure it out, Then again it could have been just me.

As I said in last post I will get you the KS log asap. Looked to be the same as previous however. Same single file was bad/infected. but it did stop at 41%
M

P.S. most of the things like adaware/spybot etc I had removed before we ever started on this since they failed most of the time, so since we see them I do not know about them for they were removed in add/remove. Granted the exe file might still be around somewhere.
——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Monday, March 9, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Sunday, March 08, 2009 19:31:10 Records in database: 1880647 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ Scan statistics: Files scanned: 88874 Threat name: 2 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 09:34:15 File name / Threat name / Threats count C:\Documents and Settings\Owner\DoctorWeb\Quarantine\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.62 1 C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.63 1 The selected area was scanned.
Hi matthewp,

Good news, your logs look clean :thumbup:


Now we just need to clean up after our selves.

Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program

NEXT
Now we need to set a new system restore point.

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

To do this: Click Start > Run > copy and paste the following into the run box:


%SystemRoot%\System32\restore\rstrui.exe


Press OK. Choose Create a Restore Point then click Next.
Name it (something you'll remember) and click Create,
when the confirmation screen shows the restore point has been created click Close.

Now remove all previous Restore Points:
Click Start > Run > copy and paste the following into the run box:


cleanmgr

At the top, click on More Options tab. Click the Clean up button in the System Restore box.
Click on the Yes button.
When finished, click on Cancel button to exit.

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
      Type Inetcpl.cpl & click OK
      Click on the Security tab
      Click Reset all zones to default level
      Make sure the Internet Zone is selected & Click Custom level
      In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
      Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • For Firefox I highly recommend these add-ons to keep your PC even more secure.NoScript - for blocking ads and other potential website attacks
    McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.
  • Please read the guide by Rorschach112 on how to prevent malware and about safe computing here

Thankyou for your patience and performing all the procedures requested.
I will finish all of this in a bit however thought you might want to know that microsoft did not like that program much. ! in a yellow triangle in the bottom left toolbar of my Desktop said: "Toolcleaner2- corrupt file The file directory C:\$Mft is corrupt and unreadable. Please run the checkdisk utility." Another is Syst restore rstrui.exe is corrupt—- System volume info \_ restore {7f7BE6……..} .. run check disk utility. Also this is a bit befor this and I forgot to put it in —virtual memory was in bad shape so the computer had to do some moving of information. Also; I am not so sure about it being better yet but I will give it a go in the areas it failed before I got started on this and will let you know.
Hi matthewp

Toolscleaner is warning that your machine has Master File Table errors.

Sometimes malware or cracked programs can be embedded with code that can corrupt system settings and files when removed.

I strongly suggest you run Check Disk, System File Checker - to restore any OS missing or corrupt files, as well as defragment your hard drive.

  • click Start>Run type CMD into the run box then click OK
    When the DOS (Command) window comes up type CHKDSK C: /F and hit the Enter key.
    You will then be told that it cannot run now but will run on a re-start so re-start your PC (this takes quite some time to run).
  • Have your XP CD handy incase corrupt files need replacing - click Start> Run type Sfc /Scannow into the run box - allow SFC to run and replace any corrupt files.
  • You can download this free defragmenting program from Auslogics >>>HERE<<

Let me know how you get on.

CB
Hey CB,
I am in the middle of finals this week so I am sorry to have so much time in between posts but I have no other choice.

I have done as you said in your last post
click Start>Run type CMD into the run box then click OK
When the DOS (Command) window comes up type CHKDSK C: /F and hit the Enter key.
You will then be told that it cannot run now but will run on a re-start so re-start your PC.

did this and all went well had to reboot and the computer needed nothing, just acted as normal

Have your XP CD handy incase corrupt files need replacing - click Start> Run type Sfc /Scannow into the run box - allow SFC to run and replace any corrupt files. did this and it ran and asked for nothing, not the first disk so I guess it has all the files it needs in the right places.

PROBLEM:
did all of that and rebooted. Went to MS site for updates. I did get service pack 3 and it installed fine, as did a few other things. Rebooted, went back got more updates 11 of 16 failed.
Most were for office and outlook but one (perhaps two) were for xp security.

Honestly I do not care about the office and outlook as long as I can get security stuff, and this machine should be getting stored soon so I can take office out and reinstall later and do all downloads then.
see post: http://forums.whatthetech.com/Ms_Updates_t…hl=dangedcoyote

I will do another update to make sure of what I am missing and let you know for sure what is missing, we can go from there.
Thanks for all the help up to this point.
Good,

It may just need the defrag then to fix the master file table errors.

One other issue..were you able to set a new restore point

Syst restore rstrui.exe is corrupt—- System volume info \_ restore {7f7BE6……..} .. run check disk utility.


an alternate method is this:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

If you continue to have issues I suggest you post in the tech forum and see if our tech gurus can assist (they are excellent)

link to this topic so they can see the malware has been cleaned.

Good luck with your finals…

CB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI