This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] hijack this log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Internet explorer is redirected from opening home page to brower-security.microsoft.com

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:44:14 PM, on 3/8/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\UAService7.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe
C:\Program Files\iolo\System Mechanic Professional\AntiVirus\ioloAV.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iolo\System Mechanic Professional\AntiVirus\iAVEmailScanner.exe
C:\Program Files\Mozilla FoxFire 3.0.1\firefox.exe
C:\WINNT\system32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchFilter.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O2 - BHO: BHO - {C9C42510-9B21-41c1-9DCD-8382A2D07C61} - C:\WINNT\system32\iehelper.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINNT\system32\TwcToolbarIe7.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [iolo AntiVirus] "C:\Program Files\iolo\System Mechanic Professional\AntiVirus\ioloAV.exe"
O4 - HKLM\..\Run: [iolo Personal Firewall] "C:\Program Files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe"
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKLM\..\Policies\Explorer\Run: [servises] C:\WINNT\system32\servises.exe
O4 - HKUS\.DEFAULT\..\Run: [servises] C:\WINNT\system32\servises.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [rundll32.exe] rundll32.exe "C:\Documents and Settings\Default User\Application Data\Macromedia\Common\51b5e00a1.dll"" (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [servises] C:\WINNT\system32\servises.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Mozilla Firefox
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O10 - Unknown file in Winsock LSP: c:\winnt\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\iavlsp.dll
O12 - Plugin for .htm: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: mkesfg - mkesfg.dll (file missing)
O22 - SharedTaskScheduler: didymiums - {e6adaaf0-79b2-4cf1-a660-50a0b33991a1} - (no file)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINNT\system32\UAService7.exe

–
End of file - 8795 bytes
Hello vdsteg and welcome back to the forums here at WTT!

:welcome:

First, use Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Also, let's get a little closer look than HijackThis will give.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Malware log:

Malwarebytes' Anti-Malware 1.30
Database version: 1358
Windows 5.0.2195 Service Pack 4

3/14/2009 7:35:50 PM
mbam-log-2009-03-14 (19-35-50).txt

Scan type: Quick Scan
Objects scanned: 56226
Time elapsed: 57 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


OT Listit Log

OTListIt logfile created on: 3/14/2009 7:40:03 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.8 Folder = C:\Documents and Settings\Administrator\Desktop
Windows 2000 Professional Edition Service Pack 4 (Version = 5.0.2195) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.47 Mb Total Physical Memory | 84.60 Mb Available Physical Memory | 33.11% Memory free
617.04 Mb Paging File | 266.63 Mb Available in Paging File | 43.21% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 16.64 Gb Total Space | 4.01 Gb Free Space | 24.07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 111.76 Gb Total Space | 91.14 Gb Free Space | 81.55% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
Drive G: | 976.13 Mb Total Space | 589.11 Mb Free Space | 60.35% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OEM-6W9RM1BTAAS
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINNT\System32\Ati2evxx.exe ()
PRC - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe (Authentium, Inc.)
PRC - C:\Program Files\iolo\common\lib\ioloServiceManager.exe ()
PRC - C:\WINNT\system32\MSTask.exe (Microsoft Corporation)
PRC - C:\WINNT\system32\UAService7.exe ()
PRC - C:\WINNT\System32\WBEM\WinMgmt.exe (Microsoft Corporation)
PRC - C:\WINNT\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\iolo\System Mechanic Professional\AntiVirus\ioloAV.exe ()
PRC - C:\Program Files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe ()
PRC - C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe (Yahoo! Inc.)
PRC - C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINNT\System32\Ati2evxx.exe ()
SRV - (dmadmin [On_Demand | Stopped]) – C:\WINNT\System32\dmadmin.exe (VERITAS Software Corp.)
SRV - (dvpapi [Auto | Running]) – C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe (Authentium, Inc.)
SRV - (Fax [On_Demand | Stopped]) – C:\WINNT\system32\faxsvc.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-061008-081103 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ioloFileInfoList [Auto | Running]) – C:\Program Files\iolo\common\lib\ioloServiceManager.exe ()
SRV - (ioloSystemService [Auto | Running]) – C:\Program Files\iolo\common\lib\ioloServiceManager.exe ()
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (MSSQLServerADHelper [On_Demand | Stopped]) – File not found
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (RemoteRegistry [Disabled | Stopped]) – C:\WINNT\system32\regsvc.exe (Microsoft Corporation)
SRV - (Schedule [Auto | Running]) – C:\WINNT\system32\MSTask.exe (Microsoft Corporation)
SRV - (UserAccess7 [Auto | Running]) – C:\WINNT\system32\UAService7.exe ()
SRV - (UtilMan [On_Demand | Stopped]) – C:\WINNT\System32\UtilMan.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Disabled | Stopped]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinMgmt [Auto | Running]) – C:\WINNT\System32\WBEM\WinMgmt.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ati2mtai [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ati2mtai.sys (ATI Technologies Inc.)
DRV - (Cdr4_2K [System | Running]) – C:\WINNT\System32\drivers\cdr4_2K.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) – C:\WINNT\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (CSS DVP [Auto | Running]) – C:\WINNT\system32\DRIVERS\css-dvp.sys (Authentium, Inc.)
DRV - (Diskperf [Boot | Running]) – C:\WINNT\System32\drivers\diskperf.sys (Microsoft Corporation)
DRV - (dmboot [Disabled | Stopped]) – C:\WINNT\System32\drivers\dmboot.sys (VERITAS Software Corp.)
DRV - (dmio [Boot | Running]) – C:\WINNT\System32\drivers\dmio.sys (VERITAS Software Corp.)
DRV - (dmload [Disabled | Stopped]) – C:\WINNT\System32\drivers\dmload.sys (VERITAS Software Corp.)
DRV - (EFS [Disabled | Running]) – C:\WINNT\System32\drivers\efs.sys (Microsoft Corporation)
DRV - (EL556 [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\EL556ND5.sys (3Com Corporation)
DRV - (EL90BC [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (FileDisk [System | Running]) – C:\WINNT\System32\drivers\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINNT\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (gmer [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\gmer.sys (GMER)
DRV - (maestro [On_Demand | Running]) – C:\WINNT\system32\drivers\es198xdl.sys (ESS Technology, Inc.)
DRV - (MPE [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\MPE.sys (Microsoft Corporation)
DRV - (NetDetect [On_Demand | Stopped]) – C:\WINNT\system32\drivers\netdtect.sys (Microsoft Corporation)
DRV - (Parallel [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\parallel.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINNT\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RCA [On_Demand | Stopped]) – C:\WINNT\system32\drivers\RCA.sys (Microsoft Corporation)
DRV - (SbcpHid [On_Demand | Stopped]) – C:\WINNT\system32\Drivers\SbcpHid.sys ()
DRV - (uhcd [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\uhcd.sys (Microsoft Corporation)
DRV - (WDHABBG [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\WDHABBG.sys (3Com Corporation)
DRV - (XPacket [Boot | Running]) – C:\WINNT\System32\xpacket.sys (iolo technologies, LLC)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FOXFIRE 3.0.1\COMPONENTS [2009/03/07 13:06:16 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FOXFIRE 3.0.1\PLUGINS [2009/03/07 13:06:15 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.3.3\Extensions\\Components: C:\PROGRAM FILES\NETSCAPE\NETSCAPE BROWSER\COMPONENTS [2008/09/13 16:03:57 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.3.3\Extensions\\Plugins: C:\PROGRAM FILES\NETSCAPE\NETSCAPE BROWSER\PLUGINS [2009/02/03 23:31:24 | 00,000,000 | —D | M]
[2008/08/30 16:08:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions
[2008/08/30 16:08:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/14 18:27:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\vwa91ztv.default\extensions
[2008/12/16 22:36:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\vwa91ztv.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/11/13 02:52:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\vwa91ztv.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2008/08/30 16:39:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2008/08/30 16:39:19 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/08/04 19:16:16 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2008/02/17 21:40:18 | 00,110,592 | —- | M] () – C:\Program Files\mozilla firefox\components\GoogleDesktopMozilla.dll

O1 HOSTS File: (25 bytes) - C:\WINNT\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (MSN Search Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)
O2 - BHO: (BHO) - {C9C42510-9B21-41c1-9DCD-8382A2D07C61} - C:\WINNT\system32\iehelper.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (The Weather Channel Toolbar) - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINNT\system32\TwcToolbarIe7.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (@msdxmLC.dll,-1@1033,&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx ()
O3 - HKLM\..\Toolbar: (MSN Search Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [iolo AntiVirus] "C:\Program Files\iolo\System Mechanic Professional\AntiVirus\ioloAV.exe" ()
O4 - HKLM..\Run: [iolo Personal Firewall] "C:\Program Files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe" ()
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Synchronization Manager] mobsync.exe /logon (Microsoft Corporation)
O4 - HKCU..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKCU..\Run: [rundll32.exe] File not found
O4 - HKLM..\RunOnce: [SMRequiresRestart] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll (Sun Microsystems, Inc.)
O9 - Extra Button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - Reg Error: Value error. File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm ()
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINNT\System32\rnr20.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O12 - Plugin for: .htm - C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll (Netscape Communications Corp.)
O15 - HKCU\..Trusted Sites: turbotax.com ([]https in Trusted sites)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab (CKAVWebScan Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} https://disneyblast.go.com/v3/setup/activex…wareControl.cab (Walt Disney Internet Group Hardware Control)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} http://disney.go.com/pirates/online/testAc…OnlineGames.cab (Disney Online Games ActiveX Control)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8313.4545717593 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINNT\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINNT\System32\msdxm.ocx ()
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\mkesfg: DllName - mkesfg.dll - File not found
O20 - Winlogon\Notify\wzcnotif: DllName - wzcdlg.dll - C:\WINNT\system32\wzcdlg.dll (Microsoft Corporation)
O21 - SSODL: Network.ConnectionTray - {7007ACCF-3202-11D1-AAD2-00805FC1270E} - C:\WINNT\system32\NETSHELL.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {e6adaaf0-79b2-4cf1-a660-50a0b33991a1} - didymiums - Reg Error: Key error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - G:\auto track mitsu.xls () - [ FAT ]

========== Files/Folders - Created Within 30 Days ==========

[2009/03/14 19:37:30 | 00,498,176 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
[2009/03/14 18:30:54 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe
[2009/03/12 15:40:23 | 00,016,384 | —- | C] () – C:\WINNT\System32\Perflib_Perfdata_688.dat
[2009/03/08 20:43:54 | 00,001,590 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/03/08 20:43:52 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/08 20:43:41 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\Desktop\HJTInstall.exe
[2009/03/08 15:12:38 | 00,016,384 | —- | C] () – C:\WINNT\System32\Perflib_Perfdata_3a0.dat
[2009/03/08 09:18:45 | 00,016,384 | —- | C] () – C:\WINNT\System32\Perflib_Perfdata_348.dat
[2009/03/08 07:08:38 | 00,044,032 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\karl terms 032009.doc
[2009/03/07 10:13:18 | 00,016,384 | —- | C] () – C:\WINNT\System32\Perflib_Perfdata_398.dat
[2009/03/03 17:40:06 | 00,009,728 | —- | C] () – C:\WINNT\System32\iehelper.dll
[2009/02/27 15:42:33 | 00,016,384 | —- | C] () – C:\WINNT\System32\Perflib_Perfdata_3c0.dat
[2009/02/26 22:19:05 | 00,201,216 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Johannes Kepler.ppt
[2009/02/26 16:29:38 | 00,020,480 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Work Cited Cal..doc
[2009/02/26 16:23:09 | 00,021,504 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Niels Abel.doc
[2009/02/25 17:23:14 | 00,023,552 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Cal. Project.doc
[2009/02/25 15:27:45 | 00,024,576 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Essays for english lit.doc
[2009/02/22 20:51:51 | 00,019,968 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Crazy Horse.doc
[2009/02/21 18:00:10 | 00,000,842 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Home Inventory.lnk
[2009/02/21 18:00:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\iiiHomeInventory Projects
[2009/02/21 18:00:06 | 00,000,000 | —D | C] – C:\Program Files\Insurance Information Institute
[2009/02/20 16:28:23 | 00,000,005 | —- | C] () – C:\WINNT\System32\_id.dat
[2009/02/20 16:28:16 | 00,023,553 | —- | C] () – C:\WINNT\System32\servises.dll
[2009/02/16 21:43:01 | 00,023,040 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Welcome to Hell.doc
[2009/02/15 16:22:52 | 03,700,736 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Dante Project.ppt
[2009/02/14 16:23:18 | 00,021,504 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\The Lost World.doc
[2009/02/14 14:43:19 | 00,025,088 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\outline3.doc
[2009/02/14 14:42:58 | 00,020,480 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Work Cited page.doc
[2009/02/12 20:45:18 | 00,028,672 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\rough draft 3.doc

========== Files - Modified Within 30 Days ==========

[4 C:\WINNT\*.tmp files]
[2009/03/14 19:37:27 | 00,498,176 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
[2009/03/14 18:31:01 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe
[2009/03/12 15:40:23 | 00,016,384 | —- | M] () – C:\WINNT\System32\Perflib_Perfdata_688.dat
[2009/03/12 15:37:04 | 00,000,006 | -H– | M] () – C:\WINNT\tasks\SA.DAT
[2009/03/12 14:58:53 | 01,010,338 | -H– | M] () – C:\WINNT\ShellIconCache
[2009/03/12 14:35:20 | 01,202,688 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\auto track mitsu.xls
[2009/03/09 20:06:18 | 00,000,284 | —- | M] () – C:\WINNT\tasks\AppleSoftwareUpdate.job
[2009/03/08 21:36:26 | 00,001,465 | —- | M] () – C:\WINNT\QUICKEN.INI
[2009/03/08 20:43:54 | 00,001,590 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/03/08 20:43:39 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\Desktop\HJTInstall.exe
[2009/03/08 20:07:14 | 00,044,032 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\karl terms 032009.doc
[2009/03/08 15:12:38 | 00,016,384 | —- | M] () – C:\WINNT\System32\Perflib_Perfdata_3a0.dat
[2009/03/08 15:10:56 | 00,023,553 | —- | M] () – C:\WINNT\System32\servises.dll
[2009/03/08 15:05:25 | 00,000,726 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\System Mechanic Professional.lnk
[2009/03/08 09:24:33 | 00,009,728 | —- | M] () – C:\WINNT\System32\iehelper.dll
[2009/03/08 09:18:45 | 00,016,384 | —- | M] () – C:\WINNT\System32\Perflib_Perfdata_348.dat
[2009/03/08 08:27:51 | 00,001,531 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/08 07:49:33 | 00,000,025 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2009/03/07 14:02:10 | 00,000,053 | —- | M] () – C:\WINNT\iPlayer.INI
[2009/03/07 10:13:18 | 00,016,384 | —- | M] () – C:\WINNT\System32\Perflib_Perfdata_398.dat
[2009/02/27 15:42:33 | 00,016,384 | —- | M] () – C:\WINNT\System32\Perflib_Perfdata_3c0.dat
[2009/02/27 00:24:07 | 00,021,504 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Niels Abel.doc
[2009/02/27 00:23:55 | 00,023,552 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Cal. Project.doc
[2009/02/27 00:20:03 | 00,201,216 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Johannes Kepler.ppt
[2009/02/26 16:29:38 | 00,020,480 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Work Cited Cal..doc
[2009/02/25 16:37:41 | 00,024,576 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Essays for english lit.doc
[2009/02/22 20:52:35 | 00,019,968 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Crazy Horse.doc
[2009/02/21 18:00:10 | 00,000,842 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Home Inventory.lnk
[2009/02/20 16:28:48 | 00,000,005 | —- | M] () – C:\WINNT\System32\_id.dat
[2009/02/16 21:44:34 | 00,023,040 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Welcome to Hell.doc
[2009/02/15 16:22:55 | 03,700,736 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Dante Project.ppt
[2009/02/15 12:14:36 | 00,007,952 | —- | M] (Microsoft Corporation) – C:\WINNT\System32\svchost.exe
[2009/02/14 16:23:20 | 00,021,504 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\The Lost World.doc
[2009/02/14 14:43:36 | 00,028,672 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\rough draft 3.doc
[2009/02/14 14:43:21 | 00,025,088 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\outline3.doc
[2009/02/14 14:43:08 | 00,020,480 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Work Cited page.doc

========== LOP Check ==========

[2009/03/07 10:14:32 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data
[2009/02/04 00:04:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Adobe
[2009/03/07 10:14:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AdobeUM
[2005/09/09 17:59:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Apple Computer
[2006/07/18 06:35:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Digital Album Organizer
[2006/07/17 14:57:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\F-Secure
[2004/11/22 12:36:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Help
[2004/11/22 11:53:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Identities
[2007/03/18 17:15:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\InstallShield
[2005/02/12 22:25:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Intuit
[2009/03/08 14:58:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\iolo
[2005/09/02 21:13:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ispnews
[2009/03/03 17:29:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2008/11/03 07:58:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2008/01/22 00:03:45 | 00,000,000 | –SD | M] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2005/11/17 17:43:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla
[2005/09/01 08:17:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\MSN Search Toolbar
[2005/09/01 08:22:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Netscape
[2005/09/02 21:21:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\PEX
[2005/10/03 07:03:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Sun
[2008/12/16 05:22:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\U3
[2007/12/15 23:41:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Viewpoint
[2008/03/09 17:57:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Wal-Mart Digital Photo Manager
[2007/07/15 17:40:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Wal-Mart Digital Photo Viewer
[2008/12/15 17:34:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Yahoo!
[2009/02/03 22:45:35 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/02/03 23:31:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/10/09 13:47:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/10/08 12:51:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2008/06/18 08:36:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/08/04 21:05:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2007/11/25 13:11:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2007/11/07 21:04:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2005/03/13 16:40:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/03/08 14:59:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2008/11/03 07:57:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2005/02/12 20:00:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2005/09/01 08:15:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Search Toolbar
[2007/03/12 17:46:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/11/03 09:06:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\qtydqhwp
[2007/04/05 17:29:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2007/10/08 12:49:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/29 18:19:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2008/12/16 15:18:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/03/09 20:06:18 | 00,000,284 | —- | M] () – C:\WINNT\Tasks\AppleSoftwareUpdate.job
[2001/05/08 06:00:00 | 00,000,065 | RH– | M] () – C:\WINNT\Tasks\desktop.ini
[2007/12/02 08:44:20 | 00,000,448 | —- | M] () – C:\WINNT\Tasks\Registry Repair 5.job
[2009/03/12 15:37:04 | 00,000,006 | -H– | M] () – C:\WINNT\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 7784 bytes -> C:\Documents and Settings\Administrator\My Documents\Map.gif:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Administrator\My Documents\Map.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
< End of report >


OTListIt Extras logfile created on: 3/14/2009 7:40:03 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.8 Folder = C:\Documents and Settings\Administrator\Desktop
Windows 2000 Professional Edition Service Pack 4 (Version = 5.0.2195) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.47 Mb Total Physical Memory | 84.60 Mb Available Physical Memory | 33.11% Memory free
617.04 Mb Paging File | 266.63 Mb Available in Paging File | 43.21% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 16.64 Gb Total Space | 4.01 Gb Free Space | 24.07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 111.76 Gb Total Space | 91.14 Gb Free Space | 81.55% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
Drive G: | 976.13 Mb Total Space | 589.11 Mb Free Space | 60.35% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OEM-6W9RM1BTAAS
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla FoxFire 3.0.1\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08094E03-AFE4-4853-9D31-6D0743DF5328}" = QuickTime
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}" = TurboTax ItsDeductible 2005
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{36495C59-089C-49D1-BD15-9E5BD86DC9A1}" = ItsDeductible Express
"{41FE2866-7D7D-4EDF-9C7A-F1F6A346BA83}" = Wal-Mart Digital Photo Manager
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"{6F716D8C-398F-11D3-85E1-005004838609}" = WebFldrs
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7D1DCBBA-F6F5-42B4-B90B-F04ACE4DFD6C}" = MSN Search Toolbar
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{ABCE1C63-56ED-41FF-BEAF-57321F70DC49}" = iTunes
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}" = Google SketchUp 6
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BBD3F66B-1180-4785-B679-3F91572CD3B4}_is1" = iolo technologies' System Mechanic Professional
"{C67DF120-4DD3-11D4-A3CA-005004AD2A5B}" = Authentium AntiVirus SDK - 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Ask Toolbar_is1" = Ask Toolbar
"ATI Display Driver" = ATI Display Driver Utilities
"bcMPEG2dec" = bitcontrol® MPEG-2 Video Decoder v2.0
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Disney Pirates of the Caribbean Online" = Disney Pirates of the Caribbean Online
"Google Desktop" = Google Desktop
"Higher Score on the ACT_is1" = Higher Score on the ACT
"Higher Score on the SAT/PSAT_is1" = Higher Score on the SAT/PSAT
"HijackThis" = HijackThis 2.0.2
"I.I.I. Home Inventory" = I.I.I. Home Inventory 3.08
"InstallShield_{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"InterActual Player" = InterActual Player
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.7)" = Mozilla Firefox (3.0.7)
"Netscape Browser" = Netscape Browser (remove only)
"Picasa2" = Picasa 2
"PrivateVideo" = PrivateVideo
"Q818043" = Windows 2000 Hotfix (SP5) Q818043
"Q828026" = Windows Media Player Hotfix [See Q828026 for more information]
"Registry Repair 55" = Migo Registry Repair 5
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"The Weather Channel Toolbar" = The Weather Channel Toolbar
"TurboTax Deluxe 2004" = TurboTax Deluxe 2004
"TurboTax Premier 2005" = TurboTax Premier 2005
"TurboTax Premier Investments 2006" = TurboTax Premier Investments 2006
"Update Rollup 1" = Update Rollup 1 for Windows 2000 SP4
"ViewpointMediaPlayer" = Viewpoint Media Player
"WDHABBG" = 3Com 56K V.90 Mini PCI Modem
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WMP7" = Windows Media Player system update (9 Series)
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"yqnfqokcnoa" = RON Tool Offersfortoday

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/6/2009 6:23:32 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Microsoft Internet Explorer | ID = 1000
Description =

Error - 3/7/2009 12:42:00 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.

Error - 3/7/2009 1:08:00 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.

Error - 3/7/2009 1:19:06 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.

Error - 3/7/2009 1:27:55 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.

Error - 3/7/2009 1:30:15 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.

Error - 3/7/2009 2:16:17 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.

Error - 3/8/2009 11:20:09 AM | Computer Name = OEM-6W9RM1BTAAS | Source = EventSystem | ID = 4100
Description = The COM+ Event System ran out of memory during its internal processing,
at line 60 of .\eventsystemobj.cp

Error - 3/8/2009 7:27:32 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Userenv | ID = 1000
Description = Windows cannot unload your registry file. If you have a roaming profile,
your settings are not replicated. Contact your administrator. DETAIL - Access
is denied. , Build number ((2195)).

Error - 3/11/2009 9:32:59 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.

[ System Events ]
Error - 11/18/2008 4:47:48 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.

Error - 11/18/2008 8:00:06 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.

Error - 11/18/2008 8:00:21 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.

Error - 11/19/2008 7:58:53 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.

Error - 11/19/2008 7:59:02 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.

Error - 11/21/2008 11:08:48 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.

Error - 11/21/2008 11:09:09 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.

Error - 12/1/2008 12:15:48 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 000476403DDE has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 12/1/2008 12:16:46 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.10
on the Network Card with network address 000476403DDE.

Error - 12/2/2008 1:32:19 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.


< End of report >
Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Please also post an updated HijackThis log and let me know how it's running.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thank you, internet explorer is now working properly once again. My firewall is also back in action. I appreciate your help and have made a donation to what the tech via paypal.
Hello, Thank you for the kind donation and glad it's working better. But absence of symptoms does not always mean you are completely clear. I would suggest you post the combofix log for review and see if there is anything else that needs to be done. Thanks, Dave

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI