This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] I've been hijacked! Browser problems.

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

About a week ago I noticed my browser had been hijacked…every time I enter a search and then select a result it redirects me to a different page. The pages it takes me to are not encrypted so I get a warning before the redirect and can bypass it manually before the redirect. This was livable but all of a sudden every time I do a search on either browser Mcafee blocks a trojan "Lodan" and then the system browser crashes…or it just crashes on it's own while I'm on a page that I typed the URL myself. I have scanned with every thing imaginable…found a suspicious program Prockill-Jkill that McAfee could not remove, tried a system restore…turned off system restore and scanned again still no luck…I have updated and updated but it seems to more of a problem than I thought…I am hopeful someone can take a look at my Hijackthis log and tell me what my lovely kids have managed to infect my computer with! My internet is almost useless if I can't do a search. Thank you so much for you looking:)

A

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:26:43 PM, on 3/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [StxTrayMenu] "C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3D15E6EB-2050-4800-B012-AA9E06A21D05} (Pearson Finance Player Control) - http://asp.mathxl.com/books/_Players/FinancePlayer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {E3E02F12-2ADB-478C-8742-5F0819F9F0F4} (Quantum Streaming IE VersionManager Class) -
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Unknown owner - (no file)
O23 - Service: LVSrvLauncher - Unknown owner - (no file)
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

–
End of file - 6876 bytes
Hi jennau, welcome to the forum.


To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


1st

Please turn System Restore ON. We may need it. An infected restore point is better than no restore point at all. It will not reinfect you unless you restore to that point.



Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.




Download OTListIt2 to your desktop.
  • Double click on OTList2.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


Please post back with
  • MBAM log
  • both OTLISTIT2 logs
No need for a Hijackthis log this time.

How is your computer at the moment?


Thanks
Thank you so much for your help. I have run the scans requested and pasted them in below..MBAM first, OTListIt, the Extras..if it fits otherwise I'll post that in another reply. The Malwarebytes did find six items that it removed but I'm still having problems with my browser…when I search, McAfee still detects the Trojan Lando and then the browser closes?

A

Malwarebytes' Anti-Malware 1.34
Database version: 1903
Windows 5.1.2600 Service Pack 3

3/26/2009 4:23:17 PM
mbam-log-2009-03-26 (16-23-17).txt

Scan type: Quick Scan
Objects scanned: 93066
Time elapsed: 9 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\mwqvb.pue (Trojan.Daonol) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MSVolume.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.


OTLISTIT Report;

OTListIt logfile created on: 3/26/2009 4:30:49 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\AJ\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.46 Mb Total Physical Memory | 87.55 Mb Available Physical Memory | 34.27% Memory free
962.51 Mb Paging File | 560.04 Mb Available in Paging File | 58.19% Paging File free
Paging file location(s): c:\pagefile.sys 384 768;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 21.12 Gb Free Space | 28.34% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 960.72 Mb Total Space | 660.03 Mb Free Space | 68.70% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 465.76 Gb Total Space | 337.03 Gb Free Space | 72.36% Space Free | Partition Type: NTFS

Computer Name: AJ-01G8QNUV9ZO7
Current User Name: AJ
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\program files\common files\mcafee\mna\mcnasvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\McShield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe (GEMTEKS)
PRC - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe (Linksys)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe (Seagate LLC)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Logitech\MouseWare\system\em_exec.exe (Logitech Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - c:\Program Files\McAfee\MSC\mcupdmgr.exe (McAfee, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\AJ\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (CCALib8 [Auto | Running]) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (HP Port Resolver [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE (Hewlett-Packard Company)
SRV - (HP Status Server [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE (Hewlett-Packard Company)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVPrcSrv [Auto | Stopped]) – File not found
SRV - (LVSrvLauncher [Auto | Stopped]) – File not found
SRV - (mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) – c:\program files\common files\mcafee\mna\mcnasvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) – C:\Program Files\McAfee\VirusScan\McShield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService [Auto | Running]) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (MSCSPTISRV [Disabled | Stopped]) – File not found
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PACSPTISVR [Disabled | Stopped]) – File not found
SRV - (Pml Driver HPZ12 [Unknown | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (SPTISRV [On_Demand | Stopped]) – File not found
SRV - (UMWdf [On_Demand | Stopped]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (WMP54Gv4SVC [Auto | Running]) – File not found

========== Driver Services (SafeList) ==========

DRV - (AegisP [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (BCM42RLY [On_Demand | Stopped]) – C:\WINDOWS\System32\BCM42RLY.SYS (Broadcom Corporation)
DRV - (ctljystk [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (emu10k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (emu10k1 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GcKernel [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\GcKernel.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HIDSwvd [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HIDSwvd.sys (Microsoft Corporation)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (itchfltr [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\itchfltr.sys (Logitech, Inc.)
DRV - (L8042pr2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\L8042pr2.Sys (Logitech, Inc.)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LMouFlt2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LMouFlt2.Sys (Logitech, Inc.)
DRV - (mfeavfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (MPFP [System | Running]) – C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4.sys (NVIDIA Corporation)
DRV - (pcouffin [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (RT2500 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\RT2500.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfman [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (USBIO [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbio.sys (Thesycon GmbH, Germany)
DRV - (vulfnths [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\vulfnth.sys (VIA Technologies, Inc.)
DRV - (vulfntrs [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\vulfntr.sys (VIA Technologies, Inc.)
DRV - (GTNDIS5 [On_Demand | Running]) – C:\WINDOWS\system32\GTNDIS5.SYS (Printing Communications Assoc., Inc. (PCAUSA))

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar;=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.update: false
FF - prefs.js..extensions.enabledItems: {0C7E3F01-99E9-4095-9BDC-F84724960B57}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/02/03 12:14:44 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2008/09/30 17:28:20 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2008/09/30 17:28:20 | 00,000,000 | —D | M]

[2008/09/30 17:35:26 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\mozilla\Extensions
[2008/09/30 17:35:26 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/09/30 17:35:26 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\mozilla\Firefox\Profiles\btn3voy4.default\extensions
[2009/02/05 20:32:02 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\mozilla\Firefox\Profiles\btn3voy4.default\extensions\{0C7E3F01-99E9-4095-9BDC-F84724960B57}
[2008/09/30 17:28:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2008/09/30 17:28:22 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/02/03 12:16:12 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/02/05 11:24:56 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\BRWSRCMP.DLL
[2009/02/05 11:24:56 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2008/09/24 19:21:16 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/09/24 19:21:16 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/09/24 19:21:16 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/09/24 19:21:16 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/09/24 19:21:16 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/09/24 19:21:16 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
[2008/11/14 07:35:18 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Logitech Utility] Logi_MwX.Exe (Logitech Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [NWEReboot] File not found
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [StxTrayMenu] "C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe" (Seagate LLC)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript (Malwarebytes Corporation)
O4 - HKLM..\RunOnceEx: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O15 - HKCU\..Trusted Sites: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Sites: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Sites: mcafee.com ([]https in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab (DwnldGroupMgr Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E3E02F12-2ADB-478C-8742-5F0819F9F0F4} (Quantum Streaming IE VersionManager Class)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ FAT32 ]
O32 - Autorun File - I:\autorun.inf () - [ NTFS ]
O33 - MountPoints2\{5ed19db2-f25f-11dd-a719-000c416c4c1f}\Shell - "" = Autorun
O33 - MountPoints2\{5ed19db2-f25f-11dd-a719-000c416c4c1f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{7128cb60-3413-11dc-a60a-000c416c4c1f}\Shell\AutoRun\command - "" = I:\Install FreeAgent Tools.exe – [2007/02/08 19:29:48 | 14,604,1088 | —- | M] (Seagate )
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[8 C:\WINDOWS\*.tmp files]
[12 C:\Documents and Settings\AJ\Desktop\*.tmp files]
[2009/03/26 16:24:27 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\drivers\hjlf.sys
[2009/03/26 12:41:45 | 00,000,000 | —D | C] – C:\Documents and Settings\AJ\Application Data\Malwarebytes
[2009/03/26 12:41:31 | 00,000,610 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/26 12:41:29 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/26 12:41:25 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/26 12:41:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
[2009/03/26 12:41:21 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/26 12:40:27 | 00,498,688 | —- | C] (OldTimer Tools) – C:\Documents and Settings\AJ\Desktop\OTListIt2.exe
[2009/03/26 12:39:42 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\AJ\Desktop\mbam-setup.exe
[2009/03/25 21:00:35 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/03/25 20:59:44 | 00,000,506 | —- | C] () – C:\Documents and Settings\AJ\Desktop\ERUNT.lnk
[2009/03/25 20:59:41 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/03/25 20:59:08 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\AJ\Desktop\erunt_setup.exe
[2009/03/25 20:36:17 | 00,022,528 | —- | C] () – C:\Documents and Settings\AJ\Desktop\R.doc
[2009/03/25 09:41:19 | 00,019,456 | —- | C] () – C:\Documents and Settings\AJ\Desktop\Copy of peewee09.xls
[2009/03/17 20:27:40 | 00,000,000 | —D | C] – C:\Program Files\Common Files\ODBC
[2009/03/17 20:26:16 | 00,000,000 | —D | C] – C:\Config.Msi
[2009/03/12 08:51:06 | 00,026,624 | —- | C] () – C:\Documents and Settings\AJ\Desktop\Script for Spanish Project.doc
[2009/03/11 18:46:11 | 00,000,162 | -H– | C] () – C:\Documents and Settings\AJ\My Documents\~$ench Style Fondue.doc
[2009/03/10 12:09:32 | 00,000,000 | —D | C] – C:\Documents and Settings\AJ\Desktop\Child Devlopment
[2009/03/09 10:52:23 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\YesVideo
[2009/03/06 16:37:27 | 00,001,648 | —- | C] () – C:\Documents and Settings\AJ\Desktop\HijackThis.lnk
[2009/03/06 16:37:27 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/06 12:55:05 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/03/06 08:13:12 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/03/06 08:11:08 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/06 08:03:55 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/03/06 08:03:53 | 00,000,781 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Ad-Aware.lnk
[2009/03/06 07:54:04 | 00,000,000 | —D | C] – C:\Program Files\Adware_Pro

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\*.tmp files]
[12 C:\Documents and Settings\AJ\Desktop\*.tmp files]
[2009/03/26 16:24:28 | 00,061,440 | —- | M] () – C:\WINDOWS\System32\drivers\hjlf.sys
[2009/03/26 14:00:54 | 00,002,497 | —- | M] () – C:\Documents and Settings\AJ\Desktop\Microsoft Office Word 2003.lnk
[2009/03/26 12:41:32 | 00,000,610 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/26 12:40:50 | 00,000,366 | —- | M] () – C:\WINDOWS\tasks\RegCure.job
[2009/03/26 12:40:22 | 00,498,688 | —- | M] (OldTimer Tools) – C:\Documents and Settings\AJ\Desktop\OTListIt2.exe
[2009/03/26 12:39:56 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\AJ\Desktop\mbam-setup.exe
[2009/03/25 20:59:46 | 00,000,506 | —- | M] () – C:\Documents and Settings\AJ\Desktop\ERUNT.lnk
[2009/03/25 20:59:10 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\AJ\Desktop\erunt_setup.exe
[2009/03/25 20:36:18 | 00,022,528 | —- | M] () – C:\Documents and Settings\AJ\Desktop\R.doc
[2009/03/25 18:36:04 | 00,016,896 | —- | M] () – C:\Documents and Settings\AJ\Desktop\Budget Sheet.xls
[2009/03/25 09:41:22 | 00,019,456 | —- | M] () – C:\Documents and Settings\AJ\Desktop\Copy of peewee09.xls
[2009/03/25 09:31:24 | 00,013,376 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2009/03/25 08:47:48 | 00,000,051 | —- | M] () – C:\WINDOWS\iTouch.ini
[2009/03/25 08:45:40 | 00,013,002 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/25 08:43:22 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/25 08:43:14 | 26,794,3936 | -HS- | M] () – C:\hiberfil.sys
[2009/03/25 08:43:14 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/23 08:12:32 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/03/17 20:37:14 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk
[2009/03/15 20:09:50 | 00,033,792 | —- | M] () – C:\Documents and Settings\AJ\My Documents\French Style Fondue.doc
[2009/03/15 01:00:02 | 00,000,344 | —- | M] () – C:\WINDOWS\tasks\McDefragTask.job
[2009/03/14 11:11:06 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/12 18:33:32 | 00,003,809 | —- | M] () – C:\Documents and Settings\AJ\My Documents\Hot Leads.rtf
[2009/03/12 08:50:44 | 00,026,624 | —- | M] () – C:\Documents and Settings\AJ\Desktop\Script for Spanish Project.doc
[2009/03/12 03:22:36 | 00,263,824 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/12 03:05:38 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/11 18:46:12 | 00,000,162 | -H– | M] () – C:\Documents and Settings\AJ\My Documents\~$ench Style Fondue.doc
[2009/03/06 16:37:30 | 00,001,648 | —- | M] () – C:\Documents and Settings\AJ\Desktop\HijackThis.lnk
[2009/03/06 08:10:50 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/03/06 08:10:10 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/06 08:03:54 | 00,000,781 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Ad-Aware.lnk
[2009/03/05 14:06:52 | 00,230,400 | -HS- | M] () – C:\Documents and Settings\AJ\Desktop\Thumbs.db
[2009/03/01 17:18:34 | 00,031,232 | —- | M] () – C:\Documents and Settings\AJ\Desktop\To-Do.xls
[2009/03/01 01:00:02 | 00,000,346 | —- | M] () – C:\WINDOWS\tasks\McQcTask.job
[2009/02/25 14:50:14 | 00,068,840 | —- | M] () – C:\Documents and Settings\AJ\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe

========== LOP Check ==========

[2006/05/22 15:48:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data
[2008/12/30 23:40:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/03/06 08:03:56 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2006/05/24 13:11:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
[2007/12/26 20:12:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
[2007/01/26 18:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
[2008/08/31 16:34:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Citrix
[2007/05/29 09:44:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
[2008/12/31 17:19:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\DVD Shrink
[2009/02/14 14:58:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Google
[2008/10/31 19:52:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\HP
[2006/06/28 21:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Kodak
[2008/03/02 12:04:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
[2008/03/05 18:34:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Logitech
[2009/03/26 12:41:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
[2007/01/26 13:50:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
[2006/05/22 15:16:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee.com
[2006/05/22 15:47:46 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
[2007/04/30 12:32:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
[2007/01/04 22:08:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MSN6
[2008/12/31 17:03:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\NCH Software
[2006/06/28 21:25:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\QuickTime
[2008/03/05 18:11:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype
[2008/10/31 19:48:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Sonic
[2007/03/27 19:40:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony Corporation
[2007/01/24 20:59:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Support.com
[2007/04/16 18:55:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2007/01/25 21:33:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
[2006/07/23 15:42:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Windows Genuine Advantage
[2009/03/09 10:52:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\YesVideo
[2009/02/03 16:40:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\ZoomBrowser
[2006/05/22 15:48:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\AJ\Application Data
[2006/05/24 13:12:34 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Adobe
[2006/05/24 13:13:08 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\AdobeUM
[2007/10/08 20:13:18 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Ahead
[2007/01/26 18:22:36 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Apple Computer
[2009/02/03 17:56:02 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Canon
[2007/12/29 18:50:42 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\CopyTrans
[2008/12/02 17:29:00 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Costco Photo Organizer
[2008/12/02 16:54:16 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Costco Photo Viewer US
[2007/05/29 09:55:22 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\CyberLink
[2008/12/25 19:11:58 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Disney Mix It Plug-in
[2007/01/09 10:47:02 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Fisher-Price
[2008/04/01 14:18:46 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Google
[2007/08/16 09:33:42 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Help
[2008/09/01 14:20:46 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\H-ITT
[2008/10/31 19:55:00 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\HP
[2006/05/22 16:04:50 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Identities
[2006/06/22 20:58:54 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Lavasoft
[2006/05/29 22:08:12 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Macromedia
[2009/03/26 12:41:46 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Malwarebytes
[2008/08/31 12:49:08 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\McAfee
[2007/11/06 18:56:02 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\MGI
[2006/05/22 15:47:46 | 00,000,000 | –SD | M] – C:\Documents and Settings\AJ\Application Data\Microsoft
[2007/01/25 21:33:48 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Mozilla
[2007/01/04 22:08:34 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\MSN6
[2007/10/28 19:22:58 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\MyPublisher
[2008/12/02 19:26:22 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Picaboo
[2008/12/02 16:55:40 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Printer Info Cache
[2008/04/09 18:03:26 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\QuickVerse 2008
[2008/04/09 18:06:40 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Quickverse booksetup command line utility
[2008/12/31 17:13:46 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\RipIt4Me
[2008/03/05 18:18:42 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\skypePM
[2007/08/02 20:34:32 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Snapfish
[2007/03/27 19:39:04 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Sony Corporation
[2008/02/12 13:52:30 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Sun
[2007/01/25 21:33:46 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Talkback
[2008/04/14 21:45:18 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Viewpoint
[2008/12/31 17:16:32 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\Vso
[2008/09/26 11:07:10 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\webex
[2009/02/03 20:00:10 | 00,000,000 | —D | M] – C:\Documents and Settings\AJ\Application Data\ZoomBrowser EX
[2001/08/18 05:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/25 08:43:22 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/03/15 01:00:02 | 00,000,344 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2009/03/14 11:11:06 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/03/23 08:12:32 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/03/01 01:00:02 | 00,000,346 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2009/03/26 12:40:50 | 00,000,366 | —- | M] () – C:\WINDOWS\Tasks\RegCure.job

========== Purity Check ==========

< End of report >

Extra Report;

OTListIt Extras logfile created on: 3/26/2009 4:30:49 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\AJ\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.46 Mb Total Physical Memory | 87.55 Mb Available Physical Memory | 34.27% Memory free
962.51 Mb Paging File | 560.04 Mb Available in Paging File | 58.19% Paging File free
Paging file location(s): c:\pagefile.sys 384 768;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 21.12 Gb Free Space | 28.34% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 960.72 Mb Total Space | 660.03 Mb Free Space | 68.70% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 465.76 Gb Total Space | 337.03 Gb Free Space | 72.36% Space Free | Partition Type: NTFS

Computer Name: AJ-01G8QNUV9ZO7
Current User Name: AJ
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Disabled:Kodak Software Updater ()
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Kodak\Kodak EasyShare software\BIN\EasyShare.exe:*:Enabled:EasyShare ()
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype File not found
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent (McAfee, Inc.)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe ()
C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe ( )
C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{1A9DEF19-760C-4e01-958F-D9B8E6C61B90}" = c5100_Help
"{222285C2-037F-4AF9-83B3-B33A7288EC9D}" = Disney Mix It Plug-in
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{3E908702-AF35-4611-9518-955DA24B7E07}" = Microsoft XML Parser and SDK
"{432C3720-37BF-4BD7-8E49-F38E090246D0}" = CR2
"{4DDC3BED-CC68-44AA-B435-D727B620CA5B}" = Linksys Wireless-G PCI Adapter
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{54C8FE84-89C4-40E8-976C-439EB0729BD6}" = CardRd81
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.79
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_AccessR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_AccessR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_AccessR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_AccessR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_AccessR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_AccessR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_AccessR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0015-0000-0000-0000000FF1CE}" = Microsoft Office Access 2007
"{91120000-0015-0000-0000-0000000FF1CE}_AccessR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91190409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Publisher 2003
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}" = SFR2
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A70700000002}" = Adobe Reader 7.0.7
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B3B9BC18-2A09-4728-9B46-12E85FF3F628}" = C5100
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{B7EF4BD8-CA13-11D5-AE3D-005004B8E30C}" = Digital Photo Navigator 1.5
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon Camera WIA Driver
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{D1973749-F5E7-40EB-B528-F2B78685B9FF}" = essvcpt
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EDE721EC-870A-11D8-9D75-000129760D75}" = PowerDirector Express
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F5A83924-6A0A-40A2-9A9C-00D876B62E7F}" = FreeAgent Pro Tools
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FDE97748-2050-47B1-9BDD-E049626FDE63}" = Smartparts Desktop
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"A106663FD3361BDFACB045D83EBA03858EB1E411" = Windows Driver Package - FTDI CDM Driver Package (03/13/2008 2.04.06)
"AccessR" = Microsoft Office Access 2007
"ActiveTouchMeetingClient" = WebEx
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"CSCLIB" = Canon Camera Support Core Library
"DPP" = Canon Utilities Digital Photo Professional 3.4
"EOS Utility" = Canon Utilities EOS Utility
"ERUNT_is1" = ERUNT 1.1j
"F2F24872454C7CAEAABD8BB063F70FBEFF01989D" = Windows Driver Package - FTDI CDM Driver Package (03/13/2008 2.04.06)
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon EOS 5D WIA Driver
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"InstallShield_{F5A83924-6A0A-40A2-9A9C-00D876B62E7F}" = FreeAgent Pro Tools
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.0.6)" = Mozilla Firefox (3.0.6)
"MSC" = McAfee SecurityCenter
"MyCamera" = Canon Utilities MyCamera
"MyPublisher" = MyPublisher
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Original Data Security Tools" = Canon Utilities Original Data Security Tools
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"Pocket DVD Wizard" = Pocket DVD Wizard
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RegCure" = RegCure 1.5.0.1
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"WFTK" = Canon Utilities WFT-E1/E2/E3 Utility
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/24/2009 4:45:02 PM | Computer Name = AJ-01G8QNUV9ZO7 | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\McAfee\VirusScan\McShield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 876 (0x36c) Thread address : 0x7C90E4F4 Thread message : Build VSCORE.14.0.0.349
/ 5300.2777 Object being scanned = \Device\HarddiskVolume1\Documents and Settings\All
Users.WINDOWS\Application Data\McAfee\MNA\NAData-journal by c:\program files\common
files\mcafee\mna\mcnasvc.exe 4(30)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0)
7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 3/24/2009 8:06:11 PM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x10011e15.

Error - 3/25/2009 10:44:36 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 7

Error - 3/25/2009 10:48:38 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 7

Error - 3/25/2009 10:48:38 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 7

Error - 3/25/2009 10:49:42 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 7

Error - 3/25/2009 10:49:42 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 7

Error - 3/25/2009 11:43:43 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3306, faulting module
unknown, version 0.0.0.0, fault address 0x10001e15.

Error - 3/25/2009 11:44:09 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Application Error | ID = 1001
Description = Fault bucket 1196984710.

Error - 3/25/2009 6:48:09 PM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Application Hang | ID = 1002
Description = Hanging application mcshell.exe, version 8.1.133.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 3/24/2009 7:14:39 PM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.104 on
the Network Card with network address 000C416C4C1F.

Error - 3/25/2009 1:34:33 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = E100B | ID = 262148
Description = Adapter Intel® PRO/100+ Management Adapter: Adapter Link Down

Error - 3/25/2009 9:21:31 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = E100B | ID = 262148
Description = Adapter Intel® PRO/100+ Management Adapter: Adapter Link Down

Error - 3/25/2009 9:26:28 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = E100B | ID = 262148
Description = Adapter Intel® PRO/100+ Management Adapter: Adapter Link Down

Error - 3/25/2009 9:35:14 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Service Control Manager | ID = 7000
Description = The Logitech Process Monitor service failed to start due to the following
error: %%3

Error - 3/25/2009 9:35:14 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Service Control Manager | ID = 7000
Description = The LVSrvLauncher service failed to start due to the following error:
%%3

Error - 3/25/2009 10:44:43 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{511AF865-22B8-4845-BAD9-B48FC9E34247}
because another computer on the network has the same name. The server could not
start.

Error - 3/25/2009 10:44:53 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Service Control Manager | ID = 7000
Description = The Logitech Process Monitor service failed to start due to the following
error: %%3

Error - 3/25/2009 10:44:53 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Service Control Manager | ID = 7000
Description = The LVSrvLauncher service failed to start due to the following error:
%%3

Error - 3/25/2009 10:54:32 AM | Computer Name = AJ-01G8QNUV9ZO7 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the McShield service.


< End of report >
Hi jennau,

Let's see if we can find this guy.

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, into the "Suspicious files to scan" box on the top of the page:

    C:\WINDOWS\System32\drivers\hjlf.sys
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :file
    C:\WINDOWS\System32\drivers\wdmaud.sys
    C:\WINDOWS\System32\wdmaud.sys
    
    :reg
    HKEY_LOCAL_MACHINE\Microsoft\Windows NT\CurrentVersion\Drivers32
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post back with
  • Virus Scan results
  • SystemLook results
  • new HJT log

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI