This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Vundo, Redirect, Trojans suspected on my PC

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is what showed up after the computer rebooted. The notepad was already open. When I tried to follow instructions to go to notepad & locate log from there the OTMoveit3 folder was not on desktop after typing in *.log . Hope this helps & if so what should I do next? ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry value HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\totasaguja deleted successfully. Registry value HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\totasaguja deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLs"|"" /E : value set successfully! ========== FILES ========== File/Folder C:\WINNT\system32\mupitera.dll not found. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\HELENE~1\LOCALS~1\Temp\~DFA0D5.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\HELENE~1\LOCALS~1\Temp\~DFA0E0.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\HELENE~1\LOCALS~1\Temp\~DF6435.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\HELENE~1\LOCALS~1\Temp\~WRD0002.doc scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINNT\temp\WFV1.tmp scheduled to be deleted on reboot. File delete failed. C:\WINNT\temp\mcmsc_9ZEMPcew7sGWmoM scheduled to be deleted on reboot. File delete failed. C:\WINNT\temp\mcafee_efnhl7CbIeu21FV scheduled to be deleted on reboot. File delete failed. C:\WINNT\temp\mcmsc_JUEotPQbTt9BsCy scheduled to be deleted on reboot. File delete failed. C:\WINNT\temp\mcmsc_2mNFzmDeibxzfFG scheduled to be deleted on reboot. Windows Temp folder emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03282009_190519 Files moved on Reboot… File C:\DOCUME~1\HELENE~1\LOCALS~1\Temp\~DFA0D5.tmp not found! File C:\DOCUME~1\HELENE~1\LOCALS~1\Temp\~DFA0E0.tmp not found! File C:\DOCUME~1\HELENE~1\LOCALS~1\Temp\~DF6435.tmp not found! File C:\DOCUME~1\HELENE~1\LOCALS~1\Temp\~WRD0002.doc not found! C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully. File C:\WINNT\temp\WFV1.tmp not found! File C:\WINNT\temp\mcmsc_9ZEMPcew7sGWmoM not found! File C:\WINNT\temp\mcafee_efnhl7CbIeu21FV not found! File C:\WINNT\temp\mcmsc_JUEotPQbTt9BsCy not found! File C:\WINNT\temp\mcmsc_2mNFzmDeibxzfFG not found!
TomK, I still can't seem to run combofix. The hourglass starts to flash a couple of times after I double click it & then nothing happens. What do you want me to do now?
I went to windows explorer to search for C:\WINNT\system32\mupitra.dll file & after I started running a search Mcafee has a popup that RemAdm-ProcLaunch!171 was detected on my computer & that it might be harmful. It gave options of removing it, trusting it, or closing the alert. It indicated the location of the file is C:\32788R22FWJW\psexec. (can't read my writing on rest of it). I tried researching from my cell phone on whether it was a legitmate program that Mcafee was giving a false/positive on or an actual virus but couldn't find anything letting me know for sure either way. So I chose the remove button but when I clicked on that another screen popped up with

To Remove these programs using Mcafee uninstaller, click ok, or click cancel & then manually remove them using the vendors uninstaller. Programs that may have been installed as a bundle or suite are about to be removed. You may have a accepted a license agreement for these programs.

I don't know what to do & would really appreciate if someone could help me figure out if I should click cancel or ok to remove RemAdm-ProcLaunch!171
sweetiehlm5,

Please click Cancel. Your anti-virus is targeting ComboFix.

Let's try to run Combofix a different way. If this doen't work, we'll run a different tool.


A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

http://forums.whatthetech.com/How_to_Disab…ams_t89859.html



C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
sweetiehlm5,

Please click Cancel. Your anti-virus is targeting ComboFix.

Let's try to run Combofix a different way. If this doen't work, we'll run a different tool.


A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

http://forums.whatthetech.com/How_to_Disab…ams_t89859.html



C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
After I copied the single line command in the runbox & clicked OK I got the prompt that windows could not locate that file. So combofix still won't work.
sweetiehlm5,

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OTListIt logfile created on: 3/29/2009 1:02:32 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\Helene Lesueur\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.30 Mb Total Physical Memory | 274.61 Mb Available Physical Memory | 53.71% Memory free
1.22 Gb Paging File | 1.01 Gb Available in Paging File | 82.71% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 38.51 Gb Free Space | 68.90% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GUESTROOM
Current User Name: Helene Lesueur
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINNT\GWMDMMSG.exe (GTW)
PRC - C:\WINNT\system32\SK9910DM.EXE (Silitek Corporation)
PRC - C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe (Roxio)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\WINNT\system32\devldr32.exe (Creative Technology Ltd.)
PRC - C:\WINNT\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\McShield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\Helene Lesueur\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (CCALib8 [Auto | Running]) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINNT\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPodService [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.)
SRV - (lxdb_device [On_Demand | Stopped]) – C:\WINNT\system32\lxdbcoms.exe ( )
SRV - (mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) – C:\Program Files\McAfee\VirusScan\McShield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService [Auto | Running]) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PictureTaker [On_Demand | Stopped]) – File not found
SRV - (WinDefend [Auto | Stopped]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========
========== Driver Services (SafeList) ==========

DRV - (ac97intc [On_Demand | Running]) – C:\WINNT\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (aeaudio [On_Demand | Stopped]) – C:\WINNT\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AN983 [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\AN983.sys (ADMtek Incorporated.)
DRV - (ASPI32 [Auto | Running]) – C:\WINNT\System32\drivers\aspi32.sys (Adaptec)
DRV - (ati2mpaa [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\ati2mpaa.sys (ATI Technologies Inc.)
DRV - (ati2mtaa [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\ati2mtaa.sys (ATI Technologies Inc.)
DRV - (BCMModem [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\BCMDM.sys (BCM)
DRV - (Cdr4_xp [System | Running]) – C:\WINNT\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) – C:\WINNT\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cdrbsvsd [System | Running]) – C:\WINNT\System32\drivers\cdrbsvsd.sys (B.H.A Corporation)
DRV - (cdudf_xp [System | Running]) – C:\WINNT\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (ctac32k [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctljystk [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (ctprxy2k [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (DCamUSBSQTECH [On_Demand | Stopped]) – C:\WINNT\System32\Drivers\SQcaptur.sys (Service & Quality Technology.)
DRV - (dvd_2K [On_Demand | Stopped]) – C:\WINNT\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (E100B [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (emu10k [On_Demand | Running]) – C:\WINNT\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (emu10k1 [On_Demand | Running]) – C:\WINNT\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emupia [On_Demand | Stopped]) – C:\WINNT\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (Eplpdx02 [On_Demand | Running]) – C:\WINNT\System32\Drivers\EPLPDX02.SYS (MK Systems CO., LTD.)
DRV - (gameenum [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINNT\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (GTWModem [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\GWMDM.sys (GTW)
DRV - (ha10kx2k [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (ialm [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (L8042pr2 [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\L8042pr2.Sys (Logitech, Inc.)
DRV - (LHidFlt2 [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\LHidFlt2.Sys (Logitech, Inc.)
DRV - (LHidUsb [On_Demand | Running]) – C:\WINNT\System32\Drivers\LHidUsb.Sys (Logitech, Inc.)
DRV - (LMouFlt2 [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\LMouFlt2.Sys (Logitech, Inc.)
DRV - (mfeavfk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) – C:\WINNT\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) – C:\WINNT\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mmc_2K [On_Demand | Running]) – C:\WINNT\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINNT\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (MPFP [System | Running]) – C:\WINNT\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (MR97310_VGA_DUAL_CAMERA [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\mr97310v.sys (Mars Semiconductor Corp.)
DRV - (ms_mpu401 [On_Demand | Stopped]) – C:\WINNT\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NwlnkIpx [Auto | Running]) – C:\WINNT\System32\DRIVERS\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb [Auto | Running]) – C:\WINNT\System32\DRIVERS\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx [Auto | Running]) – C:\WINNT\System32\DRIVERS\nwlnkspx.sys (Microsoft Corporation)
DRV - (ossrv [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pwd_2k [System | Running]) – C:\WINNT\System32\drivers\pwd_2K.sys (Roxio)
DRV - (PxHelp20 [Boot | Running]) – C:\WINNT\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfman [On_Demand | Running]) – C:\WINNT\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (Sk99202k [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\Sk99202k.sys (Silitek Corp.)
DRV - (Sk9920nt [System | Running]) – C:\WINNT\System32\DRIVERS\Sk9920nt.sys (Silitek Corp.)
DRV - (smwdm [On_Demand | Stopped]) – C:\WINNT\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (sonypvs1 [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\sonypvs1.sys (Sony Corporation)
DRV - (UdfReadr_xp [System | Running]) – C:\WINNT\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (ultra [Disabled | Stopped]) – C:\WINNT\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINNT\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (wandrv [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\wandrv.sys (America Online, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [System | Stopped]) – C:\WINNT\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.comcast.net/comcast.html"



[2006/07/17 20:02:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Helene Lesueur\Application Data\mozilla\Firefox\Profiles\5mmw5ggf.default\extensions
[2006/07/17 20:02:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2006/07/17 20:02:46 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

O1 HOSTS File: (734 bytes) - C:\WINNT\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" (Roxio)
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [FlipViewer Library] C:\Program Files\E-Book Systems\FlipViewer\\FlipViewerLibrary.exe /showmode=hide File not found
O4 - HKLM..\Run: [GWMDMMSG] GWMDMMSG.exe (GTW)
O4 - HKLM..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE (Silitek Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc.)
O4 - HKLM..\Run: [Logitech Utility] Logi_MwX.Exe (Logitech Inc.)
O4 - HKLM..\Run: [LXDBCATS] rundll32 C:\WINNT\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server (Support.com, Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINNT\System32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Sites: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Sites: mcafee.com ([]https in Trusted sites)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/OneClickFix/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/0/f…tualEarth3D.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} http://www.rockyou.com/RockYouImageUploader.cab (RockYou Image Uploader Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ic32pp {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - C:\WINNT\wc98pp.dll ()
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINNT\system32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msansspc.dll) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[3 C:\WINNT\*.tmp files]
[2009/03/29 01:00:59 | 00,498,688 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Helene Lesueur\Desktop\OTListIt2.exe
[2009/03/29 00:27:18 | 53,620,3264 | -HS- | C] () – C:\hiberfil.sys
[2009/03/29 00:26:14 | 00,000,000 | —D | C] – C:\32788R22FWJFW
[2009/03/29 00:25:26 | 00,000,000 | —D | C] – C:\32788R22FWJFW.0.tmp
[2009/03/28 23:52:31 | 02,936,706 | —- | C] () – C:\Documents and Settings\Helene Lesueur\Desktop\CombFix.exe
[2009/03/28 21:28:47 | 00,028,672 | —- | C] () – C:\Documents and Settings\Helene Lesueur\My Documents\PROCESSES.doc
[2009/03/28 19:05:19 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/03/28 18:57:55 | 00,389,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Helene Lesueur\Desktop\OTMoveIt3.exe
[2009/03/28 18:50:35 | 00,000,280 | —- | C] () – C:\Documents and Settings\Helene Lesueur\Desktop\Fix.reg
[2009/03/28 18:08:10 | 00,000,000 | —D | C] – C:\WINNT\ERDNT
[2009/03/28 18:04:39 | 00,000,000 | —D | C] – C:\Documents and Settings\Helene Lesueur\Desktop\erunt
[2009/03/28 17:50:17 | 00,513,320 | —- | C] () – C:\Documents and Settings\Helene Lesueur\Desktop\erunt.zip
[2009/03/28 15:17:02 | 00,389,120 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\cmd.execf
[2009/03/28 14:18:28 | 00,052,224 | —- | C] () – C:\Documents and Settings\Helene Lesueur\My Documents\Hi sweetiehlm5.doc
Tomk, I was able to get most of the otlist.txt before i started getting redirected another whatthetech page stating I was redirected due to hijacklog being outdated. Can you help me finish posting the rest of the otlist.txt & then the extras.txt?
Still getting redirected. It says I am using an outdated version of hijackthis & should update to latest version. Should I click on the update for the latest version from that whatthetech screen I am getting redirected to?
OTListIt Extras logfile created on: 3/29/2009 1:02:32 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\Helene Lesueur\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.30 Mb Total Physical Memory | 274.61 Mb Available Physical Memory | 53.71% Memory free
1.22 Gb Paging File | 1.01 Gb Available in Paging File | 82.71% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 38.51 Gb Free Space | 68.90% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GUESTROOM
Current User Name: Helene Lesueur
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® (Microsoft Corporation)
C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server (Yahoo! Inc.)
C:\Program Files\Windows Media Player\WMPLAYER.EXE:*:Enabled:wmplayer (Microsoft Corporation)
C:\Program Files\Replay Radio 5\ReplayRadio.exe:*:Enabled:Replay Radio 5.2 (Applian Technologies Inc.)
C:\Program Files\Replay Player\Replay Player.exe:*:Enabled:Replay Player ()
C:\Program Files\Radio Wizard\RadioWizard.exe:*:Enabled:Radio Wizard ()
C:\Program Files\MP3 Magic\MP3Magic.exe:*:Enabled:MP3 Magic (Yaosoft)
C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer (Microsoft Corporation)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Computer, Inc.)
C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Engine File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox (Yahoo! Inc.)
C:\Program Files\SUPPORT.COM\BIN\TGCMD.EXE:*:Enabled:Support.com Scheduler and Command Dispatcher (Support.com, Inc.)
C:\WINNT\EXPLORER.EXE:*:Enabled:Explorer (Microsoft Corporation)
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE:*:Enabled:OSE (Microsoft Corporation)
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent (McAfee, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{1FABA7C7-6DC0-11D6-9EAB-0050BAE317E1}" = VideoLive Mail
"{225AF9A1-B556-88D5-94AA-0010B5426419}" = My DSC
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4ecaf021-478c-40c1-b777-3368a15f9966}" = Macromedia Flash Player
"{54C0D94A-F467-4ABC-9D02-6E58748668D4}" = iTunes
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.79
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{6BC2C9ED-FD77-4A7A-BF2B-B4E7C073F66E}" = LEADTOOLS ePrint IV EVAL
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® 845G Chipset Graphics Driver Software
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90840409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel Viewer 2003
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A3EABC0-CA06-11D4-BF77-00104B130C19}" = EPSON TWAIN 5
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A0CF60B8-5156-11D5-A970-0050DA0F190F}" = SoundClick MP3 Player
"{A260B422-70E1-41E2-957D-F76FA21266D5}" = Apple Software Update
"{A8A3862C-3280-11D6-B2EA-0050BA18806B}" = Camera Driver
"{AC76BA86-7AD7-1033-7B44-A70700000002}" = Adobe Reader 7.0.7
"{B423A661-0726-405A-AFE9-C44CCB8036BA}" = DV 4100M
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{C1939820-A945-11D4-86F6-0001031E5712}" = DVD Player
"{C3A439E4-7303-491F-A678-CEA36A87D517}" = Microsoft Works Suite Add-in for Microsoft Word
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
"{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}" = Yahoo! Music Jukebox
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"AdobeESD" = Adobe Download Manager 2.0 (Remove Only)
"ArcSoft PhotoImpression 3.0" = ArcSoft PhotoImpression 3.0
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"Click'N Design 3D (V5)" = Click'N Design 3D (V5)
"Copy Utility" = Copy Utility
"Creative Driver" = Creative Driver
"CSCLIB" = Canon Camera Support Core Library
"CutePDF Writer Installation" = CutePDF Writer 2.7
"EOS Utility" = Canon Utilities EOS Utility
"Focus Magic_is1" = Focus Magic 3.02
"GTW V.92 Voice Modem" = GTW V.92 Voice Modem
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"IMSI Utilities" = IMSI Utilities
"Inkscape" = Inkscape 0.45.1
"kSolo" = kSolo Recorder
"Lexmark 840 Series" = Lexmark 840 Series
"Logitech Resource Center" = Logitech Resource Center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Masque Slots II" = Masque Slots II
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MP3_Magic_1.0" = MP3 Magic 1.21
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Network Play System (Patching)" = Network Play System (Patching)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OmniFormat" = OmniFormat
"Pdf995" = Pdf995
"PROSet" = Intel® PRO Ethernet Adapter and Software
"Radio_Wizard_1" = Radio Wizard 1.0
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"Replay_Player_for_the_PC_1.0" = Replay Player
"SK_PS2MillenniumKeyboard" = PS/2 Millennium Keyboard
"SonicShack Design Studio_is1" = SonicShack Designer Adobe AIR version
"VB Runtime" = VB Runtime
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.4.6
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wondershare DVD to WMV Converter_is1" = Wondershare DVD to WMV Converter(Build 3.2.47)
"Works2002Setup" = Microsoft Works 2002 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Customizations" = Yahoo! extras
"Yahoo! Internet Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Messenger Explorer Bar" = Yahoo! Messenger Explorer Bar
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Abacast Client" = Abacast Client
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/21/2009 9:38:27 PM | Computer Name = GUESTROOM | Source = McLogEvent | ID = 5051
Description = A thread in process C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe took
longer than 90000 ms to complete a request. The process will be terminated. Thread
id : 2636 (0xa4c) Thread address : 0x7C90E4F4 Thread message : Build VSCORE.14.0.0.349
/ 5300.2777 Object being scanned = \Device\HarddiskVolume1\WINNT\system32\wotifiri.dll

by C:\WINNT\system32\Rundll32.exe 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0)

7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 3/27/2009 10:27:47 AM | Computer Name = GUESTROOM | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module mshtml.dll, version 7.0.6000.16809, fault address 0x0003c1b5.

Error - 3/27/2009 7:19:21 PM | Computer Name = GUESTROOM | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80072f78, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 3/27/2009 8:04:18 PM | Computer Name = GUESTROOM | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80072f78, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 3/27/2009 8:09:25 PM | Computer Name = GUESTROOM | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80072f78, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 3/27/2009 9:01:40 PM | Computer Name = GUESTROOM | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module mshtml.dll, version 7.0.6000.16809, fault address 0x0009207e.

Error - 3/28/2009 3:49:20 PM | Computer Name = GUESTROOM | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module ntdll.dll, version 5.1.2600.5512, fault address 0x00037423.

Error - 3/28/2009 3:49:36 PM | Computer Name = GUESTROOM | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 3/28/2009 4:00:18 PM | Computer Name = GUESTROOM | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module urlmon.dll, version 7.0.6000.16791, fault address 0x0002d25b.

Error - 3/28/2009 11:54:09 PM | Computer Name = GUESTROOM | Source = Microsoft Office 10 | ID = 1000
Description = Faulting application winword.exe, version 10.0.2627.0, faulting module
unknown, version 0.0.0.0, fault address 0x10041e39.

[ System Events ]
Error - 3/29/2009 12:27:44 AM | Computer Name = GUESTROOM | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 3/29/2009 12:27:44 AM | Computer Name = GUESTROOM | Source = Service Control Manager | ID = 7000
Description = The Concord EyeQ Duo 1300 USB Video Capture V1.01 service failed to
start due to the following error: %%2

Error - 3/29/2009 12:29:04 AM | Computer Name = GUESTROOM | Source = Print | ID = 23
Description = Printer Export To Web failed to initialize because a suitable Web
Export driver could not be found.

Error - 3/29/2009 12:34:30 AM | Computer Name = GUESTROOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service lxdb_device
with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441097}

Error - 3/29/2009 12:34:30 AM | Computer Name = GUESTROOM | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdb_device service to
connect.

Error - 3/29/2009 12:34:30 AM | Computer Name = GUESTROOM | Source = Service Control Manager | ID = 7000
Description = The lxdb_device service failed to start due to the following error:
%%1053

Error - 3/29/2009 12:34:39 AM | Computer Name = GUESTROOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service lxdb_device
with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441097}

Error - 3/29/2009 12:51:24 AM | Computer Name = GUESTROOM | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 3/29/2009 12:51:24 AM | Computer Name = GUESTROOM | Source = Service Control Manager | ID = 7000
Description = The Concord EyeQ Duo 1300 USB Video Capture V1.01 service failed to
start due to the following error: %%2

Error - 3/29/2009 12:51:53 AM | Computer Name = GUESTROOM | Source = Print | ID = 23
Description = Printer Export To Web failed to initialize because a suitable Web
Export driver could not be found.


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI