This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] is my computer infected

42 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Almar, How did you try to run it? Did you use the command I posted to paste into the run box? Did you copy and paste it in it's entirety including the " at the begining? Thanks
Hi Almar,

Let's try this from a clean slate. One more time then we'll use a different tool.

Delete worksnow.exe from your desktop.

Open OTMoveIt3 then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

Download a new copy of worksnow.exe and use the same command as before. Accept any warnings.

Please post back with
  • the notepad you saved
  • the worksnow (combofix) log
  • new HJT log
Thanks
Hi Almar,

Thanks for trying.


Download avz4.zip from here
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: [external image: Posted Image]
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again
  • After the update, from the "File" menu, choose "Standard Scripts"
  • Put a check next to item 2: Advanced System Investigation
  • Click Execute selected scripts
  • At the next prompt, click the OK button
  • Let the scan run and click "OK" when the completion prompt pops up
  • Now Close out of the Standard Scripts window, and exit AVZ
  • Navigate to the avz4 folder and locate the folder LOG
  • Inside the LOG folder you will find virusinfo_syscheck.htm and virusinfo_syscheck.zip
  • Attach virusinfo_syscheck.zip to your next reply, along with a fresh HijackThis log

Thanks
Hi oldman Good news! I have not done your last request.The reason is that when I tried booting to normal mode this morning everything seemed to be working ok so far. which is just great and thanks to you. I believe what we did in the last operation in deleting antivirus programs and disabling AOL safety and security program has done part of the job. the only problem now I have no safety programs running on the computer, and I would like your advise on what to install or activate. I do have Windows Defender still installed and also AOL antivirus programs which are both disabled. I would appreciate your advise and please don't close this forum dialog until I report to you after knowing for certain that all is well after having used the computer for few more days just to be absolutely certain. I do thank you very much for the good work you have done and for your patience. Almar
Hi almar,

That is good news. Now that you are in normal windows let's try a few scans. We'll start with a non intrusive scan first.


Download OTListIt2 to your desktop.
  • Double click on OTList2.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

No need for a Hijackthis log this time.


Thanks
Hi oldman

This is the OT list2:

OTListIt logfile created on: 2009-04-08 14:52:56 - Run 1
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Documents and Settings\al\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd

254.98 Mb Total Physical Memory | 95.83 Mb Available Physical Memory | 37.58% Memory free
626.95 Mb Paging File | 253.22 Mb Available in Paging File | 40.39% Paging File free
Paging file location(s): C:\pagefile.sys 385 1000;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.22 Gb Total Space | 16.21 Gb Free Space | 43.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MIULING
Current User Name: al
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
PRC - C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe (AOL LLC)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe (America Online Inc)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\mcafee.com\antivirus\McShield.exe (McAfee Inc.)
PRC - C:\Program Files\mcafee.com\personal firewall\MPFService.exe (McAfee Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\mcafee.com\personal firewall\MPFTray.exe (McAfee Security)
PRC - C:\Program Files\Common Files\logishrd\WUApp32.exe ()
PRC - C:\Program Files\Common Files\AOL\1159552586\ee\SSCEvtHdlr.exe (America Online)
PRC - C:\Program Files\Common Files\AOL\1159552586\EE\aolsoftware.exe (AOL LLC)
PRC - C:\Program Files\Common Files\AOL\1159552586\EE\aolsoftware.exe (AOL LLC)
PRC - C:\Program Files\Common Files\AOL\1159552586\EE\anotify.exe (AOL LLC)
PRC - C:\WINDOWS\system32\sndvol32.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Messenger\livecall.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE (Microsoft Corporation)
PRC - C:\Documents and Settings\al\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (AOL TopSpeedMonitor [Auto | Running]) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
SRV - (aolavupd [Auto | Running]) – C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe (AOL LLC)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (McciCMService [Auto | Running]) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (McShield [Auto | Running]) – C:\Program Files\mcafee.com\antivirus\McShield.exe (McAfee Inc.)
SRV - (MpfService [Auto | Running]) – C:\Program Files\mcafee.com\personal firewall\MPFService.exe (McAfee Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WANMiniportService [Auto | Running]) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ac97intc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (aliidex [Boot | Running]) – C:\WINDOWS\System32\drivers\aliidex.sys (Windows ® 2000 DDK provider)
DRV - (aliperf [Boot | Running]) – C:\WINDOWS\system32\drivers\aliperf.sys (Windows ® 2000 DDK provider)
DRV - (AN983 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\AN983.sys (ADMtek Incorporated.)
DRV - (ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (basic2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\basic2.sys (Conexant Systems)
DRV - (brfilt [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\Brfilt.sys (Brother Industries Ltd.)
DRV - (BrSerWDM [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbScn [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrUsbScn.sys (Brother Industries Ltd.)
DRV - (Cnxtdiag [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\cnxtdiag.sys (Conexant Systems)
DRV - (epstw2k [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\epstw2k.sys (Microsoft Corporation)
DRV - (Fallback [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\fallback.sys (Conexant Systems)
DRV - (Fsks [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\fsksnt.sys (Conexant Systems)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (hidgame [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\hidgame.sys (Microsoft Corporation)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (hsf_msft [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys (Conexant)
DRV - (ICAM3NT5 [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\Icam3.sys (Microsoft Corporation)
DRV - (is-2K4OTdrv [System | Running]) – C:\WINDOWS\system32\DRIVERS\31724632.sys (Kaspersky Lab)
DRV - (K56 [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\k56nt.sys (Conexant Systems)
DRV - (mf [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\mf.sys (Microsoft Corporation)
DRV - (MPFIREWL [System | Running]) – C:\WINDOWS\System32\Drivers\MpFirewall.sys (McAfee)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (NaiAvFilter1 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\naiavf5x.sys (McAfee Inc.)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (RimUsb [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RimUsb.sys (Research In Motion Limited)
DRV - (RimVSerPort [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\RimSerial.sys (Research in Motion Ltd)
DRV - (Rksample [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\rksample.sys (Conexant Systems)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (scsiscan [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\scsiscan.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Ser2pl [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ser2pl.sys (Prolific Technology Inc.)
DRV - (sfdrv01 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (sfsync02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (SoftFax [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\faxnt.sys (Conexant Systems)
DRV - (Tones [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\tonesnt.sys (Conexant Systems)
DRV - (V124 [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\v124nt.sys (Conexant Systems)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems)
DRV - (CamDrL [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Camdrl.sys (Logitech Inc.)
DRV - (LVUSBSta [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (usbaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {C156E417-9A64-4EAC-A086-55F394343BB5}:1.0
FF - prefs.js..extensions.enabledItems: {C23BDED9-5414-4EFD-ACC9-64BFDCB0023C}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\Extensions\\{C156E417-9A64-4EAC-A086-55F394343BB5}: C:\DOCUMENTS AND SETTINGS\AL\LOCAL SETTINGS\APPLICATION DATA\{C156E417-9A64-4EAC-A086-55F394343BB5} [2008-12-17 13:24:44 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{C23BDED9-5414-4EFD-ACC9-64BFDCB0023C}: C:\DOCUMENTS AND SETTINGS\MARIAN\LOCAL SETTINGS\APPLICATION DATA\{C23BDED9-5414-4EFD-ACC9-64BFDCB0023C}\ [2009-03-02 10:06:45 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009-04-02 20:53:12 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009-03-28 20:12:37 | 00,000,000 | —D | M]

[2008-12-16 21:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\mozilla\Extensions
[2008-12-16 21:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008-12-16 21:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\mozilla\Firefox\Profiles\0fe092zp.default\extensions
[2008-12-16 21:14:05 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009-03-28 20:12:37 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-03-28 20:12:25 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-03-28 20:12:25 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-03-13 09:46:19 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009-03-13 09:46:19 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009-03-13 09:46:19 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009-03-13 09:46:19 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009-03-13 09:46:19 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-03-13 09:46:19 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009-03-13 09:46:19 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (BellSouth Toolbar) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\Program Files\blstoolbar\blstoolbar.dll ()
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (ST) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (MSNToolBandBHO) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - File not found
O3 - HKLM\..\Toolbar: (BellSouth Toolbar) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\Program Files\blstoolbar\blstoolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (MSN) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\Program Files\blstoolbar\blstoolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [MPFEXE] "C:\Program Files\mcafee.com\personal firewall\MPFTray.exe" (McAfee Security)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - Startup: C:\Documents and Settings\al\Start Menu\Programs\Startup\is-2K4OT.lnk = C:\Documents and Settings\al\Desktop\Virus Removal Tool\is-2K4OT\startup.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} https://objects.aol.com/mcafee/molbin/share…83/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by7fd.bay7.hotmail.msn.com/resources/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/sit…b?1199841972187 (MUCatalogWebControl Class)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1199841588625 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…7387.6772222222 (Reg Error: Key error.)
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} http://www.ravantivirus.com/scan/ravonline.cab (CRAVOnline Object)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} https://objects.aol.com/mcafee/molbin/share…,20/McGDMgr.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/controls/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[6 C:\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009-04-08 14:46:59 | 00,500,736 | —- | C] (OldTimer Tools) – C:\Documents and Settings\al\Desktop\OTListIt2.exe
[2009-04-08 13:49:22 | 00,059,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2009-04-08 13:49:22 | 00,059,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2009-04-08 13:47:57 | 00,000,000 | —D | C] – C:\Program Files\Common Files\logishrd
[2009-04-08 13:47:40 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood
[2009-04-08 07:45:44 | 26,744,0128 | -HS- | C] () – C:\hiberfil.sys
[2009-04-08 01:07:31 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF12995.exe
[2009-04-08 01:07:17 | 00,000,000 | —D | C] – C:\32788R22FWJFW
[2009-04-08 00:49:24 | 03,307,596 | R— | C] () – C:\Documents and Settings\al\Desktop\worksnow.exe
[2009-04-07 22:56:32 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF20066.exe
[2009-04-07 22:54:28 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF19550.exe
[2009-04-07 21:13:48 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF32735.exe
[2009-04-07 19:58:23 | 00,000,000 | —D | C] – C:\worksnow
[2009-04-07 19:37:26 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF13856.exe
[2009-04-07 16:56:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009-04-07 16:50:12 | 03,063,218 | —- | C] (Symantec Corporation) – C:\Documents and Settings\al\Desktop\Norton_Removal_Tool.exe
[2009-04-07 09:37:45 | 00,091,648 | —- | C] () – C:\Documents and Settings\al\Desktop\SystemLook.exe
[2009-04-06 08:29:41 | 01,841,184 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009-04-06 08:29:41 | 00,004,124 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009-04-05 10:36:45 | 00,001,833 | —- | C] () – C:\Documents and Settings\al\Start Menu\Programs\Startup\is-2K4OT.lnk
[2009-04-05 10:35:38 | 00,148,496 | —- | C] (Kaspersky Lab) – C:\WINDOWS\System32\drivers\31724632.sys
[2009-04-05 10:35:38 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Desktop\Virus Removal Tool
[2009-04-05 10:23:49 | 37,352,800 | —- | C] ( ) – C:\Documents and Settings\al\Desktop\setup_7.0.0.290_05.04.2009_16-12.exe
[2009-04-04 17:56:27 | 00,097,759 | —- | C] () – C:\Documents and Settings\al\Desktop\user.zip
[2009-04-03 16:18:09 | 00,000,000 | —- | C] () – C:\Documents and Settings\al\Desktop\drweb-cureit.exe
[2009-04-03 16:18:00 | 01,516,400 | —- | C] (Doctor Web, Ltd.) – C:\Documents and Settings\al\Desktop\drweb-cureit.exe.part
[2009-04-03 14:20:44 | 00,360,002 | —- | C] () – C:\Documents and Settings\al\Desktop\dds.pif
[2009-04-02 17:09:13 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Desktop\RootRepeal
[2009-04-02 17:01:26 | 00,440,104 | —- | C] () – C:\Documents and Settings\al\Desktop\RootRepeal.zip
[2009-04-02 11:25:13 | 00,000,000 | —D | C] – C:\32788R22FWJFW.0.tmp
[2009-04-02 11:08:02 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009-04-02 11:02:00 | 00,000,592 | —- | C] () – C:\Documents and Settings\al\Desktop\ERUNT.lnk
[2009-04-02 11:01:59 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009-04-02 10:55:57 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\al\Desktop\erunt-setup.exe
[2009-03-31 19:13:43 | 00,001,734 | —- | C] () – C:\Documents and Settings\al\Desktop\HijackThis.lnk
[2009-03-31 19:13:43 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009-03-31 14:03:14 | 00,000,868 | —- | C] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009-03-31 12:58:20 | 00,000,000 | —D | C] – C:\Documents and Settings\al\My Documents\Hijackthis
[2009-03-31 12:39:59 | 00,115,671 | —- | C] () – C:\Documents and Settings\al\My Documents\duaa.jpg
[2009-03-27 18:50:56 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
[2008-12-14 12:25:06 | 00,007,027 | —- | C] () – C:\WINDOWS\ajazimimimesu.dll
[2008-12-14 12:15:15 | 00,007,031 | —- | C] () – C:\WINDOWS\esadiwox.dll
[2008-01-03 18:27:54 | 00,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2007-06-04 23:21:04 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2007-06-04 23:20:25 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2007-02-03 08:59:04 | 00,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007-01-14 19:28:13 | 00,002,324 | —- | C] () – C:\WINDOWS\BRMFBIDI.INI
[2006-10-22 13:22:00 | 00,212,992 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006-05-23 14:28:44 | 00,000,208 | —- | C] () – C:\WINDOWS\Dit.INI
[2006-05-23 14:28:43 | 00,139,264 | —- | C] () – C:\WINDOWS\Dit.DLL
[2006-05-12 15:49:42 | 00,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006-05-12 15:43:15 | 00,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006-03-18 04:11:02 | 00,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005-11-22 18:37:26 | 00,000,073 | —- | C] () – C:\WINDOWS\upst.ini
[2005-08-20 15:18:31 | 00,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2005-07-18 17:26:05 | 00,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2005-06-09 16:46:15 | 00,000,062 | —- | C] () – C:\WINDOWS\draw.ini
[2005-06-09 16:41:53 | 00,000,158 | —- | C] () – C:\WINDOWS\estud.ini
[2005-04-27 14:38:00 | 00,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2005-04-27 14:37:49 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2005-04-01 17:16:00 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005-04-01 17:16:00 | 01,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005-04-01 17:16:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005-04-01 17:16:00 | 00,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005-04-01 17:16:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005-04-01 17:16:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2004-11-28 21:33:16 | 00,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2004-10-16 00:11:19 | 00,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004-10-16 00:11:19 | 00,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2004-10-15 23:48:16 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004-09-28 13:10:22 | 00,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004-06-24 19:02:30 | 00,000,043 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2004-06-24 12:17:19 | 00,000,000 | —- | C] () – C:\WINDOWS\QFN.ini
[2004-06-24 12:13:51 | 00,000,028 | —- | C] () – C:\WINDOWS\ICOA.INI
[2004-06-24 12:10:22 | 00,000,650 | —- | C] () – C:\WINDOWS\intuprof.ini
[2004-06-24 12:10:21 | 00,001,687 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004-06-24 12:10:17 | 00,000,252 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2004-06-24 12:10:14 | 00,207,872 | —- | C] () – C:\WINDOWS\System32\RDMWIN32.DLL
[2004-06-24 12:09:54 | 00,000,054 | —- | C] () – C:\WINDOWS\QFP.INI
[2004-06-24 12:09:54 | 00,000,054 | —- | C] () – C:\WINDOWS\MFF.INI
[2004-06-01 17:47:14 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004-05-31 00:32:50 | 00,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2004-05-31 00:32:49 | 00,000,027 | —- | C] () – C:\WINDOWS\upth.ini
[2004-03-19 16:05:29 | 00,002,415 | —- | C] () – C:\WINDOWS\TRA.INI
[2004-01-22 12:00:28 | 00,012,635 | —- | C] () – C:\WINDOWS\System32\DAntivirus.ini
[2003-12-04 12:59:49 | 00,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2003-10-09 08:18:08 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\missouri.dll
[2003-07-19 14:25:06 | 00,000,087 | —- | C] () – C:\WINDOWS\WALLSTRT.INI
[2003-03-27 15:28:44 | 00,004,955 | —- | C] () – C:\WINDOWS\System32\DProg.ini
[2003-02-08 18:35:07 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2003-02-08 18:34:37 | 00,000,056 | —- | C] () – C:\WINDOWS\winhelp.ini
[2003-02-08 18:34:24 | 00,795,548 | —- | C] () – C:\WINDOWS\System32\ica2.dll
[2003-02-08 18:33:33 | 01,523,712 | —- | C] () – C:\WINDOWS\System32\VARIETYPACKLOCALIZATION.DLL
[2003-02-08 18:33:32 | 01,830,912 | —- | C] () – C:\WINDOWS\System32\RFVPB.dll
[2003-02-08 18:33:32 | 01,699,840 | —- | C] () – C:\WINDOWS\System32\RFVPS.dll
[2003-02-08 18:33:32 | 00,401,408 | —- | C] () – C:\WINDOWS\System32\rfutils.dll
[2003-02-08 18:33:32 | 00,335,872 | —- | C] () – C:\WINDOWS\System32\RFVPPTB.dll
[2003-02-08 18:33:32 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\GenericVFW.dll
[2003-02-08 18:33:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\rfnullvideo.dll
[2003-02-08 18:33:32 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\RFInstallRoutines.dll
[2003-02-08 18:32:58 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2002-11-01 16:17:50 | 00,000,256 | —- | C] () – C:\WINDOWS\aucfg.ini
[2002-09-14 15:39:29 | 00,000,069 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2002-08-05 20:40:52 | 00,002,586 | —- | C] () – C:\WINDOWS\Xtreme.ini
[2002-07-04 15:05:34 | 00,000,269 | —- | C] () – C:\WINDOWS\tmupdate.ini
[2002-06-12 17:50:29 | 00,000,074 | —- | C] () – C:\WINDOWS\eFaxView.ini
[2002-05-22 10:53:49 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2002-05-01 17:35:17 | 00,000,355 | —- | C] () – C:\WINDOWS\EXLAW.INI
[2002-05-01 17:35:17 | 00,000,103 | —- | C] () – C:\WINDOWS\HIGHEDIT.INI
[2002-02-20 21:19:51 | 00,000,304 | —- | C] () – C:\WINDOWS\hpccopy.INI
[2002-02-19 19:53:46 | 00,000,928 | —- | C] () – C:\WINDOWS\System32\hpsj1695.dll
[2002-02-19 19:53:44 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2002-02-19 19:53:43 | 00,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2002-02-19 18:09:02 | 00,000,074 | —- | C] () – C:\WINDOWS\hpsjbmgr.ini
[2002-02-18 20:08:57 | 00,000,029 | —- | C] () – C:\WINDOWS\qbwcd.ini
[2002-02-18 20:07:15 | 00,003,275 | —- | C] () – C:\WINDOWS\WININIT.INI
[2002-02-18 20:06:18 | 00,001,385 | —- | C] () – C:\WINDOWS\QfnOnl.ini
[2002-02-18 20:06:08 | 00,000,362 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2002-02-18 20:06:08 | 00,000,038 | —- | C] () – C:\WINDOWS\ACCWIZ.INI
[2002-02-18 20:06:08 | 00,000,021 | —- | C] () – C:\WINDOWS\QFNOA.INI
[2002-02-17 21:20:27 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2002-01-05 12:53:40 | 00,000,482 | —- | C] () – C:\WINDOWS\ODBC.INI
[2001-12-21 15:19:36 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2001-12-21 15:02:52 | 00,000,884 | —- | C] () – C:\WINDOWS\orun32.ini
[2001-12-21 15:00:48 | 00,000,777 | —- | C] () – C:\WINDOWS\lrun32.ini
[2001-12-21 13:38:43 | 00,001,012 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001-12-21 13:38:43 | 00,000,433 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2001-12-21 13:38:09 | 00,001,899 | —- | C] () – C:\WINDOWS\win.ini
[2001-12-21 13:38:02 | 00,000,491 | —- | C] () – C:\WINDOWS\SYSTEM.INI
[2001-12-21 13:37:33 | 00,000,325 | —- | C] () – C:\WINDOWS\System32\ntnet.drv
[2001-12-14 13:34:46 | 00,164,864 | —- | C] () – C:\WINDOWS\patchw32.dll
[1999-07-23 13:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999-07-23 10:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999-01-22 14:46:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998-01-12 04:00:00 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\REGOBJ.DLL
[1997-10-24 15:56:36 | 00,000,643 | —- | C] () – C:\WINDOWS\LEXSTAT.INI

========== Files - Modified Within 30 Days ==========

[6 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009-04-08 15:04:49 | 01,843,232 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009-04-08 14:48:25 | 00,500,736 | —- | M] (OldTimer Tools) – C:\Documents and Settings\al\Desktop\OTListIt2.exe
[2009-04-08 14:17:48 | 00,000,571 | —- | M] () – C:\Documents and Settings\al\My Documents\My Sharing Folders.lnk
[2009-04-08 13:53:12 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009-04-08 10:19:48 | 00,002,497 | —- | M] () – C:\Documents and Settings\al\Desktop\Microsoft Outlook (2).lnk
[2009-04-08 08:08:36 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009-04-08 07:52:30 | 00,075,680 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2009-04-08 07:52:27 | 00,088,224 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009-04-08 07:45:52 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009-04-08 07:45:47 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009-04-08 07:45:44 | 26,744,0128 | -HS- | M] () – C:\hiberfil.sys
[2009-04-08 01:07:24 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF12995.exe
[2009-04-08 01:03:21 | 03,307,596 | R— | M] () – C:\Documents and Settings\al\Desktop\worksnow.exe
[2009-04-08 00:43:30 | 00,004,124 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009-04-07 22:56:15 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF20066.exe
[2009-04-07 22:53:36 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF19550.exe
[2009-04-07 21:13:37 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF32735.exe
[2009-04-07 19:37:19 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF13856.exe
[2009-04-07 16:52:13 | 03,063,218 | —- | M] (Symantec Corporation) – C:\Documents and Settings\al\Desktop\Norton_Removal_Tool.exe
[2009-04-07 09:37:48 | 00,091,648 | —- | M] () – C:\Documents and Settings\al\Desktop\SystemLook.exe
[2009-04-05 10:36:45 | 00,001,833 | —- | M] () – C:\Documents and Settings\al\Start Menu\Programs\Startup\is-2K4OT.lnk
[2009-04-05 10:31:33 | 37,352,800 | —- | M] ( ) – C:\Documents and Settings\al\Desktop\setup_7.0.0.290_05.04.2009_16-12.exe
[2009-04-04 17:56:35 | 00,097,759 | —- | M] () – C:\Documents and Settings\al\Desktop\user.zip
[2009-04-03 17:50:11 | 01,516,400 | —- | M] (Doctor Web, Ltd.) – C:\Documents and Settings\al\Desktop\drweb-cureit.exe.part
[2009-04-03 16:18:09 | 00,000,000 | —- | M] () – C:\Documents and Settings\al\Desktop\drweb-cureit.exe
[2009-04-03 14:20:46 | 00,360,002 | —- | M] () – C:\Documents and Settings\al\Desktop\dds.pif
[2009-04-02 17:01:38 | 00,440,104 | —- | M] () – C:\Documents and Settings\al\Desktop\RootRepeal.zip
[2009-04-02 11:02:00 | 00,000,592 | —- | M] () – C:\Documents and Settings\al\Desktop\ERUNT.lnk
[2009-04-02 10:55:59 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\al\Desktop\erunt-setup.exe
[2009-03-31 19:13:43 | 00,001,734 | —- | M] () – C:\Documents and Settings\al\Desktop\HijackThis.lnk
[2009-03-31 12:40:00 | 00,115,671 | —- | M] () – C:\Documents and Settings\al\My Documents\duaa.jpg
[2009-03-30 19:50:40 | 02,624,744 | -H– | M] () – C:\Documents and Settings\al\Local Settings\Application Data\IconCache.db
[2009-03-28 14:42:08 | 00,000,029 | —- | M] () – C:\WINDOWS\qbwcd.ini
[2009-03-28 14:41:48 | 00,001,899 | —- | M] () – C:\WINDOWS\win.ini
[2009-03-28 14:35:44 | 00,001,687 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009-03-28 11:47:17 | 00,110,060 | —- | M] () – C:\WINDOWS\hpoins11.dat
[2009-03-28 09:58:36 | 00,270,984 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009-03-28 09:50:30 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009-03-28 09:30:15 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009-03-25 09:38:21 | 00,313,276 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009-03-25 09:38:21 | 00,040,868 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009-03-18 20:09:53 | 00,002,180 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009-03-17 21:20:06 | 00,001,751 | —- | M] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache

========== LOP Check ==========

[2008-12-16 21:15:42 | 00,000,000 | RH-D | M] – C:\Documents and Settings\al\Application Data
[2008-12-19 18:56:17 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Adobe
[2006-02-14 18:07:52 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Ahead
[2007-06-30 19:03:49 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\AOL
[2007-08-05 22:05:14 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Apple Computer
[2007-06-06 16:58:12 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\BellSouth
[2008-04-17 18:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Blackberry Desktop
[2008-12-01 13:28:49 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Ceedo
[2008-10-10 21:35:23 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Google
[2004-05-31 00:09:37 | 00,000,000 | -H-D | M] – C:\Documents and Settings\al\Application Data\GTek
[2002-02-19 16:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Help
[2006-05-12 15:21:40 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\HP
[2001-12-21 14:52:15 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Identities
[2006-05-23 14:41:47 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Image Zone Express
[2001-12-21 15:01:49 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\InterTrust
[2003-11-03 17:45:12 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Macromedia
[2007-03-14 09:54:37 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\McAfee.com Personal Firewall
[2007-08-06 22:32:33 | 00,000,000 | –SD | M] – C:\Documents and Settings\al\Application Data\Microsoft
[2002-06-11 20:59:29 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Microsoft Web Folders
[2008-05-17 09:58:25 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Motive
[2008-12-16 21:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Mozilla
[2007-06-10 00:10:07 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\MSN6
[2007-07-03 21:49:55 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\MSNInstaller
[2008-04-17 19:44:10 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Research In Motion
[2002-08-01 17:43:50 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Template
[2008-10-11 22:56:35 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\Yahoo!
[2005-06-02 10:19:40 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\You've Got Pictures Screensaver
[2009-04-07 16:56:01 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009-03-27 18:51:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
[2008-12-14 18:15:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007-06-29 20:17:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2009-03-04 10:33:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007-07-25 16:51:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007-07-25 16:57:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2007-06-06 16:57:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BellSouth
[2006-02-14 19:02:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2008-10-10 21:29:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009-04-07 17:03:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2004-05-31 00:09:37 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2006-05-12 14:53:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007-06-30 19:23:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2006-06-27 13:52:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008-12-16 12:43:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\mcafee.com personal firewall
[2007-06-22 13:34:40 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008-05-16 18:15:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2007-06-10 09:40:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MotiveSysIDs
[2002-11-13 18:45:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 5.0.0527
[2004-09-29 19:05:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.1.0155
[2002-02-17 18:00:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009-04-07 16:56:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009-01-31 21:23:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2006-12-11 18:10:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2005-06-02 10:20:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2005-06-03 11:38:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2002-06-11 21:53:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBT
[2005-06-02 10:19:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005-11-02 17:26:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007-09-04 13:01:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2001-08-18 08:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009-04-08 13:53:12 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009-04-08 08:08:36 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009-04-08 07:45:52 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 2972 bytes -> C:\WINDOWS\System32\OEMLOGO.BMP:Q30lsldxJoudresxAaaqpcawXc
< End of report >
Hi oldman

and this is Extras.txt :

OTListIt Extras logfile created on: 2009-04-08 14:52:56 - Run 1
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Documents and Settings\al\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd

254.98 Mb Total Physical Memory | 95.83 Mb Available Physical Memory | 37.58% Memory free
626.95 Mb Paging File | 253.22 Mb Available in Paging File | 40.39% Paging File free
Paging file location(s): C:\pagefile.sys 385 1000;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.22 Gb Total Space | 16.21 Gb Free Space | 43.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MIULING
Current User Name: al
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL (AOL LLC)
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL (AOL LLC)
C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 (America Online, Inc.)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL (AOL LLC)
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL (AOL LLC)
C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 (America Online, Inc.)
C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe:*:Enabled:MSN Connection Center (Microsoft Corporation)
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe:*:Enabled:Acrobat Reader 5.0 (Adobe Systems Incorporated)
C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console (Microsoft Corporation)
C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client (Hewlett-Packard)
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader (America Online, Inc.)
C:\Program Files\America Online 9.0a\waol.exe:*:Enabled:AOL (America Online, Inc.)
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon (America Online, Inc)
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed (America Online Inc)
C:\Program Files\Common Files\AOL\1159552586\EE\AOLServiceHost.exe:*:Enabled:AOL (America Online, Inc.)
C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL (AOL LLC)
C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL ()
C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL (AOL Spyware Protection)
C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL (Gteko Ltd.)
C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed (AOL LLC)
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server (Yahoo! Inc.)
C:\Program Files\Common Files\AOL\1159552586\EE\aolsoftware.exe:*:Enabled:AOL Services (AOL LLC)
C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer (RealNetworks, Inc.)
C:\Program Files\att-nap\McciBrowser.exe:*:Enabled:motivebrowser.exe (Motive Communications, Inc.)
C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox (Mozilla Corporation)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe (Hewlett-Packard Co.)
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe (Hewlett-Packard Co.)
C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe (Hewlett-Packard Co.)
C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe ()
C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe ()
C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe ( )
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000000-785F-478A-BAA2-87F1A136068C}" = MSN Encarta Plus Support Files
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Disc 2
"{0878E100-C0BB-41E8-B4C6-C486B61FDA7B}" = Canon PhotoRecord
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = PhotoStitch
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = RemoteCapture Task 1.1
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{32F66A20-7614-11D4-BD11-00104BD3F987}" = MathPlayer
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A316611-45D1-429C-AA26-B71259C44689}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{45EF4EE3-F591-4B74-A477-0CAE12934CE7}" = RAW Image Task 1.2
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4C96958A-6562-4143-B820-FF4890D3B734}" = Camera Window DVC
"{4F1CECBC-670F-4daa-81D6-944B12450917}" = DIGReqEx
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{74EC78BC-B379-4E29-9006-8F161DCAABA6}" = Apple Software Update
"{759524D5-08C9-4E88-8EB3-8D6ECB226C52}" = HP Image Zone Express
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{79546A5F-AE7C-4693-8670-A3401B43ABD2}" = HP Deskjet 5900 series
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{8AF1E098-1A5C-4336-BBE2-D047ABB401ED}" = MovieEdit Task
"{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}" = Camera Window DS
"{91F1A0D6-23AD-49FE-8D4E-379485652214}" = Camera Support Core Library
"{9357AE3A-B2ED-4138-BB9B-0564352C3F0A}" = iTunes
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{98605CAA-5F52-44EC-8AF7-2EC1A4C35F2D}" = BlackBerry Desktop Software 4.2.2
"{9F7FC79B-3059-4264-9450-39EB368E3220}" = Microsoft Picture It! Library 9
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A43B2A2F-1DB5-47F9-A608-F11A4835D7CB}" = Apple Mobile Device Support
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5222E5A-13CB-4C98-9F5C-21CF6896A25C}" = HPDeskjet5900Series
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon ZoomBrowser EX
"{C7281207-4AA4-425E-B57A-0E9EF8445635}" = Camera Window MC
"{C769B501-2BE8-46ed-9E69-118F008A0917}" = DIGOpt
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CF5193F7-6B37-11D5-B7D2-00AA00A204F1}" = Microsoft Money 2002 System Pack
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0900}" = Microsoft Picture It! Express 9
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E7298FD5-1386-11D5-8D6C-0050DAD32D95}" = Microsoft Money 2002
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F8D0829C-9C6F-11D3-8080-00C04FA329AA}" = Microsoft Works 6.0
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AOL Deskbar" = AOL Deskbar
"AOL Spyware Protection" = AOL Spyware Protection
"AOL Toolbar" = AOL Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AOLCoach" = AOL Coach Version 1.0(Build:20040229.1 en)
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"BellSouth Application Management" = BellSouth Application Management
"BellsouthHelpCenter4.0b_is1" = FastAccess® DSL Help Center 4.1
"BlackBerry_{98605CAA-5F52-44EC-8AF7-2EC1A4C35F2D}" = BlackBerry Desktop Software 4.2.2
"blstoolbar" = BellSouth Toolbar 1.0
"BrothersInArmsEiB" = Brothers In Arms EiB
"Card Games" = Card Games
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F00&SUBSYS_8D8B155D" = Conexant SoftK56 Modem(M)
"CodInstl" = Intel A/V Codecs V2.0
"Createshare2" = Intel® Create & Share™ Software
"DVD Shrink_is1" = DVD Shrink 3.1.4
"ERUNT_is1" = ERUNT 1.1j
"Extreme" = Extreme Chess
"F15" = F15
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"House Beautiful 3D Interior Designer" = House Beautiful 3D Interior Designer
"HP Imaging Device Functions" = HP Imaging Device Functions 5.0
"HP PrecisionScan" = HP PrecisionScan
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = Canon RemoteCapture Task for ZoomBrowser EX
"InstallShield_{45EF4EE3-F591-4B74-A477-0CAE12934CE7}" = Canon RAW Image Task for ZoomBrowser EX
"InstallShield_{4C96958A-6562-4143-B820-FF4890D3B734}" = Canon Camera Window DVC for ZoomBrowser EX
"InstallShield_{8AF1E098-1A5C-4336-BBE2-D047ABB401ED}" = Canon MovieEdit Task for ZoomBrowser EX
"InstallShield_{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}" = Canon Camera Window DS for ZoomBrowser EX
"InstallShield_{91F1A0D6-23AD-49FE-8D4E-379485652214}" = Canon Camera Support Core Library
"InstallShield_{C7281207-4AA4-425E-B57A-0E9EF8445635}" = Canon Camera Window for ZoomBrowser EX
"IRIS 2.2" = IRIS 2.2
"Landlord Forms" = Landlord Forms
"Lexmark Z600 Series" = Lexmark Z600 Series
"Living Trust Forms" = Living Trust Forms
"Microsoft Press Interactive Training" = Microsoft Interactive Training
"Midtown Madness 2.0" = Microsoft Midtown Madness 2
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MSN Toolbar" = MSN Toolbar
"MSNIACC" = MSN Connection Center
"MSNINST" = MSN
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PictureIt_POD_v9" = Microsoft Picture It! Library 9
"PictureIt_v9" = Microsoft Picture It! Express 9
"Poker Master" = Poker Master
"Port Magic" = Pure Networks Port Magic
"Quicken Deluxe 98" = Quicken Deluxe 98
"RadialpointClientGateway_is1" = BellSouth Internet Security - Alert Manager 1.5.11
"RealPlayer 6.0" = RealPlayer Basic
"Shockwave" = Shockwave
"SSC Uninstaller" = Safety and Security Center Uninstaller
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SystemRequirementsLab" = System Requirements Lab
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 2
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"YInstHelper" = Yahoo! Install Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2009-03-31 13:44:29 | Computer Name = MIULING | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 2009-04-07 19:44:39 | Computer Name = MIULING | Source = Application Error | ID = 1000
Description = Faulting application aolsoftware.exe, version 16.0.2.1, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x00037fd4.

Error - 2009-04-08 14:14:37 | Computer Name = MIULING | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 8.1.178.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2009-04-08 14:19:05 | Computer Name = MIULING | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 8.1.178.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2009-04-08 14:22:19 | Computer Name = MIULING | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: MIULING\al Checkpoint ID: 1 Error Code: 0x80070005 Error description:
Access is denied.

Error - 2009-04-08 14:22:19 | Computer Name = MIULING | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: MIULING\al Checkpoint ID: 1 Error Code: 0x8000ffff Error description:
Catastrophic failure

Error - 2009-04-08 14:34:39 | Computer Name = MIULING | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 windefend, P2 1.1.4502.0, P3 unspecified, P4
1.55.1119.0, P5 trojan_win32_hiloti.gen!a, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10
NIL.

Error - 2009-04-08 14:35:37 | Computer Name = MIULING | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 windefend, P2 1.1.4502.0, P3 unspecified, P4
1.55.1119.0, P5 trojan_win32_hiloti.gen!a, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10
NIL.

Error - 2009-04-08 14:36:39 | Computer Name = MIULING | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 windefend, P2 1.1.4502.0, P3 unspecified, P4
1.55.1119.0, P5 trojan_win32_hiloti.gen!a, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10
NIL.

Error - 2009-04-08 14:49:51 | Computer Name = MIULING | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 8.1.178.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ Application Events ]
Error - 2009-03-31 13:44:29 | Computer Name = MIULING | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 2009-04-07 19:44:39 | Computer Name = MIULING | Source = Application Error | ID = 1000
Description = Faulting application aolsoftware.exe, version 16.0.2.1, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x00037fd4.

Error - 2009-04-08 14:14:37 | Computer Name = MIULING | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 8.1.178.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2009-04-08 14:19:05 | Computer Name = MIULING | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 8.1.178.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2009-04-08 14:22:19 | Computer Name = MIULING | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: MIULING\al Checkpoint ID: 1 Error Code: 0x80070005 Error description:
Access is denied.

Error - 2009-04-08 14:22:19 | Computer Name = MIULING | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: MIULING\al Checkpoint ID: 1 Error Code: 0x8000ffff Error description:
Catastrophic failure

Error - 2009-04-08 14:34:39 | Computer Name = MIULING | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 windefend, P2 1.1.4502.0, P3 unspecified, P4
1.55.1119.0, P5 trojan_win32_hiloti.gen!a, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10
NIL.

Error - 2009-04-08 14:35:37 | Computer Name = MIULING | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 windefend, P2 1.1.4502.0, P3 unspecified, P4
1.55.1119.0, P5 trojan_win32_hiloti.gen!a, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10
NIL.

Error - 2009-04-08 14:36:39 | Computer Name = MIULING | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 windefend, P2 1.1.4502.0, P3 unspecified, P4
1.55.1119.0, P5 trojan_win32_hiloti.gen!a, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10
NIL.

Error - 2009-04-08 14:49:51 | Computer Name = MIULING | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 8.1.178.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 2009-04-08 00:36:34 | Computer Name = MIULING | Source = Service Control Manager | ID = 7000
Description = The Security Center service failed to start due to the following error:
%%123

Error - 2009-04-08 00:44:17 | Computer Name = MIULING | Source = sfsync02 | ID = 262156
Description =

Error - 2009-04-08 00:44:49 | Computer Name = MIULING | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 2009-04-08 00:45:47 | Computer Name = MIULING | Source = Service Control Manager | ID = 7001
Description = The Fax service depends on the Print Spooler service which failed
to start because of the following error: %%1068

Error - 2009-04-08 00:45:47 | Computer Name = MIULING | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips is-2K4OTdrv Processor

Error - 2009-04-08 02:25:25 | Computer Name = MIULING | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 2009-04-08 07:45:50 | Computer Name = MIULING | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 00402B1CF80A has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 2009-04-08 07:47:19 | Computer Name = MIULING | Source = Service Control Manager | ID = 7000
Description = The ASPI32 service failed to start due to the following error: %%2

Error - 2009-04-08 07:47:19 | Computer Name = MIULING | Source = Service Control Manager | ID = 7000
Description = The Security Center service failed to start due to the following error:
%%123

Error - 2009-04-08 14:59:50 | Computer Name = MIULING | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
PC129202628113 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{C26CD74A-351C. The master browser is stopping or an election is being
forced.


< End of report >
Hi Almar.

You have AOL antivirus, which uses McAfee so you are still protected. We'll clean up somewhat and do a scan.

Next, Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:processes
Explorer.EXE 

:OTLI
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
[2009-04-02 11:25:13 | 00,000,000 | —D | C] – C:\32788R22FWJFW.0.tmp
[2009-04-07 22:56:32 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF20066.exe
[2009-04-07 22:54:28 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF19550.exe
[2009-04-07 21:13:48 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF32735.exe
[2009-04-07 19:37:26 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF13856.exe
[2009-04-07 16:56:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2008-12-14 12:25:06 | 00,007,027 | —- | C] () – C:\WINDOWS\ajazimimimesu.dll
[2008-12-14 12:15:15 | 00,007,031 | —- | C] () – C:\WINDOWS\esadiwox.dll

:Services

:Reg

:Files
C:\WINDOWS\ekacanuv.dll
C:\WINDOWS\Ssukijohapu.dll

:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL2 log and a new HJT log.

Next
Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with the
  • OTLISIT2 log
  • MBAM log
  • newHJT log taken after all other steps are completed

Thanks
Hi oldman this is the OTl2 log, I'll follow with the HJT log next reply. Thanks ========== PROCESSES ========== Process Explorer.EXE killed successfully! ========== OTLISTIT ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. C:\32788R22FWJFW.0.tmp moved successfully. C:\WINDOWS\System32\CF20066.exe moved successfully. C:\WINDOWS\System32\CF19550.exe moved successfully. C:\WINDOWS\System32\CF32735.exe moved successfully. C:\WINDOWS\System32\CF13856.exe moved successfully. C:\Documents and Settings\All Users\Application Data\NortonInstaller moved successfully. LoadLibrary failed for C:\WINDOWS\ajazimimimesu.dll C:\WINDOWS\ajazimimimesu.dll NOT unregistered. C:\WINDOWS\ajazimimimesu.dll moved successfully. LoadLibrary failed for C:\WINDOWS\esadiwox.dll C:\WINDOWS\esadiwox.dll NOT unregistered. C:\WINDOWS\esadiwox.dll moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== File/Folder C:\WINDOWS\ekacanuv.dll not found. File/Folder C:\WINDOWS\Ssukijohapu.dll not found. ========== COMMANDS ========== File delete failed. C:\Documents and Settings\al\Local Settings\Temp\etilqs_q4AOJOm5EQ14uTTK4aXz scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\YD0JIDM5\transactionID=83273867&apg=1825&site=webmd&brand=mywebmd&rf=1825&to=1825&uri=%2Fmedical%5Finformation%2Fcondition%5Fcenters%2Fmenopause%2Fdefault%2Ehtm&pos=top&a[1]. scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\6X032HQ1\hk.greetings.yahoo[1]. scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\4VWII7R9\ProductDisplay[1]. scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. Network Service Temporary Internet Files folder emptied. Windows Temp folder emptied. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.12.2 log created on 04092009_111502 Files moved on Reboot… File C:\Documents and Settings\al\Local Settings\Temp\etilqs_q4AOJOm5EQ14uTTK4aXz not found! File C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\YD0JIDM5\transactionID=83273867&apg=1825&site=webmd&brand=mywebmd&rf=1825&to=1825&uri=%2Fmedical%5Finformation%2Fcondition%5Fcenters%2Fmenopause%2Fdefault%2Ehtm&pos=top&a[1]. not found! File C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\6X032HQ1\hk.greetings.yahoo[1]. not found! File C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\4VWII7R9\ProductDisplay[1]. not found! C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\XUL.mfl moved successfully. Registry entries deleted on Reboot…
Hi oldman

this is the HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:35, on 2009-04-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\mcafee.com\personal firewall\MPFTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\mcafee.com\personal firewall\MPFTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: is-2K4OT.lnk = C:\Documents and Settings\al\Desktop\Virus Removal Tool\is-2K4OT\startup.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com/start.html
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - https://objects.aol.com/mcafee/molbin/share…83/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by7fd.bay7.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit…b?1199841972187
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1199841588625
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - https://objects.aol.com/mcafee/molbin/share…,20/McGDMgr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - AOL LLC - C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Security Center (wscsvc) - Unknown owner - C:\WINDOWS\C:\WINDOWS\System32\svchost.exe (file missing)

–
End of file - 9513 bytes
Hi Almar,

How are you making out with the Malwarebytes Anti-Malware scan?

What do you know about this folder C:\Documents and Settings\al\Desktop\Virus Removal Tool\is-2K4OT

Thanks
Hi oldman sorry for the delay. I did run Malwarebytes Anti-Malware and did the scan but I did not get any log, unless it's hiding somewhere. Shall I run it again? I don't know anything about C:\Documents and Settings\al\Desktop\Virus Removal Tool\is-2K4OT. thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI