This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] is my computer infected

42 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi oldman here's the DDS log. The OTList2 clean up did not work.it froze after clicking clean Up. I cannot see the attachment panel under the reply panel in order to attach the attach.txt. I can copy and paste if you want. let me know if that is ok. DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 17:43:22.73 on 2009-04-11 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.255.36 [GMT -4:00] AV: AOL Antivirus *On-access scanning enabled* (Outdated) FW: AOL Firewall *disabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\system32\fxssvc.exe "C:\WINDOWS\System32\svchost.exe" -k netsvcs C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\MSN Messenger\livecall.exe C:\Program Files\Common Files\AOL\1159552586\ee\SSCEvtHdlr.exe C:\Program Files\Common Files\AOL\1159552586\EE\aolsoftware.exe C:\Program Files\Common Files\AOL\1159552586\EE\aolsoftware.exe c:\program files\common files\aol\1159552586\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe C:\Program Files\Common Files\AOL\1159552586\EE\anotify.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Documents and Settings\al\Desktop\OTListIt2.exe C:\Documents and Settings\al\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://my.yahoo.com/ uInternet Settings,ProxyServer = http=127.0.0.1:9022 uInternet Settings,ProxyOverride = 127.0.0.1; BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx BHO: BellSouth Toolbar: {4e7bd74f-2b8d-469e-8cbd-fd60bb9aae2e} - c:\progra~1\blstoo~1\BLSTOO~1.DLL BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: ST: {9394ede7-c8b5-483e-8773-474bf36af6e4} - c:\program files\msn apps\st\01.03.0000.1005\en-xu\stmain.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: MSNToolBandBHO: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll BHO: {fdd3b846-8d59-4ffb-8758-209b6ad74acc} - c:\program files\microsoft money\system\mnyviewer.dll TB: MSN: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File TB: AOL Toolbar: {4982d40a-c53b-4615-b15b-b5b5e98d167c} - TB: BellSouth Toolbar: {4e7bd74f-2b8d-469e-8cbd-fd60bb9aae2e} - c:\progra~1\blstoo~1\BLSTOO~1.DLL TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [MPFEXE] "c:\program files\mcafee.com\personal firewall\MPFTray.exe" IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program files\microsoft money\system\mnyviewer.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - hxxp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxps://objects.aol.com/mcafee/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by7fd.bay7.hotmail.msn.com/resources/MsnPUpld.cab DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1199841972187 DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199841588625 DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37387.6772222222 DPF: {A3009861-330C-4E10-822B-39D16EC8829D} - hxxp://www.ravantivirus.com/scan/ravonline.cab DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxps://objects.aol.com/mcafee/molbin/shared/mcgdmgr/en-us/1,0,0,20/McGDMgr.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} - hxxp://chat.msn.com/controls/msnchat45.cab SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\al\applic~1\mozilla\firefox\profiles\0fe092zp.default\ FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/ FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: XUL Cache: {C156E417-9A64-4EAC-A086-55F394343BB5} - c:\documents and settings\al\local settings\application data\{C156E417-9A64-4EAC-A086-55F394343BB5} FF - HiddenExtension: XUL Cache: {C23BDED9-5414-4EFD-ACC9-64BFDCB0023C} - c:\documents and settings\marian\local settings\application data\{c23bded9-5414-4efd-acc9-64bfdcb0023c}\ ============= SERVICES / DRIVERS =============== R0 aliidex;aliidex;c:\windows\system32\drivers\aliidex.sys [2006-5-23 7296] R0 aliperf;aliperf;c:\windows\system32\drivers\aliperf.sys [2006-5-23 7680] R3 NaiAvFilter1;NaiAvFilter1;c:\windows\system32\drivers\naiavf5x.sys [2007-6-30 114464] S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2007-1-14 2944] S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2007-1-14 60416] S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [2007-1-14 11008] S3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [2007-1-14 10368] S3 epstw2k;SCM Parallel Port SCSI Driver;c:\windows\system32\drivers\epstw2k.sys [2002-2-19 114944] S3 ICAM3NT5;Intel USB Video Camera III;c:\windows\system32\drivers\Icam3.sys [2003-2-8 141056] S3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [2002-2-19 10880] =============== Created Last 30 ================ 2009-04-11 17:06 –d—– C:\worksnow 2009-04-11 13:49 –d—– c:\documents and settings\al\Tracing 2009-04-11 13:25 3,426,072 a——- c:\windows\system32\d3dx9_32.dll 2009-04-11 13:24 –d—– c:\program files\Microsoft SQL Server Compact Edition 2009-04-11 13:18 –d—– c:\program files\Microsoft 2009-04-11 13:17 –d—– c:\program files\Windows Live SkyDrive 2009-04-11 12:55 –d—– c:\program files\common files\Windows Live 2009-04-11 12:53 1,143,656 a——- c:\program files\wlsetup-web.exe 2009-04-09 21:38 54,156 a—h— c:\windows\QTFont.qfn 2009-04-09 21:38 1,409 a——- c:\windows\QTFont.for 2009-04-09 12:01 –d—– c:\docume~1\al\applic~1\Malwarebytes 2009-04-09 12:01 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-04-09 12:01 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-09 12:00 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-04-09 12:00 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-04-08 13:49 59,264 ac—— c:\windows\system32\dllcache\usbaudio.sys 2009-04-08 13:49 59,264 a——- c:\windows\system32\drivers\USBAUDIO.sys 2009-04-08 01:07 388,608 a——- c:\windows\system32\CF12995.exe 2009-04-06 08:29 16,021,536 a–sh— c:\windows\system32\drivers\fidbox.dat 2009-04-06 08:29 188,828 a–sh— c:\windows\system32\drivers\fidbox.idx 2009-03-31 19:13 –d—– c:\program files\Trend Micro 2009-03-29 21:11 50,688 a——- c:\program files\ATF-Cleaner.exe 2009-03-27 18:50 -cd—– c:\docume~1\alluse~1\applic~1\{92E7A367-8E12-4830-AA70-29C32E331A81} ==================== Find3M ==================== 2009-03-28 11:47 110,060 a——- c:\windows\hpoins11.dat 2009-03-18 20:09 2,180 a——- c:\windows\system32\d3d8caps.dat 2009-02-09 06:19 1,846,272 a——- c:\windows\system32\win32k.sys 2009-02-06 19:03 307,576 a——- c:\windows\WLXPGSS.SCR 2009-02-06 18:52 49,504 a——- c:\windows\system32\sirenacm.dll 2008-12-26 21:14 256 a——- c:\documents and settings\al\pool.bin 2008-01-10 22:37 12,631,561 a——- c:\program files\NVIDIA 61.77.exe 2007-08-25 10:51 10,385,200 a——- c:\documents and settings\al\HC41SInstaller.exe 2007-06-06 16:53 66,269 a——- c:\program files\INSTALL.LOG 2004-02-12 12:54 470,528 a——- c:\program files\Manual DVD shrink 3.doc 2004-01-26 00:11 848,763 a——- c:\program files\dvdshrink314setup.exe ============= FINISH: 17:44:57.54 ===============
Hi oldman here's the DDS log. The OTList2 clean up did not work.it froze after clicking clean Up. I cannot see the attachment panel under the reply panel in order to attach the attach.txt. I can copy and paste if you want. let me know if that is ok. DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 17:43:22.73 on 2009-04-11 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.255.36 [GMT -4:00] AV: AOL Antivirus *On-access scanning enabled* (Outdated) FW: AOL Firewall *disabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\system32\fxssvc.exe "C:\WINDOWS\System32\svchost.exe" -k netsvcs C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\MSN Messenger\livecall.exe C:\Program Files\Common Files\AOL\1159552586\ee\SSCEvtHdlr.exe C:\Program Files\Common Files\AOL\1159552586\EE\aolsoftware.exe C:\Program Files\Common Files\AOL\1159552586\EE\aolsoftware.exe c:\program files\common files\aol\1159552586\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe C:\Program Files\Common Files\AOL\1159552586\EE\anotify.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Documents and Settings\al\Desktop\OTListIt2.exe C:\Documents and Settings\al\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://my.yahoo.com/ uInternet Settings,ProxyServer = http=127.0.0.1:9022 uInternet Settings,ProxyOverride = 127.0.0.1; BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx BHO: BellSouth Toolbar: {4e7bd74f-2b8d-469e-8cbd-fd60bb9aae2e} - c:\progra~1\blstoo~1\BLSTOO~1.DLL BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: ST: {9394ede7-c8b5-483e-8773-474bf36af6e4} - c:\program files\msn apps\st\01.03.0000.1005\en-xu\stmain.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: MSNToolBandBHO: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll BHO: {fdd3b846-8d59-4ffb-8758-209b6ad74acc} - c:\program files\microsoft money\system\mnyviewer.dll TB: MSN: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File TB: AOL Toolbar: {4982d40a-c53b-4615-b15b-b5b5e98d167c} - TB: BellSouth Toolbar: {4e7bd74f-2b8d-469e-8cbd-fd60bb9aae2e} - c:\progra~1\blstoo~1\BLSTOO~1.DLL TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [MPFEXE] "c:\program files\mcafee.com\personal firewall\MPFTray.exe" IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program files\microsoft money\system\mnyviewer.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - hxxp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxps://objects.aol.com/mcafee/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by7fd.bay7.hotmail.msn.com/resources/MsnPUpld.cab DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1199841972187 DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199841588625 DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37387.6772222222 DPF: {A3009861-330C-4E10-822B-39D16EC8829D} - hxxp://www.ravantivirus.com/scan/ravonline.cab DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxps://objects.aol.com/mcafee/molbin/shared/mcgdmgr/en-us/1,0,0,20/McGDMgr.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} - hxxp://chat.msn.com/controls/msnchat45.cab SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\al\applic~1\mozilla\firefox\profiles\0fe092zp.default\ FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/ FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: XUL Cache: {C156E417-9A64-4EAC-A086-55F394343BB5} - c:\documents and settings\al\local settings\application data\{C156E417-9A64-4EAC-A086-55F394343BB5} FF - HiddenExtension: XUL Cache: {C23BDED9-5414-4EFD-ACC9-64BFDCB0023C} - c:\documents and settings\marian\local settings\application data\{c23bded9-5414-4efd-acc9-64bfdcb0023c}\ ============= SERVICES / DRIVERS =============== R0 aliidex;aliidex;c:\windows\system32\drivers\aliidex.sys [2006-5-23 7296] R0 aliperf;aliperf;c:\windows\system32\drivers\aliperf.sys [2006-5-23 7680] R3 NaiAvFilter1;NaiAvFilter1;c:\windows\system32\drivers\naiavf5x.sys [2007-6-30 114464] S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2007-1-14 2944] S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2007-1-14 60416] S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [2007-1-14 11008] S3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [2007-1-14 10368] S3 epstw2k;SCM Parallel Port SCSI Driver;c:\windows\system32\drivers\epstw2k.sys [2002-2-19 114944] S3 ICAM3NT5;Intel USB Video Camera III;c:\windows\system32\drivers\Icam3.sys [2003-2-8 141056] S3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [2002-2-19 10880] =============== Created Last 30 ================ 2009-04-11 17:06 –d—– C:\worksnow 2009-04-11 13:49 –d—– c:\documents and settings\al\Tracing 2009-04-11 13:25 3,426,072 a——- c:\windows\system32\d3dx9_32.dll 2009-04-11 13:24 –d—– c:\program files\Microsoft SQL Server Compact Edition 2009-04-11 13:18 –d—– c:\program files\Microsoft 2009-04-11 13:17 –d—– c:\program files\Windows Live SkyDrive 2009-04-11 12:55 –d—– c:\program files\common files\Windows Live 2009-04-11 12:53 1,143,656 a——- c:\program files\wlsetup-web.exe 2009-04-09 21:38 54,156 a—h— c:\windows\QTFont.qfn 2009-04-09 21:38 1,409 a——- c:\windows\QTFont.for 2009-04-09 12:01 –d—– c:\docume~1\al\applic~1\Malwarebytes 2009-04-09 12:01 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-04-09 12:01 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-09 12:00 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-04-09 12:00 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-04-08 13:49 59,264 ac—— c:\windows\system32\dllcache\usbaudio.sys 2009-04-08 13:49 59,264 a——- c:\windows\system32\drivers\USBAUDIO.sys 2009-04-08 01:07 388,608 a——- c:\windows\system32\CF12995.exe 2009-04-06 08:29 16,021,536 a–sh— c:\windows\system32\drivers\fidbox.dat 2009-04-06 08:29 188,828 a–sh— c:\windows\system32\drivers\fidbox.idx 2009-03-31 19:13 –d—– c:\program files\Trend Micro 2009-03-29 21:11 50,688 a——- c:\program files\ATF-Cleaner.exe 2009-03-27 18:50 -cd—– c:\docume~1\alluse~1\applic~1\{92E7A367-8E12-4830-AA70-29C32E331A81} ==================== Find3M ==================== 2009-03-28 11:47 110,060 a——- c:\windows\hpoins11.dat 2009-03-18 20:09 2,180 a——- c:\windows\system32\d3d8caps.dat 2009-02-09 06:19 1,846,272 a——- c:\windows\system32\win32k.sys 2009-02-06 19:03 307,576 a——- c:\windows\WLXPGSS.SCR 2009-02-06 18:52 49,504 a——- c:\windows\system32\sirenacm.dll 2008-12-26 21:14 256 a——- c:\documents and settings\al\pool.bin 2008-01-10 22:37 12,631,561 a——- c:\program files\NVIDIA 61.77.exe 2007-08-25 10:51 10,385,200 a——- c:\documents and settings\al\HC41SInstaller.exe 2007-06-06 16:53 66,269 a——- c:\program files\INSTALL.LOG 2004-02-12 12:54 470,528 a——- c:\program files\Manual DVD shrink 3.doc 2004-01-26 00:11 848,763 a——- c:\program files\dvdshrink314setup.exe ============= FINISH: 17:44:57.54 ===============
Hi almar,

Going by that log, all the tools have been removed. Something doesn't seem right though.

Open Task Manager by right clicking near the clock and selecting task manager.

Click the Process tab and locate OTListIt2.exe
-Click End Process

Next
  • Make sure you have an Internet Connection.
  • Download OTCleanIt to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTCleanUp to reach the Internet, please allow the application to do so.
  • Click Yes to beging the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

After you have rebooted, please download OTLISIT2 again and run a scan with it. Please post both logs.

Thanks
hi oldman

all tools remain on desktop. here is the OTLIST2 log


OTListIt logfile created on: 2009-04-11 23:16:22 - Run 2
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\al\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd

254.98 Mb Total Physical Memory | 84.38 Mb Available Physical Memory | 33.09% Memory free
626.95 Mb Paging File | 281.05 Mb Available in Paging File | 44.83% Paging File free
Paging file location(s): C:\pagefile.sys 385 1000;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.22 Gb Total Space | 18.30 Gb Free Space | 49.17% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MIULING
Current User Name: al
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
PRC - C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe (AOL LLC)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe (America Online Inc)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\mcafee.com\antivirus\McShield.exe (McAfee Inc.)
PRC - C:\Program Files\mcafee.com\personal firewall\MPFService.exe (McAfee Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\mcafee.com\personal firewall\MPFTray.exe (McAfee Security)
PRC - C:\Documents and Settings\al\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (AOL TopSpeedMonitor [Auto | Running]) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
SRV - (aolavupd [Auto | Running]) – C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe (AOL LLC)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (McciCMService [Auto | Running]) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (McShield [Auto | Running]) – C:\Program Files\mcafee.com\antivirus\McShield.exe (McAfee Inc.)
SRV - (MpfService [Auto | Running]) – C:\Program Files\mcafee.com\personal firewall\MPFService.exe (McAfee Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (SeaPort [Auto | Running]) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (WANMiniportService [Auto | Running]) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ac97intc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (aliidex [Boot | Running]) – C:\WINDOWS\System32\drivers\aliidex.sys (Windows ® 2000 DDK provider)
DRV - (aliperf [Boot | Running]) – C:\WINDOWS\system32\drivers\aliperf.sys (Windows ® 2000 DDK provider)
DRV - (AN983 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\AN983.sys (ADMtek Incorporated.)
DRV - (ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (basic2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\basic2.sys (Conexant Systems)
DRV - (brfilt [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\Brfilt.sys (Brother Industries Ltd.)
DRV - (BrSerWDM [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbScn [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrUsbScn.sys (Brother Industries Ltd.)
DRV - (CamDrL [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Camdrl.sys (Logitech Inc.)
DRV - (Cnxtdiag [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\cnxtdiag.sys (Conexant Systems)
DRV - (epstw2k [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\epstw2k.sys (Microsoft Corporation)
DRV - (Fallback [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\fallback.sys (Conexant Systems)
DRV - (Fsks [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\fsksnt.sys (Conexant Systems)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (hidgame [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\hidgame.sys (Microsoft Corporation)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (hsf_msft [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys (Conexant)
DRV - (ICAM3NT5 [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\Icam3.sys (Microsoft Corporation)
DRV - (K56 [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\k56nt.sys (Conexant Systems)
DRV - (LVUSBSta [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (mf [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\mf.sys (Microsoft Corporation)
DRV - (MPFIREWL [System | Running]) – C:\WINDOWS\System32\Drivers\MpFirewall.sys (McAfee)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (NaiAvFilter1 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\naiavf5x.sys (McAfee Inc.)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (RimUsb [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RimUsb.sys (Research In Motion Limited)
DRV - (RimVSerPort [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\RimSerial.sys (Research in Motion Ltd)
DRV - (Rksample [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\rksample.sys (Conexant Systems)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (scsiscan [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\scsiscan.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Ser2pl [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ser2pl.sys (Prolific Technology Inc.)
DRV - (sfdrv01 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (sfsync02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (SoftFax [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\faxnt.sys (Conexant Systems)
DRV - (Tones [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\tonesnt.sys (Conexant Systems)
DRV - (usbaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (V124 [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\v124nt.sys (Conexant Systems)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {C156E417-9A64-4EAC-A086-55F394343BB5}:1.0
FF - prefs.js..extensions.enabledItems: {C23BDED9-5414-4EFD-ACC9-64BFDCB0023C}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\Extensions\\{C156E417-9A64-4EAC-A086-55F394343BB5}: C:\DOCUMENTS AND SETTINGS\AL\LOCAL SETTINGS\APPLICATION DATA\{C156E417-9A64-4EAC-A086-55F394343BB5} [2008-12-17 13:24:44 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{C23BDED9-5414-4EFD-ACC9-64BFDCB0023C}: C:\DOCUMENTS AND SETTINGS\MARIAN\LOCAL SETTINGS\APPLICATION DATA\{C23BDED9-5414-4EFD-ACC9-64BFDCB0023C}\ [2009-03-02 10:06:45 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009-04-02 20:53:12 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009-03-28 20:12:37 | 00,000,000 | —D | M]

[2008-12-16 21:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\mozilla\Extensions
[2008-12-16 21:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008-12-16 21:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\mozilla\Firefox\Profiles\0fe092zp.default\extensions
[2008-12-16 21:14:05 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009-03-28 20:12:37 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-03-28 20:12:25 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-03-28 20:12:25 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-03-13 09:46:19 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009-03-13 09:46:19 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009-03-13 09:46:19 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009-03-13 09:46:19 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009-03-13 09:46:19 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-03-13 09:46:19 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009-03-13 09:46:19 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (BellSouth Toolbar) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\Program Files\blstoolbar\blstoolbar.dll ()
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (ST) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (MSNToolBandBHO) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - File not found
O3 - HKLM\..\Toolbar: (BellSouth Toolbar) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\Program Files\blstoolbar\blstoolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (MSN) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\Program Files\blstoolbar\blstoolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [MPFEXE] "C:\Program Files\mcafee.com\personal firewall\MPFTray.exe" (McAfee Security)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} https://objects.aol.com/mcafee/molbin/share…83/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by7fd.bay7.hotmail.msn.com/resources/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/sit…b?1199841972187 (MUCatalogWebControl Class)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1199841588625 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…7387.6772222222 (Reg Error: Key error.)
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} http://www.ravantivirus.com/scan/ravonline.cab (CRAVOnline Object)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} https://objects.aol.com/mcafee/molbin/share…,20/McGDMgr.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/controls/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[5 C:\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009-04-11 23:08:32 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\al\Desktop\OTListIt2.exe
[2009-04-11 23:04:53 | 00,180,736 | —- | C] (OldTimer Tools) – C:\Documents and Settings\al\Desktop\OTCleanIt.exe
[2009-04-11 17:39:48 | 00,360,002 | —- | C] () – C:\Documents and Settings\al\Desktop\dds.scr
[2009-04-11 17:20:42 | 00,000,000 | —D | C] – C:\WINDOWS\Temp
[2009-04-11 17:18:06 | 00,455,680 | —- | C] () – C:\Documents and Settings\al\Desktop\ToolsCleaner2.exe
[2009-04-11 17:06:23 | 00,000,000 | —D | C] – C:\worksnow
[2009-04-11 13:35:10 | 00,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2009-04-11 13:30:08 | 00,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2009-04-11 13:27:41 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2009-04-11 13:25:21 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009-04-11 13:24:36 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2009-04-11 13:18:13 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009-04-11 13:17:56 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009-04-11 13:17:40 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009-04-11 13:16:20 | 00,000,000 | —D | C] – C:\Program Files\Windows Live
[2009-04-11 12:55:36 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009-04-11 12:53:19 | 01,143,656 | —- | C] (Microsoft Corporation) – C:\Program Files\wlsetup-web.exe
[2009-04-10 15:33:30 | 26,744,0128 | -HS- | C] () – C:\hiberfil.sys
[2009-04-10 15:30:21 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Desktop\almar
[2009-04-10 15:19:28 | 00,000,256 | —- | C] () – C:\Documents and Settings\al\Desktop\almar.zip
[2009-04-09 21:38:52 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009-04-09 21:38:52 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009-04-09 12:01:11 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Application Data\Malwarebytes
[2009-04-09 12:01:04 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009-04-09 12:01:03 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009-04-09 12:01:01 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-04-09 12:00:58 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009-04-09 12:00:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009-04-09 11:48:05 | 02,967,800 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\al\Desktop\mbam-setup.exe
[2009-04-08 13:49:22 | 00,059,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2009-04-08 13:49:22 | 00,059,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2009-04-08 13:47:57 | 00,000,000 | —D | C] – C:\Program Files\Common Files\logishrd
[2009-04-08 01:07:31 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF12995.exe
[2009-04-08 00:49:24 | 03,307,596 | R— | C] () – C:\Documents and Settings\al\Desktop\worksnow.exe
[2009-04-07 16:50:12 | 03,063,218 | —- | C] (Symantec Corporation) – C:\Documents and Settings\al\Desktop\Norton_Removal_Tool.exe
[2009-04-07 09:37:45 | 00,091,648 | —- | C] () – C:\Documents and Settings\al\Desktop\SystemLook.exe
[2009-04-06 08:29:41 | 16,021,536 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009-04-06 08:29:41 | 00,188,828 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009-04-05 10:35:38 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Desktop\Virus Removal Tool
[2009-04-05 10:23:49 | 37,352,800 | —- | C] ( ) – C:\Documents and Settings\al\Desktop\setup_7.0.0.290_05.04.2009_16-12.exe
[2009-04-04 17:56:27 | 00,097,759 | —- | C] () – C:\Documents and Settings\al\Desktop\user.zip
[2009-04-03 16:18:09 | 00,000,000 | —- | C] () – C:\Documents and Settings\al\Desktop\drweb-cureit.exe
[2009-04-03 16:18:00 | 01,516,400 | —- | C] (Doctor Web, Ltd.) – C:\Documents and Settings\al\Desktop\drweb-cureit.exe.part
[2009-04-03 14:20:44 | 00,360,002 | —- | C] () – C:\Documents and Settings\al\Desktop\dds.pif
[2009-04-02 17:09:13 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Desktop\RootRepeal
[2009-04-02 17:01:26 | 00,440,104 | —- | C] () – C:\Documents and Settings\al\Desktop\RootRepeal.zip
[2009-04-02 11:08:02 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009-04-02 11:02:00 | 00,000,592 | —- | C] () – C:\Documents and Settings\al\Desktop\ERUNT.lnk
[2009-04-02 11:01:59 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009-04-02 10:55:57 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\al\Desktop\erunt-setup.exe
[2009-03-31 19:13:43 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009-03-31 14:03:14 | 00,000,868 | —- | C] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009-03-31 12:39:59 | 00,115,671 | —- | C] () – C:\Documents and Settings\al\My Documents\duaa.jpg
[2009-03-27 18:50:56 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
[2008-01-03 18:27:54 | 00,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2007-06-04 23:21:04 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2007-06-04 23:20:25 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2007-02-03 08:59:04 | 00,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007-01-14 19:28:13 | 00,002,324 | —- | C] () – C:\WINDOWS\BRMFBIDI.INI
[2006-10-22 13:22:00 | 00,212,992 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006-05-23 14:28:44 | 00,000,208 | —- | C] () – C:\WINDOWS\Dit.INI
[2006-05-23 14:28:43 | 00,139,264 | —- | C] () – C:\WINDOWS\Dit.DLL
[2006-05-12 15:49:42 | 00,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006-05-12 15:43:15 | 00,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006-03-18 04:11:02 | 00,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005-11-22 18:37:26 | 00,000,073 | —- | C] () – C:\WINDOWS\upst.ini
[2005-08-20 15:18:31 | 00,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2005-07-18 17:26:05 | 00,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2005-06-09 16:46:15 | 00,000,062 | —- | C] () – C:\WINDOWS\draw.ini
[2005-06-09 16:41:53 | 00,000,158 | —- | C] () – C:\WINDOWS\estud.ini
[2005-04-27 14:38:00 | 00,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2005-04-27 14:37:49 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2005-04-01 17:16:00 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005-04-01 17:16:00 | 01,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005-04-01 17:16:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005-04-01 17:16:00 | 00,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005-04-01 17:16:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005-04-01 17:16:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2004-11-28 21:33:16 | 00,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2004-10-16 00:11:19 | 00,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004-10-16 00:11:19 | 00,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2004-10-15 23:48:16 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004-09-28 13:10:22 | 00,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004-06-24 19:02:30 | 00,000,043 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2004-06-24 12:17:19 | 00,000,000 | —- | C] () – C:\WINDOWS\QFN.ini
[2004-06-24 12:13:51 | 00,000,028 | —- | C] () – C:\WINDOWS\ICOA.INI
[2004-06-24 12:10:22 | 00,000,650 | —- | C] () – C:\WINDOWS\intuprof.ini
[2004-06-24 12:10:21 | 00,001,687 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004-06-24 12:10:17 | 00,000,252 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2004-06-24 12:10:14 | 00,207,872 | —- | C] () – C:\WINDOWS\System32\RDMWIN32.DLL
[2004-06-24 12:09:54 | 00,000,054 | —- | C] () – C:\WINDOWS\QFP.INI
[2004-06-24 12:09:54 | 00,000,054 | —- | C] () – C:\WINDOWS\MFF.INI
[2004-06-01 17:47:14 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004-05-31 00:32:50 | 00,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2004-05-31 00:32:49 | 00,000,027 | —- | C] () – C:\WINDOWS\upth.ini
[2004-03-19 16:05:29 | 00,002,415 | —- | C] () – C:\WINDOWS\TRA.INI
[2004-01-22 12:00:28 | 00,012,635 | —- | C] () – C:\WINDOWS\System32\DAntivirus.ini
[2003-12-04 12:59:49 | 00,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2003-10-09 08:18:08 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\missouri.dll
[2003-07-19 14:25:06 | 00,000,087 | —- | C] () – C:\WINDOWS\WALLSTRT.INI
[2003-03-27 15:28:44 | 00,004,955 | —- | C] () – C:\WINDOWS\System32\DProg.ini
[2003-02-08 18:35:07 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2003-02-08 18:34:37 | 00,000,056 | —- | C] () – C:\WINDOWS\winhelp.ini
[2003-02-08 18:34:24 | 00,795,548 | —- | C] () – C:\WINDOWS\System32\ica2.dll
[2003-02-08 18:33:33 | 01,523,712 | —- | C] () – C:\WINDOWS\System32\VARIETYPACKLOCALIZATION.DLL
[2003-02-08 18:33:32 | 01,830,912 | —- | C] () – C:\WINDOWS\System32\RFVPB.dll
[2003-02-08 18:33:32 | 01,699,840 | —- | C] () – C:\WINDOWS\System32\RFVPS.dll
[2003-02-08 18:33:32 | 00,401,408 | —- | C] () – C:\WINDOWS\System32\rfutils.dll
[2003-02-08 18:33:32 | 00,335,872 | —- | C] () – C:\WINDOWS\System32\RFVPPTB.dll
[2003-02-08 18:33:32 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\GenericVFW.dll
[2003-02-08 18:33:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\rfnullvideo.dll
[2003-02-08 18:33:32 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\RFInstallRoutines.dll
[2003-02-08 18:32:58 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2002-11-01 16:17:50 | 00,000,256 | —- | C] () – C:\WINDOWS\aucfg.ini
[2002-09-14 15:39:29 | 00,000,069 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2002-08-05 20:40:52 | 00,002,586 | —- | C] () – C:\WINDOWS\Xtreme.ini
[2002-07-04 15:05:34 | 00,000,269 | —- | C] () – C:\WINDOWS\tmupdate.ini
[2002-06-12 17:50:29 | 00,000,074 | —- | C] () – C:\WINDOWS\eFaxView.ini
[2002-05-22 10:53:49 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2002-05-01 17:35:17 | 00,000,355 | —- | C] () – C:\WINDOWS\EXLAW.INI
[2002-05-01 17:35:17 | 00,000,103 | —- | C] () – C:\WINDOWS\HIGHEDIT.INI
[2002-02-20 21:19:51 | 00,000,304 | —- | C] () – C:\WINDOWS\hpccopy.INI
[2002-02-19 19:53:46 | 00,000,928 | —- | C] () – C:\WINDOWS\System32\hpsj1695.dll
[2002-02-19 19:53:44 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2002-02-19 19:53:43 | 00,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2002-02-19 18:09:02 | 00,000,074 | —- | C] () – C:\WINDOWS\hpsjbmgr.ini
[2002-02-18 20:08:57 | 00,000,029 | —- | C] () – C:\WINDOWS\qbwcd.ini
[2002-02-18 20:07:15 | 00,003,275 | —- | C] () – C:\WINDOWS\WININIT.INI
[2002-02-18 20:06:18 | 00,001,385 | —- | C] () – C:\WINDOWS\QfnOnl.ini
[2002-02-18 20:06:08 | 00,000,362 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2002-02-18 20:06:08 | 00,000,038 | —- | C] () – C:\WINDOWS\ACCWIZ.INI
[2002-02-18 20:06:08 | 00,000,021 | —- | C] () – C:\WINDOWS\QFNOA.INI
[2002-02-17 21:20:27 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2002-01-05 12:53:40 | 00,000,482 | —- | C] () – C:\WINDOWS\ODBC.INI
[2001-12-21 15:19:36 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2001-12-21 15:02:52 | 00,000,884 | —- | C] () – C:\WINDOWS\orun32.ini
[2001-12-21 15:00:48 | 00,000,777 | —- | C] () – C:\WINDOWS\lrun32.ini
[2001-12-21 13:38:43 | 00,001,012 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001-12-21 13:38:43 | 00,000,433 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2001-12-21 13:38:09 | 00,001,899 | —- | C] () – C:\WINDOWS\win.ini
[2001-12-21 13:38:02 | 00,000,491 | —- | C] () – C:\WINDOWS\SYSTEM.INI
[2001-12-21 13:37:33 | 00,000,325 | —- | C] () – C:\WINDOWS\System32\ntnet.drv
[2001-12-14 13:34:46 | 00,164,864 | —- | C] () – C:\WINDOWS\patchw32.dll
[1999-07-23 13:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999-07-23 10:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999-01-22 14:46:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998-01-12 04:00:00 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\REGOBJ.DLL
[1997-10-24 15:56:36 | 00,000,643 | —- | C] () – C:\WINDOWS\LEXSTAT.INI

========== Files - Modified Within 30 Days ==========

[5 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009-04-11 23:08:33 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\al\Desktop\OTListIt2.exe
[2009-04-11 23:04:58 | 00,180,736 | —- | M] (OldTimer Tools) – C:\Documents and Settings\al\Desktop\OTCleanIt.exe
[2009-04-11 23:01:15 | 00,075,680 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2009-04-11 23:00:21 | 00,088,224 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009-04-11 23:00:18 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009-04-11 22:57:21 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009-04-11 22:56:55 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009-04-11 22:56:39 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009-04-11 22:56:30 | 26,744,0128 | -HS- | M] () – C:\hiberfil.sys
[2009-04-11 22:56:30 | 00,274,168 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009-04-11 17:39:51 | 00,360,002 | —- | M] () – C:\Documents and Settings\al\Desktop\dds.scr
[2009-04-11 17:18:24 | 00,455,680 | —- | M] () – C:\Documents and Settings\al\Desktop\ToolsCleaner2.exe
[2009-04-11 13:48:25 | 00,077,576 | —- | M] () – C:\Documents and Settings\al\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009-04-11 13:43:31 | 00,407,210 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009-04-11 13:43:31 | 00,393,968 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009-04-11 13:43:31 | 00,059,472 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009-04-11 13:21:31 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009-04-11 12:34:07 | 00,000,888 | —- | M] () – C:\Documents and Settings\al\My Documents\My Sharing Folders.lnk
[2009-04-11 11:50:32 | 16,021,536 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009-04-11 11:50:32 | 00,188,828 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009-04-10 17:55:27 | 00,001,899 | —- | M] () – C:\WINDOWS\win.ini
[2009-04-10 15:19:41 | 00,000,256 | —- | M] () – C:\Documents and Settings\al\Desktop\almar.zip
[2009-04-09 21:49:06 | 00,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009-04-09 21:38:52 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009-04-09 21:38:52 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009-04-09 12:01:04 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009-04-09 11:48:23 | 02,967,800 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\al\Desktop\mbam-setup.exe
[2009-04-08 23:09:16 | 00,002,497 | —- | M] () – C:\Documents and Settings\al\Desktop\Microsoft Outlook (2).lnk
[2009-04-08 01:07:24 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF12995.exe
[2009-04-08 01:03:21 | 03,307,596 | R— | M] () – C:\Documents and Settings\al\Desktop\worksnow.exe
[2009-04-07 16:52:13 | 03,063,218 | —- | M] (Symantec Corporation) – C:\Documents and Settings\al\Desktop\Norton_Removal_Tool.exe
[2009-04-07 09:37:48 | 00,091,648 | —- | M] () – C:\Documents and Settings\al\Desktop\SystemLook.exe
[2009-04-06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-04-06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009-04-05 10:31:33 | 37,352,800 | —- | M] ( ) – C:\Documents and Settings\al\Desktop\setup_7.0.0.290_05.04.2009_16-12.exe
[2009-04-04 17:56:35 | 00,097,759 | —- | M] () – C:\Documents and Settings\al\Desktop\user.zip
[2009-04-03 17:50:11 | 01,516,400 | —- | M] (Doctor Web, Ltd.) – C:\Documents and Settings\al\Desktop\drweb-cureit.exe.part
[2009-04-03 16:18:09 | 00,000,000 | —- | M] () – C:\Documents and Settings\al\Desktop\drweb-cureit.exe
[2009-04-03 14:20:46 | 00,360,002 | —- | M] () – C:\Documents and Settings\al\Desktop\dds.pif
[2009-04-02 17:01:38 | 00,440,104 | —- | M] () – C:\Documents and Settings\al\Desktop\RootRepeal.zip
[2009-04-02 11:02:00 | 00,000,592 | —- | M] () – C:\Documents and Settings\al\Desktop\ERUNT.lnk
[2009-04-02 10:55:59 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\al\Desktop\erunt-setup.exe
[2009-03-31 12:40:00 | 00,115,671 | —- | M] () – C:\Documents and Settings\al\My Documents\duaa.jpg
[2009-03-30 19:50:40 | 02,624,744 | -H– | M] () – C:\Documents and Settings\al\Local Settings\Application Data\IconCache.db
[2009-03-28 14:42:08 | 00,000,029 | —- | M] () – C:\WINDOWS\qbwcd.ini
[2009-03-28 14:35:44 | 00,001,687 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009-03-28 11:47:17 | 00,110,060 | —- | M] () – C:\WINDOWS\hpoins11.dat
[2009-03-28 09:30:15 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009-03-18 20:09:53 | 00,002,180 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009-03-17 21:20:06 | 00,001,751 | —- | M] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache

========== Alternate Data Streams ==========

@Alternate Data Stream - 2972 bytes -> C:\WINDOWS\System32\OEMLOGO.BMP:Q30lsldxJoudresxAaaqpcawXc
< End of report >

I ran OTCleanIt, there was no log produced.
Hi almar,

It looks like AVP is uninstalled so we will remove it along with the rest of the tools. After you run the fix below, all that should be left is OTLISTIT2



Next, Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
Explorer.EXE

:OTLI
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
[2009-04-06 08:29:41 | 16,021,536 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009-04-06 08:29:41 | 00,188,828 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009-04-05 10:35:38 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Desktop\Virus Removal Tool
[2009-04-05 10:23:49 | 37,352,800 | —- | C] ( ) – C:\Documents and Settings\al\Desktop\setup_7.0.0.290_05.04.2009_16-12.exe
[2009-04-04 17:56:27 | 00,097,759 | —- | C] () – C:\Documents and Settings\al\Desktop\user.zip
[2009-04-03 16:18:09 | 00,000,000 | —- | C] () – C:\Documents and Settings\al\Desktop\drweb-cureit.exe
[2009-04-03 16:18:00 | 01,516,400 | —- | C] (Doctor Web, Ltd.) – C:\Documents and Settings\al\Desktop\drweb-cureit.exe.part
[2009-04-03 14:20:44 | 00,360,002 | —- | C] () – C:\Documents and Settings\al\Desktop\dds.pif
[2009-04-02 17:09:13 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Desktop\RootRepeal
[2009-04-02 17:01:26 | 00,440,104 | —- | C] () – C:\Documents and Settings\al\Desktop\RootRepeal.zip

:Services

:Reg

:Files
C:\Documents and Settings\al\Desktop\OTCleanIt.exe
C:\Documents and Settings\al\Desktop\ToolsCleaner2.exe
C:\Documents and Settings\al\Desktop\dds.scr
C:\worksnow
C:\Documents and Settings\al\Desktop\almar.zip
C:\WINDOWS\System32\CF12995.exe
C:\Documents and Settings\al\Desktop\worksnow.exe
C:\Documents and Settings\al\Desktop\Norton_Removal_Tool.exe
C:\Documents and Settings\al\Desktop\SystemLook.exe

:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL2 log and a new HJT log.

Thanks
Hi oldman here are the log. I still have Erunt, Malware bytes and OTList2 on my desktop plus other text files related.I no longer have HJT to run and post a log.It's been taken out by OTLiist 2 I guess. ========== PROCESSES ========== Process Explorer.EXE killed successfully! ========== OTLISTIT ========== Process Explorer.EXE killed successfully! No active process named MsMpEng.exe was found! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. C:\WINDOWS\System32\drivers\fidbox.dat moved successfully. C:\WINDOWS\System32\drivers\fidbox.idx moved successfully. Folder C:\Documents and Settings\al\Desktop\Virus Removal Tool not found. C:\Documents and Settings\al\Desktop\setup_7.0.0.290_05.04.2009_16-12.exe moved successfully. C:\Documents and Settings\al\Desktop\user.zip moved successfully. C:\Documents and Settings\al\Desktop\drweb-cureit.exe moved successfully. C:\Documents and Settings\al\Desktop\drweb-cureit.exe.part moved successfully. C:\Documents and Settings\al\Desktop\dds.pif moved successfully. C:\Documents and Settings\al\Desktop\RootRepeal moved successfully. C:\Documents and Settings\al\Desktop\RootRepeal.zip moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\Documents and Settings\al\Desktop\OTCleanIt.exe moved successfully. C:\Documents and Settings\al\Desktop\ToolsCleaner2.exe moved successfully. C:\Documents and Settings\al\Desktop\dds.scr moved successfully. C:\worksnow moved successfully. C:\Documents and Settings\al\Desktop\almar.zip moved successfully. C:\WINDOWS\System32\CF12995.exe moved successfully. C:\Documents and Settings\al\Desktop\worksnow.exe moved successfully. C:\Documents and Settings\al\Desktop\Norton_Removal_Tool.exe moved successfully. C:\Documents and Settings\al\Desktop\SystemLook.exe moved successfully. ========== COMMANDS ========== File delete failed. C:\Documents and Settings\al\Local Settings\Temp\etilqs_B9DJbNiyOzlHbyoocuoY scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\YD0JIDM5\transactionID=83273867&apg=1825&site=webmd&brand=mywebmd&rf=1825&to=1825&uri=%2Fmedical%5Finformation%2Fcondition%5Fcenters%2Fmenopause%2Fdefault%2Ehtm&pos=top&a[1]. scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\6X032HQ1\hk.greetings.yahoo[1]. scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\4VWII7R9\ProductDisplay[1]. scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. Network Service Temporary Internet Files folder emptied. Windows Temp folder emptied. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.14.0 log created on 04122009_090513 Files moved on Reboot… File C:\Documents and Settings\al\Local Settings\Temp\etilqs_B9DJbNiyOzlHbyoocuoY not found! File C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\YD0JIDM5\transactionID=83273867&apg=1825&site=webmd&brand=mywebmd&rf=1825&to=1825&uri=%2Fmedical%5Finformation%2Fcondition%5Fcenters%2Fmenopause%2Fdefault%2Ehtm&pos=top&a[1]. not found! File C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\6X032HQ1\hk.greetings.yahoo[1]. not found! File C:\Documents and Settings\al\Local Settings\Temporary Internet Files\Content.IE5\4VWII7R9\ProductDisplay[1]. not found! C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\al\Local Settings\Application Data\Mozilla\Firefox\Profiles\0fe092zp.default\XUL.mfl moved successfully. Registry entries deleted on Reboot…
Hi Almar,

That would have been ToolsRemover that removed HJT.

ERUNT is a good program to keep. You can keep a backup of yourr current registry.

MBAM is a good on demand scanner to keep.

The notepads and logs can be deleted.


Next, turn your Firewall on and update your Antivirus program. Tell us how your computer is at the moment.


You can get a new copy of HJT from


Click here to download HJTInstall.exe
Please follow the prompts to ensure it is installed in the proper folder and
a shortcut is created.

Thanks
Hi oldman How can I not be without you! thanks to you the computer is running normal again but it did take a heck of time to go through all the daily ritual of scanning and removing nasty stuff, I would never have imagined .I thank you again for your help and patience and will keep you informed if anything out of ordinary pops up. Since I do have those scanning programs still on my desktop do you advise that I use them and also be able to remove malware and viruses myself or better leave this to you. many thanks almar
Hi Almar,

Since I do have those scanning programs still on my desktop

Which tools are you refering to? All that should be left is ERUNT, MBAM and OTListIt2. We will remove OTLISTIT2, the other 2 I all ready suggested you keep amd use.


Open OTListIt2 then click the Clean Up button. You may get prompted by your firewall that OTListIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


Please post one more HJT log and we'll finish up. I gave you the link 2 replies ago.

Thanks
Hi oldman
The HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:06, on 2009-04-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\mcafee.com\personal firewall\MPFTray.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\OasClnt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\mcafee.com\personal firewall\MPFTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com/start.html
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - https://objects.aol.com/mcafee/molbin/share…83/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by7fd.bay7.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit…b?1199841972187
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1199841588625
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - https://objects.aol.com/mcafee/molbin/share…,20/McGDMgr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - AOL LLC - C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 10047 bytes
Hi Almar,

Looks good.

*We'll reset your restore points

Create a new restore point

You must be logged on to an administrator account
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create
* Remove old restore points

  • Go to Start - All Programs - Accessories - system tools.
  • Launch the Disk Cleanup tool and let it run.
  • When it finishes a box with tabs will appear, select the more options tab.
  • On this tab you will find a section for System Restore.
  • If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.


Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 5 first. Be sure to move any PDF documents to another folder first though.



Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have those all ready.

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.



-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI