This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]ย First Post

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Josh26,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please don't attach files unless specifically asked to. It's easier for me if you copy/paste the information here.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Thanks Tomk, Have been away for the weekend hence late reply. At work but will post requested details this evening when at home. Cheers Josh26
OTListIt logfile created on: 27/04/2009 7:00:04 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Brian\Local Settings\Temporary Internet Files\Content.IE5\F3T19LC4
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1022.98 Mb Total Physical Memory | 614.45 Mb Available Physical Memory | 60.06% Memory free
2.40 Gb Paging File | 2.09 Gb Available in Paging File | 87.08% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 65.98 Gb Free Space | 88.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ROBINSON
Current User Name: Brian
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2008/04/14 04:42:20 | 01,033,728 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\Explorer.EXE
PRC - [2008/10/17 14:52:10 | 00,149,352 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2007/08/24 06:35:30 | 00,243,064 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2004/04/11 10:43:44 | 00,053,248 | โ€”- | M] (CyberLink Corp.) โ€“ C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
PRC - [2008/05/07 11:41:56 | 02,162,688 | โ€”- | M] (Telstra) โ€“ C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe
PRC - [2008/10/17 14:52:10 | 00,149,352 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2009/04/20 09:18:48 | 00,148,888 | โ€”- | M] (Sun Microsystems, Inc.) โ€“ C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/04/14 04:42:30 | 01,695,232 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Program Files\Messenger\msmsgs.exe
PRC - [2007/12/08 10:42:02 | 00,376,832 | โ€”- | M] (The Eraser Project) โ€“ C:\Program Files\Eraser\Eraser.exe
PRC - [2009/01/14 11:00:00 | 00,525,664 | Rโ€” | M] (WinZip Computing, S.L.) โ€“ C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2009/04/20 09:18:48 | 00,152,984 | โ€”- | M] (Sun Microsystems, Inc.) โ€“ C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2003/06/19 22:25:00 | 00,322,120 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2008/05/16 13:01:00 | 00,159,812 | โ€”- | M] (NVIDIA Corporation) โ€“ C:\WINDOWS\system32\nvsvc32.exe
PRC - [2009/04/27 18:59:24 | 00,501,248 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Brian\Local Settings\Temporary Internet Files\Content.IE5\F3T19LC4\OTListIt2[1].exe
PRC - [2009/01/17 13:00:26 | 01,251,720 | โ€”- | M] () โ€“ C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2009/02/06 20:10:02 | 00,227,840 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\wbem\wmiprvse.exe

========== Win32 Services (SafeList) ==========

SRV - [2007/10/24 00:47:22 | 00,033,800 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe โ€“ (aspnet_state [On_Demand | Stopped])
SRV - [2007/08/24 06:35:30 | 00,243,064 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe โ€“ (Automatic LiveUpdate Scheduler [Auto | Running])
SRV - [2008/10/17 14:52:10 | 00,149,352 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe โ€“ (ccEvtMgr [Auto | Running])
SRV - [2008/10/17 14:52:10 | 00,149,352 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe โ€“ (ccSetMgr [Auto | Running])
SRV - [2007/10/24 00:47:40 | 00,070,144 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe โ€“ (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/10/17 14:52:10 | 00,149,352 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe โ€“ (CLTNetCnService [Auto | Running])
SRV - [2008/04/14 04:42:04 | 00,038,400 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll โ€“ (helpsvc [Auto | Running])
SRV - [2009/04/20 09:18:48 | 00,152,984 | โ€”- | M] (Sun Microsystems, Inc.) โ€“ C:\Program Files\Java\jre6\bin\jqs.exe โ€“ (JavaQuickStarterService [Auto | Running])
SRV - [2007/08/24 06:35:22 | 03,192,184 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE โ€“ (LiveUpdate [On_Demand | Stopped])
SRV - [2008/10/17 14:52:10 | 00,149,352 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe โ€“ (LiveUpdate Notice [Auto | Running])
SRV - [2003/06/19 22:25:00 | 00,322,120 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE โ€“ (MDM [Auto | Running])
SRV - File not found โ€“ โ€“ (Nero BackItUp Scheduler 4.0 [Auto | Stopped])
SRV - [2008/05/16 13:01:00 | 00,159,812 | โ€”- | M] (NVIDIA Corporation) โ€“ C:\WINDOWS\system32\nvsvc32.exe โ€“ (NVSvc [Auto | Running])
SRV - [2003/07/28 11:28:22 | 00,089,136 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE โ€“ (ose [On_Demand | Stopped])
SRV - [2009/01/17 13:00:26 | 01,251,720 | โ€”- | M] () โ€“ C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe โ€“ (Symantec Core LC [On_Demand | Running])
SRV - [2006/10/18 19:05:24 | 00,913,408 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Program Files\Windows Media Player\WMPNetwk.exe โ€“ (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2008/04/13 23:16:22 | 00,048,128 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\DRIVERS\61883.sys โ€“ (61883 [On_Demand | Stopped])
DRV - [2002/04/01 13:15:00 | 00,004,816 | โ€”- | M] (Andrea Electronics Corporation) โ€“ C:\WINDOWS\system32\drivers\aeaudio.sys โ€“ (aeaudio [On_Demand | Running])
DRV - [2008/04/13 23:16:22 | 00,038,912 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\DRIVERS\avc.sys โ€“ (Avc [On_Demand | Stopped])
DRV - [2004/03/23 03:24:00 | 00,004,272 | Rโ€” | M] () โ€“ C:\WINDOWS\System32\drivers\bvrp_pci.sys โ€“ (bvrp_pci [On_Demand | Stopped])
DRV - [2007/06/22 08:54:32 | 00,087,424 | โ€”- | M] (Cmotech Co., Ltd) โ€“ C:\WINDOWS\system32\DRIVERS\cmusbnet.sys โ€“ (cmusbnet [On_Demand | Running])
DRV - [2006/12/13 17:31:56 | 00,087,040 | โ€”- | M] (Cmotech Co.,Ltd) โ€“ C:\WINDOWS\system32\DRIVERS\cmusbser.sys โ€“ (cmusbser [On_Demand | Running])
DRV - [2008/07/30 16:42:12 | 00,023,888 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\system32\Drivers\COH_Mon.sys โ€“ (COH_Mon [On_Demand | Stopped])
DRV - [2005/06/13 11:58:04 | 00,162,816 | โ€”- | M] (Intel Corporation) โ€“ C:\WINDOWS\system32\DRIVERS\e100b325.sys โ€“ (E100B [On_Demand | Running])
DRV - [2009/02/28 19:00:00 | 00,371,248 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys โ€“ (eeCtrl [System | Running])
DRV - [2009/02/28 19:00:00 | 00,101,936 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys โ€“ (EraserUtilRebootDrv [On_Demand | Running])
DRV - [2008/04/13 23:16:10 | 00,051,200 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\DRIVERS\msdv.sys โ€“ (MSDV [On_Demand | Stopped])
DRV - [2009/03/16 18:00:00 | 00,089,104 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090421.006\NAVENG.SYS โ€“ (NAVENG [On_Demand | Running])
DRV - [2009/03/16 18:00:00 | 00,876,144 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090421.006\NAVEX15.SYS โ€“ (NAVEX15 [On_Demand | Running])
DRV - [2008/05/16 13:01:00 | 06,557,408 | โ€”- | M] (NVIDIA Corporation) โ€“ C:\WINDOWS\System32\DRIVERS\nv4_mini.sys โ€“ (nv [On_Demand | Running])
DRV - [2001/08/22 07:42:58 | 00,013,632 | โ€”- | M] (Dell Computer Corporation) โ€“ C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS โ€“ (OMCI [System | Running])
DRV - [2007/07/13 15:25:22 | 00,027,072 | โ€”- | M] (Printing Communications Assoc., Inc. (PCAUSA)) โ€“ C:\WINDOWS\System32\Drivers\PCASp50.sys โ€“ (PCASp50 [On_Demand | Stopped])
DRV - [2003/07/17 06:42:18 | 00,017,792 | โ€”- | M] (Parallel Technologies, Inc.) โ€“ C:\WINDOWS\System32\DRIVERS\ptilink.sys โ€“ (Ptilink [On_Demand | Running])
DRV - [2008/04/13 21:09:16 | 00,020,480 | โ€”- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) โ€“ C:\WINDOWS\System32\DRIVERS\secdrv.sys โ€“ (Secdrv [On_Demand | Stopped])
DRV - [2003/05/06 08:14:34 | 00,580,992 | โ€”- | M] (Analog Devices, Inc.) โ€“ C:\WINDOWS\system32\drivers\smwdm.sys โ€“ (smwdm [On_Demand | Running])
DRV - [2008/09/05 13:31:42 | 00,447,024 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys โ€“ (SPBBCDrv [System | Running])
DRV - [2007/11/30 22:57:12 | 00,279,088 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\System32\Drivers\SRTSP.SYS โ€“ (SRTSP [On_Demand | Running])
DRV - [2007/11/30 22:57:12 | 00,317,616 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\System32\Drivers\SRTSPL.SYS โ€“ (SRTSPL [On_Demand | Stopped])
DRV - [2007/11/30 22:57:12 | 00,043,696 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\System32\Drivers\SRTSPX.SYS โ€“ (SRTSPX [System | Running])
DRV - [2009/02/19 10:31:16 | 00,013,616 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\System32\Drivers\SYMDNS.SYS โ€“ (SYMDNS [On_Demand | Running])
DRV - [2009/01/17 13:05:09 | 00,124,464 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\system32\Drivers\SYMEVENT.SYS โ€“ (SymEvent [On_Demand | Running])
DRV - [2009/02/19 10:31:16 | 00,096,560 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\System32\Drivers\SYMFW.SYS โ€“ (SYMFW [On_Demand | Running])
DRV - [2009/02/19 10:31:16 | 00,038,576 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\System32\Drivers\SYMIDS.SYS โ€“ (SYMIDS [On_Demand | Running])
DRV - [2009/02/10 08:59:18 | 00,251,768 | โ€”- | M] (Symantec Corporation) โ€“ C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20090414.001\SymIDSCo.sys โ€“ (SYMIDSCO [On_Demand | Running])
DRV - [2009/02/19 10:31:42 | 00,031,280 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\system32\DRIVERS\SymIM.sys โ€“ (SymIM [On_Demand | Stopped])
DRV - [2009/02/19 10:31:42 | 00,031,280 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\system32\DRIVERS\SymIM.sys โ€“ (SymIMMP [On_Demand | Running])
DRV - [2009/02/19 10:31:16 | 00,037,424 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\System32\Drivers\SYMNDIS.SYS โ€“ (SYMNDIS [On_Demand | Running])
DRV - [2009/02/19 10:31:16 | 00,022,320 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\System32\Drivers\SYMREDRV.SYS โ€“ (SYMREDRV [On_Demand | Running])
DRV - [2009/02/19 10:31:16 | 00,184,496 | โ€”- | M] (Symantec Corporation) โ€“ C:\WINDOWS\System32\Drivers\SYMTDI.SYS โ€“ (SYMTDI [System | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.telstra.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/04/20 09:18:49 | 00,000,000 | โ€”D | M]


O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (BigPond Wireless Broadband 2.0 Auto Dial) - {DB92EC3F-697D-4C3B-9A3B-3ABBD23D4A85} - C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\bpwbb2ad.dll (Telstra)
O2 - BHO: (Javaโ„ข Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BigPondWirelessBroadbandCM] "C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe" -tsr (Telstra)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe" (Symantec Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide (The Eraser Project)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdatโ€ฆb?1232003071343 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/15 15:53:38 | 00,000,000 | โ€”- | M] () - C:\AUTOEXEC.BAT โ€“ [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/04/22 06:25:47 | 00,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\WinZipSE
[2009/04/22 06:25:45 | 00,000,000 | โ€”D | C] โ€“ C:\Program Files\WinZip Self-Extractor
[2009/04/20 09:19:37 | 00,000,000 | โ€”D | C] โ€“ C:\WINDOWS\Sun
[2009/04/20 09:18:43 | 00,000,000 | โ€”D | C] โ€“ C:\Program Files\Java
[2009/04/20 09:11:19 | 00,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Brian\Application Data\Sun
[2009/04/18 10:16:32 | 01,203,922 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/18 10:16:32 | 00,002,560 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\xpsp4res.dll
[2009/04/18 10:16:31 | 00,215,552 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/18 10:11:23 | 00,473,600 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/18 10:11:23 | 00,401,408 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/18 10:11:23 | 00,284,160 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/18 10:11:23 | 00,110,592 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\services.exe
[2009/04/18 10:11:22 | 00,729,088 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/18 10:11:22 | 00,714,752 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/18 10:11:22 | 00,617,472 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/18 10:11:22 | 00,453,120 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/18 10:11:22 | 00,227,840 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 21:35:54 | 00,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Brian\My Documents\My Received Files
[2009/04/15 18:55:42 | 00,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Brian\Local Settings\Application Data\Newsman Pro
[2009/04/15 07:53:10 | 00,000,000 | โ€”D | C] โ€“ C:\Program Files\NewsMan Pro
[2009/04/13 11:24:33 | 00,000,000 | โ€”D | C] โ€“ C:\Program Files\Trend Micro
[2009/04/07 18:54:29 | 00,000,000 | โ€”D | C] โ€“ C:\WINDOWS\pss
[2009/04/07 18:52:29 | 00,000,000 | โ€”D | C] โ€“ C:\Program Files\CleanUp2
[2009/04/07 06:35:32 | 00,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/04/06 06:20:53 | 00,000,712 | โ€”- | C] () โ€“ C:\Documents and Settings\Brian\Desktop\Outlook Express.lnk
[2009/04/06 06:19:37 | 00,000,654 | โ€”- | C] () โ€“ C:\Documents and Settings\Brian\Desktop\WinRAR.lnk
[2009/04/06 05:50:26 | 00,000,000 | โ€”D | C] โ€“ C:\Program Files\RAR Password Cracker
[2009/04/06 05:50:05 | 00,210,109 | โ€”- | C] () โ€“ C:\Program Files\rpc412_setup.exe
[2009/04/04 11:59:47 | 00,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Brian\My Documents\Cyberlink
[2009/04/04 11:59:47 | 00,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Brian\Application Data\CyberLink
[2009/04/04 11:59:46 | 00,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Brian\Local Settings\Application Data\PowerDVD
[2009/02/13 05:28:25 | 00,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\OpPrintServer.INI
[2009/02/13 04:46:50 | 00,000,116 | โ€”- | C] () โ€“ C:\WINDOWS\NeroDigital.ini
[2009/01/17 11:42:06 | 00,000,410 | โ€”- | C] () โ€“ C:\WINDOWS\BRWMARK.INI
[2009/01/16 07:40:09 | 00,000,376 | โ€”- | C] () โ€“ C:\WINDOWS\ODBC.INI
[2009/01/15 16:14:39 | 00,004,272 | Rโ€” | C] () โ€“ C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2008/12/31 16:04:42 | 00,691,560 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OGACheckControl.dll
[2008/05/16 13:01:00 | 01,703,936 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/16 13:01:00 | 01,019,904 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvwimg.dll
[2008/05/16 13:01:00 | 00,286,720 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvnt4cpl.dll
[2003/07/28 14:19:00 | 01,486,848 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nview.dll
[2003/07/28 14:19:00 | 00,466,944 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvshell.dll
[2003/07/17 06:51:23 | 00,000,576 | โ€”- | C] () โ€“ C:\WINDOWS\win.ini
[2003/07/17 06:47:28 | 00,000,227 | โ€”- | C] () โ€“ C:\WINDOWS\system.ini

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[2009/04/27 18:54:38 | 00,186,097 | โ€”- | M] () โ€“ C:\WINDOWS\System32\nvapps.xml
[2009/04/27 18:54:38 | 00,000,438 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\RegCure Program Check.job
[2009/04/27 18:54:32 | 00,000,006 | -Hโ€“ | M] () โ€“ C:\WINDOWS\tasks\SA.DAT
[2009/04/27 18:54:27 | 00,002,048 | โ€“S- | M] () โ€“ C:\WINDOWS\bootstat.dat
[2009/04/27 05:58:32 | 00,029,696 | โ€”- | M] () โ€“ C:\Documents and Settings\Brian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/27 05:56:57 | 00,000,116 | โ€”- | M] () โ€“ C:\WINDOWS\NeroDigital.ini
[2009/04/27 05:25:02 | 00,002,206 | โ€”- | M] () โ€“ C:\WINDOWS\System32\wpa.dbl
[2009/04/25 09:43:27 | 00,000,576 | โ€”- | M] () โ€“ C:\WINDOWS\win.ini
[2009/04/20 20:00:03 | 00,000,556 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Brian.job
[2009/04/19 05:38:24 | 00,477,846 | โ€”- | M] () โ€“ C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/19 05:38:24 | 00,406,636 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2009/04/19 05:38:24 | 00,063,644 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2009/04/18 22:26:29 | 00,001,374 | โ€”- | M] () โ€“ C:\WINDOWS\imsins.BAK
[2009/04/18 18:57:48 | 00,000,442 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\ParetoLogic Registration.job
[2009/04/11 09:37:47 | 00,021,504 | โ€”- | M] () โ€“ C:\Documents and Settings\Brian\My Documents\Geelong.xls
[2009/04/07 18:55:51 | 00,000,227 | โ€”- | M] () โ€“ C:\WINDOWS\system.ini
[2009/04/07 18:55:51 | 00,000,211 | RHS- | M] () โ€“ C:\boot.ini
[2009/04/07 00:57:24 | 24,921,544 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\MRT.exe
[2009/04/06 06:20:53 | 00,000,712 | โ€”- | M] () โ€“ C:\Documents and Settings\Brian\Desktop\Outlook Express.lnk
[2009/04/06 06:19:37 | 00,000,654 | โ€”- | M] () โ€“ C:\Documents and Settings\Brian\Desktop\WinRAR.lnk

========== LOP Check ==========

[2009/04/22 06:25:47 | 00,000,000 | RH-D | M] โ€“ C:\Documents and Settings\All Users\Application Data
[2009/01/16 07:47:35 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Adobe
[2009/02/12 18:28:29 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Ahead
[2009/02/07 05:47:38 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Cached Installations
[2009/03/02 18:00:33 | 00,000,000 | โ€“SD | M] โ€“ C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/02/12 04:51:38 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Nero
[2009/04/07 06:35:32 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/15 05:16:09 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\QuickTime
[2009/01/17 13:01:31 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Symantec
[2009/01/15 17:07:41 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/01/27 18:32:45 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\WinZip
[2009/04/22 06:25:47 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\WinZipSE
[2009/04/20 09:11:19 | 00,000,000 | RH-D | M] โ€“ C:\Documents and Settings\Brian\Application Data
[2009/01/16 13:40:32 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\Adobe
[2009/02/13 04:47:05 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\Ahead
[2009/01/18 14:14:53 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\ASCOMP Software
[2009/01/18 11:37:13 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\CoSoSys
[2009/04/04 11:59:47 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\CyberLink
[2009/01/27 18:29:44 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\Help
[2009/01/15 16:11:50 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\Identities
[2009/02/12 18:42:51 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\JPEGsnoop
[2009/01/16 06:50:57 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\Macromedia
[2009/04/11 09:05:33 | 00,000,000 | โ€“SD | M] โ€“ C:\Documents and Settings\Brian\Application Data\Microsoft
[2009/01/16 12:27:42 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\Nero
[2009/04/20 09:11:19 | 00,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Brian\Application Data\Sun
[2003/07/17 06:36:49 | 00,000,065 | RHโ€“ | M] () โ€“ C:\WINDOWS\Tasks\desktop.ini
[2009/04/20 20:00:03 | 00,000,556 | โ€”- | M] () โ€“ C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Brian.job
[2009/04/18 18:57:48 | 00,000,442 | โ€”- | M] () โ€“ C:\WINDOWS\Tasks\ParetoLogic Registration.job
[2009/04/27 18:54:38 | 00,000,438 | โ€”- | M] () โ€“ C:\WINDOWS\Tasks\RegCure Program Check.job
[2009/01/16 08:22:54 | 00,000,372 | โ€”- | M] () โ€“ C:\WINDOWS\Tasks\RegCure.job
[2009/04/27 18:54:32 | 00,000,006 | -Hโ€“ | M] () โ€“ C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
second file attachment

OTListIt Extras logfile created on: 27/04/2009 7:00:04 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Brian\Local Settings\Temporary Internet Files\Content.IE5\F3T19LC4
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1022.98 Mb Total Physical Memory | 614.45 Mb Available Physical Memory | 60.06% Memory free
2.40 Gb Paging File | 2.09 Gb Available in Paging File | 87.08% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 65.98 Gb Free Space | 88.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ROBINSON
Current User Name: Brian
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] โ€“ C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 23:23:34 | 00,558,080 | โ€”- | M] (Microsoft Corporation) โ€“ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/13 23:23:34 | 00,558,080 | โ€”- | M] (Microsoft Corporation) โ€“ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/04/14 04:42:30 | 01,695,232 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{195D958B-B33F-483B-82BC-8BD5AA14EAB4}" = Symantec Real Time Storage Protection Component
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Javaโ„ข 6 Update 13
"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}" = Component Framework
"{34EEB1F5-E939-40A1-A6BA-957282A4B2C8}" = Norton AntiVirus Help
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{52842271-922C-4907-8573-9F57A546509A}" = BigPond Wireless Broadband 2.10.6
"{52B80201-62AE-4E0A-B135-DDE0E32BF4A9}" = Canon VideoPresenter
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{570B96D1-70D3-4B48-93EF-029440FA1BCE}" = Camera Window
"{62120008-8E1E-4807-860D-A8B48F8552DB}" = Norton Protection Center
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74B4129B-24B6-44C0-8F6A-80F4E59139D2}" = SymNet
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}" = Norton AntiVirus
"{78E59435-A150-4C50-9B4B-370D9C15D1E5}" = DV NETWORK SOLUTION DISK
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{A3E0FF15-90D5-40CD-8565-B80A433B0D4C}" = PhotoStitch
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B148AB4B-C8FA-474B-B981-F2943C5B5BCD}" = OGA Notifier 1.7.0105.35.0
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B80CC46C-5839-4A48-B051-3CACF23A2718}_is1" = Eraser 5.86
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon Utilities ZoomBrowser EX
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{ED46AF9E-9157-41D6-9F2C-72818C015DB9}" = Canon Camera WIA Driver
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"BadCopy Pro" = BadCopy Pro
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{570B96D1-70D3-4B48-93EF-029440FA1BCE}" = Canon Camera Window for ZoomBrowser EX
"InstallShield_{78E59435-A150-4C50-9B4B-370D9C15D1E5}" = DV NETWORK SOLUTION DISK
"InstallShield_{A3E0FF15-90D5-40CD-8565-B80A433B0D4C}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{ED46AF9E-9157-41D6-9F2C-72818C015DB9}" = Canon MV630i WIA Driver
"IsoBuster_is1" = IsoBuster 2.5
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NewsMan Pro_is1" = NewsMan Pro (Freeware Edition) v3.0
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoRecord" = Canon PhotoRecord
"PROSet" = Intelยฎ PRO Network Connections Drivers
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"QuickTime" = QuickTime
"RAR Password Cracker" = RAR Password Cracker 4.12
"RegCure" = RegCure 1.5.0.0
"SereneScreen Marine Aquarium Time 2_is1" = SereneScreen Marine Aquarium Time 2
"SymSetup.{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}" = Norton AntiVirus (Symantec Corporation)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/04/2009 5:26:56 PM | Computer Name = ROBINSON | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 10/04/2009 7:05:14 PM | Computer Name = ROBINSON | Source = Application Hang | ID = 1002
Description = Hanging application wmplayer.exe, version 11.0.5721.5145, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/04/2009 5:16:55 AM | Computer Name = ROBINSON | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 14/04/2009 7:37:15 PM | Computer Name = ROBINSON | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 17/04/2009 2:44:19 AM | Computer Name = ROBINSON | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 19/04/2009 11:06:10 PM | Computer Name = ROBINSON | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 19/04/2009 11:06:13 PM | Computer Name = ROBINSON | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 19/04/2009 11:59:58 PM | Computer Name = ROBINSON | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 26/04/2009 3:25:22 PM | Computer Name = ROBINSON | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 27/04/2009 4:54:46 AM | Computer Name = ROBINSON | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

[ System Events ]
Error - 26/04/2009 3:25:22 PM | Computer Name = ROBINSON | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 26/04/2009 3:25:22 PM | Computer Name = ROBINSON | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%2

Error - 26/04/2009 3:25:24 PM | Computer Name = ROBINSON | Source = Service Control Manager | ID = 7000
Description = The Nero BackItUp Scheduler 4.0 service failed to start due to the
following error: %%3

Error - 27/04/2009 4:51:29 AM | Computer Name = ROBINSON | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%2

Error - 27/04/2009 4:51:29 AM | Computer Name = ROBINSON | Source = Service Control Manager | ID = 7000
Description = The Nero BackItUp Scheduler 4.0 service failed to start due to the
following error: %%3

Error - 27/04/2009 4:54:46 AM | Computer Name = ROBINSON | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 27/04/2009 4:54:46 AM | Computer Name = ROBINSON | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 27/04/2009 4:54:46 AM | Computer Name = ROBINSON | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 27/04/2009 4:54:47 AM | Computer Name = ROBINSON | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%2

Error - 27/04/2009 4:54:47 AM | Computer Name = ROBINSON | Source = Service Control Manager | ID = 7000
Description = The Nero BackItUp Scheduler 4.0 service failed to start due to the
following error: %%3


< End of report >
Josh26,


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report Asโ€ฆ.
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Josh26,

Log looks good :D


You need to create a new Clean restore point:

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

You may be asked to choose drive. Choose C: At top, click on More Options tab. Click Clean upโ€ฆ button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Your assistance has been greatly appreciated. Will follow last instructions when I get home. Was there any malware etc on my computer , as that last scan said all ok ? cheers Josh
Since this issue appears to be resolved โ€ฆ this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI