This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Cannot connect to internet after virus removal

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I recently removed a trojan virus from my desktop with Malwarebytes. The scans are clean but I am unable to connect to the Internet. I've tried several winsock fixes but no luck. I can, however, connect to the internet in safe mode. I can also use the same connection to access the internet on my laptop. Any help would be appreciated. Thanks.
Hi and :welcome:

You will need access to another computer to download HJT - transfer to the computer with the connection issue and run the program.

Post the HJT log back here.

:Instructions:

Download the latest version of Trendmicro's Hijackthis to your desktop.

Double click the downloaded program icon to install it [external image: Posted Image]
Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe

Open HJT

Click on Scan and Save a Log File, it will open in Notepad
Go to Format and make sure Wordwrap is Unchecked
Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread by using the Add Reply button.
Hi,

Thanks for the quick reply. Here's the info:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:31:00 PM, on 4/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\KSU CISCO VPN Client\VPN Client\cvpnd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\system32\NMSSvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\wanmpsvc.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\WINNT\system32\PROMon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINNT\system32\igfxtray.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\SK9910DM.EXE
C:\WINNT\GWMDMMSG.exe
C:\Program Files\PhoneTools\CapFax.EXE
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinTV\Ir.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7070
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: KSU CISCO VPN Client.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1196452767401
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {7CF052DE-C74F-421B-B04A-3B3037EF5887} (CCMPGui Class) - http://64.124.45.181/chaincast/proxy/CCMP.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: KSU CISCO VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\KSU CISCO VPN Client\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\system32\NMSSvc.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe

–
End of file - 11737 bytes
Hi,

Please do the following

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7070
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;


  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.


NEXT


In I.E.
Check internet options settings.
Tools > Internet Options > Connections
LAN settings
Choose "automatically detect settings"
uncheck both proxy settings boxes

If that resolves the connection issue, then do the following to see if there is anymore malware on your machine:

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt.
    Note:These logs can be located in the OTListIt2. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Thanks! I can connect now. Here is the info you requested:

OTListIt logfile created on: 4/23/2009 11:21:11 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

765.80 Mb Total Physical Memory | 329.58 Mb Available Physical Memory | 43.04% Memory free
1.08 Gb Paging File | 0.69 Gb Available in Paging File | 63.58% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 13.73 Gb Free Space | 18.43% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 982.72 Mb Total Space | 105.70 Mb Free Space | 10.76% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JIM20
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINNT\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\KSU CISCO VPN Client\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
PRC - C:\WINNT\wanmpsvc.exe (America Online, Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
PRC - C:\WINNT\system32\PROMon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe (Microsoft® Corporation)
PRC - C:\WINNT\system32\NMSSvc.exe (Intel Corporation)
PRC - C:\WINNT\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINNT\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINNT\system32\SK9910DM.EXE (Silitek Corporation)
PRC - C:\WINNT\GWMDMMSG.exe (GTW)
PRC - C:\Program Files\PhoneTools\CapFax.EXE (BVRP Software)
PRC - C:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\WinTV\Ir.exe (Hauppauge Computer Works)
PRC - C:\Program Files\Google\Google Updater\GoogleUpdater.exe (Google)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
PRC - C:\Documents and Settings\Owner\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (CLTNetCnService [Auto | Stopped]) – File not found
SRV - (CVPND [Auto | Running]) – C:\Program Files\KSU CISCO VPN Client\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINNT\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NMSSvc [Auto | Running]) – C:\WINNT\system32\NMSSvc.exe (Intel Corporation)
SRV - (PictureTaker [On_Demand | Stopped]) – File not found
SRV - (SeaPort [Auto | Running]) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (SfCtlCom [Auto | Running]) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (TMBMServer [Auto | Running]) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (tmproxy [On_Demand | Running]) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (WANMiniportService [Auto | Running]) – C:\WINNT\wanmpsvc.exe (America Online, Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ac97intc [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (BCMModem [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\BCMDM.sys (BCM)
DRV - (CVirtA [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (CVPNDRVA [Auto | Running]) – C:\WINNT\system32\Drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (DNE [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)
DRV - (E100B [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINNT\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (GTWModem [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\GWMDM.sys (GTW)
DRV - (HCWBT8xx [On_Demand | Running]) – C:\WINNT\system32\drivers\HCWBT8XX.sys (Hauppauge Computer Works)
DRV - (ialm [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (MA_CMIDI [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ma_cmidi.sys (M-Audio)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINNT\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv4 [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\nv4.sys (NVIDIA Corporation)
DRV - (PcdrNt [On_Demand | Stopped]) – C:\WINNT\System32\drivers\PcdrNt.sys (PC-Doctor Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Secdrv [Auto | Running]) – C:\WINNT\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Sk99202k [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\Sk99202k.sys (Silitek Corp.)
DRV - (Sk9920nt [System | Running]) – C:\WINNT\System32\DRIVERS\Sk9920nt.sys (Silitek Corp.)
DRV - (smwdm [On_Demand | Running]) – C:\WINNT\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (tmactmon [Auto | Running]) – C:\WINNT\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmcomm [Auto | Running]) – C:\WINNT\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmevtmgr [Auto | Running]) – C:\WINNT\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmpreflt [Auto | Running]) – C:\WINNT\system32\DRIVERS\tmpreflt.sys (Trend Micro Inc.)
DRV - (tmtdi [System | Running]) – C:\WINNT\system32\DRIVERS\tmtdi.sys (Trend Micro Inc.)
DRV - (tmxpflt [Auto | Running]) – C:\WINNT\system32\DRIVERS\tmxpflt.sys (Trend Micro Inc.)
DRV - (ultra [Boot | Running]) – C:\WINNT\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINNT\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (vsapint [Auto | Running]) – C:\WINNT\system32\DRIVERS\vsapint.sys (Trend Micro Inc.)
DRV - (vsdatant [On_Demand | Stopped]) – C:\WINNT\system32\vsdatant.sys (Zone Labs LLC)
DRV - (wanatw [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (WmBEnum [On_Demand | Running]) – C:\WINNT\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmFilter [On_Demand | Stopped]) – C:\WINNT\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmVirHid [On_Demand | Stopped]) – C:\WINNT\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore [On_Demand | Running]) – C:\WINNT\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ialmkchw.sys (Intel Corporation)
DRV - (NMSCFG [On_Demand | Running]) – C:\WINNT\system32\drivers\NMSCFG.SYS (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/01 22:32:19 | 00,000,000 | —D | M]


O1 HOSTS File: (736 bytes) - C:\WINNT\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll (Google Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [CapFax] C:\Program Files\PhoneTools\CapFax.EXE (BVRP Software)
O4 - HKLM..\Run: [GWMDMMSG] GWMDMMSG.exe (GTW)
O4 - HKLM..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE (Silitek Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check" File not found
O4 - HKLM..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume (Microsoft Corp.)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers (Microsoft® Corporation)
O4 - HKLM..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
O4 - HKLM..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
O4 - HKLM..\Run: [PROMon.exe] PROMon.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKLM..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ KSU CISCO VPN Client.lnk = C:\WINNT\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe (Hauppauge Computer Works)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe (Google)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINNT\System32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1196452767401 (MUWebControl Class)
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} hcp://system/RunExeActiveX.CAB (RunExeActiveX.RunExe)
O16 - DPF: {7CF052DE-C74F-421B-B04A-3B3037EF5887} http://64.124.45.181/chaincast/proxy/CCMP.cab (CCMPGui Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} hcp://system/StartFirstControl.CAB (StartFirstControl.CheckFirst)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…37849.503912037 (Reg Error: Key error.)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_06)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} http://chat.yahoo.com/cab/yvwrctl.cab (Yahoo! Webcam Viewer Wrapper)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINNT\system32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\autoexec.bat () - [ NTFS ]
O33 - MountPoints2\{194c58fe-66f5-11dd-827e-00038a000015}\Shell\AutoRun\command - "" = F:\system\viewer\FlipVideoforPC.exe – File not found
O33 - MountPoints2\{194c58fe-66f5-11dd-827e-00038a000015}\Shell\Flip Video for PC\command - "" = F:\system\viewer\FlipVideoforPC.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINNT\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2 C:\Documents and Settings\Owner\Desktop\*.tmp files]
[2009/04/23 11:20:07 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/04/22 21:30:29 | 00,001,734 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/04/22 21:30:05 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HJTInstall.exe
[2009/04/22 21:18:38 | 80,306,5856 | -HS- | C] () – C:\hiberfil.sys
[2009/04/22 17:16:59 | 00,186,880 | —- | C] (CEXX.ORG) – C:\Documents and Settings\Owner\Desktop\LSPFix.exe
[2009/04/22 16:41:40 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\pdh.dll
[2009/04/22 16:41:39 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\rpcss.dll
[2009/04/22 16:41:38 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\fastprox.dll
[2009/04/22 16:41:38 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\wmiprvse.exe
[2009/04/22 16:41:38 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\services.exe
[2009/04/22 16:41:37 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\wmiprvsd.dll
[2009/04/22 16:41:35 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\lsasrv.dll
[2009/04/22 16:41:35 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\advapi32.dll
[2009/04/22 16:41:34 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\ntdll.dll
[2009/04/22 16:40:01 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\xpsp4res.dll
[2009/04/22 16:40:00 | 01,203,922 | —- | C] () – C:\WINNT\System32\dllcache\sysmain.sdb
[2009/04/22 16:40:00 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\wordpad.exe
[2009/04/22 16:35:11 | 00,000,000 | —D | C] – C:\ERDNT
[2009/04/22 16:34:31 | 01,445,888 | —- | C] (Option^Explicit Software Solutions) – C:\Documents and Settings\Owner\Desktop\WinsockxpFix.exe
[2009/04/09 09:23:21 | 43,208,704 | —- | C] () – C:\Documents and Settings\Owner\Desktop\The Rain.wav
[2009/03/28 12:35:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Foundations Assignment
[2009/03/14 14:39:55 | 00,126,976 | —- | C] () – C:\WINNT\System32\unzdll.dll
[2009/03/06 22:30:58 | 00,061,440 | —- | C] () – C:\WINNT\System32\drivers\jhlvaxtf.sys
[2008/02/24 19:52:29 | 00,000,178 | —- | C] () – C:\WINNT\ChssBase.ini
[2008/02/19 02:33:34 | 00,446,352 | —- | C] () – C:\WINNT\System32\OpenQuicktimeLib.dll
[2007/08/31 16:10:49 | 00,065,536 | —- | C] () – C:\WINNT\System32\YCRWin32.dll
[2007/08/31 16:00:31 | 00,006,048 | —- | C] () – C:\WINNT\System32\MCC16.dll
[2007/07/16 12:58:10 | 00,197,408 | —- | C] () – C:\WINNT\System32\vpnapi.dll
[2007/07/16 12:58:00 | 00,193,312 | —- | C] () – C:\WINNT\System32\CSGina.dll
[2007/01/11 19:35:39 | 00,000,248 | —- | C] () – C:\WINNT\HCWBlast.ini
[2007/01/11 19:35:02 | 00,029,637 | —- | C] () – C:\WINNT\Irremote.ini
[2007/01/11 19:34:42 | 00,065,536 | —- | C] () – C:\WINNT\System32\dmcrypto.dll
[2007/01/11 19:32:24 | 00,003,353 | —- | C] () – C:\WINNT\HCWPNP.INI
[2006/03/26 19:33:51 | 00,000,145 | —- | C] () – C:\WINNT\game.INI
[2006/02/16 20:13:36 | 00,001,025 | —- | C] () – C:\WINNT\System32\sysprs7.dll
[2006/02/16 20:13:36 | 00,000,203 | —- | C] () – C:\WINNT\System32\lsprst7.dll
[2006/02/14 13:41:16 | 00,001,024 | —- | C] () – C:\WINNT\System32\clauth2.dll
[2006/02/14 13:41:16 | 00,001,024 | —- | C] () – C:\WINNT\System32\clauth1.dll
[2006/02/14 13:41:16 | 00,000,071 | —- | C] () – C:\WINNT\System32\ssprs.dll
[2006/02/14 13:41:16 | 00,000,000 | —- | C] () – C:\WINNT\System32\nsprs.dll
[2005/12/19 17:01:02 | 00,000,520 | —- | C] () – C:\WINNT\netdet.ini
[2005/10/01 15:15:11 | 00,106,496 | —- | C] () – C:\WINNT\System32\VSHP1020.DLL
[2005/01/22 13:35:36 | 00,000,044 | —- | C] () – C:\WINNT\Ezphoto.ini
[2004/07/25 17:44:51 | 00,056,832 | —- | C] () – C:\WINNT\System32\iyvu9_32.dll
[2004/07/20 23:18:11 | 00,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2004/06/29 16:22:09 | 00,025,601 | —- | C] () – C:\WINNT\CSTBox.INI
[2004/06/15 20:47:51 | 00,000,181 | —- | C] () – C:\WINNT\civ.ini
[2004/05/29 14:33:05 | 00,000,525 | —- | C] () – C:\WINNT\MAXLINK.INI
[2004/02/07 15:14:14 | 00,000,006 | —- | C] () – C:\WINNT\msoffice.ini
[2003/02/01 19:24:48 | 00,101,376 | —- | C] () – C:\WINNT\System32\hpgt34.dll
[2003/02/01 19:21:08 | 00,108,032 | —- | C] () – C:\WINNT\System32\sh33w32.dll
[2002/11/07 15:49:00 | 00,021,840 | —- | C] () – C:\WINNT\System32\SIntfNT.dll
[2002/11/07 15:49:00 | 00,017,212 | —- | C] () – C:\WINNT\System32\SIntf32.dll
[2002/11/07 15:49:00 | 00,012,067 | —- | C] () – C:\WINNT\System32\SIntf16.dll
[2002/09/22 18:27:34 | 00,210,944 | —- | C] () – C:\WINNT\System32\MSVCRT10.DLL
[2002/09/22 18:27:33 | 00,100,864 | —- | C] () – C:\WINNT\System32\Dc50ip32.dll
[2002/09/22 18:27:33 | 00,065,864 | —- | C] () – C:\WINNT\System32\Digita.sys
[2002/09/22 18:27:33 | 00,006,144 | —- | C] () – C:\WINNT\System32\ImgLibLead.dll
[2002/09/22 18:24:56 | 00,000,037 | —- | C] () – C:\WINNT\wininit.ini
[2002/09/15 00:03:39 | 00,000,156 | —- | C] () – C:\WINNT\QTW.INI
[2002/09/07 15:27:26 | 00,000,459 | —- | C] () – C:\WINNT\AudioCleaning.INI
[2002/09/07 14:30:03 | 00,010,240 | —- | C] () – C:\WINNT\System32\vidx16.dll
[2002/09/07 14:28:57 | 00,000,083 | —- | C] () – C:\WINNT\magix.ini
[2002/09/05 15:35:05 | 00,000,020 | —- | C] () – C:\WINNT\InfModM.ini
[2002/09/05 15:19:37 | 00,000,045 | —- | C] () – C:\WINNT\EPSC62.ini
[2002/08/29 22:26:35 | 00,000,061 | —- | C] () – C:\WINNT\smscfg.ini
[2002/08/29 22:15:53 | 00,000,370 | —- | C] () – C:\WINNT\ODBC.INI
[2002/08/29 22:13:18 | 00,000,637 | —- | C] () – C:\WINNT\QUICKEN.INI
[2002/08/29 22:13:18 | 00,000,052 | —- | C] () – C:\WINNT\intuprof.ini
[2002/08/29 22:11:44 | 00,000,256 | —- | C] () – C:\WINNT\System32\UPDATE.INI
[2002/08/29 22:11:42 | 00,000,699 | —- | C] () – C:\WINNT\System32\OEMINFO.INI
[2002/03/26 09:36:48 | 00,069,632 | —- | C] () – C:\WINNT\System32\PROInst.dll
[2002/02/06 09:04:14 | 00,065,536 | —- | C] () – C:\WINNT\System32\NMSInst.dll
[2001/10/09 14:08:15 | 00,000,873 | —- | C] () – C:\WINNT\orun32.ini
[1999/01/22 14:46:56 | 00,065,536 | —- | C] () – C:\WINNT\System32\MSRTEDIT.DLL
[1980/01/01 01:00:00 | 00,262,144 | —- | C] () – C:\WINNT\System32\shpshftr.dll
[1980/01/01 01:00:00 | 00,009,785 | —- | C] () – C:\WINNT\System32\drivers\a312.sys
[1980/01/01 01:00:00 | 00,000,752 | —- | C] () – C:\WINNT\win.ini
[1980/01/01 01:00:00 | 00,000,259 | —- | C] () – C:\WINNT\SYSTEM.INI

========== Files - Modified Within 30 Days ==========

[1 C:\WINNT\*.tmp files]
[2 C:\Documents and Settings\Owner\Desktop\*.tmp files]
[2009/04/23 11:19:04 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/04/23 11:08:22 | 00,000,330 | -H– | M] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2009/04/23 11:05:00 | 00,001,158 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2009/04/23 11:04:59 | 00,002,485 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ KSU CISCO VPN Client.lnk
[2009/04/23 11:04:27 | 00,000,006 | -H– | M] () – C:\WINNT\tasks\SA.DAT
[2009/04/23 11:04:22 | 00,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2009/04/23 11:04:21 | 80,306,5856 | -HS- | M] () – C:\hiberfil.sys
[2009/04/23 01:08:34 | 00,001,374 | —- | M] () – C:\WINNT\imsins.BAK
[2009/04/22 21:30:30 | 00,001,734 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/04/22 21:28:46 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HJTInstall.exe
[2009/04/22 17:16:14 | 00,186,880 | —- | M] (CEXX.ORG) – C:\Documents and Settings\Owner\Desktop\LSPFix.exe
[2009/04/22 17:07:47 | 00,347,092 | —- | M] () – C:\WINNT\System32\PerfStringBackup.INI
[2009/04/22 17:07:47 | 00,305,648 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2009/04/22 17:07:47 | 00,037,964 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2009/04/22 16:47:21 | 00,000,736 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2009/04/22 16:31:28 | 01,445,888 | —- | M] (Option^Explicit Software Solutions) – C:\Documents and Settings\Owner\Desktop\WinsockxpFix.exe
[2009/04/18 11:45:17 | 00,002,133 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/04/09 09:24:18 | 43,208,704 | —- | M] () – C:\Documents and Settings\Owner\Desktop\The Rain.wav
[2009/04/06 10:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINNT\System32\MRT.exe
[2009/03/30 13:01:40 | 00,000,076 | -HS- | M] () – C:\Documents and Settings\Owner\My Documents\desktop.ini
[2009/03/27 02:58:38 | 01,203,922 | —- | M] () – C:\WINNT\System32\dllcache\sysmain.sdb

========== LOP Check ==========

[2009/03/06 20:04:25 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/01 00:39:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2006/02/16 17:40:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/09/01 14:31:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/11/22 18:16:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2002/09/18 21:22:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund LLC
[2007/08/31 16:19:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2005/01/30 15:26:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/02/22 14:42:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2009/03/06 20:04:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2006/03/31 01:28:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2006/03/31 01:28:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2009/03/01 22:34:20 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/08/31 16:00:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2002/09/12 16:35:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2008/02/29 11:10:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/08/10 16:11:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2003/06/15 17:17:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2001/10/09 14:10:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2004/05/29 15:04:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/03/02 00:07:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2004/05/29 14:33:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2004/05/29 14:33:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2008/05/22 14:18:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2007/11/11 20:50:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trend Micro
[2005/08/05 19:14:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/08/31 16:51:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2007/08/31 16:23:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/03/06 20:04:49 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Owner\Application Data
[2008/03/19 11:27:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Adobe
[2005/12/07 13:58:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeUM
[2008/03/19 19:43:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apple Computer
[2004/05/29 14:42:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ArcSoft
[2009/03/29 15:27:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Canon
[2008/02/24 21:02:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ChessBase
[2005/01/30 15:27:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CyberLink
[2007/02/21 11:56:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FUJIFILM
[2007/04/13 18:18:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Google
[2003/04/24 12:29:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Help
[2001/10/09 13:57:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Identities
[2009/01/24 00:37:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InstallShield
[2007/01/27 18:07:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\iShell
[2006/11/16 22:56:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Macromedia
[2009/03/06 20:04:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2005/05/11 15:19:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\McAfee
[2007/11/30 16:41:22 | 00,000,000 | –SD | M] – C:\Documents and Settings\Owner\Application Data\Microsoft
[2009/02/12 20:17:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2002/09/12 16:47:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2004/05/29 14:33:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ScanSoft
[2005/08/26 13:04:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sun
[2002/08/29 22:17:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Symantec
[2007/08/31 16:26:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Yahoo!
[2008/10/25 14:13:06 | 00,000,284 | —- | M] () – C:\WINNT\Tasks\AppleSoftwareUpdate.job
[2001/08/18 13:00:00 | 00,000,065 | RH– | M] () – C:\WINNT\Tasks\desktop.ini
[2009/04/23 11:08:22 | 00,000,330 | -H– | M] () – C:\WINNT\Tasks\MP Scheduled Scan.job
[2009/04/23 11:04:27 | 00,000,006 | -H– | M] () – C:\WINNT\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
OTListIt Extras logfile created on: 4/23/2009 11:21:11 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

765.80 Mb Total Physical Memory | 329.58 Mb Available Physical Memory | 43.04% Memory free
1.08 Gb Paging File | 0.69 Gb Available in Paging File | 63.58% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 13.73 Gb Free Space | 18.43% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 982.72 Mb Total Space | 105.70 Mb Free Space | 10.76% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JIM20
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"80:TCP" = 80:TCP:*:Enabled:nfr
"7070:TCP" = 7070:TCP:*:Enabled:nfr

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\PC-Doctor for Windows\Pcdrw32.exe:*:Disabled:browser ()
C:\games\RedFaction\rf.exe:*:Disabled:Red Faction File not found
C:\games\RedFaction\RedFaction.exe:*:Disabled:Red Faction Launcher File not found
C:\Program Files\Warcraft III\Warcraft III.exe:*:Disabled:Warcraft III File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server File not found
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Disabled:Yahoo! Messenger File not found
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01A4AEDE-F219-49A2-B855-16A016EAF9A4}" = Intel® PROSet II
"{0AE19D89-17A9-404D-932A-FAAF43F3C77E}" = SPSS 14.0 for Windows
"{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}" = KSU CISCO VPN Client
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.4.3
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 12
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{379BD39E-F13E-458F-96D8-56BD7F2CC516}" = Series II MIDI
"{39DA87A1-0B26-4562-A70C-2A6147366E47}" = PC-Doctor Services
"{3FF0269F-3C3F-4C9D-832B-AAECC8B593CF}" = Grandmaster Challenge
"{4E10E7FC-36CD-4C22-AC20-9E15692E8C2F}" = Virtual Sound Canvas DXi
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{611BD998-34B9-4DDA-00AE-0CB4632E86FA}" = SimCity 4
"{6249C22D-E6A8-407B-BA8B-40298848ED94}" = OmniPage SE
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7148F0A8-6813-11D6-A77B-00B0D0142060}" = Java 2 Runtime Environment, SE v1.4.2_06
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro AntiVirus
"{75C023EC-64A0-44F7-9D99-C6F6E21EB6F0}" = Do More 5.0
"{82CA0A0C-A3EC-4167-B694-909205B2EDEC}" = muvee Plugin 1.0
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}" = Google Earth
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}" = PC-Doctor Consumer UI
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}" = Microsoft Works 6.0
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}" = Trend Micro AntiVirus
"{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B360A8E5-C171-4AAE-9777-65B3CDB0072C}" = CanoScan LiDE20,30 Manual
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager
"{BAD59025-5B73-4E12-B789-0028C5A573C2}" = PC-Doctor Diagnostics
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{C3A439E4-7303-491F-A678-CEA36A87D517}" = Microsoft Works Suite Add-in for Microsoft Word
"{C769A271-7E1C-48F9-B331-474600DD4C06}" = Microsoft Picture It! Photo 2002
"{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{E3436EE2-D5CB-4249-840B-3A0140CC34C3}" = PhoneTools
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F1FBF021-B965-42D3-BF63-D7A121B5490D}" = HelpSpot
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"AdobeESD" = Adobe Download Manager 1.2 (Remove Only)
"BroadJump Client Foundation" = BroadJump Client Foundation
"Cakewalk Music Creator 2003" = Cakewalk Music Creator 2003
"DreamStation DXi2" = DreamStation DXi2
"ExamView Pro" = ExamView Pro
"Finale NotePad 2003a" = Finale NotePad 2003a
"Google Updater" = Google Updater
"GTW V.92 Voicemodem" = GTW V.92 Voicemodem
"Hauppauge WinTV Infrared Remote" = Hauppauge WinTV Infrared Remote
"Hauppauge WinTV2000" = Hauppauge WinTV2000
"HijackThis" = HijackThis 2.0.2
"HP-LaserJet 1020 series" = LaserJet 1020 series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"InstallShield_{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"MacGAMUT 2000" = MacGAMUT 2000
"MAGIX audio cleaning 3.0" = MAGIX audio cleaning 3.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Monopoly" = Monopoly
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Network Play System (Patching)" = Network Play System (Patching)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OrderReminder HP LaserJet 1020" = OrderReminder HP LaserJet 1020
"PROSet" = Intel® Network Connections Drivers
"Revo Uninstaller" = Revo Uninstaller 1.80
"Shockwave" = Shockwave
"SK_PS2MillenniumKeyboard" = PS/2 Millennium Keyboard
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"web-radio Toolbar" = web-radio Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2002Setup" = Microsoft Works 2002 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Applications" = AT&T Yahoo! Applications

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/4/2009 10:41:41 AM | Computer Name = JIM20 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 4/4/2009 11:00:03 AM | Computer Name = JIM20 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 4/6/2009 11:00:03 AM | Computer Name = JIM20 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 4/8/2009 11:00:05 AM | Computer Name = JIM20 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 4/9/2009 11:00:04 AM | Computer Name = JIM20 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 4/13/2009 12:31:31 PM | Computer Name = JIM20 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 4/16/2009 11:22:31 AM | Computer Name = JIM20 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 4/18/2009 11:00:04 AM | Computer Name = JIM20 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 4/20/2009 1:34:45 PM | Computer Name = JIM20 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 4/22/2009 9:39:48 PM | Computer Name = JIM20 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 4/22/2009 12:30:56 PM | Computer Name = JIM20 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Updater Service
service to connect.

Error - 4/22/2009 1:15:50 PM | Computer Name = JIM20 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 4/22/2009 4:37:39 PM | Computer Name = JIM20 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Updater Service
service to connect.

Error - 4/22/2009 4:49:10 PM | Computer Name = JIM20 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Updater Service
service to connect.

Error - 4/22/2009 5:03:27 PM | Computer Name = JIM20 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Updater Service
service to connect.

Error - 4/22/2009 5:24:57 PM | Computer Name = JIM20 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/22/2009 5:26:07 PM | Computer Name = JIM20 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm tmtdi

Error - 4/22/2009 9:17:44 PM | Computer Name = JIM20 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/22/2009 9:18:46 PM | Computer Name = JIM20 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Updater Service
service to connect.

Error - 4/23/2009 11:04:33 AM | Computer Name = JIM20 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Google Updater Service
service to connect.


< End of report >
Hi,

Please do the following:

Run OTList2.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTLI2

    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found
    O33 - MountPoints2\{194c58fe-66f5-11dd-827e-00038a000015}\Shell\AutoRun\command - "" = F:\system\viewer\FlipVideoforPC.exe – File not found
    O33 - MountPoints2\{194c58fe-66f5-11dd-827e-00038a000015}\Shell\Flip Video for PC\command - "" = F:\system\viewer\FlipVideoforPC.exe – File not found
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

NEXT

I would like you to upload a file to be scanned
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
    • C:\WINNT\System32\drivers\jhlvaxtf.sys
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.





NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
Hi,

This is the new OTList. One note with this. The program froze while trying to empty the temporary folders. I tried it twice. Here is the information:

OTListIt logfile created on: 4/23/2009 8:47:59 PM - Run 3
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

765.80 Mb Total Physical Memory | 311.86 Mb Available Physical Memory | 40.72% Memory free
1.08 Gb Paging File | 0.65 Gb Available in Paging File | 59.77% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 14.79 Gb Free Space | 19.84% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 982.72 Mb Total Space | 105.56 Mb Free Space | 10.74% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JIM20
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINNT\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINNT\system32\PROMon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe (Microsoft® Corporation)
PRC - C:\WINNT\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINNT\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINNT\system32\SK9910DM.EXE (Silitek Corporation)
PRC - C:\WINNT\GWMDMMSG.exe (GTW)
PRC - C:\Program Files\PhoneTools\CapFax.EXE (BVRP Software)
PRC - C:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\Program Files\WinTV\Ir.exe (Hauppauge Computer Works)
PRC - C:\Program Files\Google\Google Updater\GoogleUpdater.exe (Google)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\KSU CISCO VPN Client\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
PRC - C:\WINNT\wanmpsvc.exe (America Online, Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\WINNT\system32\taskmgr.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (CLTNetCnService [Auto | Stopped]) – File not found
SRV - (CVPND [Auto | Running]) – C:\Program Files\KSU CISCO VPN Client\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINNT\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NMSSvc [Auto | Stopped]) – C:\WINNT\system32\NMSSvc.exe (Intel Corporation)
SRV - (PictureTaker [On_Demand | Stopped]) – File not found
SRV - (SeaPort [Auto | Running]) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (SfCtlCom [Auto | Running]) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (TMBMServer [Auto | Running]) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (tmproxy [On_Demand | Running]) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (WANMiniportService [Auto | Running]) – C:\WINNT\wanmpsvc.exe (America Online, Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ac97intc [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (BCMModem [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\BCMDM.sys (BCM)
DRV - (CVirtA [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (CVPNDRVA [Auto | Running]) – C:\WINNT\system32\Drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (DNE [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)
DRV - (E100B [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINNT\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (GTWModem [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\GWMDM.sys (GTW)
DRV - (HCWBT8xx [On_Demand | Running]) – C:\WINNT\system32\drivers\HCWBT8XX.sys (Hauppauge Computer Works)
DRV - (ialm [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (MA_CMIDI [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ma_cmidi.sys (M-Audio)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINNT\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv4 [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\nv4.sys (NVIDIA Corporation)
DRV - (PcdrNt [On_Demand | Stopped]) – C:\WINNT\System32\drivers\PcdrNt.sys (PC-Doctor Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Secdrv [Auto | Running]) – C:\WINNT\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Sk99202k [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\Sk99202k.sys (Silitek Corp.)
DRV - (Sk9920nt [System | Running]) – C:\WINNT\System32\DRIVERS\Sk9920nt.sys (Silitek Corp.)
DRV - (smwdm [On_Demand | Running]) – C:\WINNT\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (tmactmon [Auto | Running]) – C:\WINNT\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmcomm [Auto | Running]) – C:\WINNT\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmevtmgr [Auto | Running]) – C:\WINNT\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmpreflt [Auto | Running]) – C:\WINNT\system32\DRIVERS\tmpreflt.sys (Trend Micro Inc.)
DRV - (tmtdi [System | Running]) – C:\WINNT\system32\DRIVERS\tmtdi.sys (Trend Micro Inc.)
DRV - (tmxpflt [Auto | Running]) – C:\WINNT\system32\DRIVERS\tmxpflt.sys (Trend Micro Inc.)
DRV - (ultra [Boot | Running]) – C:\WINNT\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINNT\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (vsapint [Auto | Running]) – C:\WINNT\system32\DRIVERS\vsapint.sys (Trend Micro Inc.)
DRV - (vsdatant [On_Demand | Stopped]) – C:\WINNT\system32\vsdatant.sys (Zone Labs LLC)
DRV - (wanatw [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (WmBEnum [On_Demand | Running]) – C:\WINNT\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmFilter [On_Demand | Stopped]) – C:\WINNT\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmVirHid [On_Demand | Stopped]) – C:\WINNT\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore [On_Demand | Running]) – C:\WINNT\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://flashline.kent.edu/cp/home/loginf
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/01 22:32:19 | 00,000,000 | —D | M]


O1 HOSTS File: (736 bytes) - C:\WINNT\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll (Google Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O4 - HKLM..\Run: [CapFax] C:\Program Files\PhoneTools\CapFax.EXE (BVRP Software)
O4 - HKLM..\Run: [GWMDMMSG] GWMDMMSG.exe (GTW)
O4 - HKLM..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE (Silitek Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check" File not found
O4 - HKLM..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume (Microsoft Corp.)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers (Microsoft® Corporation)
O4 - HKLM..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
O4 - HKLM..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
O4 - HKLM..\Run: [PROMon.exe] PROMon.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKLM..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ KSU CISCO VPN Client.lnk = C:\WINNT\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe (Hauppauge Computer Works)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe (Google)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINNT\System32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1196452767401 (MUWebControl Class)
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} hcp://system/RunExeActiveX.CAB (RunExeActiveX.RunExe)
O16 - DPF: {7CF052DE-C74F-421B-B04A-3B3037EF5887} http://64.124.45.181/chaincast/proxy/CCMP.cab (CCMPGui Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} hcp://system/StartFirstControl.CAB (StartFirstControl.CheckFirst)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…37849.503912037 (Reg Error: Key error.)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_06)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} http://chat.yahoo.com/cab/yvwrctl.cab (Yahoo! Webcam Viewer Wrapper)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINNT\system32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\autoexec.bat () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINNT\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2 C:\Documents and Settings\Owner\Desktop\*.tmp files]
[2009/04/23 19:49:51 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/04/23 14:20:14 | 00,000,945 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2009/04/23 14:14:50 | 00,000,000 | —D | C] – C:\WINNT\System32\log
[2009/04/23 14:09:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Anti-Virus Software Fixes
[2009/04/23 11:20:07 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/04/22 21:18:38 | 80,306,5856 | -HS- | C] () – C:\hiberfil.sys
[2009/04/22 16:41:40 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\pdh.dll
[2009/04/22 16:41:39 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\rpcss.dll
[2009/04/22 16:41:38 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\fastprox.dll
[2009/04/22 16:41:38 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\wmiprvse.exe
[2009/04/22 16:41:38 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\services.exe
[2009/04/22 16:41:37 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\wmiprvsd.dll
[2009/04/22 16:41:35 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\lsasrv.dll
[2009/04/22 16:41:35 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\advapi32.dll
[2009/04/22 16:41:34 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\ntdll.dll
[2009/04/22 16:40:01 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\xpsp4res.dll
[2009/04/22 16:40:00 | 01,203,922 | —- | C] () – C:\WINNT\System32\dllcache\sysmain.sdb
[2009/04/22 16:40:00 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\wordpad.exe
[2009/04/22 16:35:11 | 00,000,000 | —D | C] – C:\ERDNT
[2009/03/28 12:35:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Foundations Assignment
[2009/03/14 14:39:55 | 00,126,976 | —- | C] () – C:\WINNT\System32\unzdll.dll
[2009/03/06 22:30:58 | 00,061,440 | —- | C] () – C:\WINNT\System32\drivers\jhlvaxtf.sys
[2008/02/24 19:52:29 | 00,000,178 | —- | C] () – C:\WINNT\ChssBase.ini
[2008/02/19 02:33:34 | 00,446,352 | —- | C] () – C:\WINNT\System32\OpenQuicktimeLib.dll
[2007/08/31 16:10:49 | 00,065,536 | —- | C] () – C:\WINNT\System32\YCRWin32.dll
[2007/08/31 16:00:31 | 00,006,048 | —- | C] () – C:\WINNT\System32\MCC16.dll
[2007/07/16 12:58:10 | 00,197,408 | —- | C] () – C:\WINNT\System32\vpnapi.dll
[2007/07/16 12:58:00 | 00,193,312 | —- | C] () – C:\WINNT\System32\CSGina.dll
[2007/01/11 19:35:39 | 00,000,248 | —- | C] () – C:\WINNT\HCWBlast.ini
[2007/01/11 19:35:02 | 00,029,637 | —- | C] () – C:\WINNT\Irremote.ini
[2007/01/11 19:34:42 | 00,065,536 | —- | C] () – C:\WINNT\System32\dmcrypto.dll
[2007/01/11 19:32:24 | 00,003,353 | —- | C] () – C:\WINNT\HCWPNP.INI
[2006/03/26 19:33:51 | 00,000,145 | —- | C] () – C:\WINNT\game.INI
[2006/02/16 20:13:36 | 00,001,025 | —- | C] () – C:\WINNT\System32\sysprs7.dll
[2006/02/16 20:13:36 | 00,000,203 | —- | C] () – C:\WINNT\System32\lsprst7.dll
[2006/02/14 13:41:16 | 00,001,024 | —- | C] () – C:\WINNT\System32\clauth2.dll
[2006/02/14 13:41:16 | 00,001,024 | —- | C] () – C:\WINNT\System32\clauth1.dll
[2006/02/14 13:41:16 | 00,000,071 | —- | C] () – C:\WINNT\System32\ssprs.dll
[2006/02/14 13:41:16 | 00,000,000 | —- | C] () – C:\WINNT\System32\nsprs.dll
[2005/12/19 17:01:02 | 00,000,520 | —- | C] () – C:\WINNT\netdet.ini
[2005/10/01 15:15:11 | 00,106,496 | —- | C] () – C:\WINNT\System32\VSHP1020.DLL
[2005/01/22 13:35:36 | 00,000,044 | —- | C] () – C:\WINNT\Ezphoto.ini
[2004/07/25 17:44:51 | 00,056,832 | —- | C] () – C:\WINNT\System32\iyvu9_32.dll
[2004/07/20 23:18:11 | 00,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2004/06/29 16:22:09 | 00,025,601 | —- | C] () – C:\WINNT\CSTBox.INI
[2004/06/15 20:47:51 | 00,000,181 | —- | C] () – C:\WINNT\civ.ini
[2004/05/29 14:33:05 | 00,000,525 | —- | C] () – C:\WINNT\MAXLINK.INI
[2004/02/07 15:14:14 | 00,000,006 | —- | C] () – C:\WINNT\msoffice.ini
[2003/02/01 19:24:48 | 00,101,376 | —- | C] () – C:\WINNT\System32\hpgt34.dll
[2003/02/01 19:21:08 | 00,108,032 | —- | C] () – C:\WINNT\System32\sh33w32.dll
[2002/11/07 15:49:00 | 00,021,840 | —- | C] () – C:\WINNT\System32\SIntfNT.dll
[2002/11/07 15:49:00 | 00,017,212 | —- | C] () – C:\WINNT\System32\SIntf32.dll
[2002/11/07 15:49:00 | 00,012,067 | —- | C] () – C:\WINNT\System32\SIntf16.dll
[2002/09/22 18:27:34 | 00,210,944 | —- | C] () – C:\WINNT\System32\MSVCRT10.DLL
[2002/09/22 18:27:33 | 00,100,864 | —- | C] () – C:\WINNT\System32\Dc50ip32.dll
[2002/09/22 18:27:33 | 00,065,864 | —- | C] () – C:\WINNT\System32\Digita.sys
[2002/09/22 18:27:33 | 00,006,144 | —- | C] () – C:\WINNT\System32\ImgLibLead.dll
[2002/09/22 18:24:56 | 00,000,037 | —- | C] () – C:\WINNT\wininit.ini
[2002/09/15 00:03:39 | 00,000,156 | —- | C] () – C:\WINNT\QTW.INI
[2002/09/07 15:27:26 | 00,000,459 | —- | C] () – C:\WINNT\AudioCleaning.INI
[2002/09/07 14:30:03 | 00,010,240 | —- | C] () – C:\WINNT\System32\vidx16.dll
[2002/09/07 14:28:57 | 00,000,083 | —- | C] () – C:\WINNT\magix.ini
[2002/09/05 15:35:05 | 00,000,020 | —- | C] () – C:\WINNT\InfModM.ini
[2002/09/05 15:19:37 | 00,000,045 | —- | C] () – C:\WINNT\EPSC62.ini
[2002/08/29 22:26:35 | 00,000,061 | —- | C] () – C:\WINNT\smscfg.ini
[2002/08/29 22:15:53 | 00,000,370 | —- | C] () – C:\WINNT\ODBC.INI
[2002/08/29 22:13:18 | 00,000,637 | —- | C] () – C:\WINNT\QUICKEN.INI
[2002/08/29 22:13:18 | 00,000,052 | —- | C] () – C:\WINNT\intuprof.ini
[2002/08/29 22:11:44 | 00,000,256 | —- | C] () – C:\WINNT\System32\UPDATE.INI
[2002/08/29 22:11:42 | 00,000,699 | —- | C] () – C:\WINNT\System32\OEMINFO.INI
[2002/03/26 09:36:48 | 00,069,632 | —- | C] () – C:\WINNT\System32\PROInst.dll
[2002/02/06 09:04:14 | 00,065,536 | —- | C] () – C:\WINNT\System32\NMSInst.dll
[2001/10/09 14:08:15 | 00,000,873 | —- | C] () – C:\WINNT\orun32.ini
[1999/01/22 14:46:56 | 00,065,536 | —- | C] () – C:\WINNT\System32\MSRTEDIT.DLL
[1980/01/01 01:00:00 | 00,262,144 | —- | C] () – C:\WINNT\System32\shpshftr.dll
[1980/01/01 01:00:00 | 00,009,785 | —- | C] () – C:\WINNT\System32\drivers\a312.sys
[1980/01/01 01:00:00 | 00,000,752 | —- | C] () – C:\WINNT\win.ini
[1980/01/01 01:00:00 | 00,000,259 | —- | C] () – C:\WINNT\SYSTEM.INI

========== Files - Modified Within 30 Days ==========

[1 C:\WINNT\*.tmp files]
[2 C:\Documents and Settings\Owner\Desktop\*.tmp files]
[2009/04/23 20:40:14 | 00,000,330 | -H– | M] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2009/04/23 20:37:17 | 00,001,158 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2009/04/23 20:36:44 | 00,002,485 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ KSU CISCO VPN Client.lnk
[2009/04/23 20:36:37 | 00,000,006 | -H– | M] () – C:\WINNT\tasks\SA.DAT
[2009/04/23 20:36:33 | 00,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2009/04/23 20:36:32 | 80,306,5856 | -HS- | M] () – C:\hiberfil.sys
[2009/04/23 14:21:44 | 00,305,648 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2009/04/23 14:21:44 | 00,037,964 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2009/04/23 14:21:43 | 00,347,092 | —- | M] () – C:\WINNT\System32\PerfStringBackup.INI
[2009/04/23 14:20:14 | 00,000,945 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2009/04/23 11:19:04 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/04/23 01:08:34 | 00,001,374 | —- | M] () – C:\WINNT\imsins.BAK
[2009/04/22 16:47:21 | 00,000,736 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2009/04/18 11:45:17 | 00,002,133 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2009/04/06 10:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINNT\System32\MRT.exe
[2009/03/30 13:01:40 | 00,000,076 | -HS- | M] () – C:\Documents and Settings\Owner\My Documents\desktop.ini
[2009/03/27 02:58:38 | 01,203,922 | —- | M] () – C:\WINNT\System32\dllcache\sysmain.sdb
< End of report >
Hi,

This is the online virus scan report:

VirSCAN.org Scanned Report :
Scanned time : 2009/04/23 20:57:03 (EDT)
Scanner results: 16% Scanner(6/38) found malware!
File Name : jhlvaxtf.sys
File Size : 61440 byte
File Type : PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5 : 589312a3b46721c5a751e4d5222a89be
SHA1 : 3a497d3968a4f6e3c648d196da38e5f98e75ec30
Online report : http://virscan.org/report/d431bff0ca4da1eb…cee43dab85.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090424020229 2009-04-24 1.84 -
AhnLab V3 2009.04.24.00 2009.04.24 2009-04-24 1.34 Win-Trojan/Avenger.61440
AntiVir 7.9.0.155 7.1.3.102 2009-04-23 2.02 -
Antiy 2.0.18 20090423.2316706 2009-04-23 0.12 -
Arcavir 2009 200904231200 2009-04-23 0.12 -
Authentium 5.1.1 200904231938 2009-04-23 1.65 -
AVAST! 3.0.1 090423-0 2009-04-23 0.01 -
AVG 7.5.52.442 270.12.4/2077 2009-04-23 2.03 -
BitDefender 7.81008.2850060 7.24970 2009-04-24 2.67 -
CA (VET) 9.0.0.143 31.6.6472 2009-04-24 5.58 -
ClamAV 0.95 9280 2009-04-24 0.01 -
Comodo 3.8 1130 2009-04-23 0.80 -
CP Secure 1.1.0.715 2009.04.24 2009-04-24 8.48 Malware.W32.Agent.fu
Dr.Web 4.44.0.9170 2009.04.23 2009-04-23 4.43 -
F-Prot 4.4.4.56 20090423 2009-04-23 1.63 -
F-Secure 5.51.6100 2009.04.24.01 2009-04-24 0.06 -
Fortinet 2.81-3.117 10.313 2009-04-23 0.18 PossibleThreat
GData 19.4826/19.308 20090423 2009-04-23 3.60 -
ViRobot 20090423 2009.04.23 2009-04-23 0.41 -
Ikarus T3.1.01.49 2009.04.23.72621 2009-04-23 2.71 -
JiangMin 11.0.706 2009.04.23 2009-04-23 1.76 Hoax.Agent.f
Kaspersky 5.5.10 2009.04.23 2009-04-23 0.05 -
KingSoft 2009.2.5.15 2009.4.23.21 2009-04-23 0.62 -
McAfee 5.3.00 5594 2009-04-23 2.77 -
Microsoft 1.4602 2009.04.24 2009-04-24 10.42 -
mks_vir 2.01 2009.04.23 2009-04-23 2.83 -
Norman 6.00.06 6.00.00 2009-04-23 8.01 W32/Renos.CNZ
Panda 9.05.01 2009.04.23 2009-04-23 3.10 Rootkit/Agent.LNB
Trend Micro 8.700-1004 5.982.11 2009-04-23 0.03 -
Quick Heal 10.00 2009.04.23 2009-04-23 1.79 -
Rising 20.0 21.26.34.00 2009-04-23 0.94 -
Sophos 2.85.0 4.40 2009-04-24 2.50 -
Sunbelt 5109 5109 2009-04-23 0.86 -
Symantec 1.3.0.24 20090423.004 2009-04-23 0.25 -
nProtect 20090423.01 3491828 2009-04-23 12.33 -
The Hacker [removed] v00313 2009-04-23 0.73 -
VBA32 3.12.10.3 20090423.1331 2009-04-23 1.82 -
VirusBuster 4.5.11.10 10.105.4/1295687 2009-04-23 1.59 -
Hi, Here is the Malwarebytes report. Thanks. Malwarebytes' Anti-Malware 1.36 Database version: 2031 Windows 5.1.2600 Service Pack 3 4/23/2009 10:32:20 PM mbam-log-2009-04-23 (22-32-20).txt Scan type: Quick Scan Objects scanned: 207288 Time elapsed: 1 hour(s), 14 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please click OTMoveIt3 and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Services

:Reg

:Files
C:\WINNT\System32\drivers\jhlvaxtf.sys

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



NEXT

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi, not sure if I did the first step correctly. The program said that the "C:\WINNT\System32\drivers\jhlvaxtf.sys" was moved successfully but did not respond after the empty temp folders command. I could not retrieve a log for this move. The following was in the program on reboot: Files moved on Reboot… File C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for 20k articles.zip\20k articles\ Relating Computer, Communication, and Computer-Mediated Communication Apprehensions to New Communication Technology Use in the Workplace. not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF7326.tmp not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF7337.tmp not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFA43B.tmp not found! File C:\DOCUME~1\Owner\LOCALS~1\Temp\~WRF0000.tmp not found!
Hi, this is the ComboFix output. The computer is running great, very quick.

ComboFix 09-04-25.01 - Owner 04/24/2009 14:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.412 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\winnt\system32\lsprst7.dll
c:\winnt\system32\nfr.assembly
c:\winnt\system32\nfr.gpref
c:\winnt\system32\nsprs.dll

.
((((((((((((((((((((((((( Files Created from 2009-05-24 to 2009-4-24 )))))))))))))))))))))))))))))))
.

2009-04-24 16:58 . 2009-04-24 16:58 ——– d—–w C:\_OTMoveIt
2009-04-23 23:49 . 2009-04-23 23:49 ——– d—–w C:\_OTListIt
2009-04-23 18:14 . 2009-04-23 18:14 ——– d—–w c:\winnt\system32\log
2009-04-22 23:45 . 2009-04-22 23:45 ——– d—–w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-04-22 20:41 . 2009-03-06 14:22 284160 ——w c:\winnt\system32\dllcache\pdh.dll
2009-04-22 20:41 . 2009-02-09 12:10 401408 ——w c:\winnt\system32\dllcache\rpcss.dll
2009-04-22 20:41 . 2009-02-09 12:10 473600 ——w c:\winnt\system32\dllcache\fastprox.dll
2009-04-22 20:41 . 2009-02-06 11:11 110592 ——w c:\winnt\system32\dllcache\services.exe
2009-04-22 20:41 . 2009-02-06 10:10 227840 ——w c:\winnt\system32\dllcache\wmiprvse.exe
2009-04-22 20:41 . 2009-02-09 12:10 453120 ——w c:\winnt\system32\dllcache\wmiprvsd.dll
2009-04-22 20:41 . 2009-02-09 12:10 729088 ——w c:\winnt\system32\dllcache\lsasrv.dll
2009-04-22 20:41 . 2009-02-09 12:10 617472 ——w c:\winnt\system32\dllcache\advapi32.dll
2009-04-22 20:41 . 2009-02-09 12:10 714752 ——w c:\winnt\system32\dllcache\ntdll.dll
2009-04-22 20:40 . 2008-05-03 11:55 2560 ——w c:\winnt\system32\xpsp4res.dll
2009-04-22 20:40 . 2009-03-27 06:58 1203922 ——w c:\winnt\system32\dllcache\sysmain.sdb
2009-04-22 20:40 . 2008-04-21 12:08 215552 ——w c:\winnt\system32\dllcache\wordpad.exe
2009-04-22 20:35 . 2009-04-22 20:35 ——– d—–w C:\ERDNT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-23 17:08 . 2009-03-07 00:04 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-23 01:30 . 2008-11-16 01:09 ——– d—–w c:\program files\Trend Micro
2009-04-06 19:32 . 2009-03-07 00:04 38496 —-a-w c:\winnt\system32\drivers\mbamswissarmy.sys
2009-04-06 19:32 . 2009-03-07 00:04 15504 —-a-w c:\winnt\system32\drivers\mbam.sys
2009-03-29 19:27 . 2004-05-29 18:42 ——– d—–w c:\documents and settings\Owner\Application Data\Canon
2009-03-21 14:06 . 2009-03-21 14:06 989696 ——w c:\winnt\system32\dllcache\kernel32.dll
2009-03-14 18:58 . 2002-08-30 02:12 ——– d—–w c:\program files\intel
2009-03-14 18:39 . 2009-03-14 18:39 126976 —-a-w c:\winnt\system32\unzdll.dll
2009-03-14 18:39 . 2002-08-30 02:12 ——– d—–w c:\program files\Gateway
2009-03-07 00:04 . 2009-03-07 00:04 ——– d—–w c:\documents and settings\Owner\Application Data\Malwarebytes
2009-03-07 00:04 . 2009-03-07 00:04 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-06 14:22 . 2003-11-05 23:22 284160 —-a-w c:\winnt\system32\pdh.dll
2009-03-03 00:18 . 2006-05-10 05:23 826368 —-a-w c:\winnt\system32\dllcache\wininet.dll
2009-03-03 00:18 . 2004-02-06 22:05 826368 —-a-w c:\winnt\system32\wininet.dll
2009-03-02 04:07 . 2009-03-02 02:39 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-02 02:39 . 2009-03-02 02:39 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-03-02 02:34 . 2009-03-02 02:34 ——– d—–w c:\program files\Microsoft
2009-03-02 02:32 . 2009-03-02 02:32 410984 —-a-w c:\winnt\system32\deploytk.dll
2009-03-02 02:32 . 2005-08-26 17:03 ——– d—–w c:\program files\Java
2009-03-01 04:39 . 2009-03-01 04:38 ——– d—–w c:\program files\iTunes
2009-03-01 04:39 . 2009-03-01 04:38 ——– d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-03-01 04:39 . 2005-04-14 01:07 ——– d—–w c:\program files\iPod
2009-03-01 04:35 . 2008-04-17 03:08 ——– d—–w c:\program files\QuickTime
2009-03-01 04:34 . 2007-09-01 18:31 ——– d—–w c:\program files\Common Files\Apple
2009-02-28 04:54 . 2006-10-17 18:04 636072 ——w c:\winnt\system32\dllcache\iexplore.exe
2009-02-27 14:57 . 2008-02-19 00:48 ——– d—–w c:\program files\Microsoft Silverlight
2009-02-20 10:20 . 2007-05-09 17:46 13824 ——w c:\winnt\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2006-10-27 07:44 70656 ——w c:\winnt\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 1980-01-01 05:00 161792 —-a-w c:\winnt\system32\dllcache\ieakui.dll
2009-02-09 12:10 . 1980-01-01 05:00 729088 —-a-w c:\winnt\system32\lsasrv.dll
2009-02-09 12:10 . 2004-04-21 02:45 401408 —-a-w c:\winnt\system32\rpcss.dll
2009-02-09 12:10 . 1980-01-01 05:00 714752 —-a-w c:\winnt\system32\ntdll.dll
2009-02-09 12:10 . 1980-01-01 05:00 617472 —-a-w c:\winnt\system32\advapi32.dll
2009-02-09 11:13 . 2008-10-15 15:42 1846784 ——w c:\winnt\system32\dllcache\win32k.sys
2009-02-09 11:13 . 1980-01-01 05:00 1846784 —-a-w c:\winnt\system32\win32k.sys
2009-02-07 23:02 . 2008-10-15 15:42 2066048 ——w c:\winnt\system32\dllcache\ntkrnlpa.exe
2009-02-07 23:02 . 2001-08-17 18:48 2066048 —-a-w c:\winnt\system32\ntkrnlpa.exe
2009-02-06 11:11 . 1980-01-01 05:00 110592 —-a-w c:\winnt\system32\services.exe
2009-02-06 11:08 . 2008-10-15 15:42 2189056 ——w c:\winnt\system32\dllcache\ntoskrnl.exe
2009-02-06 11:08 . 1980-01-01 05:00 2189056 —-a-w c:\winnt\system32\ntoskrnl.exe
2009-02-06 11:06 . 2008-10-15 15:42 2145280 ——w c:\winnt\system32\dllcache\ntkrnlmp.exe
2009-02-06 10:39 . 1980-01-01 05:00 35328 —-a-w c:\winnt\system32\sc.exe
2009-02-06 10:39 . 1980-01-01 05:00 35328 —-a-w c:\winnt\system32\dllcache\sc.exe
2009-02-06 10:32 . 2008-10-15 15:42 2023936 ——w c:\winnt\system32\dllcache\ntkrpamp.exe
2009-02-03 19:59 . 2009-02-03 19:59 56832 ——w c:\winnt\system32\dllcache\secur32.dll
2009-02-03 19:59 . 2003-11-05 23:25 56832 —-a-w c:\winnt\system32\secur32.dll
2008-07-25 15:32 . 2002-09-06 16:33 67016 —-a-w c:\documents and settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-07-24 20:52 . 2002-09-29 04:45 67016 —-a-w c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2004-11-04 23:49 . 2004-11-04 21:03 16706160 —-a-w c:\program files\AdbeRdr60_enu_full.exe
2008-05-20 02:50 . 2008-05-20 02:50 32768 –sha-w c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008051920080520\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2001-10-06 24576]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2001-08-23 331830]
"IgfxTray"="c:\winnt\system32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\winnt\system32\hkcmd.exe" [2005-06-21 126976]
"CapFax"="c:\program files\PhoneTools\CapFax.EXE" [2001-11-07 20480]
"Omnipage"="c:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-02 148888]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 98304]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"PROMon.exe"="PROMon.exe" - c:\winnt\system32\PROMon.exe [2002-04-18 73728]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" - c:\winnt\system32\SK9910DM.EXE [2001-01-03 66048]
"GWMDMMSG"="GWMDMMSG.exe" - c:\winnt\GWMDMMSG.exe [2002-05-07 65536]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-07-15 34880]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
KSU CISCO VPN Client.lnk - c:\winnt\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2008-11-18 2238]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
AutoStart IR.lnk - c:\program files\WinTV\Ir.exe [2008-7-31 106551]
Google Updater.lnk - c:\program files\Google\Google Updater\GoogleUpdater.exe [2007-4-13 124912]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\PC-Doctor for Windows\\Pcdrw32.exe"=
"c:\\WINNT\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7070:TCP"= 7070:TCP:nfr

R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 EVOLUSB;%EVOL_USB_SvcDesc%; [x]
R3 iscFlash;iscFlash; [x]
R3 PCDRDRV;Pcdr Helper Driver; [x]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 tmevtmgr;tmevtmgr;c:\winnt\system32\drivers\tmevtmgr.sys [2008-02-15 52240]
S2 tmpreflt;tmpreflt;c:\winnt\system32\DRIVERS\tmpreflt.sys [2008-11-26 36368]
S3 HCWBT8xx;Hauppauge WinTV 848/9 WDM Video Driver;c:\winnt\system32\drivers\HCWBT8XX.sys [2006-01-25 472644]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-02-26 648456]

.
Contents of the 'Scheduled Tasks' folder

2008-10-25 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Keyboard Preload Check - c:\oemdrvrs\KEYB\Preload.exe


.
——- Supplementary Scan ——-
.
uStart Page = https://flashline.kent.edu/cp/home/loginf
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-24 14:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-04-24 14:23
ComboFix-quarantined-files.txt 2009-04-24 18:23

Pre-Run: 16,876,961,792 bytes free
Post-Run: 19,368,374,272 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Home Edition" /fastdetect

183 — E O F — 2009-04-23 16:56
Hi,

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box, put your mouse cursor at the very beginning of the text and then hold down the left button and drag your mouse so that all of the text is highlighted. Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7070:TCP"=-

Now paste the copied text into the open notepad. To do this click in the blank page so that your cursor is flashing there and press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

* Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
* ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
* When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Hi, this is the ComboFix info:

ComboFix 09-04-25.A1 - Owner 04/25/2009 11:02.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.415 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Trend Micro AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-4-25 )))))))))))))))))))))))))))))))
.

2009-04-24 16:58 . 2009-04-24 16:58 ——– d—–w C:\_OTMoveIt
2009-04-23 23:49 . 2009-04-23 23:49 ——– d—–w C:\_OTListIt
2009-04-23 18:14 . 2009-04-23 18:14 ——– d—–w c:\winnt\system32\log
2009-04-22 23:45 . 2009-04-22 23:45 ——– d—–w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-04-22 20:41 . 2009-03-06 14:22 284160 ——w c:\winnt\system32\dllcache\pdh.dll
2009-04-22 20:41 . 2009-02-09 12:10 401408 ——w c:\winnt\system32\dllcache\rpcss.dll
2009-04-22 20:41 . 2009-02-09 12:10 473600 ——w c:\winnt\system32\dllcache\fastprox.dll
2009-04-22 20:41 . 2009-02-06 11:11 110592 ——w c:\winnt\system32\dllcache\services.exe
2009-04-22 20:41 . 2009-02-06 10:10 227840 ——w c:\winnt\system32\dllcache\wmiprvse.exe
2009-04-22 20:41 . 2009-02-09 12:10 453120 ——w c:\winnt\system32\dllcache\wmiprvsd.dll
2009-04-22 20:41 . 2009-02-09 12:10 729088 ——w c:\winnt\system32\dllcache\lsasrv.dll
2009-04-22 20:41 . 2009-02-09 12:10 617472 ——w c:\winnt\system32\dllcache\advapi32.dll
2009-04-22 20:41 . 2009-02-09 12:10 714752 ——w c:\winnt\system32\dllcache\ntdll.dll
2009-04-22 20:40 . 2008-05-03 11:55 2560 ——w c:\winnt\system32\xpsp4res.dll
2009-04-22 20:40 . 2009-03-27 06:58 1203922 ——w c:\winnt\system32\dllcache\sysmain.sdb
2009-04-22 20:40 . 2008-04-21 12:08 215552 ——w c:\winnt\system32\dllcache\wordpad.exe
2009-04-22 20:35 . 2009-04-22 20:35 ——– d—–w C:\ERDNT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-23 17:08 . 2009-03-07 00:04 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-23 01:30 . 2008-11-16 01:09 ——– d—–w c:\program files\Trend Micro
2009-04-06 19:32 . 2009-03-07 00:04 38496 —-a-w c:\winnt\system32\drivers\mbamswissarmy.sys
2009-04-06 19:32 . 2009-03-07 00:04 15504 —-a-w c:\winnt\system32\drivers\mbam.sys
2009-03-29 19:27 . 2004-05-29 18:42 ——– d—–w c:\documents and settings\Owner\Application Data\Canon
2009-03-21 14:06 . 2009-03-21 14:06 989696 ——w c:\winnt\system32\dllcache\kernel32.dll
2009-03-14 18:58 . 2002-08-30 02:12 ——– d—–w c:\program files\intel
2009-03-14 18:39 . 2009-03-14 18:39 126976 —-a-w c:\winnt\system32\unzdll.dll
2009-03-14 18:39 . 2002-08-30 02:12 ——– d—–w c:\program files\Gateway
2009-03-07 00:04 . 2009-03-07 00:04 ——– d—–w c:\documents and settings\Owner\Application Data\Malwarebytes
2009-03-07 00:04 . 2009-03-07 00:04 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-06 14:22 . 2003-11-05 23:22 284160 —-a-w c:\winnt\system32\pdh.dll
2009-03-03 00:18 . 2006-05-10 05:23 826368 —-a-w c:\winnt\system32\dllcache\wininet.dll
2009-03-03 00:18 . 2004-02-06 22:05 826368 —-a-w c:\winnt\system32\wininet.dll
2009-03-02 04:07 . 2009-03-02 02:39 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-02 02:39 . 2009-03-02 02:39 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-03-02 02:34 . 2009-03-02 02:34 ——– d—–w c:\program files\Microsoft
2009-03-02 02:32 . 2009-03-02 02:32 410984 —-a-w c:\winnt\system32\deploytk.dll
2009-03-02 02:32 . 2005-08-26 17:03 ——– d—–w c:\program files\Java
2009-03-01 04:39 . 2009-03-01 04:38 ——– d—–w c:\program files\iTunes
2009-03-01 04:39 . 2009-03-01 04:38 ——– d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-03-01 04:39 . 2005-04-14 01:07 ——– d—–w c:\program files\iPod
2009-03-01 04:35 . 2008-04-17 03:08 ——– d—–w c:\program files\QuickTime
2009-03-01 04:34 . 2007-09-01 18:31 ——– d—–w c:\program files\Common Files\Apple
2009-02-28 04:54 . 2006-10-17 18:04 636072 ——w c:\winnt\system32\dllcache\iexplore.exe
2009-02-27 14:57 . 2008-02-19 00:48 ——– d—–w c:\program files\Microsoft Silverlight
2009-02-20 10:20 . 2007-05-09 17:46 13824 ——w c:\winnt\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2006-10-27 07:44 70656 ——w c:\winnt\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 1980-01-01 05:00 161792 —-a-w c:\winnt\system32\dllcache\ieakui.dll
2009-02-09 12:10 . 1980-01-01 05:00 729088 —-a-w c:\winnt\system32\lsasrv.dll
2009-02-09 12:10 . 2004-04-21 02:45 401408 —-a-w c:\winnt\system32\rpcss.dll
2009-02-09 12:10 . 1980-01-01 05:00 714752 —-a-w c:\winnt\system32\ntdll.dll
2009-02-09 12:10 . 1980-01-01 05:00 617472 —-a-w c:\winnt\system32\advapi32.dll
2009-02-09 11:13 . 2008-10-15 15:42 1846784 ——w c:\winnt\system32\dllcache\win32k.sys
2009-02-09 11:13 . 1980-01-01 05:00 1846784 —-a-w c:\winnt\system32\win32k.sys
2009-02-07 23:02 . 2008-10-15 15:42 2066048 ——w c:\winnt\system32\dllcache\ntkrnlpa.exe
2009-02-07 23:02 . 2001-08-17 18:48 2066048 —-a-w c:\winnt\system32\ntkrnlpa.exe
2009-02-06 11:11 . 1980-01-01 05:00 110592 —-a-w c:\winnt\system32\services.exe
2009-02-06 11:08 . 2008-10-15 15:42 2189056 ——w c:\winnt\system32\dllcache\ntoskrnl.exe
2009-02-06 11:08 . 1980-01-01 05:00 2189056 —-a-w c:\winnt\system32\ntoskrnl.exe
2009-02-06 11:06 . 2008-10-15 15:42 2145280 ——w c:\winnt\system32\dllcache\ntkrnlmp.exe
2009-02-06 10:39 . 1980-01-01 05:00 35328 —-a-w c:\winnt\system32\sc.exe
2009-02-06 10:39 . 1980-01-01 05:00 35328 —-a-w c:\winnt\system32\dllcache\sc.exe
2009-02-06 10:32 . 2008-10-15 15:42 2023936 ——w c:\winnt\system32\dllcache\ntkrpamp.exe
2009-02-03 19:59 . 2009-02-03 19:59 56832 ——w c:\winnt\system32\dllcache\secur32.dll
2009-02-03 19:59 . 2003-11-05 23:25 56832 —-a-w c:\winnt\system32\secur32.dll
2008-07-25 15:32 . 2002-09-06 16:33 67016 —-a-w c:\documents and settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-07-24 20:52 . 2002-09-29 04:45 67016 —-a-w c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2004-11-04 23:49 . 2004-11-04 21:03 16706160 —-a-w c:\program files\AdbeRdr60_enu_full.exe
2008-05-20 02:50 . 2008-05-20 02:50 32768 –sha-w c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008051920080520\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-04-24_18.20.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-25 14:18 . 2009-04-25 14:18 16384 c:\winnt\Temp\Perflib_Perfdata_37c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2001-10-06 24576]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2001-08-23 331830]
"IgfxTray"="c:\winnt\system32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\winnt\system32\hkcmd.exe" [2005-06-21 126976]
"CapFax"="c:\program files\PhoneTools\CapFax.EXE" [2001-11-07 20480]
"Omnipage"="c:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-02 148888]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 98304]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"PROMon.exe"="PROMon.exe" - c:\winnt\system32\PROMon.exe [2002-04-18 73728]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" - c:\winnt\system32\SK9910DM.EXE [2001-01-03 66048]
"GWMDMMSG"="GWMDMMSG.exe" - c:\winnt\GWMDMMSG.exe [2002-05-07 65536]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-07-15 34880]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
KSU CISCO VPN Client.lnk - c:\winnt\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2008-11-18 2238]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
AutoStart IR.lnk - c:\program files\WinTV\Ir.exe [2008-7-31 106551]
Google Updater.lnk - c:\program files\Google\Google Updater\GoogleUpdater.exe [2007-4-13 124912]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\PC-Doctor for Windows\\Pcdrw32.exe"=
"c:\\WINNT\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 EVOLUSB;%EVOL_USB_SvcDesc%; [x]
R3 iscFlash;iscFlash; [x]
R3 PCDRDRV;Pcdr Helper Driver; [x]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 tmevtmgr;tmevtmgr;c:\winnt\system32\drivers\tmevtmgr.sys [2008-02-15 52240]
S2 tmpreflt;tmpreflt;c:\winnt\system32\DRIVERS\tmpreflt.sys [2008-11-26 36368]
S3 HCWBT8xx;Hauppauge WinTV 848/9 WDM Video Driver;c:\winnt\system32\drivers\HCWBT8XX.sys [2006-01-25 472644]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-02-26 648456]

.
Contents of the 'Scheduled Tasks' folder

2008-10-25 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://flashline.kent.edu/cp/home/loginf
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-25 11:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3308)
c:\program files\ScanSoft\OmniPageSE\ophook32.dll
c:\winnt\system32\WPDShServiceObj.dll
c:\winnt\system32\PortableDeviceTypes.dll
c:\winnt\system32\PortableDeviceApi.dll
.
Completion time: 2009-04-25 11:10
ComboFix-quarantined-files.txt 2009-04-25 15:10
ComboFix2.txt 2009-04-24 18:23

Pre-Run: 19,286,642,688 bytes free
Post-Run: 19,365,838,848 bytes free

178 — E O F — 2009-04-23 16:56

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI