This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Slow computer and possible malware

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello some of the problems i am having on the computer is that it is running very slow.
here is my HJT log my malware bytes log and my CA anti-virus log.
i also have gone through and taken at all my unwanted programs that were able to be removed. some of them in the add/remove programs to change remove or repair them i didn't think this was normal

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:41 PM, on 5/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\caav.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpeedItUpEX] C:\Program Files\Speeditup Free\SpeedItUp.exe -MINI
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)" -"http://www8.agame.com/games/shockwave/d/dance_trends_3d/dance_trends_3d_girlsgogames_com.htm"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - .DEFAULT User Startup: Organize.lnk = ? (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://ndormail01.dor.state.ne.us/dwa7W.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 11020 bytes

Malwarebytes' Anti-Malware 1.36
Database version: 2072
Windows 5.1.2600 Service Pack 3

5/3/2009 9:31:36 PM
mbam-log-2009-05-03 (21-31-36).txt

Scan type: Quick Scan
Objects scanned: 91675
Time elapsed: 4 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a3ed5288-f558-4f6e-8d5c-740cb6f89029} (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{343ce214-9998-4b21-a151-ffe970167297} (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Power-Antivirus-2009 (Rogue.PowerAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> Quarantined and deleted successfully.

Started scanning at 5/3/2009 10:36:11 PM. Engine Ver: 31.6.0. Sig Ver:6487. Sig Date: 5/1/2009. ArcLib Ver: 8.0.1.1.
C:\hiberfil.sys - Could not open the file.
C:\pagefile.sys - Could not open the file.
C:\Documents and Settings\All Users\Application Data\Broderbund Software\Print\PrintMaster\PMUSERS.DAT - Could not open the file.
C:\Documents and Settings\All Users\Application Data\Broderbund Software\Print\PrintMaster\PMWPRINT.INI - Could not open the file.
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea563f5ed0b8ea72081a19b9b561dd25_fafa14b3-d70b-403c-92d2-07b014f9e4d3 - Could not open the file.
C:\Documents and Settings\LocalService\NTUSER.DAT - Could not open the file.
C:\Documents and Settings\LocalService\ntuser.dat.LOG - Could not open the file.
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - Could not open the file.
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - Could not open the file.
C:\Documents and Settings\NetworkService\NTUSER.DAT - Could not open the file.
C:\Documents and Settings\NetworkService\ntuser.dat.LOG - Could not open the file.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - Could not open the file.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - Could not open the file.
C:\Documents and Settings\Owner\ntuser.dat - Could not open the file.
C:\Documents and Settings\Owner\ntuser.dat.LOG - Could not open the file.
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - Could not open the file.
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\chandir.dat - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\chandir.idx - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\chn.dat - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\chn.idx - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\D0000000.FCS - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\L0000034.FCS - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\prs.dat - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\prs.idx - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\prs_die.dat - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\prs_die.idx - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\prs_dnd.dat - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\prs_dnd.idx - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\prs_ext.dat - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\prs_ext.idx - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\prs_rcv.dat - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\prs_rcv.idx - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\storydb.dat - Could not open the file.
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Owner\Data\storydb.idx - Could not open the file.
C:\System Volume Information\MountPointManagerRemoteDatabase - Could not open the file.
C:\WINDOWS\system32\CatRoot2\edb.log - Could not open the file.
C:\WINDOWS\system32\CatRoot2\tmp.edb - Could not open the file.
C:\WINDOWS\system32\config\default - Could not open the file.
C:\WINDOWS\system32\config\default.LOG - Could not open the file.
C:\WINDOWS\system32\config\SAM - Could not open the file.
C:\WINDOWS\system32\config\SAM.LOG - Could not open the file.
C:\WINDOWS\system32\config\SECURITY - Could not open the file.
C:\WINDOWS\system32\config\SECURITY.LOG - Could not open the file.
C:\WINDOWS\system32\config\software - Could not open the file.
C:\WINDOWS\system32\config\software.LOG - Could not open the file.
C:\WINDOWS\system32\config\system - Could not open the file.
C:\WINDOWS\system32\config\system.LOG - Could not open the file.

Files Scanned: 420791
Files Infected: 0
Files Cleaned \ Deleted: 0
Files Quarantined: 0
Memory Infections: 0
Memory Infections Cleaned: 0
Boot Infections: 0
Boot Infections Cleaned: 0


Files not Cleaned\Deleted\Quarantined (Limit 100): 0

Finished scanning at 5/3/2009 11:46:49 PM.
Hi Tmasters2,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Monday, May 11, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Tuesday, May 12, 2009 00:14:00 Records in database: 2163952 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ I:\ M:\ N:\ Scan statistics: Files scanned: 88679 Threat name: 2 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 03:01:10 File name / Threat name / Threats count C:\Program Files\Common Files\aolback\Comps\toolbar\toolbr.exe Infected: not-a-virus:AdWare.Win32.SearchIt.t 1 C:\WINDOWS\CouponPrinter.ocx Infected: not-a-virus:AdWare.Win32.BHO.gkp 1 The selected area was scanned.
Tmasters2,

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
      O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
      O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
      O4 - HKCU\..\Run: [SpeedItUpEX] C:\Program Files\Speeditup Free\SpeedItUp.exe -MINI
      O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)" -"http://www8.agame.com/games/shockwave/d/dance_trends_3d/dance_trends_3d_girlsgogames_com.htm"
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\Program Files\Common Files\aolback\Comps\toolbar\toolbr.exe
    C:\WINDOWS\CouponPrinter.ocx
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Also please give me a new HijackThis log and tell me how it's running.
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\Program Files\Common Files\aolback\Comps\toolbar\toolbr.exe moved successfully.
C:\WINDOWS\CouponPrinter.ocx unregistered successfully.
C:\WINDOWS\CouponPrinter.ocx moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF14E1.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF4012.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF479E.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFB77D.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFBC32.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFE9B9.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFE9C7.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFEC7B.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\ENRP596A\ads[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\ENRP596A\iframe[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\ENRP596A\Slow_computer_possible_malware_t102747[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\0KF9Z8PM\de[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05122009_165027

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:12:34 PM, on 5/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - .DEFAULT User Startup: Organize.lnk = ? (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://ndormail01.dor.state.ne.us/dwa7W.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 10045 bytes

The computer seems to be faster, but it could still be faster, I think. Also there is a J2SE Runtime Enviroment Update 6 That did not have a remove button for it, so it is still on the computer.
Tmasters2,

Let's get a little different look.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Here is the 1st post.

OTListIt logfile created on: 5/14/2009 3:13:45 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.7 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

447.48 Mb Total Physical Memory | 120.90 Mb Available Physical Memory | 27.02% Memory free
1.03 Gb Paging File | 0.63 Gb Available in Paging File | 61.35% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.10 Gb Total Space | 124.43 Gb Free Space | 86.96% Space Free | Partition Type: NTFS
Drive D: | 5.94 Gb Total Space | 2.12 Gb Free Space | 35.64% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-AT5QGAAC3Z
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2006/11/03 19:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2007/10/18 10:24:46 | 00,801,296 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
PRC - [2007/10/18 10:24:44 | 00,145,936 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
PRC - [2008/06/24 19:10:30 | 00,281,104 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
PRC - [2007/10/18 10:24:46 | 01,010,192 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
PRC - [2009/03/06 00:04:30 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2007/08/20 13:27:26 | 00,144,960 | —- | M] (Computer Associates International, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
PRC - [2008/10/10 05:45:26 | 00,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2007/01/04 12:10:22 | 00,280,080 | —- | M] (CA, Inc.) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
PRC - [2007/08/20 13:36:42 | 00,242,952 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
PRC - [2007/01/04 16:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2008/04/13 19:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009/04/10 17:41:20 | 00,181,488 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
PRC - [2002/10/16 18:57:10 | 00,081,920 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\system32\ps2.exe
PRC - [2005/06/07 00:46:24 | 00,057,344 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
PRC - [2007/08/31 14:01:21 | 01,037,736 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft IntelliPoint\ipoint.exe
PRC - [2009/03/12 20:56:58 | 00,342,312 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/04/10 17:41:19 | 00,177,392 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
PRC - [2009/04/10 17:36:41 | 00,014,088 | —- | M] (CA) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
PRC - [2007/08/20 13:36:38 | 00,230,664 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
PRC - [2009/04/10 17:41:20 | 00,173,296 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
PRC - [2005/11/10 14:03:52 | 00,036,975 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
PRC - [2007/08/31 13:58:50 | 00,357,800 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
PRC - [2009/04/10 17:41:19 | 00,214,256 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
PRC - [2007/08/16 21:10:14 | 00,218,376 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
PRC - [2009/03/12 20:56:52 | 00,656,168 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2007/08/16 21:10:16 | 00,189,704 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
PRC - [2007/01/19 13:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe
PRC - [2009/05/14 15:12:20 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/03/06 00:04:30 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - [2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2009/04/10 17:41:19 | 00,214,256 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe – (CaCCProvSP [On_Demand | Running])
SRV - [2007/08/20 13:27:26 | 00,144,960 | —- | M] (Computer Associates International, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe – (CAISafe [Auto | Running])
SRV - [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/04/13 19:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2005/04/04 01:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [Disabled | Stopped])
SRV - [2008/10/10 05:45:26 | 00,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService [Auto | Running])
SRV - [2009/03/12 20:56:52 | 00,656,168 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2007/01/04 12:10:22 | 00,280,080 | —- | M] (CA, Inc.) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe – (ITMRTSVC [Auto | Running])
SRV - [2001/08/06 07:41:48 | 00,028,672 | —- | M] () – C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe – (nhksrv [Disabled | Stopped])
SRV - [2003/07/28 22:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2004/09/29 12:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\System32\HPZipm12.exe – (Pml Driver HPZ12 [Disabled | Stopped])
SRV - [2007/08/16 21:10:16 | 00,189,704 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe – (PPCtlPriv [On_Demand | Running])
SRV - [2007/10/18 10:24:46 | 01,010,192 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe – (UmxAgent [Auto | Running])
SRV - [2007/10/18 10:24:46 | 00,801,296 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe – (UmxCfg [Auto | Running])
SRV - [2007/10/18 10:24:44 | 00,145,936 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe – (UmxFwHlp [Auto | Running])
SRV - [2008/06/24 19:10:30 | 00,281,104 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe – (UmxPol [Auto | Running])
SRV - [2007/01/19 13:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe – (usnjsvc [On_Demand | Running])
SRV - [2007/08/20 13:36:42 | 00,242,952 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe – (VETMSGNT [Auto | Running])
SRV - [2007/01/04 16:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service [Auto | Running])
SRV - [2006/11/03 19:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend [Auto | Running])
SRV - [2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2004/10/07 20:16:04 | 00,035,840 | —- | M] (Oak Technology Inc.) – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K [System | Running])
DRV - [2005/03/04 12:02:20 | 01,066,278 | —- | M] (Agere Systems) – C:\WINDOWS\System32\DRIVERS\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2003/12/12 09:54:14 | 00,391,424 | —- | M] (Sensaura Ltd) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS – (ALCXSENS [On_Demand | Stopped])
DRV - [2004/10/01 10:24:02 | 02,279,424 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM [On_Demand | Running])
DRV - [2003/12/02 21:23:20 | 00,142,336 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys – (fasttx2k [Boot | Running])
DRV - [2004/12/16 14:36:30 | 00,042,496 | —- | M] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys – (FETND5BV [On_Demand | Running])
DRV - [2003/01/16 02:05:54 | 00,041,984 | —- | M] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\DRIVERS\fetnd5b.sys – (FETNDISB [On_Demand | Stopped])
DRV - [2009/01/15 12:19:36 | 00,023,848 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [1998/07/01 01:55:56 | 00,052,800 | —- | M] () – C:\WINDOWS\System32\drivers\HPFECP16.SYS – (HPFECP16 [Auto | Stopped])
DRV - [2004/12/14 11:07:44 | 00,051,120 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys – (HPZid412 [On_Demand | Running])
DRV - [2004/12/14 11:07:44 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys – (HPZipr12 [On_Demand | Running])
DRV - [2004/12/14 11:07:44 | 00,021,744 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys – (HPZius12 [On_Demand | Running])
DRV - [2003/11/20 19:25:14 | 00,095,579 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys – (ialm [On_Demand | Stopped])
DRV - [2008/06/24 19:08:36 | 00,063,504 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxagent.sys – (KmxAgent [System | Running])
DRV - [2008/06/24 19:08:42 | 00,134,648 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\KmxCF.sys – (KmxCF [Auto | Running])
DRV - [2008/06/24 19:08:42 | 00,088,816 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxcfg.sys – (KmxCfg [On_Demand | Running])
DRV - [2008/06/24 19:08:46 | 00,045,584 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\KmxFile.sys – (KmxFile [System | Running])
DRV - [2008/06/24 19:08:52 | 00,115,216 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxfw.sys – (KmxFw [System | Running])
DRV - [2008/06/24 19:08:56 | 00,066,576 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\KmxSbx.sys – (KmxSbx [Auto | Running])
DRV - [2008/06/24 19:08:58 | 00,093,712 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys – (KmxStart [Boot | Running])
DRV - [2007/04/11 15:32:30 | 00,020,496 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys – (L8042Kbd [On_Demand | Running])
DRV - [2007/01/23 16:44:00 | 00,062,992 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\DRIVERS\L8042mou.Sys – (L8042mou [On_Demand | Stopped])
DRV - [2007/04/11 15:32:52 | 00,034,832 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys – (LHidFilt [On_Demand | Running])
DRV - [2006/03/28 18:56:06 | 00,027,008 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\DRIVERS\LHidKE.Sys – (LHidKe [On_Demand | Stopped])
DRV - [2006/03/28 18:55:20 | 00,036,736 | —- | M] (Logitech, Inc.) – C:\WINDOWS\System32\Drivers\LHidUsbK.Sys – (LHidUsbK [On_Demand | Running])
DRV - [2007/04/11 15:32:58 | 00,036,112 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys – (LMouFilt [On_Demand | Running])
DRV - [2007/01/23 16:45:00 | 00,078,864 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\DRIVERS\LMouKE.Sys – (LMouKE [On_Demand | Stopped])
DRV - [2007/01/23 16:45:00 | 00,028,176 | —- | M] (Logitech, Inc.) – C:\WINDOWS\System32\Drivers\LUsbFilt.Sys – (LUsbFilt [On_Demand | Stopped])
DRV - [2001/12/20 10:02:12 | 00,006,656 | —- | M] (Netropa Corporation) – C:\WINDOWS\System32\DRIVERS\msikbd2k.sys – (msikbd2k [System | Running])
DRV - [2004/08/03 22:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2003/09/03 02:51:00 | 00,021,120 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys – (nv_agp [Boot | Running])
DRV - [2003/09/19 01:47:00 | 00,010,368 | —- | M] (Padus, Inc.) – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc [On_Demand | Running])
DRV - [2007/08/21 03:12:59 | 00,021,760 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\point32.sys – (Point32 [On_Demand | Running])
DRV - [1997/04/09 16:08:24 | 00,085,868 | —- | M] (Silitek Corporation.) – C:\WINDOWS\System32\drivers\ppclass.sys – (PPCLASS [Auto | Running])
DRV - [1998/02/20 14:37:10 | 00,115,136 | —- | M] (Shuttle Technology.) – C:\WINDOWS\System32\drivers\ppscan.sys – (PPSCAN [Auto | Stopped])
DRV - [2001/06/04 16:00:00 | 00,014,112 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\System32\DRIVERS\PS2.sys – (Ps2 [On_Demand | Stopped])
DRV - [2003/03/31 14:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2005/08/30 19:45:08 | 00,020,576 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2002/10/04 20:04:10 | 00,046,976 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS – (rtl8139 [On_Demand | Stopped])
DRV - [2007/11/13 05:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2003/12/06 05:13:42 | 00,429,440 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys – (SiS315 [On_Demand | Stopped])
DRV - [2003/07/18 19:58:20 | 00,036,992 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys – (SISAGP [Boot | Running])
DRV - [2003/12/05 19:25:54 | 00,011,392 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\srvkp.sys – (SiSkp [System | Running])
DRV - [2003/11/10 11:24:24 | 00,039,532 | —- | M] (Alcor Micro Corp.) – C:\WINDOWS\System32\Drivers\sunkfilt.sys – (SunkFilt [On_Demand | Stopped])
DRV - [2006/12/15 21:09:16 | 00,010,344 | —- | M] (Symantec Corporation) – C:\WINDOWS\system32\drivers\symlcbrd.sys – (symlcbrd [Auto | Running])
DRV - [2009/03/05 23:59:00 | 00,036,864 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\Drivers\usbaapl.sys – (USBAAPL [On_Demand | Stopped])
DRV - [2007/08/20 13:38:16 | 00,026,376 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-filt.sys – (VET-FILT [System | Running])
DRV - [2007/08/20 13:38:16 | 00,021,128 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-rec.sys – (VET-REC [System | Running])
DRV - [2009/04/10 17:41:19 | 00,108,368 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys – (VETEBOOT [On_Demand | Running])
DRV - [2009/04/10 17:41:19 | 00,880,560 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys – (VETEFILE [System | Running])
DRV - [2007/08/20 13:38:20 | 00,021,512 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetfddnt.sys – (VETFDDNT [System | Running])
DRV - [2007/08/20 13:38:22 | 00,032,264 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetmonnt.sys – (VETMONNT [System | Running])
DRV - [2003/07/02 14:42:00 | 00,027,904 | —- | M] (VIA Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys – (viaagp1 [Boot | Running])
DRV - [2004/12/07 21:08:58 | 00,172,672 | —- | M] (Copyright © VIA/S3 Graphics Co, Ltd.) – C:\WINDOWS\System32\DRIVERS\vtmini.sys – (viagfx [On_Demand | Running])
DRV - [2003/01/10 17:13:04 | 00,033,588 | —- | M] (America Online, Inc.) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys – (wanatw [On_Demand | Stopped])
DRV - [2003/11/20 19:26:20 | 00,122,110 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\ialmsbw.sys – ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped])
DRV - [2003/11/20 19:26:12 | 00,099,002 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\ialmkchw.sys – ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - Reg Error: Key error. File not found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07076007
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/06 20:09:41 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/06 20:09:41 | 00,000,000 | —D | M]

[2008/08/26 22:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2008/08/26 22:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/13 19:58:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\emd7utl7.default\extensions
[2008/09/23 19:23:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\emd7utl7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/04/25 10:58:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\emd7utl7.default\extensions\[removed]
[2008/08/26 22:17:14 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/29 23:56:01 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/29 23:55:49 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/29 23:55:49 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/08/26 22:16:45 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/08/26 22:16:45 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/08/26 22:16:45 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/13 01:10:20 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/08/26 22:16:45 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/07/30 09:02:12 | 00,000,897 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\livecom.png
[2008/07/30 09:02:12 | 00,001,015 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\livecom.src
[2008/08/26 22:16:45 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/08/26 22:16:45 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: () - - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl (CA, Inc.)
O4 - HKLM..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" (CA, Inc.)
O4 - HKLM..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" (CA, Inc.)
O4 - HKLM..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE (Logitech Inc.)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" (CA)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - Reg Error: Key error. File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: 82 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} http://download.microsoft.com/download/0/5…b?1090196253562 (MSSecurityAdvisor Class)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab (CBankshotZoneCtrl Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444223240000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} http://ndormail01.dor.state.ne.us/dwa7W.cab (Domino Web Access 7 Control)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\system32\UmxWnp.Dll (CA)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/01/20 20:16:37 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 03:02:32 | 00,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{2cee5c98-fca8-11da-8471-000ea6959c2c}\Shell\AutoRun\command - "" = L:\
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/05/14 15:09:21 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/05/12 16:50:27 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/05/12 16:46:31 | 00,389,632 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTMoveIt3.exe
[2009/05/12 16:11:04 | 76,658,072 | —- | C] () – C:\Documents and Settings\Owner\Desktop\jdk-6u13-windows-i586-p.1.2D0D17.efw
[2009/05/06 20:09:44 | 00,202,072 | R— | C] (Coupons, Inc.) – C:\WINDOWS\cpnprt2.cid
[2009/05/06 20:09:43 | 00,202,072 | —- | C] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2009/05/03 23:58:06 | 00,001,745 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/05/03 23:58:06 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/05/03 21:45:29 | 00,000,000 | -HSD | C] – C:\WINDOWS\ftpcache
[2009/05/03 21:25:40 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/05/03 21:25:38 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/03 21:25:38 | 00,000,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/03 21:25:36 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/03 21:25:35 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/03 21:25:34 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/03 21:11:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/05/03 21:01:32 | 00,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/24 19:42:49 | 00,001,533 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Freecell.lnk
[2009/04/24 16:36:27 | 00,000,859 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Monte Carlo Patience.lnk
[2009/04/24 16:36:13 | 00,001,502 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Solitaire.lnk
[2009/04/16 18:13:11 | 00,075,954 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2009/04/15 00:35:32 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/15 00:35:32 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/15 00:35:31 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/15 00:35:31 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/15 00:35:30 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 00:35:29 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/15 00:35:28 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/15 00:35:28 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/15 00:35:27 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/15 00:34:20 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/04/15 00:34:19 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/15 00:34:18 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2008/11/12 18:18:58 | 00,223,232 | —- | C] () – C:\WINDOWS\System32\sqlite3.dll
[2007/10/02 17:36:33 | 00,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2006/06/12 20:11:42 | 00,000,010 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/03/22 10:24:11 | 00,000,000 | —- | C] () – C:\WINDOWS\EAREMOVE.INI
[2006/01/12 20:03:00 | 00,000,000 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/01/12 20:02:55 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\msiosd32.dll
[2006/01/12 20:02:55 | 00,000,245 | —- | C] () – C:\WINDOWS\Msiosd.ini
[2005/10/14 18:06:05 | 00,000,044 | —- | C] () – C:\WINDOWS\liveup.ini
[2005/03/12 10:21:24 | 00,001,175 | —- | C] () – C:\WINDOWS\System32\imbrmute.ini
[2005/02/13 21:24:52 | 00,000,144 | —- | C] () – C:\WINDOWS\MVPHEART.INI
[2005/02/13 00:27:46 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005/01/20 17:17:43 | 00,000,123 | —- | C] () – C:\WINDOWS\MVPEUCHR.INI
[2005/01/14 18:16:05 | 00,000,048 | —- | C] () – C:\WINDOWS\PerWin.ini
[2005/01/11 21:34:12 | 00,000,271 | —- | C] () – C:\WINDOWS\MVPBR.INI
[2005/01/02 15:46:56 | 00,000,176 | —- | C] () – C:\WINDOWS\MVPSPADE.INI
[2005/01/01 00:50:16 | 00,000,596 | —- | C] () – C:\WINDOWS\MVPCRIB.INI
[2004/12/27 18:30:37 | 00,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2004/12/12 21:50:41 | 00,000,050 | —- | C] () – C:\WINDOWS\upst.ini
[2004/11/19 19:13:17 | 00,000,078 | —- | C] () – C:\WINDOWS\qwimp.ini
[2004/11/19 19:13:16 | 00,000,509 | —- | C] () – C:\WINDOWS\intuprof.ini
[2004/10/08 20:47:12 | 00,000,061 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/09/17 18:37:42 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2004/08/29 16:18:34 | 00,000,190 | —- | C] () – C:\WINDOWS\er2.ini
[2004/07/31 20:31:24 | 00,004,224 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/07/30 16:04:13 | 00,000,049 | —- | C] () – C:\WINDOWS\upth.ini
[2004/07/30 16:04:13 | 00,000,030 | —- | C] () – C:\WINDOWS\atid.ini
[2004/06/15 16:26:59 | 00,000,068 | —- | C] () – C:\WINDOWS\Prestopm.INI
[2004/06/07 18:07:25 | 00,002,334 | —- | C] () – C:\WINDOWS\vista32d.ini
[2004/06/07 17:53:47 | 00,000,231 | —- | C] () – C:\WINDOWS\ppdrv.ini
[2004/05/23 20:07:07 | 00,000,103 | —- | C] () – C:\WINDOWS\pmw.INI
[2004/05/23 10:23:55 | 00,000,138 | —- | C] () – C:\WINDOWS\HPFTBX16.INI
[2004/05/23 10:09:53 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2004/05/23 10:09:53 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2004/05/23 10:09:53 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2004/05/23 10:09:53 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2004/05/23 10:09:53 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2004/05/23 10:09:53 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/05/22 18:19:06 | 00,036,352 | —- | C] () – C:\WINDOWS\UTHUNK32.DLL
[2004/05/22 18:05:04 | 00,000,775 | —- | C] () – C:\WINDOWS\OPLIMIT.INI
[2004/05/22 18:04:29 | 00,000,602 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2004/05/22 17:48:54 | 00,000,189 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2004/05/22 17:47:44 | 00,000,512 | —- | C] () – C:\WINDOWS\ALBUM.INI
[2004/05/22 17:47:44 | 00,000,103 | —- | C] () – C:\WINDOWS\PAEDIT.INI
[2004/01/22 12:00:28 | 00,012,635 | —- | C] () – C:\WINDOWS\System32\DAntivirus.ini
[2004/01/22 04:26:02 | 00,000,451 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2004/01/21 05:04:38 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/01/21 04:52:52 | 00,002,142 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2004/01/20 23:08:05 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2004/01/20 23:07:21 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/01/20 23:07:21 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2004/01/20 23:02:24 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2004/01/20 22:56:41 | 00,030,197 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/01/20 22:56:16 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2004/01/20 22:55:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/01/20 22:42:36 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/01/20 22:34:02 | 00,000,994 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004/01/20 21:21:37 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/01/20 20:47:52 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/01/20 20:38:07 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/01/20 20:38:07 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/01/20 20:37:39 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/01/20 20:20:37 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/01/20 19:05:12 | 00,000,466 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/01/20 19:04:50 | 00,000,733 | —- | C] () – C:\WINDOWS\win.ini
[2004/01/20 19:04:46 | 00,000,262 | —- | C] () – C:\WINDOWS\system.ini
[2003/03/07 01:53:16 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\hpnvr82.dll
[2003/01/08 01:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1998/07/01 02:40:30 | 00,003,782 | —- | C] () – C:\WINDOWS\System32\HPFlnk16.ini
[1998/07/01 02:23:58 | 00,007,680 | —- | C] () – C:\WINDOWS\System32\HPFhrl16.dll
[1998/07/01 02:23:56 | 00,249,856 | —- | C] () – C:\WINDOWS\System32\HPFsrl16.dll
[1998/07/01 02:23:50 | 00,260,096 | —- | C] () – C:\WINDOWS\System32\HPFmrl16.dll
[1998/07/01 02:23:46 | 01,113,088 | —- | C] () – C:\WINDOWS\System32\HPFtrl16.dll
[1998/07/01 02:20:56 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\HPFstb16.dll
[1998/07/01 02:20:48 | 00,193,536 | —- | C] () – C:\WINDOWS\System32\HPFcps16.dll
[1998/07/01 02:20:20 | 00,076,800 | —- | C] () – C:\WINDOWS\System32\HPF24r16.dll
[1998/07/01 02:19:08 | 00,044,544 | —- | C] () – C:\WINDOWS\System32\HPFtst16.dll
[1998/07/01 02:17:26 | 00,068,096 | —- | C] () – C:\WINDOWS\System32\HPFpcl16.dll
[1998/07/01 02:15:18 | 00,163,328 | —- | C] () – C:\WINDOWS\System32\HPFntu16.dll
[1998/07/01 02:10:40 | 00,395,264 | —- | C] () – C:\WINDOWS\System32\HPFui16.dll
[1998/07/01 02:04:14 | 00,266,752 | —- | C] () – C:\WINDOWS\System32\HPFwin16.dll
[1998/07/01 02:00:18 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\HPFmon16.dll
[1998/07/01 01:59:40 | 00,033,280 | —- | C] () – C:\WINDOWS\System32\HPFcbl16.dll
[1998/07/01 01:57:42 | 00,022,528 | —- | C] () – C:\WINDOWS\System32\HPFnet16.dll
[1998/07/01 01:57:28 | 00,033,384 | —- | C] () – C:\WINDOWS\System32\HPFiop16.dll
[1998/07/01 01:57:16 | 00,069,284 | —- | C] () – C:\WINDOWS\System32\HPFpml16.dll
[1998/07/01 01:57:12 | 00,137,232 | —- | C] () – C:\WINDOWS\System32\HPFmlc16.dll
[1998/07/01 01:57:06 | 00,057,240 | —- | C] () – C:\WINDOWS\System32\HPFmem16.dll
[1998/07/01 01:57:00 | 00,048,292 | —- | C] () – C:\WINDOWS\System32\HPFlpm16.dll
[1998/07/01 01:56:48 | 00,072,368 | —- | C] () – C:\WINDOWS\System32\HPFcom16.dll
[1998/07/01 01:55:56 | 00,052,800 | —- | C] () – C:\WINDOWS\System32\drivers\HPFecp16.sys
[1998/07/01 01:55:08 | 00,029,184 | —- | C] () – C:\WINDOWS\System32\HPFrsu16.dll
[1998/07/01 01:54:38 | 00,117,760 | —- | C] () – C:\WINDOWS\System32\HPFrsa16.dll
[1998/07/01 01:50:12 | 01,777,664 | —- | C] () – C:\WINDOWS\System32\HPFimg16.dll
[1998/07/01 01:46:52 | 00,124,928 | —- | C] () – C:\WINDOWS\System32\HPFcnt16.dll

========== Files - Modified Within 30 Days ==========

[2009/05/14 15:12:20 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/05/14 02:19:25 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/05/13 23:03:57 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/13 23:03:21 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/13 23:03:19 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\desktop.ini
[2009/05/13 23:03:15 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/13 23:03:14 | 46,929,1008 | -HS- | M] () – C:\hiberfil.sys
[2009/05/13 23:02:37 | 00,075,954 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2009/05/13 18:44:15 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/05/12 17:00:55 | 00,000,591 | —- | M] () – C:\Documents and Settings\Owner\My Documents\My Sharing Folders.lnk
[2009/05/12 16:46:33 | 00,389,632 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTMoveIt3.exe
[2009/05/12 16:11:16 | 76,658,072 | —- | M] () – C:\Documents and Settings\Owner\Desktop\jdk-6u13-windows-i586-p.1.2D0D17.efw
[2009/05/10 18:53:48 | 00,000,514 | —- | M] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Owner at 5 36 PM.job
[2009/05/07 02:16:29 | 24,699,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/05/06 20:09:44 | 00,202,072 | R— | M] (Coupons, Inc.) – C:\WINDOWS\cpnprt2.cid
[2009/05/06 20:09:43 | 00,202,072 | —- | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2009/05/03 23:58:07 | 00,001,745 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/05/03 21:25:38 | 00,000,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/03 21:00:22 | 00,485,396 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/03 21:00:22 | 00,412,008 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/05/03 21:00:22 | 00,065,884 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/05/03 14:34:38 | 00,002,497 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Microsoft Office Word 2003.lnk
[2009/04/22 17:26:53 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/04/15 03:08:57 | 00,000,733 | —- | M] () – C:\WINDOWS\win.ini

========== LOP Check ==========

[2009/05/13 23:05:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/04/01 19:17:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2008/07/21 19:42:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/23 00:39:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2009/03/20 13:56:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2008/01/23 00:42:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/12/05 22:47:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/12/29 02:16:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/03/18 14:19:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ascentive
[2004/05/22 17:34:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund LLC
[2004/05/22 17:34:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2009/04/10 17:56:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2009/02/11 22:31:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/09/27 11:41:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/07/14 00:00:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gtek
[2004/01/20 21:41:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2005/08/27 20:05:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2009/03/08 13:54:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2008/07/07 16:42:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2007/07/25 20:15:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogiShrd
[2009/05/03 21:25:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2006/06/12 13:51:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2006/06/12 13:50:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/06/14 20:36:59 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2004/01/20 23:05:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2004/05/14 18:16:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 5.0.0544
[2004/05/14 18:17:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/05/03 21:11:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/03/01 14:59:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2006/06/17 23:13:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pixelStorm
[2006/06/18 02:13:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2004/07/31 00:05:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2004/05/14 18:05:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/01/20 20:21:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/05/13 22:37:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/05/03 21:15:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/05/03 20:58:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/10/23 12:18:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2009/03/20 14:04:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/05/05 13:04:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2006/09/10 11:27:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2007/06/18 18:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2008/12/27 21:54:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/05/03 21:25:40 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Owner\Application Data
[2008/07/06 10:26:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Adobe
[2006/03/08 00:19:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeAUM
[2008/07/21 19:39:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeUM
[2006/06/09 17:06:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AOL
[2005/11/03 19:08:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apple Computer
[2009/03/25 00:33:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ascentive
[2008/01/10 22:56:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BitTorrent
[2008/08/26 13:36:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Google
[2006/09/05 17:56:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Help
[2005/04/14 12:52:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HP
[2008/01/07 18:40:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Identities
[2007/03/12 12:55:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InstallShield
[2006/06/12 22:43:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2004/05/15 14:35:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/03/30 12:30:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intuit
[2005/10/04 13:52:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lavasoft
[2004/10/07 22:21:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2008/05/28 22:48:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LimeWire
[2007/01/13 16:07:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Macromedia
[2009/05/03 21:25:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2004/12/27 21:06:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\McAfee.com Personal Firewall
[2008/07/30 09:02:41 | 00,000,000 | –SD | M] – C:\Documents and Settings\Owner\Application Data\Microsoft
[2004/05/24 08:52:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2008/05/08 17:14:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/08/26 22:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla
[2007/03/01 15:50:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2005/12/24 21:11:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Musicmatch
[2007/04/22 16:08:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MySpace
[2006/05/20 20:34:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Raptisoft
[2006/03/23 11:02:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Real
[2004/01/20 23:29:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2004/10/07 22:22:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sonic
[2004/01/20 20:54:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sun
[2008/01/09 17:17:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SuperNZB
[2008/08/02 11:56:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2008/01/25 01:30:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2007/06/18 18:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Yahoo!
[2004/07/31 00:04:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\You've Got Pictures Screensaver
[2009/05/13 18:44:15 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/05/10 18:53:48 | 00,000,514 | —- | M] () – C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Owner at 5 36 PM.job
[2002/08/29 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/01 15:49:12 | 00,000,290 | -H– | M] () – C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
[2009/05/14 02:19:25 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/05/13 23:03:21 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 894 bytes -> C:\Documents and Settings\Owner\Desktop\Road Runner.url:favicon
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
< End of report >
Here is 2nd post from Extra.Txt

OTListIt Extras logfile created on: 5/14/2009 3:13:45 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.7 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

447.48 Mb Total Physical Memory | 120.90 Mb Available Physical Memory | 27.02% Memory free
1.03 Gb Paging File | 0.63 Gb Available in Paging File | 61.35% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.10 Gb Total Space | 124.43 Gb Free Space | 86.96% Space Free | Partition Type: NTFS
Drive D: | 5.94 Gb Total Space | 2.12 Gb Free Space | 35.64% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-AT5QGAAC3Z
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\CA Personal Firewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
File not found – C:\Program Files\Common Files\AOL\1104877237\ee\aolservicehost.exe:*:Enabled:AOL Services
File not found – C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
File not found – C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger
File not found – C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
[2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/03/23 11:58:06 | 00,067,128 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
[2007/01/19 13:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 17:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
File not found – C:\Program Files\America Online 9.0b\waol.exe:*:Enabled:America Online 9.0b
File not found – C:\Program Files\Common Files\AOL\1104877237\ee\aolservicehost.exe:*:Enabled:AOL Services
File not found – C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
[2004/10/26 10:50:48 | 00,264,192 | —- | M] (America Online, Inc.) – C:\WINDOWS\system32\spcauth.exe:*:Enabled:AOL
File not found – C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
File not found – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
File not found – C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger
File not found – C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed
File not found – C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
[2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
File not found – C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax
File not found – C:\Program Files\TurboTax\Deluxe 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager
[2007/03/23 11:58:06 | 00,067,128 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
File not found – C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
File not found – C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
File not found – C:\Program Files\DNA\btdna.exe:*:Enabled:DNA
File not found – C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
File not found – C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax
File not found – C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager
File not found – C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
[2007/01/19 13:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 17:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
File not found – C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk
File not found – C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM
[2009/03/12 20:56:54 | 13,498,664 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
[2008/10/10 05:45:26 | 00,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server
File not found – C:\Documents and Settings\Owner\Local Settings\Temp\7zS2.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04410000-9149-45C6-A806-F2BF9CFCE762}" = Microsoft Encarta Encyclopedia Deluxe 2004
"{0FF18B53-CA57-40BB-B562-21A27B662005}" = 1600
"{121634B0-2F4A-11D3-ADA3-00C04F52DD53}" = Windows Installer Clean Up
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{162B71B8-8464-4680-A086-601D555B331D}" = Apple Mobile Device Support
"{17293791-C82E-476C-9997-9A0FF234A19B}" = HP Product Assistant
"{181821B7-82AA-44DA-9DAF-EF254CCB670A}" = Fax
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{342C7C88-D335-4bc2-8CF1-281857629CE2}" = HP PSC & OfficeJet 4.7
"{391E18CE-7D3B-45E9-A8F0-34E77F14F47A}" = ProductContext
"{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}" = Virtual Earth 3D (Beta)
"{442BE28B-782B-4DC0-B490-E70A403B1C69}" = Readme
"{56918C0C-0D87-4CA6-92BF-4975A43AC719}" = KhalInstallWrapper
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{655CB07D-C944-40BE-B93F-55957CAC7625}" = AiO_Scan
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{722CAD74-806B-4AFC-81EA-93B915BB13B6}" = TurboTax 2008 wneiper
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{85CFD253-38AE-4DB1-ACB7-F0F4C791990D}" = AiOSoftware
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8C5FAD77-F678-4758-A296-C12F08D179E0}" = Microsoft IntelliPoint 6.2
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{C26B06A9-27BB-45B0-9873-9C623EC2BA38}" = iTunes
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB449D5A-7710-47aa-B9F5-352B877C90E6}" = 1600_Help
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{F4C6CC40-1142-49be-A28C-7BBD36F0B41A}" = 1600Trb
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"eTrust Suite Personal" = CA Internet Security Suite
"HijackThis" = HijackThis 2.0.2
"HP Photo & Imaging" = HP Image Zone 4.7
"HPExtendedCapabilities" = HP Extended Capabilities 4.7
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"TurboTax 2008" = TurboTax 2008
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"Yahoo! Companion" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/3/2009 7:46:32 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16827, faulting
module mshtml.dll, version 7.0.6000.16825, fault address 0x0028f73f.

Error - 5/3/2009 10:01:52 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = UmxAgent | ID = 108
Description = Cannot open mailslot of Ask User client. Product 0x1, Session 0, Error
0x2.

Error - 5/6/2009 1:20:44 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = UmxAgent | ID = 108
Description = Cannot open mailslot of Ask User client. Product 0x1, Session 0, Error
0x2.

Error - 5/7/2009 2:53:47 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 5/12/2009 5:19:53 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = ESENT | ID = 490
Description = svchost (1644) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 5/12/2009 5:19:53 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = ESENT | ID = 439
Description = Catalog Database (1644) Unable to write a shadowed header for file
C:\WINDOWS\system32\CatRoot2\tmp.edb. Error -1032.

Error - 5/12/2009 5:19:53 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = ESENT | ID = 485
Description = svchost (1644) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"
failed with system error 5 (0x00000005): "Access is denied. ". The delete file
operation will fail with error -1032 (0xfffffbf8).

Error - 5/12/2009 5:19:55 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = ESENT | ID = 485
Description = svchost (1644) An attempt to delete the file "C:\WINDOWS\system32\CatRoot2\tmp.edb"
failed with system error 5 (0x00000005): "Access is denied. ". The delete file
operation will fail with error -1032 (0xfffffbf8).

Error - 5/12/2009 5:55:44 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = UmxAgent | ID = 108
Description = Cannot open mailslot of Ask User client. Product 0x1, Session 0, Error
0x2.

Error - 5/14/2009 12:01:55 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = UmxAgent | ID = 108
Description = Cannot open mailslot of Ask User client. Product 0x1, Session 0, Error
0x2.

[ System Events ]
Error - 5/3/2009 9:51:14 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 5/3/2009 9:51:15 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 5/3/2009 9:58:19 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Service Control Manager | ID = 7034
Description = The PC Tools Security Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 5/3/2009 10:04:13 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon

Error - 5/3/2009 10:33:56 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
fasttx2k nv_agp SISAGP TfFsMon TfSysMon

Error - 5/6/2009 2:44:54 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon

Error - 5/12/2009 5:19:47 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon

Error - 5/12/2009 5:57:32 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon

Error - 5/13/2009 11:39:32 PM | Computer Name = YOUR-AT5QGAAC3Z | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon

Error - 5/14/2009 12:03:42 AM | Computer Name = YOUR-AT5QGAAC3Z | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon


< End of report >


Thanks very much for help!
Tmasters2,

The newest version of Java didn't install. Please try again.

Then:

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.

Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTLI
IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)

:Services

:Reg

:Files
C:\WINDOWS\cpnprt2.cid
C:\WINDOWS\System32\cpnprt2.cid

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL2 log and a new HJT log.
JavaRa 1.13 Removal Log. Report follows after line. ———————————— The JavaRa removal process was started on Sat May 16 21:06:02 2009 Found and removed: C:\Program Files\Java\j2re1.4.2_03 Found and removed: C:\Program Files\Java\jre1.5.0 Found and removed: C:\Program Files\Java\jre1.5.0_06 Found and removed: C:\Windows\System32\jpicpl32.cpl Found and removed: Software\JavaSoft\Java2D\1.5.0 Found and removed: Software\JavaSoft\Java2D\1.5.0_06 Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510006 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510006 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510006 Found and removed: SOFTWARE\Classes\JavaPlugin.150_06 Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06 Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510006 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510006 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_06 Found and removed: Software\Classes\JavaPlugin.160_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_06\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_02\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip ———————————— Finished reporting.
here is the 2nd log I saw. hope this is right. ========== PROCESSES ========== Process explorer.exe killed successfully! ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== File\Folder C:\Program Files\Common Files\aolback\Comps\toolbar\toolbr.exe not found. File\Folder C:\WINDOWS\CouponPrinter.ocx not found. ========== COMMANDS ========== File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DF10C6.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DF3A3A.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DF8D04.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DFA052.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DFB99E.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DFB9AB.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DFD7E0.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. Network Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.15.7 log created on 05162009_211559 Files moved on Reboot… C:\Documents and Settings\Owner\Local Settings\Temp\~DF10C6.tmp moved successfully. C:\Documents and Settings\Owner\Local Settings\Temp\~DF3A3A.tmp moved successfully. C:\Documents and Settings\Owner\Local Settings\Temp\~DF8D04.tmp moved successfully. C:\Documents and Settings\Owner\Local Settings\Temp\~DFA052.tmp moved successfully. File C:\Documents and Settings\Owner\Local Settings\Temp\~DFB99E.tmp not found! File C:\Documents and Settings\Owner\Local Settings\Temp\~DFB9AB.tmp not found! C:\Documents and Settings\Owner\Local Settings\Temp\~DFD7E0.tmp moved successfully. Registry entries deleted on Reboot…
Tomk,

sorry it took awhile here is the HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:58 AM, on 5/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - .DEFAULT User Startup: Organize.lnk = ? (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (file missing)
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://ndormail01.dor.state.ne.us/dwa7W.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 10025 bytes
Tmasters2,

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.



Viewpoint Manager is considered as foistware instead of malware since it is often installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
It is STRONGLY recommended that you remove the Viewpoint products; however, decide for yourself. To uninstall the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):

  • Click Start, then Settings, then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, Remove the Viewpoint component
  • Do the same for each Viewpoint component.

How are things running now?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI