This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Internet address hijack

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I access a particular listing on Google or Yahoo I get the list of websites but when I click on any of them I am hijacked to a different site. I cannot access a site from the search engine listing. I am using Windows XP with IE6. I use Norman AV and Lavasoft Adaware but they do not resolve the problem. Allen
Hi ADS, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Click here to download HJTInstall.exe
Please follow the prompts to ensure it is installed in the proper folder and
a shortcut is created.
  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

Please download DaonolFix from the link below and save it to your Desktop

Double-click DaonolFix.exe to run it.
Select 1. Find Daonol (no fix) by typing 1 and pressing Enter.
You will see a lot of files being listed - don't worry, they are just being scanned.
A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called DaonolFix.txt).



Please post back with
  • HJT (hijackthis) log
  • DaonalFix log

Thanks
Many thanks for your response.

The hijackthis log is:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:25:23, on 15/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Norman\Npm\Bin\Elogsvc.exe
C:\Program Files\Norman\Ngs\Bin\Nprosec.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norman\Npm\Bin\Zanda.exe
C:\Program Files\Norman\npm\bin\nvoy.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norman\npf\bin\npfsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SUPERMICRO\SDIII\NTService.exe
C:\WINDOWS\system32\SD3Service.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Norman\npf\bin\npfuser.exe
C:\WINDOWS\system32\WinVNC.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe
C:\Program Files\Norman\Npm\Bin\scheduler.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Norman\Npm\Bin\Njeeves.exe
C:\Program Files\Norman\npc\bin\npcsvc32.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\INTEL\DSLSetup\ProDsl.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Norman\nse\bin\NSESVC.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Norman\Npm\Bin\ZLH.EXE
C:\Program Files\Norman\npc\bin\nuaa.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\SYS32DLL.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
F:\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Norman\Nvc\Bin\nvcoas.exe
C:\Program Files\Norman\Nvc\Bin\Nip.exe
C:\Program Files\Norman\Nvc\Bin\cclaw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\MICROS~1\OFFICE11\OUTLOOK.EXE
E:\Microsoft Office\OFFICE11\WINWORD.EXE
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://discography.ledzeppelin.com/discography.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll start,C:\WINDOWS\system32\sdra64.exe,C:\WINDOWS\system32\pavuppad.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: 218538 helper - {5E5EFA8F-9F53-418E-B78E-44866667A404} - C:\WINDOWS\system32\218538\218538.dll (file missing)
O2 - BHO: MS extension - {7C7EFE99-C71F-48b8-8CC8-BA506CA76A33} - magks32.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - C:\Program Files\Common\_helper.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
O4 - HKLM\..\Run: [AWMON] "F:\Norman Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9YE.EXE /P23 "EPSON Stylus Photo R800" /O6 "USB002" /M "Stylus Photo R800"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "F:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Norman ZANDA] "C:\Program Files\Norman\Npm\Bin\ZLH.EXE" /LOAD /SPLASH
O4 - HKLM\..\Run: [NPCTray] C:\Program Files\Norman\npc\bin\npc_tray.exe /LOAD
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld08.exe
O4 - HKLM\..\Run: [pp] c:\windows\pp06.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SYS32DLL] SYS32DLL
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Supero Doctor III Client.lnk = C:\Program Files\SUPERMICRO\SDIII\SuperoDoctor.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1230734870593
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1230734831031
O18 - Filter hijack: text/html - {4996b99d-3016-491b-a605-fe0b41d3a8b9} - C:\WINDOWS\system32\dsound3dd.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing)
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - Unknown owner - C:\WINDOWS\ATKKBService.exe (file missing)
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Program Files\Norman\Npm\Bin\Elogsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Indexing Helps (Indexingbox) - Unknown owner - C:\WINDOWS\system\svchest.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Card Adapter (NETDown) - Unknown owner - C:\WINDOWS\smss.exe (file missing)
O23 - Service: Norman NJeeves - Norman ASA - C:\Program Files\Norman\Npm\Bin\Njeeves.exe
O23 - Service: Norman ZANDA - Norman ASA - C:\Program Files\Norman\Npm\Bin\Zanda.exe
O23 - Service: Norman Parental Control (NPC) - Norman ASA - C:\Program Files\Norman\npc\bin\npcsvc32.exe
O23 - Service: Norman Personal Firewall Service (NPFSvc32) - Norman ASA - C:\Program Files\Norman\npf\bin\npfsvc32.exe
O23 - Service: Norman Security service (NPROSECSVC) - Norman ASA - C:\Program Files\Norman\Ngs\Bin\Nprosec.exe
O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:\Program Files\Norman\nse\bin\NSESVC.EXE
O23 - Service: Norman User Activity Agent (NUAA) - Norman ASA - C:\Program Files\Norman\npc\bin\nuaa.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\Norman\Nvc\Bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Unknown owner - C:\Program Files\Norman\Npm\Bin\Nvcsched.exe (file missing)
O23 - Service: Norman Resource Provider (NVOY) - Norman ASA - C:\Program Files\Norman\npm\bin\nvoy.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: perfmons - Unknown owner - C:\WINDOWS\system32\perfmonss.exe (file missing)
O23 - Service: Print Service - Unknown owner - C:\WINDOWS\SYSTEM32\DHCP\dhcpclient.exe (file missing)
O23 - Service: Remote Manager - Unknown owner - C:\WINDOWS\inf\explorer.exe (file missing)
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - F:\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - F:\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe (file missing)
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB - Unknown owner - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe (file missing)
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Norman Scheduler Service (Scheduler) - Norman ASA - C:\Program Files\Norman\Npm\Bin\scheduler.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SuperMicro Health Assistant - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\NTService.exe
O23 - Service: Supero SD3Service Daemon - Unknown owner - C:\WINDOWS\system32\SD3Service.exe
O23 - Service: Applic kaspersky (WindowsKernel) - Unknown owner - C:\WINDOWS\system32\servet.exe (file missing)
O23 - Service: TridiaVNC Server (winvnc) - Tridia Corporation - C:\WINDOWS\system32\WinVNC.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
O23 - Service: Xitami Web Server (Xitami) - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe

–
End of file - 16714 bytes

DaonolFix (15.04.09) by jpshortstuff
Log created at 19:30 on 15/05/2009 by Allen Sheena
Running from C:\Documents and Settings\[removed]\Desktop\DaonolFix.exe

=====Find Daonol=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"aux"="wdmaud.drv"
"midi"="wdmaud.drv"
"midi1"="wdmaud.drv"
"midimapper"="midimap.dll"
"mixer"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm"
"msacm.msadpcm"="msadp32.acm"
"msacm.msaudio1"="msaud32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msg723"="msg723.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.siren"="sirenacm.dll"
"msacm.sl_anet"="sl_anet.acm"
"msacm.trspch"="tssoft32.acm"
"MSVideo8"="VfWWDM32.dll"
"vidc.cvid"="iccvid.dll"
"vidc.DIVX"="DivX.dll"
"VIDC.I420"="msh263.drv"
"vidc.iv31"="ir32_32.dll"
"vidc.iv32"="ir32_32.dll"
"vidc.iv41"="ir41_32.ax"
"vidc.iv50"="ir50_32.dll"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.M261"="msh261.drv"
"vidc.M263"="msh263.drv"
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"VIDC.UYVY"="msyuv.dll"
"VIDC.YUY2"="msyuv.dll"
"vidc.yv12"="DivX.dll"
"VIDC.YVU9"="tsbyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"wave"="wdmaud.drv"
"wave1"="serwvdrv.dll"
"wave2"="serwvdrv.dll"
"wave3"="serwvdrv.dll"
"wave4"="serwvdrv.dll"
"wave5"="wdmaud.drv"
"wavemapper"="msacm32.drv"

-=Daonol Files=-
(none found)

-=End Of File=-

Cheers
HI ADS,


One or more infections have been identified as being a password stealer.

I strongly suggest you do the following immediately:
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.


There are indications of an autorun infection that infects removable USB storage devies. Please do not use any such device untill we have cleaned them.



Open hijackthis, do a system scan only and checkmark these lines, if present

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll start,C:\WINDOWS\system32\sdra64.exe,C:\WINDOWS\system32\pavuppad.exe,
O2 - BHO: 218538 helper - {5E5EFA8F-9F53-418E-B78E-44866667A404} - C:\WINDOWS\system32\218538\218538.dll (file missing)
O2 - BHO: MS extension - {7C7EFE99-C71F-48b8-8CC8-BA506CA76A33} - magks32.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - C:\Program Files\Common\_helper.dll (file missing)
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld08.exe
O4 - HKLM\..\Run: [pp] c:\windows\pp06.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O18 - Filter hijack: text/html - {4996b99d-3016-491b-a605-fe0b41d3a8b9} - C:\WINDOWS\system32\dsound3dd.dll
O23 - Service: perfmons - Unknown owner - C:\WINDOWS\system32\perfmonss.exe (file missing)
O23 - Service: Print Service - Unknown owner - C:\WINDOWS\SYSTEM32\DHCP\dhcpclient.exe (file missing)
O23 - Service: Remote Manager - Unknown owner - C:\WINDOWS\inf\explorer.exe (file missing)


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



Next,

Download OTListIt2 to your desktop.
  • Double click on OTList2.exe
    • Under the Custom Scans/Fixes box at the bottom, paste in the following
    • Do Not copy the word CODE
    • please note the fix starts with the :
    :OTLI
    PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
    
    :Services
    
    :Reg
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableRegedit"=-
    
    :Files
    C:\WINDOWS\system32\winsys16_061230.dll C:\WINDOWS\system32\sdra64.exe
    C:\WINDOWS\system32\pavuppad.exe
    C:\WINDOWS\system32\218538\218538.dll 
    C:\magks32.dll /s
    C:\Program Files\Common\_helper.dll
    C:\windows\ld08.exe
    c:\windows\pp06.exe
    C:\WINDOWS\system32\dsound3dd.dll
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

    Then click the Run Fix button at the top
    • Let the program run unhindered
    • Please save the resulting log to be posted in your next reply.




    After your computer has restarted, please do the following:
  • Double click on OTList2.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


Please post back with
  • all 3 OTLISTIT2 logs

No need for a Hijackthis log this time.

Thanks
My adaware says there is an attempt to delete a registry value Root: HKEY_LOCAL_MACHINE Key: Software\Microsoft\Windows|Current Version\RunOnce Value: OTListlt Data: C:\Documents and Settings\Allen Sheena|DEsktop\OTListlt2 Should I accept? Thanks
Wow that seems to have cured the problem but I will keep an eye on it for the next few days. It is a big relief. I am sorting out my financial details and I have taken out identity theft insurance just to be on the safe side. I really appreciate your help. I did not get a report from OTList as it told me to restart my computer. Is it safe to use USB sticks that I have been using on the computer? Many thanks.
Hi ADS, Your computer is far from being clean. Please post the requested logs. The log from the first run log OTLISTIT2 can be found here C:\_OTListIt\MovedFiles in the right hand panel there will be a file that is a series of numbers ending with .log Please post that file and finish the rest of the instructions. Thanks
This is the file. ========== OTLISTIT ========== Process Explorer.EXE killed successfully! ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableRegedit not found. ========== FILES ========== File\Folder C:\WINDOWS\system32\winsys16_061230.dll C:\WINDOWS\system32\sdra64.exe not found. File move failed. C:\WINDOWS\system32\pavuppad.exe scheduled to be moved on reboot. File\Folder C:\WINDOWS\system32\218538\218538.dll not found. LoadLibrary failed for C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\magks32.dll C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\magks32.dll NOT unregistered. C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\magks32.dll moved successfully. LoadLibrary failed for C:\WINDOWS\system32\magks32.dll C:\WINDOWS\system32\magks32.dll NOT unregistered. C:\WINDOWS\system32\magks32.dll moved successfully. File\Folder C:\Program Files\Common\_helper.dll not found. File\Folder C:\windows\ld08.exe not found. File\Folder c:\windows\pp06.exe not found. File\Folder C:\WINDOWS\system32\dsound3dd.dll not found. ========== COMMANDS ========== File delete failed. C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\RAJPDJ82\activity;src=1667733;met=1;v=1;pid=29472357;aid=207238293;ko=0;cid=28042665 ;rid=28060544;rv=1;×tamp=1227481693828;eid1=2;ecn1=0;etm1=10;eid2=12;ecn2=0;etm2=5;eid5=1[1 ].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\RAJPDJ82\activity;src=1724958;met=1;v=1;pid=31092363;aid=209416659;ko=0;cid=29200509 ;rid=29218388;rv=1;×tamp=1227470372781;eid1=2;ecn1=0;etm1=30;eid2=10;ecn2=0;etm2=30;[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1BZY2ZC\activity;src=1724958;met=1;v=1;pid=31092363;aid=209416659;ko=0;cid=29200509 ;rid=29218388;rv=1;×tamp=1227470342781;eid1=2;ecn1=0;etm1=3;eid2=10;ecn2=0;etm2=3;[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1BZY2ZC\keywords;kw=meridian;cat=293;cat=14969;dcopt=ist;seg=GL_Age50plus_M_Jun08;s eg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllRe gisteredUsers[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1BZY2ZC\keywords;kw=meridian;cat=293;cat=14969;dcopt=ist;seg=GL_Age50plus_M_Jun08;s eg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllRe gisteredUsers[2].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\I3LZ2SUB\activity;src=1667733;met=1;v=1;pid=29472357;aid=207238293;ko=0;cid=28042665 ;rid=28060544;rv=1;×tamp=1227481683750;eid1=2;ecn1=1;etm1=10;eid2=12;ecn2=1;etm2=10;eid3=[1 ].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\I3LZ2SUB\activity;src=1724958;met=1;v=1;pid=31092363;aid=209416659;ko=0;cid=29200509 ;rid=29218388;rv=1;×tamp=1227470339906;eid1=2;ecn1=0;etm1=7;eid2=10;ecn2=1;etm2=0;eid3=4;[1 ].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\I3LZ2SUB\CAP89WPU.5&tz=0&r=empty&title=Home%3A%20personal%2C%20business%2C%20online%2C%20internet%2C%20banking%3A%20HSBC%20Bank%20UK&cd=32&ah=932&aw=1280&sh=960&sw=1280&pd=undefined scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TT3D2UZ\50115744,30115740,70115738,700115743,10115741,50115739,60115748,80115747,00 116901,00110353,70105659,10102908,70102910,50103251,90102909,20110352,40110351,90 105658,901056[1].xml scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TT3D2UZ\CA23KV5A._callback1&request=layout%3D2%26page%3D3907%26emitStyle%3D2%26minResult%3D10%26promotypes%3D75031%26promoStyles%3D48%26results%3D32%26query%3Dmeridian& scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\nvcbin.def.f671a029.tmp scheduled to be deleted on reboot. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05152009_214459 Files moved on Reboot… File move failed. C:\WINDOWS\system32\pavuppad.exe scheduled to be moved on reboot. File C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\RAJPDJ82\activity;src=1667733;met=1;v=1;pid=29472357;aid=207238293;ko=0;cid=28042665 ;rid=28060544;rv=1;×tamp=1227481693828;eid1=2;ecn1=0;etm1=10;eid2=12;ecn2=0;etm2=5;eid5=1[1 ].gif not found! File C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\RAJPDJ82\activity;src=1724958;met=1;v=1;pid=31092363;aid=209416659;ko=0;cid=29200509 ;rid=29218388;rv=1;×tamp=1227470372781;eid1=2;ecn1=0;etm1=30;eid2=10;ecn2=0;etm2=30;[1].gif not found! File C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1BZY2ZC\activity;src=1724958;met=1;v=1;pid=31092363;aid=209416659;ko=0;cid=29200509 ;rid=29218388;rv=1;×tamp=1227470342781;eid1=2;ecn1=0;etm1=3;eid2=10;ecn2=0;etm2=3;[1].gif not found! File C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1BZY2ZC\keywords;kw=meridian;cat=293;cat=14969;dcopt=ist;seg=GL_Age50plus_M_Jun08;s eg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllRe gisteredUsers[1].htm not found! File C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1BZY2ZC\keywords;kw=meridian;cat=293;cat=14969;dcopt=ist;seg=GL_Age50plus_M_Jun08;s eg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllRe gisteredUsers[2].htm not found! File C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\I3LZ2SUB\activity;src=1667733;met=1;v=1;pid=29472357;aid=207238293;ko=0;cid=28042665 ;rid=28060544;rv=1;×tamp=1227481683750;eid1=2;ecn1=1;etm1=10;eid2=12;ecn2=1;etm2=10;eid3=[1 ].gif not found! File C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\I3LZ2SUB\activity;src=1724958;met=1;v=1;pid=31092363;aid=209416659;ko=0;cid=29200509 ;rid=29218388;rv=1;×tamp=1227470339906;eid1=2;ecn1=0;etm1=7;eid2=10;ecn2=1;etm2=0;eid3=4;[1 ].gif not found! File C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\I3LZ2SUB\CAP89WPU.5&tz=0&r=empty&title=Home%3A%20personal%2C%20business%2C%20online%2C%20internet%2C%20banking%3A%20HSBC%20Bank%20UK&cd=32&ah=932&aw=1280&sh=960&sw=1280&pd=undefined not found! File C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TT3D2UZ\50115744,30115740,70115738,700115743,10115741,50115739,60115748,80115747,00 116901,00110353,70105659,10102908,70102910,50103251,90102909,20110352,40110351,90 105658,901056[1].xml not found! File C:\Documents and Settings\Allen Sheena\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TT3D2UZ\CA23KV5A._callback1&request=layout%3D2%26page%3D3907%26emitStyle%3D2%26minResult%3D10%26promotypes%3D75031%26promoStyles%3D48%26results%3D32%26query%3Dmeridian& not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\nvcbin.def.f671a029.tmp scheduled to be moved on reboot. Registry entries deleted on Reboot… What are the rest of the instructions. Thanks again.
Hi ADS,

Here they are
  • Double click on OTList2.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.



Thanks
Sorry for the late reply, I have been out all day.

The OTListIt.txt

OTListIt logfile created on: 16/05/2009 23:24:44 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Allen Sheena\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1022.42 Mb Total Physical Memory | 323.34 Mb Available Physical Memory | 31.63% Memory free
3.38 Gb Paging File | 2.66 Gb Available in Paging File | 78.56% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 35.80 Gb Total Space | 8.51 Gb Free Space | 23.78% Space Free | Partition Type: NTFS
Drive D: | 11.94 Gb Total Space | 9.98 Gb Free Space | 83.58% Space Free | Partition Type: NTFS
Drive E: | 11.59 Gb Total Space | 11.19 Gb Free Space | 96.59% Space Free | Partition Type: NTFS
Drive F: | 50.64 Gb Total Space | 48.18 Gb Free Space | 95.15% Space Free | Partition Type: NTFS
Drive G: | 20.35 Gb Total Space | 10.11 Gb Free Space | 49.71% Space Free | Partition Type: NTFS
Drive H: | 74.57 Gb Total Space | 44.03 Gb Free Space | 59.04% Space Free | Partition Type: NTFS
Drive I: | 74.57 Gb Total Space | 69.16 Gb Free Space | 92.75% Space Free | Partition Type: NTFS

Computer Name: AFS
Current User Name: Allen Sheena
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Norman\Npm\Bin\Elogsvc.exe (Norman ASA)
PRC - C:\Program Files\Norman\Ngs\Bin\Nprosec.exe (Norman ASA)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Norman\Npm\Bin\Zanda.exe (Norman ASA)
PRC - C:\Program Files\Norman\npm\bin\nvoy.exe (Norman ASA)
PRC - C:\Program Files\Norman\npf\bin\npfsvc32.exe (Norman ASA)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\SUPERMICRO\SDIII\NTService.exe ()
PRC - C:\WINDOWS\system32\SD3Service.exe ()
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\WinVNC.exe (Tridia Corporation)
PRC - C:\Program Files\Norman\npf\bin\npfuser.exe (Norman ASA)
PRC - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe (BitDefender)
PRC - C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe ()
PRC - C:\Program Files\Norman\Npm\Bin\scheduler.exe (Norman ASA)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Norman\npc\bin\npcsvc32.exe (Norman ASA)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Norman\Npm\Bin\Njeeves.exe (Norman ASA)
PRC - C:\Program Files\Norman\npc\bin\nuaa.exe (Norman ASA)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
PRC - C:\Program Files\INTEL\DSLSetup\ProDsl.exe (Intel Corporation)
PRC - F:\Norman Ad-Aware SE Professional\Ad-Watch.exe (Norman)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - F:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe ()
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Norman\Npm\Bin\ZLH.EXE (Norman ASA)
PRC - C:\Program Files\Common Files\Teleca Shared\Generic.exe (Teleca AB)
PRC - C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe (Sony Ericsson Mobile Communications AB)
PRC - C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\system32\SYS32DLL.exe ()
PRC - F:\InterVideo\Common\Bin\WinCinemaMgr.exe ()
PRC - C:\Program Files\Norman\nse\bin\NSESVC.EXE (Norman ASA)
PRC - C:\Program Files\Norman\Nvc\Bin\Nip.exe (Norman ASA)
PRC - C:\Program Files\Norman\Nvc\Bin\nvcoas.exe (Norman ASA)
PRC - C:\Program Files\Norman\Nvc\Bin\cclaw.exe (Norman ASA)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Allen Sheena\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (ATI Smart [Auto | Stopped]) – File not found
SRV - (ATKKeyboardService [Auto | Stopped]) – File not found
SRV - (eLoggerSvc6 [Auto | Running]) – C:\Program Files\Norman\Npm\Bin\Elogsvc.exe (Norman ASA)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (Indexingbox [Auto | Stopped]) – File not found
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LIVESRV [Auto | Stopped]) – C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (BitDefender S.R.L.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NETDown [Auto | Stopped]) – File not found
SRV - (Norman NJeeves [On_Demand | Running]) – C:\Program Files\Norman\Npm\Bin\Njeeves.exe (Norman ASA)
SRV - (Norman ZANDA [Auto | Running]) – C:\Program Files\Norman\Npm\Bin\Zanda.exe (Norman ASA)
SRV - (NPC [On_Demand | Running]) – C:\Program Files\Norman\npc\bin\npcsvc32.exe (Norman ASA)
SRV - (NPFSvc32 [Auto | Running]) – C:\Program Files\Norman\npf\bin\npfsvc32.exe (Norman ASA)
SRV - (NPROSECSVC [Auto | Running]) – C:\Program Files\Norman\Ngs\Bin\Nprosec.exe (Norman ASA)
SRV - (nsesvc [On_Demand | Running]) – C:\Program Files\Norman\nse\bin\NSESVC.EXE (Norman ASA)
SRV - (NUAA [On_Demand | Running]) – C:\Program Files\Norman\npc\bin\nuaa.exe (Norman ASA)
SRV - (nvcoas [On_Demand | Running]) – C:\Program Files\Norman\Nvc\Bin\nvcoas.exe (Norman ASA)
SRV - (NVCScheduler [On_Demand | Stopped]) – File not found
SRV - (NVOY [Auto | Running]) – C:\Program Files\Norman\npm\bin\nvoy.exe (Norman ASA)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (perfmons [Disabled | Stopped]) – File not found
SRV - (Print Service [Disabled | Stopped]) – File not found
SRV - (Remote Manager [Disabled | Stopped]) – File not found
SRV - (Roxio UPnP Renderer 9 [On_Demand | Stopped]) – F:\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe (Sonic Solutions)
SRV - (Roxio Upnp Server 9 [Auto | Stopped]) – F:\Roxio\Digital Home 9\RoxioUpnpService9.exe (Sonic Solutions)
SRV - (RoxLiveShare [Auto | Stopped]) – File not found
SRV - (RoxLiveShare9 [Auto | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (Sonic Solutions)
SRV - (RoxMediaDB [On_Demand | Stopped]) – File not found
SRV - (RoxMediaDB9 [On_Demand | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (RoxWatch [Auto | Stopped]) – File not found
SRV - (RoxWatch9 [Auto | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
SRV - (Scheduler [On_Demand | Running]) – C:\Program Files\Norman\Npm\Bin\scheduler.exe (Norman ASA)
SRV - (stllssvr [On_Demand | Stopped]) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (SuperMicro Health Assistant [Auto | Running]) – C:\Program Files\SUPERMICRO\SDIII\NTService.exe ()
SRV - (Supero SD3Service Daemon [Auto | Running]) – C:\WINDOWS\system32\SD3Service.exe ()
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WindowsKernel [Auto | Stopped]) – File not found
SRV - (winvnc [Auto | Running]) – C:\WINDOWS\system32\WinVNC.exe (Tridia Corporation)
SRV - (XCOMM [Auto | Running]) – C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe (BitDefender)
SRV - (Xitami [Auto | Running]) – C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe ()

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (Aspi32 [Auto | Running]) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (ati2mtag [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DLABMFSM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLABMFSM.SYS (Sonic Solutions)
DRV - (DLABOIOM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLACDBHM [System | Running]) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLADResM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLADResM.SYS (Sonic Solutions)
DRV - (DLAIFS_M [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLAOPIOM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLARTL_M [System | Running]) – C:\WINDOWS\System32\Drivers\DLARTL_M.SYS (Sonic Solutions)
DRV - (DLAUDFAM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (DRVNDDM [Auto | Running]) – C:\WINDOWS\System32\Drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (E1000 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\e1000325.sys (Intel Corporation)
DRV - (EIO [Auto | Running]) – C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (EPUSBDSK [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\EPUSBDSK.sys (SEIKO EPSON CORPORATION)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ggflt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (ggsemc [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (IntelC51 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (IntelC52 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC53 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (ISAIONT [System | Running]) – C:\WINDOWS\System32\drivers\IsaIoNt.sys (SuperMicro Computer, Inc.)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MASPINT [Auto | Running]) – C:\WINDOWS\System32\drivers\MASPINT.SYS (MicroStaff Co.,Ltd.)
DRV - (MemMapNt [System | Running]) – C:\WINDOWS\System32\drivers\memmapnt.sys (SuperMicro Computer, Inc.)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (mohfilt [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (Ndiskio [Auto | Running]) – C:\Program Files\Norman\Nse\Bin\NDISKIO.SYS (Norman ASA)
DRV - (NDIS_RD [Boot | Running]) – C:\WINDOWS\System32\drivers\ndis_rd.sys (Norman ASA)
DRV - (NGS [System | Running]) – c:\program files\norman\ngs\bin\ngs.sys (Norman ASA)
DRV - (NPROSEC [System | Running]) – C:\Program Files\Norman\Ngs\Bin\nprosec.sys (Norman ASA)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NvcMFlt [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvcw32mf.sys (Norman ASA)
DRV - (P32LOAD [Auto | Stopped]) – C:\WINDOWS\system32\DRIVERS\p31usbld.sys (Intel Inc.)
DRV - (PQNTDrv [System | Running]) – C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (PRO3200P [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\p32d2kP.sys (Intel Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (RxFilter [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\RxFilter.sys (Sonic Solutions)
DRV - (scsiscan [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\scsiscan.sys (Microsoft Corporation)
DRV - (sea1bus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1bus.sys (MCCI)
DRV - (sea1mdfl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mdfl.sys (MCCI)
DRV - (sea1mdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mdm.sys (MCCI)
DRV - (sea1mgmt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mgmt.sys (MCCI)
DRV - (sea1nd5 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1nd5.sys (MCCI)
DRV - (sea1obex [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1obex.sys (MCCI)
DRV - (sea1unic [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1unic.sys (MCCI)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SMBus [System | Running]) – C:\WINDOWS\System32\drivers\smbus.sys (SuperMicro Computer, Inc.)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (superbmc [System | Stopped]) – C:\WINDOWS\System32\drivers\SUPERBMC.SYS ()
DRV - (TDI_RD [System | Running]) – C:\WINDOWS\system32\drivers\TDI_RD.SYS (Norman ASA)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar;=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://discography.ledzeppelin.com/discography.html
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2008/04/24 19:37:31 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/04 13:22:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/04 13:22:44 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: F:\BITDEFENDER 2008\TBEXTENSION

[2009/05/09 14:16:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Allen Sheena\Application Data\mozilla\Firefox\Profiles\op6y78jg.default\extensions
[2009/03/16 00:38:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Allen Sheena\Application Data\mozilla\Firefox\Profiles\op6y78jg.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/05/15 12:47:22 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2008/04/24 19:36:16 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/04/04 13:22:43 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/04/24 19:36:07 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2009/04/04 13:22:43 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2009/04/04 13:22:27 | 00,067,688 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\jar50.dll
[2009/04/04 13:22:27 | 00,054,368 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\jsd3250.dll
[2009/04/04 13:22:27 | 00,034,944 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\myspell.dll
[2009/04/04 13:22:28 | 00,046,712 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\spellchk.dll
[2009/04/04 13:22:28 | 00,172,136 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\xpinstal.dll
[2009/04/04 13:22:42 | 00,001,514 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/04 13:22:42 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/04 13:22:42 | 00,001,038 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/04 13:22:42 | 00,001,046 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/04 13:22:42 | 00,002,351 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/04 13:22:42 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {7C7EFE99-C71F-48b8-8CC8-BA506CA76A33} - Reg Error: Key error. File not found
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 7.0] "F:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" (Adobe Systems Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe File not found
O4 - HKLM..\Run: [AWMON] "F:\Norman Ad-Aware SE Professional\Ad-Watch.exe" (Norman)
O4 - HKLM..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe (Intel Corporation)
O4 - HKLM..\Run: [EPSON Stylus Photo R800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9YE.EXE /P23 "EPSON Stylus Photo R800" /O6 "USB002" /M "Stylus Photo R800" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Norman ZANDA] "C:\Program Files\Norman\Npm\Bin\ZLH.EXE" /LOAD /SPLASH (Norman ASA)
O4 - HKLM..\Run: [NPCTray] C:\Program Files\Norman\npc\bin\npc_tray.exe /LOAD (Norman ASA)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [pp] c:\windows\pp06.exe File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions ()
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [sysldtray] C:\windows\ld08.exe File not found
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [SYS32DLL] SYS32DLL ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk = F:\InterVideo\Common\Bin\WinCinemaMgr.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Supero Doctor III Client.lnk = C:\Program Files\SUPERMICRO\SDIII\SuperoDoctor.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://E:\MICROS~1\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Norman\npc\bin\nlf.dll (Norman ASA)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1230734870593 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1230734831031 (MUWebControl Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) - C:\WINDOWS\system32\sdra64.exe [FILE handle not seen by OS]
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\pavuppad.exe) - C:\WINDOWS\system32\pavuppad.exe ()
O20 - Winlogon\Notify\AtiExtEvent: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/03/02 21:58:13 | 00,000,000 | —D | M] - G:\Autograph – [ NTFS ]
O33 - MountPoints2\{08c9e670-8be6-11db-a185-000000000000}\Shell\AutoRun\command - "" = J:\PCInstaller.exe – File not found
O33 - MountPoints2\{c14b9936-d0a8-11dc-a401-003048813b9a}\Shell - "" = AutoRun
O33 - MountPoints2\{c14b9936-d0a8-11dc-a401-003048813b9a}\Shell\Auto\command - "" = J:\servet.exe – File not found
O33 - MountPoints2\{c14b9936-d0a8-11dc-a401-003048813b9a}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c14b9938-d0a8-11dc-a401-003048813b9a}\Shell - "" = AutoRun
O33 - MountPoints2\{c14b9938-d0a8-11dc-a401-003048813b9a}\Shell\Auto\command - "" = J:\servet.exe – File not found
O33 - MountPoints2\{c14b9938-d0a8-11dc-a401-003048813b9a}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c2b7a9f8-86ac-11db-a17a-000000000000}\Shell\AutoRun\command - "" = J:\PCInstaller.exe – File not found
O33 - MountPoints2\{c45cb05e-91c0-11db-a193-000000000000}\Shell - "" = AutoRun
O33 - MountPoints2\{c45cb05e-91c0-11db-a193-000000000000}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c45cb05e-91c0-11db-a193-000000000000}\Shell\AutoRun\command - "" = J:\Xkey_launcher.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/15 21:43:10 | 00,000,000 | —D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\System32\*.tmp files]
[2009/05/15 21:44:59 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/05/15 21:43:05 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Allen Sheena\Desktop\OTListIt2.exe
[2009/05/15 19:29:34 | 00,100,352 | —- | C] () – C:\Documents and Settings\Allen Sheena\Desktop\DaonolFix.exe
[2009/05/15 19:05:46 | 00,389,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF20455.exe
[2009/05/15 19:01:26 | 00,389,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF19610.exe
[2009/05/15 18:59:36 | 00,000,000 | —D | C] – C:\Qoobox
[2009/05/15 18:49:52 | 00,000,816 | —- | C] () – C:\Documents and Settings\Allen Sheena\Desktop\HijackThis.lnk
[2009/05/15 18:38:36 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Allen Sheena\Desktop\HJTInstall.exe
[2009/05/15 17:40:45 | 00,500,463 | —- | C] () – C:\Documents and Settings\Allen Sheena\Desktop\J0878 Pi Data Sheet_Tomato v.2.pdf
[2009/05/15 13:00:04 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/05/15 12:43:36 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/05/15 12:40:14 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily).job
[2009/05/15 12:39:12 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}
[2009/05/15 12:39:10 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/05/15 12:39:04 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/05/15 12:39:04 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/05/15 00:32:30 | 00,000,002 | -H– | C] () – C:\WINDOWS\t55ft2692f44.dat
[2009/05/15 00:32:30 | 00,000,001 | —- | C] () – C:\WINDOWS\9g2234wesdf3dfgjf23
[2009/05/15 00:32:28 | 00,013,824 | —- | C] () – C:\WINDOWS\System32\SYS32DLL.exe
[2009/05/15 00:32:26 | 00,000,000 | —D | C] – C:\WINDOWS\System32\218538
[2009/05/13 17:16:33 | 00,062,464 | —- | C] () – C:\Documents and Settings\Allen Sheena\Desktop\Datasound Brochure.doc
[2009/05/13 00:09:07 | 00,000,000 | -HSD | C] – C:\WINDOWS\System32\bookls
[2009/05/13 00:09:05 | 00,075,264 | —- | C] () – C:\WINDOWS\internat.exe
[2009/05/13 00:09:05 | 00,059,392 | —- | C] () – C:\WINDOWS\System32\inform.dat
[2009/05/13 00:09:05 | 00,013,733 | —- | C] () – C:\WINDOWS\System32\pmx
[2009/04/27 13:50:13 | 02,432,833 | —- | C] () – C:\Documents and Settings\Allen Sheena\Desktop\Management Services Brochure.pdf
[2009/04/23 15:30:58 | 00,177,152 | —- | C] () – C:\Documents and Settings\Allen Sheena\Desktop\Pi Letterhead new logo.doc
[2007/12/21 17:33:25 | 00,000,121 | —- | C] () – C:\WINDOWS\bdagent.INI
[2007/10/12 20:08:39 | 00,000,093 | —- | C] () – C:\WINDOWS\System32\mywebhit.ini
[2007/10/12 11:25:37 | 00,237,056 | —- | C] () – C:\WINDOWS\System32\scanclient.dll
[2007/08/31 07:01:22 | 00,000,295 | —- | C] () – C:\WINDOWS\System32\adckcon.ini
[2007/08/31 06:59:54 | 00,002,479 | —- | C] () – C:\WINDOWS\System32\CCProxy.ini
[2007/08/31 06:58:56 | 00,213,504 | —- | C] () – C:\WINDOWS\System32\webps.dll
[2007/06/24 02:05:41 | 00,000,092 | —- | C] () – C:\WINDOWS\System32\pfxzmtsmtspm.dll
[2007/06/24 02:05:41 | 00,000,067 | —- | C] () – C:\WINDOWS\System32\sfxzmtforum.dll
[2007/06/24 02:05:41 | 00,000,053 | —- | C] () – C:\WINDOWS\System32\pfxzmtymsg.dll
[2007/06/24 02:05:41 | 00,000,053 | —- | C] () – C:\WINDOWS\System32\pfxzmticq.dll
[2007/06/24 02:05:41 | 00,000,053 | —- | C] () – C:\WINDOWS\System32\pfxzmtgtal.dll
[2007/06/24 02:05:41 | 00,000,053 | —- | C] () – C:\WINDOWS\System32\pfxzmtaim.dll
[2007/06/24 02:05:41 | 00,000,029 | —- | C] () – C:\WINDOWS\System32\pfxzmtwbmail.dll
[2007/06/24 02:05:41 | 00,000,025 | —- | C] () – C:\WINDOWS\System32\pfxzmtsmt.dll
[2007/06/24 02:05:41 | 00,000,012 | —- | C] () – C:\WINDOWS\System32\pfxzmtzpurse.dll
[2007/06/24 02:05:41 | 00,000,012 | —- | C] () – C:\WINDOWS\System32\pfxzmtrpurse.dll
[2007/06/24 02:05:41 | 00,000,006 | —- | C] () – C:\WINDOWS\System32\pfxzmtfpurse.dll
[2007/02/05 20:55:42 | 00,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2007/01/31 14:50:32 | 00,913,408 | —- | C] () – C:\WINDOWS\System32\xreglib.dll
[2006/12/02 15:46:34 | 00,000,826 | —- | C] () – C:\WINDOWS\DC.ini
[2006/10/22 11:22:00 | 00,212,992 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/08/09 05:19:50 | 00,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/08/09 05:19:50 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2006/08/09 02:00:00 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\besched.dll
[2006/07/11 15:29:00 | 00,028,672 | R— | C] ( ) – C:\WINDOWS\System32\DivXGraphBuilderCallback.dll
[2006/06/26 23:49:46 | 00,106,496 | —- | C] () – C:\WINDOWS\System32\PixText.dll
[2006/01/26 13:25:31 | 00,000,099 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/01/26 13:24:49 | 00,000,025 | —- | C] () – C:\WINDOWS\CDER800Euro.ini
[2005/12/30 14:19:40 | 00,000,275 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/16 19:50:16 | 00,000,303 | —- | C] () – C:\WINDOWS\doom3.ini
[2005/11/08 12:56:32 | 00,143,802 | —- | C] () – C:\WINDOWS\System32\BC30RTL.DLL
[2005/11/08 12:56:24 | 00,008,704 | —- | C] () – C:\WINDOWS\System32\TTXDSP32.DLL
[2005/11/01 15:25:18 | 00,000,195 | —- | C] () – C:\WINDOWS\perscopy.INI
[2005/10/30 13:43:47 | 00,004,292 | —- | C] () – C:\WINDOWS\estwn323.ini
[2005/10/25 20:32:26 | 00,000,061 | —- | C] () – C:\WINDOWS\cvsedit.ini
[2005/10/25 16:34:09 | 00,016,384 | —- | C] () – C:\WINDOWS\System32\ventmon.dll
[2005/10/25 13:39:15 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/10/25 13:13:01 | 00,020,213 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/10/25 12:16:17 | 00,000,291 | —- | C] () – C:\WINDOWS\msfsetup.ini
[2005/10/25 11:34:14 | 00,000,117 | —- | C] () – C:\WINDOWS\wgedit.ini
[2005/10/21 19:59:21 | 00,077,824 | R— | C] () – C:\WINDOWS\System32\SetupAux.dll
[2005/10/21 19:36:56 | 00,096,353 | R— | C] () – C:\WINDOWS\System32\devcinst.dll
[2005/10/21 01:03:17 | 00,000,032 | —- | C] () – C:\WINDOWS\CD_Start.INI
[2005/10/19 11:21:11 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/10/18 14:22:46 | 00,000,071 | —- | C] () – C:\WINDOWS\autmtst.ini
[2005/10/18 14:19:05 | 00,122,880 | —- | C] () – C:\WINDOWS\System32\SDRES.dll
[2005/10/18 14:19:05 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\SDRES_zhtw.dll
[2005/10/18 14:19:05 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\SDRES_zhcn.dll
[2005/10/18 14:19:05 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\supermon.dll
[2005/10/18 14:19:05 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\SUPERDLL.DLL
[2005/10/18 14:19:05 | 00,014,174 | —- | C] () – C:\WINDOWS\System32\drivers\SUPERBMC.SYS
[2005/10/18 14:19:05 | 00,003,857 | —- | C] () – C:\WINDOWS\System32\SuperDOpt.ini
[2005/10/18 14:19:05 | 00,003,238 | —- | C] () – C:\WINDOWS\System32\WinIo.sys
[2005/10/18 14:19:03 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2005/10/18 14:19:03 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\omnithread_rt.dll
[2005/10/18 14:19:03 | 00,044,544 | —- | C] () – C:\WINDOWS\System32\GIF89.DLL
[2005/10/18 14:18:57 | 00,010,129 | —- | C] () – C:\WINDOWS\System32\SuperD.ini
[2005/10/18 14:17:52 | 00,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2005/09/15 04:05:36 | 03,596,288 | R— | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/08/30 01:29:04 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/02 09:35:00 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/08/02 09:35:00 | 01,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/08/02 09:35:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/08/02 09:35:00 | 00,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/08/02 09:35:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/08/02 09:35:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/07/15 19:35:56 | 00,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/07/15 19:35:56 | 00,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/03/01 15:30:20 | 00,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[2004/08/04 13:00:00 | 00,000,777 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/04 13:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
[2003/10/02 02:00:00 | 00,208,896 | —- | C] () – C:\WINDOWS\System32\lockout.dll
[2003/10/02 02:00:00 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\lockres.dll
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/10/17 12:46:58 | 00,339,456 | —- | C] () – C:\WINDOWS\System32\tx32.dll

========== Files - Modified Within 30 Days ==========

[3 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/05/16 14:04:07 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/05/16 14:03:12 | 00,002,121 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2009/05/16 14:02:50 | 00,088,108 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/05/16 14:02:47 | 00,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/16 14:01:21 | 00,010,129 | —- | M] () – C:\WINDOWS\System32\SuperD.ini
[2009/05/16 14:01:05 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/16 14:01:02 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Allen Sheena\Local Settings\desktop.ini
[2009/05/16 14:00:58 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/16 12:39:49 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily).job
[2009/05/15 21:43:14 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Allen Sheena\Desktop\OTListIt2.exe
[2009/05/15 21:41:11 | 00,002,325 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\Microsoft Office Outlook 2003.lnk
[2009/05/15 19:52:47 | 00,002,301 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\Microsoft Office Word 2003.lnk
[2009/05/15 19:29:34 | 00,100,352 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\DaonolFix.exe
[2009/05/15 19:03:46 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF20455.exe
[2009/05/15 18:59:28 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF19610.exe
[2009/05/15 18:49:53 | 00,000,816 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\HijackThis.lnk
[2009/05/15 18:38:43 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Allen Sheena\Desktop\HJTInstall.exe
[2009/05/15 17:40:45 | 00,500,463 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\J0878 Pi Data Sheet_Tomato v.2.pdf
[2009/05/15 16:36:10 | 00,002,285 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\Microsoft Office PowerPoint 2003.lnk
[2009/05/15 12:42:54 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/05/15 12:42:42 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/05/15 12:39:10 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/05/15 00:32:30 | 00,000,002 | -H– | M] () – C:\WINDOWS\t55ft2692f44.dat
[2009/05/15 00:32:30 | 00,000,001 | —- | M] () – C:\WINDOWS\9g2234wesdf3dfgjf23
[2009/05/15 00:32:28 | 00,013,824 | —- | M] () – C:\WINDOWS\System32\SYS32DLL.exe
[2009/05/14 13:27:12 | 00,002,111 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\Microsoft AutoRoute.lnk
[2009/05/13 17:16:33 | 00,062,464 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\Datasound Brochure.doc
[2009/05/13 10:50:40 | 00,075,264 | —- | M] () – C:\WINDOWS\internat.exe
[2009/05/13 10:50:40 | 00,059,392 | —- | M] () – C:\WINDOWS\System32\inform.dat
[2009/05/13 10:50:40 | 00,013,733 | —- | M] () – C:\WINDOWS\System32\pmx
[2009/05/11 23:02:01 | 00,000,734 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/05/11 21:42:56 | 00,000,001 | —- | M] () – C:\WINDOWS\System32\drivers\etc\lmhosts.ive_bak
[2009/05/11 21:42:56 | 00,000,001 | —- | M] () – C:\WINDOWS\System32\drivers\etc\lmhosts
[2009/05/11 00:45:17 | 00,004,292 | —- | M] () – C:\WINDOWS\estwn323.ini
[2009/05/08 13:17:45 | 00,002,303 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\Microsoft Office Excel 2003.lnk
[2009/05/07 08:16:29 | 24,699,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/28 14:05:23 | 00,000,117 | —- | M] () – C:\WINDOWS\wgedit.ini
[2009/04/27 13:50:13 | 02,432,833 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\Management Services Brochure.pdf
[2009/04/23 15:30:58 | 00,177,152 | —- | M] () – C:\Documents and Settings\Allen Sheena\Desktop\Pi Letterhead new logo.doc
[2009/04/18 18:02:58 | 00,000,599 | —- | M] () – C:\Documents and Settings\Allen Sheena\My Documents\My Sharing Folders.lnk
[2009/04/17 08:33:04 | 00,439,994 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/17 08:33:04 | 00,383,254 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/17 08:33:04 | 00,053,608 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/17 00:32:31 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/17 00:29:07 | 00,000,777 | —- | M] () – C:\WINDOWS\win.ini

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Allen Sheena\My Documents\TFRFF.gif:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Allen Sheena\My Documents\phsyics formulae.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Allen Sheena\My Documents\phsyics formulae 2.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Allen Sheena\My Documents\maths.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Allen Sheena\My Documents\ImTOO DVD Ripper Platinum& MPEG Encoder.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Allen Sheena\Desktop\England.jpg:Roxio EMC Stream
< End of report >


Thanks
The Extras.Txt

OTListIt Extras logfile created on: 16/05/2009 23:24:44 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Allen Sheena\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1022.42 Mb Total Physical Memory | 323.34 Mb Available Physical Memory | 31.63% Memory free
3.38 Gb Paging File | 2.66 Gb Available in Paging File | 78.56% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 35.80 Gb Total Space | 8.51 Gb Free Space | 23.78% Space Free | Partition Type: NTFS
Drive D: | 11.94 Gb Total Space | 9.98 Gb Free Space | 83.58% Space Free | Partition Type: NTFS
Drive E: | 11.59 Gb Total Space | 11.19 Gb Free Space | 96.59% Space Free | Partition Type: NTFS
Drive F: | 50.64 Gb Total Space | 48.18 Gb Free Space | 95.15% Space Free | Partition Type: NTFS
Drive G: | 20.35 Gb Total Space | 10.11 Gb Free Space | 49.71% Space Free | Partition Type: NTFS
Drive H: | 74.57 Gb Total Space | 44.03 Gb Free Space | 59.04% Space Free | Partition Type: NTFS
Drive I: | 74.57 Gb Total Space | 69.16 Gb Free Space | 92.75% Space Free | Partition Type: NTFS

Computer Name: AFS
Current User Name: Allen Sheena
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"80:TCP" = 80:TCP:*:Enabled:SYS32DLL
"7171:TCP" = 7171:TCP:*:Enabled:SYS32DLL

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
F:\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe:*:Enabled:Roxio Upnp Service File not found
F:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08094E03-AFE4-4853-9D31-6D0743DF5328}" = QuickTime
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.4.2
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4D719053-5593-11D3-8F25-0060085C1758}" = Microsoft AutoRoute 2001
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{553E56C3-7AA1-45FE-A2FC-2C43DC27F765}" = iTunes
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}" = EPSON Easy Photo Print
"{668B2B3A-4241-409F-A4AE-79B5016A487E}" = Sony Ericsson PC Suite
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{79918EFC-5E93-4798-A8F6-F43851D01456}" = Supero Doctor III
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A62A068-3FD6-495A-9F66-26FE94F32EC9}" = Rhapsody Player Engine
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90415EA5-3856-4402-B566-53160813421B}" = ASUS ATI Driver
"{934E9442-D305-4ACF-AD87-A6C11D677CB9}" = ImageMixer VCD2 for FinePix
"{938B1CD7-7C60-491E-AA90-1F1888168240}" = Roxio Easy Media Creator 9 Suite
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD 4
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B2AE44CB-2AAB-4C08-A54B-D264BD604DA8}" = Citrix Presentation Server Client
"{B90450DF-E781-46FD-B1F1-0C86DA40E443}" = PIF DESIGNER
"{C339CAC7-65FF-40F3-9D56-317BF20C8CFF}" = PhoneTools eXPert
"{C8B34404-2E52-4C1F-A2B7-D26E46E5974D}" = Norman Security Suite
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D4E73194-7F99-452B-BD09-2F4A4D1A07F3}" = Intel® 537EP Modem
"{D680C913-5955-469D-9D88-C1940F7506D6}" = RAW FILE CONVERTER LE
"{DC5DB7E0-8A1D-488B-9213-7754B19E0019}" = Autograph 3 (30-day Trial)
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"Ad-Aware" = Ad-Aware
"Adobe Acrobat 7.0 Professional" = Adobe Acrobat 7.1.0 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Photoshop 7.0 ME" = Adobe Photoshop 7.0 ME
"Anatomy Trains" = Anatomy Trains
"Boots F2CD Picture Suite" = Boots F2CD Picture Suite
"DOOM Collector's Edition" = DOOM Collector's Edition
"DslSetup" = Intel® AnyPoint® Modem
"EPSON Printer and Utilities" = EPSON Printer Software
"ESPR800 Reference Guide" = ESPR800 Reference Guide
"HijackThis" = HijackThis 2.0.2
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"InstallShield_{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3
"Intel® 537EP Modem" = Intel® 537EP Modem
"Interactive Functional Anatomy 2nd Edition" = Interactive Functional Anatomy 2nd Edition
"IZArc 3.5 beta 3_is1" = IZArc 3.5 beta 3
"Knight Rider" = Knight Rider
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"MailNavigator v.1.11" = MailNavigator v.1.11
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (2.0.0.20)" = Mozilla Firefox (2.0.0.20)
"MSNINST" = MSN
"MWASPI" = MicroStaff WINASPI
"Norman Ad-Aware SE Professional" = Norman Ad-Aware SE Professional
"NVIDIA Drivers" = NVIDIA Drivers
"Privacy Guardian_is1" = Privacy Guardian 4.1
"PROSet" = Intel® PRO Network Connections Drivers
"RealPlayer 6.0" = RealPlayer
"Serif PhotoPlus 6.0" = Serif PhotoPlus 6.0
"SightSpeed" = SightSpeed (remove only)
"ST5UNST #1" = Analyst
"ST5UNST #2" = Analyst (f:\Analyst\)
"ST5UNST #3" = Analyst (f:\Analyst\) #3
"SyncBackSE_is1" = SyncBackSE
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 15/05/2009 16:39:21 | Computer Name = AFS | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: AFS\Allen Sheena Checkpoint ID: 1 Error Code: 0x8000ffff Error
description: Catastrophic failure

Error - 15/05/2009 16:54:27 | Computer Name = AFS | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: AFS\Allen Sheena Checkpoint ID: 1 Error Code: 0x80070005 Error
description: Access is denied.

Error - 15/05/2009 16:54:27 | Computer Name = AFS | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: AFS\Allen Sheena Checkpoint ID: 1 Error Code: 0x8000ffff Error
description: Catastrophic failure

Error - 15/05/2009 19:14:32 | Computer Name = AFS | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: AFS\Allen Sheena Checkpoint ID: 1 Error Code: 0x80070005 Error
description: Access is denied.

Error - 15/05/2009 19:14:32 | Computer Name = AFS | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: AFS\Allen Sheena Checkpoint ID: 1 Error Code: 0x8000ffff Error
description: Catastrophic failure

Error - 16/05/2009 00:51:36 | Computer Name = AFS | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: AFS\Allen Sheena Checkpoint ID: 1 Error Code: 0x80070005 Error
description: Access is denied.

Error - 16/05/2009 00:51:36 | Computer Name = AFS | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: AFS\Allen Sheena Checkpoint ID: 1 Error Code: 0x8000ffff Error
description: Catastrophic failure

Error - 16/05/2009 08:58:51 | Computer Name = AFS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 16/05/2009 09:02:56 | Computer Name = AFS | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: AFS\Allen Sheena Checkpoint ID: 1 Error Code: 0x80070005 Error
description: Access is denied.

Error - 16/05/2009 09:02:56 | Computer Name = AFS | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: AFS\Allen Sheena Checkpoint ID: 1 Error Code: 0x8000ffff Error
description: Catastrophic failure

[ System Events ]
Error - 16/05/2009 00:52:07 | Computer Name = AFS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
asuskbnt

Error - 16/05/2009 09:01:22 | Computer Name = AFS | Source = Service Control Manager | ID = 7000
Description = The Intel® AnyPoint® 3240 USB Modem Firmware Loader service failed
to start due to the following error: %%1058

Error - 16/05/2009 09:01:22 | Computer Name = AFS | Source = Service Control Manager | ID = 7000
Description = The ATI Smart service failed to start due to the following error:
%%2

Error - 16/05/2009 09:01:22 | Computer Name = AFS | Source = Service Control Manager | ID = 7000
Description = The ATK Keyboard Service service failed to start due to the following
error: %%2

Error - 16/05/2009 09:01:22 | Computer Name = AFS | Source = Service Control Manager | ID = 7023
Description = The IPSES service terminated with the following error: %%126

Error - 16/05/2009 09:01:22 | Computer Name = AFS | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the BitDefender Desktop Update
Service service to connect.

Error - 16/05/2009 09:01:22 | Computer Name = AFS | Source = Service Control Manager | ID = 7000
Description = The BitDefender Desktop Update Service service failed to start due
to the following error: %%1053

Error - 16/05/2009 09:02:44 | Computer Name = AFS | Source = Service Control Manager | ID = 7022
Description = The Supero SD3Service Daemon service hung on starting.

Error - 16/05/2009 09:02:46 | Computer Name = AFS | Source = Service Control Manager | ID = 7022
Description = The Windows Time service hung on starting.

Error - 16/05/2009 09:02:46 | Computer Name = AFS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
asuskbnt


< End of report >


Thanks again.
Hi ADS,

We'll stop that pesky Ad-Aware warning and also disable Windows Defender. You can re-enable them when you computer is clean.

AD-AWARE AD-WATCH
  • Right click on the Ad-Watch icon in the system tray.
  • At the bottom of the screen there will be two checkable items called "Active" and "Automatic".
    • Active: This will turn Ad-Watch On\Off without closing it.
    • Automatic: Suspicious activity will be blocked automatically.
  • Uncheck both of those boxes.

WINDOWS DEFENDER
  • Click Start > Programs > Windows Defender or launch from the system tray icon.
  • Click on Tools & Settings > Options.
  • Under Real-time protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.

Next, Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTLI
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\SYS32DLL.exe ()
SRV - (perfmons [Disabled | Stopped]) – File not found
SRV - (Print Service [Disabled | Stopped]) – File not found
SRV - (Remote Manager [Disabled | Stopped]) – File not found
SRV - (Indexingbox [Auto | Stopped]) – File not found
SRV - (NETDown [Auto | Stopped]) – File not found
SRV - (WindowsKernel [Auto | Stopped]) – File not found
O2 - BHO: (no name) - {7C7EFE99-C71F-48b8-8CC8-BA506CA76A33} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [pp] c:\windows\pp06.exe File not found
O4 - HKLM..\Run: [sysldtray] C:\windows\ld08.exe File not found
O4 - HKCU..\Run: [SYS32DLL] SYS32DLL ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\pavuppad.exe) - C:\WINDOWS\system32\pavuppad.exe ()
[2007/06/24 02:05:41 | 00,000,092 | —- | C] () – C:\WINDOWS\System32\pfxzmtsmtspm.dll
[2007/06/24 02:05:41 | 00,000,067 | —- | C] () – C:\WINDOWS\System32\sfxzmtforum.dll
[2007/06/24 02:05:41 | 00,000,053 | —- | C] () – C:\WINDOWS\System32\pfxzmtymsg.dll
[2007/06/24 02:05:41 | 00,000,053 | —- | C] () – C:\WINDOWS\System32\pfxzmticq.dll
[2007/06/24 02:05:41 | 00,000,053 | —- | C] () – C:\WINDOWS\System32\pfxzmtgtal.dll
[2007/06/24 02:05:41 | 00,000,053 | —- | C] () – C:\WINDOWS\System32\pfxzmtaim.dll
[2007/06/24 02:05:41 | 00,000,029 | —- | C] () – C:\WINDOWS\System32\pfxzmtwbmail.dll
[2007/06/24 02:05:41 | 00,000,025 | —- | C] () – C:\WINDOWS\System32\pfxzmtsmt.dll
[2007/06/24 02:05:41 | 00,000,012 | —- | C] () – C:\WINDOWS\System32\pfxzmtzpurse.dll
[2007/06/24 02:05:41 | 00,000,012 | —- | C] () – C:\WINDOWS\System32\pfxzmtrpurse.dll
[2007/06/24 02:05:41 | 00,000,006 | —- | C] () – C:\WINDOWS\System32\pfxzmtfpurse.dll

:Services

:Reg

:Files
C:\WINDOWS\system32\SYS32DLL.exe
C:\WINDOWS\System32\CF20455.exe
C:\WINDOWS\System32\CF19610.exe
C:\WINDOWS\t55ft2692f44.dat
C:\WINDOWS\9g2234wesdf3dfgjf23
C:\WINDOWS\System32\218538
C:\WINDOWS\System32\bookls
C:\WINDOWS\internat.exe
C:\WINDOWS\System32\inform.dat
C:\WINDOWS\System32\pmx
C:\WINDOWS\System32\mywebhit.ini
C:\WINDOWS\imsins.BAK

:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.


Next

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Please post back with
  • OTLISTIT2 log
  • combofix log
  • new HJT log taken last

Thanks
In Control Panel I have Windows Security Centre which gives three settings: Internet Options Windows Firewall (Off) Automatic Updates (on) There is no reference to Widows Defender. Cheers

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI