This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Poor Malware Removal contd.

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
I would greatly appreciate if someone could have a look at me HJT Log. Since attempting a removal some time ago, I have been unable to Add a printer, Enable or Disable Automatic Updates, and a few other things.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:53:56 PM, on 2/24/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\tp4serv.exe
C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\pcAnywhere\Winaw32.exe
C:\Program Files\Symantec\pcAnywhere\SessionController.exe
C:\Program Files\Symantec\pcAnywhere\awrem32.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Symantec\pcAnywhere\awrem32.exe
C:\Program Files\Notepad++\notepad++.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [TPKMAPMN] C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Pidgin] C:\Program Files\Pidgin\pidgin.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {26700CD9-6157-4B72-B46F-EC93C952F19C} (SWToolSet.Engine) - http://solarwinds.telegens.com/SWToolset.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1137342090700
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} - http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file://D:\CDVIEWER\CdViewer.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE

–
End of file - 8274 bytes
Hi elmkd,


Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • both OTL logs
Thanks
Hello, Thanks for your help with this. I got the following error: FDI cannot enumerate Files. I will try the scan again. Regards
Hi elmkd,

That is an odd error. Did you download OTL to your desktop?

If so, try this scanner instead

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Thanks
DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 9:28:39.96 on Tue 03/02/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.367.123 [GMT -5:00] AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} ============== Running Processes =============== C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe svchost.exe C:\WINDOWS\system32\tp4serv.exe C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\QCONSVC.EXE C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\explorer.exe C:\Program Files\Symantec\pcAnywhere\Winaw32.exe C:\Program Files\Symantec\pcAnywhere\SessionController.exe C:\WINDOWS\system32\WISPTIS.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Thunderbird\thunderbird.exe C:\Documents and Settings\Herbalife\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No File TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll TB: Foxit Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Pidgin] c:\program files\pidgin\pidgin.exe mRun: [TrackPointSrv] tp4serv.exe mRun: [TPKMAPMN] c:\program files\thinkpad\utilities\TpKmapMn.exe mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe mRun: [TP4EX] tp4ex.exe mRun: [S3TRAY2] S3Tray2.exe mRun: [QCWLICON] c:\program files\thinkpad\connectutilities\QCWLICON.EXE mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe mRun: [BMMLREF] c:\program files\thinkpad\utilities\BMMLREF.EXE mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [ATIModeChange] Ati2mdxx.exe mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min uPolicies-explorer: NoActiveDesktop = 01000000 IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL Trusted Zone: microsoft.com\windowsupdate DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {26700CD9-6157-4B72-B46F-EC93C952F19C} - hxxp://solarwinds.telegens.com/SWToolset.exe DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1137342090700 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} - hxxp://www.linksysfix.com/netcheck/51/install/gtdownls.cab DPF: {CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} - file://d:\cdviewer\CdViewer.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: PCANotify - PCANotify.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\herbal~1\applic~1\mozilla\firefox\profiles\h021fr2r.marcel\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - component: c:\documents and settings\herbalife\application data\mozilla\firefox\profiles\h021fr2r.marcel\extensions\{dd43485f-44cc-4452-a6c6-69356a7e33da}\platform\winnt_x86-msvc\components\ahWinUtils_32.dll FF - plugin: c:\documents and settings\herbalife\application data\mozilla\firefox\profiles\h021fr2r.marcel\extensions\[removed]\plugins\npRACtrl.dll FF - plugin: c:\progra~1\mozill~1\plugins\np_gp.dll FF - plugin: c:\progra~1\mozill~1\plugins\npatgpc.dll FF - plugin: c:\progra~1\mozill~1\plugins\npdeploytk.dll FF - plugin: c:\progra~1\mozill~1\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\progra~1\mozill~1\plugins\npmozax.dll FF - plugin: c:\progra~1\mozill~1\plugins\npnul32.dll FF - plugin: c:\progra~1\mozill~1\plugins\NPOFFICE.DLL FF - plugin: c:\progra~1\mozill~1\plugins\npOGAPlugin.dll FF - plugin: c:\progra~1\mozill~1\plugins\nppl3260.dll FF - plugin: c:\progra~1\mozill~1\plugins\nppsynth.dll FF - plugin: c:\progra~1\mozill~1\plugins\npqtplugin.dll FF - plugin: c:\progra~1\mozill~1\plugins\npqtplugin2.dll FF - plugin: c:\progra~1\mozill~1\plugins\npqtplugin3.dll FF - plugin: c:\progra~1\mozill~1\plugins\npqtplugin4.dll FF - plugin: c:\progra~1\mozill~1\plugins\npqtplugin5.dll FF - plugin: c:\progra~1\mozill~1\plugins\npqtplugin6.dll FF - plugin: c:\progra~1\mozill~1\plugins\npqtplugin7.dll FF - plugin: c:\progra~1\mozill~1\plugins\npRACtrl.dll FF - plugin: c:\progra~1\mozill~1\plugins\nprjplug.dll FF - plugin: c:\progra~1\mozill~1\plugins\nprpjplug.dll FF - plugin: c:\progra~1\mozill~1\plugins\npvlc.dll FF - plugin: c:\progra~1\mozill~1\plugins\npyaxmpb.dll FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\nppsynth.dll FF - plugin: c:\program files\mozilla firefox\plugins\npRACtrl.dll FF - plugin: c:\program files\mozilla firefox\plugins\npvlc.dll FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll FF - plugin: c:\windows\system32\photosynth\nppsynth.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-12-6 11608] R1 awlegacy;awlegacy;c:\windows\system32\drivers\AWLEGACY.sys [2003-11-17 11165] R1 bpfinder;BACKPACK Finder;c:\windows\system32\drivers\bpfinder.sys [2004-1-21 62023] R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2003-12-4 15360] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-12-6 56816] R3 bpflt;BACKPACK Filter;c:\windows\system32\drivers\bpflt.sys [2004-1-21 4538] R3 CPWNA100;Wireless Notebook Adapter 11a/g Service;c:\windows\system32\drivers\CPWNA100.sys [2006-1-11 345824] R3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [1980-1-1 14064] S3 bppccard;BACKPACK PC Card;c:\windows\system32\drivers\bppccard.sys [2004-1-21 5493] S3 bppnpdrv;BACKPACK Driver;c:\windows\system32\drivers\bppnpdrv.sys [2004-1-21 19414] S3 bpusbdrv;BACKPACK USB 1 Cable;c:\windows\system32\drivers\bpusbdrv.sys [2004-1-21 128248] S3 bpusbflt;BACKPACK USB Filter;c:\windows\system32\drivers\bpusbflt.sys [2004-1-21 8333] S3 CEBDADTV;C&E DVB-T device;c:\windows\system32\drivers\CEBDA150.sys [2006-7-5 75520] S3 PCDRDRV;Pcdr Helper Driver;\??\c:\progra~1\pc-doc~1\diagno~1\pcdrdrv.sys –> c:\progra~1\pc-doc~1\diagno~1\PCDRDRV.sys [?] S4 AW_HOST;AW_HOST;c:\windows\system32\drivers\AW_HOST5.sys [2005-11-21 11008] =============== Created Last 30 ================ 2010-03-01 18:52:10 0 d—–w- c:\documents and settings\herbalife\Tracing 2010-03-01 18:49:21 0 d—–w- c:\program files\Windows Live SkyDrive 2010-03-01 18:45:45 0 d—–w- c:\program files\common files\Windows Live 2010-02-24 18:10:18 0 d—–w- C:\Telstar ==================== Find3M ==================== 2010-03-01 19:13:47 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs 2010-03-01 19:13:38 0 —-a-w- c:\windows\system32\drivers\logiflt.iad 2010-01-07 21:07:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 21:07:04 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2008-09-16 15:32:55 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091620080917\index.dat ============= FINISH: 9:30:14.56 ===============📎Attach.zip
Hi elmkd,

There is nothing showing in these logs except old java. What malware did you attempt to remove?

We can take care of the java now

Go to ADD/Remove programs and uninstall these programs


Java 2 Runtime Environment, SE v1.4.2_12
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
Java™ SE Runtime Environment 6 Update 1


Do not uninstall Java™ 6 Update 13


Next, click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.



Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK



Let's see if a dll became unregistered

Click Start, select Run

Copy and paste the following into the run box and click OK

regsvr32 wuaueng.dll

Accept any warning. Try Windows updates again.
Unfortunately problems persist. I can't add a printer when I right click and select Add Printer nothing comes up. I get an error that crashes windows explorer whenever I open the Control Panel: "An error occurred while Windows was working with the Control Panel file: C:\WINDOWS\system32\wuaucpl.cpl" and windows explorer crashes and restarts. Microsoft Update does not function properly Microsoft Update error: [Error number: 0x80070715] The website has encountered a problem and cannot display the page you are trying to view. Even though the Microsoft Update page is actually loaded. I am unable to do a repair on my wireless connection because the wifi interface will not disable. I don't know how to resolve all of these issues. I don't remember which malware I tried to remove. Regards, M
Hi elmkd,

Do you have any logs left fron any of the tools you used to remove the malware?

  • Download FixPolicies.exe by Bill Castner and save it to your desktop.
  • Double click on FixPolicies.exe to run it.
  • Click on Install. It will create a folder named FixPolicies on your desktop.
  • Open the FixPolicies folder.
  • Double click on Fix_policies.cmd to run it. Command Prompt will open and close quickly; this is normal.


Let's try the Automated Windows Update Fix

  • Download WUFix.exe to your desktop.
  • Double-Click WUFix.exe to run fix.
  • You will see a window open and commands processing. When the window closes the fix will have completed.
  • Restart the computer.
This fix will clear the proxy cache, places Windows Update sites in the Trusted Zone, places Windows Update sites in the exception list of IE Popup Blocker, starts all dependent services, registers required DLLS, empties the Windows Update temporary folder (with backup), renames the catroot2 folder, retains update history and Event log, and deletes BITS pending download queue.
Once done, go back to the Windows Update Website (You must use the Microsoft Internet Explorer to do this).
Thank you for your reply. I did all as you instructed. I am still unable to add a printer. Even if I unplug the USB cable and re-insert it, the printer is not detected. I have tried other printers as well. If I click the add printer link, or right click in the printers folder and select add printer, nothing happens, the wizard does not open. Windows Update still gives me an Error number: 0x80070715 I am still unable to do a repair on my WIFI connection. It will not disable. Regards, Marcel Dunn
Hi elmkd,

Let's see if OTL will show us which services are running and which aren't. OTL should run with the following setup.

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Standard Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please post both logs.

Thanks
OTL logfile created on: 3/5/2010 8:34:28 AM - Run 1
OTL by OldTimer - Version 3.1.32.0 Folder = C:\Documents and Settings\Herbalife\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

367.00 Mb Total Physical Memory | 198.00 Mb Available Physical Memory | 54.00% Memory free
882.00 Mb Paging File | 635.00 Mb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 549 549 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15.69 Gb Total Space | 5.56 Gb Free Space | 35.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SOZU_JA
Current User Name: Herbalife
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/03/01 09:54:59 | 000,551,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Herbalife\Desktop\OTL.exe
PRC - [2009/10/11 04:17:36 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/07/21 13:40:24 | 000,404,737 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\update.exe
PRC - [2009/07/21 13:34:33 | 000,185,089 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009/05/13 15:48:22 | 000,108,289 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009/03/02 12:08:47 | 000,209,153 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2005/11/23 07:58:04 | 000,765,952 | —- | M] (Diskeeper Corporation) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
PRC - [2005/11/11 01:33:00 | 000,073,782 | —- | M] () – C:\WINDOWS\system32\ibmpmsvc.exe
PRC - [2003/02/17 03:30:48 | 000,032,835 | —- | M] () – C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
PRC - [2003/01/21 18:05:44 | 000,094,208 | —- | M] () – C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
PRC - [2003/01/16 20:49:12 | 000,077,824 | —- | M] () – C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
PRC - [2003/01/08 05:50:00 | 000,053,248 | —- | M] () – C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
PRC - [2003/01/08 05:50:00 | 000,049,152 | —- | M] () – C:\WINDOWS\system32\QCONSVC.EXE
PRC - [2002/12/24 05:01:00 | 000,204,800 | —- | M] (IBM Corp.) – C:\Program Files\ThinkPad\Utilities\EzEjMnAp.Exe
PRC - [2002/12/03 06:09:00 | 000,087,552 | —- | M] (IBM Corporation) – C:\WINDOWS\system32\tp4serv.exe
PRC - [2002/01/10 18:01:34 | 000,065,536 | —- | M] (IBM Corporation) – C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe


========== Modules (SafeList) ==========

MOD - [2010/03/01 09:54:59 | 000,551,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Herbalife\Desktop\OTL.exe


========== Win32 Services (SafeList) ==========

SRV - [2009/07/21 13:34:33 | 000,185,089 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2009/05/13 15:48:22 | 000,108,289 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2006/05/01 13:38:46 | 000,106,496 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\pcAnywhere\awhost32.exe – (awhost32)
SRV - [2006/03/03 21:03:10 | 000,069,632 | —- | M] (HP) [Unknown | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2006/01/19 11:29:52 | 002,041,536 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE – (LiveUpdate)
SRV - [2005/11/23 07:58:04 | 000,765,952 | —- | M] (Diskeeper Corporation) [Auto | Running] – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe – (Diskeeper)
SRV - [2005/11/11 01:33:00 | 000,073,782 | —- | M] () [Auto | Running] – C:\WINDOWS\system32\ibmpmsvc.exe – (IBMPMSVC)
SRV - [2005/04/04 00:41:10 | 000,069,632 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT)
SRV - [2003/01/08 05:50:00 | 000,049,152 | —- | M] () [Auto | Running] – C:\WINDOWS\system32\QCONSVC.EXE – (QCONSVC)


========== Driver Services (SafeList) ==========

DRV - [2009/12/08 07:16:55 | 000,056,816 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\avgntflt.sys – (avgntflt)
DRV - [2009/05/11 09:12:24 | 000,028,520 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ssmdrv.sys – (ssmdrv)
DRV - [2009/04/30 23:03:30 | 000,023,832 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lvuvcflt.sys – (FilterService)
DRV - [2009/04/30 23:03:08 | 006,754,712 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lvuvc.sys – (LVUVC) Logitech Webcam 200(UVC)
DRV - [2009/03/30 09:33:07 | 000,096,104 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avipbb.sys – (avipbb)
DRV - [2009/02/13 11:35:05 | 000,011,608 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Program Files\Avira\AntiVir Desktop\avgio.sys – (avgio)
DRV - [2008/07/28 17:19:28 | 000,116,736 | —- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mcdbus.sys – (mcdbus)
DRV - [2008/04/13 13:56:49 | 000,012,800 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usb8023x.sys – (usb_rndisx)
DRV - [2008/04/13 13:56:49 | 000,012,800 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usb8023.sys – (USB_RNDIS)
DRV - [2008/04/13 13:54:36 | 000,028,672 | —- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nscirda.sys – (NSCIRDA)
DRV - [2008/04/13 13:46:22 | 000,015,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mpe.sys – (MPE)
DRV - [2008/04/13 13:45:12 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 13:36:39 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/13 13:36:39 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2007/11/13 05:25:53 | 000,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv)
DRV - [2007/05/09 21:51:34 | 000,041,888 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LVUSBSta.sys – (LVUSBSta)
DRV - [2007/05/09 21:47:00 | 001,276,832 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LV302V32.SYS – (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2006/09/18 11:54:48 | 000,016,640 | —- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\tbhsd.sys – (tbhsd)
DRV - [2006/07/05 17:57:08 | 000,075,520 | —- | M] (Computer & Entertainment, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\CEBDA150.sys – (CEBDADTV)
DRV - [2006/01/27 18:44:24 | 000,150,528 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\b57xp32.sys – (b57w2k)
DRV - [2005/11/21 13:42:08 | 000,011,008 | —- | M] (Symantec Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\drivers\AW_HOST5.sys – (AW_HOST)
DRV - [2005/11/11 01:33:00 | 000,010,112 | —- | M] (Lenovo.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ibmpmdrv.sys – (IBMPMDRV)
DRV - [2005/10/10 14:09:38 | 000,007,552 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\awechomd.sys – (awecho)
DRV - [2005/08/26 16:20:10 | 000,016,768 | —- | M] (Computer & Entertainment, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\CEBDALDR.sys – (CEBDALDR)
DRV - [2005/01/31 05:26:06 | 000,912,768 | R— | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LV302AV.SYS – (PID_08A0) QuickCam IM(PID_08A0)
DRV - [2004/08/04 00:41:35 | 000,606,684 | —- | M] (LT) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ltmdmnt.sys – (ltmodem5)
DRV - [2003/12/11 09:10:20 | 000,345,824 | R— | M] (Royal Philips Electronics N.V.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\CPWNA100.sys – (CPWNA100)
DRV - [2003/11/17 18:06:48 | 000,011,165 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\awlegacy.sys – (awlegacy)
DRV - [2003/10/24 12:02:12 | 000,578,816 | —- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\smwdm.sys – (smwdm)
DRV - [2003/10/23 12:17:10 | 000,100,384 | —- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\aeaudio.sys – (aeaudio)
DRV - [2003/09/23 11:32:12 | 000,032,128 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\PCANDIS5.sys – (PCANDIS5)
DRV - [2003/04/21 13:00:32 | 000,013,898 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\GERNUWA.sys – (Gernuwa)
DRV - [2003/01/17 04:32:00 | 000,015,360 | —- | M] (IBM Corp.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\TPPWR.SYS – (TPPWR)
DRV - [2003/01/08 05:50:00 | 000,002,295 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\system32\drivers\IBMBLDID.SYS – (IBMTPCHK)
DRV - [2002/12/26 05:10:00 | 000,007,168 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\system32\drivers\TSMAPIP.SYS – (TSMAPIP)
DRV - [2002/12/26 04:32:00 | 000,014,848 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\SMAPINT.SYS – (Smapint)
DRV - [2002/12/26 04:32:00 | 000,008,830 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\system32\drivers\TDSMAPI.SYS – (TDSMAPI)
DRV - [2002/12/17 22:29:28 | 000,015,378 | —- | M] (IBM Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\TPHKDRV.sys – (TPHKDRV)
DRV - [2002/12/14 14:23:38 | 000,541,952 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2002/12/03 06:09:00 | 000,014,064 | —- | M] (IBM Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\tp4track.sys – (Tp4Track)
DRV - [2002/11/22 13:21:18 | 001,157,856 | —- | M] (Agere Systems) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2002/10/30 06:20:36 | 000,019,414 | R— | M] (Micro Solutions, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\bppnpdrv.sys – (bppnpdrv)
DRV - [2002/10/30 06:20:08 | 000,128,248 | R— | M] (Micro Solutions, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\bpusbdrv.sys – (bpusbdrv)
DRV - [2002/10/30 06:13:36 | 000,008,333 | R— | M] (Micro Solutions, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\bpusbflt.sys – (bpusbflt)
DRV - [2002/10/30 06:13:26 | 000,004,538 | R— | M] (Micro Solutions, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\bpflt.sys – (bpflt)
DRV - [2002/10/30 06:13:14 | 000,062,023 | R— | M] (Micro Solutions, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\bpfinder.sys – (bpfinder)
DRV - [2002/10/30 06:12:48 | 000,005,493 | R— | M] (Micro Solutions, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\bppccard.sys – (bppccard)
DRV - [2002/08/30 12:04:56 | 000,023,570 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\atisgkaf.sys – (caboagp)
DRV - [2002/08/29 08:00:00 | 000,017,792 | —- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink)
DRV - [2001/11/01 05:57:14 | 000,095,104 | —- | M] (S3 Graphics, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s3ssavm.sys – (S3SSavage)
DRV - [2001/09/13 10:58:02 | 000,007,012 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\PMEMNT.SYS – (PMEM)
DRV - [2001/08/17 17:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 17:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 17:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 17:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 17:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 16:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 16:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 16:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 16:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 16:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 16:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 16:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 16:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 16:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 16:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2001/08/17 16:48:14 | 000,011,520 | —- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\TwoTrack.sys – (TwoTrack)
DRV - [2001/08/17 15:20:04 | 000,096,256 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ac97intc.sys – (ac97intc) Intel® 82801 Audio Driver Install Service (WDM)
DRV - [2001/08/17 15:12:10 | 000,117,760 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\e100b325.sys – (E100B) Intel®


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/18 10:01:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/11/19 07:56:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009/08/20 16:50:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2009/10/20 13:52:45 | 000,000,000 | —D | M]

[2008/12/26 17:19:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Extensions
[2010/03/04 09:09:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions
[2009/07/10 08:19:49 | 000,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009/05/29 23:54:43 | 000,000,000 | —D | M] (View Source Chart) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{68836a21-fc7d-4ea1-a065-7efabd99d414}
[2010/01/26 14:33:52 | 000,000,000 | —D | M] (IE View) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2009/06/04 00:16:48 | 000,000,000 | —D | M] (IE Tab) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2009/07/10 08:20:12 | 000,000,000 | —D | M] (Image Toolbar) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{A4732521-77D9-447E-A557-B279AC923F06}
[2009/08/29 10:48:36 | 000,000,000 | —D | M] (Password Exporter) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2008/05/21 18:25:00 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2009/05/21 10:21:34 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
[2010/01/26 14:33:51 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/05/03 09:12:17 | 000,000,000 | —D | M] (Autohide) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{DD43485F-44CC-4452-A6C6-69356A7E33DA}
[2008/10/07 16:56:43 | 000,000,000 | —D | M] (Mouse Gestures Redox) – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\{FFA36170-80B1-4535-B0E3-A4569E497DD0}
[2009/11/05 12:17:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\[removed]
[2009/10/08 10:32:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Mozilla\Firefox\Profiles\h021fr2r.Marcel\extensions\[removed]
[2010/03/04 09:09:22 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2006/01/11 13:38:23 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{36C13C8F-54F1-412e-8177-2E411719162D}
[2006/01/13 10:37:56 | 000,000,000 | —D | M] (IE View) – C:\Program Files\Mozilla Firefox\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2006/01/11 13:38:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2006/01/13 10:37:56 | 000,000,000 | —D | M] (Image Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{A4732521-77D9-447E-A557-B279AC923F06}
[2006/01/13 10:37:56 | 000,000,000 | —D | M] (OpenBook) – C:\Program Files\Mozilla Firefox\extensions\{aba3f5c2-35d5-4960-bdfc-de9c162e39ce}
[2006/01/13 10:37:56 | 000,000,000 | —D | M] (Web Developer) – C:\Program Files\Mozilla Firefox\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2006/01/11 13:38:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{D058E276-9F5D-4ca2-8AE9-2416C188BECA}
[2006/01/11 13:38:18 | 000,000,000 | —D | M] (Autohide) – C:\Program Files\Mozilla Firefox\extensions\{DD43485F-44CC-4452-A6C6-69356A7E33DA}
[2006/01/11 13:38:18 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Program Files\Mozilla Firefox\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2006/01/11 13:38:17 | 000,000,000 | —D | M] (Mouse Gestures) – C:\Program Files\Mozilla Firefox\extensions\{FFA36170-80B1-4535-B0E3-A4569E497DD0}
[2009/04/02 15:40:55 | 000,027,976 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
[2009/04/02 15:40:57 | 000,126,360 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
[2008/06/02 11:59:49 | 000,098,712 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2008/06/02 11:58:54 | 000,060,824 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2009/10/20 13:51:46 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2006/05/14 12:45:26 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2006/05/23 17:19:18 | 000,418,744 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
[2007/06/07 06:43:50 | 001,138,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\nppsynth.dll
[2007/05/22 19:32:00 | 001,560,576 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npRACtrl.dll
[2005/12/12 14:54:46 | 006,740,480 | —- | M] (VideoLAN Team) – C:\Program Files\Mozilla Firefox\plugins\npvlc.dll
[2007/03/09 18:16:44 | 000,189,496 | —- | M] (Yahoo! Inc.) – C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
[2007/05/22 19:14:00 | 000,008,784 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\ractrlkeyhook.dll
[2007/06/07 06:43:50 | 001,847,296 | —- | M] (Microsoft) – C:\Program Files\Mozilla Firefox\plugins\Seadragon.dll
[2007/05/22 19:17:00 | 000,245,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\unicows.dll
[2009/11/19 07:56:32 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2009/11/19 07:56:32 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2009/11/19 07:56:33 | 000,000,759 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2009/11/19 07:56:33 | 000,000,831 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

Hosts file not found
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE ()
O4 - HKLM..\Run: [EZEJMNAP] C:\Program Files\ThinkPad\Utilities\EzEjMnAp.Exe (IBM Corp.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE ()
O4 - HKLM..\Run: [S3TRAY2] C:\WINDOWS\System32\S3Tray2.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TP4EX] C:\WINDOWS\System32\TP4EX.exe (IBM Corporation)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe ()
O4 - HKLM..\Run: [TPKMAPMN] C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe ()
O4 - HKLM..\Run: [TrackPointSrv] C:\WINDOWS\System32\tp4serv.exe (IBM Corporation)
O4 - HKCU..\Run: [Pidgin] C:\Program Files\Pidgin\pidgin.exe (The Pidgin developer community)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] http in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {26700CD9-6157-4B72-B46F-EC93C952F19C} http://solarwinds.telegens.com/SWToolset.exe (SWToolSet.Engine)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1267630650617 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1267630631900 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} http://www.linksysfix.com/netcheck/51/install/gtdownls.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} file://D:\CDVIEWER\CdViewer.cab (AMI DicomDir TreeView Control 2.1)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.0.3 208.67.222.222
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\PCANotify: DllName - PCANotify.dll - C:\WINDOWS\System32\PCANotify.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\wall2blue1024.bmp
O24 - Desktop BackupWallPaper: C:\wall2blue1024.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/01/22 09:35:24 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{1ad4f810-213c-11dd-8031-00061bda74ff}\Shell - "" = AutoRun
O33 - MountPoints2\{1ad4f810-213c-11dd-8031-00061bda74ff}\Shell\Auto\command - "" = MSInfnd.exe
O33 - MountPoints2\{1ad4f810-213c-11dd-8031-00061bda74ff}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{2a6cc130-7692-11dc-bf36-00061bda74ff}\Shell - "" = AutoRun
O33 - MountPoints2\{2a6cc130-7692-11dc-bf36-00061bda74ff}\Shell\Auto\command - "" = E:\boot.exe – File not found
O33 - MountPoints2\{2a6cc130-7692-11dc-bf36-00061bda74ff}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{402b2834-8b1b-11dd-810f-00061bda74ff}\Shell\Auto\command - "" = Windows.scr
O33 - MountPoints2\{402b2834-8b1b-11dd-810f-00061bda74ff}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{57126b31-b55f-11dc-bf80-00061bda74ff}\Shell - "" = AutoRun
O33 - MountPoints2\{57126b31-b55f-11dc-bf80-00061bda74ff}\Shell\Auto\command - "" = E:\sxs.exe – File not found
O33 - MountPoints2\{57126b31-b55f-11dc-bf80-00061bda74ff}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/03/04 09:17:21 | 000,000,000 | —D | C] – C:\Program Files\FixWindowsUpdate
[2010/03/03 09:21:16 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/03/03 09:21:16 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/03/03 09:21:16 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/03/01 14:08:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Herbalife\Favorites\My Documents\My Received Files
[2010/03/01 13:52:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Herbalife\Tracing
[2010/03/01 13:49:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2010/03/01 13:49:21 | 000,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2010/03/01 13:48:15 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/03/01 13:45:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2010/03/01 09:54:55 | 000,551,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Herbalife\Desktop\OTL.exe
[2010/02/24 13:10:18 | 000,000,000 | —D | C] – C:\Telstar
[2009/03/20 08:25:32 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/06/09 08:31:23 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/06/09 08:31:22 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/06/09 08:31:22 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2006/05/15 00:37:26 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/03/04 09:48:22 | 000,002,278 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/04 09:46:01 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/04 09:45:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/04 09:44:32 | 007,077,888 | -H– | M] () – C:\Documents and Settings\Herbalife\NTUSER.DAT
[2010/03/04 09:44:32 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Herbalife\ntuser.ini
[2010/03/02 10:37:27 | 000,327,504 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/01 14:13:47 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2010/03/01 14:13:38 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2010/03/01 13:51:32 | 000,083,392 | —- | M] () – C:\Documents and Settings\Herbalife\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/01 09:54:59 | 000,551,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Herbalife\Desktop\OTL.exe
[2010/02/05 09:30:28 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2007/09/12 11:04:00 | 000,000,404 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/09/12 11:02:28 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007/05/01 19:25:37 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2007/04/28 23:51:56 | 000,000,013 | —- | C] () – C:\WINDOWS\System32\MSVCTSCP.DLL
[2007/04/17 13:42:15 | 000,002,216 | —- | C] () – C:\WINDOWS\hpdj3500.ini
[2007/02/24 13:12:33 | 000,013,312 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2007/02/05 16:32:49 | 000,000,186 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/02/01 11:20:23 | 000,000,380 | -H– | C] () – C:\WINDOWS\WINRDPDP40.SYS
[2006/09/01 15:14:16 | 000,001,337 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/19 13:32:56 | 000,000,132 | —- | C] () – C:\Documents and Settings\Herbalife\Local Settings\Application Data\fusioncache.dat
[2006/03/16 11:23:50 | 000,000,026 | —- | C] () – C:\WINDOWS\DfrgUIEx.INI
[2006/01/26 16:48:20 | 000,027,648 | —- | C] () – C:\WINDOWS\php.ini
[2006/01/16 04:26:36 | 000,268,648 | —- | C] () – C:\WINDOWS\System32\mucltui.dll
[2006/01/11 09:09:55 | 000,082,289 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2005/12/21 05:36:46 | 000,009,728 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2005/11/05 11:46:26 | 000,000,537 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2005/07/31 15:11:24 | 000,221,696 | —- | C] () – C:\Documents and Settings\Herbalife\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/06/22 21:49:52 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/04/27 01:29:58 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2004/04/27 01:29:58 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2004/01/21 18:17:15 | 000,002,923 | R— | C] () – C:\WINDOWS\System32\bpinst.dll
[2003/12/04 23:23:14 | 000,002,481 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/12/04 22:54:03 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/12/04 22:53:26 | 000,001,112 | —- | C] () – C:\WINDOWS\System32\PX.INI
[2003/12/04 22:44:37 | 000,000,222 | —- | C] () – C:\WINDOWS\Welcome.ini
[2003/12/04 22:36:46 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2003/12/04 22:36:37 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\FPCALL.dll
[2003/12/04 22:36:17 | 000,002,295 | —- | C] () – C:\WINDOWS\System32\drivers\IBMBLDID.SYS
[2003/12/04 22:35:46 | 000,008,830 | —- | C] () – C:\WINDOWS\System32\drivers\TDSMAPI.SYS
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/11/15 04:14:28 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\AIBMRUNL.dll
[2002/09/27 13:54:29 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[1980/01/01 03:00:00 | 000,560,640 | —- | C] () – C:\WINDOWS\System32\printui.dll
[1980/01/01 03:00:00 | 000,357,888 | —- | C] () – C:\WINDOWS\System32\confmsp.dll
[1980/01/01 03:00:00 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\cmdial32.dll
[1980/01/01 03:00:00 | 000,330,752 | —- | C] () – C:\WINDOWS\System32\ippromon.dll
[1980/01/01 03:00:00 | 000,285,696 | —- | C] () – C:\WINDOWS\System32\atmfd.dll
[1980/01/01 03:00:00 | 000,181,248 | —- | C] () – C:\WINDOWS\System32\dmime.dll
[1980/01/01 03:00:00 | 000,142,336 | —- | C] () – C:\WINDOWS\System32\nwprovau.dll
[1980/01/01 03:00:00 | 000,113,152 | —- | C] () – C:\WINDOWS\System32\tp4uires.dll
[1980/01/01 03:00:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\msxml.dll

========== LOP Check ==========

[2006/01/10 23:48:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ibm
[2007/04/29 00:02:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NeuroDimension
[2006/11/08 18:00:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Palo Alto Software
[2010/03/04 09:51:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\.purple
[2010/02/24 13:10:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\FileZilla
[2009/10/20 13:52:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Foxit
[2007/07/12 01:24:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Grisoft
[2009/12/19 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\gtk-2.0
[2004/02/14 12:04:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\IBM
[2009/07/10 09:54:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\ICAClient
[2006/01/16 00:44:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Leadertech
[2009/07/01 14:07:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\NCH Swift Sound
[2009/03/10 09:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Notepad++
[2006/11/08 18:03:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Palo Alto Software
[2007/10/18 14:39:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\SmartDraw
[2006/01/16 18:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Subversion
[2009/03/12 08:55:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\TeamViewer
[2006/01/12 11:31:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\Thunderbird
[2007/02/24 13:53:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\tunebite
[2007/11/13 12:28:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Herbalife\Application Data\V-Safe
[2004/03/03 12:41:43 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\BMMTask.job

========== Purity Check ==========


< End of report >
OTL Extras logfile created on: 3/5/2010 8:34:28 AM - Run 1
OTL by OldTimer - Version 3.1.32.0 Folder = C:\Documents and Settings\Herbalife\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

367.00 Mb Total Physical Memory | 198.00 Mb Available Physical Memory | 54.00% Memory free
882.00 Mb Paging File | 635.00 Mb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 549 549 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15.69 Gb Total Space | 5.56 Gb Free Space | 35.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SOZU_JA
Current User Name: Herbalife
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"8000:UDP" = 8000:UDP:*:Disabled:Express Talk RTP Incoming Audio (UDP)
"8001:UDP" = 8001:UDP:*:Disabled:Express Talk RTP Incoming Audio (UDP)
"8002:UDP" = 8002:UDP:*:Disabled:Express Talk RTP Incoming Audio (UDP)
"8003:UDP" = 8003:UDP:*:Disabled:Express Talk RTP Incoming Audio (UDP)
"8004:UDP" = 8004:UDP:*:Disabled:Express Talk RTP Incoming Audio (UDP)
"8005:UDP" = 8005:UDP:*:Disabled:Express Talk RTP Incoming Audio (UDP)
"8006:UDP" = 8006:UDP:*:Disabled:Express Talk RTP Incoming Audio (UDP)
"8007:UDP" = 8007:UDP:*:Disabled:Express Talk RTP Incoming Audio (UDP)
"8008:UDP" = 8008:UDP:*:Disabled:Express Talk RTP Incoming Audio (UDP)
"8009:UDP" = 8009:UDP:*:Disabled:Express Talk RTP Incoming Audio (UDP)
"5070:UDP" = 5070:UDP:*:Disabled:Express Talk Sip Incoming Calls (UDP)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Trillian\trillian.exe" = C:\Program Files\Trillian\trillian.exe:*:Enabled:Trillian – File not found
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\BitComet\BitComet.exe" = C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client – (www.BitComet.com)
"C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule – (http://www.emule-project.net)
"C:\Program Files\Zend\ZendStudioClient-5.0.0\jre\bin\javaw.exe" = C:\Program Files\Zend\ZendStudioClient-5.0.0\jre\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary – File not found
"C:\Program Files\RealVNC\VNC4\winvnc4.exe" = C:\Program Files\RealVNC\VNC4\winvnc4.exe:*:Disabled:VNC Server Enterprise Edition for Win32 – File not found
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\ACSPMonitor\ASMonitor.exe" = C:\Program Files\ACSPMonitor\ASMonitor.exe:*:Enabled:System – File not found
"C:\WINDOWS\system32\ftp.exe" = C:\WINDOWS\system32\ftp.exe:*:Disabled:File Transfer Program – (Microsoft Corporation)
"D:\Setup.exe" = D:\Setup.exe:*:Enabled:Setup – File not found
"C:\Program Files\NCH Swift Sound\Talk\talk.exe" = C:\Program Files\NCH Swift Sound\Talk\talk.exe:*:Disabled:Express Talk – File not found
"C:\Program Files\TeamViewer\Version4\TeamViewer.exe" = C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Disabled:TeamViewer Remote Control Application – File not found
"C:\Program Files\CTP\CTPPhone\XPROCTP.exe" = C:\Program Files\CTP\CTPPhone\XPROCTP.exe:*:Disabled:XPROCTP – File not found
"C:\Program Files\Call The Planet\CTPSetup\XPROCTP.exe" = C:\Program Files\Call The Planet\CTPSetup\XPROCTP.exe:*:Disabled:XPROCTP – File not found
"C:\Program Files\SJphone 1.65\SJphone.exe" = C:\Program Files\SJphone 1.65\SJphone.exe:*:Enabled:SJphone 1.65 – File not found
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager – (Skype Technologies)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{061CE7E5-0115-4BB6-8381-47C602B98C7D}" = ActivePerl 5.10.0 Build 1003
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0CF4A4B6-64FA-4B6E-9130-EB4C970145BB}" = OpenOfficePluginSetup
"{12018183-866A-11D3-97DF-0000F8D8F2E9}" = Symantec pcAnywhere
"{1E34AB5C-B893-4EE9-82F3-F195978D009D}" = IBM Access Support - Local Content Pack
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = IBM ThinkPad Keyboard Customizer Utility
"{22B71A00-4DED-11D4-A5E5-0004AC564F43}" = IBM Access Connections
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 17
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B7B3B4A-AF8C-4671-A92E-3E7E9ABCB22B}" = IBM Rapid Restore PC Setup
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HydraVision
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{710C0BB2-FE39-484E-BB23-C9B96835A14A}" = Access IBM Message Center
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{93FD93BA-7C5A-4090-BF9D-F9EA3B9044C3}" = XP Themes
"{95120000-0052-0409-0000-0000000FF1CE}" = Microsoft Office Visio Viewer 2007
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
"{B5599ECB-DA72-43EE-8A30-2C80396FF8BB}" = Access IBM
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}" = QuickTime
"{C2AA63A0-27E0-458B-862A-BEC09DEA5286}" = TortoiseSVN
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF44C7A5-5705-41E4-BE84-A9A42977AB05}" = alm
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D133C77C-2AE2-4E77-903D-1B8C205112D5}" = FixWindowsUpdate
"{D1AE6D4D-C37A-487d-83D8-C333125B2459}" = HP Photosmart and Deskjet 7.0 Software
"{DE4847A9-E86B-4BBB-B991-58C5ACA4FA04}" = Diskeeper Professional Edition
"{EA664480-3844-11D5-8C25-444553540000}" = IBM TrackPoint Accessibility Features
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1F721BF-040C-4096-988A-1DB01EB73B0C}" = TPNala Wallpaper
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Access IBM Tools" = Access IBM Tools
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems AC'97 Modem
"Ask Toolbar_is1" = Foxit Toolbar
"Aspell English Dictionary_is1" = Aspell English Dictionary-0.50-2
"ATI Display Driver" = ATI Display Driver
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BitComet" = BitComet 0.60
"CCleaner" = CCleaner (remove only)
"EasyEject Utility" = IBM ThinkPad EasyEject Utility
"eMule" = eMule
"ffdshow" = ffdshow
"FileZilla Client" = FileZilla Client [removed]
"Foxit Reader" = Foxit Reader
"GNU Aspell_is1" = GNU Aspell 0.50-3
"GTK 2.0" = GTK+ Runtime 2.14.7 rev a (remove only)
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}" = QuickTime
"IrfanView" = IrfanView (remove only)
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Magic ISO Maker v5.4 (build 0251)" = Magic ISO Maker v5.4 (build 0251)
"MagicDisc 2.7.105" = MagicDisc 2.7.105
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Micro Solutions" = Backpack Driver
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.15)" = Mozilla Firefox (3.0.15)
"Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)
"Notepad++" = Notepad++
"oggcodecs" = oggcodecs 0.69.8924
"Pidgin" = Pidgin
"Power Features" = IBM ThinkPad Battery MaxiMiser and Power Management Features
"Power Management Driver" = ThinkPad Power Management Driver
"Presentation Director" = IBM ThinkPad Presentation Director
"RealPlayer 6.0" = RealPlayer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"ThinkPad Configuration" = IBM ThinkPad Configuration
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"ThinkPadSoftwareInstaller" = ThinkPad Software Installer
"TrackPoint" = IBM TrackPoint Support
"Tweak UI 2.10" = Tweak UI
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"OANDA FXNews" = OANDA FXNews
"Trader Workstation" = Trader Workstation
"TWS Demo" = TWS Demo
"WinDirStat" = WinDirStat 1.1.2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/21/2009 9:53:19 AM | Computer Name = SOZU_JA | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module askbar.dll, version 4.1.0.5, fault address 0x000060c9.

Error - 10/21/2009 9:53:27 AM | Computer Name = SOZU_JA | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module askbar.dll, version 4.1.0.5, fault address 0x000060c9.

Error - 11/2/2009 9:56:41 AM | Computer Name = SOZU_JA | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module askbar.dll, version 4.1.0.5, fault address 0x000060c9.

Error - 11/3/2009 12:55:41 PM | Computer Name = SOZU_JA | Source = Application Error | ID = 1000
Description = Faulting application pidgin.exe, version 2.5.8.0, faulting module
msvcrt.dll, version 7.0.2600.5512, fault address 0x000378c0.

Error - 11/11/2009 5:49:02 PM | Computer Name = SOZU_JA | Source = MsiInstaller | ID = 11404
Description = Product: Business Plan Pro 2007 – Error 1404.Could not delete key
\Software\Classes\. System error . Verify that you have sufficient access to
that key, or contact your support personnel.

Error - 11/11/2009 5:49:23 PM | Computer Name = SOZU_JA | Source = MsiInstaller | ID = 11404
Description = Product: Business Plan Pro 2007 – Error 1404.Could not delete key
\Software\Classes\. System error . Verify that you have sufficient access to
that key, or contact your support personnel.

Error - 11/12/2009 11:47:09 AM | Computer Name = SOZU_JA | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module askbar.dll, version 4.1.0.5, fault address 0x000060c9.

Error - 11/12/2009 11:47:20 AM | Computer Name = SOZU_JA | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module askbar.dll, version 4.1.0.5, fault address 0x000060c9.

Error - 11/12/2009 11:47:36 AM | Computer Name = SOZU_JA | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module askbar.dll, version 4.1.0.5, fault address 0x000060c9.

Error - 2/11/2010 1:11:09 PM | Computer Name = SOZU_JA | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3576, faulting module
npswf32.dll, version 10.0.32.18, fault address 0x002e5c06.

[ System Events ]
Error - 3/3/2010 9:51:56 AM | Computer Name = SOZU_JA | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/3/2010 9:51:56 AM | Computer Name = SOZU_JA | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/3/2010 9:51:56 AM | Computer Name = SOZU_JA | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/3/2010 9:51:56 AM | Computer Name = SOZU_JA | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/3/2010 9:51:56 AM | Computer Name = SOZU_JA | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/3/2010 9:51:56 AM | Computer Name = SOZU_JA | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/3/2010 9:51:56 AM | Computer Name = SOZU_JA | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/3/2010 9:51:57 AM | Computer Name = SOZU_JA | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/3/2010 1:01:31 PM | Computer Name = SOZU_JA | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 3/5/2010 9:12:17 AM | Computer Name = SOZU_JA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.


< End of report >
Also, when I try to print again from Notepad++ this is the error: The application or DLL C:\WINDOWS\system32\printui.dll is not a valid Window image. Please check this against your installation diskett. OK
Hi elmkd, I see some autorun infections on this computer. Please list all the USB storage devices you have and which drive letter they are recognized by. Not sure if this will help the other problems but we'll remove this infection and go from there. Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI