This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC operating very slowly

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi..

Hoping you can help. I'm running a PC w/WinXP SP3. I have 2 Gb of RAM and a 350Gb HDD. My protection program is Computer Associates Security Suites. Yesterday the computer started running very slowly and it took several clicks of the mouse to get any files/programs to open. I have a CPU temp monitor which usually runs about 100F but was up as high as 140F most of the day. I ran my registry cleaner, scanned for viruses/spyware with my CA program and came up empty. I also ran my defrag program but nothing seemed to help. I downloaded and ran HJT, a log of which I am attaching for your review. One thing I DID notice was that my HP All-in-One printer seemed to be using a lot of CPU resources periodically in review on my Windows Task Manager even tho I wasn't using it. It is model PSC2210v. Any clues/thoughts will be appreciated

Thanks,

Tasman27 :pullhair:

StartupList report, 10/1/2008, 10:13:53 AM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP3 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16705)
* Using default options
==================================================

Running processes:

C:\WINNT1\System32\smss.exe
C:\WINNT1\system32\winlogon.exe
C:\WINNT1\system32\services.exe
C:\WINNT1\system32\lsass.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\system32\svchost.exe
C:\WINNT1\System32\svchost.exe
C:\Ahead\InCD\InCDsrv.exe
C:\WINNT1\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT1\system32\cisvc.exe
C:\WINNT1\System32\CTsvcCDA.exe
C:\WINNT1\System32\GEARSec.exe
C:\WINNT1\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINNT1\System32\svchost.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT1\System32\MsPMSPSv.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\Explorer.EXE
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\CA\CA Internet Security Suite\cctray\cctray.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINNT1\system32\ctfmon.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\K9 Filter\K9\K9.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINNT1\system32\cidaemon.exe
C:\WINNT1\System32\HPZipm12.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Jim Fanning.DAD\Start Menu\Programs\Startup]
Launch K9.lnk = C:\K9 Filter\K9\K9.exe

Shell folders Common Startup:
[C:\Documents and Settings\All Users.WINNT1\Start Menu\Programs\Startup]
hp psc 2000 Series.lnk = C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
hpoddt01.exe.lnk = ?

PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINNT1\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

cctray = "C:\CA\CA Internet Security Suite\cctray\cctray.exe"
CAVRID = "C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
cafw = C:\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
capfasem = C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
QOELOADER = "C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
HPDJ Taskbar Utility = C:\WINNT1\system32\spool\drivers\w32x86\3\hpztsb05.exe
IntelliPoint = "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
ATICCC = "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
SmartDefrag = "C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Weather = C:\Program Files\AWS\WeatherBug\Weather.exe 1
ctfmon.exe = C:\WINNT1\system32\ctfmon.exe

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[AutorunsDisabled]
iTunesHelper = "C:\iTunes\iTunesHelper.exe"
Picasa Media Detector = C:\Picasa2\PicasaMediaDetector.exe
QuickTime Task = "C:\quicktime\qttask.exe" -atboottime
Share-to-Web Namespace Daemon = C:\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

[OptionalComponents]
=

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

[CTStartup]
CTStartup = "C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE" /play

————————————————–

Shell & screensaver key from C:\WINNT1\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINNT1\System32\ALYSSA~1.SCR
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - (no file) - AutorunsDisabled
(no name) - (no file) - {02478D38-C3F9-4efb-9B51-7695ECA05670}
(no name) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Windows Desktop Search\dsWebAllow.dll - {2F85D76C-0569-466F-A488-493E6BD0E955}
(no name) - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - (no file) - {7E853D72-626A-48EC-A868-BA8D5E23E045}
(no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - (no file) - {911C4A8E-0F75-4B83-BEB9-02BDDF29D11E}
CA Toolbar Helper - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll - {FBF2401B-7447-4727-BE5D-C19B2075CA84}

————————————————–

Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
CAAntiSpywareScan_Daily as XXXXXXX at 3 17 AM.job
Microsoft_Hardware_Launch_IPoint_exe.job

————————————————–

Enumerating Download Program Files:

[YExplorer1_8US.CAB]
CODEBASE = http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
OSD = C:\WINNT1\Downloaded Program Files\YExplorer1_8US.CAB.osd

[Shockwave ActiveX Control]
InProcServer32 = C:\WINNT1\system32\macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab

[MSSecurityAdvisor Class]
InProcServer32 = C:\WINNT1\System32\mssecadv.dll
CODEBASE = http://download.microsoft.com/download/0/5…b?1083947424312

[Checkers Class]
InProcServer32 = C:\WINNT1\Downloaded Program Files\msgrchkr.dll
CODEBASE = http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

[Installation Support]
InProcServer32 = C:\Program Files\Yahoo!\Common\Yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\Yinsthelper.dll

[AppDLCtrl Class]
InProcServer32 = C:\WINNT1\Downloaded Program Files\appdl.dll
CODEBASE = http://download.howudodat.com/chatterbox/download/appdl.cab

[CSEQueryObject Object]
InProcServer32 = C:\WINNT1\Downloaded Program Files\SearchEngineQuery.dll
CODEBASE = http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll

[MUWebControl Class]
InProcServer32 = C:\WINNT1\system32\muweb.dll
CODEBASE = http://update.microsoft.com/microsoftupdat…b?1222224306093

[Windows Live Photo Upload Control]
InProcServer32 = C:\WINNT1\Downloaded Program Files\MsnPUpld.dll
CODEBASE = http://cid-79c15117386cc58a.spaces.live.co…ad/MsnPUpld.cab

[Get_ActiveX Control]
InProcServer32 = C:\WINNT1\DOWNLO~1\HPGETD~1.OCX
CODEBASE = https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx

[MSN Games - Installer]
InProcServer32 = C:\WINNT1\Downloaded Program Files\ZIntro.ocx
CODEBASE = http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

[MessengerStatsClient Class]
InProcServer32 = C:\WINNT1\Downloaded Program Files\MessengerStatsPAClient.dll
CODEBASE = http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab

[{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}]

[{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}]

[Shockwave Flash Object]
InProcServer32 = C:\WINNT1\system32\Macromed\Flash\Flash9c.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab

[WheelofFortune Object]
InProcServer32 = C:\WINNT1\Downloaded Program Files\WoF.ocx
CODEBASE = http://messenger.zone.msn.com/binary/WoF.cab57176.cab

[{E77C0D62-882A-456F-AD8F-7C6C9569B8C7}]

[McFreeScan Class]
InProcServer32 = C:\WINNT1\McAfee.com\FreeScan\mcfscan.dll
CODEBASE = http://download.mcafee.com/molbin/iss-loc/…319/mcfscan.cab

[PCPitstop Exam]
InProcServer32 = C:\WINNT1\Downloaded Program Files\pcpitstop2.dll
CODEBASE = http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll

————————————————–

Enumerating Winsock LSP files:

NameSpace #4: C:\Program Files\Bonjour\mdnsNSP.dll
Protocol #1: C:\WINNT1\system32\VetRedir.dll
Protocol #2: C:\WINNT1\system32\VetRedir.dll
Protocol #3: C:\WINNT1\system32\VetRedir.dll
Protocol #9: C:\WINNT1\system32\VetRedir.dll

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

WPDShServiceObj: C:\WINNT1\system32\WPDShServiceObj.dll
WebCheck: C:\WINNT1\system32\webcheck.dll

————————————————–
End of report, 11,202 bytes
Report generated in 0.422 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:16:53 AM, on 10/1/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINNT1\System32\smss.exe
C:\WINNT1\system32\winlogon.exe
C:\WINNT1\system32\services.exe
C:\WINNT1\system32\lsass.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\system32\svchost.exe
C:\WINNT1\System32\svchost.exe
C:\Ahead\InCD\InCDsrv.exe
C:\WINNT1\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT1\system32\cisvc.exe
C:\WINNT1\System32\CTsvcCDA.exe
C:\WINNT1\System32\GEARSec.exe
C:\WINNT1\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINNT1\System32\svchost.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT1\System32\MsPMSPSv.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\Explorer.EXE
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\CA\CA Internet Security Suite\cctray\cctray.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINNT1\system32\ctfmon.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\K9 Filter\K9\K9.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINNT1\system32\cidaemon.exe
C:\WINNT1\System32\HPZipm12.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts file is located at: C:\WINNT1\System32\drivers\etc\hosts
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {911C4A8E-0F75-4B83-BEB9-02BDDF29D11E} - (no file)
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: (no name) - {28BC2EC4-5EAD-45E1-9F9F-82CD5E293601} - (no file)
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [cctray] "C:\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafw] C:\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT1\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SmartDefrag] "C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT1\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: Launch K9.lnk = C:\K9 Filter\K9\K9.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222224306093
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-79c15117386cc58a.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…319/mcfscan.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: AutorunsDisabled - C:\WINNT1\
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT1\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT1\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT1\System32\CTsvcCDA.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT1\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINNT1\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT1\System32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - C:\ReaConverter 5.0 Pro\rcp_scheduler.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O24 - Desktop Component 0: (no name) - (no file)

–
End of file - 13234 bytes
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Sorry about the delay in responding :(

If you still need help, scan again with HijackThis, and "copy/paste" a new log file into this thread.

Then I will analyze your log and sort out a fix for you :)

Also please describe how your computer behaves at the moment.

I need to see another log from HijackThis.
  • Run Hijackthis.
  • Click on Open the Misc Tools section.
  • Next click on Open uninstall manager.
  • Press the Save list button.
  • Save the file to your desktop, with the default name of uninstall_list
  • Copy & Paste the entire contents of that file in your in your next post.
Thanks.
Hi JP!
Thanks for your response. While I seem to have fixed the slowness on some things, it still is slow on others ie Thunderbird, Firefox. I won't take up a lot of your time except to just check it for the most obvious causes and root them out. Thanks for your assistance in advance…..

Taz

Here's the new HJT log and below a copy of the uninstall log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:43:52 PM, on 10/15/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINNT1\System32\smss.exe
C:\WINNT1\system32\winlogon.exe
C:\WINNT1\system32\services.exe
C:\WINNT1\system32\lsass.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\system32\svchost.exe
C:\WINNT1\System32\svchost.exe
C:\Ahead\InCD\InCDsrv.exe
C:\WINNT1\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT1\system32\cisvc.exe
C:\WINNT1\System32\CTsvcCDA.exe
C:\WINNT1\System32\GEARSec.exe
C:\WINNT1\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINNT1\System32\HPZipm12.exe
C:\WINNT1\System32\svchost.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT1\System32\MsPMSPSv.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\Explorer.EXE
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\CA\CA Internet Security Suite\cctray\cctray.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\iTunes\iTunesHelper.exe
C:\WINNT1\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\K9 Filter\K9\K9.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\iPod\bin\iPodService.exe
C:\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT1\system32\cidaemon.exe
C:\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\WINNT1\system32\DllHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {911C4A8E-0F75-4B83-BEB9-02BDDF29D11E} - (no file)
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: (no name) - {28BC2EC4-5EAD-45E1-9F9F-82CD5E293601} - (no file)
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [cctray] "C:\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafw] C:\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT1\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SmartDefrag] "C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [QuickTime Task] "C:\quicktime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT1\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: Launch K9.lnk = C:\K9 Filter\K9\K9.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222224306093
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-79c15117386cc58a.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…319/mcfscan.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: AutorunsDisabled - C:\WINNT1\
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT1\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT1\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT1\System32\CTsvcCDA.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT1\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINNT1\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT1\System32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - C:\ReaConverter 5.0 Pro\rcp_scheduler.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O24 - Desktop Component 0: (no name) - (no file)

–
End of file - 14286 bytes

uninstall log:

Acoustica Effects Pack
Acoustica Mixcraft 3.1
Acoustica MP3 CD Burner
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 8.1.2
Adobe Shockwave Player
Advanced WindowsCare Personal
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
Avanquest update
Bonjour
CA Anti-Spyware
CA Anti-Virus
CA Internet Security Suite
CA Pest Patrol Realtime Protection
CA Website Inspector
CCleaner (remove only)
CCScore
DMI Browse
Driver Genius Professional Edition
DriverAgent by TouchStone Software
ESSBrwr
ESSCDBK
ESScore
ESSCT
ESSEMAIL
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSTOOLS
ESSvpaht
ESSvpot
Free Window Registry Repair
FuzzyLogic4
HijackThis 2.0.2
HLPIndex
HLPSFO
Hotfix for Windows Internet Explorer 7 (KB947864)
HP Print Diagnostic Utility
HP Update
InfoView
Intel® Network Connections [removed]
i-Speeder
iTunes
K9
KSU
Legacy 6.0
LimeWire 4.18.3
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft Office Converter Pack
Microsoft Silverlight
MobileMe Control Panel
Motorola Driver Installation 3.4.0
Motorola Phone Tools
Mozilla Firefox (3.0.3)
Mozilla Thunderbird (2.0.0.17)
MSI Live Update 3
MyHeritage Family Tree Builder
Notifier
OfotoXMI
OTtBP
OTtBPSDK
PC Alert 4
PC Pitstop Optimize2 2.0
Personal Ancestral File Companion 5.2
Picasa 2
QuickTime
ReaConverter 5.0 Pro
RealPlayer
Safari
Security Task Manager 1.7f
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
SFR
SFR2
SHASTA
Shredder (3.0b1pre)
SKIN0001
SKINXSDK
Skype™ 3.8
Smart Defrag 1.0
TweakNow RegCleaner Standard
Virtual Earth 3D (Beta)
VPRINTOL
WeatherBug
WebEx
Winamp
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows XP Service Pack 3
WIRELESS
WMIinfo
Yahoo! Browser Services
Yahoo! Messenger
Yahoo! Toolbar
Hi :)

LimeWire
You have LimeWire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


You appear to have Weatherbug installed. It is considered adware as it displays pop-ups and is used to install My Search Toolbar. A safe alternative to WeatherBug is Weatherpulse. I recommend you uninstall WeatherBug for the above reasons. You can do this by clicking Start >> Control Panel >> Add/Remove Programs and clicking remove by the WeatherBug entry.

Have you or an Administrator set any restrictions for Internet Explorer or the Control Panel?

Let's get some detailed system information, check for Viruses and then we'll see what we can clean up.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

This tool will scan your system and provide some good information for us, but won't make any changes.
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Thanks.
JP,

I've done what you indicated in your last post. Here's the log from RSIT. Hope to hear from you soon….

Taz


Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-16 09:53:49
Microsoft Windows XP Professional Service Pack 3
System drive C: has 222 GB (78%) free of 286 GB
Total RAM: 2047 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:54:30 AM, on 10/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINNT1\System32\smss.exe
C:\WINNT1\system32\winlogon.exe
C:\WINNT1\system32\services.exe
C:\WINNT1\system32\lsass.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\system32\svchost.exe
C:\WINNT1\System32\svchost.exe
C:\Ahead\InCD\InCDsrv.exe
C:\WINNT1\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT1\system32\cisvc.exe
C:\WINNT1\System32\CTsvcCDA.exe
C:\WINNT1\System32\GEARSec.exe
C:\WINNT1\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINNT1\System32\HPZipm12.exe
C:\WINNT1\System32\svchost.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT1\System32\MsPMSPSv.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\Explorer.EXE
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\CA\CA Internet Security Suite\cctray\cctray.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\iTunes\iTunesHelper.exe
C:\WINNT1\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\K9 Filter\K9\K9.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\iPod\bin\iPodService.exe
C:\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT1\system32\cidaemon.exe
C:\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\WINNT1\system32\DllHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\Weatherpulse\Weather Pulse\weatherpulse.exe
C:\Documents and Settings\Jim Fanning.DAD\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Jim Fanning.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {911C4A8E-0F75-4B83-BEB9-02BDDF29D11E} - (no file)
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: (no name) - {28BC2EC4-5EAD-45E1-9F9F-82CD5E293601} - (no file)
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [cctray] "C:\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafw] C:\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT1\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SmartDefrag] "C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [QuickTime Task] "C:\quicktime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT1\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: Launch K9.lnk = C:\K9 Filter\K9\K9.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe


O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222224306093
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-79c15117386cc58a.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…319/mcfscan.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: AutorunsDisabled - C:\WINNT1\
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT1\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT1\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT1\System32\CTsvcCDA.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT1\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINNT1\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT1\System32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - C:\ReaConverter 5.0 Pro\rcp_scheduler.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O24 - Desktop Component 0: (no name) - (no file)

–
End of file - 13728 bytes

======Scheduled tasks folder======

C:\WINNT1\tasks\AppleSoftwareUpdate.job
C:\WINNT1\tasks\CAAntiSpywareScan_Daily as Jim Fanning at 3 17 AM.job
C:\WINNT1\tasks\Microsoft_Hardware_Launch_IPoint_exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F85D76C-0569-466F-A488-493E6BD0E955}]
dsWebAllowBHO Class - C:\Program Files\Windows Desktop Search\dsWebAllow.dll [2006-11-21 265504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 501400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-12-14 392240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{911C4A8E-0F75-4B83-BEB9-02BDDF29D11E}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FBF2401B-7447-4727-BE5D-C19B2075CA84}]
CA Toolbar Helper - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll [2008-07-23 275896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{28BC2EC4-5EAD-45E1-9F9F-82CD5E293601}
{10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - CA Toolbar - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll [2008-07-23 275896]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"cctray"=C:\CA\CA Internet Security Suite\cctray\cctray.exe [2008-10-10 247024]
"CAVRID"=C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe [2008-09-08 234736]
"cafw"=C:\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe [2008-08-28 771312]
"capfasem"=C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe [2008-08-28 173296]
"QOELOADER"=C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe [2008-06-17 14088]
"HPDJ Taskbar Utility"=C:\WINNT1\system32\spool\drivers\w32x86\3\hpztsb05.exe [2002-04-22 188416]
"IntelliPoint"=c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 1406024]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]
"SmartDefrag"=C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2008-09-08 1965296]
"QuickTime Task"=C:\quicktime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\iTunes\iTunesHelper.exe [2008-10-01 289576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINNT1\system32\ctfmon.exe [2008-04-13 15360]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184]
"Yahoo! Pager"=C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe [2007-08-30 4670704]
"Weather Pulse"= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jim Fanning.DAD^Start Menu^Programs^Startup^HotSync Manager.lnk]
C:\PROGRA~1\Palm\HOTSYNC.EXE [2004-04-13 299008]

C:\Documents and Settings\All Users.WINNT1\Start Menu\Programs\Startup
hp psc 2000 Series.lnk - C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
hpoddt01.exe.lnk - C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
PC Alert 4.lnk - C:\Program Files\MSI\PC Alert 4\PCAlert4.exe

C:\Documents and Settings\Jim Fanning.DAD\Start Menu\Programs\Startup
Launch K9.lnk - C:\K9 Filter\K9\K9.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINNT1\system32\Ati2evxx.dll [2006-05-03 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AutorunsDisabled]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PFW]
C:\WINNT1\system32\UmxWnp.Dll [2007-05-18 79368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINNT1\system32\WgaLogon.dll [2007-04-10 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINNT1\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"=C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\shellexecutehook.dll [2007-10-23 79408]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-11-21 233472]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"=C:\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll [2008-07-23 1377720]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NBF]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nbf.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sglfb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=5F000000
"NoViewOnDrive"=0
"NoDesktopCleanupWizard"=1
"NoDriveAutoRun"=FFFFFF03
"NoStartMenuMyMusic"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDriveTypeAutoRun"=
"NoResolveSearch"=
"EnableShellExecuteHooks"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Support.com\bin\tgcmd.exe"="C:\Program Files\Support.com\bin\tgcmd.exe:*:Enabled:Support.com Scheduler and Command Dispatcher"
"C:\WINNT1\kdx\khost.exe"="C:\WINNT1\kdx\khost.exe:*:Enabled:Secure Delivery Plug-In"
"C:\AresLite\Ares Lite Edition\AresLite.exe"="C:\AresLite\Ares Lite Edition\AresLite.exe:*:Enabled:Ares Lite Edition"
"C:\ICQ\ICQ\Icq.exe"="C:\ICQ\ICQ\Icq.exe:*:Enabled:ICQ"
"C:\Mozilla\mozilla.exe"="C:\Mozilla\mozilla.exe:*:Enabled:Mozilla"
"C:\ACT\ActUpdt.exe"="C:\ACT\ActUpdt.exe:*:Enabled:ACT! Update"
"C:\Limewire\LimeWire.exe"="C:\Limewire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Java\j2re1.4.1_03\bin\javaw.exe"="C:\Program Files\Java\j2re1.4.1_03\bin\javaw.exe:*:Enabled:javaw"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\WINNT1\system32\dpvsetup.exe"="C:\WINNT1\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINNT1\system32\rundll32.exe"="C:\WINNT1\system32\rundll32.exe:*:Disabled:Run a DLL as an App"
"C:\Program Files\SmartFTP\SmartFTP.exe"="C:\Program Files\SmartFTP\SmartFTP.exe:*:Enabled:SmartFTP"
"C:\WS_FTPLE\WS_FTP95.exe"="C:\WS_FTPLE\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"="C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"
"C:\RealPlayer\realplay.exe"="C:\RealPlayer\realplay.exe:*:Disabled:RealPlayer"
"C:\WINNT1\system32\sessmgr.exe"="C:\WINNT1\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\StubInstaller.exe"="C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Disabled:AOLTopSpeed"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Disabled:AOLTsMon"
"C:\Program Files\MSI\i-Speeder\i-Speeder.exe"="C:\Program Files\MSI\i-Speeder\i-Speeder.exe:*:Enabled:i-Speeder"
"C:\Ahead\Nero ShowTime\ShowTime.exe"="C:\Ahead\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime"
"C:\Program Files\Common Files\AOL\1152289767\ee\aim6.exe"="C:\Program Files\Common Files\AOL\1152289767\ee\aim6.exe:*:Enabled:AIM"
"C:\Program Files\Common Files\AOL\1152289767\ee\aolsoftware.exe"="C:\Program Files\Common Files\AOL\1152289767\ee\aolsoftware.exe:*:Disabled:AOL Services"
"C:\Program Files\Conference\Conference.dll"="C:\Program Files\Conference\Conference.dll:*:Disabled:Audio/Video Conference by KIOSK Team"
"C:\DAP\DAP\DAP.exe"="C:\DAP\DAP\DAP.exe:*:Disabled:Download Accelerator Plus"
"C:\Ares\Ares.exe"="C:\Ares\Ares.exe:*:Enabled:Ares"
"C:\Trillian\trillian.exe"="C:\Trillian\trillian.exe:*:Enabled:Trillian"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\AresLite\Ares Lite Edition\Ares.exe"="C:\AresLite\Ares Lite Edition\Ares.exe:*:Disabled:Ares"
"C:\NewsProxy\NewsProxy.exe"="C:\NewsProxy\NewsProxy.exe:*:Enabled:NewsProxy"
"C:\Documents and Settings\Jim Fanning.DAD\Desktop\NewsProxy.exe"="C:\Documents and Settings\Jim Fanning.DAD\Desktop\NewsProxy.exe:*:Enabled:NewsProxy"
"C:\AIM\aim.exe"="C:\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\MotoBlade\MotoBlade.exe"="C:\MotoBlade\MotoBlade.exe:*:Enabled:MotoBlade"
"C:\Documents and Settings\Jim Fanning.DAD\Local Settings\Temp\MotoBlade.exe"="C:\Documents and Settings\Jim Fanning.DAD\Local Settings\Temp\MotoBlade.exe:*:Enabled:MotoBlade"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"="C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater"
"C:\WINNT1\system32\ftp.exe"="C:\WINNT1\system32\ftp.exe:*:Enabled:File Transfer Program"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\iTunes\iTunes.exe"="C:\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\AIM\aim.exe"="C:\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd325074-aa95-11dc-b772-000c761889a9}]
shell\AutoRun\command - F:\setupSNK.exe


======List of files/folders created in the last 1 months======

2008-10-16 09:46:54 —-D—- C:\Documents and Settings\Jim Fanning.DAD\Application Data\Weather Pulse
2008-10-16 09:45:05 —-D—- C:\Weatherpulse
2008-10-15 15:48:29 —-D—- C:\WINNT1\LastGood
2008-10-15 03:06:24 —-HDC—- C:\WINNT1\$NtUninstallKB956803$
2008-10-15 03:05:50 —-HDC—- C:\WINNT1\$NtUninstallKB956391$
2008-10-15 03:05:24 —-HDC—- C:\WINNT1\$NtUninstallKB957095$
2008-10-15 03:03:10 —-HDC—- C:\WINNT1\$NtUninstallKB954211$
2008-10-15 03:02:47 —-A—- C:\WINNT1\imsins.BAK
2008-10-15 03:02:27 —-N—- C:\WINNT1\system32\spmsg.dll
2008-10-15 03:02:24 —-HDC—- C:\WINNT1\$NtUninstallKB956841$
2008-10-08 09:43:33 —-D—- C:\Motorola
2008-10-07 22:39:12 —-D—- C:\99a6ab0f464e23602880
2008-10-07 14:35:48 —-D—- C:\d138d89e0227edb14a23
2008-10-06 20:35:34 —-D—- C:\7e9a25158c5c409217d711cd60301a
2008-10-06 20:29:53 —-D—- C:\Program Files\Avanquest update
2008-10-06 20:25:35 —-D—- C:\Ringtones
2008-10-05 09:18:52 —-D—- C:\Documents and Settings\All Users.WINNT1\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-01 23:04:34 —-D—- C:\Process Explorer
2008-10-01 10:27:19 —-D—- C:\rsit
2008-10-01 09:01:42 —-D—- C:\Driver Backup 10-1-2008-9056
2008-10-01 08:35:51 —-D—- C:\Program Files\Trend Micro
2008-09-30 15:27:36 —-A—- C:\WINNT1\system32\WmiConf.txt
2008-09-30 15:18:14 —-D—- C:\Program Files\Microsoft IntelliPoint
2008-09-30 14:25:46 —-A—- C:\WINNT1\system32\CSVer.dll
2008-09-30 14:20:52 —-D—- C:\Intel
2008-09-30 13:49:07 —-D—- C:\ATI
2008-09-30 13:22:55 —-D—- C:\Driver Download
2008-09-30 12:15:23 —-D—- C:\Driver-Soft

======List of files/folders modified in the last 1 months======

2008-10-16 09:53:36 —-D—- C:\WINNT1\Prefetch
2008-10-16 09:50:52 —-AD—- C:\WINNT1\Temp
2008-10-16 09:41:59 —-D—- C:\WINNT1\system32
2008-10-16 09:41:39 —-HD—- C:\Documents and Settings\Jim Fanning.DAD\Application Data\yahoo!
2008-10-16 09:41:08 —-D—- C:\Program Files\Yahoo!
2008-10-16 09:35:50 —-D—- C:\Program Files\Mozilla Firefox
2008-10-16 09:33:56 —-D—- C:\Documents and Settings\Jim Fanning.DAD\Application Data\CallingID
2008-10-16 05:44:05 —-D—- C:\WINNT1
2008-10-15 20:31:42 —-D—- C:\Fanning Family
2008-10-15 15:52:53 —-D—- C:\WINNT1\CAVTemp
2008-10-15 15:50:49 —-AD—- C:\WINNT1\Debug
2008-10-15 15:50:38 —-HD—- C:\WINNT1\inf
2008-10-15 15:50:24 —-AD—- C:\WINNT1\system32\CatRoot
2008-10-15 15:50:02 —-RASHDC—- C:\WINNT1\system32\dllcache
2008-10-15 15:48:24 —-D—- C:\WINNT1\system32\CatRoot2
2008-10-15 13:52:19 —-D—- C:\Program Files\Mozilla Thunderbird
2008-10-15 13:30:06 —-A—- C:\WINNT1\SchedLgU.Txt
2008-10-15 03:06:29 —-D—- C:\WINNT1\system32\drivers
2008-10-15 03:06:11 —-HD—- C:\WINNT1\$hf_mig$
2008-10-15 03:04:42 —-AD—- C:\Program Files\Internet Explorer
2008-10-12 03:50:16 —-D—- C:\Legacy
2008-10-11 11:35:48 —-A—- C:\caisslog.txt
2008-10-08 09:45:20 —-SHD—- C:\WINNT1\Installer
2008-10-08 09:43:51 —-D—- C:\MotoBlade
2008-10-08 09:35:46 —-D—- C:\WINNT1\system32\Logfiles
2008-10-07 14:19:40 —-A—- C:\WINNT1\system32\MRT.exe
2008-10-07 11:11:07 —-D—- C:\Documents and Settings\Jim Fanning.DAD\Application Data\Skype
2008-10-07 11:08:19 —-SHD—- C:\Config.Msi
2008-10-07 11:07:11 —-D—- C:\Skype
2008-10-06 21:12:39 —-D—- C:\Program Files\Motorola Phone Tools
2008-10-06 20:40:36 —-D—- C:\WINNT1\WinSxS
2008-10-06 20:40:07 —-AD—- C:\Program Files\Common Files\Microsoft Shared
2008-10-06 20:39:32 —-DC—- C:\WINNT1\system32\DRVSTORE
2008-10-06 20:29:53 —-AD—- C:\Program Files
2008-10-06 16:21:08 —-D—- C:\Documents and Settings\All Users.WINNT1\Application Data\Yahoo!
2008-10-06 16:19:41 —-A—- C:\YServer.txt
2008-10-05 09:25:11 —-D—- C:\iTunes
2008-10-05 09:18:54 —-D—- C:\iPod
2008-10-04 01:29:01 —-D—- C:\Trillian
2008-10-03 12:41:15 —-A—- C:\WINNT1\system32\ieframe.dll
2008-10-01 23:57:03 —-ASH—- C:\boot.ini
2008-10-01 23:57:03 —-A—- C:\WINNT1\win.ini
2008-10-01 23:57:03 —-A—- C:\WINNT1\system.ini
2008-10-01 22:51:37 —-D—- C:\Documents and Settings\All Users.WINNT1\Application Data\PCPitstop
2008-10-01 22:48:45 —-SD—- C:\WINNT1\Downloaded Program Files
2008-10-01 03:11:30 —-D—- C:\Program Files\Messenger
2008-10-01 03:02:59 —-D—- C:\Program Files\Microsoft Silverlight
2008-09-30 21:45:59 —-AD—- C:\WINNT1\twain_32
2008-09-30 17:07:32 —-D—- C:\Program Files\ATI Technologies
2008-09-30 15:37:58 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-30 15:31:58 —-AD—- C:\Program Files\Intel
2008-09-30 15:31:42 —-A—- C:\WINNT1\system32\PerfStringBackup.INI
2008-09-30 15:30:36 —-D—- C:\WINNT1\system32\ReinstallBackups
2008-09-30 15:28:28 —-A—- C:\WINNT1\wininit.ini
2008-09-30 15:23:30 —-SD—- C:\WINNT1\Tasks
2008-09-30 15:19:25 —-RSD—- C:\WINNT1\Fonts
2008-09-29 22:14:56 —-D—- C:\CCleaner
2008-09-29 21:57:07 —-D—- C:\Documents and Settings\Jim Fanning.DAD\Application Data\wsInspector
2008-09-24 16:26:04 —-A—- C:\WINNT1\SIERRA.INI
2008-09-23 01:55:18 —-D—- C:\Job Resume
2008-09-22 13:02:28 —-A—- C:\WINNT1\MyHeritage.INI
2008-09-20 09:54:38 —-D—- C:\FTW
2008-09-20 09:54:38 —-A—- C:\WINNT1\MPLAYER.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AVG Anti-Spyware Driver;AVG Anti-Spyware Driver; \??\C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.sys []
R1 AvgAsCln;AVG Anti-Spyware Clean Driver; C:\WINNT1\System32\DRIVERS\AvgAsCln.sys [2006-09-05 3968]
R1 bc_ip_f;BC_IP_Filter; C:\WINNT1\system32\drivers\bc_ip_f.sys [2007-12-11 28776]
R1 bc_pat_f;BC_PAT_Filter; C:\WINNT1\system32\drivers\bc_pat_f.sys [2007-12-11 13544]
R1 bc_prt_f;BC_Protocol_Filter; C:\WINNT1\system32\drivers\bc_prt_f.sys [2007-12-11 17512]
R1 bc_tdi_f;BC_TDI_Filter; C:\WINNT1\system32\drivers\bc_tdi_f.sys [2007-12-11 22376]
R1 bcftdi;BCFTDI; C:\WINNT1\system32\drivers\bcftdi.sys [2007-12-10 62824]
R1 InCDPass;InCDPass; C:\WINNT1\System32\DRIVERS\InCDPass.sys [2006-03-23 29440]
R1 intelppm;Intel Processor Driver; C:\WINNT1\System32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 KmxAgent;KmxAgent; C:\WINNT1\System32\DRIVERS\kmxagent.sys [2008-06-24 63504]
R1 KmxFile;KmxFile; C:\WINNT1\System32\DRIVERS\KmxFile.sys [2008-06-24 45584]
R1 KmxFw;KmxFw; C:\WINNT1\System32\DRIVERS\kmxfw.sys [2008-06-24 115216]
R1 VETEFILE;VET File Scan Engine; C:\WINNT1\system32\drivers\VETEFILE.sys [2008-06-17 880560]
R1 VETFDDNT;VET Floppy Boot Sector Monitor; C:\WINNT1\system32\drivers\VETFDDNT.sys [2008-09-08 21488]
R1 VET-FILT;VET File System Filter; C:\WINNT1\system32\drivers\VET-FILT.sys [2008-09-08 26352]
R1 VETMONNT;VET File Monitor; C:\WINNT1\system32\drivers\VETMONNT.sys [2008-09-08 32240]
R1 VET-REC;VET File System Recognizer; C:\WINNT1\system32\drivers\VET-REC.sys [2008-09-08 21104]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINNT1\System32\drivers\ws2ifsl.sys [2002-08-29 12032]
R2 Aspi32;Aspi32; C:\WINNT1\system32\drivers\Aspi32.sys [2002-08-14 17005]
R2 ATNT40K;ActiveTouch NT Appsharing Driver; C:\WINNT1\SYSTEM32\DRIVERS\ATNT40K.SYS [2007-09-23 51304]
R2 BBFat.VxD;BlueBird DSP API; C:\WINNT1\System32\Drivers\BBFat.sys [2002-12-10 6400]
R2 BCMNTIO;BCMNTIO; \??\C:\CheckIt\DIAGNO~1\BCMNTIO.sys []
R2 KmxCF;KmxCF; C:\WINNT1\System32\DRIVERS\KmxCF.sys [2008-06-24 134648]
R2 KmxSbx;KmxSbx; C:\WINNT1\System32\DRIVERS\KmxSbx.sys [2008-06-24 66576]
R2 MAPMEM;MAPMEM; \??\C:\CheckIt\DIAGNO~1\MAPMEM.sys []
R2 PfModNT;PfModNT; \??\C:\WINNT1\system32\drivers\PfModNT.sys []
R3 ati2mtag;ati2mtag; C:\WINNT1\system32\DRIVERS\ati2mtag.sys [2006-05-03 1540608]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINNT1\System32\drivers\ctac32k.sys [2002-07-19 127948]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINNT1\system32\drivers\ctaud2k.sys [2002-07-19 837548]
R3 ctprxy2k;Creative Proxy Driver; C:\WINNT1\System32\drivers\ctprxy2k.sys [2002-07-19 11068]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINNT1\System32\drivers\ctsfm2k.sys [2002-07-19 213860]
R3 E100B;Intel® PRO Network Connection Driver; C:\WINNT1\System32\DRIVERS\e100b325.sys [2007-11-16 165496]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINNT1\System32\drivers\emupia2k.sys [2002-07-19 156604]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINNT1\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINNT1\system32\drivers\ha10kx2k.sys [2002-07-24 998004]
R3 hidusb;Microsoft HID Class Driver; C:\WINNT1\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINNT1\System32\DRIVERS\HPZid412.sys [2005-10-21 49920]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINNT1\System32\DRIVERS\HPZipr12.sys [2005-10-21 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINNT1\System32\DRIVERS\HPZius12.sys [2005-10-21 21568]
R3 KmxCfg;KmxCfg; C:\WINNT1\System32\DRIVERS\kmxcfg.sys [2008-06-24 88816]
R3 mouhid;Mouse HID Driver; C:\WINNT1\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 ossrv;Creative OS Services Driver; C:\WINNT1\system32\drivers\ctoss2k.sys [2002-07-19 195432]
R3 PCAlertDriver;PCAlertDriver; \??\C:\Program Files\MSI\PC Alert 4\NTGLM7X.sys []
R3 Pcouffin;Low level access layer for CD devices; C:\WINNT1\System32\Drivers\Pcouffin.sys [2006-08-10 47360]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINNT1\system32\DRIVERS\point32.sys [2008-06-10 31048]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINNT1\System32\Drivers\RootMdm.sys [2002-08-29 5888]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINNT1\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINNT1\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINNT1\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINNT1\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINNT1\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINNT1\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINNT1\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VETEBOOT;VET Boot Scan Engine; C:\WINNT1\system32\drivers\VETEBOOT.sys [2008-06-17 108368]
R4 InCDfs;InCD File System; C:\WINNT1\system32\drivers\InCDfs.sys [2006-03-23 102016]
S1 incdrm;InCD Reader; C:\WINNT1\system32\drivers\incdrm.sys [2006-03-23 33536]
S1 tga;tga; C:\WINNT1\system32\drivers\tga.sys []
S3 Bcfilter;Jetico Personal Firewall Network Monitor; C:\WINNT1\system32\DRIVERS\bcfilter.sys []
S3 BcfilterMP;BcfilterMP; C:\WINNT1\system32\DRIVERS\bcfilter.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINNT1\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 CoolerXPDriver;CoolerXPDriver; \??\C:\MSI\NTCooler.sys []
S3 ctljystk;Creative SBLive! Gameport; C:\WINNT1\System32\DRIVERS\ctljystk.sys [2001-08-17 3712]
S3 DMIBDriv;DMIBDriv; \??\C:\MSI\NTGLM7X.sys []
S3 motmodem;Motorola USB CDC ACM Driver; C:\WINNT1\system32\DRIVERS\motmodem.sys [2007-06-18 23680]
S3 MotoSwitchService;MotoSwitch Service; C:\WINNT1\system32\DRIVERS\motswch.sys []
S3 MPE;BDA MPE Filter; C:\WINNT1\System32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINNT1\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINNT1\System32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 P2k;Motorola USB Device; C:\WINNT1\system32\DRIVERS\P2k.sys [2006-07-28 40960]
S3 RapFile;RapFile; \??\C:\WINNT1\system32\drivers\RapFile.sys []
S3 RapNet;RapNet; \??\C:\WINNT1\system32\drivers\RapNet.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINNT1\System32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINNT1\System32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TVICHW32;TVICHW32; \??\C:\WINNT1\system32\DRIVERS\TVICHW32.SYS []
S3 usbhub20;USB 2.0 Root Hub Support; C:\WINNT1\System32\DRIVERS\usbhub20.sys [2002-04-17 49392]
S3 usbser;Motorola USB Modem Driver; C:\WINNT1\system32\DRIVERS\usbser.sys [2008-04-13 26112]
S3 VIAudio;VIA AC'97 Audio Controller (WDM); C:\WINNT1\system32\drivers\viaudios.sys [2003-06-18 91520]
S3 wanatw;WAN Miniport (ATW); C:\WINNT1\System32\DRIVERS\wanatw4.sys [2003-01-10 33588]
S3 Wdf01000;Wdf01000; C:\WINNT1\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINNT1\System32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINNT1\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINNT1\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 aic116x;aic116x; C:\WINNT1\system32\drivers\aic116x.sys []
S4 ami0nt;ami0nt; C:\WINNT1\system32\drivers\ami0nt.sys []
S4 BusLogic;BusLogic; C:\WINNT1\system32\drivers\BusLogic.sys []
S4 cpqarry2;cpqarry2; C:\WINNT1\system32\drivers\cpqarry2.sys []
S4 cpqfcalm;cpqfcalm; C:\WINNT1\system32\drivers\cpqfcalm.sys []
S4 cpqfws2e;cpqfws2e; C:\WINNT1\system32\drivers\cpqfws2e.sys []
S4 deckzpsx;deckzpsx; C:\WINNT1\system32\drivers\deckzpsx.sys []
S4 EFS;EFS; C:\WINNT1\system32\drivers\EFS.sys []
S4 Fd16_700;Fd16_700; C:\WINNT1\system32\drivers\Fd16_700.sys []
S4 fireport;fireport; C:\WINNT1\system32\drivers\fireport.sys []
S4 flashpnt;flashpnt; C:\WINNT1\system32\drivers\flashpnt.sys []
S4 IntelIde;IntelIde; C:\WINNT1\system32\drivers\IntelIde.sys []
S4 ipsraidn;ipsraidn; C:\WINNT1\system32\drivers\ipsraidn.sys []
S4 lp6nds35;lp6nds35; C:\WINNT1\system32\drivers\lp6nds35.sys []
S4 Ncrc710;Ncrc710; C:\WINNT1\system32\drivers\Ncrc710.sys []
S4 Parallel;Parallel class driver; C:\WINNT1\System32\DRIVERS\parallel.sys []
S4 ql2100;ql2100; C:\WINNT1\system32\drivers\ql2100.sys []
S4 ultra66;ultra66; C:\WINNT1\system32\drivers\ultra66.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINNT1\system32\Ati2evxx.exe [2006-05-03 413696]
R2 AVG Anti-Spyware Guard;AVG Anti-Spyware Guard; C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe [2007-10-23 312880]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 CAISafe;CAISafe; C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe [2008-06-17 144696]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINNT1\System32\CTsvcCDA.exe [1999-12-13 44032]
R2 GEARSecurity;GEARSecurity; C:\WINNT1\System32\GEARSec.exe [2003-11-11 53248]
R2 InCDsrv;InCD Helper; C:\Ahead\InCD\InCDsrv.exe [2006-03-23 880128]
R2 ITMRTSVC;CA Pest Patrol Realtime Protection Service; C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe [2007-09-26 283912]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINNT1\System32\HPZipm12.exe [2007-08-09 73728]
R2 UmxAgent;HIPS Event Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2008-01-21 1010192]
R2 UmxCfg;HIPS Configuration Interpreter; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2008-01-21 801296]
R2 UmxFwHlp;HIPS Firewall Helper; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe [2008-01-21 145936]
R2 UmxPol;HIPS Policy Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe [2008-06-24 281104]
R2 VETMSGNT;VET Message Service; C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe [2008-09-08 255216]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINNT1\System32\MsPMSPSv.exe [2000-06-26 53520]
R2 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
R3 CaCCProvSP;CaCCProvSP; C:\CA\CA Internet Security Suite\ccprovsp.exe [2008-10-10 214256]
R3 iPod Service;iPod Service; C:\iPod\bin\iPodService.exe [2008-10-01 536872]
R3 PPCtlPriv;PPCtlPriv; C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2008-09-08 185584]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S2 ATI Smart;ATI Smart; C:\WINNT1\system32\ati2sgag.exe [2006-05-03 520192]
S2 spupdsvc;Windows Service Pack Installer update service; C:\WINNT1\system32\spupdsvc.exe [2007-08-10 26488]
S3 aspnet_state;ASP.NET State Service; C:\WINNT1\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINNT1\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINNT1\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-03 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINNT1\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 KodakCCS;Kodak Camera Connection Software; C:\WINNT1\system32\drivers\KodakCCS.exe []
S3 rcp_service;ReaConverter scheduler service; C:\ReaConverter 5.0 Pro\rcp_scheduler.exe [2007-11-30 558592]
S3 UtilMan;Utility Manager; C:\WINNT1\System32\UtilMan.exe [2008-04-13 50176]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINNT1\system32\svchost.exe [2008-04-13 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINNT1\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

—————–EOF—————–
📎Kaspersky.txt
Hi :)

Open HijackThis. Hit Do A System Scan Only. Place a check next to the following items (if present):
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {911C4A8E-0F75-4B83-BEB9-02BDDF29D11E} - (no file)
O3 - Toolbar: (no name) - {28BC2EC4-5EAD-45E1-9F9F-82CD5E293601} - (no file)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} -
O20 - Winlogon Notify: AutorunsDisabled - C:\WINNT1\
O24 - Desktop Component 0: (no name) - (no file)


Close all browsers and windows except for HijackThis and click Fix Checked.


Please delete these two files:
C:\beatlesrevolver.exe
C:\beatlesrubbersoul.exe



I would recommend you empty your Junk folder from your mail.odyssy.net email account.

Do you know what these two folders are and can you empty the Junk/Trash folders?
C:\Program Files\Support.com\backup\Ju\Junk\
C:\Program Files\Support.com\backup\Tr\Trash\



Please post the info.txt log from RSIT, should be here:
C:\rsit\info.txt


Please download DirLook by jpshortstuff from one of the following mirrors:
Link 1
Link 2
Link 3
  • Double-click DirLook.exe to run it.
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the main textfield:

    C:\99a6ab0f464e23602880
    C:\d138d89e0227edb14a23
    C:\7e9a25158c5c409217d711cd60301a
  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\DirLook.txt)
Note: Scanning may take longer for large folders.

Please post a new HijackThis log as well in your next reply. Also, please give a detailed description of how your computer is running and behaving at the moment, listing any remaining problems.

Thanks.
JP…

Ok…….followed your instructions. I don't know what those folders were but I found them and deleted them. I think it might have been a backup from a Comcast remote support? I also deleted the Beatles files….they were in a zip file in the directory. Hope to hear from you soon. The HJT log is at the end of the email as is the RSIT log. The computer seems to be running better, however I seem to have issues opening icon from the desktop with the mouse. It takes several clicks to open them with the mouse set at med speed. Also Firefox is slow to open as is Thunderbird. In Fact T-Bird will take as many as 7-8 times to open before it can finally function and I can download mail. If I close it, it will basically repeat the issue. It reacts the same even if I disable the firewall. I'm not sure what is the cause of that.


Taz



Here is the dirLook log:

DirLook.exe v2.0 by jpshortstuff
Log created at 03:22 on 17/10/2008
==================================
Contents of "C:\99a6ab0f464e23602880"

—FOLDERS—

update (Created on 08/10/2008 at 03:39) d—–

—FILES—

kmdfcustom.dll (51680 bytes - created on 02/11/2006 at 12:22, modified on 02/11/2006 at 12:22) –a—
spmsg.dll (14640 bytes - created on 09/10/2006 at 02:51, modified on 09/10/2006 at 02:51) –a—
spuninst.exe (221488 bytes - created on 09/10/2006 at 02:51, modified on 09/10/2006 at 02:51) –a—
spupdsvc.exe (23856 bytes - created on 09/10/2006 at 02:51, modified on 09/10/2006 at 02:51) –a—
wdf01000.sys (492000 bytes - created on 02/11/2006 at 12:22, modified on 02/11/2006 at 12:22) –a—
wdfldr.sys (32224 bytes - created on 02/11/2006 at 12:22, modified on 02/11/2006 at 12:22) –a—

==================================
Contents of "C:\d138d89e0227edb14a23"

—FOLDERS—

update (Created on 07/10/2008 at 19:35) d—–

—FILES—

$shtdwn$.req (788 bytes - created on 07/10/2008 at 19:35, modified on 07/10/2008 at 19:35) –ah–
kmdfcustom.dll (51680 bytes - created on 02/11/2006 at 12:22, modified on 02/11/2006 at 12:22) –a—
spmsg.dll (14640 bytes - created on 09/10/2006 at 02:51, modified on 09/10/2006 at 02:51) –a—
spuninst.exe (221488 bytes - created on 09/10/2006 at 02:51, modified on 09/10/2006 at 02:51) –a—
spupdsvc.exe (23856 bytes - created on 09/10/2006 at 02:51, modified on 09/10/2006 at 02:51) –a—
wdf01000.sys (492000 bytes - created on 02/11/2006 at 12:22, modified on 02/11/2006 at 12:22) –a—
wdfldr.sys (32224 bytes - created on 02/11/2006 at 12:22, modified on 02/11/2006 at 12:22) –a—

==================================
Contents of "C:\7e9a25158c5c409217d711cd60301a"

—FOLDERS—

update (Created on 07/10/2008 at 01:35) d—–

—FILES—

kmdfcustom.dll (51680 bytes - created on 02/11/2006 at 12:22, modified on 02/11/2006 at 12:22) –a—
spmsg.dll (14640 bytes - created on 09/10/2006 at 02:51, modified on 09/10/2006 at 02:51) –a—
spuninst.exe (221488 bytes - created on 09/10/2006 at 02:51, modified on 09/10/2006 at 02:51) –a—
spupdsvc.exe (23856 bytes - created on 09/10/2006 at 02:51, modified on 09/10/2006 at 02:51) –a—
wdf01000.sys (492000 bytes - created on 02/11/2006 at 12:22, modified on 02/11/2006 at 12:22) –a—
wdfldr.sys (32224 bytes - created on 02/11/2006 at 12:22, modified on 02/11/2006 at 12:22) –a—

==================================
=EOF=

Here is the new HiJack This log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:26:12 AM, on 10/17/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINNT1\System32\smss.exe
C:\WINNT1\system32\winlogon.exe
C:\WINNT1\system32\services.exe
C:\WINNT1\system32\lsass.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\system32\svchost.exe
C:\WINNT1\System32\svchost.exe
C:\Ahead\InCD\InCDsrv.exe
C:\WINNT1\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT1\system32\cisvc.exe
C:\WINNT1\System32\CTsvcCDA.exe
C:\WINNT1\System32\GEARSec.exe
C:\WINNT1\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINNT1\System32\HPZipm12.exe
C:\WINNT1\System32\svchost.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT1\System32\MsPMSPSv.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\Explorer.EXE
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\CA\CA Internet Security Suite\cctray\cctray.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\iTunes\iTunesHelper.exe
C:\WINNT1\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\K9 Filter\K9\K9.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\iPod\bin\iPodService.exe
C:\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT1\system32\cidaemon.exe
C:\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\WINNT1\system32\DllHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\WINNT1\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [cctray] "C:\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafw] C:\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT1\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SmartDefrag] "C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [QuickTime Task] "C:\quicktime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT1\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: Launch K9.lnk = C:\K9 Filter\K9\K9.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222224306093
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-79c15117386cc58a.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…319/mcfscan.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT1\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT1\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT1\System32\CTsvcCDA.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT1\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINNT1\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT1\System32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - C:\ReaConverter 5.0 Pro\rcp_scheduler.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O24 - Desktop Component 0: (no name) - (no file)

–
End of file - 12718 bytes


Here is the RSIT log:

Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-17 03:30:19
Microsoft Windows XP Professional Service Pack 3
System drive C: has 222 GB (78%) free of 286 GB
Total RAM: 2047 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:31:01 AM, on 10/17/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINNT1\System32\smss.exe
C:\WINNT1\system32\winlogon.exe
C:\WINNT1\system32\services.exe
C:\WINNT1\system32\lsass.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\system32\svchost.exe
C:\WINNT1\System32\svchost.exe
C:\Ahead\InCD\InCDsrv.exe
C:\WINNT1\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT1\system32\cisvc.exe
C:\WINNT1\System32\CTsvcCDA.exe
C:\WINNT1\System32\GEARSec.exe
C:\WINNT1\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINNT1\System32\HPZipm12.exe
C:\WINNT1\System32\svchost.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT1\System32\MsPMSPSv.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\Explorer.EXE
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\CA\CA Internet Security Suite\cctray\cctray.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\iTunes\iTunesHelper.exe
C:\WINNT1\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\K9 Filter\K9\K9.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\iPod\bin\iPodService.exe
C:\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT1\system32\cidaemon.exe
C:\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\WINNT1\system32\DllHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Documents and Settings\Jim Fanning.DAD\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Jim Fanning.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [cctray] "C:\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafw] C:\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT1\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SmartDefrag] "C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [QuickTime Task] "C:\quicktime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT1\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: Launch K9.lnk = C:\K9 Filter\K9\K9.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222224306093
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-79c15117386cc58a.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…319/mcfscan.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT1\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT1\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT1\System32\CTsvcCDA.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT1\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINNT1\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT1\System32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - C:\ReaConverter 5.0 Pro\rcp_scheduler.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O24 - Desktop Component 0: (no name) - (no file)

–
End of file - 12803 bytes

======Scheduled tasks folder======

C:\WINNT1\tasks\AppleSoftwareUpdate.job
C:\WINNT1\tasks\CAAntiSpywareScan_Daily as Jim Fanning at 3 17 AM.job
C:\WINNT1\tasks\Microsoft_Hardware_Launch_IPoint_exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F85D76C-0569-466F-A488-493E6BD0E955}]
dsWebAllowBHO Class - C:\Program Files\Windows Desktop Search\dsWebAllow.dll [2006-11-21 265504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 501400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-12-14 392240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FBF2401B-7447-4727-BE5D-C19B2075CA84}]
CA Toolbar Helper - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll [2008-07-23 275896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - CA Toolbar - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll [2008-07-23 275896]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"cctray"=C:\CA\CA Internet Security Suite\cctray\cctray.exe [2008-10-10 247024]
"CAVRID"=C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe [2008-09-08 234736]
"cafw"=C:\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe [2008-08-28 771312]
"capfasem"=C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe [2008-08-28 173296]
"QOELOADER"=C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe [2008-06-17 14088]
"HPDJ Taskbar Utility"=C:\WINNT1\system32\spool\drivers\w32x86\3\hpztsb05.exe [2002-04-22 188416]
"IntelliPoint"=c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 1406024]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]
"SmartDefrag"=C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2008-09-08 1965296]
"QuickTime Task"=C:\quicktime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\iTunes\iTunesHelper.exe [2008-10-01 289576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINNT1\system32\ctfmon.exe [2008-04-13 15360]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184]
"Yahoo! Pager"=C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe [2007-08-30 4670704]
"Weather Pulse"= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jim Fanning.DAD^Start Menu^Programs^Startup^HotSync Manager.lnk]
C:\PROGRA~1\Palm\HOTSYNC.EXE [2004-04-13 299008]

C:\Documents and Settings\All Users.WINNT1\Start Menu\Programs\Startup
hp psc 2000 Series.lnk - C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
hpoddt01.exe.lnk - C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
PC Alert 4.lnk - C:\Program Files\MSI\PC Alert 4\PCAlert4.exe

C:\Documents and Settings\Jim Fanning.DAD\Start Menu\Programs\Startup
Launch K9.lnk - C:\K9 Filter\K9\K9.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINNT1\system32\Ati2evxx.dll [2006-05-03 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PFW]
C:\WINNT1\system32\UmxWnp.Dll [2007-05-18 79368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINNT1\system32\WgaLogon.dll [2007-04-10 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINNT1\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"=C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\shellexecutehook.dll [2007-10-23 79408]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-11-21 233472]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"=C:\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll [2008-07-23 1377720]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NBF]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nbf.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sglfb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=5F000000
"NoViewOnDrive"=0
"NoDesktopCleanupWizard"=1
"NoDriveAutoRun"=FFFFFF03
"NoStartMenuMyMusic"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDriveTypeAutoRun"=
"NoResolveSearch"=
"EnableShellExecuteHooks"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Support.com\bin\tgcmd.exe"="C:\Program Files\Support.com\bin\tgcmd.exe:*:Enabled:Support.com Scheduler and Command Dispatcher"
"C:\WINNT1\kdx\khost.exe"="C:\WINNT1\kdx\khost.exe:*:Enabled:Secure Delivery Plug-In"
"C:\AresLite\Ares Lite Edition\AresLite.exe"="C:\AresLite\Ares Lite Edition\AresLite.exe:*:Enabled:Ares Lite Edition"
"C:\ICQ\ICQ\Icq.exe"="C:\ICQ\ICQ\Icq.exe:*:Enabled:ICQ"
"C:\Mozilla\mozilla.exe"="C:\Mozilla\mozilla.exe:*:Enabled:Mozilla"
"C:\ACT\ActUpdt.exe"="C:\ACT\ActUpdt.exe:*:Enabled:ACT! Update"
"C:\Limewire\LimeWire.exe"="C:\Limewire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Java\j2re1.4.1_03\bin\javaw.exe"="C:\Program Files\Java\j2re1.4.1_03\bin\javaw.exe:*:Enabled:javaw"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\WINNT1\system32\dpvsetup.exe"="C:\WINNT1\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINNT1\system32\rundll32.exe"="C:\WINNT1\system32\rundll32.exe:*:Disabled:Run a DLL as an App"
"C:\Program Files\SmartFTP\SmartFTP.exe"="C:\Program Files\SmartFTP\SmartFTP.exe:*:Enabled:SmartFTP"
"C:\WS_FTPLE\WS_FTP95.exe"="C:\WS_FTPLE\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"="C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"
"C:\RealPlayer\realplay.exe"="C:\RealPlayer\realplay.exe:*:Disabled:RealPlayer"
"C:\WINNT1\system32\sessmgr.exe"="C:\WINNT1\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\StubInstaller.exe"="C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Disabled:AOLTopSpeed"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Disabled:AOLTsMon"
"C:\Program Files\MSI\i-Speeder\i-Speeder.exe"="C:\Program Files\MSI\i-Speeder\i-Speeder.exe:*:Enabled:i-Speeder"
"C:\Ahead\Nero ShowTime\ShowTime.exe"="C:\Ahead\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime"
"C:\Program Files\Common Files\AOL\1152289767\ee\aim6.exe"="C:\Program Files\Common Files\AOL\1152289767\ee\aim6.exe:*:Enabled:AIM"
"C:\Program Files\Common Files\AOL\1152289767\ee\aolsoftware.exe"="C:\Program Files\Common Files\AOL\1152289767\ee\aolsoftware.exe:*:Disabled:AOL Services"
"C:\Program Files\Conference\Conference.dll"="C:\Program Files\Conference\Conference.dll:*:Disabled:Audio/Video Conference by KIOSK Team"
"C:\DAP\DAP\DAP.exe"="C:\DAP\DAP\DAP.exe:*:Disabled:Download Accelerator Plus"
"C:\Ares\Ares.exe"="C:\Ares\Ares.exe:*:Enabled:Ares"
"C:\Trillian\trillian.exe"="C:\Trillian\trillian.exe:*:Enabled:Trillian"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\AresLite\Ares Lite Edition\Ares.exe"="C:\AresLite\Ares Lite Edition\Ares.exe:*:Disabled:Ares"
"C:\NewsProxy\NewsProxy.exe"="C:\NewsProxy\NewsProxy.exe:*:Enabled:NewsProxy"
"C:\Documents and Settings\Jim Fanning.DAD\Desktop\NewsProxy.exe"="C:\Documents and Settings\Jim Fanning.DAD\Desktop\NewsProxy.exe:*:Enabled:NewsProxy"
"C:\AIM\aim.exe"="C:\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\MotoBlade\MotoBlade.exe"="C:\MotoBlade\MotoBlade.exe:*:Enabled:MotoBlade"
"C:\Documents and Settings\Jim Fanning.DAD\Local Settings\Temp\MotoBlade.exe"="C:\Documents and Settings\Jim Fanning.DAD\Local Settings\Temp\MotoBlade.exe:*:Enabled:MotoBlade"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"="C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater"
"C:\WINNT1\system32\ftp.exe"="C:\WINNT1\system32\ftp.exe:*:Enabled:File Transfer Program"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\iTunes\iTunes.exe"="C:\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\AIM\aim.exe"="C:\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd325074-aa95-11dc-b772-000c761889a9}]
shell\AutoRun\command - F:\setupSNK.exe


======List of files/folders created in the last 1 months======

2008-10-17 03:22:03 —-A—- C:\DirLook.txt
2008-10-17 03:21:23 —-A—- C:\dl_log03-21_17-10-2008.txt
2008-10-16 09:46:54 —-D—- C:\Documents and Settings\Jim Fanning.DAD\Application Data\Weather Pulse
2008-10-16 09:45:05 —-D—- C:\Weatherpulse
2008-10-15 15:48:29 —-D—- C:\WINNT1\LastGood
2008-10-15 03:06:24 —-HDC—- C:\WINNT1\$NtUninstallKB956803$
2008-10-15 03:05:50 —-HDC—- C:\WINNT1\$NtUninstallKB956391$
2008-10-15 03:05:24 —-HDC—- C:\WINNT1\$NtUninstallKB957095$
2008-10-15 03:03:10 —-HDC—- C:\WINNT1\$NtUninstallKB954211$
2008-10-15 03:02:47 —-A—- C:\WINNT1\imsins.BAK
2008-10-15 03:02:27 —-N—- C:\WINNT1\system32\spmsg.dll
2008-10-15 03:02:24 —-HDC—- C:\WINNT1\$NtUninstallKB956841$
2008-10-08 09:43:33 —-D—- C:\Motorola
2008-10-07 22:39:12 —-D—- C:\99a6ab0f464e23602880
2008-10-07 14:35:48 —-D—- C:\d138d89e0227edb14a23
2008-10-06 20:35:34 —-D—- C:\7e9a25158c5c409217d711cd60301a
2008-10-06 20:29:53 —-D—- C:\Program Files\Avanquest update
2008-10-06 20:25:35 —-D—- C:\Ringtones
2008-10-05 09:18:52 —-D—- C:\Documents and Settings\All Users.WINNT1\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-01 23:04:34 —-D—- C:\Process Explorer
2008-10-01 10:27:19 —-D—- C:\rsit
2008-10-01 09:01:42 —-D—- C:\Driver Backup 10-1-2008-9056
2008-10-01 08:35:51 —-D—- C:\Program Files\Trend Micro
2008-09-30 15:27:36 —-A—- C:\WINNT1\system32\WmiConf.txt
2008-09-30 15:18:14 —-D—- C:\Program Files\Microsoft IntelliPoint
2008-09-30 14:25:46 —-A—- C:\WINNT1\system32\CSVer.dll
2008-09-30 14:20:52 —-D—- C:\Intel
2008-09-30 13:49:07 —-D—- C:\ATI
2008-09-30 13:22:55 —-D—- C:\Driver Download
2008-09-30 12:15:23 —-D—- C:\Driver-Soft

======List of files/folders modified in the last 1 months======

2008-10-17 03:21:17 —-D—- C:\WINNT1\Prefetch
2008-10-17 03:19:22 —-D—- C:\Program Files\Mozilla Firefox
2008-10-17 03:18:18 —-D—- C:\Program Files\Mozilla Thunderbird
2008-10-17 03:16:16 —-D—- C:\unzipped
2008-10-17 03:06:04 —-AD—- C:\Program Files
2008-10-17 02:37:23 —-D—- C:\Fanning Family
2008-10-16 22:14:20 —-D—- C:\WINNT1\system32
2008-10-16 22:14:20 —-D—- C:\WINNT1
2008-10-16 20:04:40 —-D—- C:\Documents and Settings\Jim Fanning.DAD\Application Data\CallingID
2008-10-16 18:11:09 —-D—- C:\WINNT1\CAVTemp
2008-10-16 10:09:14 —-AD—- C:\WINNT1\Temp
2008-10-16 09:41:39 —-HD—- C:\Documents and Settings\Jim Fanning.DAD\Application Data\yahoo!
2008-10-16 09:41:39 —-D—- C:\Documents and Settings\All Users.WINNT1\Application Data\Yahoo!
2008-10-16 09:41:08 —-D—- C:\Program Files\Yahoo!
2008-10-15 15:50:49 —-AD—- C:\WINNT1\Debug
2008-10-15 15:50:38 —-HD—- C:\WINNT1\inf
2008-10-15 15:50:24 —-AD—- C:\WINNT1\system32\CatRoot
2008-10-15 15:50:02 —-RASHDC—- C:\WINNT1\system32\dllcache
2008-10-15 15:48:24 —-D—- C:\WINNT1\system32\CatRoot2
2008-10-15 13:30:06 —-A—- C:\WINNT1\SchedLgU.Txt
2008-10-15 03:06:29 —-D—- C:\WINNT1\system32\drivers
2008-10-15 03:06:11 —-HD—- C:\WINNT1\$hf_mig$
2008-10-15 03:04:42 —-AD—- C:\Program Files\Internet Explorer
2008-10-12 03:50:16 —-D—- C:\Legacy
2008-10-11 11:35:48 —-A—- C:\caisslog.txt
2008-10-08 09:45:20 —-SHD—- C:\WINNT1\Installer
2008-10-08 09:43:51 —-D—- C:\MotoBlade
2008-10-08 09:35:46 —-D—- C:\WINNT1\system32\Logfiles
2008-10-07 14:19:40 —-A—- C:\WINNT1\system32\MRT.exe
2008-10-07 11:11:07 —-D—- C:\Documents and Settings\Jim Fanning.DAD\Application Data\Skype
2008-10-07 11:08:19 —-SHD—- C:\Config.Msi
2008-10-07 11:07:11 —-D—- C:\Skype
2008-10-06 21:12:39 —-D—- C:\Program Files\Motorola Phone Tools
2008-10-06 20:40:36 —-D—- C:\WINNT1\WinSxS
2008-10-06 20:40:07 —-AD—- C:\Program Files\Common Files\Microsoft Shared
2008-10-06 20:39:32 —-DC—- C:\WINNT1\system32\DRVSTORE
2008-10-06 16:19:41 —-A—- C:\YServer.txt
2008-10-05 09:25:11 —-D—- C:\iTunes
2008-10-05 09:18:54 —-D—- C:\iPod
2008-10-04 01:29:01 —-D—- C:\Trillian
2008-10-03 12:41:15 —-A—- C:\WINNT1\system32\ieframe.dll
2008-10-01 23:57:03 —-ASH—- C:\boot.ini
2008-10-01 23:57:03 —-A—- C:\WINNT1\win.ini
2008-10-01 23:57:03 —-A—- C:\WINNT1\system.ini
2008-10-01 22:51:37 —-D—- C:\Documents and Settings\All Users.WINNT1\Application Data\PCPitstop
2008-10-01 22:48:45 —-SD—- C:\WINNT1\Downloaded Program Files
2008-10-01 03:11:30 —-D—- C:\Program Files\Messenger
2008-10-01 03:02:59 —-D—- C:\Program Files\Microsoft Silverlight
2008-09-30 21:45:59 —-AD—- C:\WINNT1\twain_32
2008-09-30 17:07:32 —-D—- C:\Program Files\ATI Technologies
2008-09-30 15:37:58 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-30 15:31:58 —-AD—- C:\Program Files\Intel
2008-09-30 15:31:42 —-A—- C:\WINNT1\system32\PerfStringBackup.INI
2008-09-30 15:30:36 —-D—- C:\WINNT1\system32\ReinstallBackups
2008-09-30 15:28:28 —-A—- C:\WINNT1\wininit.ini
2008-09-30 15:23:30 —-SD—- C:\WINNT1\Tasks
2008-09-30 15:19:25 —-RSD—- C:\WINNT1\Fonts
2008-09-29 22:14:56 —-D—- C:\CCleaner
2008-09-29 21:57:07 —-D—- C:\Documents and Settings\Jim Fanning.DAD\Application Data\wsInspector
2008-09-24 16:26:04 —-A—- C:\WINNT1\SIERRA.INI
2008-09-23 01:55:18 —-D—- C:\Job Resume
2008-09-22 13:02:28 —-A—- C:\WINNT1\MyHeritage.INI
2008-09-20 09:54:38 —-D—- C:\FTW
2008-09-20 09:54:38 —-A—- C:\WINNT1\MPLAYER.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AVG Anti-Spyware Driver;AVG Anti-Spyware Driver; \??\C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.sys []
R1 AvgAsCln;AVG Anti-Spyware Clean Driver; C:\WINNT1\System32\DRIVERS\AvgAsCln.sys [2006-09-05 3968]
R1 bc_ip_f;BC_IP_Filter; C:\WINNT1\system32\drivers\bc_ip_f.sys [2007-12-11 28776]
R1 bc_pat_f;BC_PAT_Filter; C:\WINNT1\system32\drivers\bc_pat_f.sys [2007-12-11 13544]
R1 bc_prt_f;BC_Protocol_Filter; C:\WINNT1\system32\drivers\bc_prt_f.sys [2007-12-11 17512]
R1 bc_tdi_f;BC_TDI_Filter; C:\WINNT1\system32\drivers\bc_tdi_f.sys [2007-12-11 22376]
R1 bcftdi;BCFTDI; C:\WINNT1\system32\drivers\bcftdi.sys [2007-12-10 62824]
R1 InCDPass;InCDPass; C:\WINNT1\System32\DRIVERS\InCDPass.sys [2006-03-23 29440]
R1 intelppm;Intel Processor Driver; C:\WINNT1\System32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 KmxAgent;KmxAgent; C:\WINNT1\System32\DRIVERS\kmxagent.sys [2008-06-24 63504]
R1 KmxFile;KmxFile; C:\WINNT1\System32\DRIVERS\KmxFile.sys [2008-06-24 45584]
R1 KmxFw;KmxFw; C:\WINNT1\System32\DRIVERS\kmxfw.sys [2008-06-24 115216]
R1 VETEFILE;VET File Scan Engine; C:\WINNT1\system32\drivers\VETEFILE.sys [2008-06-17 880560]
R1 VETFDDNT;VET Floppy Boot Sector Monitor; C:\WINNT1\system32\drivers\VETFDDNT.sys [2008-09-08 21488]
R1 VET-FILT;VET File System Filter; C:\WINNT1\system32\drivers\VET-FILT.sys [2008-09-08 26352]
R1 VETMONNT;VET File Monitor; C:\WINNT1\system32\drivers\VETMONNT.sys [2008-09-08 32240]
R1 VET-REC;VET File System Recognizer; C:\WINNT1\system32\drivers\VET-REC.sys [2008-09-08 21104]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINNT1\System32\drivers\ws2ifsl.sys [2002-08-29 12032]
R2 Aspi32;Aspi32; C:\WINNT1\system32\drivers\Aspi32.sys [2002-08-14 17005]
R2 ATNT40K;ActiveTouch NT Appsharing Driver; C:\WINNT1\SYSTEM32\DRIVERS\ATNT40K.SYS [2007-09-23 51304]
R2 BBFat.VxD;BlueBird DSP API; C:\WINNT1\System32\Drivers\BBFat.sys [2002-12-10 6400]
R2 BCMNTIO;BCMNTIO; \??\C:\CheckIt\DIAGNO~1\BCMNTIO.sys []
R2 KmxCF;KmxCF; C:\WINNT1\System32\DRIVERS\KmxCF.sys [2008-06-24 134648]
R2 KmxSbx;KmxSbx; C:\WINNT1\System32\DRIVERS\KmxSbx.sys [2008-06-24 66576]
R2 MAPMEM;MAPMEM; \??\C:\CheckIt\DIAGNO~1\MAPMEM.sys []
R2 PfModNT;PfModNT; \??\C:\WINNT1\system32\drivers\PfModNT.sys []
R3 ati2mtag;ati2mtag; C:\WINNT1\system32\DRIVERS\ati2mtag.sys [2006-05-03 1540608]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINNT1\System32\drivers\ctac32k.sys [2002-07-19 127948]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINNT1\system32\drivers\ctaud2k.sys [2002-07-19 837548]
R3 ctprxy2k;Creative Proxy Driver; C:\WINNT1\System32\drivers\ctprxy2k.sys [2002-07-19 11068]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINNT1\System32\drivers\ctsfm2k.sys [2002-07-19 213860]
R3 E100B;Intel® PRO Network Connection Driver; C:\WINNT1\System32\DRIVERS\e100b325.sys [2007-11-16 165496]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINNT1\System32\drivers\emupia2k.sys [2002-07-19 156604]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINNT1\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINNT1\system32\drivers\ha10kx2k.sys [2002-07-24 998004]
R3 hidusb;Microsoft HID Class Driver; C:\WINNT1\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINNT1\System32\DRIVERS\HPZid412.sys [2005-10-21 49920]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINNT1\System32\DRIVERS\HPZipr12.sys [2005-10-21 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINNT1\System32\DRIVERS\HPZius12.sys [2005-10-21 21568]
R3 KmxCfg;KmxCfg; C:\WINNT1\System32\DRIVERS\kmxcfg.sys [2008-06-24 88816]
R3 mouhid;Mouse HID Driver; C:\WINNT1\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 ossrv;Creative OS Services Driver; C:\WINNT1\system32\drivers\ctoss2k.sys [2002-07-19 195432]
R3 PCAlertDriver;PCAlertDriver; \??\C:\Program Files\MSI\PC Alert 4\NTGLM7X.sys []
R3 Pcouffin;Low level access layer for CD devices; C:\WINNT1\System32\Drivers\Pcouffin.sys [2006-08-10 47360]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINNT1\system32\DRIVERS\point32.sys [2008-06-10 31048]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINNT1\System32\Drivers\RootMdm.sys [2002-08-29 5888]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINNT1\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINNT1\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINNT1\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINNT1\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINNT1\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINNT1\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINNT1\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VETEBOOT;VET Boot Scan Engine; C:\WINNT1\system32\drivers\VETEBOOT.sys [2008-06-17 108368]
R4 InCDfs;InCD File System; C:\WINNT1\system32\drivers\InCDfs.sys [2006-03-23 102016]
S1 incdrm;InCD Reader; C:\WINNT1\system32\drivers\incdrm.sys [2006-03-23 33536]
S1 tga;tga; C:\WINNT1\system32\drivers\tga.sys []
S3 Bcfilter;Jetico Personal Firewall Network Monitor; C:\WINNT1\system32\DRIVERS\bcfilter.sys []
S3 BcfilterMP;BcfilterMP; C:\WINNT1\system32\DRIVERS\bcfilter.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINNT1\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 CoolerXPDriver;CoolerXPDriver; \??\C:\MSI\NTCooler.sys []
S3 ctljystk;Creative SBLive! Gameport; C:\WINNT1\System32\DRIVERS\ctljystk.sys [2001-08-17 3712]
S3 DMIBDriv;DMIBDriv; \??\C:\MSI\NTGLM7X.sys []
S3 motmodem;Motorola USB CDC ACM Driver; C:\WINNT1\system32\DRIVERS\motmodem.sys [2007-06-18 23680]
S3 MotoSwitchService;MotoSwitch Service; C:\WINNT1\system32\DRIVERS\motswch.sys []
S3 MPE;BDA MPE Filter; C:\WINNT1\System32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINNT1\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINNT1\System32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 P2k;Motorola USB Device; C:\WINNT1\system32\DRIVERS\P2k.sys [2006-07-28 40960]
S3 RapFile;RapFile; \??\C:\WINNT1\system32\drivers\RapFile.sys []
S3 RapNet;RapNet; \??\C:\WINNT1\system32\drivers\RapNet.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINNT1\System32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINNT1\System32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TVICHW32;TVICHW32; \??\C:\WINNT1\system32\DRIVERS\TVICHW32.SYS []
S3 usbhub20;USB 2.0 Root Hub Support; C:\WINNT1\System32\DRIVERS\usbhub20.sys [2002-04-17 49392]
S3 usbser;Motorola USB Modem Driver; C:\WINNT1\system32\DRIVERS\usbser.sys [2008-04-13 26112]
S3 VIAudio;VIA AC'97 Audio Controller (WDM); C:\WINNT1\system32\drivers\viaudios.sys [2003-06-18 91520]
S3 wanatw;WAN Miniport (ATW); C:\WINNT1\System32\DRIVERS\wanatw4.sys [2003-01-10 33588]
S3 Wdf01000;Wdf01000; C:\WINNT1\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINNT1\System32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINNT1\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINNT1\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 aic116x;aic116x; C:\WINNT1\system32\drivers\aic116x.sys []
S4 ami0nt;ami0nt; C:\WINNT1\system32\drivers\ami0nt.sys []
S4 BusLogic;BusLogic; C:\WINNT1\system32\drivers\BusLogic.sys []
S4 cpqarry2;cpqarry2; C:\WINNT1\system32\drivers\cpqarry2.sys []
S4 cpqfcalm;cpqfcalm; C:\WINNT1\system32\drivers\cpqfcalm.sys []
S4 cpqfws2e;cpqfws2e; C:\WINNT1\system32\drivers\cpqfws2e.sys []
S4 deckzpsx;deckzpsx; C:\WINNT1\system32\drivers\deckzpsx.sys []
S4 EFS;EFS; C:\WINNT1\system32\drivers\EFS.sys []
S4 Fd16_700;Fd16_700; C:\WINNT1\system32\drivers\Fd16_700.sys []
S4 fireport;fireport; C:\WINNT1\system32\drivers\fireport.sys []
S4 flashpnt;flashpnt; C:\WINNT1\system32\drivers\flashpnt.sys []
S4 IntelIde;IntelIde; C:\WINNT1\system32\drivers\IntelIde.sys []
S4 ipsraidn;ipsraidn; C:\WINNT1\system32\drivers\ipsraidn.sys []
S4 lp6nds35;lp6nds35; C:\WINNT1\system32\drivers\lp6nds35.sys []
S4 Ncrc710;Ncrc710; C:\WINNT1\system32\drivers\Ncrc710.sys []
S4 Parallel;Parallel class driver; C:\WINNT1\System32\DRIVERS\parallel.sys []
S4 ql2100;ql2100; C:\WINNT1\system32\drivers\ql2100.sys []
S4 ultra66;ultra66; C:\WINNT1\system32\drivers\ultra66.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINNT1\system32\Ati2evxx.exe [2006-05-03 413696]
R2 AVG Anti-Spyware Guard;AVG Anti-Spyware Guard; C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe [2007-10-23 312880]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 CAISafe;CAISafe; C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe [2008-06-17 144696]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINNT1\System32\CTsvcCDA.exe [1999-12-13 44032]
R2 GEARSecurity;GEARSecurity; C:\WINNT1\System32\GEARSec.exe [2003-11-11 53248]
R2 InCDsrv;InCD Helper; C:\Ahead\InCD\InCDsrv.exe [2006-03-23 880128]
R2 ITMRTSVC;CA Pest Patrol Realtime Protection Service; C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe [2007-09-26 283912]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINNT1\System32\HPZipm12.exe [2007-08-09 73728]
R2 UmxAgent;HIPS Event Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2008-01-21 1010192]
R2 UmxCfg;HIPS Configuration Interpreter; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2008-01-21 801296]
R2 UmxFwHlp;HIPS Firewall Helper; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe [2008-01-21 145936]
R2 UmxPol;HIPS Policy Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe [2008-06-24 281104]
R2 VETMSGNT;VET Message Service; C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe [2008-09-08 255216]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINNT1\System32\MsPMSPSv.exe [2000-06-26 53520]
R2 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
R3 CaCCProvSP;CaCCProvSP; C:\CA\CA Internet Security Suite\ccprovsp.exe [2008-10-10 214256]
R3 iPod Service;iPod Service; C:\iPod\bin\iPodService.exe [2008-10-01 536872]
R3 PPCtlPriv;PPCtlPriv; C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2008-09-08 185584]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S2 ATI Smart;ATI Smart; C:\WINNT1\system32\ati2sgag.exe [2006-05-03 520192]
S2 spupdsvc;Windows Service Pack Installer update service; C:\WINNT1\system32\spupdsvc.exe [2007-08-10 26488]
S3 aspnet_state;ASP.NET State Service; C:\WINNT1\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINNT1\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINNT1\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-03 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINNT1\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 KodakCCS;Kodak Camera Connection Software; C:\WINNT1\system32\drivers\KodakCCS.exe []
S3 rcp_service;ReaConverter scheduler service; C:\ReaConverter 5.0 Pro\rcp_scheduler.exe [2007-11-30 558592]
S3 UtilMan;Utility Manager; C:\WINNT1\System32\UtilMan.exe [2008-04-13 50176]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINNT1\system32\svchost.exe [2008-04-13 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINNT1\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

—————–EOF—————–
info.txt logfile of random's system information tool 1.04 2008-10-17

03:54:20

======Uninstall list======

–>"C:\CA\CA Internet Security Suite\CA Personal

Firewall\setup\ccinstaller.exe" /u /silent /module="fw"
–>C:\Program Files\Acoustica CD Label Maker\uisurvey.exe
–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe

RealNetworks|RealPlayer|6.0
Acoustica Effects Pack–>C:\ACCOUS~1\ACF52A~1\UNWISE.EXE

C:\ACCOUS~1\ACF52A~1\INSTALL.LOG
Acoustica Mixcraft

3.1–>C:\ACCOUS~1\AC5BE3~1\ACOUST~2\Mixcraft3.exe

uninstall
Acoustica MP3 CD

Burner–>C:\ACCOUS~1\ACOUST~2\ACOUST~1\UNWISE.EXE

C:\ACCOUS~1\ACOUST~2\ACOUST~1\INSTALL.LOG
Adobe Acrobat and Reader 8.1.2 Security Update 1

(KB403742)–>MsiExec.exe

/X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player

ActiveX–>C:\WINNT1\system32\Macromed\Flash\uninstall_activeX.e

xe
Adobe Flash Player

Plugin–>C:\WINNT1\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2–>MsiExec.exe

/I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave

Player–>C:\WINNT1\system32\Macromed\SHOCKW~2\UNWISE.E

XE C:\WINNT1\system32\Macromed\SHOCKW~2\Install.log
Advanced WindowsCare Personal–>"C:\Advanced WindowsCare

V2\unins000.exe"
Apple Mobile Device Support–>MsiExec.exe

/I{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}
Apple Software Update–>MsiExec.exe

/I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ATI - Software Uninstall Utility–>C:\Program Files\ATI

Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center–>MsiExec.exe

/I{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}
ATI Display Driver–>rundll32

C:\WINNT1\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@1

6 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Avanquest update–>C:\Program Files\InstallShield Installation

Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.e

xe -runfromtemp -l0x0009 -removeonly
Bonjour–>MsiExec.exe

/I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
CA Anti-Spyware–>"C:\CA\CA Internet Security Suite\CA

Anti-Spyware\setup\ccinstaller.exe" /u /silent /module="pp"
CA Anti-Virus–>C:\CA\CA Internet Security Suite\CA

Anti-Virus\unvet32.exe
CA Internet Security Suite–>"C:\CA\CA Internet Security

Suite\caunst.exe" /u
CA Pest Patrol Realtime Protection–>MsiExec.exe

/X{F05A5232-CE5E-4274-AB27-44EB8105898D}
CA Website Inspector–>C:\CA\CA Internet Security Suite\CA

Website Inspector\CAWebsiteInspector.exe /uninstall
CCleaner (remove only)–>"C:\CCleaner\uninst.exe"
CCScore–>MsiExec.exe

/I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
DMI Browse–>C:\WINNT1\IsUninst.exe -f"C:\Program

Files\MSI\DMI Browser\Uninst.isu"
Driver Genius Professional

Edition–>"C:\Driver-Soft\DriverGenius\unins000.exe"
DriverAgent by TouchStone Software–>RunDll32.exe

advpack.dll,LaunchINFSection driveragent_exe.inf,TVICHW32Remove
ESSBrwr–>MsiExec.exe

/I{643EAE81-920C-4931-9F0B-4B343B225CA6}
ESSCDBK–>MsiExec.exe

/I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
ESScore–>MsiExec.exe

/I{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}
ESSCT–>MsiExec.exe

/I{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}
ESSEMAIL–>MsiExec.exe

/I{FEDE2483-87B7-44C1-A5BB-D75AEB8B6340}
ESSgui–>MsiExec.exe

/I{91517631-A9F3-4B7C-B482-43E0068FD55A}
ESShelp–>MsiExec.exe

/I{87843A41-7808-4F2E-B13F-25C1E67CF2FD}
ESSini–>MsiExec.exe

/I{8E92D746-CD9F-4B90-9668-42B74C14F765}
ESSPCD–>MsiExec.exe

/I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
ESSSONIC–>MsiExec.exe

/I{4F677FC7-7AA8-412B-A957-F13CBE1C7331}
ESSTOOLS–>MsiExec.exe

/I{8A502E38-29C9-49FA-BCFA-D727CA062589}
ESSvpaht–>MsiExec.exe

/I{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}
ESSvpot–>MsiExec.exe

/I{48C82F7A-F100-4DAB-A310-8E18BF2159E1}
Free Window Registry

Repair–>C:\FREEWI~1\FREEWI~1\UNWISE.EXE

C:\FREEWI~1\FREEWI~1\INSTALL.LOG
FuzzyLogic4–>C:\WINNT1\IsUninst.exe -f"C:\Program

Files\MSI\FuzzyLogic4\Uninst.isu"
HijackThis 2.0.2–>"C:\Program Files\Trend

Micro\HijackThis\HijackThis.exe" /uninstall
HLPIndex–>MsiExec.exe

/I{38441BE7-79B0-42B8-8297-833704F949FE}
HLPSFO–>MsiExec.exe

/I{8DD94CA3-BCD2-49C0-B537-F3B5D95FF0C8}
Hotfix for Windows Internet Explorer 7

(KB947864)–>"C:\WINNT1\ie7updates\KB947864-IE7\spuninst\spu

ninst.exe"
HP Print Diagnostic Utility–>MsiExec.exe

/I{5E06C076-E4E7-4239-A886-B3D8AC84C166}
HP Update–>MsiExec.exe

/X{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}
InfoView–>C:\WINNT1\IsUninst.exe -f"C:\Program

Files\MSI\InfoView\Uninst.isu"
Intel® Network Connections 13.2.8.0–>MsiExec.exe

/i{AAA4850F-7E20-40D7-A4C3-3697E7FA4A54}

ARPREMOVE=1
i-Speeder–>C:\WINNT1\IsUninst.exe -f"C:\Program

Files\MSI\i-Speeder\Uninst.isu"
iTunes–>MsiExec.exe

/I{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}
K9–>"C:\K9 Filter\K9\uninstall.exe"
KSU–>MsiExec.exe

/I{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}
Legacy 6.0–>C:\Legacy\UNWISE.EXE /U C:\Legacy\Install.log
LimeWire 4.18.3–>"C:\Limewire\uninstall.exe"
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe

/I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0 Service Pack 1–>MsiExec.exe

/I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft Office Converter Pack–>MsiExec.exe

/X{6EECB283-E65F-40EF-86D3-D51BF02A8D43}
Microsoft Silverlight–>MsiExec.exe

/I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
MobileMe Control Panel–>MsiExec.exe

/I{6DA9102E-199F-43A0-A36B-6EF48081A658}
Motorola Driver Installation 3.4.0–>MsiExec.exe

/I{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}
Motorola Phone Tools–>C:\Program Files\InstallShield Installation

Information\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}\setu

p.exe -runfromtemp -l0x0009 -removeonly
Mozilla Firefox (3.0.3)–>C:\Program Files\Mozilla

Firefox\uninstall\helper.exe
Mozilla Thunderbird (2.0.0.17)–>C:\Program Files\Mozilla

Thunderbird\uninstall\helper.exe
MSI Live Update 3–>C:\WINNT1\IsUninst.exe -f"C:\Program

Files\MSI\Live Update 3\Uninst.isu"
MyHeritage Family Tree Builder–>C:\MyHeritage\Bin\Uninstall.exe
Notifier–>MsiExec.exe

/I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}
OfotoXMI–>MsiExec.exe

/I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
OTtBP–>MsiExec.exe

/I{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}
OTtBPSDK–>MsiExec.exe

/I{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}
PC Alert 4–>C:\WINNT1\IsUninst.exe -f"C:\Program Files\MSI\PC

Alert 4\Uninst.isu"
PC Pitstop Optimize2 2.0–>"C:\PCPitstop\Optimize2\unins000.exe"
Personal Ancestral File Companion 5.2–>C:\WINNT1\IsUninst.exe

-fc:\paf5.2\PC5Uninst.isu -c"c:\paf5.2\Uninst_PDF.dll"
Picasa 2–>"C:\Picasa2\Uninstall.exe"
QuickTime–>MsiExec.exe

/I{8DC42D05-680B-41B0-8878-6C14D24602DB}
ReaConverter 5.0 Pro–>"C:\ReaConverter 5.0 Pro\unins000.exe"
RealPlayer–>C:\Program Files\Common

Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Safari–>MsiExec.exe

/I{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}
Security Task Manager 1.7f–>C:\Security Task Manager\Uninstal.exe

"C:\Documents and Settings\All Users.WINNT1\Start

Menu\Programs\Security Task Manager"
Security Update for Windows Internet Explorer 7

(KB939653)–>"C:\WINNT1\ie7updates\KB939653-IE7\spuninst\spu

ninst.exe"
Security Update for Windows Internet Explorer 7

(KB942615)–>"C:\WINNT1\ie7updates\KB942615-IE7\spuninst\spu

ninst.exe"
Security Update for Windows Internet Explorer 7

(KB944533)–>"C:\WINNT1\ie7updates\KB944533-IE7\spuninst\spu

ninst.exe"
Security Update for Windows Internet Explorer 7

(KB950759)–>"C:\WINNT1\ie7updates\KB950759-IE7\spuninst\spu

ninst.exe"
Security Update for Windows Internet Explorer 7

(KB953838)–>"C:\WINNT1\ie7updates\KB953838-IE7\spuninst\spu

ninst.exe"
Security Update for Windows Internet Explorer 7

(KB956390)–>"C:\WINNT1\ie7updates\KB956390-IE7\spuninst\spu

ninst.exe"
Security Update for Windows XP

(KB954211)–>"C:\WINNT1\$NtUninstallKB954211$\spuninst\spunin

st.exe"
Security Update for Windows XP

(KB956391)–>"C:\WINNT1\$NtUninstallKB956391$\spuninst\spunin

st.exe"
Security Update for Windows XP

(KB956803)–>"C:\WINNT1\$NtUninstallKB956803$\spuninst\spunin

st.exe"
Security Update for Windows XP

(KB956841)–>"C:\WINNT1\$NtUninstallKB956841$\spuninst\spunin

st.exe"
Security Update for Windows XP

(KB957095)–>"C:\WINNT1\$NtUninstallKB957095$\spuninst\spunin

st.exe"
SFR–>MsiExec.exe

/I{DB02F716-6275-42E9-B8D2-83BA2BF5100B}
SFR2–>MsiExec.exe

/I{ABE068DF-8DC4-4947-ABFC-DD2B40850225}
SHASTA–>MsiExec.exe

/I{605A4E39-613C-4A12-B56F-DEFBE6757237}
Shredder (3.0b1pre)–>C:\Program Files\Shredder\uninstall\helper.exe
SKIN0001–>MsiExec.exe

/I{FDF9943A-3D5C-46B3-9679-586BD237DDEE}
SKINXSDK–>MsiExec.exe

/I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}
Skype™ 3.8–>MsiExec.exe

/X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Smart Defrag 1.0–>"C:\IObit\IObit SmartDefrag\unins000.exe"
TweakNow RegCleaner Standard–>"C:\TweakNow RegCleaner

Std\unins000.exe"
Virtual Earth 3D (Beta)–>MsiExec.exe

/I{D76D1828-BBA0-4BD9-8181-5ACC617DC5F2}
VPRINTOL–>MsiExec.exe

/I{999D43F4-9709-4887-9B1A-83EBB15A8370}
Weather Pulse 2.10 build 7–>"C:\Weatherpulse\Weather

Pulse\unins000.exe"
WebEx–>C:\WINNT1\DOWNLO~1\atcliun.exe
Winamp–>"C:\Winamp\UninstWA.exe"
Windows Live installer–>MsiExec.exe

/X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger–>MsiExec.exe

/X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant–>MsiExec.exe

/I{0ED47137-C071-46CC-A243-E5E33271E10E}
Windows Media Format 11 runtime–>"C:\Program Files\Windows

Media Player\wmsetsdk.exe" /UninstallAll
Windows XP Service Pack

3–>"C:\WINNT1\$NtServicePackUninstall$\spuninst\spuninst.exe"
WIRELESS–>MsiExec.exe

/I{F9593CFB-D836-49BC-BFF1-0E669A411D9F}
WMIinfo–>C:\WINNT1\IsUninst.exe -f"C:\Program

Files\MSI\WMIinfo\Uninst.isu"
Yahoo!

Messenger–>C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U

C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG

=====HijackThis Backups=====

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions

present
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) -

{02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: (no name) -

{28BC2EC4-5EAD-45E1-9F9F-82CD5E293601} - (no file)
O2 - BHO: (no name) -

{911C4A8E-0F75-4B83-BEB9-02BDDF29D11E} - (no file)
O2 - BHO: (no name) -

{7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
R0 - HKLM\Software\Microsoft\Internet

Explorer\Search,SearchAssistant =
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control

Panel present
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} -
O20 - Winlogon Notify: AutorunsDisabled - C:\WINNT1\
O24 - Desktop Component 0: (no name) - (no file)

======Security center information======

AV: CA Anti-Virus
AV: McAfee VirusScan
FW: CA Personal Firewall
FW: McAfee Personal Firewall (disabled)

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"NUMBER_OF_PROCESSORS"=1
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\sys

tem32\WBEM;C:\Program Files\Common Files\Adaptec

Shared\System;C:\Program Files\ATI Technologies\ATI Control

Panel;C:\quicktime\QTSystem\;C:\Program

Files\Intel\DMIX;C:\Program Files\ATI Technologies\ATI.ACE\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.

WSH
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 7,

GenuineIntel
"PROCESSOR_LEVEL"=15
"PROCESSOR_REVISION"=0207
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=.;C:\Program

Files\Java\jre1.6.0_01\lib\ext\QTJava.zip;C:\Program

Files\Java\jre1.6.0_02\lib\ext\QTJava.zip;C:\Program

Files\Java\jre1.6.0_03\lib\ext\QTJava.zip;C:\Program

Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip

—————–EOF—————–
Hi.

Click Start >> Control Panel. Double click on Display (or Display Properties) and click on the Desktop tab. Click on Customize Desktop and click the Web tab.
For every item in the Web Pages box (except the "My Current Homepage" entry), uncheck it, and delete it.
Also, have a look at the Lock Desktop Items checkbox and make sure it is unchecked.
Click OK and OK again until you have exited the display properties.


Your Java Runtime Environment is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 10.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 10, The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language and save it to your desktop.
  • Close any programs you may have running - especially any web browsers.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u10-windowsi586.exe to install the newest version.
Reboot after completing these steps and post a new HijackThis log. If you are still experiencing a slow computer, take at this article:
http://www.malwareremoval.com/tutorials/runningslowly.php

If after reading that article you are still running slowly and experiencing these issues with Desktop Icons and Firefox/Thunderbird, then I recommend that you head on over to the Microsoft Windows forum at WhatTheTech once I have given you the all clear, for assistance from one of our Tech Experts. I do not believe that any of it is Malware related.

Thanks.
JP,

I followed your last set of instructions however some anomolies occurred. First, when I went to delete the out of date Java files in the Control Panel, there were only 2 that qualified:

Java2 Runtime Environment SE v1.4.2_05
Jave Runtime Environment 6 update 1

Neither file offered a 'Change/Delete' option when I clicked on them. The onlu info was when they were last used and how much they were used. Consequently, I couldn't delete these files. I then rebooted and upon boot up some of the applications being loaded actually froze on the screen. The more that opened, the more that completely froze. I then decided to hit the reset button and reboot from that. It did, in fact, finally reboot normally, but slowly. I then installed the new Jave file as instructed and rebooted. It seemed to be a slower reboot than normal. Thunderbird had a lot of problems opening from the desktop icon. After several tries, I decided to used the icon from the "programs" button in the tray however I had to use the 'safe' mode offered by Mozilla to get it open. I'm not sure exactly what's happened here. I'm attaching the latest HJT file as requested. Let me know if there's anything abnormal about it.

Thanks!

Taz

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:15:29 PM, on 10/17/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINNT1\System32\smss.exe
C:\WINNT1\system32\winlogon.exe
C:\WINNT1\system32\services.exe
C:\WINNT1\system32\lsass.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\system32\svchost.exe
C:\WINNT1\System32\svchost.exe
C:\Ahead\InCD\InCDsrv.exe
C:\WINNT1\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT1\system32\cisvc.exe
C:\WINNT1\System32\CTsvcCDA.exe
C:\WINNT1\System32\GEARSec.exe
C:\WINNT1\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT1\System32\HPZipm12.exe
C:\WINNT1\System32\svchost.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT1\System32\MsPMSPSv.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\Explorer.EXE
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\CA\CA Internet Security Suite\cctray\cctray.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINNT1\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\K9 Filter\K9\K9.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\iPod\bin\iPodService.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINNT1\system32\cidaemon.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [cctray] "C:\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafw] C:\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT1\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SmartDefrag] "C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [QuickTime Task] "C:\quicktime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT1\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: Launch K9.lnk = C:\K9 Filter\K9\K9.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222224306093
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-79c15117386cc58a.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…319/mcfscan.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT1\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT1\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT1\System32\CTsvcCDA.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT1\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINNT1\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT1\System32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - C:\ReaConverter 5.0 Pro\rcp_scheduler.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 12951 bytes
Hi.

Thats veru strange. Nothing abnormal is showing in the HJT log.

Are you an Administrator? Have you made any other software changes recently (i.e. last couple of days)?

Let's something a little different to get rid of the old Java Versions. Please make sure you are logged in as an Administrator and then do the following:

Download JavaRa and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
Please reboot, post that log, along with a new HijackThis log and the answers to my above questions.

Thanks.
Hi JP..

Well, Yes I am logged in as the administrator of this computer as I'm the only one who uses it. Secondly, I haven't put anything new on here for probably 1-2 weeks which was a new driver update program. I did the JavaRA download and run and it did find quite a few files it deleted. The log file is attached as is the new HJT log file. After I ran the JavaRA program I had to push the rest button to get it to reboot. Clicking on the start button in the tray wouldn't open it to get to the reboot screen. Let me know what else you want me to do.

Thanks again…

Taz


JavaRa 1.11 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Sat Oct 18 02:18:32 2008

Found and removed: C:\Program Files\Java\j2re1.4.1_02

Found and removed: C:\Program Files\Java\j2re1.4.1_03

Found and removed: C:\Program Files\Java\j2re1.4.2_05

Found and removed: C:\Program Files\Java\jre1.6.0_01

Found and removed: C:\Program Files\Java\jre1.6.0_02

Found and removed: C:\Program Files\Java\jre1.6.0_03

Found and removed: C:\Program Files\Java\jre1.6.0_05

Found and removed: C:\Program Files\Common Files\Java\Update\Base Images\j2re1.4.2-b28

Found and removed: C:\Program Files\Java Web Start

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\javaw.Exe

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4

Found and removed: Software\JavaSoft\Java2D\1.5.0_01

Found and removed: Software\JavaSoft\Java2D\1.5.0_02

Found and removed: Software\JavaSoft\Java2D\1.5.0_04

Found and removed: Software\JavaSoft\Java2D\1.5.0_06

Found and removed: Software\JavaSoft\Java2D\1.5.0_09

Found and removed: Software\JavaSoft\Java2D\1.5.0_10

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\JavaPlugin.160_01

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_01

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410205

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410205

Found and removed: SOFTWARE\Classes\JavaPlugin.141_03

Found and removed: SOFTWARE\Classes\JavaPlugin.142_05

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.1_03

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_05

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.1_03

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_05

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_05

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\JavaPlugin.141_03

Found and removed: Software\Classes\JavaPlugin.142_05

Found and removed: Software\Classes\JavaPlugin.160_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_02\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_01.b06\

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_01

Found and removed: Software\JavaSoft\Java2D\1.6.0_01

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

JavaRa 1.11 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Sat Oct 18 02:19:33 2008

————————————

Finished reporting.



JavaRa 1.11 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Sat Oct 18 02:19:42 2008

————————————

Finished reporting.


















Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:37:42 AM, on 10/18/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINNT1\System32\smss.exe
C:\WINNT1\system32\winlogon.exe
C:\WINNT1\system32\services.exe
C:\WINNT1\system32\lsass.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\system32\svchost.exe
C:\WINNT1\System32\svchost.exe
C:\Ahead\InCD\InCDsrv.exe
C:\WINNT1\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT1\system32\cisvc.exe
C:\WINNT1\System32\CTsvcCDA.exe
C:\WINNT1\System32\GEARSec.exe
C:\WINNT1\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT1\System32\HPZipm12.exe
C:\WINNT1\System32\svchost.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT1\System32\MsPMSPSv.exe
C:\WINNT1\system32\Ati2evxx.exe
C:\WINNT1\Explorer.EXE
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\CA\CA Internet Security Suite\cctray\cctray.exe
C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINNT1\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\K9 Filter\K9\K9.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\iPod\bin\iPodService.exe
C:\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINNT1\system32\cidaemon.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [cctray] "C:\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafw] C:\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT1\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SmartDefrag] "C:\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [QuickTime Task] "C:\quicktime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT1\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: Launch K9.lnk = C:\K9 Filter\K9\K9.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222224306093
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-79c15117386cc58a.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…319/mcfscan.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT1\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT1\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\ewido anti-spyware 4.0\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT1\System32\CTsvcCDA.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT1\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINNT1\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT1\System32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - C:\ReaConverter 5.0 Pro\rcp_scheduler.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 12861 bytes
I'm really struggling to see where these problems are coming from - I don't think they are malware related. Bear with me, I will ask for some advice from some of my fellow staff members and tech experts. Thanks.
Hi.

AVG AntiSpyware is now an outdated program I'm afraid. I would recommend you uninstall it, and replace it with a program that is kept up to date, like SpyBot. I will suggesting a few of these in my last post to you, so you can make the decision then.

Another useful guide for slow computers is this one here:
http://users.telenet.be/bluepatchy/miekiem…owcomputer.html
As recommended by many of our staff.

You are experiencing issues with your mouse-clicks, perhaps the problem lies in the mouse itself. Have you tried a USB mouse or any alternative just in case?

If you aren't experiencing any Malware Problems, then I will probably send you over to the Tech Forums here, a couple of our Tech Experts have already said they would be happy to help you with these issues.

Thanks.
JP, I read your last note. I've pretty much followed the recommendations from the site link you gave me. Things seemed to be improved enough that I can live with it. The main issue I still have is Mozilla Thunderbird not loading when the computer is rebooted. I've tried everything I know but no luck. I still have to load/unload it several times before it finally loads to download mail. Mozilla's site is no help. I suspect they have a glitch in the latest version 2.0.0.17 as the previous versions never had the problem. Thanks for your patience and assistance! Taz
Hi tasman27

Log looks good :thumbup:

You can now delete any other tools I had you download and use, unless you wish to keep them.


Set correct settings for files that should be hidden in Windows XP
  • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
  • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
  • If unchecked please checkHide protected operating system files (Recommended)
  • If necessary check "Display content of system folders"
  • If necessary Uncheck Hide file extensions for known file types.
  • Click OK
As far as I can see, all your malware problems are gone. Luckily, this is not the end of our expertise here at WhatTheTech. We have tech helpers working in other areas of this site that will be more than happy to assist with the other problems that you are experiencing.
So, I recommend you start a new topic in one of the following forums:
Microsoft Windows
Browsers, Internet and Email

Describe what problems you are having, and include a link to this topic so they can see what has already been done.

The response time over there is usually very good, and you should be receiving expert help from one of our advisers shortly.


Now that your system appears to be clean, theres just a few steps I'd like you to take to prevent any future infections.
  • System restore:
    We will now clear your existing system restore points and establish a new clean restore point:
    • Go to Start > All Programs > Accessories > System Tools > System Restore
    • Select Create a restore point, and Ok it.
    • Next, go to Start > Run and type in cleanmgr
    • Select the More options tab
    • Choose the option to clean up system restore and OK it.

      This will remove all restore points except the new one you just created.
    Make sure you do this now, as your System Restore currently has infected files in it.

  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI