Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

May Have Cnn Alert Trojan


  • This topic is locked This topic is locked
15 replies to this topic

#1 jsu627

jsu627

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 23 September 2008 - 06:27 PM

I got dinged by the CNN Alert Trojan, and have spent a lot of time trying to remove it with Webroot Spy Sweeper. Spy Sweeper appears to have removed the exe file, but not traces in the registry. I corresponded with their support, but they couldn't help. I also have Norton on my system, perhaps there are better tools now, but I went to college with Peter, so I use it out of loyalty. I have also used counterspy from sunbelt.

In the course of using the procedures suggested before making this post, I got rid of a lot of stuff, including, I think, the 16 traces of the CNN Trojan in my registry. However, I really need to make sure I don't have any password stealers left, so I am submitting the Hijackthis log.

Although likely unrelated, my audio quit about the same time I started going through this. I hear the Windows song on start up, but nothing else, either web audio or CD's gets out of my box. I've switched cables, and fiddled with the ASUS sound utility, but to no avail.

Thanks for taking a look at this!

John

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:12:06 PM, on 9/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBAMTray.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Mozy\mozybackup.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\WinTV\Ir.exe
C:\Program Files\Mozy\mozystat.exe
C:\Program Files\ASUS\Asus Probe\ASUSPROB.EXE
C:\Program Files\FileBX\FileBX.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\WinTidy\WinTidy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\EUDORA 7\Eudora.exe
C:\Program Files\Info Select 8\is.exe
C:\PROGRA~1\MICROS~3\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [CoolSwitch] "C:\WINDOWS\system32\taskswitch.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] "C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" -onlytray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] "C:\WINDOWS\system32\dumprep.exe" 0 -k
O4 - HKLM\..\Run: [SoundMan] "C:\WINDOWS\SOUNDMAN.EXE"
O4 - HKLM\..\Run: [SBAMTray] "C:\Program Files\Sunbelt Software\CounterSpy\SBAMTray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Picasa Media Detector] "C:\Program Files\Picasa2\PicasaMediaDetector.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] "C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: AutorunsDisabled
O4 - Startup: FileBox eXtender.lnk = C:\Program Files\FileBX\FileBX.exe
O4 - Startup: Norton Internet Security.lnk = ?
O4 - Startup: WinTidy.lnk = C:\Program Files\WinTidy\WinTidy.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O4 - Global Startup: Mozy Status.lnk = C:\Program Files\Mozy\mozystat.exe
O4 - Global Startup: Probe V2.24.10.lnk = ?
O8 - Extra context menu item: &Save Flash In This Page by Flash Saver - C:\PROGRA~1\FLASHS~1\save.htm
O8 - Extra context menu item: Copy to Semagic - C:\Program Files\Semagic\copy.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Semagic - C:\Program Files\Semagic\link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1221580891203
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Unknown owner - C:\Program Files\Mozy\mozybackup.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Sunbelt VIPRE Antivirus Service (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 12812 bytes

BC AdBot (Login to Remove)

 


m

#2 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:04:18 PM

Posted 03 October 2008 - 02:45 PM

:thumbsup: to BleepingComputer.com

I want to apologise that it has taken so long to get back to you. We on the HJT Team are working as fast as possible to get your log answered.

If you do not still need help, please let me know, so that I can move on to other users who still need help.

Please take note of the following:
  • While a HJT Team member is working with you, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. :)
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Please reply using the Posted Image button in the lower left hand corner of your screen.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave, and if there is no contact for that amount of time I will have to assume you have "vanished" :).
If you would still like help, please follow the instructions below:

We need to create an OTViewIt Report
  • Please download OTViewIt by OldTimer.
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
  • OTViewIt.txt <-- Will be opened
  • Extra.txt <-- Will be minimized
Please do an online scan with Kaspersky WebScanner.
  • Please visit the Kaspersky Online Scanner website.
    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
In your next reply, please include the following:
  • OTViewIt.txt
  • Extra.txt
  • Kaspersky's Log

Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#3 jsu627

jsu627
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 03 October 2008 - 09:07 PM

Thanks for your response. I have run the OTViewIt and Kaspersky scans. Logs are below:

Hope this helps, and many thanks again,

John

***********************************

OTViewIt logfile created on: 10/3/2008 4:02:10 PM - Run 2
OTViewIt by OldTimer - Version 1.0.9.2 Folder = C:\Documents and Settings\JSU\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.83 Gb Available Physical Memory | 41.35% Memory free
3.35 Gb Paging File | 2.46 Gb Available in Paging File | 73.54% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 23.17 Gb Free Space | 31.09% Space Free | Partition Type: NTFS
Drive D: | 279.47 Gb Total Space | 82.53 Gb Free Space | 29.53% Space Free | Partition Type: NTFS
Drive E: | 279.47 Gb Total Space | 11.03 Gb Free Space | 3.95% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOHN
Current User Name: JSU
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2008/01/31 14:15:06 | 00,149,864 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
[2008/01/23 14:56:45 | 01,251,720 | ---- | M] () -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
[2008/09/22 13:00:53 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
[2001/08/23 18:37:39 | 00,167,936 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Hardware\Mouse\point32.exe
[2005/10/11 21:01:06 | 00,419,408 | ---- | M] (Acronis) -- C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
[2005/10/11 21:01:06 | 00,069,632 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
[2002/03/19 17:30:00 | 00,045,632 | ---- | M] () -- C:\WINDOWS\system32\TaskSwitch.exe
[2005/06/29 15:29:26 | 00,176,128 | ---- | M] (Nokia) -- C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[2008/06/10 04:27:04 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[2008/01/31 14:15:06 | 00,149,864 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
[2004/11/15 03:20:20 | 00,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
[2008/08/26 17:29:20 | 00,677,160 | ---- | M] (Sunbelt Software) -- C:\Program Files\Sunbelt Software\CounterSpy\SBAMTray.exe
[2008/08/09 16:04:58 | 05,418,864 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
[2008/04/13 17:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
[2008/02/25 18:23:34 | 00,443,968 | ---- | M] (Google Inc.) -- C:\Program Files\Picasa2\PicasaMediaDetector.exe
[2005/08/30 11:31:18 | 00,118,272 | ---- | M] (Nokia.) -- C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
[2008/06/09 10:16:32 | 02,363,392 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
[2005/10/11 21:01:06 | 00,151,552 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
[2004/07/21 16:26:36 | 00,176,241 | ---- | M] (American Power Conversion Corporation) -- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
[2006/09/29 11:01:06 | 00,258,560 | -H-- | M] (ASUSTeK COMPUTER INC.) -- C:\WINDOWS\ATKKBService.exe
[2007/08/31 11:49:50 | 00,243,064 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
[2008/06/09 10:21:58 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
[2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
[2007/05/09 08:27:42 | 00,087,608 | ---- | M] () -- C:\Program Files\Mozy\mozybackup.exe
[2007/06/04 12:47:20 | 00,106,551 | ---- | M] (Hauppauge Computer Works) -- C:\Program Files\WinTV\Ir.exe
[2008/07/14 08:26:02 | 02,311,472 | ---- | M] () -- C:\Program Files\Mozy\mozystat.exe
[2002/12/06 16:07:48 | 00,617,984 | ---- | M] () -- C:\Program Files\ASUS\Asus Probe\AsusProb.exe
[2004/07/21 16:28:02 | 00,413,807 | ---- | M] (American Power Conversion Corporation) -- C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
[2007/01/22 13:29:22 | 00,512,000 | ---- | M] (Hyperionics Technology LLC) -- C:\Program Files\FileBX\FileBX.exe
[2008/08/09 14:42:02 | 03,585,384 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
[2001/10/08 06:14:20 | 00,585,216 | ---- | M] (Ziff Davis Media, Inc.) -- C:\Program Files\WinTidy\WinTidy.exe
[2008/04/13 17:12:21 | 00,267,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\fxssvc.exe
[2008/08/26 17:20:46 | 00,869,672 | ---- | M] (Sunbelt Software) -- C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe
[2005/08/26 19:12:04 | 07,286,851 | ---- | M] (Micro Logic, Corp.) -- C:\Program Files\Info Select 8\is.exe
[2008/01/11 11:23:38 | 00,050,184 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
[2008/06/30 14:21:54 | 10,740,744 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
[2008/06/30 14:21:54 | 10,740,744 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
[2001/07/03 09:17:04 | 00,065,536 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
[2008/09/28 06:47:11 | 00,307,712 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2006/10/04 09:04:20 | 02,658,304 | R--- | M] (QUALCOMM Incorporated) -- C:\Program Files\EUDORA 7\Eudora.exe
[2008/08/09 14:42:02 | 00,181,608 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\Program Files\Webroot\Spy Sweeper\SSU.exe
[2008/10/03 15:55:41 | 00,419,840 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JSU\Desktop\OTViewIt.exe

========== (O23) Win32 Services ==========

[2008/09/22 13:00:53 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice [Auto | Running])
[2005/10/11 21:01:06 | 00,151,552 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc [Auto | Running])
[2004/07/21 16:26:36 | 00,176,241 | ---- | M] (American Power Conversion Corporation) -- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe -- (APC UPS Service [Auto | Running])
[2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2006/09/29 11:01:06 | 00,258,560 | -H-- | M] (ASUSTeK COMPUTER INC.) -- C:\WINDOWS\ATKKBService.exe -- (ATKKeyboardService [Auto | Running])
[2007/08/31 11:49:50 | 00,243,064 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler [Auto | Running])
[2008/01/31 14:15:06 | 00,149,864 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE -- (ccEvtMgr [Auto | Running])
[2008/01/31 14:15:06 | 00,149,864 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE -- (ccSetMgr [Auto | Running])
[2008/04/13 17:12:14 | 00,005,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cisvc.exe -- (cisvc [On_Demand | Stopped])
[2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2008/01/31 14:15:06 | 00,149,864 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE -- (CLTNetCnService [Auto | Running])
[2007/08/22 00:21:30 | 00,055,640 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe -- (comHost [On_Demand | Stopped])
[2008/04/13 17:12:21 | 00,267,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\fxssvc.exe -- (Fax [Auto | Stop_Pending])
[2005/04/29 18:21:06 | 00,139,264 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM) [On_Demand | Stopped])
[2004/11/30 11:08:56 | 00,020,543 | ---- | M] (Apache Software Foundation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe -- (ForcewareWebInterface [On_Demand | Stopped])
[2007/01/03 18:40:21 | 00,136,120 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
[2007/02/20 15:11:28 | 00,815,104 | ---- | M] (Hauppauge Computer Works) -- C:\Program Files\WinTV\HCWTVServer.exe -- (HauppaugeTVServer [On_Demand | Stopped])
[2003/04/01 22:08:30 | 00,069,632 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\IcdSptSv.exe -- (ICDSPTSV [On_Demand | Stopped])
[2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2008/06/09 10:21:58 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
[2007/08/23 13:35:22 | 03,192,184 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE -- (LiveUpdate [On_Demand | Stopped])
[2008/01/31 14:15:06 | 00,149,864 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE -- (LiveUpdate Notice [Auto | Running])
[2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe -- (MDM [Auto | Running])
[2007/05/09 08:27:42 | 00,087,608 | ---- | M] () -- C:\Program Files\Mozy\mozybackup.exe -- (mozybackup [Auto | Running])
[2005/04/29 18:18:24 | 00,131,136 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe -- (nSvcIp [On_Demand | Stopped])
[2005/04/29 18:18:08 | 00,057,412 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe -- (nSvcLog [On_Demand | Stopped])
[2007/01/25 10:31:34 | 00,093,048 | ---- | M] (CACE Technologies) -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd [On_Demand | Stopped])
[2008/08/26 17:20:46 | 00,869,672 | ---- | M] (Sunbelt Software) -- C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe -- (SBAMSvc [Auto | Running])
[2008/01/23 14:56:45 | 01,251,720 | ---- | M] () -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC [Auto | Running])
[2008/04/13 17:12:38 | 00,073,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\tlntsvr.exe -- (TlntSvr [On_Demand | Stopped])
[2008/08/09 14:42:02 | 03,585,384 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe -- (WebrootSpySweeperService [Auto | Running])
[2006/11/03 19:19:58 | 00,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend [Auto | Stopped])
[2006/10/18 21:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services ==========

File not found -- C:\5a15c3d05b32fc85.dat -- (5a15c3d05b32fc85 [On_Demand | Stopped])
[2008/04/13 11:46:20 | 00,048,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\61883.sys -- (61883 [On_Demand | Stopped])
[2004/11/17 20:05:38 | 02,297,664 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
[2005/03/09 15:53:00 | 00,036,352 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8 [System | Running])
[2004/03/10 14:31:18 | 00,003,328 | ---- | M] () -- C:\WINDOWS\system32\drivers\AsInsHelp32.sys -- (ASInsHelp [Auto | Running])
[2004/10/14 02:52:28 | 00,004,962 | ---- | M] () -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO [System | Running])
[1997/04/22 10:16:00 | 00,006,272 | ---- | M] () -- C:\WINDOWS\system32\drivers\ASLM75.SYS -- (aslm75 [System | Running])
[2006/10/31 16:55:38 | 00,011,008 | ---- | M] (ASUSTeK COMPUTER INC.) -- C:\WINDOWS\system32\drivers\atkkbnt.sys -- (asuskbnt [System | Running])
[2008/04/13 11:46:20 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\avc.sys -- (Avc [On_Demand | Stopped])
[2000/07/24 02:01:00 | 00,019,537 | ---- | M] (Brother Industries Ltd.) -- C:\WINDOWS\system32\drivers\BRPAR.SYS -- (BrPar [Auto | Running])
[2008/04/13 11:46:23 | 00,017,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ccdecode.sys -- (CCDECODE [On_Demand | Stopped])
[2008/07/30 17:42:12 | 00,023,888 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon [On_Demand | Stopped])
[2007/08/08 16:39:56 | 00,036,056 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\CO_Mon.sys -- (CO_Mon [Auto | Running])
File not found -- C:\e1156cd8ea126d58.dat -- (e1156cd8ea126d58 [On_Demand | Stopped])
File not found -- C:\ed4133b8c68c615a.dat -- (ed4133b8c68c615a [On_Demand | Stopped])
[2008/09/02 01:00:00 | 00,371,248 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl [System | Running])
[2006/06/14 14:44:30 | 00,012,288 | R--- | M] (ASUSTeK Computer Inc.) -- C:\WINDOWS\system32\drivers\EIO.sys -- (EIO [Auto | Running])
[2007/03/22 13:57:14 | 00,028,672 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\drivers\elagopro.sys -- (elagopro [Auto | Running])
[2007/03/22 13:57:14 | 00,005,376 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\drivers\elaunidr.sys -- (elaunidr [Auto | Running])
[2008/09/02 01:00:00 | 00,099,376 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv [On_Demand | Running])
File not found -- C:\f725fb005c50b854.dat -- (f725fb005c50b854 [On_Demand | Stopped])
[2008/04/13 11:45:29 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum [On_Demand | Running])
[2007/02/27 15:40:54 | 00,150,784 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\drivers\HCWUSB2AV.sys -- (hcwAVD2 [On_Demand | Running])
[2008/04/13 11:36:38 | 00,020,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\hidbatt.sys -- (HidBatt [On_Demand | Stopped])
[2002/11/28 21:23:24 | 00,039,048 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\drivers\IcdUsb2.sys -- (ICDUSB2 [On_Demand | Stopped])
[2001/08/23 00:33:10 | 00,010,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ipfilter.sys -- (IPFilter [On_Demand | Running])
[2008/07/14 08:25:28 | 00,053,752 | ---- | M] (Mozy, Inc.) -- C:\WINDOWS\system32\drivers\mozy.sys -- (mozyFilter [System | Running])
[2008/04/13 11:46:22 | 00,015,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE [On_Demand | Stopped])
[2008/04/13 11:46:09 | 00,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\msdv.sys -- (MSDV [On_Demand | Stopped])
[2008/04/13 11:39:50 | 00,005,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\mstee.sys -- (MSTEE [On_Demand | Stopped])
[2001/08/17 07:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401 [On_Demand | Running])
[2004/08/12 19:56:20 | 00,005,810 | ---- | M] () -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor [On_Demand | Running])
[2008/04/13 11:46:25 | 00,085,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\nabtsfec.sys -- (NABTSFEC [On_Demand | Stopped])
[2008/08/20 01:00:00 | 00,089,104 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081003.003\NAVENG.SYS -- (NAVENG [On_Demand | Running])
[2008/08/20 01:00:00 | 00,873,552 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081003.003\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
[2008/04/13 11:46:22 | 00,010,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ndisip.sys -- (NdisIP [On_Demand | Stopped])
[2008/04/13 11:53:09 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm [On_Demand | Stopped])
[2007/01/25 10:31:34 | 00,042,000 | ---- | M] (CACE Technologies) -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF [On_Demand | Stopped])
[2005/05/17 02:45:08 | 00,092,800 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvata.sys -- (nvata [Boot | Running])
[2005/04/05 12:22:28 | 00,033,536 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
[2005/04/05 12:22:30 | 00,012,928 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
[2005/04/05 12:22:20 | 00,100,096 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\NVTCP.SYS -- (NVTCP [System | Running])
[2004/01/12 01:51:44 | 01,252,474 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\P1120Vid.sys -- (P1120VID [On_Demand | Running])
[2008/06/19 17:24:30 | 00,028,544 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot [Boot | Running])
[2001/08/23 05:00:00 | 00,003,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\pciide.sys -- (PCIIde [Boot | Running])
[2008/04/13 11:31:30 | 00,035,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\processr.sys -- (Processor [System | Stopped])
[2001/08/23 05:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2008/02/22 19:38:33 | 00,043,872 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2001/08/23 05:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\rootmdm.sys -- (ROOTMODEM [On_Demand | Running])
[2007/11/06 10:00:58 | 00,087,848 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\system32\drivers\SBREDrv.sys -- (SBRE [On_Demand | Running])
File not found -- C:\WINDOWS\system32\DDMI2.sys -- (SDDMI2 [On_Demand | Stopped])
[2007/11/13 03:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [Auto | Running])
[2003/11/30 19:54:20 | 00,043,136 | ---- | M] (Prolific Technology Inc.) -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl [On_Demand | Stopped])
[2005/03/31 11:32:42 | 00,175,104 | ---- | M] (Silicon Image, Inc) -- C:\WINDOWS\system32\drivers\Si3114r5.sys -- (Si3114r5 [Boot | Running])
[2004/11/01 12:21:32 | 00,010,368 | ---- | M] (Silicon Image, Inc.) -- C:\WINDOWS\system32\drivers\SiWinAcc.sys -- (SiFilter [Boot | Running])
[2008/04/13 11:46:23 | 00,011,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\slip.sys -- (SLIP [On_Demand | Stopped])
[2005/10/11 21:01:02 | 00,082,400 | ---- | M] (Acronis) -- C:\WINDOWS\system32\drivers\snapman.sys -- (snapman [Boot | Running])
[2007/08/17 14:23:28 | 00,446,512 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv [System | Running])
[2007/12/01 00:57:12 | 00,279,088 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP [On_Demand | Running])
[2007/12/01 00:57:12 | 00,317,616 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL [On_Demand | Stopped])
[2007/12/01 00:57:12 | 00,043,696 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX [System | Running])
[2008/08/09 14:42:12 | 00,029,808 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\WINDOWS\system32\drivers\ssfs0bbc.sys -- (ssfs0bbc [Boot | Running])
[2008/08/09 14:42:14 | 00,023,152 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\WINDOWS\system32\drivers\sshrmd.sys -- (SSHRMD [Boot | Running])
[2008/08/09 14:42:14 | 00,166,512 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\WINDOWS\system32\drivers\ssidrv.sys -- (SSIDRV [Boot | Running])
[2008/01/04 21:34:36 | 00,023,920 | ---- | M] (Webroot Software Inc (www.webroot.com)) -- C:\WINDOWS\system32\drivers\sskbfd.sys -- (SSKBFD [On_Demand | Running])
[2008/04/13 11:46:21 | 00,015,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\streamip.sys -- (streamip [On_Demand | Stopped])
[2008/06/13 14:13:38 | 00,013,616 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symdns.sys -- (SYMDNS [On_Demand | Running])
[2008/05/30 18:30:52 | 00,123,952 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
[2008/06/13 14:13:38 | 00,096,432 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symfw.sys -- (SYMFW [On_Demand | Running])
[2008/06/13 14:13:38 | 00,038,576 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symids.sys -- (SYMIDS [On_Demand | Running])
[2008/09/12 00:33:21 | 00,250,224 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20080926.005\SymIDSCo.sys -- (SYMIDSCO [On_Demand | Running])
[2008/06/13 14:14:02 | 00,031,280 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIM [On_Demand | Stopped])
[2008/06/13 14:14:02 | 00,031,280 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIMMP [On_Demand | Running])
[2006/10/16 07:01:05 | 00,010,344 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd [Auto | Running])
[2008/06/13 14:13:38 | 00,037,424 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symndis.sys -- (SYMNDIS [On_Demand | Running])
[2008/06/13 14:13:38 | 00,022,320 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symredrv.sys -- (SYMREDRV [On_Demand | Running])
[2008/06/13 14:13:40 | 00,184,240 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symtdi.sys -- (SYMTDI [System | Running])
[2005/10/11 21:01:03 | 00,028,896 | ---- | M] (Acronis) -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter [Auto | Running])
[2005/10/11 21:01:03 | 00,211,520 | ---- | M] (Acronis) -- C:\WINDOWS\system32\drivers\timntr.sys -- (timounter [Boot | Running])
[2008/04/13 11:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Running])
[2008/04/13 11:45:35 | 00,030,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbehci.sys -- (usbehci [On_Demand | Running])
[2008/04/13 11:45:35 | 00,017,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbohci.sys -- (usbohci [On_Demand | Running])
[2006/09/29 11:06:26 | 00,010,752 | ---- | M] (ASUSTeK COMPUTER INC.) -- C:\WINDOWS\system32\drivers\Video3D32.sys -- (Video3D [On_Demand | Running])
[2001/08/23 05:00:00 | 00,012,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ws2ifsl.sys -- (WS2IFSL [System | Running])
[2008/04/13 11:46:24 | 00,019,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wstcodec.sys -- (WSTCODEC [On_Demand | Stopped])
[2006/09/28 19:55:50 | 00,077,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\WudfPf.sys -- (WudfPf [On_Demand | Stopped])
[2006/09/28 20:00:34 | 00,082,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\WudfRd.sys -- (WudfRd [On_Demand | Stopped])
[2005/09/19 08:41:00 | 00,241,280 | ---- | M] (Marvell) -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp [On_Demand | Running])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.google.com/ie
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.google.com
"SearchMigratedDefaultName"=Google
"SearchMigratedDefaultURL"=http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
"Secondary Start Pages"=
"Start Page"=http://www.google.com/

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search]
"Default_Search_URL"=http://www.google.com/ie

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=http://www.google.com/keyword/%s

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.google.com/ie
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.google.com
"SearchMigratedDefaultName"=Google
"SearchMigratedDefaultURL"=http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
"Secondary Start Pages"=
"Start Page"=http://www.google.com/

[HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Search]
"Default_Search_URL"=http://www.google.com/ie

[HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\Software\Microsoft\Internet Explorer\SearchURL]
""=http://www.google.com/keyword/%s

[HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} (HKLM) -- C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
{6D53EC84-6AAE-4787-AEEE-F4628F01010C} (HKLM) -- C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)

========== (O3) Toolbars ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" (HKLM) -- C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" (HKLM) -- C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" (HKLM) -- C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
""= File not found
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" (Acronis)
"Acronis True Image Monitor"="C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe" (Acronis)
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" ()
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep.exe" 0 -k (Microsoft Corporation)
"NWEReboot"= File not found
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" (Symantec Corporation)
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" -onlytray (Nokia)
"POINTER"=point32.exe File not found
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
"SBAMTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBAMTray.exe" (Sunbelt Software)
"SoundMan"="C:\WINDOWS\SOUNDMAN.EXE" (Realtek Semiconductor Corp.)
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray (Webroot Software, Inc.)
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden (Hewlett-Packard Company)
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" (Google Inc.)
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" (Safer Networking Limited)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden (Hewlett-Packard Company)
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" (Google Inc.)
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" (Safer Networking Limited)

========== (O4) Startup Folders ==========

[2004/07/21 16:17:16 | 00,221,295 | ---- | M] (American Power Conversion Corporation) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
[2008/03/15 14:47:00 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
[2007/06/04 12:47:20 | 00,106,551 | ---- | M] (Hauppauge Computer Works) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
[2008/07/14 08:26:02 | 02,311,472 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Mozy Status.lnk = C:\Program Files\Mozy\mozystat.exe
[2002/12/06 16:07:48 | 00,617,984 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Probe V2.24.10.lnk = C:\Program Files\ASUS\Asus Probe\AsusProb.exe
[2008/03/15 14:46:45 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\JSU\Start Menu\Programs\Startup\AutorunsDisabled
[2007/01/22 13:29:22 | 00,512,000 | ---- | M] (Hyperionics Technology LLC) -- C:\Documents and Settings\JSU\Start Menu\Programs\Startup\FileBox eXtender.lnk = C:\Program Files\FileBX\FileBX.exe
File not found -- C:\Documents and Settings\JSU\Start Menu\Programs\Startup\Norton Internet Security.lnk = C:\Program Files\Common Files\Symantec Shared\NMAIN.EXE
[2001/10/08 06:14:20 | 00,585,216 | ---- | M] (Ziff Davis Media, Inc.) -- C:\Documents and Settings\JSU\Start Menu\Programs\Startup\WinTidy.lnk = C:\Program Files\WinTidy\WinTidy.exe

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=255
"_NoDriveTypeAutoRun"=145

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=255
"_NoDriveTypeAutoRun"=145

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
&Save Flash In This Page by Flash Saver: C:\Program Files\Flash Saver\save.htm [2006/06/09 10:38:20 | 00,002,999 | ---- | M] ()
Copy to Semagic: C:\Program Files\Semagic\copy.htm [2007/02/11 15:33:07 | 00,000,267 | ---- | M] ()
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office10\EXCEL.EXE [2008/06/20 14:37:18 | 09,068,544 | R--- | M] (Microsoft Corporation)
Semagic: C:\Program Files\Semagic\link.htm [2007/02/11 15:33:07 | 00,000,186 | ---- | M] ()

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Sun Java Console -- C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
{09EA1F80-F40A-11D1-B792-444553540001}: Flash Saver -- C:\Program Files\Flash Saver\save.htm ()
{09EA1F80-F40A-11D1-B792-444553540001}: Flash Saver -- C:\Program Files\Flash Saver\save.htm ()
{85d1f590-48f4-11d9-9669-0800200c9a66}: Uninstall BitDefender Online Scanner v8 -- C:\WINDOWS\bdoscandel.exe ()
{B13B4423-2647-4cfc-A4B3-C7D56CB83487}: Share in Hello -- C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
{B13B4423-2647-4cfc-A4B3-C7D56CB83487}: Share in H&ello -- C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Spybot - Search & Destroy Configuration -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: @xpsp3res.dll,-20001 -- C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Messenger -- C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Windows Messenger -- C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
3 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
: msn in My Computer

[HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
: msn in My Computer

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{17492023-C23A-453E-A040-C7C580BBF700}: http://download.microsoft.com/download/5/b...heckControl.cab -- Windows Genuine Advantage Validation Tool
{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}: http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab -- ActiveScan 2.0 Installer Class
{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}: http://download.bitdefender.com/resources/scan8/oscan8.cab -- BDSCANONLINE Control
{644E432F-49D3-41A1-8DD5-E099162EEEC5}: http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab -- Symantec RuFSI Utility Class
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}: http://update.microsoft.com/microsoftupdat...b?1221580891203 -- MUWebControl Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_03
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_05
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab -- Shockwave Flash Object

========== (O17) DNS Name Servers ==========

{0F31A890-745A-481E-B299-357E769A5F21} (Servers: | Description: )
{AFDD09B9-F1BE-4385-950A-85BE8697A54C} (Servers: | Description: 1394 Net Adapter)
{B927ABE0-43FD-491F-918D-265BC16E2176} (Servers: | Description: Marvell Yukon 88E8001/8003/8010 PCI Gigabit Ethernet Controller)
{CB752939-8410-4619-A23C-4BF3CEAE6103} (Servers: | Description: )

========== (O20) Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
WgaLogon: "DllName" = WgaLogon.dll -- C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)

========== (O21) SSODL Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"UPnPMonitor"={e57ce738-33e8-4c51-8354-bb4de9d215d1} (HKLM) -- C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)
"WPDShServiceObj"={AAA288BA-9A4C-45B0-95D7-94D524869DB5} (HKLM) -- C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" (HKLM) -- C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
"{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}" (HKLM) -- C:\WINDOWS\system32\wyrsdj.dll File not found
"{6BBAA1E6-CF54-4139-AB9C-8491A9F909D7}" (HKLM) -- C:\WINDOWS\system32\wfrdvq.dll File not found
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}" (HKLM) -- C:\Program Files\Eudora 6.2\EuShlExt.dll File not found

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
[2005/10/08 05:50:10 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]

========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c9c0303-37bc-11da-8362-806d6172696f}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c9c0303-37bc-11da-8362-806d6172696f}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c9c0303-37bc-11da-8362-806d6172696f}\Shell\AutoRun\command]
""=F:\ASUSACPI.exe -- File not found


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7893ffc9-d6e4-11dc-92e1-0013d4a4667b}\Shell\AutoRun\command]
""=L:\setupSNK.exe -- File not found

========== Files/Folders - Created Within 30 Days ==========

[7 C:\WINDOWS\*.tmp files]
[2008/10/03 15:55:34 | 00,419,840 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\JSU\Desktop\OTViewIt.exe
[2008/09/30 01:14:38 | 00,008,084 | ---- | C] () -- C:\WINDOWS\mozy.flt
[2008/09/30 01:14:38 | 00,004,584 | ---- | C] () -- C:\WINDOWS\mozy.blk
[2008/09/28 19:40:16 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2008/09/28 19:40:16 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2008/09/23 08:59:02 | 02,482,695 | ---- | C] (McAfee Inc.) -- C:\Documents and Settings\JSU\Desktop\stinger.exe
[2008/09/23 06:12:13 | 00,000,000 | ---D | C] -- C:\Security Threat Logs
[2008/09/22 22:00:13 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\pavboot.sys
[2008/09/22 22:00:03 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2008/09/22 21:49:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\BDOSCAN8
[2008/09/22 18:31:55 | 00,000,977 | ---- | C] () -- C:\Documents and Settings\JSU\Desktop\Spybot - Search & Destroy.lnk
[2008/09/22 18:31:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/09/22 17:37:13 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2008/09/22 13:12:34 | 15,083,520 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\JSU\Desktop\spybotsd160.exe
[2008/09/22 12:59:56 | 00,000,837 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Watch.lnk
[2008/09/22 12:59:56 | 00,000,837 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2008/09/22 12:59:53 | 00,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2008/09/22 12:59:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/09/22 12:56:36 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2008/09/21 21:54:48 | 00,001,778 | ---- | C] () -- C:\Documents and Settings\JSU\Desktop\HijackThis.lnk
[2008/09/21 21:54:48 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2008/09/17 13:58:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\JSU\Application Data\Sunbelt
[2008/09/17 13:58:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sunbelt
[2008/09/17 13:57:59 | 00,001,813 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CounterSpy.lnk
[2008/09/17 13:57:48 | 00,000,000 | ---D | C] -- C:\Program Files\Sunbelt Software

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2008/10/03 15:55:41 | 00,419,840 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JSU\Desktop\OTViewIt.exe
[2008/10/02 19:43:31 | 00,008,084 | ---- | M] () -- C:\WINDOWS\mozy.flt
[2008/10/02 19:43:31 | 00,004,584 | ---- | M] () -- C:\WINDOWS\mozy.blk
[2008/10/02 19:34:43 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/09/29 09:00:02 | 00,001,766 | ---- | M] () -- C:\WINDOWS\tasks\wrSpySweeper_LDAE20F3256BE4D8FAD4B09D4E8906455.job
[2008/09/28 19:40:16 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2008/09/28 19:40:16 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2008/09/28 17:01:29 | 00,001,856 | -H-- | M] () -- C:\Documents and Settings\JSU\My Documents\Default.rdp
[2008/09/28 11:18:26 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/09/28 11:18:09 | 00,012,692 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008/09/28 11:17:58 | 00,002,048 | -H-- | M] () -- C:\WINDOWS\bootstat.dat
[2008/09/26 22:52:35 | 00,000,618 | ---- | M] () -- C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - JSU.job
[2008/09/26 07:21:04 | 00,001,646 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2008/09/23 08:59:06 | 02,482,695 | ---- | M] (McAfee Inc.) -- C:\Documents and Settings\JSU\Desktop\stinger.exe
[2008/09/22 18:31:55 | 00,000,977 | ---- | M] () -- C:\Documents and Settings\JSU\Desktop\Spybot - Search & Destroy.lnk
[2008/09/22 13:12:44 | 15,083,520 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\JSU\Desktop\spybotsd160.exe
[2008/09/22 12:59:56 | 00,000,837 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Watch.lnk
[2008/09/22 12:59:56 | 00,000,837 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2008/09/21 22:20:57 | 00,000,828 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Quicken 2006 Premier.lnk
[2008/09/21 21:54:48 | 00,001,778 | ---- | M] () -- C:\Documents and Settings\JSU\Desktop\HijackThis.lnk
[2008/09/20 20:37:08 | 00,000,116 | -H-- | M] () -- C:\WINDOWS\NeroDigital.ini
[2008/09/17 13:57:59 | 00,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CounterSpy.lnk
[2008/09/15 12:16:24 | 00,000,426 | -H-- | M] () -- C:\WINDOWS\BRWMARK.INI
[2008/09/11 15:11:25 | 00,030,720 | ---- | M] () -- C:\Documents and Settings\JSU\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/11 10:01:14 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
< End of report >

*************************

OTViewIt Extras logfile created on: 10/3/2008 4:02:10 PM - Run 2
OTViewIt by OldTimer - Version 1.0.9.2 Folder = C:\Documents and Settings\JSU\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.83 Gb Available Physical Memory | 41.35% Memory free
3.35 Gb Paging File | 2.46 Gb Available in Paging File | 73.54% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 23.17 Gb Free Space | 31.09% Space Free | Partition Type: NTFS
Drive D: | 279.47 Gb Total Space | 82.53 Gb Free Space | 29.53% Space Free | Partition Type: NTFS
Drive E: | 279.47 Gb Total Space | 11.03 Gb Free Space | 3.95% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOHN
Current User Name: JSU
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] --

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify"=1
"FirewallDisableNotify"=1
"UpdatesDisableNotify"=0
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 17:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008/04/13 11:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/13 17:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2004/11/30 11:08:56 | 00,020,543 | ---- | M] (Apache Software Foundation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server
[2005/08/26 19:12:04 | 07,286,851 | ---- | M] (Micro Logic, Corp.) -- C:\Program Files\Info Select 8\is.exe:*:Enabled:Info Select
File not found -- C:\Program Files\SmartFTP\SmartFTP.exe:*:Enabled:SmartFTP Client
[2008/04/13 11:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/11/09 11:47:40 | 03,643,192 | ---- | M] (SightSpeed Inc.) -- C:\Program Files\SightSpeed\SightSpeed.exe:*:Enabled:SightSpeed

========== HKEY_USERS Protocol Defaults ==========


[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
shell -- shell protocol not assigned

========== HKEY_USERS Protocol Defaults ==========


[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
shell -- shell protocol not assigned

========== HKEY_USERS Protocol Defaults ==========


[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
shell -- shell protocol not assigned

========== HKEY_USERS Protocol Defaults ==========


[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
shell -- shell protocol not assigned

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2004/01/29 07:08:23 | 00,868,352 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (cdo:{CD00020A-8B95-11D1-82DB-00C04FB1625D} (HKLM) [Microsoft PKM KnowledgePluggable Class])
ipp: [HKLM - No CLSID value]
[2004/01/29 07:08:23 | 01,130,496 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
msdaipp: [HKLM - No CLSID value]
[2004/01/29 07:08:23 | 01,130,496 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[2004/01/29 07:08:23 | 01,130,496 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]
[2000/04/19 18:47:36 | 00,520,117 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (ms-itss:{0A9007C0-4076-11D3-8789-0000F8105754} (HKLM) [Microsoft Infotech Storage Protocol for IE 4.0])
[2008/01/24 15:22:56 | 07,255,384 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01BDFB08-EE88-4E5E-94A6-AE9EDCFA40C5}"=Microsoft IntelliPoint 4.0
"{07CC76F1-0697-497C-BD47-EB5661AACD4D}"=Eudora
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}"=Symantec KB-DocID:2003093015493306
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}"=LightScribe System Software 1.14.17.1
"{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}"=Cool & Quiet
"{1CB92574-96F2-467B-B793-5CEB35C40C29}"=Image Resizer Powertoy for Windows XP
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}"=Google Earth
"{1F5B0556-0FD4-4AD9-9545-43C13B5A85C5}"=SymNet
"{1F6423DE-7959-4178-80E0-023C7EAA5347}"=NVIDIA ForceWare Network Access Manager
"{2227E1FA-01F5-483C-AB0E-2A308E900B3D}"=InterVideo FilterSDK for Hauppauge
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}"=Quicken 2006
"{29C22873-B939-4EF9-B6E3-1EFE7FA392D1}"=ASUS nVidia Driver
"{2FBF04DC-404C-4FA4-BA28-99903080D2B9}"=Magnifier Powertoy for Windows XP
"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}"=Component Framework
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}"=ASUS Gamer OSD
"{3248F0A8-6813-11D6-A77B-00B0D0150050}"=J2SE Runtime Environment 5.0 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0150060}"=J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150100}"=J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}"=J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}"=Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}"=Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}"=Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}"=Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{3C1599DA-9ED9-4090-930F-B8BC4D99D6B0}"=Nokia Connectivity Cable Driver
"{3EB8267F-CAB5-4C8B-B2BC-24B48E1CCF15}"=CounterSpy
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}"=Spy Sweeper Core
"{48606B2A-EECD-4C8D-AC0E-A21C6F7C2026}"=Eudora
"{48B82226-75E3-4E90-92CC-D30F79EA6380}"=Norton Security Scan
"{4E475FD4-4513-4B1D-8DDA-43912B068C99}"=HTML Slideshow Powertoy for Windows XP
"{55A6283C-638A-4EE0-B491-51118554BDA2}"=Norton Confidential Core
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}"=APC PowerChute Personal Edition
"{62120008-8E1E-4807-860D-A8B48F8552DB}"=Norton Protection Center
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}"=Windows Genuine Advantage v1.3.0254.0
"{66944448-6FC9-11D5-9C48-00105AE19B66}"=Gordi's Enchanted Playroom
"{6CCC133E-9A2F-4CAA-8866-75D029CD3AB3}"=Digital Voice Editor 3
"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable
"{748F4870-8350-11D3-B0BF-080009FB4A19}"=HP Share-to-Web
"{76F8CB2B-6516-4E1E-B6F1-AED4ABDB4B0A}_is1"=Spy Sweeper
"{77772678-817F-4401-9301-ED1D01A8DA56}"=SPBBC 32bit
"{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}"=Norton AntiVirus
"{84B2CF01-194D-2284-B313-F2E0D78D1033}"=Nero 7 Demo
"{85D3CC30-8859-481A-9654-FD9B74310BEF}"=Musicmatch® Jukebox
"{8DBF971D-A2C8-11D5-9C48-00105AE19B66}"=Gordi and the Math Invaders
"{90120000-0020-0409-0000-0000000FF1CE}"=Compatibility Pack for the 2007 Office system
"{90170409-6000-11D3-8CFE-0050048383C9}"=Microsoft FrontPage 2002
"{90190409-6000-11D3-8CFE-0050048383C9}"=Microsoft Publisher 2002
"{90AF0409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office PowerPoint Viewer 2003
"{91110409-6000-11D3-8CFE-0050048383C9}"=Microsoft Office XP Professional
"{915A6279-B4CA-11D4-9766-00508BC086E6}"=Party Fun Adventure
"{929408E6-D265-4174-805F-81D1D914E2A4}"=QuickTime
"{940E5FC0-CF77-4DDC-B3CA-D6A288775714}"=Brother Peer to Peer Print (NetBIOS) 1.16
"{A06275F4-324B-4E85-95E6-87B2CD729401}"=Windows Defender
"{A1960A82-DB70-474D-A86B-FA74466103C6}"=Drivers Install For Linksys Easylink Advisor
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}"=Microsoft Visual C++ 2005 Redistributable
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}"=Windows Defender Signatures
"{A7050037-F0EA-4BAB-BCD5-FC05507D6147}"=Alt-Tab Task Switcher Powertoy for Windows XP
"{AA751A0B-C6E8-11D4-9766-00508BC086E6}"=Reading Adventure
"{AC76BA86-7AD7-1033-7B44-A81200000003}"=Adobe Reader 8.1.2
"{AC76BA86-7AD7-5464-3428-800000000003}"=Spelling Dictionaries Support For Adobe Reader 8
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}"=ccCommon
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1"=Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}"=Microsoft .NET Framework 2.0 Service Pack 1
"{C0B88772-EACC-4F69-9F77-59A4894CF170}"=hp officejet d series
"{C151CE54-E7EA-4804-854B-F515368B0798}"=Athlon 64 Processor Driver
"{C1C185CA-C531-49F5-A6FA-B838405A049D}"=Norton Internet Security
"{C39DE425-6CCF-4B12-A101-3CB5CF3AF3AD}"=Slideshow Generator Powertoy for Windows XP
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}"=Marvell Miniport Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{D526EDEA-907D-4564-B662-D6F8F924A1D9}"=Brother HL-2070N
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}"=LiveUpdate Notice (Symantec Corporation)
"{DDC63227-BA06-4855-B002-BDB49E9F677E}"=Symantec Technical Support Web Controls
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}"=Ad-Aware
"{E0F1D3B6-F50E-49AE-A942-FFDFFA16F9A9}"=PhotoStreamer 2
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}"=Windows Media Encoder 9 Series
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}"=Norton AntiVirus Help
"{E80F62FF-5D3C-4A19-8409-9721F2928206}"=LiveUpdate (Symantec Corporation)
"{ED13A39F-2F2C-41DA-A455-0ACC853D69EF}"=Symantec Real Time Storage Protection Component
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}"=AppCore
"{F4026ECE-9F19-43EC-9FC8-474C2DB7D2BE}"=ASUS Utilities
"{FB08F381-6533-4108-B7DD-039E11FBC27E}"=Realtek AC'97 Audio
"{FBD6A335-7E02-43B0-AF58-1B472F9BD3E1}"=Nokia PC Suite
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}"=HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"ActiveScan 2.0"=Panda ActiveScan 2.0
"Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player Plugin
"Adobe Shockwave Player"=Adobe Shockwave Player
"ASUS Probe V2.24.10"=ASUS Probe V2.24.10
"Audacity_is1"=Audacity 1.2.6
"AutoPlay me for PowerPoint Trial_is1"=AutoPlay me for PowerPoint Trial 3.0.0
"Caillou's Preschool"=Caillou's Preschool
"ComcastHSI"=Comcast High-Speed Internet Install Wizard
"Creative PD1120"=Creative WebCam NX Ultra Driver (1.01.03.0112)
"Dreamship Tales"=Dreamship Tales
"DVD Identifier_is1"=DVD Identifier
"FileBox eXtender"=FileBox eXtender
"Flash Movie Player"=Flash Movie Player 1.4
"Flash Saver"=Flash Saver
"FLVPlayer"=FLV Player 1.3.3
"Folding@Home"=Folding@Home
"Freeciv-2.1.3-gtk2"=Freeciv 2.1.3 (GTK+ client)
"FTP Commander"=FTP Commander
"Hauppauge WinTV"=Hauppauge WinTV
"Hauppauge WinTV Infrared Remote"=Hauppauge WinTV Infrared Remote
"Hauppauge WinTV Radio"=Hauppauge WinTV Radio
"Hauppauge WinTV Scheduler"=Hauppauge WinTV Scheduler
"Hauppauge WinTV TV Services"=Hauppauge WinTV TV Services
"Hauppauge WinTV-PVR USB 2 Drivers"=Hauppauge WinTV-PVR USB 2 Drivers
"HijackThis"=HijackThis 2.0.2
"HP Photo Printing Software"=HP Photo Printing Software
"HyperSnap 6"=HyperSnap 6
"IC Card Reader Driver"=IC Card Reader Driver v1.9e2
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"InstallShield_{1F6423DE-7959-4178-80E0-023C7EAA5347}"=NVIDIA ForceWare Network Access Manager
"InstallShield_{3C1599DA-9ED9-4090-930F-B8BC4D99D6B0}"=Nokia Connectivity Cable Driver
"InstallShield_{929408E6-D265-4174-805F-81D1D914E2A4}"=QuickTime
"InstallShield_{F4026ECE-9F19-43EC-9FC8-474C2DB7D2BE}"=ASUS Utilities
"InstallShield_{FBD6A335-7E02-43B0-AF58-1B472F9BD3E1}"=Nokia PC Suite
"InterActual Player"=InterActual Player
"Jay Jay Sky Heroes to the Rescue"=Jay Jay Sky Heroes to the Rescue
"Learn to Read with Phonics 1st and 2nd Grade"=Learn to Read with Phonics 1st and 2nd Grade
"LochJournal_is1"=LochJournal 2.2
"Micro Logic Info Select 8"=Micro Logic Info Select 8
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3)
"mozy_is1"=MozyHome 1.8.10.0
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"Muppet Babies Toyland Train"=Muppet Babies Toyland Train
"nanoPEG-Editor 2.6.0 for WinTV_is1"=nanoPEG-Editor 2.6.0 for WinTV
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers"=NVIDIA Drivers
"PC Magazine's WinTidy_is1"=WinTidy 2.0
"PhotoStreamer 2"=PhotoStreamer 2
"Picasa2"=Picasa 2
"PicasaNet"=Hello (remove only)
"PixWizard"=PixWizard
"PixWizard 1.36"=PixWizard 1.36
"PolderbitSRecorder"=PolderbitS Sound Recorder and Editor
"PPTView97"=Microsoft PowerPoint Viewer 97
"PsuedoLiveUpdate"=LiveUpdate (Symantec Corporation)
"Quicken for Windows 6 Deluxe"=Quicken for Windows 6 Deluxe
"ReaJPEG_is1"=ReaJPEG 2.0
"RealPlayer 6.0"=RealPlayer
"Rosetta Stone 2.1.5.1A"=Rosetta Stone 2.1.5.1A
"SecondLife"=SecondLife (remove only)
"Semagic"=Semagic (remove only)
"SightSpeed"=SightSpeed (remove only)
"SmartInstaller"=EarthLink Smart Installer
"SymSetup.{C1C185CA-C531-49F5-A6FA-B838405A049D}"=Norton Internet Security (Symantec Corporation)
"TrueImage"=Acronis True Image
"Tweak UI 2.10"=Tweak UI
"VRtainment CapturePad_is1"=VRtainment CapturePad 0.1beta
"What's Running_is1"=What's Running 2.2
"Wiggle and Giggle"=Wiggle and Giggle
"Windows Live Safety scanner"=Windows Live Safety scanner
"Windows Media Encoder 9"=Windows Media Encoder 9 Series
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Windows Media Player 11
"Windows XP Service Pack"=Windows XP Service Pack 3
"WinPcapInst"=WinPcap 4.0
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
"xvid"=XviD MPEG-4 Video Codec
"ZipCentral_is1"=ZipCentral 4.01
"Zoboomafoo Animal Alphabet™"=Zoboomafoo Animal Alphabet™

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Digital Editions"=Adobe Digital Editions

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Digital Editions"=Adobe Digital Editions

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/15/2008 1:24:06 PM | Computer Name = JOHN | Source = Application Hang | ID = 1001
Description = Fault bucket 829830123.

Error - 9/15/2008 1:26:42 PM | Computer Name = JOHN | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3105, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/15/2008 3:37:43 PM | Computer Name = JOHN | Source = Application Hang | ID = 1002
Description = Hanging application audacity.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/15/2008 3:37:48 PM | Computer Name = JOHN | Source = Application Hang | ID = 1001
Description = Fault bucket 03874438.

Error - 9/22/2008 10:03:48 PM | Computer Name = JOHN | Source = Application Hang | ID = 1002
Description = Hanging application SpybotSD.exe, version 1.6.0.30, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/22/2008 10:03:53 PM | Computer Name = JOHN | Source = Application Hang | ID = 1001
Description = Fault bucket 834373986.

Error - 9/24/2008 8:46:17 AM | Computer Name = JOHN | Source = Application Error | ID = 1000
Description = Faulting application teatimer.exe, version 1.6.2.23, faulting module
kernel32.dll, version 5.1.2600.5512, fault address 0x00012aeb.

Error - 9/24/2008 8:47:08 AM | Computer Name = JOHN | Source = Application Error | ID = 1001
Description = Fault bucket 893503255.

Error - 10/3/2008 7:01:22 PM | Computer Name = JOHN | Source = Application Hang | ID = 1002
Description = Hanging application OTViewIt.exe, version 1.0.9.2, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/3/2008 7:01:27 PM | Computer Name = JOHN | Source = Application Hang | ID = 1001
Description = Fault bucket 950480312.

[ System Events ]
Error - 9/23/2008 11:37:27 AM | Computer Name = JOHN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for Start with the following error:
%%5

Error - 9/23/2008 12:51:16 PM | Computer Name = JOHN | Source = DCOM | ID = 10010
Description = The server {03E0E6C2-363B-11D3-B536-00902771A435} did not register
with DCOM within the required timeout.

Error - 9/23/2008 8:28:45 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for Start with the following error:
%%5

Error - 9/24/2008 8:47:10 AM | Computer Name = JOHN | Source = NetBT | ID = 4321
Description = The name "TAS :1d" could not be registered on the Interface
with IP address 192.168.1.103. The machine with the IP address 192.168.1.100 did
not allow the name to be claimed by this machine.

Error - 9/24/2008 8:52:20 AM | Computer Name = JOHN | Source = NetBT | ID = 4321
Description = The name "TAS :1d" could not be registered on the Interface
with IP address 192.168.1.103. The machine with the IP address 192.168.1.100 did
not allow the name to be claimed by this machine.

Error - 9/24/2008 8:57:30 AM | Computer Name = JOHN | Source = NetBT | ID = 4321
Description = The name "TAS :1d" could not be registered on the Interface
with IP address 192.168.1.103. The machine with the IP address 192.168.1.100 did
not allow the name to be claimed by this machine.

Error - 9/24/2008 6:57:19 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for Start with the following error:
%%5

Error - 9/27/2008 4:48:18 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for Start with the following error:
%%5

Error - 9/28/2008 2:21:22 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Sunbelt VIPRE Antivirus
Service service to connect.

Error - 9/28/2008 2:21:22 PM | Computer Name = JOHN | Source = Service Control Manager | ID = 7000
Description = The Sunbelt VIPRE Antivirus Service service failed to start due to
the following error: %%1053


< End of report >

********************************

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, October 3, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, October 03, 2008 21:54:15
Records in database: 1287039
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\

Scan statistics:
Files scanned: 145992
Threat name: 3
Infected objects: 3
Suspicious objects: 2
Duration of the scan: 02:20:30


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\457B0C7A.exe Infected: Trojan-Downloader.Win32.Zlob.bqd 1
C:\Documents and Settings\JSU\.housecall6.6\Quarantine\movie.rar.bac_a01780 Infected: Trojan-Downloader.Win32.Agent.aevg 1
C:\Documents and Settings\JSU\.housecall6.6\Quarantine\movie.rar.bac_a04048 Infected: Trojan-Downloader.Win32.Agent.aevg 1
C:\Program Files\EUDORA 7\Out.mbx.001 Suspicious: Trojan-Spy.HTML.Fraud.gen 1
D:\Eudora Backup\EUDORA 7\Out.mbx.001 Suspicious: Trojan-Spy.HTML.Fraud.gen 1

The selected area was scanned.

******************************

#4 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:04:18 PM

Posted 03 October 2008 - 10:03 PM

Hello, jsu627.
We need to uninstall one or more programs
Please click on Start > Control Panel > Add/Remove Programs and uninstall the following programs(if present):
J2SE Runtime Environment 5.0 Update 5, J2SE Runtime Environment 5.0 Update 6, J2SE Runtime Environment 5.0 Update 10, J2SE Runtime Environment 5.0 Update 11, Java™ SE Runtime Environment 6 Update 1, Java™ 6 Update 2, Java™ 6 Update 3, Java™ 6 Update 5

We need to clear out some temporary data.
Please download ATF Cleaner by Atribune. (This program is for XP and Windows 2000 only)Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

We need to execute an OTMoveIt3 script
  • Please download OTMoveIt3 by OldTimer and save it to your desktop.
  • Double click the Posted Image icon on your desktop.
  • Paste the following code under the Posted Image area. Do not include the word "Code".
    :services
    5a15c3d05b32fc85
    e1156cd8ea126d58
    ed4133b8c68c615a
    f725fb005c50b854
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
    "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"=-
    "{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
    "{C4069E3A-68F1-403E-B40E-20066696354B}"=-
    [HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
    "{C4069E3A-68F1-403E-B40E-20066696354B}"=-
    [HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
    "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"=-
    "{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    ""=-
    "NWEReboot"=-
    "POINTER"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}"=-
    "{6BBAA1E6-CF54-4139-AB9C-8491A9F909D7}"=-
    "{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"=-
    [-HKEY_CLASSES_ROOT\CLSID\{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}]
    [-HKEY_CLASSES_ROOT\CLSID\{6BBAA1E6-CF54-4139-AB9C-8491A9F909D7}]
    [-HKEY_CLASSES_ROOT\CLSID\{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}]
    :commands
    [EmptyTemp]
  • Push the large Posted Image button.
  • OTMI3 may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the Posted Image line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
I would like us to use ESET (NOD32)'s Online Scanner
  • Please go to ESET OnlineScan (NOD32)
  • You will then see the Terms of Use, tick the check-box infront of YES, I accept the Terms of Use
  • Now click Start
  • Should you face a Security Warning that asks if you want to install and run a file called "OnlineScanner.cab", click Yes
  • Click Start
    • Note: (the Onlinescanner will now prepare itself for running on your pc)
  • To do a full-scan, tick: "Remove found threats" and "Scan potentially unwanted applications"
  • Press Scan
  • The Onlinescan will now start and scan your pc (this could take a while)
  • When the scan has finished, it will show a screen with two tabs "overview" and "details" and the option to get information or buy software, just close the window
  • Click Start >> Run... >> type: C:\Program Files\EsetOnlineScanner\log.txt
  • The Scanresults will now open in Notepad
  • Click into the text area, right-click and chose "select all" (or use +A)
  • Right-click again and chose "Copy" (or +C)
  • Close/Exit Notepad
  • Navigate to this thread and post your log along with anything else requested from us, by right-clicking and "paste" (or ctrl+v) in the text area of the reply post you just created.
Note: For Vista Users: Eset is compatible but Internet Explorer must be run as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.)

In your next reply, please include the following:
  • OTMoveIt3's Log
  • ESET OnlineScan's Log

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#5 jsu627

jsu627
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 04 October 2008 - 01:53 PM

Hi Billy3

Thanks for the reply.



miexec.exe browser helper error message from Web Root Spy Sweep when removing Java aps

Jave ™ 6 Update 7 remains.


During boot up after OTMoveIt3 ran, got this error message from Spybot Search and Destroy. I did not approve the registry entry change.

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: system32.exe

Description
Added by the _AGOBOT-KU_ WORM! Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list

I tried to run the ESET scan, but IE no longer has active x add-ons enabled, and I couldn't get them back using the IE toggle in accessories/system tools. I'm sending you this, and I'll try to get IE back and use the ESET scan then.

John

Here is the OTMoveIt3 log:

========== SERVICES/DRIVERS ==========
Service 5a15c3d05b32fc85 stopped successfully.
Service 5a15c3d05b32fc85 deleted successfully.
Service e1156cd8ea126d58 stopped successfully.
Service e1156cd8ea126d58 deleted successfully.
Service ed4133b8c68c615a stopped successfully.
Service ed4133b8c68c615a deleted successfully.
Service f725fb005c50b854 stopped successfully.
Service f725fb005c50b854 deleted successfully.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found.
Registry value HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_USERS\S-1-5-21-507921405-1275210071-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NWEReboot deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\POINTER deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{6BBAA1E6-CF54-4139-AB9C-8491A9F909D7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6BBAA1E6-CF54-4139-AB9C-8491A9F909D7}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}\ deleted successfully.
Registry key HKEY_CLASSES_ROOT\CLSID\{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}\\ not found.
Registry key HKEY_CLASSES_ROOT\CLSID\{6BBAA1E6-CF54-4139-AB9C-8491A9F909D7}\\ not found.
Registry key HKEY_CLASSES_ROOT\CLSID\{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}\\ not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\Arj.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\avlib.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\Avp1.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\AvpMgr.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\CAB.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\dmap.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\dtreg.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\FsDrvPlg.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\FSSync.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\HashCont.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\HashMD5.PPL scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\HCCMP.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\ichk2.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\iChkSA.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\IWGen.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\kave.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\kosglue-7.0.25.0.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\lha.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\L_llio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\mdb.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\minizip.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\MKavIO.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\msoe.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\nfio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\prKernel.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\prLoader.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\PrUtil.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\rar.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\ScanningProcess.exe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\sfdb.PPL scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\TempFile.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\thpimpl.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\UniArc.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\WDiskIO.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\hsperfdata_JSU\5748 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\etilqs_c0YYHWnvxgdc9imkXmqp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\JSU\LOCALS~1\Temp\fla29E9.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\JETEF22.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_9b8.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\T30DebugLogFile.txt scheduled to be deleted on reboot.
Windows Temp folder emptied.
File delete failed. C:\Documents and Settings\JSU\Application Data\Sun\Java\Deployment\cache\6.0\14\757e808e-468dba3f scheduled to be deleted on reboot.
Java cache emptied.
File delete failed. C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.3.1 log created on 10042008_103144

Files moved on Reboot...
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\Arj.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\avlib.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\Avp1.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\AvpMgr.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\CAB.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\dmap.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\dtreg.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\FsDrvPlg.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\FSSync.dll
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\FSSync.dll NOT unregistered.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\FSSync.dll moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\HashCont.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\HashMD5.PPL moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\HCCMP.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\ichk2.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\iChkSA.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\IWGen.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\kave.dll
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\kave.dll NOT unregistered.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\kave.dll moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\kosglue-7.0.25.0.dll
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\kosglue-7.0.25.0.dll NOT unregistered.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\kosglue-7.0.25.0.dll moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\lha.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\L_llio.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\mdb.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\minizip.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\MKavIO.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\msoe.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\nfio.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\prKernel.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\prLoader.dll
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\prLoader.dll NOT unregistered.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\prLoader.dll moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\PrUtil.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\rar.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\ScanningProcess.exe moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\sfdb.PPL moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\TempFile.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\thpimpl.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\UniArc.ppl moved successfully.
C:\DOCUME~1\JSU\LOCALS~1\Temp\jkos-JSU\binaries\WDiskIO.ppl moved successfully.
File C:\DOCUME~1\JSU\LOCALS~1\Temp\hsperfdata_JSU\5748 not found!
File C:\DOCUME~1\JSU\LOCALS~1\Temp\etilqs_c0YYHWnvxgdc9imkXmqp not found!
File C:\DOCUME~1\JSU\LOCALS~1\Temp\fla29E9.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\JETEF22.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_9b8.dat not found!
C:\WINDOWS\temp\T30DebugLogFile.txt moved successfully.
C:\Documents and Settings\JSU\Application Data\Sun\Java\Deployment\cache\6.0\14\757e808e-468dba3f moved successfully.
C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\JSU\Local Settings\Application Data\Mozilla\Firefox\Profiles\bhaldl4t.default\XUL.mfl moved successfully.

____________________

#6 jsu627

jsu627
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 04 October 2008 - 02:15 PM

After rebooting I can't get IE to enable Active X add-ons still. Also the buttons on the right side of my Microsoft track ball no longer navigate backwards and forwards through web pages like they used to.

Should I try reinstalling IE?

John

#7 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:04:18 PM

Posted 04 October 2008 - 03:10 PM

Hello, jsu627.
Alright on the ESET thing.. .we used Kaspersky earlier and that should be fine.

OTMI is able to do things despite TeaTimer... the key got deleted.

Unfortunately you can't simply reinstall IE as it's part of the operating system install itself. Reinstalling IE == reinstalling windows. Go ahead and attempt this fix to get your mouse and ActiveX working again.

We need to execute an OTMoveIt3 script
  • Please download OTMoveIt3 by OldTimer and save it to your desktop.
  • Double click the Posted Image icon on your desktop.
  • Paste the following code under the Posted Image area. Do not include the word "Code".
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "POINTER"="point32.exe"
  • Push the large Posted Image button.
  • OTMI3 may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the Posted Image line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
We need to repair some of windows' internal registration settings
  • Please download Dial-A-Fix from one of the following mirrors:
  • Extract the zip file to your desktop.
  • Double click Dial-a-Fix.exe to start the program.
  • Press the green double checkmark box (Looks like this: Posted Image)
  • UNcheck "Empty Temp Folders", as well as "Adjust Time/Date" in the prep section. The prep section should then look like this:
    Posted Image
  • When the window looks like this, press the GO button in the bottom of the window.
    Posted Image
  • Exit/Close Dial-A-Fix
In your next reply, please include the following:
  • OTMoveIt3's Log
  • A New HiJack This log

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#8 jsu627

jsu627
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 05 October 2008 - 08:14 AM

Hi Billy3,

Here is the OTMoveIt3 log: I did it twice, got the same result. It did not ask me to reboot.

Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]> in the current context!
Error: Unable to interpret <"POINTER"="point32.exe"> in the current context!

OTMoveIt3 by OldTimer - Version 1.0.3.1 log created on 10052008_060004

I ran Dial-A-Fix, seemingly uneventfully.

The new Hijack This log is below.

The only other thing that has been happening lately is that Symantec is sending me several Norton Security updates every day. I am beginning to wonder if they are bogus?

Thanks,

John

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:10:42 AM, on 10/5/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Mozy\mozybackup.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBAMTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinTV\Ir.exe
C:\Program Files\Mozy\mozystat.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\ASUS\Asus Probe\ASUSPROB.EXE
C:\Program Files\FileBX\FileBX.exe
C:\Program Files\WinTidy\WinTidy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\System32\dllhost.exe
C:\Documents and Settings\JSU\Desktop\SECURITY\OTMoveIt3.exe
C:\Program Files\ZipCentral\ZCentral.exe
C:\DOCUME~1\JSU\LOCALS~1\Temp\_ZCTmp.Dir\Dial-a-fix-v0.60.0.24\Dial-a-fix.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [CoolSwitch] "C:\WINDOWS\system32\taskswitch.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] "C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" -onlytray
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] "C:\WINDOWS\system32\dumprep.exe" 0 -k
O4 - HKLM\..\Run: [SoundMan] "C:\WINDOWS\SOUNDMAN.EXE"
O4 - HKLM\..\Run: [SBAMTray] "C:\Program Files\Sunbelt Software\CounterSpy\SBAMTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Picasa Media Detector] "C:\Program Files\Picasa2\PicasaMediaDetector.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] "C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: AutorunsDisabled
O4 - Startup: FileBox eXtender.lnk = C:\Program Files\FileBX\FileBX.exe
O4 - Startup: Norton Internet Security.lnk = ?
O4 - Startup: WinTidy.lnk = C:\Program Files\WinTidy\WinTidy.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O4 - Global Startup: Mozy Status.lnk = C:\Program Files\Mozy\mozystat.exe
O4 - Global Startup: Probe V2.24.10.lnk = ?
O8 - Extra context menu item: &Save Flash In This Page by Flash Saver - C:\PROGRA~1\FLASHS~1\save.htm
O8 - Extra context menu item: Copy to Semagic - C:\Program Files\Semagic\copy.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Semagic - C:\Program Files\Semagic\link.htm
O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1221580891203
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Unknown owner - C:\Program Files\Mozy\mozybackup.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Sunbelt VIPRE Antivirus Service (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 12477 bytes

#9 jsu627

jsu627
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 05 October 2008 - 09:11 AM

PS:

I just rebooted. IE still doesn't have Active X. I was able to get my trackball working by reinstalling it from the mouse icon in the control panel. Sound is still gone.

John

#10 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:04:18 PM

Posted 05 October 2008 - 09:35 AM

Alright... Strange that sound is messed up.....
Please to to Start -> Run and type in "Services.msc" (without quotes).
Scroll all the way down to "Windows Audio". Is that service listed as "Started"?

EDIT: Also, what is the make and model of your machine?

Billy3

Edited by Billy O'Neal, 05 October 2008 - 09:36 AM.

Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#11 jsu627

jsu627
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 05 October 2008 - 09:59 AM

Windows Audio is listed as started.

The machine is one a friend and I assembled from components:

AMD A8N 3800 FX2
ASUS SLI Deluxe MOBO
ASUS N6200TC Graphics
2 Gig Ram
Windows XP Professional

Thanks,

John

#12 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:04:18 PM

Posted 05 October 2008 - 10:05 AM

Do you know who makes the sound card? Have you tried reinstalling drivers for it? Or is it integrated on the motherboard?

Did the speaker cable come unplugged (Sorry... have to ask)

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#13 jsu627

jsu627
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 05 October 2008 - 10:17 AM

Sound card is on mobo, nVidia(0059), DirectX 9.0c, Driver version is: 5.10.0.5750, Audio Codec is: ALC850

I've tried reinstalling the drivers, but not recently. maybe that's the next thing to do after I get Windows working again.

And, yes, I've tried two different cables, but who knows?.... :thumbsup:


Might it be a good idea to do a windows repair? I've not done it yet because I'm a little concerned that it might screw up...

Thanks,

John

#14 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:04:18 PM

Posted 05 October 2008 - 11:58 AM

Hello, jsu627.
I'm honestly not 100% sure what's going on here... I would start a topic over in http://www.bleepingcomputer.com/forums/f/56/windows-xp-home-and-professional/ , as they know how to better deal with configuration problems. Does not look like it's a malware problem here.

I would attempt reinstallation of drivers first though :)

Congratulations! You now appear clean! :thumbsup:

Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware


We Need to Clean Up Our Mess
  • Please download OTCleanIt from one of the following mirrors and save it to your desktop:
  • Double click the Posted Image icon.
  • Push the large "Cleanup" button.
  • Allow your system to reboot.
Reset System Restore
Windows' "System Restore" feature can cause malware files to be cached and retained by your system. Resetting System Restore will clean these files from your system, and will allow you to use System Restore without fear of reinfection.
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Note: You should only do this once, not on a regular basis!
You will not be able to restore computer to any earlier than today!

Recommendations
Below are some recommendations to lower your chances of (re)infection.
  • Install and maintain an outbound firewall
  • Install Spyware Blaster and update it regularly
    If you wish, the commercial version provides automatic updating.
  • Install the MVPs hosts file, and update it regularly
    You can use the HostMan host file manager to do this automaticly if you wish.
    For more information on the hosts file, and what it can do for you, you can view the Tutorial on the Hosts file
  • Install an Anti-Spyware program, and update it regularly
    Malware Byte's Anti Malware is an excellent Anti-Spyware scanner. It's scan times are usually under ten minutes, and has excellent detection and removal rates.
    SUPERAntiSpyware is another good scanner with high detection and removal rates.
    Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.
  • Keep Windows (and your other Microsoft software) up to date!
    I cannot stress how important this is enough. Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.

    If you are using Windows XP or earlier
    Visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!

    If you are using Windows Vista
    • Click the "Start Menu" (or Windows Orb)
    • Click "All Programs"
    • Click "Windows Update"
    • On the left, choose "Change Settings"
    • Ensure that the checkbox "Use Microsoft Update" at the bottom of the window is checked.
    • Press OK and accept the UAC prompt.
      Note: You shouldn't need to check this checkbox every single time you update, only the first time.
    • Click "Check for Updates" in the upper left corner.
    • Follow the instructions to install the latest updates.
    • Reboot and repeat the "Check for Updates" until there are no more critical updates to install
  • Keep your other software up to date as well
    Software does not need to be made by Microsoft to be insecure. You can use the Secunia Online Software occasionally to help you check for out of date software on your machine.
  • Stay up to date!
    The MOST IMPORTANT part of any security setup is keeping the software up to date. Malware writers release new variants every single day. If your software updates don't keep up, then the malware will always be one step ahead. Not a good thing :).
Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#15 jsu627

jsu627
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 05 October 2008 - 12:51 PM

Thanks Billy3,

I'll keep at the configuration stuff, but assume at this point the Trojan part of the CNN Alert Malware is gone, and start using this machine for critical work again.

I really appreciate the attention you've paid to this.

John




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users