arachnid40

Info.com Redirect Hijackthis Log[RESOLVED]

Recommended Posts

My dads system keeps redirecting I am doing a virus scan now from safemode, here is the highjackthis log:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 4:17:55 PM, on 6/10/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16827)

Boot mode: Safe mode with network support

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\AVG\AVG8\avgui.exe

C:\Program Files\AVG\AVG8\avgscanx.exe

C:\Program Files\AVG\AVG8\avgcsrvx.exe

C:\Program Files\Internet Explorer\Iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduser

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe

O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,[email protected]

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [mumservice] C:\Program Files\Motorola\Software Update\mumservice.exe

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [Weather Pulse] C:\Program Files\Weather Pulse\weatherpulse.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe

O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O15 - Trusted Zone: *.antimalwareguard.com

O15 - Trusted Zone: *.antimalwareguard.com (HKLM)

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)

O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE

--

End of file - 7950 bytes

Share this post


Link to post
Share on other sites

hi

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Please download GooredFix from one of the locations below and save it to your Desktop

Download Mirror #1

Download Mirror #2

  • Double-click GooredFix.exe to run it.
  • Select 1. Find Goored (no fix) by typing 1 and pressing Enter.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).

Note: Do not run Option #2 yet.

Share this post


Link to post
Share on other sites

Rooter.exe (v1.0) by Eric_71

¨

Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3

32_bits - x86 Family 15 Model 44 Stepping 2, AuthenticAMD

¨

C:\ [Fixed-NTFS] .. ( Total:30467 Mo - Free:8372 Mo )

D:\ [Fixed-FAT32] .. ( Total:7680 Mo - Free:2209 Mo )

E:\ [CD_Rom]

F:\ [CD_Rom]

G:\ [Removable]

H:\ [Removable]

I:\ [Removable]

J:\ [Removable]

¨

Scan : 13:19.46

Path : C:\Documents and Settings\HP_Owner\Desktop\Rooter.exe

User : HP_Owner ( Administrator -> YES )

¨

----------------------\\ Processes

¨

Locked [system Process] (0)

______ System (4)

______ \SystemRoot\System32\smss.exe (472)

______ \??\C:\WINDOWS\system32\csrss.exe (544)

______ \??\C:\WINDOWS\system32\winlogon.exe (568)

______ C:\WINDOWS\system32\services.exe (620)

______ C:\WINDOWS\system32\lsass.exe (632)

______ C:\WINDOWS\system32\svchost.exe (784)

______ C:\WINDOWS\system32\svchost.exe (864)

______ C:\WINDOWS\System32\svchost.exe (932)

______ C:\WINDOWS\system32\svchost.exe (972)

______ C:\WINDOWS\system32\svchost.exe (1184)

______ C:\WINDOWS\system32\svchost.exe (1276)

______ C:\WINDOWS\system32\spoolsv.exe (1364)

______ C:\WINDOWS\Explorer.EXE (1592)

______ C:\WINDOWS\system32\svchost.exe (1808)

______ C:\WINDOWS\system32\ctfmon.exe (1832)

______ C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (1860)

______ C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (1876)

______ C:\Program Files\Java\jre6\bin\jqs.exe (1924)

______ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (1972)

______ C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE (232)

______ C:\WINDOWS\system32\svchost.exe (396)

______ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (968)

______ C:\PROGRA~1\AVG\AVG8\avgrsx.exe (1236)

______ C:\PROGRA~1\AVG\AVG8\avgnsx.exe (1260)

______ C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (1788)

______ C:\Program Files\QuickTime\qttask.exe (1820)

______ C:\PROGRA~1\AVG\AVG8\avgtray.exe (1980)

______ C:\Program Files\Java\jre6\bin\jusched.exe (2068)

______ C:\Program Files\Weather Pulse\weatherpulse.exe (2124)

______ C:\Program Files\Messenger\msmsgs.exe (2148)

______ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (2176)

______ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (2196)

______ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (2308)

______ C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe (2344)

______ C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (2384)

______ C:\WINDOWS\System32\alg.exe (2876)

______ C:\WINDOWS\system32\lxcecoms.exe (3120)

______ C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe (3512)

______ C:\WINDOWS\ALCXMNTR.EXE (4024)

______ c:\windows\system\hpsysdrv.exe (228)

______ C:\Program Files\Java\jre6\bin\jusched.exe (1732)

______ C:\Program Files\Java\jre6\bin\jucheck.exe (1036)

______ C:\Program Files\AVG\AVG8\avgscanx.exe (2480)

______ C:\Program Files\AVG\AVG8\avgcsrvx.exe (804)

______ C:\Program Files\Internet Explorer\Iexplore.exe (3040)

______ C:\Program Files\internet explorer\iexplore.exe (1544)

______ C:\Documents and Settings\HP_Owner\Desktop\Rooter.exe (3952)

¨

----------------------\\ Device\Harddisk0\

¨

\Device\Harddisk0 [sectors : 63 x 512 Bytes]

¨

\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:8068967424)

\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:8068999680 | Length:31946987520)

¨

----------------------\\ Scheduled Tasks

¨

C:\WINDOWS\Tasks\desktop.ini

C:\WINDOWS\Tasks\SA.DAT

C:\WINDOWS\Tasks\Symantec NetDetect.job

C:\WINDOWS\Tasks\xhhfhgbo.job

¨

----------------------\\ Registry

¨

¨

----------------------\\ Files & Folders

¨

C:\DOCUME~1\HP_Owner\My Documents\FrostWire\Incomplete\T-76192-avs video converter 5 crack.zip

C:\DOCUME~1\HP_Owner\My Documents\FrostWire\Incomplete\T-76194-avs video converter 5 keygen [sSG].zip

==> Cracks & Keygens <==

¨

----------------------\\ Scan completed at 13:20.13

¨

C:\Rooter$\Rooter_1.txt - (11/06/2009 | 13:20.13).c

GooredFix v1.92 by jpshortstuff

Log created at 13:21 on 11/06/2009 running Option #1 (HP_Owner)

Firefox version 3.0.10 (en-US)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]

"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]

"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]

"[email protected]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"

Share this post


Link to post
Share on other sites

hi

Please download OTM

  • Save it to your desktop.
  • Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    :Processes
    explorer.exe

    :Services

    :Reg

    :Files
    C:\WINDOWS\Tasks\xhhfhgbo.job
    C:\DOCUME~1\HP_Owner\My Documents\FrostWire\Incomplete\T-76192-avs video converter 5 crack.zip
    C:\DOCUME~1\HP_Owner\My Documents\FrostWire\Incomplete\T-76194-avs video converter 5 keygen [SSG].zip

    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]


  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %systemroot%\System32\antiwpa.dll
    %systemroot%\SYSTEM32\wpa.dll
    %systemroot%\setup\scripts\biestart.exe
    %systemroot%\system32\drivers\royal.sys
    %SYSTEMDRIVE%\*.
    %SYSTEMDRIVE%\*.*
    %PROGRAMFILES%\*.

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Share this post


Link to post
Share on other sites

========== PROCESSES ==========

Process explorer.exe killed successfully.

========== SERVICES/DRIVERS ==========

========== REGISTRY ==========

========== FILES ==========

C:\WINDOWS\Tasks\xhhfhgbo.job moved successfully.

C:\DOCUME~1\HP_Owner\My Documents\FrostWire\Incomplete\T-76192-avs video converter 5 crack.zip moved successfully.

C:\DOCUME~1\HP_Owner\My Documents\FrostWire\Incomplete\T-76194-avs video converter 5 keygen [sSG].zip moved successfully.

========== COMMANDS ==========

File delete failed. C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.

File delete failed. C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\IadHide5.dll scheduled to be deleted on reboot.

File delete failed. C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\_hphtra07.log scheduled to be deleted on reboot.

File delete failed. C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\~DF23F6.tmp scheduled to be deleted on reboot.

File delete failed. C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\~DF23FB.tmp scheduled to be deleted on reboot.

User's Temp folder emptied.

User's Internet Explorer cache folder emptied.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\X00ND4CK\iframe[1].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\V87EISV7\index[1].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\H3ITMSMP\PNCARAK6T7CAPUX7I6CAC6382TCAFFSJ2CCADLJ6PSCAS4SNR0CAHSS331CA4ZA9EVCAK4YEBQC

AT7Q5E4CA6I9B23CA41ZS8ECA6JT9NCCA3CR27PCAUNAQUACA950S8TCAFP3HUZCAHMS1NKCAE1ZK0A.h

tm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\GQ2XQUAJ\ads[6].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\8PE6H8GP\listings[2].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.

User's Temporary Internet Files folder emptied.

File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.

Local Service Temp folder emptied.

Local Service Temporary Internet Files folder emptied.

Network Service Temp folder emptied.

Network Service Temporary Internet Files folder emptied.

File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4bc.dat scheduled to be deleted on reboot.

Windows Temp folder emptied.

Java cache emptied.

FireFox cache emptied.

Temp folders emptied.

Explorer started successfully

OTM by OldTimer - Version 2.1.0.1 log created on 06122009_111506

Files moved on Reboot...

C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\hpodvd09.log moved successfully.

DllUnregisterServer procedure not found in C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\IadHide5.dll

C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\IadHide5.dll NOT unregistered.

C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\IadHide5.dll moved successfully.

C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\_hphtra07.log moved successfully.

File C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\~DF23F6.tmp not found!

File C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\~DF23FB.tmp not found!

C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\X00ND4CK\iframe[1].htm moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\V87EISV7\index[1].htm moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\H3ITMSMP\PNCARAK6T7CAPUX7I6CAC6382TCAFFSJ2CCADLJ6PSCAS4SNR0CAHSS331CA4ZA9EVCAK4YEBQC

AT7Q5E4CA6I9B23CA41ZS8ECA6JT9NCCA3CR27PCAUNAQUACA950S8TCAFP3HUZCAHMS1NKCAE1ZK0A.h

tm moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\GQ2XQUAJ\ads[6].htm moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\8PE6H8GP\listings[2].htm moved successfully.

File move failed. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be moved on reboot.

File C:\WINDOWS\temp\Perflib_Perfdata_4bc.dat not found!

Registry entries deleted on Reboot...

OTL logfile created on: 6/12/2009 11:25:03 AM - Run 1

OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\HP_Owner\Desktop

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.12 Gb Total Physical Memory | 0.48 Gb Available Physical Memory | 42.67% Memory free

2.69 Gb Paging File | 2.10 Gb Available in Paging File | 77.96% Paging File free

Paging file location(s): C:\pagefile.sys 1728 3456 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 29.75 Gb Total Space | 8.52 Gb Free Space | 28.63% Space Free | Partition Type: NTFS

Drive D: | 7.50 Gb Total Space | 2.16 Gb Free Space | 28.76% Space Free | Partition Type: FAT32

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: YOUR-27E1513D96

Current User Name: HP_Owner

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Output = Minimal

File Age = 30 Days

Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)

PRC - C:\Program Files\Internet Explorer\Iexplore.exe (Microsoft Corporation)

PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)

PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)

PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)

PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)

PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE (HP)

PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)

PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)

PRC - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)

PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)

PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)

PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)

PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)

PRC - C:\Program Files\Weather Pulse\weatherpulse.exe (Tropic Designs)

PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

PRC - C:\WINDOWS\system32\lxcecoms.exe (Lexmark International, Inc.)

PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

PRC - C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)

PRC - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)

PRC - C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe (Yahoo! Inc.)

PRC - C:\WINDOWS\ALCXMNTR.EXE (Realtek Semiconductor Corp.)

PRC - c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)

PRC - C:\Documents and Settings\HP_Owner\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)

========== Win32 Services (SafeList) ==========

SRV - (ACDaemon [Auto | Running]) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)

SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)

SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)

SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)

SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)

SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)

SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)

SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)

SRV - (KodakCCS [On_Demand | Stopped]) -- File not found

SRV - (lxce_device [On_Demand | Running]) -- C:\WINDOWS\system32\lxcecoms.exe (Lexmark International, Inc.)

SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)

SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)

SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE (HP)

SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)

DRV - (AmdK8 [system | Running]) -- C:\WINDOWS\system32\DRIVERS\AmdK8.sys (Advanced Micro Devices)

DRV - (AvgLdx86 [system | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)

DRV - (AvgMfx86 [system | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)

DRV - (AvgTdiX [system | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)

DRV - (HSFHWBS2 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)

DRV - (HSF_DP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)

DRV - (iaStor [boot | Running]) -- C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)

DRV - (MBAMSwissArmy [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)

DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)

DRV - (motccgp [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\motccgp.sys (Motorola)

DRV - (motccgpfl [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\motccgpfl.sys (Motorola)

DRV - (MotDev [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\motodrv.sys (Motorola Inc)

DRV - (motmodem [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\motmodem.sys (Motorola)

DRV - (motport [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\motport.sys (Motorola)

DRV - (pavboot [boot | Running]) -- C:\WINDOWS\system32\drivers\pavboot.sys (Panda Security, S.L.)

DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)

DRV - (PxHelp20 [boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)

DRV - (rtl8139 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)

DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)

DRV - (SiS315 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)

DRV - (SiSkp [system | Running]) -- C:\WINDOWS\system32\DRIVERS\srvkp.sys (Silicon Integrated Systems Corporation)

DRV - (SISNIC [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\sisnic.sys (SiS Corporation)

DRV - (WIBUKEY [Auto | Running]) -- C:\WINDOWS\SYSTEM32\DRIVERS\Wibukey.sys (WIBU-SYSTEMS AG)

DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [email protected]:1.0

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/01/01 17:35:17 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/10 11:41:04 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/11 13:27:50 | 00,000,000 | ---D | M]

[2009/05/10 11:41:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\mozilla\Extensions

[2009/05/10 11:41:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2009/05/10 11:41:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\mozilla\Firefox\Profiles\1wlaqw20.default\extensions

[2009/06/11 13:39:20 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions

[2009/05/10 11:40:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009/06/11 13:27:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

[2009/04/23 21:38:30 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll

[2009/04/23 21:38:32 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll

[2009/04/23 17:39:08 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml

[2009/04/23 17:39:08 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml

[2009/04/23 17:39:08 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml

[2009/04/23 17:39:08 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml

[2009/04/23 17:39:08 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml

[2009/04/23 17:39:08 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml

[2009/04/23 17:39:08 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (305265 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: 127.0.0.1 www.007guard.com

O1 - Hosts: 127.0.0.1 007guard.com

O1 - Hosts: 127.0.0.1 008i.com

O1 - Hosts: 127.0.0.1 www.008k.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 www.00hq.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 010402.com

O1 - Hosts: 127.0.0.1 www.032439.com

O1 - Hosts: 127.0.0.1 032439.com

O1 - Hosts: 127.0.0.1 www.0scan.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 www.1000gratisproben.com

O1 - Hosts: 127.0.0.1 1000gratisproben.com

O1 - Hosts: 127.0.0.1 www.1001namen.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 100888290cs.com

O1 - Hosts: 127.0.0.1 www.100888290cs.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 www.100sexlinks.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 www.10sek.com

O1 - Hosts: 127.0.0.1 www.1-2005-search.com

O1 - Hosts: 127.0.0.1 1-2005-search.com

O1 - Hosts: 10535 more lines...

O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)

O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found

O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)

O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)

O4 - HKLM..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run (Hewlett-Packard Company)

O4 - HKLM..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe (Hewlett-Packard)

O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found

O4 - HKLM..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,[email protected] ()

O4 - HKLM..\Run: [mumservice] C:\Program Files\Motorola\Software Update\mumservice.exe (Motorola)

O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)

O4 - HKLM..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent File not found

O4 - HKLM..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)

O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)

O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)

O4 - HKCU..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - HKCU..\Run: [Weather Pulse] C:\Program Files\Weather Pulse\weatherpulse.exe (Tropic Designs)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()

O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()

O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O15 - HKLM\..Trusted Domains: antimalwareguard.com ([]* in Trusted sites)

O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKCU\..Trusted Domains: antimalwareguard.com ([]* in Trusted sites)

O15 - HKCU\..Trusted Domains: 55 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)

O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)

O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Reg Error: Key error.)

O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)

O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)

O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)

O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)

O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)

O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)

O24 - Desktop Components:0 (My Current Home Page) - About:Home

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2005/06/24 22:32:00 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]

O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell - "" = AutoRun

O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun - "" = Auto&Play

O34 - HKLM BootExecute: (autocheck) - File not found

O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)

O34 - HKLM BootExecute: (*) - * [2009/06/12 11:24:58 | 00,000,000 | ---D | M]

NetSvcs: 6to4 -

NetSvcs: AppMgmt - File not found

NetSvcs: AudioSrv - C:\WINDOWS\System32\audiosrv.dll (Microsoft Corporation)

NetSvcs: Browser - C:\WINDOWS\System32\browser.dll (Microsoft Corporation)

NetSvcs: CryptSvc - C:\WINDOWS\System32\cryptsvc.dll (Microsoft Corporation)

NetSvcs: DMServer - C:\WINDOWS\System32\dmserver.dll (Microsoft Corp.)

NetSvcs: DHCP - C:\WINDOWS\System32\dhcpcsvc.dll (Microsoft Corporation)

NetSvcs: ERSvc - C:\WINDOWS\System32\ersvc.dll (Microsoft Corporation)

NetSvcs: EventSystem - C:\WINDOWS\system32\es.dll (Microsoft Corporation)

NetSvcs: FastUserSwitchingCompatibility - C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)

NetSvcs: HidServ - File not found

NetSvcs: Ias -

NetSvcs: Iprip -

NetSvcs: Irmon -

NetSvcs: LanmanServer - C:\WINDOWS\System32\srvsvc.dll (Microsoft Corporation)

NetSvcs: LanmanWorkstation - C:\WINDOWS\System32\wkssvc.dll (Microsoft Corporation)

NetSvcs: Messenger - C:\WINDOWS\System32\msgsvc.dll (Microsoft Corporation)

NetSvcs: Netman - C:\WINDOWS\System32\netman.dll (Microsoft Corporation)

NetSvcs: Nla - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)

NetSvcs: Ntmssvc - C:\WINDOWS\system32\ntmssvc.dll (Microsoft Corporation)

NetSvcs: NWCWorkstation -

NetSvcs: Nwsapagent -

NetSvcs: Rasauto - C:\WINDOWS\System32\rasauto.dll (Microsoft Corporation)

NetSvcs: Rasman - C:\WINDOWS\System32\rasmans.dll (Microsoft Corporation)

NetSvcs: Remoteaccess - C:\WINDOWS\System32\mprdim.dll (Microsoft Corporation)

NetSvcs: Schedule - C:\WINDOWS\system32\schedsvc.dll (Microsoft Corporation)

NetSvcs: Seclogon - C:\WINDOWS\System32\seclogon.dll (Microsoft Corporation)

NetSvcs: SENS - C:\WINDOWS\system32\sens.dll (Microsoft Corporation)

NetSvcs: Sharedaccess - C:\WINDOWS\System32\ipnathlp.dll (Microsoft Corporation)

NetSvcs: SRService - C:\WINDOWS\system32\srsvc.dll (Microsoft Corporation)

NetSvcs: Tapisrv - C:\WINDOWS\System32\tapisrv.dll (Microsoft Corporation)

NetSvcs: Themes - C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)

NetSvcs: TrkWks - C:\WINDOWS\system32\trkwks.dll (Microsoft Corporation)

NetSvcs: W32Time - C:\WINDOWS\system32\w32time.dll (Microsoft Corporation)

NetSvcs: WZCSVC - C:\WINDOWS\System32\wzcsvc.dll (Microsoft Corporation)

NetSvcs: Wmi -

NetSvcs: WmdmPmSp -

NetSvcs: winmgmt - C:\WINDOWS\system32\wbem\WMIsvc.dll (Microsoft Corporation)

NetSvcs: wscsvc - C:\WINDOWS\system32\wscsvc.dll (Microsoft Corporation)

NetSvcs: xmlprov - C:\WINDOWS\System32\xmlprov.dll (Microsoft Corporation)

NetSvcs: BITS - C:\WINDOWS\system32\qmgr.dll (Microsoft Corporation)

NetSvcs: wuauserv - C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)

NetSvcs: ShellHWDetection - C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)

NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)

NetSvcs: WmdmPmSN - C:\WINDOWS\system32\MsPMSNSv.dll (Microsoft Corporation)

NetSvcs: napagent - C:\WINDOWS\System32\qagentrt.dll (Microsoft Corporation)

NetSvcs: hkmsvc - C:\WINDOWS\System32\kmsvc.dll (Microsoft Corporation)

SafeBootMin: AppMgmt - (Microsoft Corporation)

SafeBootMin: Base - Driver Group

SafeBootMin: Boot Bus Extender - Driver Group

SafeBootMin: Boot file system - Driver Group

SafeBootMin: CryptSvc - (Microsoft Corporation)

SafeBootMin: DcomLaunch - (Microsoft Corporation)

SafeBootMin: dmadmin - (Microsoft Corp., Veritas Software)

SafeBootMin: dmboot.sys - (Microsoft Corp., Veritas Software)

SafeBootMin: dmio.sys - (Microsoft Corp., Veritas Software)

SafeBootMin: dmload.sys - (Microsoft Corp., Veritas Software.)

SafeBootMin: dmserver - (Microsoft Corp.)

SafeBootMin: EventLog - (Microsoft Corporation)

SafeBootMin: File system - Driver Group

SafeBootMin: Filter - Driver Group

SafeBootMin: HelpSvc - (Microsoft Corporation)

SafeBootMin: Netlogon - (Microsoft Corporation)

SafeBootMin: PCI Configuration - Driver Group

SafeBootMin: PlugPlay - (Microsoft Corporation)

SafeBootMin: PNP Filter - Driver Group

SafeBootMin: Primary disk - Driver Group

SafeBootMin: RpcSs - (Microsoft Corporation)

SafeBootMin: SCSI Class - Driver Group

SafeBootMin: sermouse.sys - Driver

SafeBootMin: sr.sys - (Microsoft Corporation)

SafeBootMin: SRService - (Microsoft Corporation)

SafeBootMin: System Bus Extender - Driver Group

SafeBootMin: vds - Service

SafeBootMin: vga.sys - Driver

SafeBootMin: vgasave.sys - (Microsoft Corporation)

SafeBootMin: WinMgmt - (Microsoft Corporation)

SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy

SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: AFD - (Microsoft Corporation)

SafeBootNet: AppMgmt - (Microsoft Corporation)

SafeBootNet: Base - Driver Group

SafeBootNet: Boot Bus Extender - Driver Group

SafeBootNet: Boot file system - Driver Group

SafeBootNet: Browser - (Microsoft Corporation)

SafeBootNet: CryptSvc - (Microsoft Corporation)

SafeBootNet: DcomLaunch - (Microsoft Corporation)

SafeBootNet: Dhcp - (Microsoft Corporation)

SafeBootNet: dmadmin - (Microsoft Corp., Veritas Software)

SafeBootNet: dmboot.sys - (Microsoft Corp., Veritas Software)

SafeBootNet: dmio.sys - (Microsoft Corp., Veritas Software)

SafeBootNet: dmload.sys - (Microsoft Corp., Veritas Software.)

SafeBootNet: dmserver - (Microsoft Corp.)

SafeBootNet: DnsCache - (Microsoft Corporation)

SafeBootNet: EventLog - (Microsoft Corporation)

SafeBootNet: File system - Driver Group

SafeBootNet: Filter - Driver Group

SafeBootNet: HelpSvc - (Microsoft Corporation)

SafeBootNet: ip6fw.sys - (Microsoft Corporation)

SafeBootNet: ipnat.sys - (Microsoft Corporation)

SafeBootNet: LanmanServer - (Microsoft Corporation)

SafeBootNet: LanmanWorkstation - (Microsoft Corporation)

SafeBootNet: LmHosts - (Microsoft Corporation)

SafeBootNet: Messenger - (Microsoft Corporation)

SafeBootNet: NDIS - (Microsoft Corporation)

SafeBootNet: NDIS Wrapper - Driver Group

SafeBootNet: Ndisuio - (Microsoft Corporation)

SafeBootNet: NetBIOS - (Microsoft Corporation)

SafeBootNet: NetBIOSGroup - Driver Group

SafeBootNet: NetBT - (Microsoft Corporation)

SafeBootNet: NetDDEGroup - Driver Group

SafeBootNet: Netlogon - (Microsoft Corporation)

SafeBootNet: NetMan - (Microsoft Corporation)

SafeBootNet: Network - Driver Group

SafeBootNet: NetworkProvider - Driver Group

SafeBootNet: NtLmSsp - (Microsoft Corporation)

SafeBootNet: PCI Configuration - Driver Group

SafeBootNet: PlugPlay - (Microsoft Corporation)

SafeBootNet: PNP Filter - Driver Group

SafeBootNet: PNP_TDI - Driver Group

SafeBootNet: Primary disk - Driver Group

SafeBootNet: rdpcdd.sys - (Microsoft Corporation)

SafeBootNet: rdpdd.sys - (Microsoft Corporation)

SafeBootNet: rdpwd.sys - (Microsoft Corporation)

SafeBootNet: rdsessmgr - (Microsoft Corporation)

SafeBootNet: RpcSs - (Microsoft Corporation)

SafeBootNet: SCSI Class - Driver Group

SafeBootNet: sermouse.sys - Driver

SafeBootNet: SharedAccess - (Microsoft Corporation)

SafeBootNet: sr.sys - (Microsoft Corporation)

SafeBootNet: SRService - (Microsoft Corporation)

SafeBootNet: Streams Drivers - Driver Group

SafeBootNet: System Bus Extender - Driver Group

SafeBootNet: Tcpip - (Microsoft Corporation)

SafeBootNet: TDI - Driver Group

SafeBootNet: tdpipe.sys - (Microsoft Corporation)

SafeBootNet: tdtcp.sys - (Microsoft Corporation)

SafeBootNet: termservice - (Microsoft Corporation)

SafeBootNet: vga.sys - Driver

SafeBootNet: vgasave.sys - (Microsoft Corporation)

SafeBootNet: WinMgmt - (Microsoft Corporation)

SafeBootNet: WZCSVC - (Microsoft Corporation)

SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net

SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient

SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService

SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans

SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)

ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)

ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow

ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4

ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 10.4

ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation

ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 10.4

ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java

ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack

ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe

ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)

ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring

ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow

ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx

ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help

ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes

ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7

ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW

ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools

ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements

ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player

ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access

ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework

ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders

ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll

ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings

ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install

ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser

ActiveX: {8D1D0E9A-C799-4D28-9E29-0061D1E66E43} - Microsoft .NET Framework 1.1 Hotfix (KB928366)

ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding

ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider

ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts

ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework

ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler

ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1

ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player

ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help

ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.

ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface

ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe

ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP

ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig

ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

Drivers32: midi - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)

Drivers32: midimapper - C:\WINDOWS\system32\midimap.dll (Microsoft Corporation)

Drivers32: mixer - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)

Drivers32: msacm.imaadpcm - C:\WINDOWS\system32\imaadp32.acm (Microsoft Corporation)

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)

Drivers32: msacm.msadpcm - C:\WINDOWS\system32\msadp32.acm (Microsoft Corporation)

Drivers32: msacm.msaudio1 - C:\WINDOWS\system32\msaud32.acm (Microsoft Corporation)

Drivers32: msacm.msg711 - C:\WINDOWS\system32\msg711.acm (Microsoft Corporation)

Drivers32: msacm.msg723 - C:\WINDOWS\system32\msg723.acm (Microsoft Corporation)

Drivers32: msacm.msgsm610 - C:\WINDOWS\system32\msgsm32.acm (Microsoft Corporation)

Drivers32: msacm.sl_anet - C:\WINDOWS\system32\sl_anet.acm (Sipro Lab Telecom Inc.)

Drivers32: msacm.trspch - C:\WINDOWS\system32\tssoft32.acm (DSP GROUP, INC.)

Drivers32: vidc.cvid - C:\WINDOWS\system32\iccvid.dll (Radius Inc.)

Drivers32: vidc.I420 - C:\WINDOWS\system32\msh263.drv (Microsoft Corporation)

Drivers32: vidc.iv31 - C:\WINDOWS\system32\ir32_32.dll ()

Drivers32: vidc.iv32 - C:\WINDOWS\system32\ir32_32.dll ()

Drivers32: vidc.iv41 - C:\WINDOWS\system32\ir41_32.ax (Intel Corporation)

Drivers32: vidc.iv50 - C:\WINDOWS\system32\ir50_32.dll (Intel Corporation)

Drivers32: vidc.iyuv - C:\WINDOWS\system32\iyuv_32.dll (Microsoft Corporation)

Drivers32: vidc.LEAD - C:\WINDOWS\system32\LCODCCMP.DLL (LEAD Technologies, Inc.)

Drivers32: vidc.M261 - C:\WINDOWS\system32\msh261.drv (Microsoft Corporation)

Drivers32: vidc.M263 - C:\WINDOWS\system32\msh263.drv (Microsoft Corporation)

Drivers32: vidc.mrle - C:\WINDOWS\system32\msrle32.dll (Microsoft Corporation)

Drivers32: vidc.msvc - C:\WINDOWS\system32\msvidc32.dll (Microsoft Corporation)

Drivers32: vidc.uyvy - C:\WINDOWS\system32\msyuv.dll (Microsoft Corporation)

Drivers32: vidc.yuy2 - C:\WINDOWS\system32\msyuv.dll (Microsoft Corporation)

Drivers32: vidc.yvu9 - C:\WINDOWS\system32\tsbyuv.dll (Microsoft Corporation)

Drivers32: vidc.yvyu - C:\WINDOWS\system32\msyuv.dll (Microsoft Corporation)

Drivers32: wave - C:\WINDOWS\system32\wdmaud.drv (Microsoft Corporation)

Drivers32: wavemapper - C:\WINDOWS\system32\msacm32.drv (Microsoft Corporation)

========== Files/Folders - Created Within 30 Days ==========

[2099/01/01 12:00:00 | 00,011,168 | -H-- | C] () -- C:\WINDOWS\System32\bikiyodi

[2009/06/12 11:23:35 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.exe

[2009/06/12 11:15:06 | 00,000,000 | ---D | C] -- C:\_OTM

[2009/06/12 11:14:17 | 00,389,632 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTM.exe

[2009/06/11 13:21:18 | 00,094,208 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\GooredFix.exe

[2009/06/11 13:20:12 | 00,000,000 | ---D | C] -- C:\Rooter$

[2009/06/11 13:18:44 | 00,128,861 | ---- | C] (Eric_71) -- C:\Documents and Settings\HP_Owner\Desktop\Rooter.exe

[2009/06/10 18:44:23 | 12,074,88512 | -HS- | C] () -- C:\hiberfil.sys

[2009/06/04 15:22:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Application Data\KodakCredentialStore

[2008/10/21 14:24:22 | 00,000,040 | ---- | C] () -- C:\WINDOWS\nero.INI

[2007/09/26 10:24:21 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2007/05/17 10:16:06 | 00,000,071 | ---- | C] () -- C:\WINDOWS\EurekaLog.ini

[2007/01/02 16:14:10 | 00,000,166 | ---- | C] () -- C:\WINDOWS\PONY.INI

[2006/06/22 21:03:05 | 00,000,227 | ---- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini

[2006/06/22 21:02:55 | 00,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini

[2006/06/22 21:01:53 | 00,000,228 | ---- | C] () -- C:\WINDOWS\HP_ISRegionListUpdatelog_HPSU.ini

[2006/06/22 21:01:40 | 00,000,214 | ---- | C] () -- C:\WINDOWS\HP_InstantSHareJPG.ini

[2006/06/22 20:59:38 | 00,000,217 | ---- | C] () -- C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini

[2006/06/19 15:01:28 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcevs.dll

[2006/06/12 19:41:42 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI

[2006/05/23 22:23:40 | 00,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini

[2006/05/23 22:21:40 | 00,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini

[2006/02/03 15:24:27 | 00,000,405 | ---- | C] () -- C:\WINDOWS\cdplayer.ini

[2006/01/22 17:22:47 | 00,000,305 | ---- | C] () -- C:\WINDOWS\bundle.ini

[2006/01/22 17:01:50 | 00,000,039 | ---- | C] () -- C:\WINDOWS\Primax7700.ini

[2006/01/22 16:51:27 | 00,001,046 | ---- | C] () -- C:\WINDOWS\maxlink.ini

[2005/09/10 13:37:36 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2005/09/10 13:01:51 | 00,013,568 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS

[2005/09/10 13:01:42 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll

[2005/09/10 12:58:38 | 00,000,172 | ---- | C] () -- C:\WINDOWS\Quicken.ini

[2005/09/10 12:52:15 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2005/09/10 12:33:03 | 00,000,269 | ---- | C] () -- C:\WINDOWS\WININIT.INI

[2005/09/10 12:12:05 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini

[2005/09/10 12:05:08 | 00,138,945 | ---- | C] () -- C:\WINDOWS\System32\VGAunistlog.ini

[2005/09/10 12:05:08 | 00,075,418 | ---- | C] () -- C:\WINDOWS\VGAsetup.ini

[2005/09/10 11:51:28 | 00,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini

[2005/09/10 11:46:17 | 00,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll

[2005/06/24 22:32:00 | 00,000,817 | ---- | C] () -- C:\WINDOWS\win.ini

[2005/06/24 15:26:26 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

[2005/05/09 23:52:32 | 00,022,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys

[2004/06/15 22:38:02 | 00,000,560 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini

[2003/01/07 22:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

[2001/07/06 22:30:00 | 00,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini

========== Files - Modified Within 30 Days ==========

[9 C:\WINDOWS\System32\*.tmp files]

[2 C:\WINDOWS\*.tmp files]

[2009/06/12 11:25:00 | 00,000,366 | ---- | M] () -- C:\WINDOWS\tasks\Symantec NetDetect.job

[2009/06/12 11:23:35 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.exe

[2009/06/12 11:23:23 | 00,000,248 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.dat

[2009/06/12 11:20:09 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009/06/12 11:19:53 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\HP_Owner\Local Settings\desktop.ini

[2009/06/12 11:19:51 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009/06/12 11:19:49 | 12,074,88512 | -HS- | M] () -- C:\hiberfil.sys

[2009/06/12 11:14:17 | 00,389,632 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTM.exe

[2009/06/12 11:11:59 | 37,066,405 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm

[2009/06/12 11:11:59 | 00,075,180 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg

[2009/06/11 13:21:18 | 00,094,208 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\GooredFix.exe

[2009/06/11 13:18:44 | 00,128,861 | ---- | M] (Eric_71) -- C:\Documents and Settings\HP_Owner\Desktop\Rooter.exe

[2009/06/11 12:15:28 | 00,000,071 | ---- | M] () -- C:\WINDOWS\EurekaLog.ini

[2009/06/11 07:30:45 | 00,165,912 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2009/06/10 22:43:23 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2009/06/07 20:37:45 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009/06/04 15:23:00 | 03,859,456 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb

[2009/06/04 15:22:59 | 06,673,408 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb

[2009/06/01 09:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe

========== LOP Check ==========

[2009/05/10 11:45:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data

[2005/09/10 12:42:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe

[2007/09/26 10:15:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ahead

[2009/01/07 18:06:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ArcSoft

[2009/03/04 17:53:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg8

[2008/10/22 13:59:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVS4YOU

[2007/06/16 08:02:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software

[2006/05/27 14:10:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink

[2006/06/19 15:04:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FaxCtr

[2009/05/21 10:58:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google

[2008/05/24 16:53:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft

[2005/09/10 13:31:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard

[2005/09/10 12:16:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HP

[2008/12/10 17:00:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HP Product Assistant

[2005/09/10 12:33:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallShield

[2005/09/10 12:58:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intuit

[2006/08/20 15:56:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear

[2009/02/22 10:52:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kodak

[2008/08/31 11:53:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2009/03/15 12:06:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft

[2009/01/09 17:05:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir

[2008/03/11 16:51:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon

[2005/09/10 12:53:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\QuickTime

[2006/07/25 19:39:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games

[2005/09/10 11:53:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI

[2005/09/10 12:15:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sonic

[2008/01/21 16:58:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony Ericsson

[2009/04/06 09:27:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

[2009/01/01 17:50:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Symantec

[2008/01/21 16:58:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Teleca

[2009/05/05 19:54:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2007/08/30 14:29:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Transparent

[2006/03/03 17:19:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia

[2006/04/17 14:03:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage

[2009/01/23 01:23:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Yahoo!

[2008/12/30 20:18:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion

[2009/06/04 15:22:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data

[2008/05/13 17:57:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Adobe

[2006/06/20 19:55:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\AdobeAUM

[2008/05/24 07:55:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\AdobeUM

[2007/09/26 10:59:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Ahead

[2007/12/25 14:50:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\alawar

[2008/08/10 12:06:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Any Video Converter

[2005/09/10 12:53:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Apple Computer

[2009/01/08 18:06:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\ArcSoft

[2008/10/22 13:59:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\AVSMedia

[2009/04/11 21:05:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Blitware

[2006/05/27 14:16:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\CyberLink

[2006/06/20 13:00:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\FaxCtr

[2008/12/23 22:05:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\FrostWire

[2006/03/26 10:08:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\FUJIFILM

[2006/12/04 18:57:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\funkitron

[2006/11/03 19:47:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Google

[2007/03/31 10:30:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Help

[2006/05/29 19:21:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\HP

[2006/01/22 17:07:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\HPQ

[2005/07/13 09:48:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Identities

[2007/05/28 17:48:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\InstallShield

[2005/09/10 12:57:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Intuit

[2009/06/04 15:22:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\KodakCredentialStore

[2006/02/04 17:01:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Lavasoft

[2006/02/03 15:22:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Leadertech

[2006/01/22 18:51:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Macromedia

[2008/08/31 11:53:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Malwarebytes

[2009/01/01 17:31:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Microsoft

[2009/05/10 11:41:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla

[2009/04/29 20:42:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\MSNInstaller

[2008/10/03 15:36:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\MySpace

[2008/03/11 16:51:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Oberon

[2009/01/08 10:56:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\OpenOffice.org2

[2006/07/18 16:33:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\PlayFirst

[2008/03/10 21:33:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Pogo Games

[2009/01/01 17:32:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Real

[2005/09/10 13:00:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\SampleView

[2007/02/04 19:36:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\ScamBlocker

[2009/01/07 18:12:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Skinux

[2006/02/03 15:23:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Sonic

[2007/01/21 12:46:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Sony Ericsson

[2006/01/26 21:47:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Sun

[2009/01/01 17:32:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Symantec

[2008/01/21 17:30:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Teleca

[2006/06/11 10:19:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Template

[2009/05/11 13:53:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Vso

[2009/01/01 18:06:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Weather Pulse

[2007/08/23 20:44:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\WinBatch

[2009/04/18 15:16:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\WinRAR

[2008/03/12 19:55:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\HP_Owner\Application Data\Yahoo!

[2004/08/04 12:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini

[2009/06/12 11:20:09 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

[2009/06/12 11:25:00 | 00,000,366 | ---- | M] () -- C:\WINDOWS\Tasks\Symantec NetDetect.job

========== Purity Check ==========

========== Custom Scans ==========

< %systemroot%\System32\antiwpa.dll >

< %systemroot%\SYSTEM32\wpa.dll >

< %systemroot%\setup\scripts\biestart.exe >

< %systemroot%\system32\drivers\royal.sys >

< %SYSTEMDRIVE%\*. >

[2009/06/12 11:24:58 | 00,000,000 | ---D | M] -- C:

[2009/06/11 12:21:19 | 00,000,000 | -H-D | M] -- C:\$AVG8.VAULT$

[2009/06/12 11:15:06 | 00,000,000 | ---D | M] -- C:\_OTM

[2009/01/01 17:53:17 | 00,000,000 | RHSD | M] -- C:\cmdcons

[2009/06/11 20:19:39 | 00,000,000 | -HSD | M] -- C:\Config.Msi

[2009/01/01 15:28:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings

[2007/01/05 16:16:33 | 00,000,000 | ---D | M] -- C:\Downloads

[2006/01/30 16:56:28 | 00,000,000 | ---D | M] -- C:\Encore Software

[2007/02/11 12:49:45 | 00,000,000 | ---D | M] -- C:\f151cf42a4ccc10168db

[2009/03/20 16:26:22 | 00,000,000 | -HSD | M] -- C:\found.000

[2009/01/04 12:18:16 | 00,000,000 | ---D | M] -- C:\fsaua.data

[2008/11/16 09:53:59 | 00,000,000 | ---D | M] -- C:\Games

[2008/08/21 13:44:45 | 00,000,000 | ---D | M] -- C:\hijackthis

[2009/01/01 18:00:38 | 00,000,000 | -H-D | M] -- C:\hp

[2006/01/30 16:38:50 | 00,000,000 | ---D | M] -- C:\Images

[2006/01/22 17:16:33 | 00,000,000 | ---D | M] -- C:\KPCMS

[2009/01/01 13:36:29 | 00,000,000 | RH-D | M] -- C:\MSOCache

[2008/08/10 12:31:51 | 00,000,000 | ---D | M] -- C:\My Music

[2008/07/06 19:42:37 | 00,000,000 | ---D | M] -- C:\Pictures

[2009/05/11 13:22:46 | 00,000,000 | ---D | M] -- C:\Program Files

[2009/05/11 13:14:52 | 00,000,000 | ---D | M] -- C:\Python22

[2009/05/10 14:02:36 | 00,000,000 | ---D | M] -- C:\Qoobox

[2009/05/11 13:07:51 | 00,000,000 | -HSD | M] -- C:\RECYCLER

[2007/07/14 14:54:41 | 00,000,000 | ---D | M] -- C:\Ringtones

[2009/06/11 13:20:13 | 00,000,000 | ---D | M] -- C:\Rooter$

[2006/06/19 15:15:57 | 00,000,000 | ---D | M] -- C:\ScanSoft Documents

[2009/04/05 09:01:10 | 00,000,000 | -HSD | M] -- C:\System Volume Information

[2005/09/10 11:46:17 | 00,000,000 | -H-D | M] -- C:\system.sav

[2008/12/10 16:55:37 | 00,000,000 | ---D | M] -- C:\SystemRoot

[2007/09/26 10:01:45 | 00,000,000 | ---D | M] -- C:\Temp

[2009/06/11 07:31:28 | 00,000,000 | ---D | M] -- C:\WINDOWS

[2007/12/29 21:55:57 | 00,000,000 | ---D | M] -- C:\ZCAVIToDVD

< %SYSTEMDRIVE%\*.* >

[2005/06/24 22:32:00 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT

[2009/01/01 15:27:17 | 00,000,213 | RHS- | M] () -- C:\BOOT.BAK

[2009/01/01 17:53:22 | 00,000,283 | RHS- | M] () -- C:\boot.ini

[2006/06/19 15:01:14 | 00,000,242 | ---- | M] () -- C:\CDFE.log

[2009/02/22 10:40:18 | 00,231,896 | ---- | M] () -- C:\ClearLog.txt

[2004/08/04 05:00:00 | 00,260,272 | RHS- | M] () -- C:\cmldr

[2009/05/10 14:02:32 | 00,015,041 | ---- | M] () -- C:\ComboFix.txt

[2005/06/24 22:32:00 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2007/06/16 07:40:28 | 00,000,000 | ---- | M] () -- C:\DBS.TXT

[2007/03/25 12:49:40 | 00,010,450 | ---- | M] () -- C:\debug.log

[2007/02/26 17:09:59 | 00,000,213 | ---- | M] () -- C:\Expiration.Log

[2008/02/02 22:27:25 | 00,468,301 | ---- | M] () -- C:\fout

[2009/06/12 11:19:49 | 12,074,88512 | -HS- | M] () -- C:\hiberfil.sys

[2005/06/24 22:32:00 | 00,000,000 | RHS- | M] () -- C:\IO.SYS

[2006/08/09 17:41:45 | 00,000,026 | ---- | M] () -- C:\ioSpecial.ini

[2006/03/11 21:03:06 | 00,011,031 | ---- | M] () -- C:\log.txt

[2009/01/07 17:53:56 | 00,633,178 | ---- | M] () -- C:\logfile

[2009/05/05 19:01:13 | 00,001,767 | ---- | M] () -- C:\lxce.log

[2006/06/19 15:01:05 | 00,000,000 | ---- | M] () -- C:\lxcefire.csv

[2006/06/19 15:01:42 | 00,000,867 | ---- | M] () -- C:\LXCEINST.csv

[2009/01/18 20:01:58 | 00,245,230 | ---- | M] () -- C:\lxcescan.log

[2005/06/24 22:32:00 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2004/08/04 05:00:00 | 00,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2009/01/04 18:35:40 | 00,250,048 | RHS- | M] () -- C:\ntldr

[2009/06/12 11:19:48 | 18,119,39328 | -HS- | M] () -- C:\pagefile.sys

[2005/10/31 08:56:00 | 00,700,416 | ---- | M] (LimeWire) -- C:\StubInstaller.exe

[2009/01/04 17:53:12 | 00,001,020 | ---- | M] () -- C:\updatedatfix.log

[2008/03/06 11:10:32 | 00,000,146 | ---- | M] () -- C:\YServer.txt

< %PROGRAMFILES%\*. >

[2009/05/11 13:22:46 | 00,000,000 | ---D | M] -- C:\Program Files

[2008/07/27 16:18:22 | 00,000,000 | ---D | M] -- C:\Program Files\3GP Converter 2007

[2006/01/28 11:54:42 | 00,000,000 | ---D | M] -- C:\Program Files\Abacast

[2006/06/19 15:06:44 | 00,000,000 | ---D | M] -- C:\Program Files\Abbyy FineReader 6.0 Sprint

[2009/01/07 14:57:30 | 00,000,000 | ---D | M] -- C:\Program Files\ACE-HIGH MP3 WAV WMA OGG Converter

[2008/07/27 16:21:13 | 00,000,000 | ---D | M] -- C:\Program Files\Acoustica Mixcraft

[2007/03/01 17:02:59 | 00,000,000 | ---D | M] -- C:\Program Files\Acoustica Shared Effects

[2005/09/10 12:42:43 | 00,000,000 | ---D | M] -- C:\Program Files\Adobe

[2008/12/30 20:14:10 | 00,000,000 | ---D | M] -- C:\Program Files\Advanced Registry Optimizer

[2008/11/04 14:34:07 | 00,000,000 | ---D | M] -- C:\Program Files\Ahead

[2007/12/25 15:11:43 | 00,000,000 | ---D | M] -- C:\Program Files\Alawar

[2008/05/24 16:57:34 | 00,000,000 | ---D | M] -- C:\Program Files\Alwil Software

[2008/08/09 19:56:15 | 00,000,000 | ---D | M] -- C:\Program Files\Any Video Converter

[2009/01/07 18:04:50 | 00,000,000 | ---D | M] -- C:\Program Files\ArcSoft

[2008/02/02 21:05:45 | 00,000,000 | ---D | M] -- C:\Program Files\ARNGAS

[2008/12/30 20:19:29 | 00,000,000 | ---D | M] -- C:\Program Files\AskBarDis

[2008/12/30 20:19:30 | 00,000,000 | ---D | M] -- C:\Program Files\AskSearch

[2007/10/16 18:46:45 | 00,000,000 | ---D | M] -- C:\Program Files\Avanquest update

[2009/03/04 17:53:04 | 00,000,000 | ---D | M] -- C:\Program Files\AVG

[2008/10/22 13:57:23 | 00,000,000 | ---D | M] -- C:\Program Files\AVSMedia

[2007/08/31 09:42:49 | 00,000,000 | ---D | M] -- C:\Program Files\BFG

[2006/08/21 14:44:14 | 00,000,000 | ---D | M] -- C:\Program Files\CDKnet

[2009/05/11 13:16:04 | 00,000,000 | ---D | M] -- C:\Program Files\Common Files

[2005/06/27 10:20:52 | 00,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications

[2005/09/10 12:11:13 | 00,000,000 | ---D | M] -- C:\Program Files\CONEXANT

[2006/05/27 14:09:43 | 00,000,000 | ---D | M] -- C:\Program Files\CyberLink

[2008/06/01 15:53:06 | 00,000,000 | ---D | M] -- C:\Program Files\Disc2Phone

[2008/08/10 13:00:57 | 00,000,000 | ---D | M] -- C:\Program Files\DsNET Corp

[2009/05/01 20:25:18 | 00,000,000 | ---D | M] -- C:\Program Files\Easy Internet signup

[2006/01/22 17:07:53 | 00,000,000 | ---D | M] -- C:\Program Files\EPSON

[2006/02/05 12:29:13 | 00,000,000 | ---D | M] -- C:\Program Files\ewido anti-malware

[2008/12/24 19:13:34 | 00,000,000 | ---D | M] -- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)

[2006/01/22 17:11:04 | 00,000,000 | ---D | M] -- C:\Program Files\FinePixViewer

[2006/02/03 13:37:53 | 00,000,000 | ---D | M] -- C:\Program Files\GameHouse

[2008/07/20 11:27:25 | 00,000,000 | ---D | M] -- C:\Program Files\GameHouse Games Collection

[2006/03/26 10:31:32 | 00,000,000 | ---D | M] -- C:\Program Files\GIMP-2.0

[2009/05/21 11:13:15 | 00,000,000 | ---D | M] -- C:\Program Files\Google

[2008/05/24 16:54:32 | 00,000,000 | ---D | M] -- C:\Program Files\Grisoft

[2009/01/04 17:52:44 | 00,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard

[2005/09/10 12:17:09 | 00,000,000 | ---D | M] -- C:\Program Files\HP

[2009/05/11 13:19:14 | 00,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information

[2005/09/10 12:43:52 | 00,000,000 | ---D | M] -- C:\Program Files\IntelliMover Data Transfer Demo

[2009/06/10 22:41:34 | 00,000,000 | ---D | M] -- C:\Program Files\Internet Explorer

[2006/12/26 17:15:32 | 00,000,000 | ---D | M] -- C:\Program Files\IrfanView

[2006/09/22 16:27:34 | 00,000,000 | ---D | M] -- C:\Program Files\Jasc Software Inc

[2009/06/11 13:27:18 | 00,000,000 | ---D | M] -- C:\Program Files\Java

[2009/02/22 11:00:32 | 00,000,000 | ---D | M] -- C:\Program Files\KODAK

[2006/02/04 17:00:52 | 00,000,000 | ---D | M] -- C:\Program Files\Lavasoft

[2009/01/18 11:14:08 | 00,000,000 | ---D | M] -- C:\Program Files\Lexmark 4300 Series

[2006/06/19 15:05:40 | 00,000,000 | ---D | M] -- C:\Program Files\Lexmark Fax Solutions

[2009/06/11 12:05:10 | 00,000,000 | ---D | M] -- C:\Program Files\Lx_cats

[2006/08/20 15:56:43 | 00,000,000 | ---D | M] -- C:\Program Files\Mahjong Escape

[2006/06/14 22:16:25 | 00,000,000 | ---D | M] -- C:\Program Files\Majesco Entertainment

[2009/05/10 11:33:14 | 00,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware

[2009/01/05 04:08:16 | 00,000,000 | ---D | M] -- C:\Program Files\Messenger

[2006/01/22 16:33:02 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft

[2005/09/10 12:50:51 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync

[2005/07/13 09:48:48 | 00,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage

[2005/09/10 12:44:41 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Money 2005

[2005/09/10 12:50:27 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Office

[2005/09/10 12:44:54 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Dancer LE

[2005/09/10 12:45:26 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Digital Media Edition

[2005/09/10 12:45:15 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Photo Story 2 LE

[2005/09/10 12:50:26 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio

[2005/09/10 12:48:25 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Works

[2005/09/10 12:49:29 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET

[2007/05/16 11:56:10 | 00,000,000 | ---D | M] -- C:\Program Files\Mirror Magic

[2008/12/24 19:13:33 | 00,000,000 | ---D | M] -- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)

[2009/05/11 13:19:15 | 00,000,000 | ---D | M] -- C:\Program Files\Motorola

[2007/10/16 18:49:18 | 00,000,000 | ---D | M] -- C:\Program Files\Motorola Phone Tools

[2009/01/04 18:39:24 | 00,000,000 | ---D | M] -- C:\Program Files\Movie Maker

[2009/06/11 13:46:14 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox

[2005/07/13 09:48:52 | 00,000,000 | ---D | M] -- C:\Program Files\MSN

[2005/09/10 12:29:34 | 00,000,000 | ---D | M] -- C:\Program Files\MSN Encarta Standard

[2005/07/13 09:48:56 | 00,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone

[2006/11/18 19:51:52 | 00,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0

[2007/01/21 15:50:44 | 00,000,000 | ---D | M] -- C:\Program Files\mTC

[2009/03/10 17:13:29 | 00,000,000 | ---D | M] -- C:\Program Files\MySpace

[2007/03/01 16:27:46 | 00,000,000 | ---D | M] -- C:\Program Files\MysteryCaseFilesHuntsville_at

[2009/01/04 18:39:07 | 00,000,000 | ---D | M] -- C:\Program Files\NetMeeting

[2009/04/06 12:07:01 | 00,000,000 | ---D | M] -- C:\Program Files\Norton Security Scan

[2008/08/21 14:05:34 | 00,000,000 | ---D | M] -- C:\Program Files\Oberon Media

[2005/09/10 13:14:11 | 00,000,000 | ---D | M] -- C:\Program Files\Online Services

[2008/06/25 13:10:38 | 00,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 2.3

[2008/06/25 13:11:48 | 00,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 2.4

[2009/01/04 18:39:00 | 00,000,000 | ---D | M] -- C:\Program Files\Outlook Express

[2009/03/30 09:34:41 | 00,000,000 | ---D | M] -- C:\Program Files\Panda Security

[2005/09/10 13:17:44 | 00,000,000 | ---D | M] -- C:\Program Files\PC-Doctor 5 for Windows

[2005/09/10 13:09:16 | 00,000,000 | ---D | M] -- C:\Program Files\PC-Doctor for DOS

[2006/04/08 12:31:56 | 00,000,000 | ---D | M] -- C:\Program Files\PopCap Games

[2005/09/10 12:58:41 | 00,000,000 | ---D | M] -- C:\Program Files\Quicken

[2005/09/10 12:53:41 | 00,000,000 | ---D | M] -- C:\Program Files\QuickTime

[2005/09/10 12:30:37 | 00,000,000 | ---D | M] -- C:\Program Files\Real

[2006/08/09 17:32:57 | 00,000,000 | ---D | M] -- C:\Program Files\ReflexiveArcade

[2006/01/22 17:10:21 | 00,000,000 | ---D | M] -- C:\Program Files\REGSHAVE

[2008/12/24 19:13:34 | 00,000,000 | ---D | M] -- C:\Program Files\SDHelper (Spybot - Search & Destroy)

[2005/09/10 12:05:41 | 00,000,000 | ---D | M] -- C:\Program Files\SiS VGA Utilities V3.67e

[2007/02/08 13:54:57 | 00,000,000 | ---D | M] -- C:\Program Files\Skype

[2007/12/07 15:53:44 | 00,000,000 | ---D | M] -- C:\Program Files\SmartSoftVideoConverter

[2009/05/11 13:17:57 | 00,000,000 | ---D | M] -- C:\Program Files\Sonic

[2008/01/21 16:57:50 | 00,000,000 | ---D | M] -- C:\Program Files\Sony Ericsson

[2009/04/10 16:41:20 | 00,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy

[2009/05/05 19:52:44 | 00,000,000 | ---D | M] -- C:\Program Files\SpywareBlaster

[2009/01/01 17:50:44 | 00,000,000 | ---D | M] -- C:\Program Files\Symantec

[2009/04/06 09:21:18 | 00,000,000 | ---D | M] -- C:\Program Files\TeaTimer (Spybot - Search & Destroy)

[2008/12/30 20:12:22 | 00,000,000 | ---D | M] -- C:\Program Files\The Weather Channel FW

[2006/07/07 13:53:42 | 00,000,000 | ---D | M] -- C:\Program Files\Thomson

[2007/03/01 16:41:56 | 00,000,000 | ---D | M] -- C:\Program Files\Total Video Converter

[2007/08/30 14:29:56 | 00,000,000 | ---D | M] -- C:\Program Files\Transparent

[2008/08/21 13:47:15 | 00,000,000 | ---D | M] -- C:\Program Files\Trend Micro

[2008/08/21 14:06:09 | 00,000,000 | ---D | M] -- C:\Program Files\Troll

[2005/06/27 10:21:02 | 00,000,000 | ---D | M] -- C:\Program Files\Uninstall Information

[2005/09/10 13:03:15 | 00,000,000 | ---D | M] -- C:\Program Files\Updates from HP

[2006/01/22 17:22:48 | 00,000,000 | ---D | M] -- C:\Program Files\Veo Stingray

[2009/05/11 13:53:56 | 00,000,000 | ---D | M] -- C:\Program Files\VSO

[2009/06/12 11:14:55 | 00,000,000 | ---D | M] -- C:\Program Files\Weather Pulse

[2009/04/18 15:17:25 | 00,000,000 | ---D | M] -- C:\Program Files\WIBUKEY

[2009/04/18 15:17:25 | 00,000,000 | ---D | M] -- C:\Program Files\WIBU-SYSTEMS

[2009/05/11 13:19:43 | 00,000,000 | ---D | M] -- C:\Program Files\WildTangent

[2006/12/19 18:23:45 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2

[2009/01/13 18:04:06 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Player

[2009/01/04 18:39:01 | 00,000,000 | ---D | M] -- C:\Program Files\Windows NT

[2005/06/27 10:21:06 | 00,000,000 | ---D | M] -- C:\Program Files\WindowsUpdate

[2009/04/18 15:16:33 | 00,000,000 | ---D | M] -- C:\Program Files\WinRAR

[2007/04/08 15:32:30 | 00,000,000 | ---D | M] -- C:\Program Files\WMA To MP3 Converter

[2005/07/13 09:49:16 | 00,000,000 | ---D | M] -- C:\Program Files\xerox

[2008/12/30 20:13:46 | 00,000,000 | ---D | M] -- C:\Program Files\Yahoo!

[2007/12/25 12:33:20 | 00,000,000 | ---D | M] -- C:\Program Files\Yahoo! Games

[2007/03/01 16:21:23 | 00,000,000 | -H-D | M] -- C:\Program Files\Zero G Registry

========== Alternate Data Streams ==========

@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4EFDF5FB

@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA

@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0879ECE9

@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >

OTL Extras logfile created on: 6/12/2009 11:25:03 AM - Run 1

OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\HP_Owner\Desktop

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.12 Gb Total Physical Memory | 0.48 Gb Available Physical Memory | 42.67% Memory free

2.69 Gb Paging File | 2.10 Gb Available in Paging File | 77.96% Paging File free

Paging file location(s): C:\pagefile.sys 1728 3456 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 29.75 Gb Total Space | 8.52 Gb Free Space | 28.63% Space Free | Partition Type: NTFS

Drive D: | 7.50 Gb Total Space | 2.16 Gb Free Space | 28.76% Space Free | Partition Type: FAT32

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: YOUR-27E1513D96

Current User Name: HP_Owner

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Output = Minimal

File Age = 30 Days

Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusOverride" = 0

"FirewallOverride" = 0

"AntiVirusDisableNotify" = 1

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

%ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes File not found

C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP (Hewlett-Packard)

%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe (Hewlett-Packard Co.)

C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe (Hewlett-Packard Co.)

C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe (Hewlett-Packard Co.)

C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe (Hewlett-Packard Co.)

C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe (Hewlett-Packard Co.)

C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe ()

C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe (Hewlett-Packard)

C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe (Hewlett-Packard Co.)

C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe (Hewlett-Packard)

C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe (Hewlett-Packard Co.)

C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe ()

C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe ( )

C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe (Hewlett-Packard Co.)

C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP (Hewlett-Packard)

C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare (Eastman Kodak Company)

%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)

C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)

C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe (AVG Technologies CZ, s.r.o.)

C:\Program Files\Motorola\Software Update\msu.exe:*:Enabled:msu (Motorola)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00060000-0000-1004-8002-0000C06B5161}" = WIBU-KEY Setup (WIBU-KEY Remove)

"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card

"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery

"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1

"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations

"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan

"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE

"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo

"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD

"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{1A103D70-5C9B-4E1A-B306-5106C68F9914}" = Microsoft Plus! Dancer LE

"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3

"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config

"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 14

"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload

"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload

"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt

"{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005

"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp

"{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0

"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices

"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1

"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant

"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer

"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works

"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore

"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg

"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001

"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy

"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book

"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap

"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg

"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1

"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B

"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA

"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr

"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1

"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc

"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer

"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin

"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08

"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware

"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder

"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config

"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up

"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder

"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr

"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS

"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini

"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003

"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui

"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme

"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse

"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL

"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy

"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers

"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour

"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder

"{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows

"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0

"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK

"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook

"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI

"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy

"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore

"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone

"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2

"{B8EF780F-126C-4CF0-AAB2-1B68BF06BA1C}" = Motorola Driver Installation 3.7.0

"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm

"{BE9FEFBA-F2F8-468B-A108-4356F73A3E9C}" = Office 2003 Tour

"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan

"{C83A12B9-B31B-461A-BBD4-CE9B988094F1}" = HP Photosmart Cameras 5.0

"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar

"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax

"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = HP Organize

"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software

"{D518592A-0F1E-40ca-BECB-3D3F026C6B0D}" = CameraDrivers

"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR

"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp

"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant

"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page

"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips

"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter

"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card

"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK

"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status

"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS

"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock

"{FE155C7A-E4B9-4D98-ADB2-BC4CFFB2A12C}" = Motorola Software Update

"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update

"ActiveScan 2.0" = Panda ActiveScan 2.0

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"Adobe Shockwave Player" = Adobe Shockwave Player 11.5

"AVG8Uninstall" = AVG 8.5

"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Data Fax SoftModem with SmartCP

"HijackThis" = HijackThis 2.0.2

"HP Document Viewer" = HP Document Viewer 5.3

"HP Imaging Device Functions" = HP Imaging Device Functions 5.3

"HP Photo & Imaging" = HP Image Zone 5.3

"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3

"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)

"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs

"ie7" = Windows Internet Explorer 7

"Install WeatherBug" = Remove WeatherBug Installer

"InstallShield_{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005

"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up

"InstallShield_{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows

"Lexmark 4300 Series" = Lexmark 4300 Series

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0

"Money2005b" = Microsoft Money 2005

"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)

"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP

"MSNINST" = MSN

"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs

"QuickTime" = QuickTime

"RealPlayer 6.0" = RealPlayer

"SiS VGA Driver" = SiS VGA Utilities

"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5

"Weather Pulse_is1" = Weather Pulse 2.05 build 36

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"Windows Media Player" = Windows Media Player 11

"Windows XP Service Pack" = Windows XP Service Pack 3

"WinRAR archiver" = WinRAR archiver

"WMFDist11" = Windows Media Format 11 runtime

"wmp11" = Windows Media Player 11

"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

"Yahoo! Messenger" = Yahoo! Messenger

========== Last 10 Event Log Errors ==========

[ Application Events ]

Error - 4/19/2009 3:35:35 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000

Description = Faulting application p2kcommander.exe, version 0.0.0.0, faulting module

p2kcommander.exe, version 0.0.0.0, fault address 0x00010c7a.

Error - 4/19/2009 3:35:39 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000

Description = Faulting application msu.exe, version 2008.50.0.1, faulting module

pst.dll, version 2008.48.1.0, fault address 0x000962c7.

Error - 4/25/2009 9:41:45 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000

Description = Faulting application p2kcommander.exe, version 0.0.0.0, faulting module

p2kcommander.exe, version 0.0.0.0, fault address 0x00010c7a.

Error - 4/25/2009 9:41:52 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000

Description = Faulting application msu.exe, version 2008.50.0.1, faulting module

pst.dll, version 2008.48.1.0, fault address 0x000962c7.

Error - 4/25/2009 9:48:43 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000

Description = Faulting application p2kcommander.exe, version 0.0.0.0, faulting module

p2kcommander.exe, version 0.0.0.0, fault address 0x00010c7a.

Error - 4/25/2009 9:48:59 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000

Description = Faulting application p2kcommander.exe, version 0.0.0.0, faulting module

p2kcommander.exe, version 0.0.0.0, fault address 0x00010c7a.

Error - 4/25/2009 9:49:21 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000

Description = Faulting application p2kcommander.exe, version 0.0.0.0, faulting module

p2kcommander.exe, version 0.0.0.0, fault address 0x00010c7a.

Error - 4/25/2009 9:49:46 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000

Description = Faulting application p2kcommander.exe, version 0.0.0.0, faulting module

p2kcommander.exe, version 0.0.0.0, fault address 0x00010c7a.

Error - 4/25/2009 9:50:05 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000

Description = Faulting application p2kcommander.exe, version 0.0.0.0, faulting module

p2kcommander.exe, version 0.0.0.0, fault address 0x00010c7a.

Error - 4/25/2009 10:02:56 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000

Description = Faulting application msu.exe, version 2008.50.0.1, faulting module

pst.dll, version 2008.48.1.0, fault address 0x000962c7.

[ System Events ]

Error - 6/10/2009 2:07:26 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

ftsata2

Error - 6/10/2009 7:06:33 PM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service EventSystem

with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 6/10/2009 7:07:41 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

AmdK8 AvgLdx86 AvgMfx86 Fips ftsata2 pavboot

Error - 6/10/2009 9:33:17 PM | Computer Name = YOUR-27E1513D96 | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service EventSystem

with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 6/10/2009 9:46:28 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

ftsata2

Error - 6/11/2009 1:40:05 AM | Computer Name = YOUR-27E1513D96 | Source = sr | ID = 1

Description = The System Restore filter encountered the unexpected error '0xC0000001'

while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring

the volume.

Error - 6/11/2009 10:32:10 AM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

ftsata2

Error - 6/12/2009 2:10:34 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

ftsata2

Error - 6/12/2009 2:17:48 PM | Computer Name = YOUR-27E1513D96 | Source = sr | ID = 1

Description = The System Restore filter encountered the unexpected error '0xC0000001'

while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring

the volume.

Error - 6/12/2009 2:21:28 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

ftsata2

< End of report >

Share this post


Link to post
Share on other sites

hi

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
    O15 - HKLM\..Trusted Domains: antimalwareguard.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: antimalwareguard.com ([]* in Trusted sites)
    O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell - "" = AutoRun
    O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun - "" = Auto&Play
    [2099/01/01 12:00:00 | 00,011,168 | -H-- | C] () -- C:\WINDOWS\System32\bikiyodi
    [2009/03/20 16:26:22 | 00,000,000 | -HSD | M] -- C:\found.000

    :Services

    :Reg

    :Files

    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done

Download RootRepeal.zip and unzip it to your Desktop.

  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:

    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services

    [*]Click the OK button

    [*]In the next dialog, select all drives showing

    [*]Click OK to start the scan

    Note: The scan can take some time.
    DO NOT
    run any other programs while the scan is running

    [*]When the scan is complete, the Save Report button will become available

    [*]Click this and save the report to your Desktop as RootRepeal.txt

If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.

To attach a file, do the following:

  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on attach_add.png to insert the attachment into your post

Share this post


Link to post
Share on other sites

ROOTREPEAL © AD, 2007-2009

==================================================

Scan Time: 2009/06/14 11:10

Program Version: Version 1.3.0.0

Windows Version: Windows XP SP3

==================================================

Drivers

-------------------

Name: dump_atapi.sys

Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys

Address: 0xAF0C2000 Size: 98304 File Visible: No Signed: -

Status: -

Name: dump_WMILIB.SYS

Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS

Address: 0xBADE6000 Size: 8192 File Visible: No Signed: -

Status: -

Name: rootrepeal.sys

Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys

Address: 0xAE446000 Size: 49152 File Visible: No Signed: -

Status: -

Name: UACotnkrodakiybirv.sys

Image Path: C:\WINDOWS\system32\drivers\UACotnkrodakiybirv.sys

Address: 0xAF3A4000 Size: 81920 File Visible: - Signed: -

Status: Hidden from Windows API!

Hidden/Locked Files

-------------------

Path: C:\hiberfil.sys

Status: Locked to the Windows API!

Path: C:\WINDOWS\system32\UAChdqjkoilrlawhio.db

Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UAChtkoknbgikhvmqu.dat

Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\uacinit.dll

Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACmsqodyutpwsrthl.dll

Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACovyptehrrsioutl.dll

Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACqmrrvxfuwnqmexm.dll

Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACsnuhcfdjwuguxly.dll

Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\uactmp.db

Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACtwwrdjmiwflkmod.log

Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACulqkidrcmncelid.dll

Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACypynsbabbwkxtqh.dll

Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\UAC3227.tmp

Status: Invisible to the Windows API!

Path: C:\Program Files\Yahoo! Games\Mystery P.I. - The New York Fortune\MysteryPINewYork.exe:{F69430C2-1C01-34AB-A92B-6E5D72461829}

Status: Visible to the Windows API, but not on disk.

Path: C:\Program Files\Yahoo! Games\Sally's Salon\SallysSalon.exe:{8CF10B37-8F6C-48BF-A6CF-215AB3EF6B47}

Status: Visible to the Windows API, but not on disk.

Path: C:\Program Files\Yahoo! Games\Women's Murder Club - A Darker Shade of Grey\WMC2.exe:{F745CF62-E9C6-B82F-1623-2D95FB482B59}

Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\system32\drivers\UACotnkrodakiybirv.sys

Status: Invisible to the Windows API!

Path: C:\Documents and Settings\HP_Owner\Local Settings\Temp\UACd250.tmp

Status: Invisible to the Windows API!

Stealth Objects

-------------------

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: winlogon.exe (PID: 572) Address: 0x00670000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: winlogon.exe (PID: 572) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: services.exe (PID: 620) Address: 0x00670000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: services.exe (PID: 620) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: lsass.exe (PID: 632) Address: 0x00740000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: lsass.exe (PID: 632) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: svchost.exe (PID: 784) Address: 0x03070000 Size: 49152

Object: Hidden Module [Name: UACmsqodyutpwsrthl.dll]

Process: svchost.exe (PID: 784) Address: 0x00bb0000 Size: 69632

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: svchost.exe (PID: 784) Address: 0x00710000 Size: 49152

Object: Hidden Module [Name: UACsnuhcfdjwuguxly.dll]

Process: svchost.exe (PID: 784) Address: 0x00a10000 Size: 81920

Object: Hidden Module [Name: UAC3227.tmptehrrsioutl.dll]

Process: svchost.exe (PID: 784) Address: 0x00ac0000 Size: 200704

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: svchost.exe (PID: 784) Address: 0x00d50000 Size: 45056

Object: Hidden Module [Name: UACovyptehrrsioutl.dll]

Process: svchost.exe (PID: 784) Address: 0x02ef0000 Size: 200704

Object: Hidden Module [Name: UACypynsbabbwkxtqh.dll]

Process: svchost.exe (PID: 784) Address: 0x03110000 Size: 53248

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: svchost.exe (PID: 784) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: svchost.exe (PID: 860) Address: 0x00710000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: svchost.exe (PID: 860) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: svchost.exe (PID: 936) Address: 0x00710000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: svchost.exe (PID: 936) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: svchost.exe (PID: 980) Address: 0x00710000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: svchost.exe (PID: 980) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: svchost.exe (PID: 1244) Address: 0x00710000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: svchost.exe (PID: 1244) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: svchost.exe (PID: 1380) Address: 0x00710000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: svchost.exe (PID: 1380) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: Explorer.EXE (PID: 1392) Address: 0x00c30000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: Explorer.EXE (PID: 1392) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: spoolsv.exe (PID: 1592) Address: 0x009a0000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: spoolsv.exe (PID: 1592) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: ctfmon.exe (PID: 1620) Address: 0x009b0000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: ctfmon.exe (PID: 1620) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: GoogleToolbarNotifier.exe (PID: 160) Address: 0x00970000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: GoogleToolbarNotifier.exe (PID: 160) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: svchost.exe (PID: 544) Address: 0x00710000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: svchost.exe (PID: 544) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: ACService.exe (PID: 924) Address: 0x00730000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: ACService.exe (PID: 924) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: avgwdsvc.exe (PID: 972) Address: 0x00730000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: avgwdsvc.exe (PID: 972) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: jqs.exe (PID: 1100) Address: 0x00710000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: jqs.exe (PID: 1100) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: MDM.EXE (PID: 1216) Address: 0x009d0000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: MDM.EXE (PID: 1216) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: HPZIPM12.EXE (PID: 1232) Address: 0x006e0000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: HPZIPM12.EXE (PID: 1232) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: svchost.exe (PID: 1760) Address: 0x00710000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: svchost.exe (PID: 1760) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: avgrsx.exe (PID: 1784) Address: 0x00760000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: avgrsx.exe (PID: 1784) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: avgnsx.exe (PID: 1816) Address: 0x00780000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: avgnsx.exe (PID: 1816) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: alg.exe (PID: 1756) Address: 0x00720000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: alg.exe (PID: 1756) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: HPWuSchd2.exe (PID: 2288) Address: 0x009a0000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: HPWuSchd2.exe (PID: 2288) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: ACDaemon.exe (PID: 2344) Address: 0x00be0000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: ACDaemon.exe (PID: 2344) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: jusched.exe (PID: 2480) Address: 0x00be0000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: jusched.exe (PID: 2480) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: lxcecoms.exe (PID: 2748) Address: 0x009d0000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: lxcecoms.exe (PID: 2748) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: Updates from HP.exe (PID: 2976) Address: 0x00950000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: Updates from HP.exe (PID: 2976) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: ALCXMNTR.EXE (PID: 3760) Address: 0x00a20000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: ALCXMNTR.EXE (PID: 3760) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: hpsysdrv.exe (PID: 3856) Address: 0x00960000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: hpsysdrv.exe (PID: 3856) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: jusched.exe (PID: 3888) Address: 0x00be0000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: jusched.exe (PID: 3888) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: iexplore.exe (PID: 3980) Address: 0x00a30000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: iexplore.exe (PID: 3980) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: RootRepeal.exe (PID: 2912) Address: 0x00b10000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: RootRepeal.exe (PID: 2912) Address: 0x10000000 Size: 45056

Object: Hidden Module [Name: UACulqkidrcmncelid.dll]

Process: Iexplore.exe (PID: 2872) Address: 0x00a30000 Size: 49152

Object: Hidden Module [Name: UACqmrrvxfuwnqmexm.dll]

Process: Iexplore.exe (PID: 2872) Address: 0x10000000 Size: 45056

==EOF==

Share this post


Link to post
Share on other sites

hi

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  1. If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".

[*]During the download, rename Combofix to Combo-Fix as follows:

CF_download_FF.gif

CF_download_rename.gif

[*]It is important you rename Combofix during the download, but not after.

[*]Please do not rename Combofix to other names, but only to the one indicated.

[*]Close any open browsers.

[*]Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

-----------------------------------------------------------

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    -----------------------------------------------------------


  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

-----------------------------------------------------------

[*]Double click on combo-Fix.exe & follow the prompts.

[*]When finished, it will produce a report for you.

[*]Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

Share this post


Link to post
Share on other sites

I tried to diable AVG but combo fix siad it was still running I scanned anyway here is log files you wanted:

ComboFix 09-06-16.05 - HP_Owner 06/17/2009 11:20.2 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1151.770 [GMT -7:00]

Running from: c:\documents and settings\HP_Owner\Desktop\Combo-Fix.exe

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\HP_Owner\Application Data\inst.exe

c:\documents and settings\HP_Owner\Local Settings\Temporary Internet Files\favicon.ico

c:\windows\system32\drivers\UACotnkrodakiybirv.sys

c:\windows\system32\UAChdqjkoilrlawhio.db

c:\windows\system32\UAChtkoknbgikhvmqu.dat

c:\windows\system32\uacinit.dll

c:\windows\system32\UACmsqodyutpwsrthl.dll

c:\windows\system32\UACosxvdpqnrwoagjq.log

c:\windows\system32\UACovyptehrrsioutl.dll

c:\windows\system32\UACqmrrvxfuwnqmexm.dll

c:\windows\system32\UACsnuhcfdjwuguxly.dll

c:\windows\system32\uactmp.db

c:\windows\system32\UACtwwrdjmiwflkmod.log

c:\windows\system32\UACulqkidrcmncelid.dll

c:\windows\system32\UACvyednynmbfuxjxm.log

c:\windows\system32\UACypynsbabbwkxtqh.dll

D:\Desktop.ini

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Service_UACd.sys

((((((((((((((((((((((((( Files Created from 2009-05-17 to 2009-06-17 )))))))))))))))))))))))))))))))

.

2009-06-14 20:05 . 2009-06-14 20:06 34 ----a-w- c:\documents and settings\HP_Owner\jagex_runescape_preferences.dat

2009-06-14 20:05 . 2009-06-14 20:05 -------- d-----w- c:\windows\.jagex_cache_32

2009-06-14 18:02 . 2009-06-14 18:02 -------- d-----w- C:\_OTL

2009-06-14 01:45 . 2009-06-14 01:45 -------- d-----w- c:\documents and settings\HP_Owner\Saved Games

2009-06-14 01:45 . 2009-06-14 01:45 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Flood Light Games

2009-06-14 01:45 . 2009-06-14 01:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Flood Light Games

2009-06-14 00:42 . 2009-06-14 00:42 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Yahoov1001

2009-06-12 18:15 . 2009-06-12 18:15 -------- d-----w- C:\_OTM

2009-06-11 20:25 . 2009-06-11 20:25 152576 ----a-w- c:\documents and settings\HP_Owner\Application Data\Sun\Java\jre1.6.0_14\lzma.dll

2009-06-11 20:20 . 2009-06-11 20:20 -------- d-----w- C:\Rooter$

2009-06-04 22:22 . 2009-06-04 22:22 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\KodakCredentialStore

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-06-17 18:19 . 2009-01-08 01:05 720 ----a-w- c:\documents and settings\All Users\Application Data\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll

2009-06-16 13:07 . 2007-04-22 16:18 -------- d-----w- c:\program files\Weather Pulse

2009-06-14 01:43 . 2006-05-12 22:45 -------- d-----w- c:\program files\Yahoo! Games

2009-06-13 23:28 . 2006-06-19 22:03 -------- d-----w- c:\program files\Lx_cats

2009-06-13 04:03 . 2006-04-08 19:28 77 ----a-w- c:\windows\popcinfo.dat

2009-06-11 20:27 . 2005-09-10 18:56 -------- d-----w- c:\program files\Java

2009-05-21 18:33 . 2009-01-02 00:36 410984 ----a-w- c:\windows\system32\deploytk.dll

2009-05-21 18:13 . 2005-09-10 20:14 -------- d-----w- c:\program files\Google

2009-05-11 20:53 . 2008-10-22 21:21 -------- d-----w- c:\program files\VSO

2009-05-11 20:53 . 2008-10-22 21:20 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Vso

2009-05-11 20:53 . 2008-10-22 21:21 47360 ----a-w- c:\documents and settings\HP_Owner\Application Data\pcouffin.sys

2009-05-11 20:53 . 2008-10-22 21:21 47360 ----a-w- c:\documents and settings\HP_Owner\Application Data\pcouffin.sys

2009-05-11 20:19 . 2005-09-10 19:34 -------- d-----w- c:\program files\WildTangent

2009-05-11 20:19 . 2009-04-18 22:16 -------- d-----w- c:\program files\Motorola

2009-05-11 20:19 . 2005-09-10 19:05 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-05-11 20:17 . 2005-09-10 19:32 -------- d-----w- c:\program files\Sonic

2009-05-11 20:17 . 2005-09-10 19:05 -------- d-----w- c:\program files\Common Files\InstallShield

2009-05-11 20:17 . 2005-09-10 19:22 -------- d-----w- c:\program files\Common Files\Sonic Shared

2009-05-10 18:41 . 2009-05-10 18:41 0 ----a-w- c:\windows\nsreg.dat

2009-05-10 18:33 . 2009-01-02 01:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-05-10 18:32 . 2009-01-02 01:02 2967799 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe

2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll

2009-05-06 02:54 . 2008-02-10 20:38 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

2009-05-06 02:52 . 2006-02-05 00:29 -------- d-----w- c:\program files\SpywareBlaster

2009-05-06 02:08 . 2009-05-06 02:08 32 --s-a-w- c:\windows\system32\3829490159.dat

2009-05-02 03:25 . 2005-09-10 20:10 -------- d-----w- c:\program files\Easy Internet signup

2009-05-02 00:03 . 2009-03-05 00:53 11952 ----a-w- c:\windows\system32\avgrsstx.dll

2009-05-02 00:03 . 2009-03-05 00:53 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2009-05-02 00:03 . 2009-03-05 00:53 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys

2009-05-02 00:02 . 2009-03-05 00:53 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2009-04-30 03:42 . 2009-04-30 03:42 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\MSNInstaller

2009-04-29 04:56 . 2004-08-04 12:00 827392 ----a-w- c:\windows\system32\wininet.dll

2009-04-29 04:55 . 2004-08-04 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll

2009-04-19 18:46 . 2007-06-16 15:15 -------- d-----w- c:\program files\Common Files\Motorola Shared

2009-04-19 17:13 . 2009-04-19 17:13 152576 ----a-w- c:\documents and settings\HP_Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll

2009-04-18 22:17 . 2009-04-18 22:17 -------- d-----w- c:\program files\WIBUKEY

2009-04-18 22:17 . 2009-04-18 22:17 -------- d-----w- c:\program files\WIBU-SYSTEMS

2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys

2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll

2009-04-06 22:32 . 2009-01-02 01:01 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-04-06 22:32 . 2009-01-02 01:01 15504 ----a-w- c:\windows\system32\drivers\mbam.sys

2001-09-29 01:00 . 2007-03-02 00:02 164864 ----a-w- c:\program files\UNWISE.EXE

2006-04-30 21:53 . 2006-04-30 21:53 22 --sha-w- c:\windows\SMINST\HPCD.sys

.

((((((((((((((((((((((((((((( [email protected]_20.52.46 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-06-17 18:19 . 2009-06-17 18:19 16384 c:\windows\Temp\Perflib_Perfdata_4f0.dat

+ 2009-01-14 01:02 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll

- 2009-01-14 01:02 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll

+ 2004-08-04 12:00 . 2009-04-29 04:56 44544 c:\windows\system32\pngfilt.dll

+ 2007-08-14 02:54 . 2009-04-29 04:55 52224 c:\windows\system32\msfeedsbs.dll

- 2007-08-14 02:54 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll

+ 2009-05-19 20:24 . 2009-05-19 20:24 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe

+ 2004-08-04 12:00 . 2009-04-29 04:55 27648 c:\windows\system32\jsproxy.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll

- 2007-08-14 02:39 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe

+ 2007-08-14 02:39 . 2009-04-28 09:05 13824 c:\windows\system32\ieudinit.exe

- 2004-08-04 12:00 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll

+ 2004-08-04 12:00 . 2009-04-29 04:55 44544 c:\windows\system32\iernonce.dll

+ 2004-08-04 12:00 . 2009-04-28 09:05 70656 c:\windows\system32\ie4uinit.exe

- 2004-08-04 12:00 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe

- 2007-08-14 02:36 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll

+ 2007-08-14 02:36 . 2009-04-29 04:55 63488 c:\windows\system32\icardie.dll

+ 2007-08-14 02:36 . 2009-04-29 04:56 44544 c:\windows\system32\dllcache\pngfilt.dll

- 2007-08-14 02:36 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll

+ 2009-01-08 00:39 . 2009-04-29 04:55 52224 c:\windows\system32\dllcache\msfeedsbs.dll

- 2009-01-08 00:39 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll

+ 2007-08-14 02:54 . 2009-04-29 04:55 27648 c:\windows\system32\dllcache\jsproxy.dll

- 2007-08-14 02:54 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll

- 2009-01-08 00:39 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe

+ 2009-01-08 00:39 . 2009-04-28 09:05 13824 c:\windows\system32\dllcache\ieudinit.exe

+ 2007-08-14 02:39 . 2009-04-29 04:55 44544 c:\windows\system32\dllcache\iernonce.dll

- 2007-08-14 02:39 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll

- 2007-08-14 02:45 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll

+ 2007-08-14 02:45 . 2009-04-29 04:55 78336 c:\windows\system32\dllcache\ieencode.dll

- 2007-08-14 02:39 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe

+ 2007-08-14 02:39 . 2009-04-28 09:05 70656 c:\windows\system32\dllcache\ie4uinit.exe

- 2009-01-08 00:39 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll

+ 2009-01-08 00:39 . 2009-04-29 04:55 63488 c:\windows\system32\dllcache\icardie.dll

- 2005-06-24 22:25 . 2009-01-05 02:00 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

+ 2005-06-24 22:25 . 2009-06-17 18:08 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

- 2005-06-24 22:25 . 2009-01-05 02:00 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat

+ 2005-06-24 22:25 . 2009-06-17 18:08 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat

+ 2009-05-24 16:46 . 2009-05-24 16:46 78562 c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

- 2009-03-18 00:37 . 2009-01-17 01:45 58736 c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL

+ 2009-04-29 10:17 . 2009-04-29 10:17 58736 c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL

- 2009-03-18 00:37 . 2009-01-17 02:16 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll

+ 2009-04-28 10:23 . 2009-04-28 10:23 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll

+ 2009-04-29 10:17 . 2009-04-29 10:17 52288 c:\windows\system32\Adobe\Shockwave 11\gtapi.dll

- 2009-03-18 00:37 . 2009-01-17 01:45 52288 c:\windows\system32\Adobe\Shockwave 11\gtapi.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 44544 c:\windows\ie7updates\KB969897-IE7\pngfilt.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 52224 c:\windows\ie7updates\KB969897-IE7\msfeedsbs.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 27648 c:\windows\ie7updates\KB969897-IE7\jsproxy.dll

+ 2009-06-11 05:41 . 2009-02-20 10:20 13824 c:\windows\ie7updates\KB969897-IE7\ieudinit.exe

+ 2009-06-11 05:41 . 2009-02-20 18:09 44544 c:\windows\ie7updates\KB969897-IE7\iernonce.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 78336 c:\windows\ie7updates\KB969897-IE7\ieencode.dll

+ 2009-06-11 05:41 . 2009-02-20 10:20 70656 c:\windows\ie7updates\KB969897-IE7\ie4uinit.exe

+ 2009-06-11 05:41 . 2009-02-20 18:09 63488 c:\windows\ie7updates\KB969897-IE7\icardie.dll

+ 2009-06-14 20:05 . 2009-06-14 20:05 49152 c:\windows\.jagex_cache_32\runescape\jagmisc.dll

+ 2009-06-14 20:05 . 2009-06-14 20:05 77824 c:\windows\.jagex_cache_32\runescape\jaggl.dll

+ 2009-04-28 10:26 . 2009-04-28 10:26 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll

- 2009-03-18 00:37 . 2009-01-17 02:17 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll

+ 2004-08-04 12:00 . 2009-04-29 04:56 233472 c:\windows\system32\webcheck.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll

+ 2004-08-04 12:00 . 2009-04-29 04:56 105984 c:\windows\system32\url.dll

+ 2004-08-04 12:00 . 2009-04-29 04:56 102912 c:\windows\system32\occache.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll

+ 2004-08-04 12:00 . 2009-04-29 04:56 671232 c:\windows\system32\mstime.dll

+ 2004-08-04 12:00 . 2009-04-29 04:56 193024 c:\windows\system32\msrating.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll

+ 2004-08-04 12:00 . 2009-04-29 04:56 477696 c:\windows\system32\mshtmled.dll

- 2007-08-14 02:54 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll

+ 2007-08-14 02:54 . 2009-04-29 04:55 459264 c:\windows\system32\msfeeds.dll

+ 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe

+ 2009-06-11 20:27 . 2009-05-21 18:34 148888 c:\windows\system32\javaws.exe

- 2009-04-19 17:14 . 2009-03-09 12:19 148888 c:\windows\system32\javaws.exe

- 2009-04-19 17:14 . 2009-03-09 12:19 144792 c:\windows\system32\javaw.exe

+ 2009-06-11 20:27 . 2009-05-21 18:34 144792 c:\windows\system32\javaw.exe

+ 2009-06-11 20:27 . 2009-05-21 18:34 144792 c:\windows\system32\java.exe

- 2009-04-19 17:14 . 2009-03-09 12:19 144792 c:\windows\system32\java.exe

- 2007-08-14 02:34 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll

+ 2007-08-14 02:34 . 2009-04-29 04:55 268288 c:\windows\system32\iertutil.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll

+ 2004-08-04 12:00 . 2009-04-29 04:55 385024 c:\windows\system32\iedkcs32.dll

+ 2007-07-11 20:27 . 2009-04-29 04:55 383488 c:\windows\system32\ieapfltr.dll

- 2007-07-11 20:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll

+ 2004-08-04 12:00 . 2009-04-25 05:26 161792 c:\windows\system32\ieakui.dll

- 2004-08-04 12:00 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll

+ 2004-08-04 12:00 . 2009-04-29 04:55 230400 c:\windows\system32\ieaksie.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll

+ 2004-08-04 12:00 . 2009-04-29 04:55 153088 c:\windows\system32\ieakeng.dll

- 2005-06-25 05:42 . 2009-03-12 22:47 165912 c:\windows\system32\FNTCACHE.DAT

+ 2005-06-25 05:42 . 2009-06-11 14:30 165912 c:\windows\system32\FNTCACHE.DAT

+ 2004-08-04 12:00 . 2009-04-29 04:55 133120 c:\windows\system32\extmgr.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll

+ 2004-08-04 12:00 . 2009-04-29 04:55 214528 c:\windows\system32\dxtrans.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll

+ 2004-08-04 12:00 . 2009-04-29 04:55 347136 c:\windows\system32\dxtmsft.dll

+ 2009-01-05 01:06 . 2009-04-29 04:56 827392 c:\windows\system32\dllcache\wininet.dll

+ 2007-08-14 02:54 . 2009-04-29 04:56 233472 c:\windows\system32\dllcache\webcheck.dll

- 2007-08-14 02:54 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll

+ 2007-08-14 02:44 . 2009-04-29 04:56 105984 c:\windows\system32\dllcache\url.dll

- 2007-08-14 02:44 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll

+ 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll

+ 2007-08-14 02:44 . 2009-04-29 04:56 102912 c:\windows\system32\dllcache\occache.dll

- 2007-08-14 02:44 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll

+ 2007-08-14 02:54 . 2009-04-29 04:56 671232 c:\windows\system32\dllcache\mstime.dll

- 2007-08-14 02:54 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll

+ 2007-08-14 02:44 . 2009-04-29 04:56 193024 c:\windows\system32\dllcache\msrating.dll

- 2007-08-14 02:44 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll

+ 2007-08-14 02:54 . 2009-04-29 04:56 477696 c:\windows\system32\dllcache\mshtmled.dll

- 2007-08-14 02:54 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll

- 2009-01-08 00:39 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll

+ 2009-01-08 00:39 . 2009-04-29 04:55 459264 c:\windows\system32\dllcache\msfeeds.dll

+ 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll

+ 2007-08-14 02:43 . 2009-04-25 05:27 636088 c:\windows\system32\dllcache\iexplore.exe

- 2009-01-08 00:39 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll

+ 2009-01-08 00:39 . 2009-04-29 04:55 268288 c:\windows\system32\dllcache\iertutil.dll

- 2007-08-14 02:39 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll

+ 2007-08-14 02:39 . 2009-04-29 04:55 385024 c:\windows\system32\dllcache\iedkcs32.dll

+ 2009-01-08 00:39 . 2009-04-29 04:55 383488 c:\windows\system32\dllcache\ieapfltr.dll

- 2009-01-08 00:39 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll

- 2004-08-04 12:00 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll

+ 2004-08-04 12:00 . 2009-04-25 05:26 161792 c:\windows\system32\dllcache\ieakui.dll

- 2007-08-14 02:39 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll

+ 2007-08-14 02:39 . 2009-04-29 04:55 230400 c:\windows\system32\dllcache\ieaksie.dll

- 2007-08-14 02:39 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll

+ 2007-08-14 02:39 . 2009-04-29 04:55 153088 c:\windows\system32\dllcache\ieakeng.dll

+ 2007-08-14 02:54 . 2009-04-29 04:55 133120 c:\windows\system32\dllcache\extmgr.dll

- 2007-08-14 02:54 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll

+ 2007-08-14 02:35 . 2009-04-29 04:55 214528 c:\windows\system32\dllcache\dxtrans.dll

- 2007-08-14 02:35 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll

- 2007-08-14 02:35 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll

+ 2007-08-14 02:35 . 2009-04-29 04:55 347136 c:\windows\system32\dllcache\dxtmsft.dll

- 2007-08-14 02:39 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll

+ 2007-08-14 02:39 . 2009-04-29 04:55 124928 c:\windows\system32\dllcache\advpack.dll

- 2004-08-04 12:00 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll

+ 2004-08-04 12:00 . 2009-04-29 04:55 124928 c:\windows\system32\advpack.dll

- 2009-03-18 00:37 . 2009-01-17 02:16 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe

+ 2009-04-28 10:24 . 2009-04-28 10:24 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe

+ 2009-04-29 10:28 . 2009-04-29 10:28 468408 c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe

- 2009-03-18 00:37 . 2009-01-17 02:18 446464 c:\windows\system32\Adobe\Shockwave 11\Proj.dll

+ 2009-04-28 10:26 . 2009-04-28 10:26 446464 c:\windows\system32\Adobe\Shockwave 11\Proj.dll

+ 2009-04-28 10:24 . 2009-04-28 10:24 372736 c:\windows\system32\Adobe\Shockwave 11\Plugin.dll

+ 2009-04-29 10:17 . 2009-04-29 10:17 716800 c:\windows\system32\Adobe\Shockwave 11\gi.dll

+ 2009-04-28 10:26 . 2009-04-28 10:26 614400 c:\windows\system32\Adobe\Shockwave 11\Control.dll

+ 2009-04-29 10:29 . 2009-04-29 10:29 202168 c:\windows\system32\Adobe\Director\swdir.dll

- 2009-03-18 00:29 . 2009-01-17 00:19 202168 c:\windows\system32\Adobe\Director\swdir.dll

+ 2009-04-28 10:25 . 2009-04-28 10:25 131072 c:\windows\system32\Adobe\Director\np32dsw.dll

+ 2009-06-11 05:41 . 2009-03-03 00:18 826368 c:\windows\ie7updates\KB969897-IE7\wininet.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 233472 c:\windows\ie7updates\KB969897-IE7\webcheck.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 105984 c:\windows\ie7updates\KB969897-IE7\url.dll

+ 2009-06-11 05:41 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB969897-IE7\spuninst\updspapi.dll

+ 2009-06-11 05:41 . 2008-07-09 07:38 231288 c:\windows\ie7updates\KB969897-IE7\spuninst\spuninst.exe

+ 2009-06-11 05:41 . 2009-02-20 18:09 102912 c:\windows\ie7updates\KB969897-IE7\occache.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 671232 c:\windows\ie7updates\KB969897-IE7\mstime.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 193024 c:\windows\ie7updates\KB969897-IE7\msrating.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 477696 c:\windows\ie7updates\KB969897-IE7\mshtmled.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 459264 c:\windows\ie7updates\KB969897-IE7\msfeeds.dll

+ 2009-06-11 05:41 . 2009-02-28 04:54 636072 c:\windows\ie7updates\KB969897-IE7\iexplore.exe

+ 2009-06-11 05:41 . 2009-02-20 18:09 268288 c:\windows\ie7updates\KB969897-IE7\iertutil.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 385024 c:\windows\ie7updates\KB969897-IE7\iedkcs32.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 383488 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dll

+ 2009-06-11 05:41 . 2009-02-20 05:14 161792 c:\windows\ie7updates\KB969897-IE7\ieakui.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 230400 c:\windows\ie7updates\KB969897-IE7\ieaksie.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 153088 c:\windows\ie7updates\KB969897-IE7\ieakeng.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 133120 c:\windows\ie7updates\KB969897-IE7\extmgr.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 214528 c:\windows\ie7updates\KB969897-IE7\dxtrans.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 347136 c:\windows\ie7updates\KB969897-IE7\dxtmsft.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 124928 c:\windows\ie7updates\KB969897-IE7\advpack.dll

+ 2004-08-04 12:00 . 2009-04-29 04:56 1159680 c:\windows\system32\urlmon.dll

+ 2004-08-04 12:00 . 2009-04-29 04:56 3596288 c:\windows\system32\mshtml.dll

+ 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\system32\Macromed\Flash\NPSWF32.dll

+ 2007-08-14 02:54 . 2009-04-29 04:55 6066176 c:\windows\system32\ieframe.dll

- 2007-08-14 02:54 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll

+ 2009-01-05 01:18 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys

+ 2009-01-05 01:06 . 2009-04-29 04:56 1159680 c:\windows\system32\dllcache\urlmon.dll

+ 2009-01-05 01:07 . 2009-04-29 04:56 3596288 c:\windows\system32\dllcache\mshtml.dll

- 2009-01-08 00:39 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll

+ 2009-01-08 00:39 . 2009-04-29 04:55 6066176 c:\windows\system32\dllcache\ieframe.dll

+ 2009-04-28 10:00 . 2009-04-28 10:00 1011712 c:\windows\system32\Adobe\Shockwave 11\iml32.dll

+ 2009-04-29 10:17 . 2009-04-29 10:17 1145896 c:\windows\system32\Adobe\Shockwave 11\gt.exe

- 2009-03-18 00:37 . 2009-01-17 01:45 1145896 c:\windows\system32\Adobe\Shockwave 11\gt.exe

- 2009-03-18 00:37 . 2009-01-17 01:58 1798144 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll

+ 2009-04-28 10:04 . 2009-04-28 10:04 1798144 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 1160192 c:\windows\ie7updates\KB969897-IE7\urlmon.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 3595264 c:\windows\ie7updates\KB969897-IE7\mshtml.dll

+ 2009-06-11 05:41 . 2009-02-20 18:09 6066176 c:\windows\ie7updates\KB969897-IE7\ieframe.dll

+ 2009-06-11 05:41 . 2008-07-09 14:25 2455488 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dat

+ 2009-04-17 04:32 . 2009-06-01 16:51 23635392 c:\windows\system32\MRT.exe

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Weather Pulse"="c:\program files\Weather Pulse\weatherpulse.exe" [2009-01-02 3328512]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-01-09 4363504]

"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-02 68856]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]

"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-09 54840]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-09-10 180269]

"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-04-29 188728]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-09-10 98304]

"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]

"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-02 1947928]

"mumservice"="c:\program files\Motorola\Software Update\mumservice.exe" [2009-03-25 996608]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]

"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-05-26 49152]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]

Kodak EasyShare software.lnk - c:\program files\KODAK\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]

KODAK Software Updater.lnk - c:\program files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]

Updates from HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2005-9-10 36903]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-05-02 00:03 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=

"c:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

"c:\\Program Files\\Motorola\\Software Update\\msu.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [3/30/2009 9:35 AM 28544]

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/4/2009 5:53 PM 325896]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/4/2009 5:53 PM 108552]

R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/4/2009 5:53 PM 298776]

S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1/1/2009 6:01 PM 38496]

S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [3/15/2009 11:24 AM 18688]

S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [3/15/2009 11:24 AM 8320]

S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [3/15/2009 11:24 AM 42112]

S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [3/15/2009 11:24 AM 23680]

.

Contents of the 'Scheduled Tasks' folder

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser

uInternet Settings,ProxyServer = http=localhost:7171

uInternet Settings,ProxyOverride = *.local;<local>

uSearchURL,(Default) = hxxp://www.google.com/keyword/%s

IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

FF - ProfilePath -

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-06-17 11:32

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,[email protected]???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(576)

c:\windows\system32\COMRes.dll

c:\windows\system32\CLBCATQ.DLL

.

Completion time: 2009-06-17 11:34

ComboFix-quarantined-files.txt 2009-06-17 18:34

ComboFix2.txt 2009-05-10 21:02

Pre-Run: 7,515,369,472 bytes free

Post-Run: 8,843,395,072 bytes free

387 --- E O F --- 2009-06-17 04:12

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:38:08 AM, on 6/17/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16850)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\WINDOWS\system32\svchost.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\WINDOWS\system32\notepad.exe

C:\WINDOWS\explorer.exe

C:\Program Files\internet explorer\iexplore.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduser

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe

O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,[email protected]

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [mumservice] C:\Program Files\Motorola\Software Update\mumservice.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [Weather Pulse] C:\Program Files\Weather Pulse\weatherpulse.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe

O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)

O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE

--

End of file - 8281 bytes

Share this post


Link to post
Share on other sites

hi

Please download OTM

  • Save it to your desktop.
  • Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    :Processes
    explorer.exe

    :Services

    :Reg

    :Files
    c:\windows\system32\3829490159.dat
    :Commands
    [purity]
    [emptytemp]
    [Reboot]


  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM and reboot your PC.

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Download TFC to your desktop

  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

Please download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Go to Kaspersky website and perform an online antivirus scan.

  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases

[*]Click on My Computer under Scan.

[*]Once the scan is complete, it will display the results. Click on View Scan Report.

[*]You will see a list of infected items there. Click on Save Report As....

[*]Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

Share this post


Link to post
Share on other sites

The Kaspersky virus scan froze up said it found 2 threats but I could not get the report. The Internet explorer locks up as well I had to use firefox. Here are the scan's I have:

========== PROCESSES ==========

Process explorer.exe killed successfully.

========== SERVICES/DRIVERS ==========

========== REGISTRY ==========

========== FILES ==========

c:\windows\system32\3829490159.dat moved successfully.

========== COMMANDS ==========

File delete failed. C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\etilqs_3pHhcZVPer2RNIjC1gIj scheduled to be deleted on reboot.

File delete failed. C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.

File delete failed. C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\_hphtra07.log scheduled to be deleted on reboot.

User's Temp folder emptied.

User's Internet Explorer cache folder emptied.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

User's Temporary Internet Files folder emptied.

File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.

Local Service Temp folder emptied.

Local Service Temporary Internet Files folder emptied.

Network Service Temp folder emptied.

Network Service Temporary Internet Files folder emptied.

File delete failed. C:\WINDOWS\temp\15250cc2-50c5-4bc9-bdbc-5c12238317ee.tmp scheduled to be deleted on reboot.

File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_110.dat scheduled to be deleted on reboot.

Windows Temp folder emptied.

Java cache emptied.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\urlclassifier3.sqlite scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\XUL.mfl scheduled to be deleted on reboot.

FireFox cache emptied.

Temp folders emptied.

OTM by OldTimer - Version 2.1.0.1 log created on 06182009_134537

Files moved on Reboot...

File C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\etilqs_3pHhcZVPer2RNIjC1gIj not found!

C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\hpodvd09.log moved successfully.

C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\_hphtra07.log moved successfully.

File C:\WINDOWS\temp\15250cc2-50c5-4bc9-bdbc-5c12238317ee.tmp not found!

File C:\WINDOWS\temp\Perflib_Perfdata_110.dat not found!

C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\Cache\_CACHE_001_ moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\Cache\_CACHE_002_ moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\Cache\_CACHE_003_ moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\Cache\_CACHE_MAP_ moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\urlclassifier3.sqlite moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wlaqw20.default\XUL.mfl moved successfully.

Registry entries deleted on Reboot...

Malwarebytes' Anti-Malware 1.38

Database version: 2305

Windows 5.1.2600 Service Pack 3

6/18/2009 2:21:15 PM

mbam-log-2009-06-18 (14-21-15).txt

Scan type: Quick Scan

Objects scanned: 93011

Time elapsed: 9 minute(s), 57 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 2

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

c:\documents and settings\HP_Owner\Desktop\MyFunCardsSetup2.3.50.45.ZUfox000.exe (Adware.MyWeb) -> Quarantined and deleted successfully.

Share this post


Link to post
Share on other sites

try this

Please click here to download AVP Tool by Kaspersky.

  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the
    F8
    key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit
    enter
    .


  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.


  • System Memory

  • Startup Objects

  • Disk Boot Sectors.

  • My Computer.

  • Also any other drives (Removable that you may have)

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

Share this post


Link to post
Share on other sites

Wow that was a long scan over 7 hours!!! here ya go:

Scan

----

Scanned: 1760841

Detected: 6

Untreated: 0

Start time: 6/21/2009 11:12:34 AM

Duration: 07:10:08

Finish time: 6/21/2009 6:22:42 PM

Detected

--------

Status Object

------ ------

deleted: adware not-a-virus:AdWare.Win32.MyWay.j File: C:\hp\bin\wbug\HPSummer2005.exe//WiseSFXDropper//WISE0016.BIN

deleted: adware not-a-virus:AdWare.Win32.SearchIt.t File: C:\Program Files\Online Services\AOL\United States\AOL90\comps\toolbar\toolbr.EXE//WiseSFXDropper//WISE0015.BIN

deleted: adware not-a-virus:AdWare.Win32.MyWay.j File: D:\I386\Apps\APP31789\src\HPSummer2005.exe//WiseSFXDropper//WISE0016.BIN

deleted: adware not-a-virus:AdWare.Win32.MyWay.j File: D:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP187\A0021115.exe//WiseSFXDropper//WISE0016.BIN

deleted: adware not-a-virus:AdWare.Win32.MyWay.j File: D:\I386\Apps\APP31789\src\HPSummer2005.exe//WiseSFXDropper

deleted: adware not-a-virus:AdWare.Win32.MyWay.j File: D:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP187\A0021115.exe//WiseSFXDropper

Events

------

Time Name Status Reason

---- ---- ------ ------

6/21/2009 11:12:42 AM Running module: smss.exe\smss.exe ok scanned

Statistics

----------

Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted

------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------

Settings

--------

Parameter Value

--------- -----

Security Level Recommended

Action Prompt for action when the scan is complete

Run mode Manually

File types Scan all files

Scan only new and changed files No

Scan archives All

Scan embedded OLE objects All

Skip if object is larger than No

Skip if scan takes longer than No

Parse email formats No

Scan password-protected archives No

Enable iChecker technology No

Enable iSwift technology No

Show detected threats on "Detected" tab Yes

Rootkits search Yes

Deep rootkits search No

Use heuristic analyzer Yes

Quarantine

----------

Status Object Size Added

------ ------ ---- -----

Backup

------

Status Object Size

------ ------ ----

Share this post


Link to post
Share on other sites

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 9:31:39 AM, on 6/24/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16850)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

C:\Program Files\QuickTime\qttask.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\lxcecoms.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Weather Pulse\weatherpulse.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe

C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe

C:\WINDOWS\ALCXMNTR.EXE

c:\windows\system\hpsysdrv.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduser

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe

O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,[email protected]

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [mumservice] C:\Program Files\Motorola\Software Update\mumservice.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [Weather Pulse] C:\Program Files\Weather Pulse\weatherpulse.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe

O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)

O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE

--

End of file - 8815 bytes

Share this post


Link to post
Share on other sites

Your logs are clean

Follow these steps to uninstall Combofix and tools used in the removal of malware

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    CF_Cleanup.png

  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :

http://www.adobe.com/products/acrobat/readstep2.html

Below I have included a number of recommendations for how to protect your computer against malware infections.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

    [*]ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

    [*]MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    [*]Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more

    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up

    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from

    Here

    If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.

    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

    [*]Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

    [*]ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

    [*]FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.

    [*] Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

    [*]Please read my guide on how to prevent malware and about safe computing here

Thank you for your patience, and performing all of the procedures requested.

Share this post


Link to post
Share on other sites

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.