This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC running slow

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

PC started running slow when loading browser, web pages, etc.

Here is HJT scan:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:44:23 PM, on 03/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
O1 - Hosts: 74.208.77.54 hcurltest1
O1 - Hosts: 82.165.161.232 hcurltest2
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [j2 4.2] "C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\WINDOWS\system32\atonecli.dll (HKCU)
O9 - Extra 'Tools' menuitem: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\WINDOWS\system32\atonecli.dll (HKCU)
O15 - Trusted Zone: http://www.forexchartscapes.com
O15 - Trusted Zone: http://mail.prescott-training.com
O15 - Trusted Zone: http://www.wmtradio.com
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1233096567888
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://profbusinesssolutions.webex.com/cli…bex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 8307 bytes
Hello Posted Image

Please do the following.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt.
    Note:These logs can be located in the OTListIt2. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
It ran for a short bit and I got this error message: Win32 Error. Code: 1500. The event log file is corrupted.

Below is the other data:

OTListIt logfile created on: 03/26/2009 7:51:24 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\Kurt Enget\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

1.97 Gb Total Physical Memory | 1.54 Gb Available Physical Memory | 78.33% Memory free
3.82 Gb Paging File | 3.45 Gb Available in Paging File | 90.39% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 99.29 Gb Total Space | 73.99 Gb Free Space | 74.51% Space Free | Partition Type: NTFS
Drive D: | 11.46 Gb Total Space | 1.28 Gb Free Space | 11.13% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KURT
Current User Name: Kurt Enget
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
PRC - C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe (j2 Global Communications, Inc.)
PRC - C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe (Maxtor Corporation)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\system32\lxczcoms.exe ( )
PRC - C:\Program Files\Maxtor\Sync\SyncServices.exe (Seagate Technology LLC)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\system32\mqsvc.exe (Microsoft Corporation)
PRC - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\system32\mqtgsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehmsas.exe (Microsoft Corporation)
PRC - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
PRC - C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Technologies)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Kurt Enget\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AddFiltr [On_Demand | Stopped]) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (getPlus® Helper [On_Demand | Stopped]) – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqwmiex [Auto | Running]) – C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (lxcz_device [Auto | Running]) – C:\WINDOWS\system32\lxczcoms.exe ( )
SRV - (Maxtor Sync Service [Auto | Running]) – C:\Program Files\Maxtor\Sync\SyncServices.exe (Seagate Technology LLC)
SRV - (McrdSvc [Auto | Running]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (MSMQ [Auto | Running]) – C:\WINDOWS\system32\mqsvc.exe (Microsoft Corporation)
SRV - (MSMQTriggers [Auto | Running]) – C:\WINDOWS\system32\mqtgsvc.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMConnectCDS [On_Demand | Stopped]) – C:\Program Files\Windows Media Connect 2\wmccds.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (5U870CAP_VID_1262&PID_25FD [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\5U870CAP.sys (Ricoh)
DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (AmdK8 [System | Running]) – C:\WINDOWS\system32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (BCM43XX [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (BrSerIf [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrSerIf.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BTWUSB [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (eabfiltr [System | Running]) – C:\WINDOWS\system32\DRIVERS\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabusb [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\eabusb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\cpqbttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HdAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\CHDAud.sys (Conexant Systems Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (iaStor [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MQAC [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mqac.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (MXOPSWD [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\mxopswd.sys (Maxtor Corp.)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (nvsmu [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvsmu.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (rimmptsk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rimsptsk.sys (REDC)
DRV - (rismxdp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\rixdptsk.sys (REDC)
DRV - (RMCAST [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RMCast.sys (Microsoft Corporation)
DRV - (rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sscdbus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sscdbus.sys (MCCI Corporation)
DRV - (sscdmdfl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdmdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sscdmdm.sys (MCCI Corporation)
DRV - (sscdserd [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sscdserd.sys (MCCI Corporation)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (USB_RNDIS [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7


FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/01/27 19:50:46 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2009/03/18 08:41:14 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/06 11:09:32 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/22 15:29:32 | 00,000,000 | —D | M]

[2009/01/02 13:23:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\mozilla\Extensions
[2009/01/02 13:23:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/22 10:28:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\mozilla\Firefox\Profiles\csynuasi.default\extensions
[2009/03/22 22:09:10 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/06 11:09:27 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/06 11:09:27 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/06 11:09:27 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/01/19 19:28:04 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/01/19 19:28:04 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/01/19 19:28:04 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/01/19 19:28:04 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/01/19 19:28:04 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/01/19 19:28:04 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/01/19 19:28:04 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (79 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 74.208.77.54 hcurltest1
O1 - Hosts: 82.165.161.232 hcurltest2
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C7768536-96F8-4001-B1A2-90EE21279187} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe ()
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s ()
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [j2 4.2] "C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe" /R (j2 Global Communications, Inc.)
O4 - HKLM..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" (Lexmark International, Inc.)
O4 - HKLM..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" (Maxtor Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe ()
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe ()
O4 - Startup: C:\Documents and Settings\Kurt Enget\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 227
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: forexchartscapes.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: prescott-training.com ([mail] http in Trusted sites)
O15 - HKCU\..Trusted Domains: prescott-training.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: wmtradio.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 3 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1233096567888 (WUWebControl Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://profbusinesssolutions.webex.com/cli…bex/ieatgpc.cab (GpcContainer Class)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - D:\AUTOEXEC.BAT () - [ FAT32 ]
O33 - MountPoints2\{54530632-275a-11dd-9b18-001636bd680c}\Shell\AutoRun\command - "" = .\Encryption Tool\MaxtorEncryption.exe
O33 - MountPoints2\F\Shell\AutoRun\command - "" = .\Encryption Tool\MaxtorEncryption.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/03/26 07:49:49 | 00,498,688 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kurt Enget\Desktop\OTListIt2.exe
[2009/03/24 09:21:14 | 00,886,817 | —- | C] () – C:\Documents and Settings\Kurt Enget\Desktop\The Prescott Group Remote Web Workplace.mht
[2009/03/22 22:44:10 | 00,001,734 | —- | C] () – C:\Documents and Settings\Kurt Enget\Desktop\HijackThis.lnk
[2009/03/22 22:43:02 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Kurt Enget\Desktop\HJTInstall.exe
[2009/03/21 00:01:04 | 00,001,218 | —- | C] () – C:\Documents and Settings\Kurt Enget\My Documents\McAll Frank.rtf
[2009/03/20 08:49:41 | 04,315,880 | -H– | C] () – C:\Documents and Settings\Kurt Enget\Local Settings\Application Data\IconCache.db
[2009/03/19 10:43:58 | 00,195,072 | —- | C] () – C:\Documents and Settings\Kurt Enget\Desktop\Consultant Roster 3.19.09.xls
[2009/03/18 08:41:15 | 00,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2009/03/18 08:41:01 | 00,278,528 | —- | C] (Real Networks, Inc) – C:\WINDOWS\System32\pncrt.dll
[2009/03/14 11:38:07 | 00,001,319 | —- | C] () – C:\Documents and Settings\Kurt Enget\Desktop\Management by Statistics.lnk
[2009/03/14 11:38:07 | 00,000,184 | —- | C] () – C:\WINDOWS\mbsw.ini
[2009/03/14 11:38:06 | 00,716,800 | —- | C] (Indigo Rose Corporation) – C:\WINDOWS\iun6002.exe
[2009/03/14 11:38:01 | 00,000,000 | —D | C] – C:\STATSWIN
[2009/03/14 09:50:13 | 00,000,349 | —- | C] () – C:\Documents and Settings\Kurt Enget\My Documents\Pond problem.rtf
[2009/03/12 15:35:42 | 00,000,000 | —D | C] – C:\Documents and Settings\Kurt Enget\My Documents\EditMessageLight.aspx_files
[2009/03/12 15:35:41 | 00,092,673 | —- | C] () – C:\Documents and Settings\Kurt Enget\My Documents\EditMessageLight.aspx.htm
[2009/03/04 15:12:17 | 00,000,539 | —- | C] () – C:\Documents and Settings\Kurt Enget\Desktop\Shortcut to Jarrett Buys.lnk
[2009/02/28 15:23:33 | 00,000,000 | —D | C] – C:\Documents and Settings\Kurt Enget\My Documents\Coaching
[2009/02/28 00:24:25 | 00,006,735 | —- | C] () – C:\Documents and Settings\Kurt Enget\My Documents\Caitlin chat 2.27.08.rtf
[2009/02/27 00:32:49 | 01,024,551 | —- | C] () – C:\Documents and Settings\Kurt Enget\My Documents\Europac report.pdf
[2009/02/26 20:07:01 | 00,001,587 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Interbank FX Trader 4.lnk
[2009/02/26 20:06:55 | 00,000,000 | —D | C] – C:\Program Files\Interbank FX Trader 4
[2009/02/26 08:37:13 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/02/25 12:50:16 | 00,139,155 | —- | C] () – C:\Documents and Settings\Kurt Enget\My Documents\ES 03-09 02_25_2009 (610 Tick)3.jpg
[2009/02/25 12:06:32 | 00,139,644 | —- | C] () – C:\Documents and Settings\Kurt Enget\My Documents\ES 03-09 02_25_2009 (610 Tick)1.jpg
[2009/02/25 11:38:54 | 00,137,310 | —- | C] () – C:\Documents and Settings\Kurt Enget\My Documents\ES 03-09 02_25_2009 (610 Tick).jpg
[2009/02/25 08:40:46 | 00,001,655 | —- | C] () – C:\Documents and Settings\All Users\Desktop\FXCM Trading Station.lnk
[2009/02/25 08:40:41 | 00,000,000 | —D | C] – C:\Program Files\Candleworks
[2009/02/25 08:28:44 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/03/26 07:49:50 | 00,498,688 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kurt Enget\Desktop\OTListIt2.exe
[2009/03/26 07:48:52 | 00,001,179 | —- | M] () – C:\hpqp.ini
[2009/03/25 23:35:26 | 00,195,072 | —- | M] () – C:\Documents and Settings\Kurt Enget\Desktop\Consultant Roster 3.19.09.xls
[2009/03/25 23:15:04 | 00,068,505 | —- | M] () – C:\Documents and Settings\Kurt Enget\Desktop\Today.rtf
[2009/03/25 22:29:36 | 00,002,257 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/03/25 22:28:36 | 00,000,039 | —- | M] () – C:\XP_TV.ini
[2009/03/25 22:28:11 | 00,000,434 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2009/03/25 22:28:11 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/25 22:27:46 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/25 22:27:38 | 21,124,66944 | -HS- | M] () – C:\hiberfil.sys
[2009/03/25 18:29:47 | 00,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2009/03/24 13:39:20 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/03/24 13:39:20 | 00,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/03/24 13:30:40 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/03/24 13:30:40 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/03/24 13:30:13 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/03/24 13:30:13 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/03/24 13:29:54 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/03/24 13:29:54 | 00,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/03/24 12:58:36 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/03/24 12:58:36 | 00,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/03/24 09:55:54 | 00,297,158 | —- | M] () – C:\Documents and Settings\Kurt Enget\My Documents\Journal.rtf
[2009/03/24 09:21:18 | 00,886,817 | —- | M] () – C:\Documents and Settings\Kurt Enget\Desktop\The Prescott Group Remote Web Workplace.mht
[2009/03/23 23:27:19 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/03/23 23:27:19 | 00,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/03/23 23:20:58 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/03/23 23:20:58 | 00,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/03/23 23:19:52 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/03/23 23:19:52 | 00,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/03/23 23:19:16 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/03/23 23:19:16 | 00,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/03/23 23:14:37 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/03/23 23:14:37 | 00,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/03/23 08:16:21 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/03/23 08:16:21 | 00,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/03/23 08:09:35 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/03/23 08:09:35 | 00,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/03/23 08:05:39 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/03/23 08:05:39 | 00,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/03/23 08:04:19 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/03/23 08:04:19 | 00,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/03/23 08:03:35 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/03/23 08:03:35 | 00,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/03/23 07:51:01 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/03/23 07:51:01 | 00,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/03/22 23:23:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/03/22 23:23:11 | 00,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/03/22 23:21:25 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/03/22 23:21:25 | 00,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/03/22 23:18:37 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/03/22 23:18:37 | 00,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/03/22 23:14:57 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/03/22 23:14:57 | 00,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/03/22 22:44:10 | 00,001,734 | —- | M] () – C:\Documents and Settings\Kurt Enget\Desktop\HijackThis.lnk
[2009/03/22 22:43:02 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Kurt Enget\Desktop\HJTInstall.exe
[2009/03/22 22:30:01 | 00,051,048 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/03/22 15:34:03 | 00,539,836 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/22 15:34:03 | 00,455,316 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/22 15:34:03 | 00,075,264 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/21 00:01:04 | 00,001,218 | —- | M] () – C:\Documents and Settings\Kurt Enget\My Documents\McAll Frank.rtf
[2009/03/20 08:49:41 | 04,315,880 | -H– | M] () – C:\Documents and Settings\Kurt Enget\Local Settings\Application Data\IconCache.db
[2009/03/19 11:07:54 | 00,000,388 | —- | M] () – C:\WINDOWS\Lexstat.ini
[2009/03/19 00:00:43 | 00,000,184 | —- | M] () – C:\WINDOWS\mbsw.ini
[2009/03/18 08:41:01 | 00,278,528 | —- | M] (Real Networks, Inc) – C:\WINDOWS\System32\pncrt.dll
[2009/03/17 08:05:06 | 00,002,359 | —- | M] () – C:\Documents and Settings\All Users\Desktop\NinjaTrader 6.5.lnk
[2009/03/14 11:38:07 | 00,001,319 | —- | M] () – C:\Documents and Settings\Kurt Enget\Desktop\Management by Statistics.lnk
[2009/03/14 11:38:07 | 00,000,610 | —- | M] () – C:\WINDOWS\win.ini
[2009/03/14 11:37:26 | 00,716,800 | —- | M] (Indigo Rose Corporation) – C:\WINDOWS\iun6002.exe
[2009/03/14 09:50:13 | 00,000,349 | —- | M] () – C:\Documents and Settings\Kurt Enget\My Documents\Pond problem.rtf
[2009/03/12 15:35:42 | 00,092,673 | —- | M] () – C:\Documents and Settings\Kurt Enget\My Documents\EditMessageLight.aspx.htm
[2009/03/12 08:11:33 | 00,323,520 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/12 08:08:36 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/08 08:44:24 | 00,000,985 | —- | M] () – C:\Documents and Settings\Kurt Enget\Local Settings\Application Data\print.ini
[2009/03/04 15:12:17 | 00,000,539 | —- | M] () – C:\Documents and Settings\Kurt Enget\Desktop\Shortcut to Jarrett Buys.lnk
[2009/03/04 14:26:26 | 00,000,673 | —- | M] () – C:\Documents and Settings\Kurt Enget\My Documents\travel list.rtf
[2009/03/01 13:47:45 | 00,006,735 | —- | M] () – C:\Documents and Settings\Kurt Enget\My Documents\Caitlin chat 2.27.08.rtf
[2009/02/27 00:32:49 | 01,024,551 | —- | M] () – C:\Documents and Settings\Kurt Enget\My Documents\Europac report.pdf
[2009/02/26 20:07:01 | 00,001,587 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Interbank FX Trader 4.lnk
[2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/02/25 12:50:16 | 00,139,155 | —- | M] () – C:\Documents and Settings\Kurt Enget\My Documents\ES 03-09 02_25_2009 (610 Tick)3.jpg
[2009/02/25 12:06:32 | 00,139,644 | —- | M] () – C:\Documents and Settings\Kurt Enget\My Documents\ES 03-09 02_25_2009 (610 Tick)1.jpg
[2009/02/25 11:38:54 | 00,137,310 | —- | M] () – C:\Documents and Settings\Kurt Enget\My Documents\ES 03-09 02_25_2009 (610 Tick).jpg
[2009/02/25 08:40:46 | 00,001,655 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FXCM Trading Station.lnk

========== LOP Check ==========

[2009/03/08 08:52:23 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/01/04 09:59:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/08/12 18:11:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/12/03 22:24:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Brother
[2006/09/20 02:15:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2007/09/16 11:42:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FaxCtr
[2009/01/02 22:52:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2006/09/20 02:15:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2006/09/20 00:39:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2006/09/20 02:31:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2007/09/11 13:54:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\j2 Messenger 4.2 Setup
[2008/06/30 09:07:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/05/30 18:37:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Maxtor
[2009/02/10 17:23:29 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/09/01 11:17:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2008/08/14 18:07:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2009/01/04 09:56:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NOS
[2008/10/21 00:49:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2006/09/20 00:39:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/04/06 19:11:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2006/09/20 00:39:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2007/09/14 09:02:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2007/12/09 16:37:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/01/17 16:27:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/01/27 18:51:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/11/23 23:11:01 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Kurt Enget\Application Data
[2008/04/21 10:02:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\acccore
[2009/01/25 22:47:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Adobe
[2008/05/06 17:21:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\AdobeUM
[2008/04/21 10:01:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\AIM
[2008/04/21 10:02:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\AIMPro
[2008/08/12 18:11:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Apple Computer
[2008/06/30 09:25:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\cafebczd
[2007/09/16 13:17:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\ComcastToolbar
[2007/11/02 16:43:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\CyberLink
[2007/09/11 11:51:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Earthlink
[2008/10/02 11:56:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\FaxCtr
[2008/04/26 12:40:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Google
[2008/01/04 20:54:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\GTek
[2008/01/28 12:04:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Help
[2008/04/26 21:23:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\HP
[2006/09/20 00:39:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Identities
[2006/09/20 02:31:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Intuit
[2008/07/28 12:34:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\j2 Messenger
[2006/09/20 02:14:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Macromedia
[2008/06/30 09:07:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Malwarebytes
[2008/08/26 20:14:23 | 00,000,000 | –SD | M] – C:\Documents and Settings\Kurt Enget\Application Data\Microsoft
[2009/01/02 13:23:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Mozilla
[2007/09/11 13:05:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\MSNInstaller
[2007/12/24 16:53:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Netscape
[2008/05/01 16:42:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Productivity Tools
[2009/03/18 08:41:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Real
[2008/10/30 09:30:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Sibelius Software
[2009/03/26 07:50:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Skype
[2009/03/26 00:13:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\skypePM
[2008/07/12 16:53:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Smith Micro
[2008/07/12 18:18:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Sprint Desktop Sync
[2007/02/18 15:44:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Sun
[2007/01/31 22:38:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\teamspeak2
[2007/01/21 12:49:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\Template
[2007/01/29 12:16:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\U3
[2008/12/17 13:41:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\webex
[2008/06/26 22:26:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\WinRAR
[2008/04/19 19:25:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kurt Enget\Application Data\ZoomBrowser EX
[2009/03/25 22:28:11 | 00,000,434 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2006/03/16 00:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/25 22:28:11 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
Hi

I would like you to upload a couple of files for analysis
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
    • C:\hpqp.ini
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Please do the same for the following files:

C:\WINDOWS\tasks\At1.job
C:\WINDOWS\mbsw.ini


Please make sure when you post the results that you identify which result is for which file.

Thanks


Once that is completed, please do the following:


You have MalwareBytes AntiMalware installed
  • Please open that program,
  • search for updates,
  • then run a quick scan,
  • allow it to remove any problems it finds
  • post the results back here.

Next


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

  • Then open HJT
  • run a scan and save a log file
  • post the fresh HJT log


In your next response I need

  • VirScan results
  • MBAM log
  • Kaspersky report
  • Fresh HJT log
C:\hpqp.ini

VirSCAN.org Scanned Report :
Scanned time : 2009/03/27 19:14:33 (CST)
Scanner results: All Scanners reported not find malware!
File Name : hpqp.ini
File Size : 1179 byte
File Type : ASCII text, with very long lines, with CRLF line terminators
MD5 : 0ffa3cb8b93a2f46b5defa0a305a4e74
SHA1 : 22958047c559b6953d29be8e89a6792239943a4b
Online report : http://virscan.org/report/b66a3feee6454edf…6f54708e85.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090326052159 2009-03-26 40.13 -
AhnLab V3 2009.03.27.02 2009.03.27 2009-03-27 40.13 -
AntiVir 7.9.0.129 7.1.2.225 2009-03-27 1.97 -
Antiy 2.0.18 20090327.2244355 2009-03-27 0.12 -
Authentium 5.1.1 200903262306 2009-03-26 1.09 -
AVAST! 3.0.1 090326-0 2009-03-26 0.00 -
AVG 7.5.52.442 270.11.30/2026 2009-03-27 1.98 -
BitDefender 7.81008.2815681 7.24443 2009-03-27 2.60 -
CA (VET) 9.0.0.143 31.6.6419 2009-03-27 40.12 -
ClamAV 0.94.2 9173 2009-03-27 0.00 -
Comodo 3.8 1085 2009-03-26 40.13 -
CP Secure 1.1.0.715 2009.03.27 2009-03-27 7.67 -
Dr.Web 4.44.0.9170 2009.03.27 2009-03-27 4.33 -
F-Prot 4.4.4.56 20090326 2009-03-26 1.09 -
F-Secure 5.51.6100 2009.03.27.03 2009-03-27 0.04 -
Fortinet 2.81-3.117 10.207 2009-03-26 40.13 -
GData 19.4257/19.277 20090327 2009-03-27 40.13 -
ViRobot 20090325 2009.03.25 2009-03-25 43.13 -
Ikarus T3.1.01.48 2009.03.27.72485 2009-03-27 2.86 -
JiangMin 11.0.706 2009.03.27 2009-03-27 43.13 -
Kaspersky 5.5.10 2009.03.27 2009-03-27 0.02 -
KingSoft 2009.2.5.15 2009.3.27.10 2009-03-27 40.13 -
McAfee 5.3.00 5565 2009-03-26 2.67 -
Microsoft 1.4502 2009.03.27 2009-03-27 40.13 -
mks_vir 2.01 2009.03.27 2009-03-27 2.64 -
Norman 6.00.06 6.00.00 2009-03-26 8.01 -
Panda 9.05.01 2009.03.26 2009-03-26 40.13 -
Trend Micro 8.700-1004 5.926.03 2009-03-26 0.02 -
Quick Heal 10.00 2009.03.26 2009-03-26 40.15 -
Rising 20.0 21.22.41.00 2009-03-27 40.13 -
Sophos 2.85.0 4.40 2009-03-27 4.94 -
Sunbelt 5062 5062 2009-03-26 43.13 -
Symantec 1.3.0.24 20090326.007 2009-03-26 0.16 -
nProtect 20090326.01 3379984 2009-03-26 40.13 -
The Hacker [removed] v00292 2009-03-26 43.13 -
VBA32 3.12.10.1 20090326.1408 2009-03-26 1.68 -
VirusBuster 4.5.11.10 10.102.24/1054037 2009-03-26 1.29 -


C:\WINDOWS\tasks\At1.job

VirSCAN.org Scanned Report :
Scanned time : 2009/03/27 19:32:00 (CST)
Scanner results: All Scanners reported not find malware!
File Name : At1.job
File Size : 434 byte
File Type : locale data table
MD5 : 784f12e311ce67ac9b358d68aa828a3b
SHA1 : 6e487669abaa4988ed8aa5ce1b5feea85814a988
Online report : http://virscan.org/report/6f1a525d17ee2780…3e985cf369.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090326052159 2009-03-26 40.13 -
AhnLab V3 2009.03.27.03 2009.03.27 2009-03-27 40.13 -
AntiVir 7.9.0.129 7.1.2.225 2009-03-27 1.96 -
Antiy 2.0.18 20090327.2244355 2009-03-27 0.12 -
Authentium 5.1.1 200903262306 2009-03-26 1.10 -
AVAST! 3.0.1 090326-0 2009-03-26 0.00 -
AVG 7.5.52.442 270.11.30/2026 2009-03-27 1.97 -
BitDefender 7.81008.2815681 7.24443 2009-03-27 2.60 -
CA (VET) 9.0.0.143 31.6.6419 2009-03-27 40.13 -
ClamAV 0.94.2 9173 2009-03-27 0.00 -
Comodo 3.8 1086 2009-03-27 40.13 -
CP Secure 1.1.0.715 2009.03.27 2009-03-27 7.68 -
Dr.Web 4.44.0.9170 2009.03.27 2009-03-27 4.27 -
F-Prot 4.4.4.56 20090326 2009-03-26 1.08 -
F-Secure 5.51.6100 2009.03.27.06 2009-03-27 4.94 -
Fortinet 2.81-3.117 10.207 2009-03-26 43.13 -
GData 19.4257/19.277 20090327 2009-03-27 40.13 -
ViRobot 20090327 2009.03.27 2009-03-27 40.13 -
Ikarus T3.1.01.48 2009.03.27.72485 2009-03-27 2.87 -
JiangMin 11.0.706 2009.03.27 2009-03-27 40.13 -
Kaspersky 5.5.10 2009.03.27 2009-03-27 0.02 -
KingSoft 2009.2.5.15 2009.3.27.10 2009-03-27 40.13 -
McAfee 5.3.00 5565 2009-03-26 2.67 -
Microsoft 1.4502 2009.03.27 2009-03-27 40.13 -
mks_vir 2.01 2009.03.27 2009-03-27 2.65 -
Norman 6.00.06 6.00.00 2009-03-26 8.01 -
Panda 9.05.01 2009.03.26 2009-03-26 40.13 -
Trend Micro 8.700-1004 5.926.03 2009-03-26 0.02 -
Quick Heal 10.00 2009.03.26 2009-03-26 40.13 -
Rising 20.0 21.22.41.00 2009-03-27 40.13 -
Sophos 2.85.0 4.40 2009-03-27 1.90 -
Sunbelt 5062 5062 2009-03-26 43.13 -
Symantec 1.3.0.24 20090326.007 2009-03-26 0.25 -
nProtect 20090326.01 3379984 2009-03-26 40.13 -
The Hacker [removed] v00292 2009-03-26 43.13 -
VBA32 3.12.10.1 20090326.1408 2009-03-26 1.78 -
VirusBuster 4.5.11.10 10.102.24/1054037 2009-03-26 1.29 -


C:\WINDOWS\mbsw.ini
VirSCAN.org Scanned Report :
Scanned time : 2009/03/27 20:49:56 (CST)
Scanner results: All Scanners reported not find malware!
File Name : mbsw.ini
File Size : 184 byte
File Type : ASCII text, with CRLF line terminators
MD5 : 6b76e1d493b5d9b1084fde4a706cc9d1
SHA1 : 27b679ba7943b81aac1688c244c26eb3c86f237e
Online report : http://virscan.org/report/e4ed165cfec6557f…94b559c72a.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090326052159 2009-03-26 40.13 -
AhnLab V3 2009.03.27.03 2009.03.27 2009-03-27 40.13 -
AntiVir 7.9.0.129 7.1.2.225 2009-03-27 1.96 -
Antiy 2.0.18 20090327.2244355 2009-03-27 0.12 -
Authentium 5.1.1 200903262306 2009-03-26 1.10 -
AVAST! 3.0.1 090326-0 2009-03-26 0.89 -
AVG 7.5.52.442 270.11.30/2026 2009-03-27 1.98 -
BitDefender 7.81008.2815681 7.24443 2009-03-27 2.63 -
CA (VET) 9.0.0.143 31.6.6420 2009-03-27 40.13 -
ClamAV 0.94.2 9173 2009-03-27 0.00 -
Comodo 3.8 1086 2009-03-27 40.13 -
CP Secure 1.1.0.715 2009.03.27 2009-03-27 7.68 -
Dr.Web 4.44.0.9170 2009.03.27 2009-03-27 4.27 -
F-Prot 4.4.4.56 20090326 2009-03-26 1.09 -
F-Secure 5.51.6100 2009.03.27.06 2009-03-27 4.97 -
Fortinet 2.81-3.117 10.207 2009-03-26 40.13 -
GData 19.4259/19.277 20090327 2009-03-27 40.13 -
ViRobot 20090327 2009.03.27 2009-03-27 40.13 -
Ikarus T3.1.01.48 2009.03.27.72485 2009-03-27 2.86 -
JiangMin 11.0.706 2009.03.27 2009-03-27 40.13 -
Kaspersky 5.5.10 2009.03.27 2009-03-27 0.02 -
KingSoft 2009.2.5.15 2009.3.27.10 2009-03-27 40.13 -
McAfee 5.3.00 5565 2009-03-26 2.67 -
Microsoft 1.4502 2009.03.27 2009-03-27 40.13 -
mks_vir 2.01 2009.03.27 2009-03-27 2.62 -
Norman 6.00.06 6.00.00 2009-03-26 8.01 -
Panda 9.05.01 2009.03.26 2009-03-26 40.13 -
Trend Micro 8.700-1004 5.926.03 2009-03-26 0.02 -
Quick Heal 10.00 2009.03.26 2009-03-26 40.13 -
Rising 20.0 21.22.41.00 2009-03-27 40.13 -
Sophos 2.85.0 4.40 2009-03-27 1.89 -
Sunbelt 5062 5062 2009-03-26 40.13 -
Symantec 1.3.0.24 20090326.007 2009-03-26 0.24 -
nProtect 20090326.01 3379984 2009-03-26 40.13 -
The Hacker [removed] v00292 2009-03-26 43.13 -
VBA32 3.12.10.1 20090326.1408 2009-03-26 1.67 -
VirusBuster 4.5.11.10 10.102.24/1054037 2009-03-26 1.29 -

Malware scan:
Malwarebytes' Anti-Malware 1.35
Database version: 1905
Windows 5.1.2600 Service Pack 3

03/27/2009 9:24:45 AM
mbam-log-2009-03-27 (09-24-45).txt

Scan type: Quick Scan
Objects scanned: 74179
Time elapsed: 3 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


I ran the Kaspersky Scanner. It found zero infected files. I couldn't get it to print a report.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:34:53 AM, on 03/30/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
O1 - Hosts: 74.208.77.54 hcurltest1
O1 - Hosts: 82.165.161.232 hcurltest2
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [j2 4.2] "C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.forexchartscapes.com
O15 - Trusted Zone: http://mail.prescott-training.com
O15 - Trusted Zone: http://www.wmtradio.com
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1233096567888
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 8709 bytes
Hi,

Please do the following

Open HijackThis.
Click Do a System Scan Only.
Put a checkmark in the box on the left side of these entries only:


O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


Close ALL windows and browsers except HijackThis and click "Fix checked"
Exit HijackThis


Did you set these hosts files?

O1 - Hosts: 74.208.77.54 hcurltest1
O1 - Hosts: 82.165.161.232 hcurltest2

Did you choose to place these entries into your trusted zone?

O15 - Trusted Zone: http://www.forexchartscapes.com
O15 - Trusted Zone: http://mail.prescott-training.com
O15 - Trusted Zone: http://www.wmtradio.com

Please advise
Checked and fixed file in HJT

I did not set these hosts files as far as I know. I don't know what they are or how I would go about setting:

O1 - Hosts: 74.208.77.54 hcurltest1
O1 - Hosts: 82.165.161.232 hcurltest2


I did place these websites in my trusted zone:

O15 - Trusted Zone: http://www.forexchartscapes.com
O15 - Trusted Zone: http://mail.prescott-training.com
O15 - Trusted Zone: http://www.wmtradio.com

(I no longer need the wmt.radio.com website)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:08:47 AM, on 04/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
O1 - Hosts: 74.208.77.54 hcurltest1
O1 - Hosts: 82.165.161.232 hcurltest2
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [j2 4.2] "C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.forexchartscapes.com
O15 - Trusted Zone: http://mail.prescott-training.com
O15 - Trusted Zone: http://www.wmtradio.com
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1233096567888
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 8431 bytes
Hi,

This will reset your hosts file:


Please do the following

Download HostsXpert by FunkyToad from >>>here<<< and save it to your Desktop.

You will need to extract the ZIPPED file(s):
Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish

  • You should now see the HostsXpert folder
  • open it and double click HostsXpert.exe
  • Click on Restore MS Hosts File.
  • In the confirmation window, click on OK.
  • Click on Make Hosts Read Only to secure it against further infection.
  • If it says "Make Writable?", click it and it should change to the above.
  • Close program when complete.
  • Empty Recycle Bin

NEXT

If you want to remove a web site from the Trusted sites Web content zone, follow these steps:

  • Start Internet Explorer.
  • On the Tools menu, click Internet Options.
  • On the Security tab, click the Trusted sites Web content zone, and then click Sites.
  • In the Trusted sites dialog box, click the Web site that you want to remove, and then click Remove.
  • Click OK to close the Trusted sites dialog box.
  • Click OK to close the Internet Options dialog box

Please complete the above, then post back a fresh HJT log afterwards and describe how your computer is running and if you have any other issues.

Thanks

CB
PC, overall, is running fine now. However, web pages are loading very slow. Sometimes this is a problem, sometimes it is not. I am wondering if it is a problem with my cable company, rather than the PC.

I do see the java icon spinning away as pages load. I recently installed the full java program in order to participate in an online training presentation. Would java be causing web pages to load extremely slow?

Here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:22:38 PM, on 04/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [j2 4.2] "C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.forexchartscapes.com
O15 - Trusted Zone: http://mail.prescott-training.com
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1233096567888
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 8462 bytes
Hi,

Good news, your logs are clean :thumbup:

java shouldn't cause the problem. I don't see any reason from your system why you are experiencing slow loading, it may be your internet provider.

If It becomes an issue, post a new topic in out tech section and have them take a look. Link back to this topic so they can see you are clean of Malware.

In the meantime we need to clean up after ourselves.

Please do the following

Clean up with OTListIt2:
  • Double-click OTListIt2.exe to start the program.
  • Close all other programs apart from OTListIt2 as this step will require a reboot
  • On the OTListIt2 main screen, press the [external image: Posted Image] button
  • Say Yes to the prompt and then allow the program to reboot your computer.

NEXT:

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points
We need to set a new system restore point:
Click Start > Run > copy and paste the following into the run box:


%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next.
Name it (something you'll remember) and click Create,
when the confirmation screen shows the restore point has been created click Close.
Now remove all previous Restore Points:
Click Start > Run > copy and paste the following into the run box:


cleanmgr

At the top, click on More Options tab. Click the Clean up button in the System Restore box.
Click on the Yes button.
When finished, click on Cancel button to exit.

NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more.  Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • For Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories.  This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.
  • Please read the guide by Rorschach112on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI