This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] possible trojan

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi there

i recently got a laptop from hp , i did a disk clean up the other night and had 182 gigs, without loading on anything to it, today it is down to 169 gigs. added to that DEP is crashing the browsers (opera, firefox and ie) and messenger as well as java and my wireless connection

im using nod32 and it didnt find anything as soon as i ran hijack this it closed it down, i tried disabling nod and its stilling giving trouble

im running vista premium 64bit

heres my log that i was able to get thanx for any help

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:35:52 PM, on 4/1/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\ESET\nod32kui.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (file missing)
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
O4 - HKLM\..\Run: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files (x86)\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_5730ce9f\AESTSr64.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Google Update Service (gupdate1c9aaa645aac2bc) (gupdate1c9aaa645aac2bc) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files (x86)\Eset\nod32krn.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files (x86)\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_5730ce9f\STacSV64.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11830 bytes
Hi legion,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
ok java is updated

ATF Cleaner freed up about 31mb


Malwarebytes' Anti-Malware was run here is the log

Malwarebytes' Anti-Malware 1.36
Database version: 1953
Windows 6.0.6001 Service Pack 1

4/8/2009 1:29:04 PM
mbam-log-2009-04-08 (13-28-38).txt

Scan type: Quick Scan
Objects scanned: 56720
Time elapsed: 3 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


and here is the HIJACKTHIS log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:35:52 PM, on 4/8/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Users\Rory Hamilton\Program Files (x86)\DNA\btdna.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\AVG\AVG8\avgtray.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~2\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~2\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
O4 - HKLM\..\Run: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Rory Hamilton\Program Files (x86)\DNA\btdna.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_5730ce9f\AESTSr64.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files (x86)\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_5730ce9f\STacSV64.exe (file missing)
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12986 bytes



the laptop is a bit sluggish it takes a while to load windows even before i ran the atf cleaner. and the hard drive space is down to 154 gb but im able to browse again on the laptop.

thanx
legion,

-> No action taken.


Did you click on Remove Selected? If not you need to run Malwarebytes again and do so.

Then


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
ok here is the log ——————————————————————————- KASPERSKY ONLINE SCANNER 7 REPORT Thursday, April 9, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 64-bit Service Pack 1 (build 6001) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Friday, April 10, 2009 01:28:50 Records in database: 2029622 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 153452 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 02:30:05 No malware has been detected. The scan area is clean. The selected area was scanned. and the infection was cleared originally by malwarebytes im just trying to find out where could the space be going
legion,

Let's get an indepth look as what is running in there. We might not figure this out but maybe we'll see something:

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
ok here is the extras log

OTListIt Extras logfile created on: 4/10/2009 7:06:14 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Users\Rory Hamilton\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.53 Gb Available Physical Memory | 67.64% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 219.97 Gb Total Space | 153.97 Gb Free Space | 70.00% Space Free | Partition Type: NTFS
Drive D: | 12.91 Gb Total Space | 2.02 Gb Free Space | 15.64% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RORYHAMILTON-PC
Current User Name: Rory Hamilton
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\Windows\system32\regedit.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2009/02/17 11:10:02 | 00,637,232 | —- | M] (BitTorrent, Inc.) – C:\Program Files (x86)\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{01C9296A-717B-180B-6C1B-972B2A240787}" = Catalyst Control Center Core Implementation
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D5ADBC6-EAC6-6044-0C97-1F7CF77F4AC4}" = Catalyst Control Center Graphics Full New
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{13C984A7-4904-2D52-E0FA-56564B993150}" = ccc-core-static
"{13E5609E-A4A2-F837-86AD-7105855D96CC}" = CCC Help Chinese Standard
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22507ED9-4D42-D684-C96F-6B8870EF4236}" = CCC Help Finnish
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2C5D17D6-3FE0-2275-D0A7-866CD704F701}" = Catalyst Control Center Localization Czech
"{2CC69A5D-226D-6ABE-53D1-FCD400CED07C}" = CCC Help Spanish
"{2FB49B58-79BA-BAC5-E7FE-5D6A6C1E8BB9}" = CCC Help Greek
"{30A6DC6F-C97A-3C6D-54B3-E284CC2EC9E3}" = CCC Help German
"{30D3B7BC-5798-45D9-822D-05CA18F39E99}" = HPTCSSetup
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZero Preloader
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{42300B1F-93D5-DDB9-4563-49399402B70F}" = CCC Help Dutch
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A136EC-88BF-4B95-99F5-C45D3930E1CC}" = HP MULTIPLE MODEM INSTALLER for VISTA
"{4A4E7060-5110-1C02-9227-CC6E9662DD7F}" = Catalyst Control Center Localization Russian
"{4ECD755B-EA8E-1F6D-27D3-D77324033090}" = Catalyst Control Center Localization French
"{4F038D40-0B3C-88C8-BCEB-268A3A89C312}" = Catalyst Control Center Localization Korean
"{4F924BE2-FE46-7A15-DA29-214DDCB65A13}" = Catalyst Control Center Localization Dutch
"{53A4B5BE-5C9A-024D-8A19-5D13668DFE34}" = Catalyst Control Center Localization Turkish
"{558FF444-F562-4E4C-98BD-7B20EE184D2E}" = Catalyst Control Center - Branding
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{5FED28FC-6C33-1B35-1651-C3466CCB047B}" = CCC Help English
"{60820957-6977-9543-D784-F6DCDC265ED4}" = Catalyst Control Center Graphics Full Existing
"{6423EF83-6E1D-4D22-A36F-689CD19FD4D2}" = Juno Preloader
"{658940CB-D84C-23A6-6008-9A89111863A2}" = CCC Help Russian
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"{69162FA0-D2C9-0963-B4F6-3898269786EC}" = Catalyst Control Center Localization Italian
"{6A370610-3778-44AF-9AAC-69B2FD1A3356}" = Microsoft Live Search Toolbar
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{79DB85E8-EEBF-B0D2-651A-398814CB664C}" = Catalyst Control Center Localization Thai
"{7BEF7553-EE3E-DE5D-2576-262D0EC93FB9}" = CCC Help Italian
"{824A7ACB-5101-5244-6470-9EC0DBAB67A3}" = CCC Help Danish
"{82DE85F1-AAA1-BC75-AD7E-640332C8F98B}" = Catalyst Control Center Localization Danish
"{8659BC40-A836-3B79-0D79-DC761DA734D6}" = Catalyst Control Center Localization Finnish
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{00C5525B-3CB3-467D-8100-2E6FB306CD86}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{92751A73-9C38-51D6-CFE7-D66ADF26A17A}" = CCC Help Portuguese
"{936622D2-47A8-FC24-FA43-5899EFCA8844}" = CCC Help Swedish
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{9B13D1C1-1BCD-8677-E129-6E1928223F1B}" = Catalyst Control Center Graphics Light
"{A0B89436-5683-A215-0952-11F3C15040C9}" = Catalyst Control Center Localization German
"{A2A60894-E3ED-46FE-9A6A-7CF7A87572A0}" = Opera 9.64
"{A3AB35FA-943E-4799-99DC-46EFD59E998F}" = AMD USB Audio Driver Filter
"{A3E53E55-0359-104E-7624-9AB51B1BCE66}" = CCC Help Japanese
"{A4B8BD05-69FB-8F9A-6C93-E405D0B56361}" = Catalyst Control Center Localization Greek
"{A9134088-CCC0-56E7-9C75-86811084AB99}" = Skins
"{AB10EFAD-17B5-5295-6214-400CE5681661}" = CCC Help Norwegian
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B3284308-AAAE-8021-F19C-42B894135B5C}" = Catalyst Control Center Localization Polish
"{BB1A8D7E-A399-35CE-7DEF-1022A600FDE9}" = Catalyst Control Center Localization Swedish
"{BB640A89-2E5E-2BB1-97A7-E953ACC9D374}" = CCC Help Polish
"{BDBB3B7C-80F1-160F-59D6-DAF7BCCD5BF3}" = Catalyst Control Center Graphics Previews Vista
"{C0626560-9EB6-0A04-C704-4D6AA38A873D}" = CCC Help Thai
"{C4898551-1329-E6BF-7E7D-1B93B15AFAA8}" = Catalyst Control Center Localization Chinese Traditional
"{C4CF43CE-94AE-498E-9EB1-C804E05CB3CA}" = HP User Guides 0125
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CCDA625A-06DB-A9D5-B672-B5B416723DF8}" = Catalyst Control Center Localization Hungarian
"{D0650094-44A0-67C7-70A4-CF00576237A8}" = CCC Help Korean
"{D36D8B67-ED17-9C76-73CA-D4AF448028FD}" = Catalyst Control Center Graphics Previews Common
"{D6E1FB7C-C1FD-E326-AE52-F9D7D8A1D122}" = CCC Help Chinese Traditional
"{DC7B0CCB-67A5-CC25-34A7-1BBF6D1E1280}" = Catalyst Control Center Localization Japanese
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{E00CD076-B59D-1825-6FAA-383BE7CCEBFE}" = CCC Help Turkish
"{E27C8061-488F-1D13-9B43-25659DD1CBDE}" = Catalyst Control Center Localization Chinese Standard
"{E288A04A-A9D7-F79A-7E88-58321A0F12FC}" = Catalyst Control Center Localization Portuguese
"{E374D624-9BE9-3209-201D-931893B99C37}" = Catalyst Control Center Localization Spanish
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{ED5862BF-C91D-0358-B62D-C0FAF7F9C66E}" = Catalyst Control Center InstallProxy
"{EE1AAA45-21EE-1630-DB15-164DD1DB2E47}" = CCC Help French
"{EFEAED6F-B458-A1C7-49BC-F1CA1C75C8AE}" = Catalyst Control Center Localization Norwegian
"{F63B8DC4-4309-9F2E-07C1-4BE967F5668D}" = CCC Help Hungarian
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F7CCA8CB-FF7C-A5CF-4C77-F9F31BB2D227}" = CCC Help Czech
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player 10 ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ask Toolbar_is1" = Ask Toolbar
"AVG8Uninstall" = AVG 8.5
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"NIS" = Norton Internet Security
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/3/2009 10:37:51 PM | Computer Name = RoryHamilton-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/3/2009 10:48:23 PM | Computer Name = RoryHamilton-PC | Source = Application Error | ID = 1000
Description = Faulting application update.exe_AntiVir Desktop, version 9.0.0.42,
time stamp 0x49afa5d1, faulting module unknown, version 0.0.0.0, time stamp 0x00000000,
exception code 0xc0000005, fault offset 0x02c700c4, process id 0x1240, application
start time 0x01c9b4cfc2cc8793.

Error - 4/3/2009 10:50:26 PM | Computer Name = RoryHamilton-PC | Source = Google Update | ID = 20
Description =

Error - 4/3/2009 10:50:27 PM | Computer Name = RoryHamilton-PC | Source = Application Error | ID = 1000
Description = Faulting application GoogleUpdate.exe, version 1.2.131.7, time stamp
0x48af14ef, faulting module ntdll.dll, version 6.0.6001.18000, time stamp 0x4791a783,
exception code 0xc0000029, fault offset 0x00066fee, process id 0xbec, application
start time 0x01c9b4d012b2a193.

Error - 4/3/2009 10:56:33 PM | Computer Name = RoryHamilton-PC | Source = Application Error | ID = 1000
Description = Faulting application avnotify.exe, version 9.0.9.0, time stamp 0x4979da2f,
faulting module aeemu.dll_unloaded, version 0.0.0.0, time stamp 0x48ee016f, exception
code 0xc0000005, fault offset 0x02d800c8, process id 0xa2c, application start time
0x01c9b4d0df80af53.

Error - 4/3/2009 10:56:50 PM | Computer Name = RoryHamilton-PC | Source = Application Error | ID = 1000
Description = Faulting application avnotify.exe, version 9.0.9.0, time stamp 0x4979da2f,
faulting module aeheur.dll_unloaded, version 0.0.0.0, time stamp 0x49a5549e, exception
code 0xc0000005, fault offset 0x02f400c4, process id 0xb40, application start time
0x01c9b4d0fdaa8c33.

Error - 4/3/2009 11:07:09 PM | Computer Name = RoryHamilton-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3372, time stamp 0x49cbcea4,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x031500c4, process id 0x11c4, application start time 0x01c9b4d25d192953.

Error - 4/3/2009 11:08:13 PM | Computer Name = RoryHamilton-PC | Source = Application Error | ID = 1000
Description = Faulting application avscan.exe, version 9.0.3.3, time stamp 0x49a3ceeb,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x04be00c4, process id 0x344, application start time 0x01c9b4cf7ff8cd73.

Error - 4/4/2009 2:29:35 AM | Computer Name = RoryHamilton-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/4/2009 8:51:14 PM | Computer Name = RoryHamilton-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 3/25/2009 1:29:11 PM | Computer Name = RoryHamilton-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X MS Host Controller' (PCI\VEN_197B&DEV_2383&SUBSYS_30FB103C&REV_00\4&2a995034&0&0328)
disappeared from the system without first being prepared for removal.

Error - 3/25/2009 1:29:11 PM | Computer Name = RoryHamilton-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X xD Host Controller' (PCI\VEN_197B&DEV_2384&SUBSYS_30FB103C&REV_00\4&2a995034&0&0428)
disappeared from the system without first being prepared for removal.

Error - 3/25/2009 11:38:04 PM | Computer Name = RoryHamilton-PC | Source = HTTP | ID = 15016
Description =

Error - 3/26/2009 8:13:27 AM | Computer Name = RoryHamilton-PC | Source = HTTP | ID = 15016
Description =

Error - 3/26/2009 5:15:12 PM | Computer Name = RoryHamilton-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address [removed] on
the Network Card with network address 0015960963C8.

Error - 3/26/2009 5:18:08 PM | Computer Name = RoryHamilton-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X SD/MMC Host Controller' (PCI\VEN_197B&DEV_2382&SUBSYS_30FB103C&REV_00\4&2a995034&0&0028)
disappeared from the system without first being prepared for removal.

Error - 3/26/2009 5:18:08 PM | Computer Name = RoryHamilton-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X SD Host Controller' (PCI\VEN_197B&DEV_2381&SUBSYS_30FB103C&REV_00\4&2a995034&0&0228)
disappeared from the system without first being prepared for removal.

Error - 3/26/2009 5:18:08 PM | Computer Name = RoryHamilton-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X MS Host Controller' (PCI\VEN_197B&DEV_2383&SUBSYS_30FB103C&REV_00\4&2a995034&0&0328)
disappeared from the system without first being prepared for removal.

Error - 3/26/2009 5:18:08 PM | Computer Name = RoryHamilton-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X xD Host Controller' (PCI\VEN_197B&DEV_2384&SUBSYS_30FB103C&REV_00\4&2a995034&0&0428)
disappeared from the system without first being prepared for removal.

Error - 3/28/2009 12:26:33 AM | Computer Name = RoryHamilton-PC | Source = HTTP | ID = 15016
Description =


< End of report >
and the otlist

OTListIt logfile created on: 4/10/2009 7:06:14 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Users\Rory Hamilton\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.53 Gb Available Physical Memory | 67.64% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 219.97 Gb Total Space | 153.97 Gb Free Space | 70.00% Space Free | Partition Type: NTFS
Drive D: | 12.91 Gb Total Space | 2.02 Gb Free Space | 15.64% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RORYHAMILTON-PC
Current User Name: Rory Hamilton
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2009/04/03 22:43:53 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgwdsvc.exe
PRC - [2008/06/09 10:21:58 | 00,073,728 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
PRC - [2008/10/22 23:45:51 | 00,115,560 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
PRC - [2008/10/06 08:54:52 | 00,365,952 | —- | M] () – C:\Program Files (x86)\SMINST\BLService.exe
PRC - [2008/06/29 15:10:18 | 00,241,734 | —- | M] () – C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
PRC - [2008/09/24 18:08:26 | 00,296,320 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
PRC - [2008/09/24 18:08:26 | 00,116,096 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
PRC - [2009/04/03 22:43:55 | 00,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgemc.exe
PRC - [2009/04/03 22:43:55 | 00,691,992 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgcsrvx.exe
PRC - [2009/03/19 11:54:50 | 00,321,344 | —- | M] (BitTorrent, Inc.) – C:\Users\Rory Hamilton\Program Files (x86)\DNA\btdna.exe
PRC - [2009/02/06 18:51:28 | 03,885,408 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
PRC - [2008/09/26 02:36:40 | 01,148,200 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2008/09/25 18:41:44 | 01,152,296 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
PRC - [2008/09/25 18:42:24 | 00,189,736 | —- | M] (CyberLink) – C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2008/09/24 18:07:58 | 00,206,120 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
PRC - [2007/05/08 15:24:20 | 00,054,840 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
PRC - [2008/04/15 13:51:00 | 00,488,752 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
PRC - [2009/04/03 22:43:55 | 01,932,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgtray.exe
PRC - [2008/05/01 15:25:56 | 00,165,192 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
PRC - [2009/04/08 13:12:17 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Java\jre6\bin\jusched.exe
PRC - [2007/09/26 06:34:40 | 00,316,720 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
PRC - [2008/04/11 08:04:54 | 00,685,360 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
PRC - [2009/04/10 07:04:20 | 00,500,736 | —- | M] (OldTimer Tools) – C:\Users\Rory Hamilton\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/10/15 03:39:50 | 00,089,088 | —- | M] () – C:\Windows\sysnative\DriverStore\FileRepository\stwrt64.inf_5730ce9f\AESTSr64.exe – (AESTFilters [Auto | Running])
SRV - [2007/12/11 12:11:30 | 00,015,872 | —- | M] () – C:\Windows\sysnative\agr64svc.exe – (AgereModemAudio [Auto | Running])
SRV - [2008/09/16 19:14:32 | 00,905,216 | —- | M] () – C:\Windows\sysnative\Ati2evxx.exe – (Ati External Event Utility [Auto | Running])
SRV - [2009/04/03 22:43:55 | 00,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
SRV - [2009/04/03 22:43:53 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - [2008/07/27 10:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/27 10:01:49 | 00,093,184 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
SRV - [2008/04/03 10:33:26 | 00,193,840 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe – (Com4QLBEx [On_Demand | Stopped])
SRV - [2008/01/20 18:51:36 | 00,344,064 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehRecvr.exe – (ehRecvr [On_Demand | Stopped])
SRV - [2008/01/20 18:51:36 | 00,153,600 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 07:03:48 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehstart.dll – (ehstart [Auto | Stopped])
SRV - [2008/06/19 17:17:12 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Running])
SRV - [2008/06/16 07:02:28 | 00,094,208 | —- | M] (Hewlett-Packard) – c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe – (HP Health Check Service [Auto | Running])
SRV - [2008/05/01 15:25:56 | 00,165,192 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe – (hpqwmiex [On_Demand | Running])
SRV - [2008/03/18 16:25:40 | 00,023,040 | —- | M] () – C:\Windows\sysnative\Hpservice.exe – (hpsrv [Auto | Running])
SRV - [2004/10/22 02:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/06/19 17:16:53 | 00,859,648 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2008/06/09 10:21:58 | 00,073,728 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe – (LightScribeService [Auto | Running])
SRV - [2008/06/19 17:16:54 | 00,119,808 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/10/22 23:45:51 | 00,115,560 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe – (Norton Internet Security [Auto | Running])
SRV - [2007/08/24 03:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 13:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/01/20 18:47:55 | 00,079,360 | —- | M] () – C:\Windows\sysnative\pcasvc.dll – (PcaSvc [Auto | Running])
SRV - [2008/01/20 18:51:00 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\perfhost.exe – (PerfHost [On_Demand | Stopped])
SRV - [2008/10/06 08:54:52 | 00,365,952 | —- | M] () – C:\Program Files (x86)\SMINST\BLService.exe – (Recovery Service for Windows [Auto | Running])
SRV - [2008/06/29 15:10:18 | 00,241,734 | —- | M] () – C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe – (RichVideo [Auto | Running])
SRV - [2008/10/15 03:39:52 | 00,279,040 | —- | M] () – C:\Windows\sysnative\DriverStore\FileRepository\stwrt64.inf_5730ce9f\STacSV64.exe – (STacSV [Auto | Running])
SRV - [2008/09/24 18:08:26 | 00,296,320 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe – (TVCapSvc [Auto | Running])
SRV - [2008/09/24 18:08:26 | 00,116,096 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe – (TVSched [Auto | Running])
SRV - [2008/01/20 18:52:15 | 01,216,000 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Running])

========== Driver Services (SafeList) ==========

DRV - [2008/03/27 12:10:14 | 00,040,296 | —- | M] () – C:\Windows\sysnative\DRIVERS\Accelerometer.sys – (Accelerometer [On_Demand | Running])
DRV - [2008/02/29 15:59:32 | 01,252,352 | —- | M] () – C:\Windows\sysnative\DRIVERS\agrsm64.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2008/03/31 01:36:18 | 00,195,120 | —- | M] () – C:\Windows\sysnative\DRIVERS\Apfiltr.sys – (ApfiltrService [On_Demand | Running])
DRV - [2008/09/16 20:01:26 | 04,709,888 | —- | M] () – C:\Windows\sysnative\DRIVERS\atikmdag.sys – (atikmdag [On_Demand | Running])
DRV - [2008/04/28 00:25:06 | 00,016,400 | —- | M] () – C:\Windows\sysnative\DRIVERS\AtiPcie.sys – (AtiPcie [Boot | Running])
DRV - [2009/04/03 22:44:05 | 00,414,216 | —- | M] () – C:\Windows\sysnative\Drivers\avgldx64.sys – (AvgLdx64 [System | Running])
DRV - [2009/04/03 22:44:02 | 00,033,160 | —- | M] () – C:\Windows\sysnative\Drivers\avgmfx64.sys – (AvgMfx64 [System | Running])
DRV - [2009/04/03 22:44:11 | 00,133,640 | —- | M] () – C:\Windows\sysnative\Drivers\avgtdia.sys – (AvgTdiA [System | Running])
DRV - [2009/02/11 07:40:57 | 01,522,168 | —- | M] () – C:\Windows\sysnative\DRIVERS\bcmwl664.sys – (BCM43XX [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,428,592 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\ccHPx64.sys – (ccHP [System | Running])
DRV - [2008/01/20 18:46:51 | 00,017,792 | —- | M] () – C:\Windows\sysnative\DRIVERS\CmBatt.sys – (CmBatt [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,475,696 | —- | M] (Symantec Corporation) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl [System | Running])
DRV - [2008/01/24 04:24:24 | 00,060,928 | —- | M] () – C:\Windows\sysnative\DRIVERS\enecir.sys – (enecir [On_Demand | Running])
DRV - [2006/11/01 21:28:10 | 00,273,920 | —- | M] () – C:\Windows\sysnative\drivers\HdAudio.sys – (HdAudAddService [On_Demand | Running])
DRV - [2008/03/27 12:10:56 | 00,026,984 | —- | M] () – C:\Windows\sysnative\DRIVERS\hpdskflt.sys – (hpdskflt [Boot | Running])
DRV - [2007/06/18 16:13:12 | 00,018,432 | —- | M] () – C:\Windows\sysnative\DRIVERS\HpqKbFiltr.sys – (HpqKbFiltr [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,395,312 | —- | M] (Symantec Corporation) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20080826.006\IDSVia64.sys – (IDSVia64 [System | Running])
DRV - [2008/07/21 01:53:04 | 00,145,496 | —- | M] () – C:\Windows\sysnative\DRIVERS\jmcr.sys – (JMCR [On_Demand | Stopped])
DRV - [2008/01/20 18:46:57 | 03,154,432 | —- | M] () – C:\Windows\sysnative\DRIVERS\NETw3v64.sys – (NETw3v64 [On_Demand | Stopped])
DRV - [2008/04/15 01:05:42 | 00,161,792 | —- | M] () – C:\Windows\sysnative\DRIVERS\Rtlh64.sys – (RTL8169 [On_Demand | Running])
DRV - [2008/01/20 18:46:55 | 00,111,104 | —- | M] () – C:\Windows\sysnative\DRIVERS\sdbus.sys – (sdbus [On_Demand | Stopped])
DRV - [2008/10/22 23:45:52 | 00,474,672 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SRTSP64.SYS – (SRTSP [On_Demand | Stopped])
DRV - [2008/10/22 23:45:52 | 00,032,304 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SRTSPX64.SYS – (SRTSPX [System | Running])
DRV - [2008/10/15 03:39:54 | 00,465,408 | —- | M] () – C:\Windows\sysnative\DRIVERS\stwrt64.sys – (STHDA [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,016,432 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMDNS.SYS – (SYMDNS [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,402,480 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMEFA64.SYS – (SymEFA [Boot | Running])
DRV - [2009/03/20 04:23:30 | 00,172,080 | —- | M] () – C:\Windows\sysnative\Drivers\SYMEVENT64x86.SYS – (SymEvent [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,138,800 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMFW.SYS – (SYMFW [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,032,304 | R— | M] () – C:\Windows\sysnative\DRIVERS\SymIMv.sys – (SymIM [System | Running])
DRV - [2008/10/22 23:45:52 | 00,046,640 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMNDISV.SYS – (SYMNDISV [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,033,840 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMREDRV.SYS – (SYMREDRV [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,283,696 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMTDI.SYS – (SYMTDI [System | Running])
DRV - [2008/05/28 17:54:18 | 00,026,168 | —- | M] () – C:\Windows\sysnative\DRIVERS\usbfilter.sys – (usbfilter [On_Demand | Running])
DRV - [2008/01/20 18:47:27 | 00,168,704 | —- | M] () – C:\Windows\sysnative\Drivers\usbvideo.sys – (usbvideo [On_Demand | Running])
DRV - [2006/10/03 17:45:36 | 00,273,408 | —- | M] () – C:\Windows\sysnative\DRIVERS\yk60x64.sys – (yukonx64 [On_Demand | Stopped])
DRV - [2008/09/26 02:36:34 | 00,027,632 | —- | M] (Cyberlink Corp.) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl – ({55662437-DA8C-40c0-AADA-2C816A897A49} [Auto | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.0.20080710
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1
FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090207
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.2.20080717
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES (X86)\AVG\AVG8\FIREFOX [2009/04/03 22:43:52 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\PROGRAM FILES (X86)\AVG\AVG8\TOOLBARFF [2009/04/03 22:43:52 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/04/04 17:09:12 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS [2009/04/05 09:00:37 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS [2009/04/08 13:12:46 | 00,000,000 | —D | M]

[2009/03/19 09:12:54 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Extensions
[2009/03/19 09:12:54 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/09 17:47:52 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions
[2009/04/08 13:17:12 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/04/03 22:27:36 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2009/03/28 15:36:09 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions\[removed]
[2009/04/03 22:27:36 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions\[removed]
[2009/03/28 15:36:18 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions\[removed]\chrome\mozapps\extensions
[2009/03/28 21:07:48 | 00,002,273 | —- | M] () – C:\Users\Rory Hamilton\AppData\Roaming\Mozilla\FireFox\Profiles\6oseyu8c.default\searchplugins\ask.xml
[2009/03/28 21:07:48 | 00,000,567 | —- | M] () – C:\Users\Rory Hamilton\AppData\Roaming\Mozilla\FireFox\Profiles\6oseyu8c.default\searchplugins\yahoo.xml
[2009/04/08 13:12:49 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2009/04/05 09:00:37 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/08 13:12:49 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/05 09:00:14 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/04/05 09:00:14 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2009/04/05 09:00:27 | 00,001,394 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/05 09:00:27 | 00,002,193 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2009/04/05 09:00:27 | 00,001,534 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/05 09:00:27 | 00,002,343 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2009/04/05 09:00:27 | 00,001,706 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2009/04/05 09:00:27 | 00,001,178 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/05 09:00:27 | 00,000,792 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files (x86)\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files (x86)\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files (x86)\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" (CyberLink)
O4 - HKLM..\Run: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam" (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0" (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" (CyberLink Corp.)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Users\Rory Hamilton\Program Files (x86)\DNA\btdna.exe" (BitTorrent, Inc.)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\system32\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/04/10 07:03:59 | 00,500,736 | —- | C] (OldTimer Tools) – C:\Users\Rory Hamilton\Desktop\OTListIt2.exe
[2009/04/09 17:41:38 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Adobe
[2009/04/08 13:27:10 | 00,001,888 | —- | C] () – C:\Users\Rory Hamilton\Desktop\HijackThis.lnk
[2009/04/08 13:24:33 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Desktop\logs
[2009/04/08 13:24:06 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/04/08 13:24:06 | 00,000,808 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/08 13:24:04 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/06 22:32:29 | 00,010,888 | —- | C] () – C:\Users\Rory Hamilton\Documents\JAMAICA COMMANDS A POSITION THAT ALLOWS IT TO BE UTILIZED BY CERTAIN PARTIES TO CARRY OUT TRADE IN CONTRABAND.docx
[2009/04/04 16:59:07 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/04/04 16:58:45 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/04/04 16:58:44 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/04/04 16:58:43 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/04/04 16:58:43 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/04/04 16:58:43 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/04/04 16:57:42 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/04/04 16:57:28 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/04/03 23:26:07 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/04/03 23:25:52 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/04/03 23:25:44 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/04/03 23:25:33 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/04/03 23:25:29 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/04/03 23:21:33 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2009/04/03 23:08:15 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/04/03 23:08:14 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/04/03 23:08:13 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/04/03 23:08:12 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/04/03 23:08:12 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/04/03 23:08:12 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2009/04/03 23:07:52 | 03,580,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/04/03 23:07:49 | 06,069,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/04/03 23:07:48 | 01,166,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/04/03 23:07:47 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/04/03 23:07:46 | 00,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/04/03 23:07:46 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/04/03 23:07:43 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/04/03 23:07:40 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/04/03 23:07:40 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/04/03 23:06:07 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2009/04/03 23:06:04 | 04,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2009/04/03 23:05:55 | 03,080,704 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2009/04/03 23:05:54 | 02,927,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\explorer.exe
[2009/04/03 23:05:44 | 01,191,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3.dll
[2009/04/03 23:05:39 | 02,868,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2009/04/03 23:05:36 | 02,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2009/04/03 23:05:35 | 00,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2009/04/03 23:05:33 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2009/04/03 23:05:28 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schannel.dll
[2009/04/03 23:05:14 | 11,580,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shell32.dll
[2009/04/03 23:05:00 | 01,334,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml6.dll
[2009/04/03 23:04:54 | 00,712,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecs.dll
[2009/04/03 23:04:54 | 00,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2009/04/03 23:04:54 | 00,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2009/04/03 23:04:51 | 00,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2009/04/03 23:04:42 | 00,443,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32spl.dll
[2009/04/03 23:04:31 | 01,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2009/04/03 23:04:23 | 00,303,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gdi32.dll
[2009/04/03 23:04:19 | 00,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2009/04/03 22:50:02 | 00,466,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netapi32.dll
[2009/04/03 22:47:21 | 00,000,000 | —D | C] – C:\Windows\System32\drivers\avg
[2009/04/03 22:45:39 | 00,561,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2009/04/03 22:45:39 | 00,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2009/04/03 22:45:39 | 00,034,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2009/04/03 22:45:28 | 00,162,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/04/03 22:45:28 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/04/03 22:44:17 | 00,001,649 | —- | C] () – C:\Users\Public\Desktop\AVG Free 8.5.lnk
[2009/04/03 22:43:52 | 00,000,000 | —D | C] – C:\ProgramData\avg8
[2009/04/03 22:43:52 | 00,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2009/04/03 22:28:01 | 40,242,58560 | -HS- | C] () – C:\hiberfil.sys
[2009/04/03 18:43:28 | 00,000,000 | —D | C] – C:\Program Files (x86)\Avira
[2009/04/03 17:48:20 | 00,000,000 | —D | C] – C:\ProgramData\Avira
[2009/04/02 18:44:28 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Microsoft Help
[2009/04/02 14:18:59 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Malwarebytes
[2009/04/02 14:18:53 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/04/02 14:18:52 | 00,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2009/04/02 04:50:35 | 00,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2009/04/01 13:35:35 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/03/31 20:55:47 | 01,702,434 | -H– | C] () – C:\Users\Rory Hamilton\AppData\Local\IconCache.db
[2009/03/31 18:04:55 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\Downloads
[2009/03/30 16:20:46 | 00,000,000 | —D | C] – C:\BDE32
[2009/03/30 16:19:01 | 00,000,000 | —D | C] – C:\BC5
[2009/03/30 14:51:30 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\InstallShield
[2009/03/29 19:06:57 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\books
[2009/03/29 16:26:11 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\My Received Files
[2009/03/22 12:50:44 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\Webcam
[2009/03/22 06:26:13 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Real
[2009/03/22 06:26:13 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Real
[2009/03/22 06:23:23 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\vlc
[2009/03/22 06:07:56 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\My Library
[2009/03/22 05:09:51 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\FrostWire
[2009/03/22 05:09:45 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\FrostWire
[2009/03/22 05:03:54 | 00,000,000 | —D | C] – C:\Program Files (x86)\FrostWire
[2009/03/22 05:00:09 | 00,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Reader
[2009/03/21 22:52:45 | 00,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2009/03/21 20:27:01 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\BitTorrent
[2009/03/21 20:25:35 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Google
[2009/03/21 20:24:52 | 00,000,000 | —D | C] – C:\ProgramData\Google Updater
[2009/03/21 20:24:49 | 00,000,000 | —D | C] – C:\Program Files (x86)\Google
[2009/03/21 09:33:38 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Opera
[2009/03/21 09:33:38 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Opera
[2009/03/21 08:46:17 | 00,000,000 | —D | C] – C:\Program Files (x86)\free-downloads.net
[2009/03/21 08:45:50 | 00,000,000 | —D | C] – C:\Program Files (x86)\Alcohol Soft
[2009/03/21 07:51:00 | 00,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2009/03/19 13:09:20 | 00,005,632 | —- | C] () – C:\Users\Rory Hamilton\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/19 12:29:41 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\CyberLink
[2009/03/19 11:07:12 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\Boson NetSim Labs
[2009/03/19 10:57:15 | 00,000,000 | —D | C] – C:\ProgramData\Boson Software
[2009/03/19 10:55:26 | 00,000,000 | —D | C] – C:\Program Files (x86)\Boson Software
[2009/03/19 10:27:56 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\WinRAR
[2009/03/19 10:27:19 | 00,000,000 | —D | C] – C:\Program Files (x86)\WinRAR
[2009/03/19 10:25:16 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\DNA
[2009/03/19 10:25:15 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\DNA
[2009/03/19 10:25:15 | 00,000,000 | —D | C] – C:\Program Files (x86)\DNA
[2009/03/19 10:25:15 | 00,000,000 | —D | C] – C:\Program Files (x86)\BitTorrent
[2009/03/19 10:25:12 | 00,000,000 | —D | C] – C:\Program Files (x86)\AskBarDis
[2009/03/19 10:08:40 | 00,000,680 | —- | C] () – C:\Users\Rory Hamilton\AppData\Local\d3d9caps.dat
[2009/03/19 09:53:28 | 00,000,000 | —D | C] – C:\Program Files (x86)\Opera
[2009/03/19 09:40:50 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Macromedia
[2009/03/19 09:28:27 | 00,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2009/03/19 09:28:15 | 00,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2009/03/19 09:27:54 | 00,000,000 | —D | C] – C:\Program Files (x86)\Windows Live SkyDrive
[2009/03/19 09:27:32 | 00,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2009/03/19 09:24:55 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2009/03/19 09:12:52 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Mozilla
[2009/03/19 09:12:52 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Mozilla
[2009/03/19 09:12:47 | 00,001,778 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/03/19 09:12:44 | 00,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2009/03/19 09:09:35 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Adobe
[2009/03/19 08:52:19 | 00,000,000 | —D | C] – C:\installprogram
[2009/03/19 08:46:43 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2009/03/18 21:25:51 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Hewlett-Packard
[2009/03/18 21:24:59 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\ATI
[2009/03/18 21:24:59 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\ATI
[2009/03/18 21:24:56 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Hewlett-Packard
[2009/03/18 21:24:43 | 00,000,402 | -HS- | C] () – C:\Users\Rory Hamilton\Documents\desktop.ini
[2009/03/18 21:24:43 | 00,000,282 | -HS- | C] () – C:\Users\Rory Hamilton\Desktop\desktop.ini
[2009/03/18 21:24:43 | 00,000,174 | -HS- | C] () – C:\Users\Rory Hamilton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2009/03/18 21:24:36 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Identities
[2009/03/18 21:24:30 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\VirtualStore
[2009/03/18 21:23:29 | 00,075,280 | —- | C] () – C:\Users\Rory Hamilton\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/03/18 21:21:23 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\HP TCS
[2009/03/18 21:21:16 | 00,002,105 | —- | C] () – C:\Users\Public\Desktop\eBay.lnk
[2009/03/18 21:20:51 | 00,001,901 | —- | C] () – C:\Users\Public\Desktop\HP Total Care Advisor.lnk
[2009/03/18 21:19:44 | 00,000,000 | —D | C] – C:\Program Files (x86)\AMD
[2009/03/18 21:19:07 | 00,000,000 | RHS- | C] () – C:\Windows\System32\drivers\103C_HP_cNB_Pavilion dv4 Notebook PC_Y5335KV_0U_QCND9071YTH_E505779-001_4A_I30FB_SHP_V01.82_F.33_T081102_WV3-1_L409_M3837_J250_7AMD_8F31_92.10_#090211_N10EC8136;14E44315_(NB200UA#ABA)_XMOBI
LE_CN10_Z_21_G10029612.MRK
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\Documents\My Videos
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\Documents\My Pictures
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\Documents\My Music
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\AppData\Local\Temporary Internet Files
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\AppData\Local\History
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\AppData\Local\Application Data
[2009/03/18 21:18:09 | 00,000,000 | –SD | C] – C:\Users\Rory Hamilton\AppData\Roaming\Microsoft
[2009/03/18 21:18:09 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Media Center Programs
[2009/03/18 21:18:09 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Temp
[2009/03/18 21:18:09 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Microsoft
[2006/11/02 04:34:27 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 04:34:27 | 00,000,144 | —- | C] () – C:\Windows\win.ini

========== Files - Modified Within 30 Days ==========

[2009/04/10 07:04:20 | 00,500,736 | —- | M] (OldTimer Tools) – C:\Users\Rory Hamilton\Desktop\OTListIt2.exe
[2009/04/10 06:54:41 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/04/10 06:54:35 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/04/10 06:54:30 | 40,242,58560 | -HS- | M] () – C:\hiberfil.sys
[2009/04/10 00:54:52 | 01,702,434 | -H– | M] () – C:\Users\Rory Hamilton\AppData\Local\IconCache.db
[2009/04/08 13:27:10 | 00,001,888 | —- | M] () – C:\Users\Rory Hamilton\Desktop\HijackThis.lnk
[2009/04/08 13:24:06 | 00,000,808 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/07 03:21:09 | 00,010,888 | —- | M] () – C:\Users\Rory Hamilton\Documents\JAMAICA COMMANDS A POSITION THAT ALLOWS IT TO BE UTILIZED BY CERTAIN PARTIES TO CARRY OUT TRADE IN CONTRABAND.docx
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/04/04 01:26:15 | 00,075,280 | —- | M] () – C:\Users\Rory Hamilton\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/04/03 22:44:17 | 00,001,649 | —- | M] () – C:\Users\Public\Desktop\AVG Free 8.5.lnk
[2009/03/20 04:23:26 | 00,000,368 | -HS- | M] () – C:\Users\Public\Desktop\desktop.ini
[2009/03/20 04:23:22 | 00,002,290 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2009/03/19 13:22:08 | 00,005,632 | —- | M] () – C:\Users\Rory Hamilton\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/19 10:08:40 | 00,000,680 | —- | M] () – C:\Users\Rory Hamilton\AppData\Local\d3d9caps.dat
[2009/03/19 09:12:47 | 00,001,778 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/03/18 21:24:49 | 00,000,402 | -HS- | M] () – C:\Users\Rory Hamilton\Documents\desktop.ini
[2009/03/18 21:24:49 | 00,000,282 | -HS- | M] () – C:\Users\Rory Hamilton\Desktop\desktop.ini
[2009/03/18 21:24:49 | 00,000,174 | -HS- | M] () – C:\Users\Rory Hamilton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2009/03/18 21:19:07 | 00,000,000 | RHS- | M] () – C:\Windows\System32\drivers\103C_HP_cNB_Pavilion dv4 Notebook PC_Y5335KV_0U_QCND9071YTH_E505779-001_4A_I30FB_SHP_V01.82_F.33_T081102_WV3-1_L409_M3837_J250_7AMD_8F31_92.10_#090211_N10EC8136;14E44315_(NB200UA#ABA)_XMOBI
LE_CN10_Z_21_G10029612.MRK

========== LOP Check ==========

[2009/04/10 06:54:41 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/04/10 00:55:00 | 00,014,542 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========

< End of report >


thanx
legion,

I'm not seeing anything. I suggest you post in the windows forum and see if the Tech Team can help. Please post a link there back to this thread so that they can see your logs.

Log looks good :D

Cleanup

  • Double click on OTListIt2 to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

You need to create a new Clean restore point:

  • Download SysRestorePoint to your desktop and unzip it to it's own folder.
  • Double click SysRestorePoint.exe so that we can make a new system restore point.
  • A box will pop up after it has made a new point, usually after a few seconds. Close that window and exit the program.
Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI