This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] homepage hijacked, favorites gone

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
My homepage has been hijacked, and odd spyware programs installed, I'm getting popups, also my entire favorites file has been deleted, although the recycle bin is empty.
I cannot open certain programs at all such as Kodak easyshare. I have done nothing other than download the hijack this file.
Here is a copy of this file.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:53:40 AM, on 4/13/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Compaq Organize.lnk = ?
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 7023 bytes

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.

Hi sambluedog and welcome to What the Tech :)

I'm Dakeyras and I am going to try to assist you with your problem. Please take note of the below:
  • I will start working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine!.
  • The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Refrain from running self fixes as this will hinder the malware removal process.
  • It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
Fix Policies:

Download to your Desktop, FixPolicies.exe, a self-extracting ZIP archive from here.
  • Double-click FixPolicies.exe
  • Click the "Install" button on the bottom toolbar of the box that will open.
  • The program will create a new Folder called FixPolicies.
  • Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmd.
  • A black box should briefly appear and then close.
Next:

Please download Rooter.exe to your desktop.
  • Then double-click it to start the tool.
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt.
  • Post the contents of Rooter.txt in your next reply.
Next:

Now lets carry out a more in-depth scan of your computer as follows:
  • Please download Random's System Information Tool by random/random from here and save it to your desktop.
Make sure that RSIT.exe is on the your Desktop before running the application.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open:
    • log.txt will be opened maximized.
    • info.txt will be opened minimized.
  • Please post the contents of both log.txt and info.txt.
When completed the above, please post back the following in the order asked for:
  • How is you computer performing now, any other symptoms and or problems encountered?
  • Rooter Log.
  • Both RSIT logs. <– Post them individually please.
Hi :) Do you still need help with your machine? If the instructions are unclear or something isn't working, please let me know before proceeding.
Hi, yes I do still need help, I had to go out of town unexpectedly, I'll be back home later tonight. I'll print and run the instructions you sent, and get back to you after. Thanks so much!!
Hi :) Absolutely fine and no problem as long as you reply back within the next five days. Thank you for the courtesy of informing myself :thumbup:
Hi,
I'm back at it again, :)

This is the rooter info,
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 2

C:\ [Fixed] - NTFS - (Total:146474 Mo/Free:2742 Mo)
D:\ [Fixed] - FAT32 - (Total:6130 Mo/Free:1019 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [Removable] (Total:0 Mo/Free:0 Mo)
G:\ [Removable] (Total:0 Mo/Free:0 Mo)
H:\ [Removable] (Total:0 Mo/Free:0 Mo)
I:\ [Removable] (Total:0 Mo/Free:0 Mo)

Fri 04/17/2009|19:44

———————-\\ Processes..

–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\Explorer.EXE
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
———- c:\Program Files\Common Files\LightScribe\LSSrvc.exe
———- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
———- C:\WINDOWS\system32\wdfmgr.exe
———- C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
———- C:\WINDOWS\System32\alg.exe
———- C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
———- C:\WINDOWS\ALCXMNTR.EXE
———- C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
———- C:\WINDOWS\system32\ctfmon.exe
———- C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
———- C:\HP\KBD\KBD.EXE
———- C:\WINDOWS\AGRSMMSG.exe
———- c:\windows\system\hpsysdrv.exe
———- C:\Program Files\Java\jre1.5.0\bin\jusched.exe
———- C:\WINDOWS\system32\wuauclt.exe
———- C:\Program Files\iTunes\iTunesHelper.exe
———- C:\Program Files\iPod\bin\iPodService.exe
———- C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
———- C:\Program Files\Internet Explorer\iexplore.exe
———- C:\WINDOWS\system32\WISPTIS.EXE
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

———————-\\ ROOTKIT !!


———————-\\ Rogues..

C:\DOCUME~1\COMPAQ~1\APPLIC~1\Privacy center

———————-\\ Cracks & Keygens..

C:\DOCUME~1\ALLUSE~1\Application Data\Webroot\Spy Sweeper\Updates\crack-r.ide.zip
C:\DOCUME~1\ALLUSE~1\Application Data\Webroot\Spy Sweeper\Updates\crack-s.ide.zip


1 - "C:\Rooter$\Rooter_1.txt" - Fri 04/17/2009|19:45

———————-\\ Scan completed at 19:45

________________________________________________________________________________
__________________________________________________

RSIT LOG TEXT
Logfile of random's system information tool 1.06 (written by random/random)
Run by [removed] at 2009-04-17 19:47:17
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 105 GB (72%) free of 146 GB
Total RAM: 383 MB (17% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:47:36 PM, on 4/17/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Desktop\RSIT.exe
C:\Program Files\trend micro\Compaq_Owner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SiSPower] "Rundll32.exe" SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] "c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AlcxMonitor] "ALCXMNTR.EXE"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - Startup: Compaq Organize.lnk = ?
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Google; Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe

–
End of file - 7556 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Easy Internet Sign-up.job
C:\WINDOWS\tasks\EasyShare Registration RunOnce Task.job
C:\WINDOWS\tasks\EasyShare Registration Task.job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\wrSpySweeper_L41413D1F152F418098E2E87AD0478F8E.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-04 54248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2005-06-10 720896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask.com Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-02-09 764296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google; - c:\program files\google\googletoolbar1.dll [2005-06-10 720896]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask.com Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-02-09 764296]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SiSPower"=SiSPower.dll,ModeAgent []
"HPBootOp"=C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [2005-02-26 245760]
"LSBWatcher"=c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe [2004-10-14 253952]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2005-06-10 180269]
"BOC-426"= []
"AlcxMonitor"=C:\WINDOWS\ALCXMNTR.EXE [2004-09-07 57344]
"SpySweeper"=C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-04-06 6345840]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Compaq Connections.lnk - C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Start Menu\Programs\Startup
Compaq Organize.lnk - C:\Program Files\Hewlett-Packard\Compaq Organize\bin\displayAgent.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=
scecli
scecli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WebrootSpySweeperService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WRConsumerService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe"="C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe:*:Enabled:BackWeb for Presario"
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\iTunes\iTunes.exe"="%ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes"

======List of files/folders created in the last 1 months======

2009-04-17 19:47:17 —-D—- C:\rsit
2009-04-17 19:45:20 —-A—- C:\Rooter.txt
2009-04-17 19:44:06 —-D—- C:\Rooter$
2009-04-17 19:18:36 —-D—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Adobe
2009-04-16 22:22:19 —-HDC—- C:\WINDOWS\$NtUninstallKB959426$
2009-04-16 22:22:07 —-HDC—- C:\WINDOWS\$NtUninstallKB961373$
2009-04-16 22:21:20 —-HDC—- C:\WINDOWS\$NtUninstallKB956572$
2009-04-16 22:21:02 —-HDC—- C:\WINDOWS\$NtUninstallKB952004$
2009-04-16 22:20:49 —-HDC—- C:\WINDOWS\$NtUninstallKB960803$
2009-04-16 22:20:36 —-HDC—- C:\WINDOWS\$NtUninstallKB923561$
2009-04-13 22:57:37 —-D—- C:\Program Files\Ask.com
2009-04-13 21:21:40 —-A—- C:\WINDOWS\WRSetup.dll
2009-04-13 21:21:39 —-D—- C:\Program Files\Webroot
2009-04-13 21:21:39 —-D—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Webroot
2009-04-13 21:21:39 —-D—- C:\Documents and Settings\All Users\Application Data\Webroot
2009-04-13 20:27:50 —-D—- C:\WINSSLog
2009-04-13 20:27:20 —-D—- C:\3784796955e3fedf47954793104d4958
2009-04-13 20:16:52 —-D—- C:\Program Files\Microsoft Easy Assist
2009-04-13 20:16:44 —-D—- C:\Documents and Settings\All Users\Application Data\Applications
2009-04-13 19:42:33 —-D—- C:\WINDOWS\system32\CatRoot_bak
2009-04-13 19:38:16 —-D—- C:\WINDOWS\Prefetch
2009-04-13 19:34:55 —-D—- C:\WINDOWS\pss
2009-04-13 16:42:52 —-D—- C:\WINDOWS\system32\scripting
2009-04-13 16:42:51 —-D—- C:\WINDOWS\system32\en
2009-04-13 16:42:51 —-D—- C:\WINDOWS\system32\bits
2009-04-13 16:38:51 —-A—- C:\WINDOWS\system32\xpsp2res.dll
2009-04-13 16:38:47 —-A—- C:\WINDOWS\system32\qmgr.dll
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\lmhsvc.dll
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\kernel32.dll
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\imagehlp.dll
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\ftp.exe
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\format.com
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\dhcpcsvc.dll
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\csrsrv.dll
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\comdlg32.dll
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\comctl32.dll
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\cmd.exe
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\cacls.exe
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\autoconv.exe
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\autochk.exe
2009-04-13 16:37:39 —-A—- C:\WINDOWS\system32\advapi32.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\rasapi32.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\printui.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\perfctrs.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\olecnv32.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\oleaut32.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\nwprovau.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\ntvdm.exe
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\ntprint.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\ntlsapi.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\ntdll.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\nslookup.exe
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\msv1_0.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\msgsvc.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\mgmtapi.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\lsasrv.dll
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\locator.exe
2009-04-13 16:37:38 —-A—- C:\WINDOWS\system32\localspl.dll
2009-04-13 16:37:37 —-A—- C:\WINDOWS\system32\schannel.dll
2009-04-13 16:37:37 —-A—- C:\WINDOWS\system32\scardsvr.exe
2009-04-13 16:37:37 —-A—- C:\WINDOWS\system32\savedump.exe
2009-04-13 16:37:37 —-A—- C:\WINDOWS\system32\samsrv.dll
2009-04-13 16:37:37 —-A—- C:\WINDOWS\system32\samlib.dll
2009-04-13 16:37:37 —-A—- C:\WINDOWS\system32\rshx32.dll
2009-04-13 16:37:37 —-A—- C:\WINDOWS\system32\rastapi.dll
2009-04-13 16:37:37 —-A—- C:\WINDOWS\system32\rasman.dll
2009-04-13 16:37:37 —-A—- C:\WINDOWS\system32\rasdlg.dll
2009-04-13 16:37:37 —-A—- C:\WINDOWS\system32\rasauto.dll
2009-04-13 16:37:36 —-A—- C:\WINDOWS\system32\userinit.exe
2009-04-13 16:37:36 —-A—- C:\WINDOWS\system32\untfs.dll
2009-04-13 16:37:36 —-A—- C:\WINDOWS\system32\ulib.dll
2009-04-13 16:37:36 —-A—- C:\WINDOWS\system32\tcpmonui.dll
2009-04-13 16:37:36 —-A—- C:\WINDOWS\system32\syssetup.dll
2009-04-13 16:37:36 —-A—- C:\WINDOWS\system32\srvsvc.dll
2009-04-13 16:37:36 —-A—- C:\WINDOWS\system32\smss.exe
2009-04-13 16:37:36 —-A—- C:\WINDOWS\system32\setupapi.dll
2009-04-13 16:37:36 —-A—- C:\WINDOWS\system32\sessmgr.exe
2009-04-13 16:37:36 —-A—- C:\WINDOWS\system32\services.exe
2009-04-13 16:37:31 —-A—- C:\WINDOWS\system32\ntkrnlpa.exe
2009-04-13 16:37:31 —-A—- C:\WINDOWS\system32\hal.dll
2009-04-13 16:37:30 —-A—- C:\WINDOWS\system32\ntoskrnl.exe
2009-04-13 16:10:00 —-D—- C:\WINDOWS\system32\en-US
2009-04-13 16:08:04 —-A—- C:\WINDOWS\system32\xmllite.dll
2009-04-13 03:06:56 —-HDC—- C:\WINDOWS\$NtUninstallKB958215$
2009-04-13 03:06:06 —-HDC—- C:\WINDOWS\$NtUninstallKB960714$
2009-04-13 03:01:34 —-HDC—- C:\WINDOWS\$NtUninstallKB944338-v2$
2009-04-13 03:00:48 —-HDC—- C:\WINDOWS\$NtUninstallKB936782_WMP10$
2009-04-13 01:29:05 —-A—- C:\WINDOWS\system32\MRT.exe
2009-04-13 01:29:03 —-D—- C:\891f6c9327a65ac6ddeb
2009-04-12 23:58:02 —-A—- C:\WINDOWS\system32\spdwnwxp.exe
2009-04-12 23:56:56 —-A—- C:\WINDOWS\005609_.tmp
2009-04-12 23:33:06 —-A—- C:\WINDOWS\system32\xpsp3res.dll
2009-04-12 23:28:51 —-D—- C:\WINDOWS\system32\PreInstall
2009-04-12 23:28:49 —-A—- C:\WINDOWS\system32\spupdsvc.exe
2009-04-12 23:16:08 —-SHD—- C:\WINDOWS\ftpcache
2009-04-12 23:05:00 —-RSHD—- C:\cmdcons
2009-04-12 23:04:40 —-D—- C:\WINDOWS\setupupd
2009-04-12 22:43:42 —-D—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Macromedia
2009-04-12 22:32:25 —-A—- C:\WINDOWS\system32\wmpns.dll
2009-04-12 22:31:45 —-A—- C:\WINDOWS\system32\ps2.EXE
2009-04-12 22:31:34 —-ASH—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\desktop.ini
2009-04-12 22:31:32 —-SD—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Microsoft
2009-04-12 22:31:32 —-D—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Symantec
2009-04-12 22:31:32 —-D—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\SampleView
2009-04-12 22:31:32 —-D—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Real
2009-04-12 22:31:32 —-D—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\InterMute
2009-04-12 22:31:32 —-D—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Identities
2009-04-12 22:31:32 —-D—- C:\Documents and Settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Apple Computer
2009-04-12 22:26:47 —-D—- C:\WINDOWS\system32\SoftwareDistribution
2009-04-12 21:54:57 —-RSHD—- C:\WINDOWS\system32\dllcache
2009-04-12 18:19:06 —-D—- C:\Program Files\UNICCodec
2009-04-12 18:12:37 —-D—- C:\Documents and Settings\All Users\Application Data\01862234
2009-04-12 18:09:05 —-D—- C:\Documents and Settings\All Users\Application Data\01861234
2009-04-02 14:30:04 —-A—- C:\WINDOWS\system32\wrLZMA.dll
2009-04-02 14:29:56 —-A—- C:\WINDOWS\system32\SsiEfr.exe

======List of files/folders modified in the last 1 months======

2009-04-17 19:47:36 —-D—- C:\Program Files\Trend Micro
2009-04-17 19:47:27 —-D—- C:\WINDOWS\TEMP
2009-04-17 18:36:32 —-D—- C:\Program Files
2009-04-17 17:16:40 —-D—- C:\WINDOWS
2009-04-17 12:39:19 —-D—- C:\WINDOWS\system32\CatRoot2
2009-04-17 09:47:54 —-D—- C:\WINDOWS\system32
2009-04-17 09:47:54 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-17 09:43:51 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-04-17 09:43:42 —-D—- C:\WINDOWS\system32\wbem
2009-04-17 09:43:42 —-D—- C:\WINDOWS\AppPatch
2009-04-16 22:22:24 —-HD—- C:\WINDOWS\inf
2009-04-16 22:22:11 —-A—- C:\WINDOWS\imsins.BAK
2009-04-16 22:21:56 —-D—- C:\Program Files\Internet Explorer
2009-04-16 22:21:12 —-HD—- C:\WINDOWS\$hf_mig$
2009-04-14 11:50:58 —-SHD—- C:\WINDOWS\Installer
2009-04-14 11:50:58 —-HD—- C:\Config.Msi
2009-04-14 03:01:32 —-D—- C:\Program Files\Messenger
2009-04-14 03:01:26 —-D—- C:\WINDOWS\system32\CatRoot
2009-04-14 03:01:01 —-D—- C:\WINDOWS\ie7updates
2009-04-13 22:57:43 —-A—- C:\WINDOWS\win.ini
2009-04-13 22:57:38 —-SD—- C:\WINDOWS\Tasks
2009-04-13 22:56:48 —-D—- C:\WINDOWS\system32\drivers
2009-04-13 20:25:11 —-D—- C:\WINDOWS\WinSxS
2009-04-13 19:41:32 —-RASH—- C:\boot.ini
2009-04-13 19:41:32 —-A—- C:\WINDOWS\system.ini
2009-04-13 19:37:55 —-D—- C:\WINDOWS\system32\Setup
2009-04-13 19:37:52 —-RSD—- C:\WINDOWS\Fonts
2009-04-13 19:37:52 —-D—- C:\WINDOWS\ime
2009-04-13 19:24:49 —-D—- C:\WINDOWS\system32\usmt
2009-04-13 19:24:46 —-D—- C:\WINDOWS\system32\Restore
2009-04-13 19:24:46 —-D—- C:\WINDOWS\system32\oobe
2009-04-13 19:24:45 —-D—- C:\WINDOWS\system32\npp
2009-04-13 19:23:52 —-D—- C:\WINDOWS\system32\Com
2009-04-13 19:22:45 —-D—- C:\WINDOWS\system
2009-04-13 19:22:45 —-D—- C:\WINDOWS\srchasst
2009-04-13 19:22:43 —-D—- C:\WINDOWS\PeerNet
2009-04-13 19:22:42 —-D—- C:\WINDOWS\msagent
2009-04-13 19:22:37 —-D—- C:\WINDOWS\Help
2009-04-13 19:22:32 —-D—- C:\Program Files\Windows NT
2009-04-13 19:22:32 —-D—- C:\Program Files\Windows Media Player
2009-04-13 19:22:31 —-D—- C:\Program Files\Outlook Express
2009-04-13 19:22:31 —-D—- C:\Program Files\NetMeeting
2009-04-13 19:22:29 —-D—- C:\Program Files\Movie Maker
2009-04-13 19:22:22 —-D—- C:\Program Files\Common Files\System
2009-04-13 18:57:51 —-AC—- C:\WINDOWS\ntbtlog.txt
2009-04-13 16:56:04 —-D—- C:\WINDOWS\network diagnostic
2009-04-13 16:53:50 —-A—- C:\WINDOWS\setuplog.txt
2009-04-13 16:49:12 —-D—- C:\WINDOWS\security
2009-04-13 16:39:56 —-D—- C:\WINDOWS\system32\ReinstallBackups
2009-04-13 16:37:13 —-D—- C:\WINDOWS\EHome
2009-04-13 16:19:56 —-D—- C:\Program Files\Common Files\Symantec Shared
2009-04-13 16:10:04 —-D—- C:\WINDOWS\system32\config
2009-04-13 16:09:47 —-HDC—- C:\WINDOWS\ie7
2009-04-13 16:08:14 —-HDC—- C:\WINDOWS\$NtUninstallKB915865$
2009-04-13 16:07:07 —-HDC—- C:\WINDOWS\$NtUninstallKB904942$
2009-04-13 15:29:57 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-04-13 03:07:48 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-04-13 03:07:43 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2009-04-13 03:07:35 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2009-04-13 03:07:29 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2009-04-13 03:07:22 —-HDC—- C:\WINDOWS\$NtUninstallKB923723$
2009-04-13 03:07:15 —-HDC—- C:\WINDOWS\$NtUninstallKB955839$
2009-04-13 03:06:45 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2009-04-13 03:06:40 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2009-04-13 03:06:30 —-HDC—- C:\WINDOWS\$NtUninstallKB960225$
2009-04-13 03:06:24 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2009-04-13 03:05:44 —-HDC—- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-04-13 03:04:32 —-HDC—- C:\WINDOWS\$NtUninstallKB941569$
2009-04-13 03:04:15 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2009-04-13 03:04:09 —-HDC—- C:\WINDOWS\$NtUninstallKB957097$
2009-04-13 03:04:02 —-HDC—- C:\WINDOWS\$NtUninstallKB960715$
2009-04-13 03:03:57 —-HDC—- C:\WINDOWS\$NtUninstallKB923689$
2009-04-13 03:03:44 —-HDC—- C:\WINDOWS\$NtUninstallKB958687$
2009-04-13 03:03:35 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2009-04-13 03:02:54 —-HDC—- C:\WINDOWS\$NtUninstallKB967715$
2009-04-13 03:02:48 —-HDC—- C:\WINDOWS\$NtUninstallKB950760$
2009-04-13 03:02:40 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2009-04-13 03:02:33 —-HDC—- C:\WINDOWS\$NtUninstallKB958690$
2009-04-13 03:02:23 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2009-04-13 03:02:14 —-HDC—- C:\WINDOWS\$NtUninstallKB954600$
2009-04-13 03:02:08 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2009-04-13 03:02:00 —-HDC—- C:\WINDOWS\$NtUninstallKB955069$
2009-04-13 03:01:54 —-HDC—- C:\WINDOWS\$NtUninstallKB956802$
2009-04-13 00:07:34 —-D—- C:\Program Files\Common Files
2009-04-13 00:06:11 —-D—- C:\Documents and Settings\All Users\Application Data\Symantec
2009-04-13 00:05:02 —-A—- C:\WINDOWS\BOC426.INI
2009-04-13 00:01:27 —-D—- C:\Program Files\PC-Doctor for Windows
2009-04-13 00:00:45 —-D—- C:\Python22
2009-04-12 23:54:04 —-SD—- C:\WINDOWS\Downloaded Program Files
2009-04-12 23:54:04 —-D—- C:\Program Files\Common Files\InstallShield
2009-04-12 23:53:45 —-D—- C:\Program Files\Common Files\Sonic Shared
2009-04-12 23:47:41 —-D—- C:\Documents and Settings\All Users\Application Data\BOC426
2009-04-12 23:28:48 —-HDC—- C:\WINDOWS\$NtUninstallKB898461$
2009-04-12 23:05:00 —-AC—- C:\WINDOWS\UPGRADE.TXT
2009-04-12 23:04:58 —-D—- C:\WINDOWS\setup.pss
2009-04-12 22:57:40 —-D—- C:\Program Files\Symantec
2009-04-12 22:41:18 —-SHD—- C:\RECYCLER
2009-04-12 22:36:40 —-D—- C:\Program Files\Easy Internet signup
2009-04-12 22:35:18 —-A—- C:\WINDOWS\system32\ssmute.ini
2009-04-12 22:32:27 —-A—- C:\WINDOWS\OEWABLog.txt
2009-04-12 22:31:31 —-D—- C:\Documents and Settings
2009-04-12 22:29:54 —-D—- C:\sysprep
2009-04-12 22:29:46 —-HD—- C:\hp
2009-04-12 22:28:25 —-RASH—- C:\BOOT.BAK
2009-04-12 22:27:01 —-D—- C:\WINDOWS\Registration
2009-04-12 22:27:00 —-D—- C:\WINDOWS\SoftwareDistribution
2009-04-12 22:07:49 —-D—- C:\WINDOWS\I386
2009-04-12 22:06:10 —-D—- C:\Program Files\Common Files\Services
2009-04-12 22:05:51 —-D—- C:\WINDOWS\system32\ras
2009-04-12 22:05:32 —-D—- C:\WINDOWS\system32\icsxml
2009-04-12 22:05:32 —-D—- C:\WINDOWS\system32\ias
2009-04-12 22:04:14 —-RD—- C:\WINDOWS\Web
2009-04-12 22:04:14 —-D—- C:\WINDOWS\addins
2009-04-12 22:04:07 —-D—- C:\WINDOWS\Media
2009-04-12 22:03:56 —-D—- C:\WINDOWS\Cursors
2009-04-12 22:03:52 —-AHDC—- C:\WINDOWS\$NtUninstallKB891781$
2009-04-12 22:03:52 —-AHDC—- C:\WINDOWS\$NtUninstallKB890175$
2009-04-12 22:03:52 —-AHDC—- C:\WINDOWS\$NtUninstallKB888239$
2009-04-12 22:03:52 —-AHDC—- C:\WINDOWS\$NtUninstallKB888113$
2009-04-12 22:03:52 —-AHDC—- C:\WINDOWS\$NtUninstallKB887742$
2009-04-12 22:03:52 —-AHDC—- C:\WINDOWS\$NtUninstallKB885836$
2009-04-12 22:03:52 —-AHDC—- C:\WINDOWS\$NtUninstallKB885835$
2009-04-12 22:03:51 —-AHDC—- C:\WINDOWS\$NtUninstallKB885250$
2009-04-12 22:03:51 —-AHDC—- C:\WINDOWS\$NtUninstallKB883667$
2009-04-12 22:03:51 —-AHDC—- C:\WINDOWS\$NtUninstallKB873339$
2009-04-12 22:03:51 —-AHDC—- C:\WINDOWS\$NtUninstallKB867282$
2009-04-12 22:03:48 —-RHD—- C:\MSOCache
2009-04-12 22:03:25 —-RD—- C:\WINDOWS\Offline Web Pages
2009-04-12 22:03:21 —-RSD—- C:\WINDOWS\assembly
2009-04-12 13:52:24 —-D—- C:\Documents and Settings\All Users\Application Data\Google Updater
2009-04-06 13:26:46 —-A—- C:\WINDOWS\system32\capicom.dll
2009-03-24 20:43:26 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2009-03-24 20:43:22 —-D—- C:\Program Files\SpywareBlaster

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 pwipf6;pwipf6; C:\WINDOWS\system32\drivers\pwipf6.sys [2009-04-13 108296]
R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2005-04-12 11904]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2004-06-29 1268204]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-04-20 2317696]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 GEARAspiWDM;GEAR CDRom Filter; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2004-09-15 13872]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2002-07-29 23808]
R3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2005-04-12 247296]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\sisnic.sys [2003-07-11 32768]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2004-08-04 5504]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-07-25 100032]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-05-08 53248]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine; C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe [2009-04-02 4048240]
R2 WRConsumerService;Webroot Client Service; C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe [2009-04-13 1181040]
R3 iPodService;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2004-10-14 327680]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-07-25 2119360]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

—————–EOF—————–

________________________________________________________________________________
_______________________________________________


RSIT INFO TEXT


info.txt logfile of random's system information tool 1.06 2009-04-17 19:47:40

======Uninstall list======

Ask.com Toolbar–>MsiExec.exe /I{86D4B82A-ABED-442A-BE86-96357B70F4FE}
GTOneCare–>MsiExec.exe /X{8B21B9EF-6DBF-4F63-8CC7-9F6A56D1EE8E}
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB915865)–>"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0–>C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Easy Assist v2–>MsiExec.exe /I{326957C7-83FD-4550-A59A-849B7B4297DE}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Security Update for Step By Step Interactive Training (KB923723)–>"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127-v2)–>"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)–>"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB963027)–>"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)–>"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923689)–>"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464-v2)–>"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944338-v2)–>"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)–>"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)–>"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958215)–>"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)–>"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)–>"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)–>"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)–>"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960714)–>"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)–>"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)–>"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)–>"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Spy Sweeper Core–>MsiExec.exe /I{3F5B6210-0903-4DC6-8034-8F488AA3A782}
Update for Windows XP (KB904942)–>"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)–>"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Webroot Internet Security Essentials–>"C:\Program Files\Webroot\WebrootSecurity\unins001.exe" /Log="C:\DOCUME~1\COMPAQ~1.YOU\LOCALS~1\Temp\Uninstall.txt"
Windows Internet Explorer 7–>"C:\WINDOWS\ie7\spuninst\spuninst.exe"

======Security center information======

AV: Webroot Internet Security Essentials
FW: Webroot Internet Security Essentials

======System event log======

Computer Name: YOUR-F78BF48CE2
Event Code: 7023
Message: The Application Management service terminated with the following error:
The specified module could not be found.


Record Number: 570
Source Name: Service Control Manager
Time Written: 20090412235318.000000-240
Event Type: error
User:

Computer Name: YOUR-F78BF48CE2
Event Code: 7023
Message: The Application Management service terminated with the following error:
The specified module could not be found.


Record Number: 567
Source Name: Service Control Manager
Time Written: 20090412235318.000000-240
Event Type: error
User:

Computer Name: YOUR-F78BF48CE2
Event Code: 7023
Message: The Application Management service terminated with the following error:
The specified module could not be found.


Record Number: 564
Source Name: Service Control Manager
Time Written: 20090412235318.000000-240
Event Type: error
User:

Computer Name: YOUR-F78BF48CE2
Event Code: 7023
Message: The Application Management service terminated with the following error:
The specified module could not be found.


Record Number: 561
Source Name: Service Control Manager
Time Written: 20090412235318.000000-240
Event Type: error
User:

Computer Name: YOUR-F78BF48CE2
Event Code: 7023
Message: The Application Management service terminated with the following error:
The specified module could not be found.


Record Number: 558
Source Name: Service Control Manager
Time Written: 20090412235318.000000-240
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 12 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=0c00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–



Thanks so much!!!
OOPS! Sorry I forgot my info on how the computers working.. Here goes, Hi, the computer turns on and I can access the internet. I've found most of my documents although I can only open them in wordpad. They were in a hidden file. I've sent them to shared documents. My pics were also moved to a hidden file, I've copied everything to my picasa account just in case. My kodak program will not boot up, there seems to be a problem with microsoft office. My virus protection program ( windows one care live) was gone and would not reload (problematic in terms of having no virus protection , but I didn't really like it anyway.)I've downloaded a trial verson of webroots program ( I used to use this, and do like it) to keep thing patched until I get everything figured out. The firewall keeps turning off (I'm using windows defender) The boclean program that I was using is just gone. When I open the add/delete programs box there's only a handful of items even in there. Everything seems to have gone into hiding.
Hi :)

If I may bring your attention to the below:

We do not support Pirated/Warez/Cracked

This service is free and provided by volunteers.

We do not support the use of illegal Pirated/Warez/Cracked software.

Helping a person who insists on using such software, could be construed in the eyes of the law to be aiding and abetting a crime. Therefore you will be asked to remove any cracked programs and in the case of your operating system, to obtain a valid licensed copy.

You may be asked to remove any such software before receiving any help.

Source

Which relates to:

C:\DOCUME~1\ALLUSE~1\Application Data\Webroot\Spy Sweeper\Updates\crack-r.ide.zip
C:\DOCUME~1\ALLUSE~1\Application Data\Webroot\Spy Sweeper\Updates\crack-s.ide.zip

I take a very dim view of this, please remove them forthwith, thank you.

Next:

I have to say the situation is not looking good concerning your Operating System and we may have to consider either a repair of the aforementioned and or a reformat/reinstallation. I will however await the outcome of my outlined tasks for your good self before considering these options. This is just so you are aware of the situation as I see it so far.

With regard to the below it may seem a lot but I assure you nothing is too complicated. Just take your time and if you do not understand anything and or any problems encountered, stop what you are doing and inform myself OK.

Webroot Internet Security Essentials, this is not a particularly good bundled application in my humble opinion but any Anti-Virus is better than none at all so even though a 30 day trial leave it in place for the duration of this malware removal process. We can address this afterwords and I can advise suitable alternatives if you so wish.

Random Access Memory:

Total RAM: 383 MB (17% free)

Some friendly advice concerning the above. It would be prudent in the future to consider installing some new upgraded memory modules.

Though Microsoft claims XP will run with a mere 128 MB installed in my humble opinion a minimum of 1 GB is far better.

If you wish to upgrade the installed memory, Crucial have a Active X scanner which is perfectly safe and will advise if your system can support any upgraded memory modules. They cater for the US/UK and Europe.

Next:
  • Please download this tool from Microsoft.
  • Double click on MGADiag.exe to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in. Save this file and post it in your next reply.
Next:

Please download ATF Cleaner to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please post that log in your next reply.
The log can also be found here:
  • Launch Malwarebytes' Anti-Malware
  • Click on the Logs radio tab.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs can be read here
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
This tool is not a toy and not for everyday use. ComboFix SHOULD NOT be used unless requested by a forum helper.


When completed the above, please post back the following in the order asked for: (Post them all indvidually for ease if you so wish)
  • How is you computer performing now, any other symptoms?
  • MGADiag Log.
  • Malwarebytes_Anti-Malware Log.
  • ComboFix Log.
  • A new HijackThis Log.
I'm assuming the two files you suggested for removal are not part of my current trial version of webroot. I'm not really sure where they came from, although I'm not the only one who used this computer.The search I did found them archived, when I tried to delete them I Igot a popup "output file could not be created. Is there another way to be rid of them?
Okay, here's the MGADiag log Diagnostic Report (1.9.0006.1): —————————————– WGA Data–> Validation Status: Validation Control not Installed Validation Code: 0 Online Validation Code: N/A Cached Validation Code: N/A Windows Product Key: *****-*****-BRVBB-38MQ9-3PMFT Windows Product Key Hash: 2V2VyxlfhiaCt/JkDzYQfiNOHMA= Windows Product ID: 76477-OEM-2111907-00106 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010300.2.0.hom ID: {A238E6F5-8F75-4954-AB1E-4BCE36FF30E1}(1) Is Admin: Yes TestCab: 0x0 WGA Version: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1 Resolution Status: N/A WgaER Data–> ThreatID(s): N/A Version: N/A WGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 WGATray.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-230-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32) Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {A238E6F5-8F75-4954-AB1E-4BCE36FF30E1}1.9.0006.15.1.2600.2.00010300.2.0.homx32*****-*****-*****-*****-3PMFT76477-OEM-2111907-001062S-1-5-21-382391205-272575057-1790030595Compaq Presario 061ED795AA-ABA SR1536NX NA530Phoenix Technologies, LTD 3.1220050420000000.000000+000HP PAVILION4D6B35D70184405D04090409Eastern Standard Time(GMT-05:00)02Hewlett-Packard CompanyCompaq Presario 109 Licensing Data–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: yes Marker string from BIOS: E06B:Compaq Computer Corporation|1085F:Compaq Computer Corporation|E10D:Compaq Computer Corporation|108FD:Compaq Computer Corporation|108FD:Compaq Computer Corporation|E10D:Hewlett-Packard Company|1DA50:Hewlett-Packard Company Marker string from OEMBIOS.DAT: HP PAVILION OEM Activation 2.0 Data–> N/A
The antimalware log Malwarebytes' Anti-Malware 1.36 Database version: 2009 Windows 5.1.2600 Service Pack 2 4/19/2009 10:47:20 AM mbam-log-2009-04-19 (10-47-20).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 191712 Time elapsed: 1 hour(s), 28 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 8 Files Infected: 22 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Registry Defender Platinum (Rogue.RegistryDefender) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Privacy center (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\dbases (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\keys (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\temp (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\UNICCodec (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Program Files\UNICCodec (Trojan.DNSChanger) -> Quarantined and deleted successfully. Files Infected: C:\Program Files\UNICCodec\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0009117.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP8\A0001211.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP8\A0001202.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP8\A0001222.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP8\A0001278.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Registry Defender Platinum\Customer Support.lnk (Rogue.RegistryDefender) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Registry Defender Platinum\Registry Defender.lnk (Rogue.RegistryDefender) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Registry Defender Platinum\User Guide.lnk (Rogue.RegistryDefender) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\dbases\cg.dat (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\dbases\mw.dat (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\dbases\rd.dat (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\dbases\sc.dat (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\dbases\sm.dat (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\dbases\sp.dat (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\keys\cg.key (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\keys\rd.key (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\keys\sc.key (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\keys\sp.key (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\temp\settings.ini (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Application Data\Privacy center\temp\spfilter (Rogue.PrivacyCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\UNICCodec\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Combo-fix log


ComboFix 09-04-19.05 - Compaq_Owner 04/19/2009 11:03.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.144 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Webroot Internet Security Essentials *On-access scanning disabled* (Updated)
FW: Webroot Internet Security Essentials *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\COMPAQ~1.YOU\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\Compaq_Owner\Application Data\Microsoft\SystemCertificates\Request
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\IE4 Error Log.txt
c:\windows\pi.exe
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))
.

2009-04-19 13:15 . 2009-04-19 13:15 ——– d—–w c:\documents and settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Malwarebytes
2009-04-19 13:15 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-19 13:15 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-19 13:15 . 2009-04-19 13:15 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-19 13:06 . 2009-04-19 13:06 ——– d—–w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-04-19 01:01 . 2009-04-19 01:01 ——– d—–w c:\documents and settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\AdobeUM
2009-04-19 01:00 . 2009-04-19 01:00 ——– d—–w c:\documents and settings\Compaq_Owner.YOUR-F78BF48CE2\Local Settings\Application Data\Adobe
2009-04-17 23:47 . 2009-04-17 23:48 ——– d—–w C:\rsit
2009-04-17 23:44 . 2009-04-17 23:45 ——– d—–w C:\Rooter$
2009-04-14 03:01 . 2009-04-19 15:01 ——– d—–w c:\documents and settings\Compaq_Owner.YOUR-F78BF48CE2\Local Settings\Application Data\AskToolbar
2009-04-14 02:57 . 2009-04-14 02:57 ——– d—–w c:\program files\Ask.com
2009-04-14 02:56 . 2009-04-14 02:54 108296 —-a-w c:\windows\system32\drivers\pwipf6.sys
2009-04-14 01:25 . 2009-04-14 01:25 151 —-a-w c:\documents and settings\Compaq_Owner.YOUR-F78BF48CE2\Local Settings\Application Data\fusioncache.dat
2009-04-14 01:21 . 2009-04-06 17:32 1563008 —-a-w c:\windows\WRSetup.dll
2009-04-14 01:21 . 2009-04-14 03:03 ——– d—–w c:\documents and settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Webroot
2009-04-14 01:21 . 2009-04-14 01:25 ——– d—–w c:\documents and settings\All Users\Application Data\Webroot
2009-04-14 01:21 . 2009-04-14 01:21 ——– d—–w c:\program files\Webroot
2009-04-14 01:19 . 2009-04-14 02:56 164 —-a-w c:\windows\install.dat
2009-04-14 00:27 . 2009-04-14 00:28 ——– d—–w C:\WINSSLog
2009-04-14 00:27 . 2009-04-14 00:32 ——– d—–w C:\3784796955e3fedf47954793104d4958
2009-04-14 00:16 . 2009-04-14 00:16 ——– d—–w c:\program files\Microsoft Easy Assist
2009-04-14 00:16 . 2009-04-14 00:16 ——– d—–w c:\documents and settings\All Users\Application Data\Applications
2009-04-13 23:42 . 2009-04-13 23:50 ——– d—–w c:\windows\system32\CatRoot_bak
2009-04-13 20:42 . 2009-04-13 23:22 ——– d—–w c:\windows\system32\scripting
2009-04-13 20:42 . 2009-04-13 23:22 ——– d—–w c:\windows\system32\bits
2009-04-13 20:42 . 2009-04-13 20:42 ——– d—–w c:\windows\system32\en
2009-04-13 20:37 . 2004-08-04 12:00 831519 —-a-w c:\windows\system32\dllcache\mswdat10.dll
2009-04-13 20:10 . 2009-02-20 18:09 52224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
2009-04-13 20:10 . 2009-02-20 18:09 459264 ——w c:\windows\system32\dllcache\msfeeds.dll
2009-04-13 20:10 . 2009-02-20 18:09 268288 ——w c:\windows\system32\dllcache\iertutil.dll
2009-04-13 20:10 . 2009-02-20 18:09 6066176 ——w c:\windows\system32\dllcache\ieframe.dll
2009-04-13 20:10 . 2009-02-20 10:20 13824 ——w c:\windows\system32\dllcache\ieudinit.exe
2009-04-13 20:10 . 2008-07-09 14:30 991232 ——w c:\windows\system32\dllcache\ieframe.dll.mui
2009-04-13 20:10 . 2009-02-20 18:09 63488 ——w c:\windows\system32\dllcache\icardie.dll
2009-04-13 20:10 . 2009-02-20 18:09 383488 ——w c:\windows\system32\dllcache\ieapfltr.dll
2009-04-13 20:10 . 2008-07-09 14:25 2455488 ——w c:\windows\system32\dllcache\ieapfltr.dat
2009-04-13 05:29 . 2009-04-13 07:13 ——– d—–w C:\891f6c9327a65ac6ddeb
2009-04-13 03:58 . 2008-04-14 00:12 7680 —-a-w c:\windows\system32\spdwnwxp.exe
2009-04-13 03:56 . 2006-12-28 19:01 19569 —-a-w c:\windows\005609_.tmp
2009-04-13 03:48 . 2009-04-13 23:39 40040 —-a-w c:\documents and settings\Compaq_Owner.YOUR-F78BF48CE2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-13 03:28 . 2008-07-09 07:38 26488 —-a-w c:\windows\system32\spupdsvc.exe
2009-04-13 03:16 . 2009-04-13 03:16 917504 —-a-w c:\windows\system32\FLASH.OCX
2009-04-13 03:16 . 2009-04-13 03:16 ——– d-sh–w c:\windows\ftpcache
2009-04-13 02:43 . 2009-04-13 02:43 ——– d-sh–w c:\documents and settings\Compaq_Owner.YOUR-F78BF48CE2\UserData
2009-04-13 02:32 . 2004-08-04 12:00 221184 —-a-w c:\windows\system32\wmpns.dll
2009-04-13 02:32 . 2009-04-13 02:32 1876 –sha-r c:\windows\system32\drivers\103C_HP_CPC_ED795AA-ABA SR1536NX NA530_YC_0Pres_QMXK526_E53NAheRED3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.12_T050420_WXH2_L409_M384_J160_7AMD_8Athlon 64_92.21_#050725_N10390900_Z11C1048C_G10396330.MRK
2009-04-13 02:29 . 2005-06-10 17:08 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\Symantec
2009-04-13 02:29 . 2005-06-10 17:04 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\InterMute
2009-04-13 02:29 . 2005-06-10 16:59 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\SampleView
2009-04-13 02:29 . 2005-06-10 16:45 ——– d—–w c:\windows\system32\config\systemprofile\WINDOWS
2009-04-13 02:29 . 2005-06-10 16:45 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\Apple Computer
2009-04-13 01:54 . 2009-04-17 02:22 ——– d-sh–r c:\windows\system32\dllcache
2009-04-12 22:12 . 2009-04-12 22:12 ——– d—–w c:\documents and settings\All Users\Application Data\01862234
2009-04-12 22:09 . 2009-04-12 22:09 ——– d—–w c:\documents and settings\All Users\Application Data\01861234
2009-04-12 19:54 . 2009-04-12 19:54 ——– d—–w c:\documents and settings\My Documents\Audible
2009-04-12 19:53 . 2009-04-12 19:54 ——– d—–r c:\documents and settings\My Documents
2009-04-02 18:30 . 2009-04-02 18:30 176752 —-a-w c:\windows\system32\drivers\ssidrv.sys
2009-04-02 18:30 . 2009-04-02 18:30 23152 —-a-w c:\windows\system32\drivers\sshrmd.sys
2009-04-02 18:30 . 2009-04-02 18:30 29808 —-a-w c:\windows\system32\drivers\ssfs0bbc.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-19 15:08 . 2005-06-10 16:47 3649 —-a-w c:\windows\viassary-hp.reg
2009-04-17 23:47 . 2008-07-02 02:32 ——– d—–w c:\program files\Trend Micro
2009-04-17 23:45 . 2009-04-17 23:45 2771 —-a-w C:\Rooter.txt
2009-04-13 23:22 . 2004-08-04 18:00 250032 –sha-r C:\ntldr
2009-04-13 23:21 . 2005-01-27 05:13 83187 —-a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-13 23:21 . 2009-04-13 23:21 45056 —-a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2009-04-13 23:21 . 2009-04-13 23:21 44032 —-a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2009-04-13 20:58 . 2006-01-31 18:02 982 —ha-w C:\IPH.PH
2009-04-13 20:19 . 2005-06-10 17:07 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-04-13 04:06 . 2005-06-10 17:06 ——– d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-04-13 04:01 . 2005-06-10 16:52 ——– d—–w c:\program files\PC-Doctor for Windows
2009-04-13 03:54 . 2005-06-10 16:23 ——– d—–w c:\program files\Common Files\InstallShield
2009-04-13 03:53 . 2005-06-10 16:34 ——– d—–w c:\program files\Common Files\Sonic Shared
2009-04-13 03:47 . 2008-07-02 19:51 ——– d—–w c:\documents and settings\All Users\Application Data\BOC426
2009-04-13 02:57 . 2005-06-10 17:06 ——– d—–w c:\program files\Symantec
2009-04-13 02:53 . 2009-04-13 02:31 ——– d—–w c:\documents and settings\Compaq_Owner.YOUR-F78BF48CE2\Application Data\Symantec
2009-04-13 02:36 . 2005-06-10 16:54 ——– d—–w c:\program files\Easy Internet signup
2009-04-12 21:40 . 2008-12-07 20:25 55865 —-a-w C:\logfile
2009-04-12 17:52 . 2007-07-19 23:18 ——– d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-08 00:47 . 2007-03-10 01:41 24344 -c–a-w c:\documents and settings\Compaq_Owner\Application Data\wklnhst.dat
2009-03-25 00:43 . 2007-11-04 15:36 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-25 00:43 . 2008-07-02 20:01 ——– d—–w c:\program files\SpywareBlaster
2009-03-21 14:18 . 2009-04-13 20:37 986112 —-a-w c:\windows\system32\dllcache\kernel32.dll
2009-03-16 23:13 . 2009-03-16 23:13 ——– d—–w c:\documents and settings\Compaq_Owner\Application Data\Sony Corporation
2009-03-16 22:51 . 2009-03-16 22:51 ——– d—–w c:\program files\Sony
2009-03-16 22:50 . 2009-03-16 22:50 ——– d—–w c:\documents and settings\All Users\Application Data\Sony Corporation
2009-03-14 20:31 . 2008-10-17 16:38 ——– d—–w c:\program files\Napster
2009-03-06 14:44 . 2009-04-13 20:37 283648 —-a-w c:\windows\system32\dllcache\pdh.dll
2009-03-06 14:44 . 2004-08-04 12:00 283648 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-04 11:00 826368 —-a-w c:\windows\system32\wininet.dll
2009-03-03 00:18 . 2004-08-04 11:00 826368 ——w c:\windows\system32\dllcache\wininet.dll
2009-02-28 04:54 . 2004-08-04 12:00 636072 ——w c:\windows\system32\dllcache\iexplore.exe
2009-02-22 17:41 . 2009-02-22 17:41 ——– d—–w c:\program files\THQ
2009-02-20 10:20 . 2004-08-04 12:00 70656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 2004-08-04 12:00 161792 ——w c:\windows\system32\dllcache\ieakui.dll
2009-02-09 10:20 . 2009-04-13 20:37 399360 —-a-w c:\windows\system32\dllcache\rpcss.dll
2009-02-09 10:20 . 2009-04-13 20:37 723456 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:20 . 2009-04-13 20:37 723456 —-a-w c:\windows\system32\dllcache\lsasrv.dll
2009-02-09 10:20 . 2004-08-04 12:00 399360 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 10:20 . 2009-04-13 20:38 473088 —-a-w c:\windows\system32\dllcache\fastprox.dll
2009-02-09 10:20 . 2009-04-13 20:37 616960 —-a-w c:\windows\system32\dllcache\advapi32.dll
2009-02-09 10:20 . 2009-04-13 20:37 616960 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 10:20 . 2009-04-13 20:37 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 10:20 . 2009-04-13 20:37 714752 —-a-w c:\windows\system32\dllcache\ntdll.dll
2009-02-09 10:20 . 2009-04-13 20:38 453120 —-a-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-02-09 10:19 . 2009-01-09 23:37 1846272 —-a-w c:\windows\system32\win32k.sys
2009-02-09 10:19 . 2009-01-09 23:37 1846272 —-a-w c:\windows\system32\dllcache\win32k.sys
2009-02-06 17:24 . 2009-04-13 20:37 2180480 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 17:24 . 2009-04-13 20:37 2180480 —-a-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 17:22 . 2009-04-13 20:38 2136064 —-a-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 17:14 . 2009-04-13 20:37 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 17:14 . 2009-04-13 20:37 110592 —-a-w c:\windows\system32\dllcache\services.exe
2009-02-06 16:54 . 2004-08-04 12:00 35328 —-a-w c:\windows\system32\sc.exe
2009-02-06 16:54 . 2004-08-04 12:00 35328 —-a-w c:\windows\system32\dllcache\sc.exe
2009-02-06 16:49 . 2009-04-13 20:38 2015744 —-a-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-06 16:49 . 2009-04-13 20:37 2057728 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 16:49 . 2009-04-13 20:37 2057728 —-a-w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-06 16:39 . 2009-04-13 20:38 227840 —-a-w c:\windows\system32\dllcache\wmiprvse.exe
2009-02-03 20:08 . 2009-04-13 20:37 55808 —-a-w c:\windows\system32\dllcache\secur32.dll
2009-02-03 20:08 . 2004-08-04 12:00 55808 —-a-w c:\windows\system32\secur32.dll
2008-12-07 20:17 . 2005-07-26 23:08 1825 —-a-w c:\program files\Kodak EasyShare.lnk
2008-09-01 19:15 . 2005-07-28 11:30 39896 -c–a-w c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-05-18 01:10 . 2008-05-18 01:10 12754672 —-a-w c:\documents and settings\My Documents\MP10Setup.exe
2007-05-28 20:10 . 2007-05-28 20:10 2272 -c–a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2007-04-09 14:08 . 2007-04-09 14:08 233921 -c–a-w c:\documents and settings\My Documents\SpPremDemo.zip
2006-09-29 13:05 . 2006-09-29 13:05 2626744 —-a-w c:\documents and settings\My Documents\comcast_photoshow_deluxe_4.exe
2006-09-02 12:55 . 2006-08-24 12:15 10698768 —-a-w c:\documents and settings\My Documents\sspsetup1_.exe
2006-01-31 21:31 . 2006-01-31 21:31 774144 -c–a-w c:\program files\RngInterstitial.dll
2005-07-28 11:29 . 2005-07-28 11:29 135 -c–a-w c:\documents and settings\Compaq_Owner\Local Settings\Application Data\fusioncache.dat
2007-11-04 15:2007-07-19 23:19 23:39 . c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-02-09 19:06 764296 —-a-w c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-02-09 764296]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-02-09 764296]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-06-10 180269]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2009-04-06 6345840]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-01-04 49152]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344]

c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-3-16 385024]

c:\documents and settings\Compaq_Owner.YOUR-F78BF48CE2\Start Menu\Programs\Startup\
Compaq Organize.lnk - c:\program files\Hewlett-Packard\Compaq Organize\bin\displayAgent.exe [2005-6-10 36864]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - c:\program files\Compaq Connections\6750491\Program\Compaq Connections.exe [2005-6-10 45056]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-9-19 282624]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=

S0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2009-04-02 29808]
S1 pwipf6;pwipf6;c:\windows\system32\drivers\pwipf6.sys [2009-04-14 108296]
S2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [2009-04-14 1181040]

.
Contents of the 'Scheduled Tasks' folder

2009-04-13 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2005-03-04 01:04]

2009-04-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-01 21:17]

2009-04-19 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-02-09 19:06]

2009-04-17 c:\windows\Tasks\wrSpySweeper_L41413D1F152F418098E2E87AD0478F8E.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-04-14 17:32]

2009-04-17 c:\windows\Tasks\wrSpySweeper_L41413D1F152F418098E2E87AD0478F8E.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-04-14 17:32]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-BOC-426 - (no file)
Notify-dimsntfy - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-19 11:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(4008)
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
———————— Other Running Processes ————————
.
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\program files\Webroot\WebrootSecurity\SpySweeper.exe
c:\progra~1\HEWLET~1\COMPAQ~1\bin\nda.exe
c:\program files\Webroot\WebrootSecurity\SSU.exe
.
**************************************************************************
.
Completion time: 2009-04-19 11:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-19 15:13

Pre-Run: 110,393,561,088 bytes free
Post-Run: 110,697,537,536 bytes free

259 — E O F — 2009-04-17 02:22
And a new hijack this log!!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:51:47 PM, on 4/19/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SiSPower] "Rundll32.exe" SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] "c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AlcxMonitor] "ALCXMNTR.EXE"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - Startup: Compaq Organize.lnk = ?
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe

–
End of file - 7198 bytes
Hi :)

I'm assuming the two files you suggested for removal are not part of my current trial version of webroot. I'm not really sure where they came from, although I'm not the only one who used this computer.The search I did found them archived, when I tried to delete them I Igot a popup "output file could not be created. Is there another way to be rid of them?

Not a problem we can address this later on.

For now it appears your actual Operating System has not been validated by Microsoft. Please carry out the below:

Validate Windows:

Navigate to this page and on the left hand side within the Validate Now box click on the Validate Windows tab. This process should not take long.

Next:

  • Double click on MGADiag.exe to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in.
  • Save this file and post it in your next reply and we then can continue the malware removal process.
Here's the newest MGADiag. report, Diagnostic Report (1.9.0006.1): —————————————– WGA Data–> Validation Status: Genuine Validation Code: 0 Online Validation Code: N/A Cached Validation Code: N/A Windows Product Key: *****-*****-BRVBB-38MQ9-3PMFT Windows Product Key Hash: 2V2VyxlfhiaCt/JkDzYQfiNOHMA= Windows Product ID: 76477-OEM-2111907-00106 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010300.2.0.hom ID: {A238E6F5-8F75-4954-AB1E-4BCE36FF30E1}(3) Is Admin: Yes TestCab: 0x0 WGA Version: Registered, 1.9.9.1 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1 Resolution Status: N/A WgaER Data–> ThreatID(s): N/A Version: N/A WGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 WGATray.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-230-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32) Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {A238E6F5-8F75-4954-AB1E-4BCE36FF30E1}1.9.0006.15.1.2600.2.00010300.2.0.homx32*****-*****-*****-*****-3PMFT76477-OEM-2111907-001062S-1-5-21-382391205-272575057-1790030595Compaq Presario 061ED795AA-ABA SR1536NX NA530Phoenix Technologies, LTD 3.1220050420000000.000000+000HP PAVILION4D6B35D70184405D04090409Eastern Standard Time(GMT-05:00)02Hewlett-Packard CompanyCompaq Presario 109 Licensing Data–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: yes Marker string from BIOS: E06B:Compaq Computer Corporation|1085F:Compaq Computer Corporation|E10D:Compaq Computer Corporation|108FD:Compaq Computer Corporation|108FD:Compaq Computer Corporation|E10D:Hewlett-Packard Company|1DA50:Hewlett-Packard Company Marker string from OEMBIOS.DAT: HP PAVILION OEM Activation 2.0 Data–> N/A

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI