This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] can't get on any mcafee sites and google redirects

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. I have been having puter problems for about 5 days. If I google anything when I click on the website I want, I am redirected to an ad site with a similar name. I can get the site I want by hitting the back button. I got an error message from mcafee saying I needed to reinstall because there was an error - I can't get onto any mcafee sites, totally blocked. Also unable to run virus scan. The computer also has been slow during this time period and doing other strange things. Sometimes the pointer doesn't jive with the mouse. I tried to go back to a restore point before the problems, was able to restore to Saturday. Mcafee worked at that spot, but I could not get on the internet, so had to undo my restore. I did a Mcafee scan before undoing though and that was clean. I could not go to restore points farther back than Saturday, it just wouldn't do it. I've tried spybot and malware scans. I downloaded hijackthis and will post the log. I use windows XP. Whoever tries to help, let me warn you, I am very computer illiterate. Here is the log from hijackthis. Thanks for helping.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:29:16 PM, on 4/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PCDrProfiler] "C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" -r
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [SpybotDeletingA4824] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\actorobject.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4307] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\actorobject.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9323] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1558] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9795] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8718] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7898] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8191] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9957] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8339] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3383] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7518] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2734] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4445] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5961] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2532] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2371] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3539] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9163] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5305] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5209] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6775] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2057] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6932] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4384] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1824] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5852] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5378] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1111] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1356] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA78] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar"
O4 - HKLM\..\RunOnce: [SpybotDeletingC676] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar"
O4 - HKLM\..\RunOnce: [SpybotDeletingA348] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5873] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3626] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4181] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9318] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6288] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2175] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5364] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8668] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6697] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1089] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6113] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA370] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6954] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4235] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5733] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1153] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC283] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7078] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8608] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1711] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3789] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt"
O4 - HKLM\..\RunOnce: [SpybotDeletingA581] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9044] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1596] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2488] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8720] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC396] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5922] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1163] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8200] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6126] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7936] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6868] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1253] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4233] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7998] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4676] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9579] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7030] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA278] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar"
O4 - HKLM\..\RunOnce: [SpybotDeletingC960] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4400] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3187] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4307] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6553] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3076] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7407] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6813] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7840] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7370] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5367] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7882] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3177] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8978] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7612] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1886] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9912] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4168] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7255] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5313] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8516] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9528] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3671] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9696] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3408] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2309] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9987] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9287] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2911] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8633] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9307] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8502] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\WireControl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7458] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\WireControl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA454] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\controlpanel\index.html "
O4 - HKLM\..\RunOnce: [SpybotDeletingC8708] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\controlpanel\index.html "
O4 - HKLM\..\RunOnce: [SpybotDeletingA4331] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl.cda nfo"
O4 - HKLM\..\RunOnce: [SpybotDeletingC638] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl.cda nfo"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1390] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl_Uni nstall.cdas"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8551] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl_Uni nstall.cdas"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6769] command.com /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5626] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe
O4 - HKCU\..\Run: [ErrorEasy] C:\Program Files\ErrorEasy\ErrorEasy.exe -boot
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - S-1-5-18 Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite….x/qtplugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof…?1233333242859
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge…sh/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
–
End of file - 24692 bytes
Hi wilma1313, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Spybot has hung and may be corruptd. Please go to add/remove programs and uninstall it. You can all ways reinstall it after we are done.


Next

Download the HostsXpert 4.3 - Hosts File Manager.
  • Unzip HostsXpert 4.3 - Hosts File Manager to a convenient folder such as C:\HostsXpert 4.3 - Hosts File Manager
  • Run HostsXpert 4.3 - Hosts File Manager from the folder you extracted it to
  • Click on "File Handling".
  • Click on "Restore MS Hosts File".
  • Click OK on the Confirmation box.
  • Click on "Make Read Only?"
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

Next

Download OTListIt2 to your desktop.
  • Double click on OTList2.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

No need for a Hijackthis log this time.

Thanks
Hi, I had lost my desktop and start button and everything and had limited access to things using the task manager. Lost my sound for awhile too. Was unable to uninstall spybot because I couldn't get to control panel. I went ahead and downloaded Hostxpert adn I got my desktop/start button back. I followed your instructions and was fine until the point of click on OK in the conf box – then I get an error message "Cannot create file C:/windows/system32/Drivers/ETC/Hosts" After ok to the error message it kicks me out of the program. I then went ahead and uninstalled spybot. When I restarted I lost my desktop and all that, but just unzipped HostsXpert and got that back. At this point, I don't want to proceed with the next set of instructions until I hear from you again. I go to work shortly, but will check back as soon as I get home! Thanks so much for your help and thanks for restoring my desktop at least - its very encouraging :-)
Hi Wilma1313,

Try this for HostXpert,

Open Windows Explorer (right click your start button and select Explore)

At the top of windows explorer, click tools, folder options, click the
view tab

-check Display the contents of system folders
-check Show hidden files and folders
-uncheck "Hide extensions for known file types" box
-uncheck "Hide protecting operating system files" box

Click Apply, click OK

Next navigate to this folder C:\WINDOWS\system32\drivers\etc

Click on the folder etc
  • In the right hand panel, please locate this file hosts
  • right click on the file and select properties
  • on the General tab, clear the check marks from both boxes in the attributes section.
  • Click Apply, click OK
Try HostXpert again.

Try to download and run OTLISTIT2 even if you can't get HostsXpert to run.

Thanks
Hi.

Hostexperts worked with new instructions. Here are the logs you requested. Thanks!

OTListIt logfile created on: 4/20/2009 8:10:13 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.52 Gb Available Physical Memory | 76.28% Memory free
3.84 Gb Paging File | 3.52 Gb Available in Paging File | 91.59% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.23 Gb Total Space | 192.00 Gb Free Space | 85.63% Space Free | Partition Type: NTFS
Drive D: | 8.63 Gb Total Space | 0.35 Gb Free Space | 4.02% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-4DACD0EA75
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe (Intel Corporation)
PRC - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Documents and Settings\HP_Administrator\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (ELService [Auto | Running]) – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe (Intel Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IAANTMON [Auto | Running]) – C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (McAfee SiteAdvisor Service [Auto | Running]) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McrdSvc [Auto | Running]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (McShield [Unknown | Paused]) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (MpfService [Auto | Running]) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (Pml Driver HPZ12 [Auto | Stopped]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (e1express [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\e1e5132.sys (Intel Corporation)
DRV - (ELacpi [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ELacpi.sys (Intel Corporation)
DRV - (ELhid [System | Running]) – C:\WINDOWS\System32\Drivers\Elhid.sys (Intel Corporation)
DRV - (ELkbd [System | Running]) – C:\WINDOWS\System32\Drivers\Elkbd.sys (Intel Corporation)
DRV - (ELmon [System | Running]) – C:\WINDOWS\System32\Drivers\Elmon.sys (Intel Corporation)
DRV - (ELmou [System | Running]) – C:\WINDOWS\System32\Drivers\Elmou.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (grmnusb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\grmnusb.sys (GARMIN Corp.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (HSXHWBS2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSX_DP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\igxpmp32.sys (Intel Corporation)
DRV - (iaStor [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\iastor.sys (Intel Corporation)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mfeavfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (MPFP [System | Running]) – C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (winachsx [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.9
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\PROGRAM FILES\MCAFEE\SITEADVISOR [2009/03/30 20:06:06 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2009/01/14 21:12:29 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/01/26 21:03:25 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/14 12:44:02 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/14 12:44:01 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Components: C:\PROGRAM FILES\NETSCAPE\NETSCAPE BROWSER\COMPONENTS [2008/10/22 06:59:59 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Plugins: C:\PROGRAM FILES\NETSCAPE\NETSCAPE BROWSER\PLUGINS [2008/10/22 06:59:59 | 00,000,000 | —D | M]

[2009/04/14 12:44:03 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\mozilla\Extensions
[2009/04/14 12:44:03 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/14 12:44:03 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\mozilla\Firefox\Profiles\7yvz8mmx.default\extensions
[2009/04/13 21:19:32 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/13 21:19:32 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/26 14:11:21 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/26 14:11:22 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/26 13:56:22 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/26 13:56:22 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/26 13:56:22 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/26 13:56:22 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/26 13:56:22 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/26 13:56:22 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/26 13:56:22 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (698 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (hpWebHelper Class) - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll (Hewlett-Packard)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (&Google; Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" (Sonic Solutions)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode (Promise Technology, Inc.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [PCDrProfiler] "C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" -r ()
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe" (SoftThinks)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [gStart] C:\Garmin\gStart.exe (GARMIN Corp.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [*Restore] C:\WINDOWS\system32\restore\rstrui.exe -c (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingA1089] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1111] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1153] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1253] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1390] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl_Uninstall.cdas" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1596] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1711] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1886] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2057] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2175] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2309] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2371] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2734] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA278] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3076] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3383] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA348] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3626] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA370] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4168] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4235] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4307] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4331] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl.cdanfo" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4384] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4400] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA454] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\controlpanel\index.html" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5209] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5313] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA581] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5852] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5922] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5961] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA6769] command.com /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA6813] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7078] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7370] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA78] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7882] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7898] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7936] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7998] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8200] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8502] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\WireControl.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8633] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8668] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8720] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8978] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9163] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9287] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9318] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9528] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9579] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9696] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9957] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingC1163] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1356] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1824] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2488] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2532] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC283] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2911] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3177] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3187] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3408] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3539] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3671] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3789] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC396] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4181] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4233] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4445] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4676] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5305] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5364] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5367] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5378] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5626] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5733] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5873] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6113] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6126] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6288] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC638] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl.cdanfo" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6553] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6697] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC676] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6775] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6868] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6932] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6954] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7030] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7255] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7407] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7458] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\WireControl.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7518] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7612] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7840] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8191] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8339] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8516] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8551] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl_Uninstall.cdas" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8608] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8708] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\controlpanel\index.html" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9044] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9307] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC960] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9912] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9987] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts" (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O9 - Extra Button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1233333242859 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - D:\AUTOEXEC.BAT () - [ FAT32 ]
O32 - Autorun File - D:\Autorun.inf () - [ FAT32 ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\HP_Administrator\My Documents\*.tmp files]
[2009/04/20 20:04:43 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\Don't mess with this stuff
[2009/04/20 08:35:49 | 00,048,640 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\LL Menu doc May.doc
[2009/04/20 08:35:28 | 00,065,281 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\hurleybus.jpg
[2009/04/20 08:35:00 | 00,281,600 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\Krista week 4 cycle L.doc
[2009/04/20 08:34:54 | 00,304,128 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\Krista Week3Cycle Menu L.doc
[2009/04/20 08:34:49 | 00,304,640 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\Krista Week 2 Cycle L.doc
[2009/04/20 08:34:43 | 00,296,448 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\Krista Week 1 Cycle Menu L.doc
[2009/04/20 08:33:33 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTListIt2.exe
[2009/04/20 08:13:34 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\HostsXpert
[2009/04/20 08:12:39 | 00,353,485 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\HostsXpert.zip
[2009/04/19 01:52:57 | 00,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2009/04/18 21:44:56 | 00,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2009/04/18 21:44:55 | 00,000,000 | —D | C] – C:\Program Files\Bonjour
[2009/04/18 21:44:53 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/04/18 21:38:00 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/04/18 10:57:21 | 00,019,968 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\RACES 2009.doc
[2009/04/17 21:43:42 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2009/04/15 19:19:27 | 00,289,789 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\fs_medicare.pdf
[2009/04/15 17:23:13 | 00,001,745 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\HijackThis.lnk
[2009/04/15 17:23:13 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/14 23:08:13 | 00,000,312 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\http–www.hammernutrition.com-za-.url
[2009/04/14 20:22:49 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/14 18:17:19 | 00,000,444 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BE67FE08-B319-4BEF-B647-CB7E1C35E89D}.job
[2009/04/14 16:46:06 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/14 16:46:06 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/14 16:46:06 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/14 16:46:06 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/14 16:46:06 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/14 16:46:05 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/14 16:46:05 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/14 16:46:05 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/14 16:46:05 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/14 16:45:53 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/04/14 16:45:52 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/14 16:45:52 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/14 11:25:53 | 01,608,902 | -H– | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\IconCache.db
[2009/04/14 06:55:23 | 00,548,352 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\Prevention colon cancer.doc
[2009/04/13 21:19:43 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla
[2009/04/13 21:19:43 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla
[2009/04/13 21:19:35 | 00,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/04/13 20:53:06 | 00,000,480 | —- | C] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2009/04/13 09:26:32 | 00,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2009/04/13 09:21:56 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/04/13 08:31:43 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/04/13 08:22:08 | 00,000,000 | —D | C] – C:\a3350f91734deac12ec05080
[2009/04/12 10:22:19 | 00,001,751 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 7.0.lnk
[2009/04/12 09:57:53 | 00,000,452 | —- | C] () – C:\WINDOWS\tasks\ErrorEasy Scan.job
[2009/04/12 09:57:40 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\ErrorEasy
[2009/04/08 19:23:44 | 00,029,696 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\Lori I have an additional order to add on for Jewel Coon.doc
[2009/04/08 18:05:56 | 01,724,383 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\PPPlus-Lori-Howard-20090408-1805.dat
[2009/04/04 21:26:40 | 00,124,650 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\BMTR_Map_2008_15K.pdf
[2009/03/31 17:11:17 | 00,068,608 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\Medicine Interactions with Grapefruit.doc
[2009/03/29 15:20:12 | 00,000,518 | —- | C] () – C:\WINDOWS\FdlistDA.EQS
[2009/03/29 08:55:50 | 00,124,650 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\BMTR_Map_2008_15K.pdf
[2009/03/24 17:20:37 | 01,663,569 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\PPPlus-Lori-Howard-20090324-1720.dat
[2009/03/23 19:42:34 | 00,000,062 | —- | C] () – C:\WINDOWS\dcmvwr.INI
[2008/06/29 11:11:06 | 00,077,824 | R— | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2007/05/18 15:18:09 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/11/29 21:14:10 | 00,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/11/28 07:44:23 | 00,002,102 | —- | C] () – C:\WINDOWS\ERA.INI
[2006/11/25 08:07:58 | 00,001,963 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/11/22 19:58:38 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/11/22 08:00:52 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/08/20 00:14:25 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/08/19 23:55:51 | 00,028,848 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2006/08/19 23:51:17 | 00,014,317 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2006/08/19 23:51:12 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2006/08/19 23:48:05 | 00,000,219 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/08/19 23:38:08 | 00,004,539 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/08/19 23:37:32 | 00,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/08/19 23:32:29 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/08/19 23:28:29 | 00,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/08/19 23:24:46 | 00,348,880 | —- | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2006/08/19 23:24:46 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4624.dll
[2006/08/19 23:06:42 | 00,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2006/08/19 23:06:42 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2006/08/19 23:06:26 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2006/06/16 13:58:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/30 23:02:00 | 00,000,683 | —- | C] () – C:\WINDOWS\win.ini
[2005/08/30 15:52:36 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
[2005/08/05 23:01:54 | 00,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/09/16 22:24:26 | 03,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/08/09 23:00:00 | 01,287,680 | —- | C] () – C:\WINDOWS\System32\quartz(2).dll
[2004/07/26 09:51:38 | 00,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/07/07 03:00:00 | 00,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== Files - Modified Within 30 Days ==========

[78 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\HP_Administrator\My Documents\*.tmp files]
[2009/04/20 20:08:01 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTListIt2.exe
[2009/04/20 20:04:11 | 00,000,698 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/04/20 17:05:31 | 00,000,444 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BE67FE08-B319-4BEF-B647-CB7E1C35E89D}.job
[2009/04/20 09:27:06 | 00,019,968 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\RACES 2009.doc
[2009/04/20 08:20:23 | 00,020,781 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2009/04/20 08:19:57 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/20 08:19:55 | 21,374,73024 | -HS- | M] () – C:\hiberfil.sys
[2009/04/20 08:19:55 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/20 08:12:39 | 00,353,485 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\HostsXpert.zip
[2009/04/19 13:52:12 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/19 13:46:21 | 00,025,088 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\2009 - training log.doc
[2009/04/19 12:00:00 | 00,000,452 | —- | M] () – C:\WINDOWS\tasks\ErrorEasy Scan.job
[2009/04/18 10:57:24 | 00,039,424 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\5 K april log.doc
[2009/04/15 21:26:28 | 00,000,312 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\http–www.hammernutrition.com-za-.url
[2009/04/15 19:45:47 | 00,548,352 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\Prevention colon cancer.doc
[2009/04/15 19:19:27 | 00,289,789 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\fs_medicare.pdf
[2009/04/15 17:23:13 | 00,001,745 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\HijackThis.lnk
[2009/04/15 07:09:10 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/15 07:07:49 | 00,441,626 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/15 07:07:49 | 00,382,022 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/15 07:07:49 | 00,053,640 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/15 01:19:52 | 00,000,362 | —- | M] () – C:\WINDOWS\tasks\McDefragTask.job
[2009/04/14 21:09:40 | 00,004,539 | —- | M] () – C:\WINDOWS\WININIT.INI
[2009/04/14 12:41:57 | 00,000,246 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2009/04/14 11:25:53 | 01,608,902 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\IconCache.db
[2009/04/13 21:19:35 | 00,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/04/13 20:53:06 | 00,000,480 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2009/04/13 16:45:55 | 00,000,087 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\desktop.ini
[2009/04/13 08:04:40 | 00,000,683 | —- | M] () – C:\WINDOWS\win.ini
[2009/04/12 10:22:19 | 00,001,768 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2009/04/12 10:22:19 | 00,001,751 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 7.0.lnk
[2009/04/08 19:23:44 | 00,029,696 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\Lori I have an additional order to add on for Jewel Coon.doc
[2009/04/08 18:05:57 | 01,724,383 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\PPPlus-Lori-Howard-20090408-1805.dat
[2009/04/08 12:43:32 | 00,047,616 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\library.doc
[2009/04/06 09:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/04 21:26:40 | 00,124,650 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\BMTR_Map_2008_15K.pdf
[2009/03/31 17:16:49 | 00,068,608 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\Medicine Interactions with Grapefruit.doc
[2009/03/29 15:46:55 | 00,048,640 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\LL Menu doc May.doc
[2009/03/29 15:44:10 | 00,002,102 | —- | M] () – C:\WINDOWS\ERA.INI
[2009/03/29 15:43:10 | 00,000,518 | —- | M] () – C:\WINDOWS\FdlistDA.EQS
[2009/03/29 15:13:21 | 00,625,044 | —- | M] () – C:\WINDOWS\FdItemDA.EQS
[2009/03/29 15:13:21 | 00,014,496 | —- | M] () – C:\WINDOWS\ExercsDA.EQS
[2009/03/29 15:13:21 | 00,011,264 | —- | M] () – C:\WINDOWS\RecmndDA.EQS
[2009/03/29 15:13:19 | 00,008,870 | —- | M] () – C:\WINDOWS\MeasrsDA.EQS
[2009/03/29 08:55:50 | 00,124,650 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\BMTR_Map_2008_15K.pdf
[2009/03/27 19:50:13 | 00,019,968 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\blank2.doc
[2009/03/27 01:58:38 | 01,203,922 | —- | M] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/03/24 17:20:38 | 01,663,569 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\PPPlus-Lori-Howard-20090324-1720.dat
[2009/03/23 19:42:34 | 00,000,062 | —- | M] () – C:\WINDOWS\dcmvwr.INI

========== LOP Check ==========

[2009/04/17 21:43:17 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/10/22 07:00:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/02/10 17:00:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/11/22 19:58:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2009/04/18 21:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/10/22 07:00:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/01/30 20:23:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2006/08/19 23:44:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2006/08/19 23:42:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2009/01/01 11:09:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2009/01/15 22:43:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/04/25 14:59:40 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2006/08/20 00:11:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2006/11/24 11:27:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2008/12/02 07:11:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2006/08/19 23:38:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2006/08/19 23:48:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/01/16 08:12:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/09/30 16:52:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2008/11/01 16:10:56 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/11/21 22:14:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2006/08/19 23:29:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/08/28 17:23:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SiteAdvisor
[2006/08/19 23:33:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2009/04/20 08:18:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2006/11/21 22:14:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/08/19 23:42:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2006/12/21 17:59:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/06/29 09:37:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/04/13 21:19:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\HP_Administrator\Application Data
[2009/02/10 17:00:29 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Adobe
[2008/07/13 15:10:31 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
[2006/11/22 19:58:52 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\AOL
[2008/10/22 07:00:33 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
[2007/03/18 17:22:35 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\CyberLink
[2009/04/12 09:58:26 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\ErrorEasy
[2008/02/07 13:42:14 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\GOODSEARCH
[2006/11/25 08:22:54 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Google
[2008/06/28 11:59:44 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Gtek
[2008/01/30 23:51:21 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Help
[2006/11/24 11:33:07 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\HP
[2006/11/21 16:22:47 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\HPQ
[2005/11/14 20:04:10 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Identities
[2008/12/15 07:49:52 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Image Zone Express
[2006/08/19 23:48:07 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Intuit
[2008/01/30 22:43:36 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Macromedia
[2009/01/16 08:13:04 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
[2008/12/30 08:51:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft
[2009/04/18 21:30:28 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Move Networks
[2009/04/14 12:33:43 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla
[2008/06/28 21:29:05 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\MSNInstaller
[2007/08/31 19:20:36 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Printer Info Cache
[2008/06/28 16:58:54 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Real
[2008/01/30 22:51:06 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Sun
[2006/11/24 11:08:40 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Template
[2008/02/11 09:08:49 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\U3
[2007/07/25 22:26:47 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\WinBatch
[2006/11/21 22:15:02 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\You've Got Pictures Screensaver
[2004/08/10 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/13 20:53:06 | 00,000,480 | —- | M] () – C:\WINDOWS\Tasks\Easy Internet Sign-up.job
[2009/04/19 12:00:00 | 00,000,452 | —- | M] () – C:\WINDOWS\Tasks\ErrorEasy Scan.job
[2009/04/15 01:19:52 | 00,000,362 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2009/02/01 02:00:09 | 00,000,354 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2009/04/20 08:19:57 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/04/20 17:05:31 | 00,000,444 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{BE67FE08-B319-4BEF-B647-CB7E1C35E89D}.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 3382 bytes -> C:\Documents and Settings\HP_Administrator\Desktop\http–www.hammernutrition.com-za-.url:favicon
< End of report >





OTListIt Extras logfile created on: 4/20/2009 8:10:13 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.52 Gb Available Physical Memory | 76.28% Memory free
3.84 Gb Paging File | 3.52 Gb Available in Paging File | 91.59% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.23 Gb Total Space | 192.00 Gb Free Space | 85.63% Space Free | Partition Type: NTFS
Drive D: | 8.63 Gb Total Space | 0.35 Gb Free Space | 4.02% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-4DACD0EA75
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP (Hewlett-Packard)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\DISC\DISCover.exe:*:Enabled:DISCover Drop & Play System (Digital Interactive Systems Corporation)
C:\Program Files\DISC\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub (Digital Interactive Systems Corporation, Inc.)
C:\Program Files\DISC\myFTP.exe:*:Enabled:DISCover FTP (Digital Interactive Systems Corporation, Inc.)
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP (Hewlett-Packard)
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink File not found
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe ()
C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe ( )
C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent (McAfee, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{1341D838-719C-4A05-B50F-49420CA1B4BB}" = HP Boot Optimizer
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 2.1
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{5FDD0538-C67A-4F67-B3F8-09D1AAF04D99}" = muvee autoProducer unPlugged 2.0
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{82081779-4175-4666-A457-AB711CD37EF0}" = cp_LightScribeConfig
"{829DAAD6-BB11-4BB7-921B-07FFB703F944}" = CP_Package_Variety3
"{82E55892-6FFD-403F-AA97-D726846768AA}" = CP_AtenaShokunin1Config
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{866A0078-DEA7-4348-9C9A-999AF2991EAA}" = SlideShowMusic
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8A534F71-3202-4464-A422-B767295E67B9}" = CP_Package_Variety2
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{93E5A317-24EC-4744-812C-16FECFE86E6A}" = CP_Package_Variety1
"{9455959E-D588-EFAE-329C-F66CC797F32A}" = Adobe Media Player
"{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}" = Apple Mobile Device Support
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9F7AF7CD-E3D0-4C68-A3BA-C76C359B3AA8}" = LightScribe 1.4.105.1
"{9FC8D8F8-AF3A-4488-98AF-51C6DEC732F2}" = c3100_Help
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A9F5421F-DA70-4C77-BB97-8D77EC33ED5E}" = HP Photosmart and Deskjet 7.0.A
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3FAA091-B278-44A7-BF48-190811C5F9F7}" = cp_UpdateProjectsConfig
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{DAAD5187-62C5-4AD6-A526-803C18C4944D}" = HP Web Helper
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}" = iTunes
"{DE659AC8-EEF0-4115-AA0C-6500D194FB10}" = Garmin Training Center v5
"{EB8C9964-09AC-48bf-8B98-027609C78251}" = C3100
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{EEFEBB48-329E-46F6-AEB8-929A5BAFDB2F}" = Intel® Viiv™ Software
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FB4740B3-2530-452D-A825-F7AB246CA7DF}" = muvee autoProducer 5.0
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Data Fax SoftModem with SmartCP
"DISCover" = DISCover
"EL" = Intel® Quick Resume Technology Drivers
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Photosmart for Media Center PC" = HP Photosmart for Media Center PC
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Install WeatherBug" = Remove WeatherBug Installer
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2006b" = Microsoft Money 2006
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Netscape Browser" = Netscape Browser (remove only)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OfficeTrial" = Microsoft Office Standard Edition 2003 60 days trial
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"PROSet" = Intel® PRO Network Connections Drivers
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealPlayer 6.0" = RealPlayer
"Rhapsody" = Rhapsody
"WildTangent hpmedia Master Uninstall" = My HP Games
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar for Internet Explorer
"Yahoo! Toolbar" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/3/2009 10:39:22 AM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office XP Professional - Update '{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}'
could not be installed. Error code 1603. Windows Installer can create logs to help
troubleshoot issues with installing software packages. Use the following link for
instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Error - 2/8/2009 11:21:16 AM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office XP Professional – Error 1706. Setup cannot
find the required files. Check your connection to the network, or CD-ROM drive.
For other potential solutions to this problem, see C:\Program Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 2/8/2009 11:21:18 AM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office XP Professional - Update '{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}'
could not be installed. Error code 1603. Windows Installer can create logs to help
troubleshoot issues with installing software packages. Use the following link for
instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Error - 2/10/2009 6:13:14 PM | Computer Name = YOUR-4DACD0EA75 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/10/2009 6:13:20 PM | Computer Name = YOUR-4DACD0EA75 | Source = Application Hang | ID = 1001
Description = Fault bucket 1015682910.

Error - 2/14/2009 2:08:57 PM | Computer Name = YOUR-4DACD0EA75 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/15/2009 10:13:20 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/15/2009 10:13:22 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Hang | ID = 1001
Description = Fault bucket 1110235319.

Error - 2/24/2009 8:19:28 PM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module webhelper.dll, version 1.0.0.1, fault address 0x0000efd3.

Error - 2/24/2009 8:19:30 PM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1001
Description = Fault bucket 1138990828.

[ System Events ]
Error - 4/20/2009 9:04:43 PM | Computer Name = YOUR-4DACD0EA75 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/20/2009 9:05:23 PM | Computer Name = YOUR-4DACD0EA75 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/20/2009 9:06:03 PM | Computer Name = YOUR-4DACD0EA75 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/20/2009 9:06:44 PM | Computer Name = YOUR-4DACD0EA75 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/20/2009 9:07:24 PM | Computer Name = YOUR-4DACD0EA75 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/20/2009 9:08:04 PM | Computer Name = YOUR-4DACD0EA75 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/20/2009 9:08:45 PM | Computer Name = YOUR-4DACD0EA75 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/20/2009 9:09:25 PM | Computer Name = YOUR-4DACD0EA75 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/20/2009 9:10:06 PM | Computer Name = YOUR-4DACD0EA75 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/20/2009 9:10:46 PM | Computer Name = YOUR-4DACD0EA75 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.


< End of report >
Hi Wilma1313

We'll start here. It looks like System restore is se to run on each boot up. We'll try to stop that from happening as it will just keep replacing what we fix. DO NOT turn System Restore off, we will try to fix it with this next fix.

Back up your registry with ERUNT
  • Download ERUNT from Here or HERE and save it to your desktop.
  • Double click erunt-setup.exe to install the program
  • Follow the prompts, and then uncheck Create NTREGOPT desktop icon at the Additional Tasks screen.
  • Click No when you are prompted about creating an ERUNT entry in the startup folder.
  • At the next screen, uncheck Show documentation and check Launch ERUNT
  • If ERUNT doesn't start by itself, launch it from the desktop shortcut.
  • At the configuration screen, make sure all 3 checkboxes are checked
  • Click Ok to run the backup process


It is important that you click Yes when prompted by this next tool to reboot your computer.

Next, Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTLI
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O4 - HKLM..\RunOnce: [*Restore] C:\WINDOWS\system32\restore\rstrui.exe -c (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingA1089] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1111] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1153] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1253] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1390] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl_Uninstall.cdas" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1596] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1711] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1886] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2057] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2175] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2309] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2371] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2734] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA278] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3076] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3383] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA348] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3626] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA370] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4168] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4235] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4307] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4331] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl.cdanfo" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4384] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4400] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA454] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\controlpanel\index.html" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5209] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5313] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA581] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5852] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5922] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5961] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA6769] command.com /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA6813] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7078] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7370] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA78] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7882] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7898] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7936] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7998] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8200] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8502] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\WireControl.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8633] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8668] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8720] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8978] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9163] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9287] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9318] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9528] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9579] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9696] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9957] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll" ()
O4 - HKLM..\RunOnce: [SpybotDeletingC1163] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1356] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1824] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2488] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2532] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC283] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2911] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3177] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3187] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3408] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3539] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3671] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3789] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC396] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4181] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4233] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4445] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4676] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5305] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5364] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5367] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5378] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5626] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5733] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5873] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6113] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6126] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6288] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC638] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl.cdanfo" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6553] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6697] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC676] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6775] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6868] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6932] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6954] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7030] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7255] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7407] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7458] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\WireControl.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7518] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7612] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7840] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8191] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8339] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8516] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8551] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl_Uninstall.cdas" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8608] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8708] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\controlpanel\index.html" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9044] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9307] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC960] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9912] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini" (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9987] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts" (Microsoft Corporation)

:Services

:Reg

:Files

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL2 log and a new HJT log.

Thanks
Hi,
Here are the logs requested.

========== PROCESSES ==========
Process explorer.exe killed successfully!
========== OTLISTIT ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\*Restore deleted successfully.
C:\WINDOWS\system32\restore\rstrui.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA1089 deleted successfully.
C:\WINDOWS\system32\command.com moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA1111 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA1153 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA1253 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA1390 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl_Uninstall.cdas" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA1596 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA1711 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA1886 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA2057 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA2175 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA2309 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA2371 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA2734 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA278 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA3076 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA3383 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA348 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA3626 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA370 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA4168 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA4235 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA4307 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA4331 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl.cdanfo" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA4384 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA4400 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA454 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\controlpanel\index.html" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA5209 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA5313 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA581 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA5852 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA5922 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA5961 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA6769 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA6813 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA7078 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA7370 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA78 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA7882 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA7898 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA7936 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA7998 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA8200 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA8502 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\WireControl.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA8633 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA8668 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA8720 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA8978 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA9163 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA9287 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA9318 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA9528 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA9579 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA9696 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA9957 deleted successfully.
File command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC1163 deleted successfully.
C:\WINDOWS\system32\cmd.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC1356 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC1824 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC2488 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC2532 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC283 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC2911 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC3177 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC3187 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC3408 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC3539 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC3671 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC3789 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC396 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC4181 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC4233 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC4445 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC4676 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC5305 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC5364 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC5367 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC5378 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC5626 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC5733 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC5873 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC6113 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC6126 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC6288 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC638 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl.cdanfo" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC6553 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC6697 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC676 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC6775 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC6868 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC6932 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC6954 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC7030 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC7255 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC7407 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC7458 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\WireControl.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC7518 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC7612 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC7840 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC8191 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC8339 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC8516 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC8551 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl_Uninstall.cdas" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC8608 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC8708 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\controlpanel\index.html" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC9044 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC9307 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC960 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC9912 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini" not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC9987 deleted successfully.
File cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts" not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Acr2F4F.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Acr2F50.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\mcafee_IlBhJkR94Ac1dtS scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_2OJoZDrxq95kpvV scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_T0dYrrJjh4ErEV5 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1e8.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_iqNcG2N9jHG2FkJ scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_oi0NvIDwxr12E1X scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_XEMtZRm1HNI3HP8 scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTListIt2 by OldTimer - Version 2.0.14.0 log created on 04212009_061944

Files moved on Reboot…
File move failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Acr2F4F.tmp scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Acr2F50.tmp scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\mcafee_IlBhJkR94Ac1dtS scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\mcmsc_2OJoZDrxq95kpvV scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\mcmsc_T0dYrrJjh4ErEV5 scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\Perflib_Perfdata_1e8.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\sqlite_iqNcG2N9jHG2FkJ scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\sqlite_oi0NvIDwxr12E1X scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\sqlite_XEMtZRm1HNI3HP8 scheduled to be moved on reboot.

Registry entries deleted on Reboot…


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:28:31 AM, on 4/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PCDrProfiler] "C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" -r
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - S-1-5-18 Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233333242859
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 10699 bytes



Thanks much, glad for help from someone who knows what is going on. Had I messed around with this on my own anymore than I already had, I'm sure things would have gotten much worse or I would have bought a new puter. Really glad don't have to do that, don't want Vista! Computer seems to be a little better, mouse is working. Got some popups still. Google still redirects. Can't access mcafee. I expected we would have more to do so all that just information for you – not a complaint!!!!!
Hi Wilma1313,


  • Clcik Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.


You have this program installed, Malwarebytes' Anti-Malware_ (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back with the MBAM log and a new HJT log.

Thanks
Hi Wilma1313,

Try copying and pasting these commands, one at a time, into the run box and clicking Ok

C:\Windows\System32\command.com

C:\Windows\System32\cmd.exe

If the command window does come up, and you recieve a windows popup message similar to"Windows can not end this program……." when trying to close it, type exit and hit enter to close it.

Let me know if either of those commands will open the command window.



Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
  • Do Not copy the word CODE note it starts with the :

    :filefind
    cmd.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Thanks
SystemLook v1.0 by jpshortstuff (14.04.09) Hi, Neither command opened a box. The first one did generate a cannot find error message. The second one caused my desktop to go away a couple seconds, then back to normal. Here are the results from the look log. Log created at 06:07 on 22/04/2009 by HP_Administrator (Administrator - Elevation successful) ========== filefind ========== Searching for "cmd.exe" C:\WINDOWS\$NtServicePackUninstall$\cmd.exe —–c 388608 bytes [12:30 15/08/2008] [04:00 10/08/2004] EEB024F2C81F0D55936FB825D21A91D6 C:\WINDOWS\ServicePackFiles\i386\cmd.exe —— 389120 bytes [01:18 05/08/2008] [00:12 14/04/2008] 6D778E0F95447E6546553EEEA709D03C C:\WINDOWS\system32\cmd.exe –a— 389120 bytes [01:18 05/08/2008] [00:12 14/04/2008] 6D778E0F95447E6546553EEEA709D03C C:\WINDOWS\system32\dllcache\cmd.exe –a— 389120 bytes [01:18 05/08/2008] [00:12 14/04/2008] 6D778E0F95447E6546553EEEA709D03C C:\_OTListIt\MovedFiles\04212009_061944\WINDOWS\system32\cmd.exe –a— 389120 bytes [04:00 10/08/2004] [00:12 14/04/2008] 6D778E0F95447E6546553EEEA709D03C -=End Of File=-
Hi Wilma1313,

Please run SystemLook with this script

:filefind 
command.com
rstrui.exe

Thanks
Here it is! SystemLook v1.0 by jpshortstuff (14.04.09) Log created at 20:00 on 22/04/2009 by HP_Administrator (Administrator - Elevation successful) ========== filefind ========== Searching for "command.com" C:\_OTListIt\MovedFiles\04212009_061944\WINDOWS\system32\command.com –a— 50620 bytes [04:00 10/08/2004] [04:00 10/08/2004] BE67D29CA914DE072D9971E3FFFC4050 Searching for "rstrui.exe" C:\WINDOWS\$NtServicePackUninstall$\rstrui.exe —–c 380416 bytes [12:31 15/08/2008] [04:00 10/08/2004] 4375CD59161C0A033DF68D9510D1F8CF C:\WINDOWS\ServicePackFiles\i386\rstrui.exe —— 380416 bytes [01:18 05/08/2008] [00:12 14/04/2008] BD6C1488F63D64DEA8EE514802FC2CDD C:\WINDOWS\system32\dllcache\rstrui.exe –a— 380416 bytes [01:18 05/08/2008] [00:12 14/04/2008] BD6C1488F63D64DEA8EE514802FC2CDD C:\WINDOWS\system32\Restore\rstrui.exe –a— 380416 bytes [01:18 05/08/2008] [00:12 14/04/2008] BD6C1488F63D64DEA8EE514802FC2CDD C:\_OTListIt\MovedFiles\04212009_061944\WINDOWS\system32\restore\rstrui.exe –a— 380416 bytes [04:00 10/08/2004] [00:12 14/04/2008] BD6C1488F63D64DEA8EE514802FC2CDD -=End Of File=-
Hi Wilma1313,

We have to move a file back into the origonal location.

Please open Windows Explorer (right click your start button and select explore)

In the left hand panel, click the + sign beside My Computer
  • Navigate to this folder
    C:\_OTListIt\MovedFiles\04212009_061944\WINDOWS\system32
    • by clicking the + signs beside
  • Local disk C:
  • _OTListIt
  • MovedFiles
  • 04212009_061944
  • WINDOWS
  • Click on system32
  • In the right hand panel, please locate this file command.com
  • right click on the file and select copy

Back in the left hand panel, please scroll down and click the + sign beside WINDOWS (note this is a different Windows folder than the previous one you were in)
  • scroll down and right click on System32
  • Select paste

Try this now

  • Clcik Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.

Did it work? Please continue with the rest of the instructions.

Thanks
Good morning, Same thing happened after following the move instructions. Icons disappear and come back. Went thru a second time to make sure I did what I was supposed to and when I got to the last paste step got a message asking if I wanted to replace the 1st command.com I moved to system 32 with the new one, so know I did it right. Off to work, but will be looking for new instructions sometime after Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI