This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Restore help

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I got a virus on my Windows XP, started out as advertising for Virus removing software. Then it took over my desktop, wouldn't allow me to go on any websites, finally had to do a system restore.. I am sure the virus is still lurking in my hard-drive somewhere. Is there anything to do now? My computer is an HP, I bought it in 2006. Any help would be appreciated, and thank you for being there.
Hi there. Lets see what you have first

Download Rooter.exe to your desktop
  • Doubleclick it to start the tool.
  • A Notepad file containing the report will open, also found at %systemdrive%(usually C:)\Rooter.txt. Copy and paste it with your OTLI log.

THEN

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 2

C:\ [Fixed] - NTFS - (Total:145479 Mo/Free:1383 Mo)
D:\ [Fixed] - FAT32 - (Total:7124 Mo/Free:1214 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [Removable] (Total:0 Mo/Free:0 Mo)
G:\ [Removable] (Total:0 Mo/Free:0 Mo)
H:\ [Removable] (Total:0 Mo/Free:0 Mo)
I:\ [Removable] (Total:0 Mo/Free:0 Mo)

Sat 05/02/2009| 9:46

———————-\\ Processes..

–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\Ati2evxx.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
———- C:\Program Files\Alwil Software\Avast4\ashServ.exe
———- C:\WINDOWS\system32\Ati2evxx.exe
———- C:\WINDOWS\Explorer.EXE
———- C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
———- C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\WINDOWS\system32\ctfmon.exe
———- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
———- C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
———- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
———- C:\WINDOWS\system32\wdfmgr.exe
———- C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
———- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
———- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
———- C:\WINDOWS\System32\alg.exe
———- C:\WINDOWS\system32\wbem\wmiprvse.exe
———- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
———- C:\WINDOWS\system32\wuauclt.exe
———- C:\HP\KBD\KBD.EXE
———- C:\WINDOWS\ALCXMNTR.EXE
———- C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
———- c:\windows\system\hpsysdrv.exe
———- C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
———- C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
———- C:\Program Files\AOL 9.1\waol.exe
———- C:\Program Files\AOL 9.1\shellmon.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

———————-\\ ROOTKIT !!


———————-\\ Cracks & Keygens..

C:\DOCUME~1\COMPAQ~1\Local Settings\Temporary Internet Files\Content.IE5\G5IRODAN\1-video-ribhillis-wallcracks-160dfh042909[1].jpg


1 - "C:\Rooter$\Rooter_1.txt" - Sat 05/02/2009| 9:47

———————-\\ Scan completed at 9:47


OTListIt logfile created on: 5/2/2009 9:54:27 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.3 Folder = C:\Documents and Settings\Compaq_Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

446.48 Mb Total Physical Memory | 85.54 Mb Available Physical Memory | 19.16% Memory free
1.03 Gb Paging File | 0.58 Gb Available in Paging File | 56.31% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.07 Gb Total Space | 121.35 Gb Free Space | 85.42% Space Free | Partition Type: NTFS
Drive D: | 6.96 Gb Total Space | 1.19 Gb Free Space | 17.04% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-27E1513D96
Current User Name: Compaq_Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Software Update\HPwuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe (Hewlett-Packard)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe ()
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - C:\HP\KBD\KBD.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\ALCXMNTR.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AOL 9.1\waol.exe (AOL, LLC.)
PRC - C:\Program Files\AOL 9.1\shellmon.exe (AOL, LLC.)
PRC - C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Compaq_Owner\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (AgereSoftModem [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AmdK8 [System | Running]) – C:\WINDOWS\system32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (bb-run [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (ftsata2 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (iaStor [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RTL8023xp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\wanatw4.sys (America Online, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AOL Search"
FF - prefs.js..browser.search.defaulturl: "http://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopie7&query="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: [removed]:1.0.5.1116
FF - prefs.js..extensions.enabledItems: {C5AD2162-156C-432C-9A06-7720B2C2FE13}:1.0
FF - prefs.js..extensions.enabledItems: {3409CF0C-6974-4CBF-9D7A-DD9AAF454458}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "http://searchservice.myspace.com/index.cfm?fuseaction=sitesearch.results&type=Web&orig=IMC-FF&qry="

FF - HKLM\software\mozilla\Netscape Browser 8.0.3.4\Extensions\\Components: C:\PROGRAM FILES\NETSCAPE\NETSCAPE BROWSER\COMPONENTS [2005/12/02 18:13:38 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.3.4\Extensions\\Plugins: C:\PROGRAM FILES\NETSCAPE\NETSCAPE BROWSER\PLUGINS [2009/04/28 22:00:03 | 00,000,000 | —D | M]

[2008/12/09 17:49:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\mozilla\Extensions
[2008/12/09 17:49:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/01 20:19:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\mozilla\Firefox\Profiles\3o4p97mx.default\extensions
[2008/12/09 18:50:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\mozilla\Firefox\Profiles\3o4p97mx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/04/28 23:18:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\mozilla\Firefox\Profiles\3o4p97mx.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/12/28 14:48:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\mozilla\Firefox\Profiles\3o4p97mx.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}
[2008/11/13 01:03:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\mozilla\Firefox\Profiles\3o4p97mx.default\extensions\[removed]
[2009/05/01 20:19:19 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/27 21:35:46 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{3409CF0C-6974-4CBF-9D7A-DD9AAF454458}
[2009/04/27 21:14:36 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/24 22:15:13 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{C5AD2162-156C-432C-9A06-7720B2C2FE13}
[2009/04/27 21:14:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/27 21:14:30 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/12/09 17:48:45 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/12/09 17:48:45 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/12/09 17:48:45 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/12/09 17:48:45 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/12/09 17:48:45 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/09 17:48:45 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/12/09 17:48:45 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run (Hewlett-Packard Company)
O4 - HKLM..\Run: [PCDrProfiler] File not found
O4 - HKCU..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1\AOL.EXE" -b (AOL, LLC.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe (Motive Communications, Inc.)
O4 - Startup: C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\AOL Desktop.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe (AOL LLC)
O4 - Startup: C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\Compaq Organize.lnk = C:\Program Files\Hewlett-Packard\Compaq Organize\bin\displayAgent.exe (NeoPlanet)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html (Google Inc.)
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html (Google Inc.)
O8 - Extra context menu item: Add To Compaq Organize… - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html [2005/12/02 18:33:51 | 00,000,000 | —D | M]
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html (Google Inc.)
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/06/25 00:32:00 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell - "" = AutoRun
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/05/02 09:52:19 | 00,502,272 | —- | C] (OldTimer Tools) – C:\DOCUME~1\COMPAQ~1\Desktop\OTListIt2.exe
[2009/05/02 09:50:56 | 00,267,612 | —- | C] () – C:\DOCUME~1\COMPAQ~1\Desktop\Rooter.exe
[2009/05/02 09:46:04 | 00,000,000 | —D | C] – C:\Rooter$
[2009/05/01 15:39:21 | 00,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2009/04/30 19:45:45 | 02,245,632 | —- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\BCBSSaver.doc
[2009/04/29 03:28:14 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthport.sys
[2009/04/29 03:28:14 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2009/04/29 03:25:17 | 02,180,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2009/04/29 03:25:17 | 02,136,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2009/04/29 03:25:16 | 02,057,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2009/04/29 03:25:16 | 02,015,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2009/04/29 03:21:28 | 00,351,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp3res.dll
[2009/04/29 03:01:07 | 00,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2009/04/28 18:49:20 | 00,000,062 | -HS- | C] () – C:\Documents and Settings\Compaq_Owner\Application Data\desktop.ini
[2009/04/28 18:49:19 | 00,000,083 | -HS- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\desktop.ini
[2009/04/28 18:49:19 | 00,000,062 | -HS- | C] () – C:\Documents and Settings\Compaq_Owner\Local Settings\desktop.ini
[2009/04/28 18:49:16 | 00,000,084 | -HS- | C] () – C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\desktop.ini
[2009/04/28 18:49:16 | 00,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Application Data\Symantec
[2009/04/28 18:49:16 | 00,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Application Data\Real
[2009/04/28 18:49:16 | 00,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft
[2009/04/28 18:49:16 | 00,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Application Data\Intuit
[2009/04/28 18:49:16 | 00,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Application Data\Identities
[2009/04/28 18:49:15 | 00,000,000 | –SD | C] – C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files
[2009/04/28 18:49:15 | 00,000,000 | –SD | C] – C:\Documents and Settings\Compaq_Owner\Local Settings\History
[2009/04/28 18:49:15 | 00,000,000 | R–D | C] – C:\DOCUME~1\COMPAQ~1\My Documents\My Videos
[2009/04/28 18:49:15 | 00,000,000 | R–D | C] – C:\DOCUME~1\COMPAQ~1\My Documents\My Pictures
[2009/04/28 18:49:15 | 00,000,000 | R–D | C] – C:\DOCUME~1\COMPAQ~1\My Documents\My Music
[2009/04/28 18:49:15 | 00,000,000 | -H-D | C] – C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data
[2009/04/28 18:49:15 | 00,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Local Settings\Temp
[2009/04/28 18:47:29 | 00,002,194 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\BLOCKBUSTER Online.lnk
[2009/04/28 18:47:29 | 00,002,085 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\AOL Latino 3 Meses Incluidos.lnk
[2009/04/28 18:47:29 | 00,001,990 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\My Compaq Games.lnk
[2009/04/28 18:47:29 | 00,001,941 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\AOL 3 Months Included.lnk
[2009/04/28 18:47:29 | 00,001,905 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\eBay.lnk
[2009/04/28 18:47:29 | 00,001,878 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Microsoft Office 2003 Edition 60 Days Trial Welcome Tour.lnk
[2009/04/28 18:47:29 | 00,001,854 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\MSN.lnk
[2009/04/28 18:47:29 | 00,001,577 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Quicken 2006 New User Edition.lnk
[2009/04/28 18:47:29 | 00,001,537 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\HP Extended Service Plans.lnk
[2009/04/28 18:47:29 | 00,000,905 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\RealPlayer.lnk
[2009/04/28 18:47:22 | 00,001,841 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Easy Internet Sign-up.lnk
[2009/04/28 18:45:58 | 00,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2009/04/28 18:42:55 | 00,012,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mouhid.sys
[2009/04/28 18:42:48 | 00,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidusb.sys
[2009/04/28 18:20:00 | 00,024,360 | R— | C] (America Online) – C:\WINDOWS\System32\drivers\ATWPKT2.SYS
[2009/04/28 17:12:37 | 30,401,112 | —- | C] (Logitech, Inc.) – C:\DOCUME~1\COMPAQ~1\Desktop\qc1150.exe
[2009/04/28 16:59:40 | 15,334,168 | —- | C] () – C:\DOCUME~1\COMPAQ~1\Desktop\ymsgr_setup(2).exe
[2009/04/28 16:58:16 | 15,334,168 | —- | C] () – C:\DOCUME~1\COMPAQ~1\Desktop\ymsgr_setup.exe
[2009/04/28 16:49:15 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/04/28 16:47:50 | 00,000,000 | —D | C] – C:\WINDOWS\setupupd
[2009/04/28 16:35:33 | 00,001,717 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\avast! Antivirus.lnk
[2009/04/28 16:35:29 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/04/28 16:35:28 | 00,051,376 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/04/28 16:35:28 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/04/28 16:35:26 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/04/28 16:35:22 | 00,114,768 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/04/28 16:35:22 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/04/28 16:35:22 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/04/28 16:35:22 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/04/28 16:35:04 | 01,256,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/04/28 16:35:04 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/04/28 16:31:26 | 00,308,160 | —- | C] (ALWIL Software) – C:\DOCUME~1\COMPAQ~1\Desktop\avast_home_setup(2).exe
[2009/04/28 16:29:37 | 00,308,160 | —- | C] (ALWIL Software) – C:\DOCUME~1\COMPAQ~1\Desktop\avast_home_setup.exe
[2009/04/28 15:53:40 | 00,001,715 | —- | C] () – C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\Compaq Organize.lnk
[2009/04/28 15:51:37 | 00,221,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmpns.dll
[2009/04/28 15:51:28 | 00,001,862 | RHS- | C] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_EL435AA-ABA SR1720NX NA610_YC_0Pres_QMXF602_E61NAheRED1_48_IAmberine M_SASUSTek Computer INC._V1.03_B3.13_T051115_WXH2_L409_M447_J160_7AMD_8Sempron_91.99_#060224_N10EC81
39_Z11C10620_G10025954.MRK
[2009/04/28 15:51:26 | 46,824,2432 | -HS- | C] () – C:\hiberfil.sys
[2009/04/28 15:50:54 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2009/04/28 08:52:05 | 00,000,000 | —D | C] – C:\ComboFix
[2009/04/28 00:50:29 | 00,082,132 | —- | C] () – C:\VETlog.dmp
[2009/04/27 17:01:11 | 00,000,204 | —- | C] () – C:\xcrashdump.dat
[2009/04/26 11:58:20 | 05,037,946 | —- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\chinookwater.wmv
[2009/04/26 11:54:59 | 00,422,912 | —- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\MARS.pps
[2009/04/25 18:23:34 | 00,027,937 | —- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\Picture 12.jpg
[2009/04/25 01:18:45 | 00,005,515 | —- | C] () – C:\DOCUME~1\COMPAQ~1\Desktop\alltel_logo.jpg
[2009/04/24 22:15:06 | 00,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Application Data\pidle
[2009/04/21 18:39:25 | 01,123,734 | —- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\105-0547_IMG.jpg
[2009/04/17 17:11:29 | 01,585,664 | —- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\Red_Sea_Crossing1.pps
[2009/04/11 10:24:42 | 00,001,813 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Logitech QuickCam.lnk
[2009/04/08 19:13:08 | 02,747,663 | —- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\DumbBuck.wmv
[2009/04/07 22:43:36 | 00,118,954 | —- | C] () – C:\DOCUME~1\COMPAQ~1\Desktop\donald_duck_christmas_by_donald_duck-ringtone.mp3
[2009/04/07 22:41:30 | 00,000,000 | —D | C] – C:\Program Files\white boy stuff
[2009/04/07 22:40:31 | 00,000,000 | —D | C] – C:\DOCUME~1\ALLUSE~1\Documents\white boy stuff
[2009/04/07 22:40:21 | 00,000,022 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Documents\New Compressed (zipped) Folder (2).zip
[2009/04/07 22:40:13 | 00,000,022 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Documents\New Compressed (zipped) Folder.zip
[2009/04/05 21:45:08 | 02,059,120 | —- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\autoroute.wmv
[2009/04/05 10:24:19 | 02,973,357 | —- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\SomewhereinTexas.wmv
[2009/04/04 19:12:33 | 00,055,164 | —- | C] () – C:\DOCUME~1\COMPAQ~1\Desktop\application.pdf
[2009/04/04 01:53:58 | 00,030,369 | —- | C] () – C:\DOCUME~1\COMPAQ~1\My Documents\Picture 7.jpg
[2008/01/13 16:02:59 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/11/17 23:50:40 | 00,000,044 | —- | C] () – C:\WINDOWS\liveup.ini
[2006/11/10 11:43:21 | 00,000,214 | —- | C] () – C:\WINDOWS\HP_InstantSHareJPG.ini
[2006/05/31 13:08:59 | 00,000,000 | —- | C] () – C:\WINDOWS\PTWebCam.INI
[2006/05/31 13:05:06 | 00,000,029 | —- | C] () – C:\WINDOWS\Pt.dll
[2006/05/22 12:09:26 | 00,000,030 | —- | C] () – C:\WINDOWS\atid.ini
[2005/12/02 19:00:39 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/12/02 18:38:33 | 00,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2005/12/02 18:32:47 | 00,012,993 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/12/02 18:32:40 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/12/02 18:30:41 | 00,000,054 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/12/02 18:27:57 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/12/02 18:22:12 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/12/02 18:22:12 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/12/02 18:22:12 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/12/02 18:22:12 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/12/02 18:22:12 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/12/02 18:22:12 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/12/02 18:14:54 | 00,000,102 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/12/02 18:13:47 | 00,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2005/12/02 18:07:51 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/12/02 17:53:16 | 00,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/12/02 17:49:59 | 00,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/12/02 17:49:59 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/12/02 17:49:35 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/10/05 15:50:52 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/06/25 00:32:00 | 00,000,666 | —- | C] () – C:\WINDOWS\win.ini
[2005/06/24 17:26:26 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
[2004/06/16 00:38:02 | 00,000,592 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/08 01:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/05/02 09:52:28 | 00,502,272 | —- | M] (OldTimer Tools) – C:\DOCUME~1\COMPAQ~1\Desktop\OTListIt2.exe
[2009/05/02 09:51:02 | 00,267,612 | —- | M] () – C:\DOCUME~1\COMPAQ~1\Desktop\Rooter.exe
[2009/05/02 09:38:00 | 00,000,256 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2009/05/02 09:02:05 | 00,000,666 | —- | M] () – C:\WINDOWS\win.ini
[2009/05/01 20:31:04 | 00,000,246 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2009/05/01 20:07:19 | 00,003,649 | —- | M] () – C:\WINDOWS\viassary-hp.reg
[2009/05/01 20:07:08 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/01 20:07:00 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Compaq_Owner\Local Settings\desktop.ini
[2009/05/01 20:06:58 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/01 20:06:55 | 46,824,2432 | -HS- | M] () – C:\hiberfil.sys
[2009/04/30 19:45:58 | 02,245,632 | —- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\BCBSSaver.doc
[2009/04/30 04:40:33 | 00,382,022 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/30 04:40:33 | 00,053,640 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/30 04:40:31 | 00,441,626 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/30 03:25:56 | 00,179,448 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/30 03:19:07 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/28 18:47:48 | 00,001,063 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2009/04/28 18:46:56 | 00,000,213 | RHS- | M] () – C:\BOOT.BAK
[2009/04/28 18:43:28 | 00,000,231 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/28 17:15:07 | 30,401,112 | —- | M] (Logitech, Inc.) – C:\DOCUME~1\COMPAQ~1\Desktop\qc1150.exe
[2009/04/28 16:59:40 | 15,334,168 | —- | M] () – C:\DOCUME~1\COMPAQ~1\Desktop\ymsgr_setup(2).exe
[2009/04/28 16:59:34 | 15,334,168 | —- | M] () – C:\DOCUME~1\COMPAQ~1\Desktop\ymsgr_setup.exe
[2009/04/28 16:51:19 | 00,000,283 | RHS- | M] () – C:\boot.ini
[2009/04/28 16:45:54 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/28 16:35:33 | 00,001,717 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\avast! Antivirus.lnk
[2009/04/28 16:35:22 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/04/28 16:31:26 | 00,308,160 | —- | M] (ALWIL Software) – C:\DOCUME~1\COMPAQ~1\Desktop\avast_home_setup(2).exe
[2009/04/28 16:29:37 | 00,308,160 | —- | M] (ALWIL Software) – C:\DOCUME~1\COMPAQ~1\Desktop\avast_home_setup.exe
[2009/04/28 15:51:32 | 00,001,862 | RHS- | M] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_EL435AA-ABA SR1720NX NA610_YC_0Pres_QMXF602_E61NAheRED1_48_IAmberine M_SASUSTek Computer INC._V1.03_B3.13_T051115_WXH2_L409_M447_J160_7AMD_8Sempron_91.99_#060224_N10EC81
39_Z11C10620_G10025954.MRK
[2009/04/28 15:50:55 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2009/04/28 15:50:54 | 00,001,841 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Easy Internet Sign-up.lnk
[2009/04/28 01:05:50 | 00,082,132 | —- | M] () – C:\VETlog.dmp
[2009/04/27 21:22:32 | 00,000,204 | —- | M] () – C:\xcrashdump.dat
[2009/04/27 10:36:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/26 11:58:49 | 05,037,946 | —- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\chinookwater.wmv
[2009/04/26 11:55:03 | 00,422,912 | —- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\MARS.pps
[2009/04/25 17:37:34 | 00,027,937 | —- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\Picture 12.jpg
[2009/04/25 01:18:45 | 00,005,515 | —- | M] () – C:\DOCUME~1\COMPAQ~1\Desktop\alltel_logo.jpg
[2009/04/24 06:00:26 | 00,380,928 | -HS- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\Thumbs.db
[2009/04/21 18:39:32 | 01,123,734 | —- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\105-0547_IMG.jpg
[2009/04/20 20:37:01 | 00,001,038 | —- | M] () – C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\AOL Desktop.lnk
[2009/04/17 17:11:38 | 01,585,664 | —- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\Red_Sea_Crossing1.pps
[2009/04/11 10:24:43 | 00,001,813 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Logitech QuickCam.lnk
[2009/04/08 19:13:24 | 02,747,663 | —- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\DumbBuck.wmv
[2009/04/07 22:44:01 | 00,002,137 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\iTunes.lnk
[2009/04/07 22:43:38 | 00,118,954 | —- | M] () – C:\DOCUME~1\COMPAQ~1\Desktop\donald_duck_christmas_by_donald_duck-ringtone.mp3
[2009/04/07 22:40:21 | 00,000,022 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Documents\New Compressed (zipped) Folder (2).zip
[2009/04/07 22:40:13 | 00,000,022 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Documents\New Compressed (zipped) Folder.zip
[2009/04/05 21:45:20 | 02,059,120 | —- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\autoroute.wmv
[2009/04/05 10:24:36 | 02,973,357 | —- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\SomewhereinTexas.wmv
[2009/04/04 19:12:35 | 00,055,164 | —- | M] () – C:\DOCUME~1\COMPAQ~1\Desktop\application.pdf
[2009/04/04 01:52:45 | 00,030,369 | —- | M] () – C:\DOCUME~1\COMPAQ~1\My Documents\Picture 7.jpg

========== LOP Check ==========

[2005/12/02 18:46:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data
[2009/02/01 14:01:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2005/12/02 18:22:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/12/28 11:03:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/12/28 10:46:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2007/11/29 18:58:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2008/08/31 12:46:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/08/31 12:58:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2007/04/05 23:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2008/06/07 11:29:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avira
[2007/08/06 18:02:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2009/02/08 22:06:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CardPlayer
[2008/01/26 10:34:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\comodo
[2007/06/08 08:53:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2006/02/25 21:31:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2005/12/02 18:14:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2005/12/02 18:30:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2008/01/24 21:50:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2007/12/05 02:41:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Leapfrog
[2009/04/11 10:24:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2008/05/09 19:35:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logitech
[2007/11/29 19:02:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macromedia
[2008/05/31 19:51:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/03/14 16:10:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2007/03/14 12:50:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\mcafee.com personal firewall
[2008/10/25 16:06:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2008/10/25 15:55:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microgaming
[2005/12/02 18:27:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/03/29 21:47:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2006/02/23 22:42:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2006/02/23 22:43:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2005/12/02 17:54:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2005/12/02 18:10:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2008/01/26 10:42:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/12/24 00:06:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/04/28 16:45:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/02/15 00:52:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/04/09 00:18:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Transparent
[2006/09/24 23:02:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2008/01/28 00:38:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/04/03 23:04:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2007/03/04 00:05:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/09/21 19:00:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2008/12/24 06:33:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2008/12/25 01:38:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/04/28 15:52:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data
[2008/12/28 11:00:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\acccore
[2008/11/23 10:52:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Adobe
[2007/02/13 22:49:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\AdobeUM
[2007/11/29 19:03:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\AOL
[2008/09/28 14:50:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Apple Computer
[2007/04/05 22:35:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\AVG7
[2008/01/26 10:25:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Comodo
[2007/06/24 14:55:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\GetRightToGo
[2007/03/28 16:36:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Google
[2007/09/10 19:47:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Help
[2006/04/23 15:15:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\HP
[2006/02/25 21:08:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\HPQ
[2005/07/13 11:48:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Identities
[2006/11/10 11:52:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Image Zone Express
[2008/11/09 02:16:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\InstallShield
[2006/11/28 02:00:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\InterVideo
[2005/12/02 18:30:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Intuit
[2007/01/09 22:40:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Leadertech
[2008/12/07 00:33:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\LimeWire
[2006/12/26 22:52:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia
[2008/01/26 08:21:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes
[2007/03/14 11:38:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\McAfee.com Personal Firewall
[2008/12/23 13:58:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Microgaming
[2009/04/28 15:52:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft
[2006/05/30 22:51:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Motive
[2008/12/28 10:46:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla
[2008/06/15 08:48:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\MSNInstaller
[2007/04/01 12:13:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\MySpace
[2009/01/14 22:40:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\OpenOffice.org
[2007/06/09 17:40:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\OpenOffice.org2
[2008/01/25 21:25:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Opera
[2009/04/24 22:29:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\pidle
[2006/04/24 11:51:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\PlayFirst
[2008/12/23 19:05:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Pokerari
[2009/04/28 15:52:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Real
[2009/03/09 22:09:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\SecondLife
[2008/08/22 19:46:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Sibelius Software
[2007/01/09 22:41:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Sonic
[2006/03/11 00:53:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Sun
[2008/12/24 00:06:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\SUPERAntiSpyware.com
[2009/04/28 15:52:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Symantec
[2008/01/27 17:45:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Talkback
[2008/01/18 20:26:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Uniblue
[2007/02/08 08:47:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint
[2008/11/09 02:25:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\VTExtra
[2007/03/04 21:00:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\WildTangent
[2009/01/26 10:20:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\WinBatch
[2008/01/26 10:53:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\WinPatrol
[2008/01/15 08:29:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\Yahoo!
[2006/02/23 22:43:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Compaq_Owner\Application Data\You've Got Pictures Screensaver
[2007/05/07 19:45:31 | 00,000,584 | —- | M] () – C:\WINDOWS\Tasks\AOL One-click Fixes.job
[2009/04/27 10:36:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/05/02 09:38:00 | 00,000,256 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2004/08/04 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/28 15:50:55 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Easy Internet Sign-up.job
[2009/05/01 20:07:08 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BB5259D1
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8CEFE51A
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:44DAF2F1
< End of report >

OTListIt Extras logfile created on: 5/2/2009 9:54:27 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.3 Folder = C:\Documents and Settings\Compaq_Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

446.48 Mb Total Physical Memory | 85.54 Mb Available Physical Memory | 19.16% Memory free
1.03 Gb Paging File | 0.58 Gb Available in Paging File | 56.31% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.07 Gb Total Space | 121.35 Gb Free Space | 85.42% Space Free | Partition Type: NTFS
Drive D: | 6.96 Gb Total Space | 1.19 Gb Free Space | 17.04% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-27E1513D96
Current User Name: Compaq_Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe:*:Enabled:Compaq Connections (Hewlett-Packard)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe:*:Enabled:Compaq Connections (Hewlett-Packard)
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink File not found
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpace Instant Messenger ()
C:\Program Files\AOL 9.1\waol.exe:*:Enabled:AOL Software (AOL, LLC.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{382E94C0-6E22-44e4-B003-8EB31DFE296F}" = cp_LightScribeConfig
"{3912A629-0020-0005-3757-2FBA74D4DF0A}" = InterVideo WinDVD Player
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91477C6F-EC7C-4BFC-BBE1-E45908019DED}" = LightScribe 1.4.52.1
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{A01FC76F-CC09-4658-9E37-5C2F635EE708}" = Microsoft Office 2003 Edition 60 Days Trial Welcome Tour
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{C104580B-1C79-4d73-9BF0-CA0B184296A4}" = cp_LightScribePlugin
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = Compaq Organize
"{D7DBA21A-CDE5-42EC-BB1C-AE4B3E616B9A}_is1" = HP Support Overview
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"045C89A0-CA37-443C-8826-F750227DE69C" = Shooting Stars Pool from Compaq (remove only)
"05E21449-3BA3-42BF-BBDA-95205F4EA40A" = Polar Bowler from Compaq (remove only)
"0BD36D37-C5D7-4B96-B64A-CB2C3A82EC4D" = Zuma Deluxe from Compaq (remove only)
"29FF6D07-4A15-41F1-9D5E-E0F3A58012C6" = Bounce Symphony from Compaq (remove only)
"3330A279-CC39-4A17-AE19-DA464B26AD9A" = Polar Golfer from Compaq (remove only)
"3B3B73D1-DC4A-4780-B0E4-E823D08B3397" = 5 Card Slingo from Compaq (remove only)
"422C7575-C10D-4795-87FA-9972765379E6" = Mah Jong Quest from Compaq (remove only)
"52AEBC18-F252-4B0C-B3E1-724537D9F873" = Ricochet Lost Worlds from Compaq (remove only)
"53474592-01BC-4338-8647-FE350957D912" = Barnyard Invasion from Compaq (remove only)
"5AF1DD17-7B06-45EF-8592-2E524E458BAB" = Insaniquarium Deluxe from Compaq (remove only)
"63E4EC24-7173-4E1F-9C77-B4403CBCF91F" = Lemonade Tycoon 2 from Compaq (remove only)
"66195170-D19D-46C5-8FB7-8A4630071ADC" = Tradewinds from Compaq (remove only)
"75528D5F-DD82-402E-BA7C-045B7DC6A712" = Blasterball 2 from Compaq (remove only)
"85CF9BF3-1057-468C-962D-31BAABC6AC72" = FATE from Compaq (remove only)
"8D11F98B-4931-44F6-8FC6-971CCBBBB131" = Snowboard SuperJam from Compaq (remove only)
"9448DE42-C017-4A3E-A0BB-C50BF673E9E0" = Chuzzle Deluxe from Compaq (remove only)
"997DD523-B925-4C73-970B-C201E8F781AD" = AstroPop Deluxe from Compaq (remove only)
"9D7E7CDA-051E-4B0D-8CEE-58F41F449CF9" = Blasterball 2 Remix from Compaq (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems PCI-SV92PP Soft Modem
"AT&&T Yahoo! Messenger" = AT&T Yahoo! Messenger
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"BBCBAA5D-AC5A-4098-A53E-EC60A68F38F9" = Shrek 2 Ogre Bowler from Compaq (remove only)
"BBE9E0F3-11F7-4424-9905-8E0153E872C1" = Family Feud
"BFAF1EEC-E987-415B-BCB8-80CDB0BC6CDF" = Blackhawk Striker 2 from Compaq (remove only)
"C43D84CD-EBFC-48D3-A330-7868C8AD415A" = Crystal Maze from Compaq (remove only)
"C6D35CCA-3F9E-4B6E-A17F-409EE7379D6B" = Boggle Supreme from Compaq (remove only)
"Compaq Game Console" = Compaq Game Console and games
"D84AC71A-75E8-4709-8BA5-4B46EAC00C5E" = Bejeweled 2 Deluxe from Compaq (remove only)
"DE87FA96-7840-420C-86F9-33F3B7B3CED1" = Super Granny from Compaq (remove only)
"E1A0F769-A43A-4DDB-9F73-12791E453557" = Puzzle Express from Compaq (remove only)
"E618FC78-EE4F-4243-8409-078EB5E0B1F6" = Bookworm Deluxe from Compaq (remove only)
"F05A08BF-E600-4FBD-A53A-3D47296B1275" = Lexibox Deluxe from Compaq (remove only)
"F19E8CDF-5EFD-45E0-9FAF-66CBAE84B1D9" = Slingo Deluxe from Compaq (remove only)
"FA6A73EB-40AB-4B58-851D-3892B3C10EF6" = SCRABBLE from Compaq (remove only)
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HPOOVClient-5577497 Uninstaller" = Compaq Connections (remove only)
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2005b" = Microsoft Money 2005
"Netscape Browser" = Netscape Browser (remove only)
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"PS2" = PS2
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealPlayer 6.0" = RealPlayer
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/28/2009 6:07:42 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000
Description = Faulting application quickcam10.exe, version 10.0.0.1439, faulting
module quickcam10.exe, version 10.0.0.1439, fault address 0x0001d69a.

Error - 4/28/2009 6:18:44 PM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000
Description = Faulting application quickcam10.exe, version 10.0.0.1439, faulting
module quickcam10.exe, version 10.0.0.1439, fault address 0x0001d69a.

Error - 4/30/2009 12:01:50 AM | Computer Name = YOUR-27E1513D96 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3399, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 4/30/2009 5:36:35 AM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 4/30/2009 5:38:16 AM | Computer Name = YOUR-27E1513D96 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 4/30/2009 5:38:16 AM | Computer Name = YOUR-27E1513D96 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error
message: The referenced assembly is not installed on your system. .

Error - 4/30/2009 5:38:16 AM | Computer Name = YOUR-27E1513D96 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Common Files\AOL\Launch\aollaunch.exe.
Reference
error message: The operation completed successfully. .

Error - 4/30/2009 11:13:47 PM | Computer Name = YOUR-27E1513D96 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 4/30/2009 11:13:47 PM | Computer Name = YOUR-27E1513D96 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error
message: The referenced assembly is not installed on your system. .

Error - 4/30/2009 11:13:47 PM | Computer Name = YOUR-27E1513D96 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Common Files\AOL\Launch\aollaunch.exe.
Reference
error message: The operation completed successfully. .

Error - 5/1/2009 9:07:13 PM | Computer Name = YOUR-27E1513D96 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 5/1/2009 9:07:13 PM | Computer Name = YOUR-27E1513D96 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error
message: The referenced assembly is not installed on your system. .

Error - 5/1/2009 9:07:13 PM | Computer Name = YOUR-27E1513D96 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Common Files\AOL\Launch\aollaunch.exe.
Reference
error message: The operation completed successfully. .


< End of report >
Hi again that does not look to bad although you have a few outdated programmes plus the remnants of Norton which should be removed. What problems are you experiencing ?
Thank you, I guess I'm just wondering if the virus is gone, and I have very little memory on my pc. I went to my control panel and removed all the Norton I could find. The system restore brought Norton back I guess, (It came with the pc when new), because I've never used it. Thank you.
Lets get you tidied up now :)

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.

If you want to use Java then get the new version details below.
To remove all of Norton download and run the Norton Removal Tool
On completion of my tool removal download and run Auslogics disc defragmenter


Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..Run OTListit and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u13-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u13-windows-i586-p.exe and select "Run as an Administrator.")

XP
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SuperAntispyware Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI