This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] nar.vbs virus removal help

52 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is my first time using this forum, so please let me know if I do something incorrectly.

My thumb drive has been infected at least twice with the nar.vbs virus (detected on a work PC running eTrust a/v). I believe it is coming from my HP notebook. I have also had my external hard drive plugged into my notebook for backups and I am concerned that may have the virus as well. ESet nod32 and a Kaspersky online scan failed to detect any viruses, however the registry has the following:

C:/windows/system32/RunDLL32.exe Shell32.DLL, Shellexec_RunDLL wscript.exe nar.vbs

I use Windows Defender and eSet Nod32. Also, while trying to download and install Ad-Aware, I mistakenly installed Adaware Professional, which seems to be malware (at least as detected by Spybot). Windows Defender tried to save me from myself, but I clicked through the warning…STUPID…I KNOW!!!!

I am also worried because I have used my thumb drive in several PC's at work. eTrust A/V detected the virus on my thumb drive twice and stopped any infection on my main PC, but other PC's not using eTrust never gave any warnings. I worry they are infected as well.

Help is greatly appreciated!!



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:33:08 PM, on 7/8/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files (x86)\Windows Live\Toolbar\wltuser.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - (no file)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.8.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://wavonline.webex.com/client/T25L/nbr/ieatgpc1.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1c9e63c4b66d350) (gupdate1c9e63c4b66d350) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files (x86)\Kodak\AiO\Center\EKDiscovery.exe
O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files (x86)\Kodak\AiO\center\KodakSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 15868 bytes
Malwarebytes' Anti-Malware 1.38 Database version: 2395 Windows 6.0.6001 Service Pack 1 7/8/2009 4:09:11 PM mbam-log-2009-07-08 (16-09-11).txt Scan type: Quick Scan Objects scanned: 83348 Time elapsed: 2 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 1 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Program Files (x86)\Adware Professional (Rogue.AdwareProfessional) -> Quarantined and deleted successfully. Files Infected: c:\program files (x86)\adware professional\noadware4_070809.na (Rogue.AdwareProfessional) -> Quarantined and deleted successfully. c:\program files (x86)\adware professional\nutilities.dll (Rogue.AdwareProfessional) -> Quarantined and deleted successfully.
Here is the new Hijack This log after running MAM. Seems my Adaware Professional malware was taken care of by MAM.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:23:02 PM, on 7/8/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files (x86)\Windows Live\Toolbar\wltuser.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - (no file)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.8.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://wavonline.webex.com/client/T25L/nbr/ieatgpc1.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1c9e63c4b66d350) (gupdate1c9e63c4b66d350) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files (x86)\Kodak\AiO\Center\EKDiscovery.exe
O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files (x86)\Kodak\AiO\center\KodakSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 15877 bytes
Hi,

Sorry, not clear on which PC you are wanting checked - your notebook? How many PC's are involved?

Lets check them one by one.

which is the computer running the 64bit system?

First - run this program. - make sure your external hard drive is plugged in as well as the infected thumbdrive (it would be a good idea to reformat that)

Download Flash_Disinfector.exe from HERE and save it to your desktop.

  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.

NEXT:

Run this program on the computer with the 64bit system:

(we'll call this computer #1)

Download OTSto your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Check the box that says 64 bit
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.
Sorry my first post was confusing.

Goal #1 - clean personal HP notebook.
Goal #2 - clean flash drive and two external hard drives.

I will worry about work PC's later.

Before starting, I plugged in both external hard drives and my flash drive. I ran the flash_disinfector from the desktop and it seemed to work fine (if finished VERY quickly). I did get a message that said the program may not have installed correctly, but I choose the option that it did install correctly (the scan ran and said finished.)

Here is the OTS scan results.

OTS logfile created on: 7/12/2009 11:11:10 AM - Run 1
OTS by OldTimer - Version 3.0.9.3	 Folder = C:\Users\Eric\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
4.00 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 66.43% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.13 Gb Total Space | 190.63 Gb Free Space | 66.86% Space Free | Partition Type: NTFS
Drive D: | 12.95 Gb Total Space | 1.78 Gb Free Space | 13.77% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 14.92 Gb Total Space | 6.35 Gb Free Space | 42.53% Space Free | Partition Type: FAT32
Drive G: | 298.09 Gb Total Space | 262.09 Gb Free Space | 87.92% Space Free | Partition Type: NTFS
Drive H: | 465.76 Gb Total Space | 334.64 Gb Free Space | 71.85% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
 
Computer Name: SCOTT-NOTEBOOK
Current User Name: Eric
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
 
[Processes - Safe List]
aluschedulersvc.exe -> c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe -> [2007/08/23 14:35:00 | 00,243,064 | —- | M] (Symantec Corporation)
applemobiledeviceservice.exe -> C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/05/29 13:41:26 | 00,144,712 | —- | M] (Apple Inc.)
ekdiscovery.exe -> C:\Program Files (x86)\Kodak\AiO\Center\EKDiscovery.exe -> [2009/05/04 12:15:26 | 00,279,960 | —- | M] (Eastman Kodak Company)
ekrn.exe -> C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -> [2008/03/13 16:49:56 | 00,472,320 | —- | M] (ESET)
googlequicksearchbox.exe -> C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe -> [2009/04/15 08:02:29 | 00,068,592 | —- | M] (Google Inc.)
googletoolbarnotifier.exe -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2009/06/07 09:45:59 | 00,039,408 | —- | M] (Google Inc.)
hpqsrmon.exe -> C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe -> [2008/06/02 02:55:22 | 00,080,896 | —- | M] (Hewlett-Packard)
hpqtoaster.exe -> C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe -> [2007/05/16 13:43:06 | 00,677,432 | R— | M] ()
hpqwmiex.exe -> C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe -> [2006/05/02 18:41:28 | 00,135,168 | —- | M] (Hewlett-Packard Development Company, L.P.)
hpswp_clipbook.exe -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe -> [2008/10/15 14:55:10 | 00,116,016 | —- | M] (Hewlett-Packard Co.)
hpwamain.exe -> C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe -> [2007/09/13 11:47:52 | 00,480,560 | —- | M] (Hewlett-Packard Development Company, L.P.)
hpwuschd2.exe -> C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe -> [2007/05/08 16:24:20 | 00,054,840 | —- | M] (Hewlett-Packard)
iaantmon.exe -> C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -> [2008/04/15 17:54:42 | 00,354,840 | —- | M] (Intel Corporation)
ieuser.exe -> C:\Program Files (x86)\Internet Explorer\ieuser.exe -> [2008/01/20 21:50:38 | 00,299,520 | —- | M] (Microsoft Corporation)
ipodservice.exe -> C:\Program Files (x86)\iPod\bin\iPodService.exe -> [2009/05/30 12:30:20 | 00,541,992 | —- | M] (Apple Inc.)
ituneshelper.exe -> C:\Program Files (x86)\iTunes\iTunesHelper.exe -> [2009/05/30 12:30:26 | 00,292,136 | —- | M] (Apple Inc.)
jusched.exe -> C:\Program Files (x86)\Java\jre6\bin\jusched.exe -> [2009/04/15 05:41:20 | 00,148,888 | —- | M] (Sun Microsystems, Inc.)
kodaksvc.exe -> C:\Program Files (x86)\Kodak\AiO\center\KodakSvc.exe -> [2009/04/17 12:08:26 | 00,032,768 | —- | M] (Eastman Kodak Company)
lightscribecontrolpanel.exe -> C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -> [2009/03/17 13:17:04 | 02,387,968 | —- | M] (Hewlett-Packard Company)
lssrvc.exe -> C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -> [2009/03/17 13:25:40 | 00,073,728 | —- | M] (Hewlett-Packard Company)
mdnsresponder.exe -> C:\Program Files (x86)\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.)
ots.exe -> C:\Users\Eric\Desktop\OTS.exe -> [2009/07/12 11:07:20 | 00,513,536 | —- | M] (OldTimer Tools)
qpcapsvc.exe -> C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe -> [2007/12/19 21:28:34 | 00,271,760 | —- | M] ()
qpservice.exe -> C:\Program Files (x86)\HP\QuickPlay\QPService.exe -> [2007/12/19 21:27:50 | 00,468,264 | —- | M] (CyberLink Corp.)
richvideo.exe -> C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe -> [2007/01/09 05:25:30 | 00,272,024 | —- | M] ()
schedhlp.exe -> C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe -> [2009/01/20 23:34:36 | 00,377,232 | —- | M] (Acronis)
sdwinsec.exe -> C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -> [2009/01/26 15:31:10 | 01,153,368 | —- | M] (Safer Networking Ltd.)
seaport.exe -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -> [2009/05/19 11:36:18 | 00,240,512 | —- | M] (Microsoft Corporation)
timountermonitor.exe -> C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe -> [2009/01/20 23:45:00 | 00,960,536 | —- | M] (Acronis)
trueimagemonitor.exe -> C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe -> [2009/01/20 23:06:10 | 04,359,280 | —- | M] (Acronis)
wifimsg.exe -> C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe -> [2007/01/08 18:53:06 | 00,311,296 | —- | M] (Hewlett-Packard Development Company, L.P.)
 
[Win32 Services - Safe List]
64bit-(EhttpSrv) Eset HTTP Server [Win32_Own | On_Demand | Stopped] -> C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -> [2008/03/13 16:55:30 | 00,021,760 | —- | M] (ESET)
64bit-(ekrn) Eset Service [Win32_Own | Auto | Running] -> C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -> [2008/03/13 16:49:56 | 00,472,320 | —- | M] (ESET)
64bit-(WinDefend) Windows Defender [Win32_Shared | Auto | Running] -> C:\Program Files\Windows Defender\mpsvc.dll -> [2008/01/20 21:47:32 | 00,383,544 | —- | M] (Microsoft Corporation)
64bit-(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | Auto | Running] -> C:\Program Files\Windows Media Player\wmpnetwk.exe -> [2008/01/20 21:52:15 | 01,216,000 | —- | M] (Microsoft Corporation)
(AcrSch2Svc) Acronis Scheduler2 Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -> [2009/01/20 23:37:46 | 00,828,856 | —- | M] (Acronis)
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/05/29 13:41:26 | 00,144,712 | —- | M] (Apple Inc.)
(Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Win32_Own | Auto | Running] -> c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe -> [2007/08/23 14:35:00 | 00,243,064 | —- | M] (Symantec Corporation)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.)
(clr_optimization_v2.0.50727_32) Microsoft .NET Framework NGEN v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/07/27 13:03:13 | 00,069,632 | —- | M] (Microsoft Corporation)
(clr_optimization_v2.0.50727_64) Microsoft .NET Framework NGEN v2.0.50727_X64 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -> [2008/07/27 13:01:49 | 00,093,184 | —- | M] (Microsoft Corporation)
(Com4Qlb) Com4Qlb [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -> [2007/03/05 12:30:06 | 00,110,592 | —- | M] (Hewlett-Packard Development Company, L.P.)
(ehRecvr) Windows Media Center Receiver Service [Win32_Own | On_Demand | Stopped] -> C:\Windows\ehome\ehRecvr.exe -> [2008/01/20 21:51:36 | 00,344,064 | —- | M] (Microsoft Corporation)
(ehSched) Windows Media Center Scheduler Service [Win32_Own | On_Demand | Stopped] -> C:\Windows\ehome\ehsched.exe -> [2008/01/20 21:51:36 | 00,153,600 | —- | M] (Microsoft Corporation)
(ehstart) Windows Media Center Service Launcher [Win32_Shared | Auto | Stopped] -> C:\Windows\ehome\ehstart.dll -> [2006/11/02 10:03:48 | 00,015,360 | —- | M] (Microsoft Corporation)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe -> [2008/06/19 20:17:12 | 00,046,104 | —- | M] (Microsoft Corporation)
(fsssvc) Windows Live Family Safety [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe -> [2009/02/06 18:08:58 | 00,533,360 | —- | M] (Microsoft Corporation)
(GameConsoleService) GameConsoleService [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe -> [2007/07/23 18:33:06 | 00,181,800 | —- | M] (WildTangent, Inc.)
(gupdate1c9e63c4b66d350) Google Update Service (gupdate1c9e63c4b66d350) [Win32_Own | Auto | Stopped] -> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -> [2009/06/05 19:18:09 | 00,133,104 | —- | M] (Google Inc.)
(gusvc) Google Software Updater [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2009/06/07 09:45:55 | 00,182,768 | —- | M] (Google)
(HP Health Check Service) HP Health Check Service [Win32_Own | Auto | Running] -> c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe -> [2008/10/09 07:56:48 | 00,094,208 | —- | M] (Hewlett-Packard)
(hpqwmiex) hpqwmiex [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe -> [2006/05/02 18:41:28 | 00,135,168 | —- | M] (Hewlett-Packard Development Company, L.P.)
(IAANTMON) Intel(R) Matrix Storage Event Monitor [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -> [2008/04/15 17:54:42 | 00,354,840 | —- | M] (Intel Corporation)
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -> [2005/04/04 00:41:10 | 00,069,632 | —- | M] (Macrovision Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -> [2008/06/19 20:16:53 | 00,859,648 | —- | M] (Microsoft Corporation)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> C:\Program Files (x86)\iPod\bin\iPodService.exe -> [2009/05/30 12:30:20 | 00,541,992 | —- | M] (Apple Inc.)
(KeyIso) CNG Key Isolation [Win32_Shared | On_Demand | Running] -> C:\Windows\SysWow64\keyiso.dll -> [2006/11/02 04:46:05 | 00,018,944 | —- | M] (Microsoft Corporation)
(Kodak AiO Network Discovery Service) Kodak AiO Network Discovery Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Kodak\AiO\Center\EKDiscovery.exe -> [2009/05/04 12:15:26 | 00,279,960 | —- | M] (Eastman Kodak Company)
(KodakSvc) Kodak AiO Device Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Kodak\AiO\center\KodakSvc.exe -> [2009/04/17 12:08:26 | 00,032,768 | —- | M] (Eastman Kodak Company)
(LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -> [2009/03/17 13:25:40 | 00,073,728 | —- | M] (Hewlett-Packard Company)
(LiveUpdate) LiveUpdate [Win32_Shared | On_Demand | Stopped] -> c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE -> [2007/08/23 14:35:00 | 03,192,184 | —- | M] (Symantec Corporation)
(MSDTC) Distributed Transaction Coordinator [Win32_Own | Unknown | Stopped] -> C:\Windows\SysWow64\Msdtc -> [2006/11/02 08:34:14 | 00,000,000 | —D | M]
(Netlogon) Netlogon [Win32_Shared | On_Demand | Stopped] -> C:\Windows\SysWow64\netlogon.dll -> [2008/01/20 21:48:28 | 00,592,384 | —- | M] (Microsoft Corporation)
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2008/11/04 01:06:28 | 00,441,712 | —- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 17:03:08 | 00,145,184 | —- | M] (Microsoft Corporation)
(QPCapSvc) QuickPlay Background Capture Service (QBCS) [Win32_Own | Auto | Running] -> C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe -> [2007/12/19 21:28:34 | 00,271,760 | —- | M] ()
(QPSched) QuickPlay Task Scheduler (QTS) [Win32_Own | Auto | Stopped] -> C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe -> [2007/12/19 21:28:34 | 00,112,016 | —- | M] ()
(RichVideo) Cyberlink RichVideo Service(CRVS) [Win32_Own | Auto | Running] -> C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe -> [2007/01/09 05:25:30 | 00,272,024 | —- | M] ()
(SBSDWSCService) SBSD Security Center Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -> [2009/01/26 15:31:10 | 01,153,368 | —- | M] (Safer Networking Ltd.)
(SeaPort) SeaPort [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -> [2009/05/19 11:36:18 | 00,240,512 | —- | M] (Microsoft Corporation)
(vds) Virtual Disk [Win32_Own | On_Demand | Stopped] -> C:\Windows\SysWow64\Wbem\vds.mof -> [2006/11/02 01:35:15 | 00,060,994 | —- | M] ()
(VSS) Volume Shadow Copy [Win32_Own | On_Demand | Stopped] -> C:\Windows\SysWow64\Wbem\vss.mof -> [2006/11/02 01:35:15 | 00,055,846 | —- | M] ()
 
[Driver Services - Safe List]
64bit-(BCM43XV) Broadcom Extensible 802.11 Network Adapter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\bcmwl664.sys -> [2006/10/06 21:13:22 | 00,550,912 | —- | M] ()
64bit-(CmBatt) Microsoft ACPI Control Method Battery Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\CmBatt.sys -> [2008/01/20 21:46:51 | 00,017,792 | —- | M] ()
64bit-(eamon) eamon [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\eamon.sys -> [2008/03/13 16:43:44 | 00,045,064 | —- | M] ()
64bit-(easdrv) easdrv [Kernel | System | Running] -> C:\Windows\SysNative\DRIVERS\easdrv.sys -> [2008/03/13 16:44:38 | 00,026,632 | —- | M] ()
64bit-(epfwtdir) epfwtdir [Kernel | System | Running] -> C:\Windows\SysNative\DRIVERS\epfwtdir.sys -> [2008/03/13 16:52:40 | 00,038,408 | —- | M] ()
64bit-(fssfltr) fssfltr [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\fssfltr.sys -> [2009/02/06 18:42:12 | 00,061,808 | —- | M] ()
64bit-(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -> [2009/03/19 16:34:18 | 00,029,544 | —- | M] ()
64bit-(HdAudAddService) Microsoft 1.1 UAA Function Driver for High Definition Audio Service [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\HdAudio.sys -> [2006/11/02 00:28:10 | 00,273,920 | —- | M] ()
64bit-(HpqKbFiltr) HpqKbFilter Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys -> [2007/06/18 19:13:12 | 00,018,432 | —- | M] ()
64bit-(HpqRemHid) HP Remote Control HID Device [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\HpqRemHid.sys -> [2007/07/11 12:30:34 | 00,009,088 | —- | M] ()
64bit-(HSFHWAZL) HSFHWAZL [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS -> [2008/01/20 21:46:57 | 00,286,720 | —- | M] ()
64bit-(HSF_DPV) HSF_DPV [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS -> [2008/01/20 21:46:57 | 01,523,712 | —- | M] ()
64bit-(iaStor) Intel AHCI Controller [Kernel | Boot | Running] -> C:\Windows\SysNative\DRIVERS\iaStor.sys -> [2008/04/15 17:54:16 | 00,388,120 | —- | M] ()
64bit-(NETw3v64) Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 64 Bit [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\NETw3v64.sys -> [2008/01/20 21:46:57 | 03,154,432 | —- | M] ()
64bit-(NETw4v64) Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\NETw4v64.sys -> [2007/06/28 10:09:56 | 03,148,288 | —- | M] ()
64bit-(NETw5v64) Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\NETw5v64.sys -> [2008/11/17 15:50:30 | 04,751,360 | —- | M] ()
64bit-(NVENETFD) NVIDIA nForce Networking Controller Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\nvm60x64.sys -> [2006/10/09 21:09:03 | 00,742,696 | —- | M] ()
64bit-(rimmptsk) rimmptsk [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\rimmpx64.sys -> [2007/08/08 17:39:46 | 00,060,928 | —- | M] ()
64bit-(rimsptsk) rimsptsk [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\rimspx64.sys -> [2007/07/26 20:33:54 | 00,055,296 | —- | M] ()
64bit-(rismxdp) Ricoh xD-Picture Card Driver [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\rixdpx64.sys -> [2007/07/27 19:45:52 | 00,057,856 | —- | M] ()
64bit-(RTL8169) Realtek 8169 NT Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\Rtlh64.sys -> [2009/03/06 09:06:18 | 00,197,120 | —- | M] ()
64bit-(sdbus) sdbus [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\sdbus.sys -> [2008/01/20 21:46:55 | 00,111,104 | —- | M] ()
64bit-(smserial) smserial [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\smserial.sys -> [2007/01/17 08:48:30 | 01,455,616 | —- | M] ()
64bit-(snapman380) Acronis Snapshots Manager (Build 380) [Kernel | Boot | Running] -> C:\Windows\SysNative\DRIVERS\snman380.sys -> [2009/05/31 12:45:54 | 00,237,600 | —- | M] ()
64bit-(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\SynTP.sys -> [2008/06/20 16:37:42 | 00,325,680 | —- | M] ()
64bit-(tdrpman174) Acronis Try&Decide and Restore Points filter (build 174) [Kernel | Boot | Running] -> C:\Windows\SysNative\DRIVERS\tdrpm174.sys -> [2009/05/31 12:46:09 | 01,581,088 | —- | M] ()
64bit-(tifsfilter) Acronis True Image FS Filter [File_System | Auto | Running] -> C:\Windows\SysNative\DRIVERS\tifsfilt.sys -> [2009/05/31 12:45:57 | 00,083,488 | —- | M] ()
64bit-(timounter) Acronis True Image Backup Archive Explorer [Kernel | Boot | Running] -> C:\Windows\SysNative\DRIVERS\timntr.sys -> [2009/05/31 12:45:57 | 00,880,160 | —- | M] ()
64bit-(USBAAPL64) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\Drivers\usbaapl64.sys -> [2009/05/29 13:36:16 | 00,048,640 | —- | M] ()
64bit-(usbvideo) USB Video Device (WDM) [Kernel | On_Demand | Running] -> C:\Windows\SysNative\Drivers\usbvideo.sys -> [2008/01/20 21:47:27 | 00,168,704 | —- | M] ()
64bit-(winachsf) winachsf [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS -> [2008/01/20 21:46:57 | 00,724,480 | —- | M] ()
64bit-(WpdUsb) WpdUsb [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\wpdusb.sys -> [2008/01/20 21:47:28 | 00,046,080 | —- | M] ()
(mpsdrv) Windows Firewall Authorization Driver [Kernel | On_Demand | Running] -> C:\Windows\SysWow64\Wbem\mpsdrv.mof -> [2006/09/18 16:35:23 | 00,001,088 | —- | M] ()
(Tcpip) TCP/IP Protocol Driver [Kernel | Boot | Running] -> C:\Windows\SysWow64\Wbem\tcpip.mof -> [2006/09/18 16:36:40 | 00,003,066 | —- | M] ()
 
[Registry - Safe List]
< 64bit-Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  [binary data] -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop -> 
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  [binary data] -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop -> 
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> 
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> 
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\] > -> -> 
HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\: Main\\"Default_Page_URL" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop -> 
HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\: Main\\"Local Page" -> \blank.htm -> 
HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\: Main\\"Start Page" -> http://www.google.com/ -> 
HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\: Main\\"StartPageCache" -> 1 -> 
HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\: "ProxyEnable" -> 0 -> 
< FireFox Settings [Prefs.js] > -> C:\Users\Eric\AppData\Roaming\Mozilla\FireFox\Profiles\i8amx185.default\prefs.js -> 
browser.search.defaultenginename -> "Google" ->
browser.search.defaulturl -> "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=" ->
browser.search.selectedEngine -> "Google" ->
browser.startup.homepage -> "http://go.microsoft.com/fwlink/?LinkId=69157" ->
extensions.enabledItems -> {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20090119W ->
extensions.enabledItems -> {20a82645-c095-46ed-80e3-08825760534b}:1.1 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions ->  -> 
HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/06/27 10:28:46 | 00,000,000 | —D | M]
HKLM\software\mozilla\Firefox\Extensions\\[removed] -> C:\PROGRAM FILES (X86)\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON2 [C:\PROGRAM FILES (X86)\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON2] -> [2009/04/15 07:07:31 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions ->  -> 
HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS] -> [2009/06/24 07:36:45 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS] -> [2009/06/24 07:36:45 | 00,000,000 | —D | M]
< FireFox Extensions [User Folders] > -> 
 -> C:\Users\Eric\AppData\Roaming\mozilla\Extensions -> [2009/04/16 01:23:01 | 00,000,000 | —D | M]
 -> C:\Users\Eric\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2009/04/16 01:23:01 | 00,000,000 | —D | M]
 -> C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\i8amx185.default\extensions -> [2009/07/12 07:47:19 | 00,097,775 | —- | M] ()
 -> C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\i8amx185.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} -> [2009/07/12 07:47:19 | 00,097,775 | —- | M] ()
 -> C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\i8amx185.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} -> [2009/07/12 07:47:19 | 00,097,775 | —- | M] ()
< FireFox Extensions [Program Folders] > -> 
 -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\extensions -> [2009/06/24 07:36:45 | 09,777,144 | —- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/06/24 07:36:45 | 09,777,144 | —- | M] (Mozilla Foundation)
< FireFox Components [Program Folders] > -> 
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components\ -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components -> [2009/06/24 07:36:45 | 00,000,000 | —D | M]
browserdirprovider.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009/06/24 07:36:25 | 00,023,032 | —- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009/06/24 07:36:25 | 00,134,648 | —- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > -> 
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\ -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins -> [2009/06/24 07:36:45 | 00,000,000 | —D | M]
npnul32.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009/06/24 07:36:30 | 00,065,528 | —- | M] (mozilla.org)
npqtplugin.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin.dll -> [2009/06/03 18:23:53 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin2.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin2.dll -> [2009/06/03 18:23:53 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin3.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin3.dll -> [2009/06/03 18:23:53 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin4.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin4.dll -> [2009/06/03 18:23:53 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin5.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin5.dll -> [2009/06/03 18:23:53 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin6.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin6.dll -> [2009/06/03 18:23:53 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin7.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin7.dll -> [2009/06/03 18:23:53 | 00,143,360 | —- | M] (Apple Inc.)
QuickTimePlugin.class -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\QuickTimePlugin.cla -> [2009/06/03 18:23:53 | 00,004,208 | —- | M] ()
< FireFox SearchPlugins [Program Folders] > -> 
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins -> [2009/06/24 07:36:45 | 00,000,000 | —D | M]
amazondotcom.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\amazondotcom.xml -> [2009/06/24 07:36:32 | 00,001,394 | —- | M] ()
answers.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\answers.xml -> [2009/06/24 07:36:32 | 00,002,193 | —- | M] ()
creativecommons.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\creativecommons.xml -> [2009/06/24 07:36:32 | 00,001,534 | —- | M] ()
eBay.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\eBay.xml -> [2009/06/24 07:36:32 | 00,002,343 | —- | M] ()
google.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\google.xml -> [2009/06/24 07:36:32 | 00,001,706 | —- | M] ()
wikipedia.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\wikipedia.xml -> [2009/06/24 07:36:32 | 00,001,178 | —- | M] ()
yahoo.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\yahoo.xml -> [2009/06/24 07:36:32 | 00,000,792 | —- | M] ()
< HOSTS File > (761 bytes and 20 lines) -> C:\Windows\SysNative\Drivers\etc\hosts -> 
Reset Hosts
127.0.0.1	   localhost
::1			 localhost
< 64bit-BHO's [HKEY_LOCAL_MACHINE] > -> 64bit-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} [HKLM] -> C:\Program Files\Windows Live\Family Safety\fssbho.dll [Windows Live Family Safety Browser Helper Class] -> [2009/02/06 18:42:14 | 00,068,976 | —- | M] (Microsoft Corporation)
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 23:08:42 | 00,062,080 | —- | M] (Adobe Systems Incorporated)
{22BF413B-C6D2-4d91-82A9-A0F997BA588C} [HKLM] -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [Skype add-on (mastermind)] -> [2009/06/02 11:56:14 | 01,082,880 | —- | M] (Skype Technologies S.A.)
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> [2009/01/26 15:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} [HKLM] -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [Search Helper] -> [2009/05/19 11:36:18 | 00,137,600 | —- | M] (Microsoft Corporation)
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2009/01/22 15:41:30 | 00,408,448 | —- | M] (Microsoft Corporation)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar Helper] -> [2009/06/07 09:45:48 | 00,259,696 | —- | M] (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll [Google Toolbar Notifier BHO] -> [2009/06/29 06:50:43 | 00,669,168 | —- | M] (Google Inc.)
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [Google Dictionary Compression sdch] -> [2009/06/07 09:45:48 | 00,470,512 | —- | M] (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [Java™ Plug-In 2 SSV Helper] -> [2009/04/15 05:41:20 | 00,035,840 | —- | M] (Sun Microsystems, Inc.)
{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} [HKLM] -> C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [Windows Live Toolbar Helper] -> [2009/02/06 18:17:46 | 01,068,904 | —- | M] (Microsoft Corporation)
{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} [HKLM] -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [HP Smart BHO Class] -> [2008/10/15 14:44:30 | 00,505,136 | —- | M] (Hewlett-Packard Co.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{21FA44EF-376D-4D53-9B0F-8A89D3229068}" [HKLM] -> C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [&Windows Live Toolbar] -> [2009/02/06 18:17:46 | 01,068,904 | —- | M] (Microsoft Corporation)
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar] -> [2009/06/07 09:45:48 | 00,259,696 | —- | M] (Google Inc.)
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{21FA44EF-376D-4D53-9B0F-8A89D3229068}" [HKLM] -> C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [&Windows Live Toolbar] -> [2009/02/06 18:17:46 | 01,068,904 | —- | M] (Microsoft Corporation)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar] -> [2009/06/07 09:45:48 | 00,259,696 | —- | M] (Google Inc.)
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{21FA44EF-376D-4D53-9B0F-8A89D3229068}" [HKLM] -> C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [&Windows Live Toolbar] -> [2009/02/06 18:17:46 | 01,068,904 | —- | M] (Microsoft Corporation)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar] -> [2009/06/07 09:45:48 | 00,259,696 | —- | M] (Google Inc.)
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\] > -> HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{21FA44EF-376D-4D53-9B0F-8A89D3229068}" [HKLM] -> C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [&Windows Live Toolbar] -> [2009/02/06 18:17:46 | 01,068,904 | —- | M] (Microsoft Corporation)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar] -> [2009/06/07 09:45:48 | 00,259,696 | —- | M] (Google Inc.)
< 64bit-Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Acronis Scheduler2 Service" -> C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe ["C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"] -> [2009/01/20 23:34:36 | 00,377,232 | —- | M] (Acronis)
"egui" -> C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe ["C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice] -> [2008/03/13 16:48:32 | 01,908,480 | —- | M] (ESET)
"EKIJ5000StatusMonitor" -> C:\Windows\SysNative\spool\DRIVERS\x64\3\EKIJ5000MUI.exe [C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe] -> [2009/04/07 17:39:28 | 01,832,960 | —- | M] ()
"HP Health Check Scheduler" ->  [[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe] -> File not found
"IAAnotif" -> C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe ["C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe"] -> [2008/04/15 17:54:40 | 00,178,712 | —- | M] (Intel Corporation)
"NvCplDaemon" -> C:\Windows\SysNative\NvCpl.DLL [RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup] -> [2008/12/04 02:42:00 | 15,880,736 | —- | M] ()
"NvMediaCenter" -> C:\Windows\SysNative\NvMcTray.DLL [RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit] -> [2008/12/04 02:42:00 | 00,082,464 | —- | M] ()
"OnScreenDisplay" -> C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe [C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe] -> [2008/01/23 21:46:54 | 00,685,568 | —- | M] ( Hewlett-Packard Development Company, L.P.)
"RtHDVCpl" -> C:\Windows\RAVCpl64.exe [RAVCpl64.exe] -> [2007/10/09 11:58:36 | 05,429,760 | —- | M] (Realtek Semiconductor)
"SMSERIAL" -> C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe] -> [2007/01/17 08:43:14 | 00,833,536 | —- | M] (Motorola Inc.)
"SynTPEnh" -> C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] -> [2008/06/20 16:37:40 | 01,533,736 | —- | M] (Synaptics, Inc.)
"Windows Defender" -> C:\Program Files\Windows Defender\MSASCui.exe [%ProgramFiles%\Windows Defender\MSASCui.exe -hide] -> [2008/01/20 21:47:32 | 01,584,184 | —- | M] (Microsoft Corporation)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"AcronisTimounterMonitor" -> C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe [C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe] -> [2009/01/20 23:45:00 | 00,960,536 | —- | M] (Acronis)
"Adobe Reader Speed Launcher" -> C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/10/15 01:04:34 | 00,039,792 | —- | M] (Adobe Systems Incorporated)
"AppleSyncNotifier" -> C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe] -> [2009/05/20 22:01:32 | 00,177,472 | —- | M] (Apple Inc.)
"Conime" -> C:\Windows\SysWow64\conime.exe [%windir%\system32\conime.exe] -> [2008/01/20 21:49:12 | 00,069,120 | —- | M] (Microsoft Corporation)
"EKIJ5000StatusMonitor" -> C:\Windows\SysWow64\spool\DRIVERS\x64\3\EKIJ5000MUI.exe [C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe] -> File not found
"Google Quick Search Box" -> C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe ["C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe"  /autorun] -> [2009/04/15 08:02:29 | 00,068,592 | —- | M] (Google Inc.)
"HP Health Check Scheduler" -> c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe] -> [2008/10/09 07:58:56 | 00,075,008 | —- | M] (Hewlett-Packard)
"HP Software Update" -> C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe] -> [2007/05/08 16:24:20 | 00,054,840 | —- | M] (Hewlett-Packard)
"hpqSRMon" -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe] -> [2008/06/02 02:55:22 | 00,080,896 | —- | M] (Hewlett-Packard)
"hpWirelessAssistant" -> C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe] -> [2007/09/13 11:47:52 | 00,480,560 | —- | M] (Hewlett-Packard Development Company, L.P.)
"iTunesHelper" -> C:\Program Files (x86)\iTunes\iTunesHelper.exe ["C:\Program Files (x86)\iTunes\iTunesHelper.exe"] -> [2009/05/30 12:30:26 | 00,292,136 | —- | M] (Apple Inc.)
"QlbCtrl" ->  [%ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start] -> File not found
"QPService" -> C:\Program Files (x86)\HP\QuickPlay\QPService.exe ["C:\Program Files (x86)\HP\QuickPlay\QPService.exe"] -> [2007/12/19 21:27:50 | 00,468,264 | —- | M] (CyberLink Corp.)
"QuickTime Task" -> C:\Program Files (x86)\QuickTime\QTTask.exe ["C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime] -> [2009/05/26 17:18:30 | 00,413,696 | —- | M] (Apple Inc.)
"SunJavaUpdateSched" -> C:\Program Files (x86)\Java\jre6\bin\jusched.exe ["C:\Program Files (x86)\Java\jre6\bin\jusched.exe"] -> [2009/04/15 05:41:20 | 00,148,888 | —- | M] (Sun Microsystems, Inc.)
"TrueImageMonitor.exe" -> C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe] -> [2009/01/20 23:06:10 | 04,359,280 | —- | M] (Acronis)
"UCam_Menu" -> C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe ["C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"] -> [2007/08/17 01:13:28 | 00,218,408 | —- | M] (CyberLink Corp.)
"WAWifiMessage" -> C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe [C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe] -> [2007/01/08 18:53:06 | 00,311,296 | —- | M] (Hewlett-Packard Development Company, L.P.)
< Run [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2008/01/20 21:47:33 | 01,233,920 | —- | M] (Microsoft Corporation)
"WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008/01/20 21:47:52 | 02,153,472 | —- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2008/01/20 21:47:33 | 01,233,920 | —- | M] (Microsoft Corporation)
"WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008/01/20 21:47:52 | 02,153,472 | —- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\] > -> HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"LightScribe Control Panel" -> C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden] -> [2009/03/17 13:17:04 | 02,387,968 | —- | M] (Hewlett-Packard Company)
"msnmsgr" -> C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe ["C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background] -> File not found
"Sidebar" -> C:\Program Files\Windows Sidebar\sidebar.exe [C:\Program Files\Windows Sidebar\sidebar.exe /autoRun] -> [2008/01/20 21:47:57 | 01,555,968 | —- | M] (Microsoft Corporation)
"Skype" -> C:\Program Files (x86)\Skype\Phone\Skype.exe ["C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized] -> [2009/06/02 11:56:00 | 24,264,488 | R— | M] (Skype Technologies S.A.)
"SpybotSD TeaTimer" -> C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe] -> [2009/01/26 15:31:16 | 02,144,088 | RHS- | M] (Safer Networking Limited)
"swg" -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2009/06/07 09:45:59 | 00,039,408 | —- | M] (Google Inc.)
"WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008/01/20 21:47:52 | 02,153,472 | —- | M] (Microsoft Corporation)
"WMPNSCFG" -> C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe [C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe] -> File not found
< Software Policy Settings [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000] > -> HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\SOFTWARE\Policies\Microsoft\Internet Explorer -> 
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoActiveDesktop" ->  [1] -> File not found
\\"ForceActiveDesktopOn" ->  [0] -> File not found
\\"NoActiveDesktopChanges" ->  [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"ConsentPromptBehaviorAdmin" ->  [2] -> File not found
\\"ConsentPromptBehaviorUser" ->  [1] -> File not found
\\"EnableInstallerDetection" ->  [1] -> File not found
\\"EnableLUA" ->  [1] -> File not found
\\"EnableSecureUIAPaths" ->  [1] -> File not found
\\"EnableVirtualization" ->  [1] -> File not found
\\"PromptOnSecureDesktop" ->  [1] -> File not found
\\"ValidateAdminCodeSignatures" ->  [0] -> File not found
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"scforceoption" ->  [0] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"FilterAdministratorToken" ->  [0] -> File not found
\\"EnableUIADesktopToggle" ->  [0] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
\UIPI\Clipboard\ExceptionFormats\\"CF_TEXT" ->  [1] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_BITMAP" ->  [2] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_OEMTEXT" ->  [7] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIB" ->  [8] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_PALETTE" ->  [9] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_UNICODETEXT" ->  [13] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIBV5" ->  [17] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000] > -> HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveAutoRun" ->  [FF FF FF FF  [binary data]] -> File not found
\\"NoDriveTypeAutoRun" ->  [36] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000] > -> HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
< 64bit-Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\] > -> HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\Software\Microsoft\Internet Explorer\MenuExt\ -> 
E&xport to Microsoft Excel -> C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000] -> [2009/05/04 08:40:04 | 18,333,536 | —- | M] (Microsoft Corporation)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\] > -> HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\Software\Microsoft\Internet Explorer\MenuExt\ -> 
E&xport to Microsoft Excel -> C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000] -> [2009/05/04 08:40:04 | 18,333,536 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}:{5F7B1267-94A9-47F5-98DB-E99415F33AEC} [HKLM] -> C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll [Button: Blog This] -> [2009/02/06 18:07:54 | 00,187,248 | —- | M] (Microsoft Corporation)
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}:{5F7B1267-94A9-47F5-98DB-E99415F33AEC} [HKLM] -> C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll [Menu: &Blog This in Windows Live Writer] -> [2009/02/06 18:07:54 | 00,187,248 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2008/10/25 07:52:00 | 00,604,056 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2008/10/25 07:52:00 | 00,604,056 | —- | M] (Microsoft Corporation)
{3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF}:Exec [HKLM] -> C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe [Button: PokerStars] -> [2009/07/11 01:15:21 | 00,562,968 | —- | M] (PokerStars)
{58ECB495-38F0-49cb-A538-10282ABF65E7}:Exec [HKLM] -> Reg Error: Value error. [Button: HP Smart Select] -> File not found
{77BF5300-1474-4EC7-9980-D32B190E9B07}:{77BF5300-1474-4EC7-9980-D32B190E9B07} [HKLM] -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [Button: Skype] -> [2009/06/02 11:56:14 | 01,082,880 | —- | M] (Skype Technologies S.A.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2009/03/06 04:04:56 | 00,039,464 | —- | M] (Microsoft Corporation)
{DDE87865-83C5-48c4-8357-2F5B1AA84522}:{DDE87865-83C5-48c4-8357-2F5B1AA84522} [HKLM] -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [Button: HP Smart Select] -> [2008/10/15 14:44:30 | 00,505,136 | —- | M] (Hewlett-Packard Co.)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search && Destroy Configuration] -> [2009/01/26 15:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
< 64bit-Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< 64bit-Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< 64bit-Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< 64bit-Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\] > -> HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\] > -> HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{4871A87A-BFDD-4106-8153-FFDE2BAC2967} [HKLM] -> http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.8.cab [DLM Control] -> 
{6F15128C-E66A-490C-B848-5000B5ABEEAC} [HKLM] -> https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab [HP Download Manager] -> 
{7530BFB8-7293-4D34-9923-61A11451AFC5} [HKLM] -> http://download.eset.com/special/eos/OnlineScanner.cab [OnlineScanner Control] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab [Java Plug-in 1.6.0_13] -> 
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab [Java Plug-in 1.6.0_02] -> 
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab [Java Plug-in 1.6.0_13] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab [Java Plug-in 1.6.0_13] -> 
{E06E2E99-0AA1-11D4-ABA6-0060082AA75C} [HKLM] -> https://wavonline.webex.com/client/T25L/nbr/ieatgpc1.cab [GpcContainer Class] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> 
DhcpNameServer -> [removed] [removed] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{4AA6E3A5-6D8E-4FA0-93B1-860735EA4966}\\DhcpNameServer -> 208.67.222.222 208.67.220.220   (Realtek RTL8168B/8111B Family PCI-E GBE NIC) -> 
{7203C842-2207-4221-9522-DB98C69F39F3}\\DhcpNameServer -> [removed] [removed]   (Intel(R) PRO/Wireless 3945ABG Network Connection) -> 
< 64bit-Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
64bit-*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
explorer.exe -> C:\Windows\explorer.exe -> [2008/10/29 01:49:22 | 03,080,704 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2008/10/29 01:29:41 | 02,927,104 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Vista Public Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications -> 
< Vista Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications -> 
64bit-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
\List\\"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" -> C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe [C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink] -> [2006/08/30 15:35:12 | 00,952,088 | —- | M] (EarthLink, Inc.)
< Vista Active Firewall Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules -> 
{036F3367-7BA3-44E8-AF6F-B6F83372DF37} -> rport=2177 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31265 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{0625F0EB-43DD-42D5-98DA-03D44AE6F307} -> lport=139 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28503 | app=system | 
{0D806C0C-0D95-498D-93B4-E01E8673BCFD} -> lport=138 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28527 | app=system | 
{0E0449C8-B2A7-466B-A796-1A5B9151E571} -> lport=445 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28511 | app=system | 
{129C7EE6-46DB-47F2-8218-48FB6FEF545D} -> lport=9324 | profile=public | protocol=6 | dir=in | action=allow | name=ekdiscovery | 
{25D9CA81-DAF8-48CB-9928-885A8BD1AD1C} -> lport=9322 | profile=public | protocol=6 | dir=in | action=allow | name=ekdiscovery | 
{2C70658D-94AF-4681-802C-15B9E4EF5AAB} -> lport=2177 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31253 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{2F40087A-0AE6-4F9D-8AD8-4DDFDC8984B3} -> rport=137 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28523 | app=system | 
{38257B5E-71AE-45BA-A453-611C622D1F5D} -> lport=9323 | profile=public | protocol=6 | dir=in | action=allow | name=ekdiscovery | 
{4BD53FD9-6C2A-4F64-BCA4-E02C986E931A} -> lport=10243 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31285 | app=system | 
{4C5A1697-3E3C-4571-854B-6F74BF9E4D18} -> rport=1900 | profile=domain | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31273 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv | 
{5F0F5A09-BDCA-4819-8A8C-73B058D1B80D} -> lport=2177 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31261 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{69458542-D8A2-4ECF-AF19-378623A968EF} -> rport=139 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28507 | app=system | 
{85B40735-3690-495C-8429-80C8F3B373C8} -> lport=2869 | profile=domain | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31277 | app=system | 
{967F64C1-2598-4B39-AB6A-9BB22F9929A7} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28535 | app=%systemroot%\system32\spoolsv.exe | svc=spooler | 
{9C8BAD65-2DDE-4C21-9864-660943171E2E} -> lport=9324 | profile=private | protocol=6 | dir=in | action=allow | name=ekdiscovery | 
{A2B3333E-6B68-41C4-ABC0-DBC8FA48CB86} -> rport=10243 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31289 | app=system | 
{A5D98F2F-3C6B-48C1-8A50-6C2A693F4764} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28539 | svc=rpcss | 
{AD6C02F8-8FFD-4765-979D-9438B44FC671} -> rport=445 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28515 | app=system | 
{B2D2392C-A055-4118-A90C-CF5CCA79E10E} -> rport=138 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28531 | app=system | 
{B85BFE64-F32E-411A-866C-62FA51380D82} -> lport=9323 | profile=private | protocol=6 | dir=in | action=allow | name=ekdiscovery | 
{B8C87A33-C2AC-4884-8372-CF222CCDCDA7} -> lport=9322 | profile=private | protocol=6 | dir=in | action=allow | name=ekdiscovery | 
{BB1C4F93-E985-406B-A367-2502EAF7E9B9} -> lport=1900 | profile=domain | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31269 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv | 
{BBCB75FD-CCD7-49DE-8880-67592C06494D} -> lport=137 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28519 | app=system | 
{BBE45120-E9B3-4780-949C-33432D515002} -> rport=2177 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31257 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules -> 
{042C3286-466E-4E09-8D34-F5A5CCBBE557} -> profile=public | protocol=6 | dir=in | action=allow | name=bonjour | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
{09690D15-88F7-4C07-8BEB-52990EE022F3} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31025 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{0DAF408A-D234-4FED-8F92-FA7213667FF3} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31281 | app=system | 
{0E2CC26E-117B-4B55-BA91-1F614C536291} -> profile=public | protocol=17 | dir=in | action=allow | name=microsoft office onenote | app=c:\program files (x86)\microsoft office\office12\onenote.exe | 
{0F76C035-7741-4FE4-8C8E-66EAF9669860} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31293 | app=%programfiles%\windows media player\wmplayer.exe | 
{26A54064-B771-48ED-A004-C4EA66541C62} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31297 | app=%programfiles%\windows media player\wmplayer.exe | 
{27AE8CEF-24CC-4C6F-AC74-43D79AF12B2D} -> profile=private | protocol=1 | dir=out | action=allow | name=@firewallapi.dll,-28544 | 
{2E472F4E-0913-4FB5-BDE6-6AFD1D34C966} -> dir=in | action=allow | name=cyberlink powerdirector | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe | 
{3DEF736A-E7AB-42B3-8751-76A8DEEE8206} -> profile=public | protocol=17 | dir=in | action=allow | name=bonjour | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
{4679F29B-F29A-4289-B558-2C90563AB904} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31309 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{4FC93147-EF44-462A-B0E6-82D9F48B7465} -> profile=domain | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31024 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{573E3800-2438-445B-9BFA-55B31FB356A8} -> profile=domain | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31023 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{6D18FF12-E37E-44FD-A9F7-0FF42260C397} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31305 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{6F0F4B02-C166-4581-B02E-63E8DEAC1B9D} -> profile=domain | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31007 | app=%programfiles%\windows media player\wmplayer.exe | 
{701DA645-C31F-4C59-B650-0F9F9B21FF3F} -> profile=public | protocol=17 | dir=in | action=allow | name=itunes | app=c:\program files (x86)\itunes\itunes.exe | 
{74A35B19-3CEE-4087-90ED-287EC3B2ACD2} -> profile=public | protocol=6 | dir=in | action=allow | name=microsoft office onenote | app=c:\program files (x86)\microsoft office\office12\onenote.exe | 
{81FAA986-7A5C-49EF-8AC0-4170A83D4A8F} -> profile=public | protocol=6 | dir=in | action=allow | name=itunes | app=c:\program files (x86)\itunes\itunes.exe | 
{89D0516E-0C78-47E7-9A33-D0093E2AF699} -> profile=domain | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31003 | app=%programfiles%\windows media player\wmplayer.exe | 
{8EBD22DE-F0C4-4BCD-AB6A-FDA397EE9335} -> profile=private | protocol=58 | dir=in | action=allow | name=@firewallapi.dll,-28545 | 
{9290B435-8617-4515-86CD-82522E35016C} -> dir=in | action=allow | name=windows live sync | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | 
{94D8AF44-A3BC-4CFD-ABA0-38649658BCA7} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31324 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{9B990D47-7533-4960-BB96-026E6544D4DA} -> profile=private | protocol=58 | dir=out | action=allow | name=@firewallapi.dll,-28546 | 
{9D819751-ED51-4CBB-BD05-B84ABDECC616} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31325 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{9E2D0611-608C-44B3-BED3-CF5AE37498BA} -> profile=private | protocol=1 | dir=in | action=allow | name=@firewallapi.dll,-28543 | 
{9F67C80F-9C46-4D82-8519-F78827ACE7D1} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31321 | app=%systemroot%\system32\svchost.exe | svc=upnphost | 
{A07C74C8-E0E8-4E55-87DF-0F7DAF89454F} -> profile=private | protocol=6 | dir=in | action=allow | name=kodak aio scheduled maintenance | app=c:\program files (x86)\kodak\aio\center\kodak.statistics.exe | 
{B6916F4D-F034-4855-87CA-4D13D19CA989} -> profile=public | protocol=17 | dir=in | action=allow | name=aol loader | app=c:\program files (x86)\common files\aol\loader\aolload.exe | 
{BBA08CD3-2C8F-4C14-8258-0DA006FD050E} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31323 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{C3BD140B-C899-4023-88F6-CB11EC0BA12C} -> dir=in | action=allow | name=quick play | app=c:\program files (x86)\hp\quickplay\qp.exe | 
{C8B1FA08-4508-4E2F-86C2-2EAF5B7F89A8} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31301 | app=%programfiles%\windows media player\wmplayer.exe | 
{CC7E52DD-E26A-443E-9053-2A943E7685D2} -> profile=private | protocol=17 | dir=in | action=allow | name=kodak aio scheduled maintenance | app=c:\program files (x86)\kodak\aio\center\kodak.statistics.exe | 
{CF0DA15E-4C2A-45CE-BB7A-899A724D68B1} -> dir=in | action=allow | name=quick play resident program | app=c:\program files (x86)\hp\quickplay\qpservice.exe | 
{D8DB2BE8-8061-4486-B560-85F1386B72BC} -> dir=in | action=allow | name=skype | app=c:\program files (x86)\skype\phone\skype.exe | 
{D97DF203-1562-4A97-9E70-4E879CE4E3D6} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31317 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{F8E695BF-A263-432E-BA12-86AE6440684B} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31011 | app=%programfiles%\windows media player\wmplayer.exe | 
{F95D1EFC-35AC-439B-B77B-CC8B9FC434D9} -> profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31313 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{FF153752-858D-4F24-97E4-1D632EF5F2DB} -> profile=public | protocol=6 | dir=in | action=allow | name=aol loader | app=c:\program files (x86)\common files\aol\loader\aolload.exe | 
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" -> C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe [C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink] -> [2006/08/30 15:35:12 | 00,952,088 | —- | M] (EarthLink, Inc.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" -> C:\Windows\SysNative\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/01/20 21:46:54 | 00,079,872 | —- | M] ()
< Drives with AutoRun files > ->  -> 
C:\autorun.inf [] -> C:\autorun.inf [ NTFS ] -> [2009/07/12 10:56:40 | 00,000,000 | RHSD | M]
D:\AUTOMODE [@echo off | IF EXIST C:\ST_RP\MANUALMODE ECHO MANUAL BATCH MODE ALREADY SET ! | IF NOT EXIST C:\ST_RP\MANUALMODE ECHO SET TO MANUAL BATCH EXECUTION ! | IF NOT EXIST C:\ST_RP\MANUALMODE IF EXIST C:\ST_RP\AUTOMODE DEL C:\ST_RP\AUTOMODE /F > NUL | IF NOT EXIST C:\ST_RP\MANUALMODE COPY C:\ST_RP\SET_AUTO_MODE.CMD C:\ST_RP\MANUALMODE > NUL | ECHO. | ] -> D:\AUTOMODE [ NTFS ] -> [2005/09/11 10:18:54 | 00,000,340 | -HS- | M] ()
D:\autorun.inf [] -> D:\autorun.inf [ NTFS ] -> [2009/07/12 10:56:40 | 00,000,000 | RHSD | M]
F:\autorun.inf [] -> F:\autorun.inf [ FAT32 ] -> [2009/07/12 10:56:42 | 00,000,000 | RHSD | M]
G:\autorun.inf [] -> G:\autorun.inf [ NTFS ] -> [2009/07/12 10:56:41 | 00,000,000 | RHSD | M]
H:\autorun.inf [] -> H:\autorun.inf [ NTFS ] -> [2009/07/12 10:56:41 | 00,000,000 | RHSD | M]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
 
[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
 
[Files/Folders - Created Within 30 Days]
OTS.exe -> C:\Users\Eric\Desktop\OTS.exe -> [2009/07/12 11:07:01 | 00,513,536 | —- | C] (OldTimer Tools)
autorun.inf -> C:\autorun.inf -> [2009/07/12 10:56:40 | 00,000,000 | RHSD | C]
Flash_Disinfector.exe -> C:\Users\Eric\Desktop\Flash_Disinfector.exe -> [2009/07/12 10:56:14 | 00,132,597 | —- | C] ()
PokerStars -> C:\Users\Eric\AppData\Local\PokerStars -> [2009/07/11 01:15:29 | 00,000,000 | —D | C]
PokerStars.lnk -> C:\Users\Public\Desktop\PokerStars.lnk -> [2009/07/11 01:15:23 | 00,000,900 | —- | C] ()
PokerStars -> C:\Program Files (x86)\PokerStars -> [2009/07/11 01:15:15 | 00,000,000 | —D | C]
Apple Computer -> C:\Users\Eric\AppData\Local\Apple Computer -> [2009/07/08 16:17:24 | 00,000,000 | —D | C]
Malwarebytes -> C:\Users\Eric\AppData\Roaming\Malwarebytes -> [2009/07/08 16:05:43 | 00,000,000 | —D | C]
Malwarebytes' Anti-Malware.lnk -> C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/07/08 16:05:42 | 00,000,848 | —- | C] ()
mbamswissarmy.sys -> C:\Windows\SysWow64\drivers\mbamswissarmy.sys -> [2009/07/08 16:05:39 | 00,038,160 | —- | C] (Malwarebytes Corporation)
Malwarebytes -> C:\ProgramData\Malwarebytes -> [2009/07/08 16:05:38 | 00,000,000 | —D | C]
mbam.sys -> C:\Windows\SysNative\drivers\mbam.sys -> [2009/07/08 16:05:37 | 00,022,040 | —- | C] ()
Malwarebytes' Anti-Malware -> C:\Program Files (x86)\Malwarebytes' Anti-Malware -> [2009/07/08 16:05:37 | 00,000,000 | —D | C]
mbam-setup.exe -> C:\Users\Eric\Desktop\mbam-setup.exe -> [2009/07/08 16:03:35 | 03,561,752 | —- | C] (Malwarebytes Corporation									)
HJTInstall.exe -> C:\Users\Eric\Desktop\HJTInstall.exe -> [2009/07/08 15:44:57 | 00,812,344 | —- | C] (Trend Micro Inc.)
HijackThis.lnk -> C:\Users\Eric\Desktop\HijackThis.lnk -> [2009/07/08 14:32:46 | 00,001,928 | —- | C] ()
Trend Micro -> C:\Program Files (x86)\Trend Micro -> [2009/07/08 14:32:44 | 00,000,000 | —D | C]
Spybot - Search & Destroy.lnk -> C:\Users\Eric\Desktop\Spybot - Search & Destroy.lnk -> [2009/07/08 14:24:08 | 00,001,097 | —- | C] ()
Spybot - Search & Destroy -> C:\ProgramData\Spybot - Search & Destroy -> [2009/07/08 14:23:59 | 00,000,000 | —D | C]
Spybot - Search & Destroy -> C:\Program Files (x86)\Spybot - Search & Destroy -> [2009/07/08 14:23:59 | 00,000,000 | —D | C]
{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} -> C:\ProgramData\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} -> [2009/07/08 14:10:56 | 00,000,000 | —D | C]
GoogleUpdateTaskMachineUA.job -> C:\Windows\tasks\GoogleUpdateTaskMachineUA.job -> [2009/07/01 06:56:49 | 00,000,898 | —- | C] ()
GoogleUpdateTaskMachineCore.job -> C:\Windows\tasks\GoogleUpdateTaskMachineCore.job -> [2009/07/01 06:56:26 | 00,000,894 | —- | C] ()
Diagnostics -> C:\Diagnostics -> [2009/06/26 21:41:24 | 00,000,000 | —D | C]
Safari.lnk -> C:\Users\Public\Desktop\Safari.lnk -> [2009/06/24 13:02:40 | 00,001,866 | —- | C] ()
Safari -> C:\Program Files (x86)\Safari -> [2009/06/24 13:02:33 | 00,000,000 | —D | C]
Alex Feinman -> C:\Program Files\Alex Feinman -> [2009/06/19 08:54:33 | 00,000,000 | —D | C]
RTCOM -> C:\Windows\SysWow64\RTCOM -> [2009/06/14 20:29:19 | 00,000,000 | —D | C]
HPCeeScheduleForEric.job -> C:\Windows\tasks\HPCeeScheduleForEric.job -> [2009/06/14 20:27:34 | 00,000,330 | —- | C] ()
Hewlett-Packard -> C:\Users\Eric\AppData\Local\Hewlett-Packard -> [2009/06/14 20:27:34 | 00,000,000 | —D | C]
USetup.iss -> C:\Windows\USetup.iss -> [2009/06/14 20:01:16 | 00,000,553 | —- | C] ()
rixdicon.dll -> C:\Windows\SysNative\rixdicon.dll -> [2009/06/14 19:47:20 | 00,172,032 | —- | C] ()
rimmpx64.sys -> C:\Windows\SysNative\drivers\rimmpx64.sys -> [2009/06/14 19:47:20 | 00,060,928 | —- | C] ()
rixdpx64.sys -> C:\Windows\SysNative\drivers\rixdpx64.sys -> [2009/06/14 19:47:20 | 00,057,856 | —- | C] ()
rimspx64.sys -> C:\Windows\SysNative\drivers\rimspx64.sys -> [2009/06/14 19:47:20 | 00,055,296 | —- | C] ()
HP Help and Support.lnk -> C:\Users\Public\Desktop\HP Help and Support.lnk -> [2009/06/14 19:21:47 | 00,001,965 | —- | C] ()
EncDec.dll -> C:\Windows\SysNative\EncDec.dll -> [2009/06/13 20:49:47 | 00,558,592 | —- | C] ()
psisrndr.ax -> C:\Windows\SysNative\psisrndr.ax -> [2009/06/13 20:49:44 | 00,289,792 | —- | C] ()
EncDec.dll -> C:\Windows\SysWow64\EncDec.dll -> [2009/06/13 20:49:43 | 00,428,544 | —- | C] (Microsoft Corporation)
psisdecd.dll -> C:\Windows\SysNative\psisdecd.dll -> [2009/06/13 20:49:43 | 00,375,808 | —- | C] ()
psisdecd.dll -> C:\Windows\SysWow64\psisdecd.dll -> [2009/06/13 20:49:43 | 00,293,376 | —- | C] (Microsoft Corporation)
mpg2splt.ax -> C:\Windows\SysNative\mpg2splt.ax -> [2009/06/13 20:49:43 | 00,227,328 | —- | C] ()
psisrndr.ax -> C:\Windows\SysWow64\psisrndr.ax -> [2009/06/13 20:49:43 | 00,217,088 | —- | C] (Microsoft Corporation)
mpg2splt.ax -> C:\Windows\SysWow64\mpg2splt.ax -> [2009/06/13 20:49:43 | 00,177,664 | —- | C] (Microsoft Corporation)
MSNP.ax -> C:\Windows\SysNative\MSNP.ax -> [2009/06/13 20:49:43 | 00,101,376 | —- | C] ()
MSNP.ax -> C:\Windows\SysWow64\MSNP.ax -> [2009/06/13 20:49:42 | 00,080,896 | —- | C] (Microsoft Corporation)
Eric Scott Bio.doc -> C:\Users\Eric\Documents\Eric Scott Bio.doc -> [2009/06/13 17:16:25 | 00,025,088 | —- | C] ()
EKDeviceServices.dll -> C:\Windows\SysWow64\EKDeviceServices.dll -> [2009/06/12 07:52:56 | 00,012,800 | —- | C] ()
primopdf.ini -> C:\Windows\primopdf.ini -> [2009/04/26 23:13:36 | 00,000,326 | —- | C] ()
edvrClient.ini -> C:\Windows\edvrClient.ini -> [2009/03/03 16:14:00 | 00,000,080 | —- | C] ()
tcpmon.ini -> C:\Windows\SysWow64\tcpmon.ini -> [2008/01/20 21:50:05 | 00,060,124 | —- | C] ()
msjetoledb40.dll -> C:\Windows\SysWow64\msjetoledb40.dll -> [2008/01/20 21:49:49 | 00,368,640 | —- | C] ()
system.ini -> C:\Windows\system.ini -> [2006/11/02 07:34:27 | 00,000,219 | —- | C] ()
win.ini -> C:\Windows\win.ini -> [2006/11/02 07:34:27 | 00,000,144 | —- | C] ()
 
[Files/Folders - Modified Within 30 Days]
1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> 
8 C:\Users\Eric\AppData\Local\Temp\*.tmp files -> C:\Users\Eric\AppData\Local\Temp\*.tmp -> 
NTUSER.DAT -> C:\Users\Eric\NTUSER.DAT -> [2009/07/12 11:11:22 | 02,097,152 | -HS- | M] ()
OTS.exe -> C:\Users\Eric\Desktop\OTS.exe -> [2009/07/12 11:07:20 | 00,513,536 | —- | M] (OldTimer Tools)
nvModes.dat -> C:\ProgramData\nvModes.dat -> [2009/07/12 11:06:00 | 00,041,824 | —- | M] ()
nvModes.001 -> C:\ProgramData\nvModes.001 -> [2009/07/12 11:06:00 | 00,041,824 | —- | M] ()
hpqp.ini -> C:\Users\Public\Documents\hpqp.ini -> [2009/07/12 11:05:30 | 00,000,253 | —- | M] ()
GoogleUpdateTaskMachineCore.job -> C:\Windows\tasks\GoogleUpdateTaskMachineCore.job -> [2009/07/12 11:05:10 | 00,000,894 | —- | M] ()
GoogleUpdateTaskMachineUA.job -> C:\Windows\tasks\GoogleUpdateTaskMachineUA.job -> [2009/07/12 11:01:00 | 00,000,898 | —- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2009/07/12 11:00:31 | 00,003,216 | -H– | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2009/07/12 11:00:31 | 00,003,216 | -H– | M] ()
SA.DAT -> C:\Windows\tasks\SA.DAT -> [2009/07/12 11:00:26 | 00,000,006 | -H– | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2009/07/12 11:00:25 | 00,067,584 | –S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/07/12 11:00:14 | 42,933,20704 | -HS- | M] ()
NTUSER.DAT{1862cd1a-571f-11de-9b2b-001e68408ea9}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Eric\NTUSER.DAT{1862cd1a-571f-11de-9b2b-001e68408ea9}.TMContainer00000000000000000001.regtrans-ms -> [2009/07/12 10:58:31 | 00,524,288 | -HS- | M] ()
NTUSER.DAT{1862cd1a-571f-11de-9b2b-001e68408ea9}.TM.blf -> C:\Users\Eric\NTUSER.DAT{1862cd1a-571f-11de-9b2b-001e68408ea9}.TM.blf -> [2009/07/12 10:58:31 | 00,065,536 | -HS- | M] ()
IconCache.db -> C:\Users\Eric\AppData\Local\IconCache.db -> [2009/07/12 10:58:16 | 02,397,637 | -H– | M] ()
Flash_Disinfector.exe -> C:\Users\Eric\Desktop\Flash_Disinfector.exe -> [2009/07/12 10:56:15 | 00,132,597 | —- | M] ()
PerfStringBackup.INI -> C:\Windows\SysNative\PerfStringBackup.INI -> [2009/07/12 10:54:26 | 00,690,960 | —- | M] ()
perfh009.dat -> C:\Windows\SysNative\perfh009.dat -> [2009/07/12 10:54:26 | 00,595,684 | —- | M] ()
perfc009.dat -> C:\Windows\SysNative\perfc009.dat -> [2009/07/12 10:54:26 | 00,101,350 | —- | M] ()
PublishedRacMonSWITable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonSWITable.DAT -> [2009/07/12 10:49:54 | 00,188,292 | —- | M] ()
PublishedRacMonAFLTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonAFLTable.DAT -> [2009/07/12 10:49:54 | 00,014,352 | —- | M] ()
PublishedRacMonIndex.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonIndex.DAT -> [2009/07/12 10:49:54 | 00,002,136 | —- | M] ()
PublishedRacMonOSFTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonOSFTable.DAT -> [2009/07/12 10:49:54 | 00,000,552 | —- | M] ()
PublishedRacMonHFLTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonHFLTable.DAT -> [2009/07/12 10:49:54 | 00,000,000 | —- | M] ()
PublishedRacMonCLKTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonCLKTable.DAT -> [2009/07/12 10:49:54 | 00,000,000 | —- | M] ()
Kodak AiO Scheduled Maintenance.job -> C:\Windows\tasks\Kodak AiO Scheduled Maintenance.job -> [2009/07/12 07:52:00 | 00,000,418 | —- | M] ()
qmgr1.dat -> C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat -> [2009/07/12 07:43:28 | 04,194,304 | —- | M] ()
qmgr0.dat -> C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat -> [2009/07/12 07:43:28 | 04,194,304 | —- | M] ()
PokerStars.lnk -> C:\Users\Public\Desktop\PokerStars.lnk -> [2009/07/11 01:15:23 | 00,000,900 | —- | M] ()
Malwarebytes' Anti-Malware.lnk -> C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/07/08 16:05:42 | 00,000,848 | —- | M] ()
mbam-setup.exe -> C:\Users\Eric\Desktop\mbam-setup.exe -> [2009/07/08 16:03:51 | 03,561,752 | —- | M] (Malwarebytes Corporation									)
HJTInstall.exe -> C:\Users\Eric\Desktop\HJTInstall.exe -> [2009/07/08 15:45:01 | 00,812,344 | —- | M] (Trend Micro Inc.)
HijackThis.lnk -> C:\Users\Eric\Desktop\HijackThis.lnk -> [2009/07/08 14:32:46 | 00,001,928 | —- | M] ()
Spybot - Search & Destroy.lnk -> C:\Users\Eric\Desktop\Spybot - Search & Destroy.lnk -> [2009/07/08 14:24:08 | 00,001,097 | —- | M] ()
Adobe Reader 8.lnk -> C:\Users\Public\Desktop\Adobe Reader 8.lnk -> [2009/07/08 14:10:40 | 00,001,917 | —- | M] ()
HPCeeScheduleForEric.job -> C:\Windows\tasks\HPCeeScheduleForEric.job -> [2009/06/24 22:38:53 | 00,000,330 | —- | M] ()
Safari.lnk -> C:\Users\Public\Desktop\Safari.lnk -> [2009/06/24 13:02:40 | 00,001,866 | —- | M] ()
Google Chrome.lnk -> C:\Users\Public\Desktop\Google Chrome.lnk -> [2009/06/24 08:16:15 | 00,002,025 | —- | M] ()
mbamswissarmy.sys -> C:\Windows\SysWow64\drivers\mbamswissarmy.sys -> [2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation)
mbam.sys -> C:\Windows\SysNative\drivers\mbam.sys -> [2009/06/17 11:27:46 | 00,022,040 | —- | M] ()
index.dat -> C:\Users\Eric\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2009/06/14 20:10:20 | 00,032,768 | -HS- | M] ()
index.dat -> C:\Users\Eric\AppData\Local\Temp\History\History.IE5\index.dat -> [2009/06/14 20:10:20 | 00,016,384 | -HS- | M] ()
DIFxAPI.dll -> C:\Windows\DIFxAPI.dll -> [2009/06/14 20:01:01 | 00,525,792 | —- | M] (Microsoft Corporation)
HP Help and Support.lnk -> C:\Users\Public\Desktop\HP Help and Support.lnk -> [2009/06/14 19:21:47 | 00,001,965 | —- | M] ()
Eric Scott Bio.doc -> C:\Users\Eric\Documents\Eric Scott Bio.doc -> [2009/06/13 20:16:03 | 00,025,088 | —- | M] ()
CarboniteSetup64.exe -> C:\Users\Eric\AppData\Local\Temp\CarboniteSetup64.exe -> [2009/04/29 17:22:04 | 01,067,008 | R— | M] (Carbonite, Inc.)
opa12.dat -> C:\ProgramData\Microsoft\OFFICE\DATA\opa12.dat -> [2009/04/15 08:56:02 | 00,008,428 | —- | M] ()
Amy.dat -> C:\ProgramData\Microsoft\User Account Pictures\Amy.dat -> [2009/04/15 07:43:44 | 00,000,000 | —- | M] ()
Eric.dat -> C:\ProgramData\Microsoft\User Account Pictures\Eric.dat -> [2009/04/14 21:28:33 | 00,000,000 | —- | M] ()
 
[File - Lop Check]
Roaming -> C:\Users\Amy\AppData\Roaming -> [2009/06/26 19:15:13 | 00,000,000 | —D | M]
Media Center Programs -> C:\Users\Amy\AppData\Roaming\Media Center Programs -> [2006/11/02 10:07:25 | 00,000,000 | —D | M]
Roaming -> C:\Users\Default\AppData\Roaming -> [2006/11/02 10:07:25 | 00,000,000 | —D | M]
Media Center Programs -> C:\Users\Default\AppData\Roaming\Media Center Programs -> [2006/11/02 10:07:25 | 00,000,000 | —D | M]
Roaming -> C:\Users\Default User\AppData\Roaming -> [2006/11/02 10:07:25 | 00,000,000 | —D | M]
Media Center Programs -> C:\Users\Default User\AppData\Roaming\Media Center Programs -> [2006/11/02 10:07:25 | 00,000,000 | —D | M]
Roaming -> C:\Users\Eric\AppData\Roaming -> [2009/07/08 16:05:43 | 00,000,000 | —D | M]
Acronis -> C:\Users\Eric\AppData\Roaming\Acronis -> [2009/05/31 14:03:44 | 00,000,000 | —D | M]
CyberLink -> C:\Users\Eric\AppData\Roaming\CyberLink -> [2009/04/26 13:59:16 | 00,000,000 | —D | M]
Download Manager -> C:\Users\Eric\AppData\Roaming\Download Manager -> [2009/06/10 07:59:35 | 00,000,000 | —D | M]
edvrclient -> C:\Users\Eric\AppData\Roaming\edvrclient -> [2009/04/17 17:11:04 | 00,000,000 | —D | M]
Media Center Programs -> C:\Users\Eric\AppData\Roaming\Media Center Programs -> [2006/11/02 10:07:25 | 00,000,000 | —D | M]
Move Networks -> C:\Users\Eric\AppData\Roaming\Move Networks -> [2009/05/19 14:56:50 | 00,000,000 | —D | M]
Temp -> C:\Users\Eric\AppData\Roaming\Temp -> [2009/06/12 08:14:23 | 00,000,000 | —D | M]
Template -> C:\Users\Eric\AppData\Roaming\Template -> [2009/04/19 09:56:54 | 00,000,000 | —D | M]
C:\Windows\Tasks\ -> C:\Windows\Tasks -> [2009/07/01 06:56:50 | 00,000,000 | —D | M]
GoogleUpdateTaskMachineCore.job -> C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job -> [2009/07/12 11:05:10 | 00,000,894 | —- | M] ()
GoogleUpdateTaskMachineUA.job -> C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job -> [2009/07/12 11:01:00 | 00,000,898 | —- | M] ()
HPCeeScheduleForEric.job -> C:\Windows\Tasks\HPCeeScheduleForEric.job -> [2009/06/24 22:38:53 | 00,000,330 | —- | M] ()
Kodak AiO Scheduled Maintenance.job -> C:\Windows\Tasks\Kodak AiO Scheduled Maintenance.job -> [2009/07/12 07:52:00 | 00,000,418 | —- | M] ()
SA.DAT -> C:\Windows\Tasks\SA.DAT -> [2009/07/12 11:00:26 | 00,000,006 | -H– | M] ()
SCHEDLGU.TXT -> C:\Windows\Tasks\SCHEDLGU.TXT -> [2009/07/12 10:58:27 | 00,022,016 | —- | M] ()
 
[File - Purity Scan]
 
< End of report >
Hi,

Please do the following:

Start OTS Copy/Paste the information inside the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill All Processes]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\] > ->
YN -> HKEY_USERS\S-1-5-21-832491973-3289131749-1530605032-1000\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.


NEXT



**Vista users - right click on the IE icon and run as administrator

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
All Processes Killed [Registry - Safe List] Registry key HKEY_USERS\1-5-21-832491973-3289131749-1530605032-1000\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found. [Empty Temp Folders] User: All Users User: Amy ->Temp folder emptied: 72443166 bytes ->Temporary Internet Files folder emptied: 68429559 bytes ->Java cache emptied: 7745878 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Eric ->Temp folder emptied: 4861656 bytes File delete failed. C:\Users\Eric\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 206987552 bytes ->Java cache emptied: 12684181 bytes ->FireFox cache emptied: 65186649 bytes ->Google Chrome cache emptied: 5699264 bytes ->Apple Safari cache emptied: 29796 bytes User: Public %systemdrive% .tmp files removed: 0 bytes C:\Windows\E80F62FF5D3C4A1984099721F2928206.TMP folder deleted successfully. %systemroot% .tmp files removed: 22016 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes Windows Temp folder emptied: 7868 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 423.56 mb < End of fix log > OTS by OldTimer - Version 3.0.9.3 fix logfile created on 07122009_121202 Files\Folders moved on Reboot… Registry entries deleted on Reboot… ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Sunday, July 12, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 64-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Sunday, July 12, 2009 18:57:09 Records in database: 2463228 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ Scan statistics: Files scanned: 171339 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 03:11:00 No malware has been detected. The scan area is clean. The selected area was scanned.
Please re-run the Malwarebytes program to make sure that comes up clean also, Also, please advise how your computer is running now and if there are any outstanding issues.
My computer has always ran fine, just knew there was a virus of some sort. Thank you so much for the help. Since we did the fixes with the flash drive and external hard drives attached, they should be clean as well, correct? Malwarebytes' Anti-Malware 1.38 Database version: 2395 Windows 6.0.6001 Service Pack 1 7/12/2009 5:49:11 PM mbam-log-2009-07-12 (17-49-11).txt Scan type: Quick Scan Objects scanned: 82805 Time elapsed: 2 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
yes,

looks clean, time for some housekeeping:

Please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


[external image: Posted Image] Your Java is out of date.

Java™ 6 Update 13 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.

An update should begin; > follow the prompts.

Now, please go to your Add/Remove programs, uninstall all the old Java programs, leaving the newly installed Java 6, update 14.


NEXT

  • Make sure you have an Internet Connection.
  • Double-click OTS.exe to run it. (Vista users, please right click on OTS.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTS to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You should be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Now we need to create a new clean SYSTEM RESTORE point.

  • Close and save any documents that you may have open.
  • Open up the Start Menu and right-click on "Computer", and then select "Properties"
  • This will take you into the System area of Control Panel. Click on the "Advanced system settings" on the left hand side.
  • Now select the "System Protection" tab to get to the System Restore section.
  • Click the "Create" button to create a new restore point. You'll be prompted for a name, and you might want to give it a useful name that you'll be able to easily identify later.
  • Click the Create button, and then the system will create the restore point.
  • When it's all finished, you'll get a message saying it's completed successfully.
  • You will now have a new restore point

Then remove all previous Restore Points
  • Click Start Menu > Run > copy and paste
  • cleanmgr into the run box
  • At the top, click on the More Options tab, under System Restore and Shadow Copies group,
  • Click the Clean up button,
  • Vista will ask you if you’re sure, click on Yes button.
  • When finished, click on Cancel button to exit.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.

Note: Some of these programs may not be compatible with your 64bit system - try them, take from them what you will.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Java did not show up in the classic view of the control panel. I deleted all previous Java programs and installed the most up to date version. Having problems deleting previous restore points. Clicked the Start icon, typed run….in the run dialog box typed "cleanmgr"… Disk Clean Up window opens with two options…1 - My Files Only or 2 - Files From All Users on This Computer… There is not a "more options tab".
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI