This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer has slowed down ~ also had issues with Adobe

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have had a major slow down since a recent Windows update. Some sites are saying I dont have the latest Java version, but I downloaded it. Here is my log: Also when I ran it I got the notification that Hijack was barred from some host files

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:20:27 PM, on 3/30/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files (x86)\AVG\AVG8\avgtray.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\AVG\AVG8\aAvgApi.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~2\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~2\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [googletalk] C:\Users\Lisa\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\AESTSr64.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgfws8.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcg_device - Unknown owner - C:\Windows\system32\lxcgcoms.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\STacSV64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12918 bytes
Hi mrs_bojangles,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Some sites are saying I dont have the latest Java version, but I downloaded it.

You don't have the latest version installed anyway.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "JRE 6 Update 14.
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u14-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
I seem to be still having Java issues. Once it is done and says it installed, it is not listed under prgrams, nor is it listed in the control panel. The only place I can find it it in ad/remove area of programs in the control panel. I deleted everything before I installed the first time, and the second time I cleared everything out again and made sure I was offline without my AVG running and stopped my Windows Defender. Can you advise as to what may be stopping it from loading properly?
mrs_bojangles,

Let's try this:

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.

Then try to install the new Java.

Even if it doesn't work, please continue with the other instructions.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:20:27 PM, on 3/30/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files (x86)\AVG\AVG8\avgtray.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\AVG\AVG8\aAvgApi.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~2\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~2\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [googletalk] C:\Users\Lisa\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\AESTSr64.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgfws8.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcg_device - Unknown owner - C:\Windows\system32\lxcgcoms.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\STacSV64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12918 bytes
mrs_bojangles, I'm not sure how to interpret your post. Javara wouldn't run? Java wouldn't update? Malwarebytes Antimalware wouldn't run?
Java would not give me the log file that it said it would create. I did not try to reinstall Java. Malaware ran fine with no detections. I have been keeping that ever since my last issue in March. I typically run it about once a month.
mrs_bojangles,

Let's try for a different log.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTL logfile created on: 8/10/2009 1:53:41 PM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Users\Lisa\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.31 Gb Available Physical Memory | 61.72% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.03 Gb Total Space | 153.24 Gb Free Space | 69.02% Space Free | Partition Type: NTFS
Drive D: | 10.85 Gb Total Space | 1.83 Gb Free Space | 16.88% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LISA-PC
Current User Name: Lisa
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2009/07/28 16:57:38 | 00,297,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgwdsvc.exe
PRC - [2009/07/28 16:57:44 | 01,370,488 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgfws8.exe
PRC - [2008/02/26 16:13:22 | 00,073,728 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
PRC - [2008/05/15 00:56:54 | 00,292,248 | —- | M] () – C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
PRC - [2008/05/15 00:56:58 | 00,116,112 | —- | M] () – C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
PRC - [2008/03/26 17:26:56 | 00,341,328 | —- | M] () – C:\Windows\SMINST\BLService.exe
PRC - [2007/01/09 04:25:00 | 00,272,024 | —- | M] () – C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
PRC - [2007/01/04 16:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
PRC - [2009/07/28 16:58:04 | 00,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgemc.exe
PRC - [2009/07/28 16:58:16 | 00,693,016 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgcsrvx.exe
PRC - [2008/03/27 03:15:24 | 00,656,040 | —- | M] () – C:\Program Files (x86)\Lexmark Z2300 Series\lxdpmon.exe
PRC - [2008/02/26 16:08:32 | 02,289,664 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
PRC - [2006/09/11 05:40:32 | 00,218,032 | —- | M] (Macrovision Corporation) – C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
PRC - [2008/05/15 00:56:38 | 00,468,264 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\HP\QuickPlay\QPService.exe
PRC - [2008/03/14 10:45:10 | 00,202,032 | —- | M] ( Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
PRC - [2008/06/02 02:55:22 | 00,080,896 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
PRC - [2007/05/08 18:24:20 | 00,054,840 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
PRC - [2007/11/20 09:44:58 | 00,488,752 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
PRC - [2008/01/25 20:05:30 | 00,148,832 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
PRC - [2008/12/29 22:58:01 | 00,185,872 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
PRC - [2008/03/27 03:15:26 | 00,107,176 | —- | M] (Lexmark International Inc.) – C:\Program Files (x86) (x86)\Lexmark Z2300 Series\ezprint.exe
PRC - [2007/09/26 08:34:40 | 00,316,720 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
PRC - [2008/04/03 13:33:26 | 00,193,840 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
PRC - [2008/04/11 11:04:54 | 00,685,360 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
PRC - [2009/02/20 14:22:34 | 00,079,088 | —- | M] (Yahoo! Inc.) – C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
PRC - [2009/04/21 22:34:24 | 12,314,456 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE
PRC - [2009/07/28 16:58:16 | 00,693,016 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgcsrvx.exe
PRC - [2008/11/13 10:33:54 | 00,097,128 | —- | M] (Microsoft Corp.) – C:\Program Files (x86)\Microsoft\Office Live\OfficeLiveSignIn.exe
PRC - [2009/08/10 13:50:13 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV:64bit: - [2008/06/27 15:53:06 | 00,089,088 | —- | M] () – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_bd5387da\AESTSr64.exe – (AESTFilters [Auto | Running])
SRV:64bit: - [2008/03/18 17:26:56 | 00,015,872 | —- | M] () – C:\Windows\SysNative\agr64svc.exe – (AgereModemAudio [Auto | Running])
SRV:64bit: - [2008/09/28 23:50:22 | 00,905,216 | —- | M] () – C:\Windows\SysNative\Ati2evxx.exe – (Ati External Event Utility [Auto | Running])
SRV:64bit: - [2008/08/07 15:47:58 | 00,028,464 | —- | M] () – C:\Windows\SysNative\Hpservice.exe – (hpsrv [Auto | Running])
SRV:64bit: - [2005/07/25 14:58:12 | 00,451,584 | —- | M] () – C:\Windows\SysNative\lxcgcoms.exe – (lxcg_device [On_Demand | Stopped])
SRV:64bit: - [2008/02/27 11:06:50 | 01,044,648 | —- | M] () – C:\Windows\SysNative\lxdpcoms.exe – (lxdp_device [Auto | Running])
SRV:64bit: - [2008/09/11 11:53:00 | 00,279,040 | —- | M] () – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_bd5387da\STacSV64.exe – (STacSV [Auto | Running])
SRV:64bit: - [2008/01/20 21:47:32 | 00,383,544 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\mpsvc.dll – (WinDefend [Auto | Running])
SRV:64bit: - [2008/01/20 21:52:15 | 01,216,000 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Running])
SRV - [2009/07/28 16:58:04 | 00,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
SRV - [2009/07/28 16:57:38 | 00,297,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - [2009/07/28 16:57:44 | 01,370,488 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgfws8.exe – (avgfws8 [Auto | Running])
SRV - [2008/07/27 13:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/27 13:01:49 | 00,093,184 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
SRV - [2008/04/03 13:33:26 | 00,193,840 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe – (Com4QLBEx [On_Demand | Running])
SRV - [2008/01/20 21:51:36 | 00,344,064 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehRecvr.exe – (ehRecvr [On_Demand | Stopped])
SRV - [2008/01/20 21:51:36 | 00,153,600 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 10:03:48 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehstart.dll – (ehstart [Auto | Stopped])
SRV - [2008/06/19 20:17:12 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2007/12/04 19:41:34 | 00,181,784 | —- | M] (WildTangent, Inc.) – C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe – (GameConsoleService [On_Demand | Stopped])
SRV - [2008/10/09 08:56:48 | 00,094,208 | —- | M] (Hewlett-Packard) – c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe – (HP Health Check Service [Auto | Running])
SRV - [2008/01/25 20:05:30 | 00,148,832 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe – (hpqwmiex [On_Demand | Running])
SRV - [2004/10/22 05:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/06/19 20:16:53 | 00,859,648 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2006/11/02 04:46:05 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\keyiso.dll – (KeyIso [On_Demand | Running])
SRV - [2008/02/26 16:13:22 | 00,073,728 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe – (LightScribeService [Auto | Running])
SRV - [2008/02/27 11:06:28 | 00,594,600 | —- | M] ( ) – C:\Windows\SysWow64\lxdpcoms.exe – (lxdp_device [Auto | Running])
SRV - [2006/11/02 08:34:14 | 00,000,000 | —D | M] – C:\Windows\SysWow64\Msdtc – (MSDTC [Unknown | Stopped])
SRV - [2008/01/20 21:48:28 | 00,592,384 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\netlogon.dll – (Netlogon [On_Demand | Stopped])
SRV - [2003/07/28 13:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/05/15 00:56:54 | 00,292,248 | —- | M] () – C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe – (QPCapSvc [Auto | Running])
SRV - [2008/05/15 00:56:58 | 00,116,112 | —- | M] () – C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe – (QPSched [Auto | Running])
SRV - [2008/03/26 17:26:56 | 00,341,328 | —- | M] () – C:\Windows\SMINST\BLService.exe – (Recovery Service for Windows [Auto | Running])
SRV - [2007/01/09 04:25:00 | 00,272,024 | —- | M] () – C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe – (RichVideo [Auto | Running])
SRV - [2007/12/07 00:20:56 | 00,088,560 | —- | M] (Sonic Solutions) – C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe – (Roxio UPnP Renderer 9 [On_Demand | Stopped])
SRV - [2007/12/07 00:20:52 | 00,362,992 | —- | M] (Sonic Solutions) – C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe – (Roxio Upnp Server 9 [Auto | Stopped])
SRV - [2008/03/06 17:19:44 | 00,313,840 | —- | M] (Sonic Solutions) – C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe – (RoxLiveShare9 [Auto | Stopped])
SRV - [2008/03/06 17:19:40 | 01,108,464 | —- | M] (Sonic Solutions) – C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe – (RoxMediaDB9 [On_Demand | Stopped])
SRV - [2008/03/06 17:19:44 | 00,170,480 | —- | M] (Sonic Solutions) – C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe – (RoxWatch9 [Auto | Stopped])
SRV - [2006/11/02 01:35:15 | 00,060,994 | —- | M] () – C:\Windows\SysWow64\Wbem\vds.mof – (vds [On_Demand | Stopped])
SRV - [2007/01/04 16:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service [Auto | Running])
SRV - [2006/11/02 01:35:15 | 00,055,846 | —- | M] () – C:\Windows\SysWow64\Wbem\vss.mof – (VSS [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV:64bit: - [2008/08/07 15:44:58 | 00,040,240 | —- | M] () – C:\Windows\SysNative\DRIVERS\Accelerometer.sys – (Accelerometer [On_Demand | Running])
DRV:64bit: - [2008/03/21 17:47:14 | 01,253,376 | —- | M] () – C:\Windows\SysNative\DRIVERS\agrsm64.sys – (AgereSoftModem [On_Demand | Running])
DRV:64bit: - [2008/04/14 17:55:54 | 00,210,448 | —- | M] () – C:\Windows\SysNative\DRIVERS\ahcix64s.sys – (ahcix64s [Boot | Running])
DRV:64bit: - [2008/01/07 15:42:06 | 00,018,488 | —- | M] () – C:\Windows\SysNative\DRIVERS\Amddfltr64.sys – (Amddfltr64 [Boot | Running])
DRV:64bit: - [2008/04/27 13:09:18 | 01,133,568 | —- | M] () – C:\Windows\SysNative\DRIVERS\athrx.sys – (athr [On_Demand | Running])
DRV:64bit: - [2008/09/29 00:28:20 | 04,709,376 | —- | M] () – C:\Windows\SysNative\DRIVERS\atikmdag.sys – (atikmdag [On_Demand | Running])
DRV:64bit: - [2008/04/27 17:25:06 | 00,016,400 | —- | M] () – C:\Windows\SysNative\DRIVERS\AtiPcie.sys – (AtiPcie [Boot | Running])
DRV:64bit: - [2009/04/27 23:04:57 | 00,029,464 | —- | M] () – C:\Windows\SysNative\DRIVERS\avgfwd6a.sys – (Avgfwfd [System | Running])
DRV:64bit: - [2009/07/28 16:58:16 | 00,427,016 | —- | M] () – C:\Windows\SysNative\Drivers\avgldx64.sys – (AvgLdx64 [System | Running])
DRV:64bit: - [2009/07/28 16:58:19 | 00,033,416 | —- | M] () – C:\Windows\SysNative\Drivers\avgmfx64.sys – (AvgMfx64 [System | Running])
DRV:64bit: - [2009/04/27 23:04:24 | 00,014,856 | —- | M] () – C:\Windows\SysNative\Drivers\avgrkx64.sys – (AvgRkx64 [Boot | Running])
DRV:64bit: - [2009/04/27 23:04:19 | 00,133,640 | —- | M] () – C:\Windows\SysNative\Drivers\avgtdia.sys – (AvgTdiA [System | Running])
DRV:64bit: - [2006/10/06 21:13:22 | 00,550,912 | —- | M] () – C:\Windows\SysNative\DRIVERS\bcmwl664.sys – (BCM43XV [On_Demand | Stopped])
DRV:64bit: - [2008/01/20 21:46:51 | 00,017,792 | —- | M] () – C:\Windows\SysNative\DRIVERS\CmBatt.sys – (CmBatt [On_Demand | Running])
DRV:64bit: - [2008/09/04 17:48:00 | 00,064,000 | —- | M] () – C:\Windows\SysNative\DRIVERS\enecir.sys – (enecir [On_Demand | Running])
DRV:64bit: - [2006/11/02 00:28:10 | 00,273,920 | —- | M] () – C:\Windows\SysNative\drivers\HdAudio.sys – (HdAudAddService [On_Demand | Running])
DRV:64bit: - [2008/08/07 15:49:42 | 00,028,464 | —- | M] () – C:\Windows\SysNative\DRIVERS\hpdskflt.sys – (hpdskflt [Boot | Running])
DRV:64bit: - [2007/06/18 19:13:12 | 00,018,432 | —- | M] () – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys – (HpqKbFiltr [On_Demand | Running])
DRV:64bit: - [2007/07/11 12:30:34 | 00,009,088 | —- | M] () – C:\Windows\SysNative\DRIVERS\HpqRemHid.sys – (HpqRemHid [On_Demand | Stopped])
DRV:64bit: - [2008/01/20 21:46:57 | 00,286,720 | —- | M] () – C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS – (HSFHWAZL [On_Demand | Stopped])
DRV:64bit: - [2008/01/20 21:46:57 | 01,523,712 | —- | M] () – C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS – (HSF_DPV [On_Demand | Stopped])
DRV:64bit: - [2006/10/09 21:09:03 | 00,742,696 | —- | M] () – C:\Windows\SysNative\DRIVERS\nvm60x64.sys – (NVENETFD [On_Demand | Stopped])
DRV:64bit: - [2007/05/01 04:00:00 | 00,052,856 | —- | M] () – C:\Windows\SysNative\Drivers\PxHlpa64.sys – (PxHlpa64 [Boot | Running])
DRV:64bit: - [2007/05/31 13:39:32 | 00,027,520 | —- | M] () – C:\Windows\SysNative\Drivers\RimUsb_AMD64.sys – (RimUsb [On_Demand | Stopped])
DRV:64bit: - [2007/01/18 16:10:22 | 00,030,336 | —- | M] () – C:\Windows\SysNative\DRIVERS\RimSerial_AMD64.sys – (RimVSerPort [On_Demand | Running])
DRV:64bit: - [2008/01/20 21:49:47 | 00,011,264 | —- | M] () – C:\Windows\SysNative\Drivers\RootMdm.sys – (ROOTMODEM [On_Demand | Running])
DRV:64bit: - [2009/01/20 07:49:48 | 00,195,584 | —- | M] () – C:\Windows\SysNative\DRIVERS\Rtlh64.sys – (RTL8169 [On_Demand | Running])
DRV:64bit: - [2008/09/19 17:43:58 | 00,068,096 | —- | M] () – C:\Windows\SysNative\drivers\RTSTOR64.SYS – (RTSTOR [On_Demand | Running])
DRV:64bit: - [2008/09/11 11:54:44 | 00,465,408 | —- | M] () – C:\Windows\SysNative\DRIVERS\stwrt64.sys – (STHDA [On_Demand | Running])
DRV:64bit: - [2008/03/28 03:06:00 | 00,324,656 | —- | M] () – C:\Windows\SysNative\DRIVERS\SynTP.sys – (SynTP [On_Demand | Running])
DRV:64bit: - [2008/01/20 21:47:27 | 00,168,704 | —- | M] () – C:\Windows\SysNative\Drivers\usbvideo.sys – (usbvideo [On_Demand | Running])
DRV:64bit: - [2008/01/20 21:46:57 | 00,724,480 | —- | M] () – C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS – (winachsf [On_Demand | Stopped])
DRV:64bit: - [2008/01/20 21:46:59 | 00,036,864 | —- | M] () – C:\Windows\SysNative\DRIVERS\WinUSB.SYS – (winusb [On_Demand | Stopped])
DRV:64bit: - [2008/01/20 21:47:28 | 00,046,080 | —- | M] () – C:\Windows\SysNative\DRIVERS\wpdusb.sys – (WpdUsb [On_Demand | Stopped])
DRV - [2006/09/18 16:35:23 | 00,001,088 | —- | M] () – C:\Windows\SysWow64\Wbem\mpsdrv.mof – (mpsdrv [On_Demand | Running])
DRV - [2006/09/18 16:36:40 | 00,003,066 | —- | M] () – C:\Windows\SysWow64\Wbem\tcpip.mof – (Tcpip [Boot | Running])
DRV - [2008/01/20 21:49:57 | 00,016,384 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\winusb.dll – (winusb [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - URLSearchHook: - Reg Error: Key error. File not found
IE - URLSearchHook: *{5aa14397-d310-447d-8548-2dd90218a07d} - Reg Error: Key error. File not found
IE - URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.1.20080205
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/23 21:58:56 | 00,000,000 | —D | M]

[2008/11/04 22:33:48 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\mozilla\Extensions
[2008/11/04 22:33:48 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/29 08:41:19 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\mozilla\Firefox\Profiles\g7kjn0qd.default\extensions
[2008/11/06 00:12:06 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\mozilla\Firefox\Profiles\g7kjn0qd.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2003/07/14 23:56:52 | 00,013,888 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL
[2008/12/29 22:58:10 | 00,144,960 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll
[2008/12/29 22:58:23 | 00,008,192 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll
[2008/12/29 22:58:07 | 00,094,208 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll

O1 HOSTS File: (736 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (Freecause Toolbar BHO) - {FC78E410-0EFA-4BEC-B283-D1DB1922F420} - C:\Program Files (x86)\CoolChaser Layout Auto Insert\Toolbar.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (CoolChaser Layout Auto Insert) - {B0208007-27C1-4BCD-93EF-EFF5DB61FC22} - C:\Program Files (x86)\CoolChaser Layout Auto Insert\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (CoolChaser Layout Auto Insert) - {B0208007-27C1-4BCD-93EF-EFF5DB61FC22} - C:\Program Files (x86)\CoolChaser Layout Auto Insert\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4:64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Lexmark Z2300 Series\ezprint.exe (Lexmark International Inc.)
O4:64bit: - HKLM..\Run: [lxdpmon.exe] C:\Program Files (x86)\Lexmark Z2300 Series\lxdpmon.exe ()
O4:64bit: - HKLM..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
O4:64bit: - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files (x86)\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EzPrint] C:\Program Files (x86) (x86)\Lexmark Z2300 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [lxdpmon.exe] C:\Program Files (x86) (x86)\Lexmark Z2300 Series\lxdpmon.exe ()
O4 - HKLM..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] C:\Program Files (x86)\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [googletalk] C:\Users\Lisa\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.DLL (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: eBay Search - C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTb.dll File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Reg Error: Key error.)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} https://ediagnostics.lexmark.com/serval.cab (Lexmark eDiagnostics Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter: - text/xml - Reg Error: Key error. File not found
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/08/10 13:50:02 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe
[2009/08/10 13:49:25 | 00,000,162 | -H– | C] () – C:\Users\Lisa\Desktop\~$ou don.doc
[2009/08/10 10:37:51 | 00,000,000 | —D | C] – C:\Users\Lisa\Desktop\JavaRa
[2009/08/10 10:36:32 | 00,071,798 | —- | C] () – C:\Users\Lisa\Desktop\JavaRa.zip
[2009/08/10 10:35:16 | 00,002,920 | —- | C] () – C:\Users\Lisa\Desktop\mbam-setup.exe
[2009/08/10 10:23:25 | 00,272,384 | —- | C] (OldTimer Tools) – C:\Users\Lisa\Desktop\TFC.exe
[2009/08/10 10:22:56 | 16,668,448 | —- | C] (Sun Microsystems, Inc.) – C:\Users\Lisa\Desktop\jre-6u15-windows-i586.exe
[2009/08/09 19:40:20 | 00,039,424 | —- | C] () – C:\Users\Lisa\Desktop\You don.doc
[2009/08/07 00:03:25 | 00,020,992 | —- | C] () – C:\Users\Lisa\Documents\Using only song names from ONE ARTIST.doc
[2009/07/29 08:44:57 | 00,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2009/07/29 08:41:16 | 00,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2009/07/29 08:40:27 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe AIR
[2009/07/28 22:55:32 | 00,000,000 | —D | C] – C:\ProgramData\NOS
[2009/07/28 22:55:32 | 00,000,000 | —D | C] – C:\Program Files (x86)\NOS
[2009/07/28 17:38:17 | 00,030,192 | —- | C] () – C:\Users\Lisa\Desktop\big_404308.jpg
[2009/07/28 17:36:02 | 00,016,274 | —- | C] () – C:\Users\Lisa\Desktop\big_9222104455501087088.jpg
[2009/07/28 17:31:36 | 00,020,423 | —- | C] () – C:\Users\Lisa\Desktop\big_4043560.jpg
[2009/07/28 17:03:29 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.dll
[2009/07/28 17:03:28 | 09,233,408 | —- | C] () – C:\Windows\SysNative\mshtml.dll
[2009/07/28 17:03:27 | 11,067,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieframe.dll
[2009/07/28 17:03:26 | 12,458,496 | —- | C] () – C:\Windows\SysNative\ieframe.dll
[2009/07/28 17:03:24 | 02,334,208 | —- | C] () – C:\Windows\SysNative\iertutil.dll
[2009/07/28 17:03:24 | 01,985,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iertutil.dll
[2009/07/28 17:03:23 | 01,484,288 | —- | C] () – C:\Windows\SysNative\urlmon.dll
[2009/07/28 17:03:23 | 01,208,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\urlmon.dll
[2009/07/28 17:03:23 | 01,146,880 | —- | C] () – C:\Windows\SysNative\wininet.dll
[2009/07/28 17:03:23 | 00,915,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2009/07/28 17:03:22 | 01,538,560 | —- | C] () – C:\Windows\SysNative\inetcpl.cpl
[2009/07/28 17:03:22 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2009/07/28 17:03:22 | 00,700,928 | —- | C] () – C:\Windows\SysNative\msfeeds.dll
[2009/07/28 17:03:22 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2009/07/28 17:03:22 | 00,458,240 | —- | C] () – C:\Windows\SysNative\iedkcs32.dll
[2009/07/28 17:03:22 | 00,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2009/07/28 17:03:22 | 00,243,712 | —- | C] () – C:\Windows\SysNative\occache.dll
[2009/07/28 17:03:22 | 00,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2009/07/28 17:03:22 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2009/07/28 17:03:21 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.tlb
[2009/07/28 17:03:21 | 01,638,912 | —- | C] () – C:\Windows\SysNative\mshtml.tlb
[2009/07/28 17:03:21 | 00,252,416 | —- | C] () – C:\Windows\SysNative\iepeers.dll
[2009/07/28 17:03:21 | 00,219,136 | —- | C] () – C:\Windows\SysNative\ieui.dll
[2009/07/28 17:03:21 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2009/07/28 17:03:21 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2009/07/28 17:03:21 | 00,162,816 | —- | C] () – C:\Windows\SysNative\ieUnatt.exe
[2009/07/28 17:03:21 | 00,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2009/07/28 17:03:21 | 00,132,096 | —- | C] () – C:\Windows\SysNative\iesysprep.dll
[2009/07/28 17:03:21 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2009/07/28 17:03:21 | 00,077,312 | —- | C] () – C:\Windows\SysNative\iesetup.dll
[2009/07/28 17:03:21 | 00,072,192 | —- | C] () – C:\Windows\SysNative\iernonce.dll
[2009/07/28 17:03:21 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2009/07/28 17:03:21 | 00,071,680 | —- | C] () – C:\Windows\SysNative\msfeedsbs.dll
[2009/07/28 17:03:21 | 00,070,656 | —- | C] () – C:\Windows\SysNative\ie4uinit.exe
[2009/07/28 17:03:21 | 00,057,667 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2009/07/28 17:03:21 | 00,057,667 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2009/07/28 17:03:21 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2009/07/28 17:03:21 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedsbs.dll
[2009/07/28 17:03:21 | 00,031,744 | —- | C] () – C:\Windows\SysNative\jsproxy.dll
[2009/07/28 17:03:21 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jsproxy.dll
[2009/07/28 17:03:21 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2009/07/28 17:03:21 | 00,012,288 | —- | C] () – C:\Windows\SysNative\msfeedssync.exe
[2009/07/14 23:31:14 | 00,015,872 | —- | C] () – C:\Users\Lisa\Documents\MC Inmates.xls
[2009/07/14 17:26:06 | 40,242,62656 | -HS- | C] () – C:\hiberfil.sys
[2009/07/14 14:45:00 | 00,189,440 | —- | C] () – C:\Windows\SysNative\t2embed.dll
[2009/07/14 14:45:00 | 00,096,256 | —- | C] () – C:\Windows\SysNative\fontsub.dll
[2009/07/14 14:44:59 | 00,366,080 | —- | C] () – C:\Windows\SysNative\atmfd.dll
[2009/07/14 14:44:59 | 00,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2009/07/14 14:44:59 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2009/07/14 14:44:59 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2009/07/14 14:44:59 | 00,048,128 | —- | C] () – C:\Windows\SysNative\atmlib.dll
[2009/07/14 14:44:59 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dciman32.dll
[2009/05/22 14:17:56 | 01,101,824 | —- | C] ( ) – C:\Windows\SysWow64\lxdpserv.dll
[2009/05/22 14:17:56 | 00,843,776 | —- | C] ( ) – C:\Windows\SysWow64\lxdpusb1.dll
[2009/05/22 14:17:56 | 00,647,168 | —- | C] ( ) – C:\Windows\SysWow64\lxdppmui.dll
[2009/05/22 14:17:56 | 00,364,544 | —- | C] ( ) – C:\Windows\SysWow64\lxdpinpa.dll
[2009/05/22 14:17:56 | 00,348,160 | —- | C] () – C:\Windows\SysWow64\LXDPinst.dll
[2009/05/22 14:17:56 | 00,339,968 | —- | C] ( ) – C:\Windows\SysWow64\lxdpiesc.dll
[2009/05/22 14:17:56 | 00,335,872 | —- | C] () – C:\Windows\SysWow64\lxdpcomx.dll
[2009/05/22 14:17:55 | 00,851,968 | —- | C] ( ) – C:\Windows\SysWow64\lxdpcomc.dll
[2009/05/22 14:17:55 | 00,663,552 | —- | C] ( ) – C:\Windows\SysWow64\lxdphbn3.dll
[2009/05/22 14:17:55 | 00,569,344 | —- | C] ( ) – C:\Windows\SysWow64\lxdplmpm.dll
[2009/05/22 14:17:55 | 00,376,832 | —- | C] ( ) – C:\Windows\SysWow64\lxdpcomm.dll
[2009/05/22 14:17:55 | 00,053,248 | —- | C] ( ) – C:\Windows\SysWow64\lxdpprox.dll
[2008/11/04 23:47:49 | 00,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/01/20 21:50:05 | 00,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 21:49:49 | 00,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2006/11/02 07:34:27 | 00,000,240 | —- | C] () – C:\Windows\win.ini
[2006/11/02 07:34:27 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2003/01/07 16:05:08 | 00,002,695 | —- | C] () – C:\Windows\SysWow64\OUTLPERF.INI

========== Files - Modified Within 30 Days ==========

[2009/08/10 13:55:48 | 00,000,416 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{BDFA058D-84F3-4BA6-B100-54E081A495E4}.job
[2009/08/10 13:50:13 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe
[2009/08/10 13:49:41 | 00,039,424 | —- | M] () – C:\Users\Lisa\Desktop\You don.doc
[2009/08/10 13:49:25 | 00,000,162 | -H– | M] () – C:\Users\Lisa\Desktop\~$ou don.doc
[2009/08/10 12:28:27 | 00,000,273 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2009/08/10 12:23:08 | 00,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/08/10 12:23:07 | 00,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/08/10 12:23:03 | 00,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2009/08/10 12:23:02 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/08/10 12:22:55 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/08/10 12:22:51 | 40,242,62656 | -HS- | M] () – C:\hiberfil.sys
[2009/08/10 12:21:50 | 03,210,675 | -H– | M] () – C:\Users\Lisa\AppData\Local\IconCache.db
[2009/08/10 10:36:33 | 00,071,798 | —- | M] () – C:\Users\Lisa\Desktop\JavaRa.zip
[2009/08/10 10:35:16 | 00,002,920 | —- | M] () – C:\Users\Lisa\Desktop\mbam-setup.exe
[2009/08/10 10:23:34 | 00,272,384 | —- | M] (OldTimer Tools) – C:\Users\Lisa\Desktop\TFC.exe
[2009/08/10 10:22:58 | 16,668,448 | —- | M] (Sun Microsystems, Inc.) – C:\Users\Lisa\Desktop\jre-6u15-windows-i586.exe
[2009/08/10 09:52:43 | 39,703,076 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2009/08/10 09:52:43 | 00,060,243 | —- | M] () – C:\Windows\SysNative\drivers\Avg\microavi.avg
[2009/08/09 20:20:30 | 00,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deploytk.dll
[2009/08/07 00:03:25 | 00,020,992 | —- | M] () – C:\Users\Lisa\Documents\Using only song names from ONE ARTIST.doc
[2009/07/28 17:38:08 | 00,030,192 | —- | M] () – C:\Users\Lisa\Desktop\big_404308.jpg
[2009/07/28 17:35:53 | 00,016,274 | —- | M] () – C:\Users\Lisa\Desktop\big_9222104455501087088.jpg
[2009/07/28 17:31:07 | 00,020,423 | —- | M] () – C:\Users\Lisa\Desktop\big_4043560.jpg
[2009/07/28 16:58:20 | 00,012,464 | —- | M] () – C:\Windows\SysNative\avgrssta.dll
[2009/07/28 16:58:19 | 00,033,416 | —- | M] () – C:\Windows\SysNative\drivers\avgmfx64.sys
[2009/07/28 16:58:16 | 00,427,016 | —- | M] () – C:\Windows\SysNative\drivers\avgldx64.sys
[2009/07/21 17:11:15 | 01,146,880 | —- | M] () – C:\Windows\SysNative\wininet.dll
[2009/07/21 17:11:04 | 01,484,288 | —- | M] () – C:\Windows\SysNative\urlmon.dll
[2009/07/21 17:09:54 | 00,243,712 | —- | M] () – C:\Windows\SysNative\occache.dll
[2009/07/21 17:07:37 | 09,233,408 | —- | M] () – C:\Windows\SysNative\mshtml.dll
[2009/07/21 17:07:34 | 00,700,928 | —- | M] () – C:\Windows\SysNative\msfeeds.dll
[2009/07/21 17:07:34 | 00,071,680 | —- | M] () – C:\Windows\SysNative\msfeedsbs.dll
[2009/07/21 17:06:56 | 00,031,744 | —- | M] () – C:\Windows\SysNative\jsproxy.dll
[2009/07/21 17:06:48 | 01,538,560 | —- | M] () – C:\Windows\SysNative\inetcpl.cpl
[2009/07/21 17:06:31 | 02,334,208 | —- | M] () – C:\Windows\SysNative\iertutil.dll
[2009/07/21 17:06:31 | 00,219,136 | —- | M] () – C:\Windows\SysNative\ieui.dll
[2009/07/21 17:06:31 | 00,132,096 | —- | M] () – C:\Windows\SysNative\iesysprep.dll
[2009/07/21 17:06:31 | 00,077,312 | —- | M] () – C:\Windows\SysNative\iesetup.dll
[2009/07/21 17:06:30 | 12,458,496 | —- | M] () – C:\Windows\SysNative\ieframe.dll
[2009/07/21 17:06:30 | 00,252,416 | —- | M] () – C:\Windows\SysNative\iepeers.dll
[2009/07/21 17:06:30 | 00,072,192 | —- | M] () – C:\Windows\SysNative\iernonce.dll
[2009/07/21 17:06:27 | 00,458,240 | —- | M] () – C:\Windows\SysNative\iedkcs32.dll
[2009/07/21 16:52:28 | 00,915,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2009/07/21 16:52:13 | 01,208,832 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\urlmon.dll
[2009/07/21 16:50:46 | 00,206,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2009/07/21 16:48:31 | 05,937,152 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.dll
[2009/07/21 16:48:27 | 00,594,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2009/07/21 16:48:27 | 00,055,296 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedsbs.dll
[2009/07/21 16:47:47 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jsproxy.dll
[2009/07/21 16:47:41 | 01,469,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2009/07/21 16:47:28 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2009/07/21 16:47:28 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2009/07/21 16:47:27 | 01,985,536 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iertutil.dll
[2009/07/21 16:47:27 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2009/07/21 16:47:26 | 11,067,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieframe.dll
[2009/07/21 16:47:26 | 00,184,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2009/07/21 16:47:26 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2009/07/21 16:47:21 | 00,386,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2009/07/21 15:34:53 | 00,162,816 | —- | M] () – C:\Windows\SysNative\ieUnatt.exe
[2009/07/21 15:34:41 | 00,070,656 | —- | M] () – C:\Windows\SysNative\ie4uinit.exe
[2009/07/21 15:34:12 | 00,012,288 | —- | M] () – C:\Windows\SysNative\msfeedssync.exe
[2009/07/21 15:34:00 | 01,638,912 | —- | M] () – C:\Windows\SysNative\mshtml.tlb
[2009/07/21 15:13:58 | 00,133,632 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2009/07/21 15:13:51 | 00,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2009/07/21 15:13:15 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2009/07/21 15:12:49 | 01,638,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.tlb
[2009/07/21 14:09:32 | 00,057,667 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2009/07/21 13:31:43 | 00,057,667 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2009/07/15 03:49:58 | 00,395,664 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2009/07/14 23:31:15 | 00,015,872 | —- | M] () – C:\Users\Lisa\Documents\MC Inmates.xls

========== LOP Check ==========

[2009/05/25 22:45:38 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming
[2009/02/17 18:03:13 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\aAvgApi
[2008/11/04 10:14:36 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\ATI
[2009/07/29 23:56:30 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Azureus
[2009/03/07 00:26:19 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Blackberry Desktop
[2009/01/29 23:17:57 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\CyberLink
[2009/03/24 17:43:08 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Hewlett Packard
[2009/08/09 15:49:22 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\LimeWire
[2006/11/02 10:07:25 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Media Center Programs
[2008/12/26 23:25:39 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\PeerNetworking
[2009/03/06 23:56:28 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Research In Motion
[2009/03/07 00:00:24 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Roxio
[2008/11/04 22:45:15 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Thunderbird
[2009/03/05 14:38:34 | 00,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\WildTangent
[2009/08/10 12:23:02 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/08/10 12:21:55 | 00,032,578 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/08/10 13:55:48 | 00,000,416 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{BDFA058D-84F3-4BA6-B100-54E081A495E4}.job

========== Purity Check ==========


< End of report >


OTL Extras logfile created on: 8/10/2009 1:53:41 PM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Users\Lisa\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.31 Gb Available Physical Memory | 61.72% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.03 Gb Total Space | 153.24 Gb Free Space | 69.02% Space Free | Partition Type: NTFS
Drive D: | 10.85 Gb Total Space | 1.83 Gb Free Space | 16.88% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LISA-PC
Current User Name: Lisa
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl[@ = cplfile] – C:\Windows\SysNative\control.exe ()
.hlp[@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html[@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf[@ = inffile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.ini[@ = inifile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
.js[@ = JSFile] – C:\Windows\SysNative\WScript.exe ()
.jse[@ = JSEFile] – C:\Windows\SysNative\WScript.exe ()
.txt[@ = txtfile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.vbe[@ = VBEFile] – C:\Windows\SysNative\WScript.exe ()
.vbs[@ = VBSFile] – C:\Windows\SysNative\WScript.exe ()
.wsf[@ = WSFFile] – C:\Windows\SysNative\WScript.exe ()
.wsh[@ = WSHFile] – C:\Windows\SysNative\WScript.exe ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.reg [@ = regfile] – C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1DDC4105-BD94-4A26-B4CE-3344AABFDE11}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{24CCD886-699F-41D0-8935-67819614ADF7}" = dir=in | app=c:\program files (x86)\avg\avg8\avgnsa.exe |
"{46553242-1377-4575-80FE-46EDBDA141E5}" = dir=in | app=c:\program files (x86)\hp\quickplay\qp.exe |
"{478A56B5-B080-4C15-AA77-440F34B68005}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{4ECBE0D2-777B-42C4-8539-15950758EBD4}" = dir=in | app=c:\program files (x86)\avg\avg8\avgupd.exe |
"{5110A6C5-D9C1-4104-BF30-02D511C4068F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{6C4B424A-4835-4B29-B9AC-6143A63AC2FA}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{6C6A2C24-4BE3-4CF3-A0B6-B86FB8D35973}" = dir=in | app=c:\program files (x86)\hp\quickplay\qpservice.exe |
"{752DBD47-93CB-4791-A21D-01DD4559719D}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{9E4871FC-D995-4299-9289-E31A7712431B}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{DE8BA1D0-1FE9-4C43-9AF0-B2E76ECDDBE8}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{FB10A1DB-877A-45F4-9160-82DA75D7913D}" = dir=in | app=c:\program files (x86)\avg\avg8\avgemc.exe |
"TCP Query User{7D1FEEF7-3B14-4ADF-B95D-73C0B8D9B89C}C:\program files (x86) (x86)\lexmark z2300 series\lxdpmon.exe" = protocol=6 | dir=in | app=c:\program files (x86) (x86)\lexmark z2300 series\lxdpmon.exe |
"UDP Query User{B8852EA6-708F-47EA-B9C9-A773CC1CEACD}C:\program files (x86) (x86)\lexmark z2300 series\lxdpmon.exe" = protocol=17 | dir=in | app=c:\program files (x86) (x86)\lexmark z2300 series\lxdpmon.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1AD2F8FE-A357-4728-BDF8-B92D794CE793}" = HP QuickTouch 1.00 D2
"{22ABA92B-6C1B-46D8-AC2B-C48EEAE172A9}" = VD64Inst
"{2DAD765B-0681-E028-F0EB-8CF5D70904C4}" = ATI Catalyst Install Manager
"{2F97CE84-9C33-4631-821B-85EA371EA254}" = ProtectSmart Hard Drive Protection
"{4BFA6EEB-AAED-4334-8E98-A907DE4DD5CF}" = AMD Driver Support for HP 3D DriverGuard
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C823E340-0984-050C-DFCA-657C26BE568E}" = ccc-utility64
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"07B260955637F1FF7587ED2AA87459040DD09BF7" = Windows Driver Package - ENE (enecir) HIDClass (09/04/2008 2.6.0.0)
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"Lexmark 2300 Series" = Lexmark 2300 Series
"Lexmark Z2300 Series" = Lexmark Z2300 Series
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{1A0F7DFF-6F13-458C-8EC3-5386E8C251C6}" = BlackBerry Device Software Updater
"{1C34CDB8-113E-1075-2689-286A54CF50AD}" = Catalyst Control Center Graphics Full Existing
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{2BEA657F-D1A0-5978-D8FA-E4541E2717FB}" = Catalyst Control Center Graphics Full New
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 D3
"{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}" = muvee autoProducer 6.1
"{380357CA-29F4-4B3C-B401-32C057E6B59B}" = HP Smart Web Printing
"{38EAC694-0D90-445F-8C17-8B50ADFE3162}" = Slingbox Flash Tour
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{45A136EC-88BF-4B95-99F5-C45D3930E1CC}" = HP MULTIPLE MODEM INSTALLER for VISTA
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.7
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{52CC81B2-19E8-E159-EF1C-F737762D99D2}" = Catalyst Control Center Graphics Previews Vista
"{558FF444-F562-4E4C-98BD-7B20EE184D2E}" = Catalyst Control Center - Branding
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{582287DA-0806-4AC0-BF19-C15E3A466034}" = LightScribe System Software 1.12.33.2
"{619B5360-FB03-D666-6C84-7982E1B1EE63}" = ccc-core-static
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{68957F05-0940-4BC5-A29E-7C0542007560}" = SHSU Menu
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73224864-7DAB-305E-2705-85109D8D4C7C}" = Skins
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{83B41111-C648-3AF1-CB40-38BFBDDA445F}" = Catalyst Control Center Core Implementation
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A1399B3E-93A8-E865-EC9B-6B452E3094E5}" = Catalyst Control Center InstallProxy
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A5CE7175-080D-49AC-B5A3-E7E3502428F5}" = HP Wireless Assistant
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{B28759B8-5FC6-4F56-9C6C-6EDAD36455A9}" = Roxio Media Manager
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B95197E0-3A42-8935-8CC8-86E2238B62D2}" = CCC Help English
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE5E3F15-320A-4865-97D3-F07227C5BB2F}" = BlackBerry Desktop Software 4.5
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E3778D3F-0038-F606-CE2A-C82B4398B05A}" = Catalyst Control Center Graphics Previews Common
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{F31E534B-4199-4552-8154-5C130710D68E}" = HP Total Care Advisor
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{F48098CD-2D66-4861-85EC-DC1D4D09D5F9}" = HP User Guides 0102
"{F4FF044B-D02A-FFA9-0F7D-3EE46B788A42}" = Catalyst Control Center Graphics Light
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG8Uninstall" = AVG 8.5
"BlackBerry_{CE5E3F15-320A-4865-97D3-F07227C5BB2F}" = BlackBerry Desktop Software 4.5
"CCleaner" = CCleaner (remove only)
"CoolChaser Layout Auto Insert" = CoolChaser Layout Auto Insert
"Graboid Video" = Graboid Video 1.3
"HijackThis" = HijackThis 2.0.2
"HP Smart Web Printing" = HP Smart Web Printing
"InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"LimeWire" = LimeWire 4.18.8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"RealPlayer 6.0" = RealPlayer
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6d
"Vuze" = Vuze
"WildTangent hp Master Uninstall" = My HP Games
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/8/2009 12:05:39 AM | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/9/2009 3:26:33 AM | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/9/2009 2:24:39 PM | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/9/2009 6:13:59 PM | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/9/2009 6:14:22 PM | Computer Name = Lisa-PC | Source = Windows Search Service | ID = 3024
Description =

Error - 8/9/2009 8:49:39 PM | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/9/2009 9:14:01 PM | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/9/2009 11:11:07 PM | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/10/2009 10:50:47 AM | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/10/2009 11:40:59 AM | Computer Name = Lisa-PC | Source = EventSystem | ID = 4621
Description =

[ System Events ]
Error - 8/10/2009 1:19:15 PM | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 8/10/2009 1:19:15 PM | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 8/10/2009 1:19:15 PM | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7031
Description =

Error - 8/10/2009 1:19:16 PM | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 8/10/2009 1:19:16 PM | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 8/10/2009 1:19:16 PM | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 8/10/2009 1:19:16 PM | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 8/10/2009 1:23:02 PM | Computer Name = Lisa-PC | Source = HTTP | ID = 15016
Description =

Error - 8/10/2009 1:24:24 PM | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 8/10/2009 2:36:34 PM | Computer Name = Lisa-PC | Source = VDS Dynamic Provider | ID = 16908298
Description =


< End of report >
mrs_bojangles,

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTL
IE - URLSearchHook: - Reg Error: Key error. File not found
IE - URLSearchHook: *{5aa14397-d310-447d-8548-2dd90218a07d} - Reg Error: Key error. File not found
IE - URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log and a new HJT log.
OTL by OldTimer - Version 3.0.10.5 log created on 08102009_150816




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:20:27 PM, on 3/30/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files (x86)\AVG\AVG8\avgtray.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\AVG\AVG8\aAvgApi.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~2\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~2\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [googletalk] C:\Users\Lisa\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\AESTSr64.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgfws8.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcg_device - Unknown owner - C:\Windows\system32\lxcgcoms.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\STacSV64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12918 bytes
mrs_bojangles,

Did OTL not give you a log?

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
I clicked on the "how to disable security programs" ~ "here" and it isnt attached to a link. I tried running the program you gave me, but it came back immediately without finding anything or scanning any files. Although my AVG icon was not on, I am presuming it is what held it up.
ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=0

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI